Recycle IT Australia

NIST SP 800-88 Rev. 2: What Changed for IT Asset Disposal

NIST SP 800-88 Rev. 2 is the current NIST guidance for media sanitisation. Published on 26 September 2025, it supersedes SP 800-88 Rev. 1 from 2014 and changes how organisations should think about sanitising information storage media before reuse or disposal.

Rather than acting mainly as a device-by-device wiping manual, Rev. 2 places greater emphasis on establishing and operating an organisation-wide media sanitisation program based on information sensitivity, risk, appropriate techniques, verification, validation and documented outcomes.

What is media sanitisation?

NIST describes media sanitisation as a process that makes access to target data on the media infeasible for a given level of effort. The objective is confidentiality: an organisation should select a sanitisation approach that is appropriate to the information, the media and the intended disposition of the asset.

What changed from Rev. 1 to Rev. 2?

1. The focus moved to a formal sanitisation program

Rev. 2 shifts attention from individual hands-on sanitisation decisions to an agency or enterprise program. That means organisations should think beyond a single wipe command and define policy, responsibilities, approved methods, evidence and decision-making for the full asset lifecycle.

2. Detailed device and tool instructions were reduced

Except for cryptographic erase, NIST removed most specific sanitisation technique and tool details and instead recommends using standards such as IEEE 2883, applicable NSA specifications or another organisationally approved standard.

3. Validation has greater importance

Successful sanitisation is not only about whether a tool completed. Organisations should distinguish between verification—checking that the sanitisation process completed as intended—and validation—deciding whether the resulting sanitisation is effective and acceptable for the confidentiality requirements and risk.

4. Cryptographic erase guidance was expanded

Rev. 2 expands and consolidates guidance around cryptographic erase, including key sanitisation and circumstances involving externally managed keys. Organisations using cryptographic erase should ensure its prerequisites and trust assumptions are satisfied rather than treating it as a universal shortcut.

5. Modern storage environments are better reflected

The guidance uses the broader concept of information storage media and better accommodates logical storage and modern computing environments. Sanitisation policy therefore needs to account for more than traditional hard disk drives.

Clear, Purge and Destroy

NIST continues to use the familiar sanitisation categories Clear, Purge and Destroy. The appropriate category depends on the sensitivity of the information, the media, available trusted techniques and what will happen to the asset next.

  • Clear applies logical techniques intended to protect against simple, non-invasive recovery methods.
  • Purge provides a higher level of assurance using suitable techniques intended to make recovery infeasible even with more advanced laboratory methods.
  • Destroy physically renders the media unusable so that data recovery is infeasible.

The correct choice should come from an organisation’s sanitisation policy and risk assessment, not simply from a preference for a particular number of overwrite passes.

What evidence should an organisation retain?

A defensible IT asset disposition process should be able to show what asset was processed, the sanitisation decision made, the technique or approved standard used, the result, verification and validation outcomes where applicable, and who or what performed the process. Serial-level records and certificates make that evidence easier to retain and audit.

For larger ITAD programs, this evidence should connect with collection records, inventory, chain of custody and final reuse, recycling or destruction outcomes. See Recycle IT’s IT asset audit and reporting service.

What does Rev. 2 mean when choosing an erasure solution or ITAD provider?

Organisations should ask whether the sanitisation method is appropriate for the actual media, whether the implementation can be trusted, what current standard or certification supports it, and what evidence is produced for each asset.

For example, Blancco states that Drive Eraser v7.18.0 has received ADISA product assurance certification covering NIST SP 800-88 Rev. 2 and IEEE 2883 for specified HDD and SSD media, including NVMe. Organisations using any erasure product should verify the exact deployed product version, supported media and current certification rather than assuming every version has the same assurance.

Secure data sanitisation with Recycle IT

Recycle IT Australia provides secure data sanitisation and destruction as part of IT asset disposal and e-waste services, with asset tracking and reporting to support an auditable chain of custody. Requirements vary by organisation and data classification, so the sanitisation method should be agreed as part of the project scope.

Request an ITAD or data sanitisation quote to discuss asset types, security requirements and reporting needs.

Official and technical sources

This article provides general information about the current NIST publication and is not a substitute for your organisation’s security policy, risk assessment or regulatory requirements.