NIST SP 800-88 Rev. 2 is the current NIST guidance for media sanitisation. Published on 26 September 2025, it supersedes SP 800-88 Rev. 1 from 2014 and changes how organisations should think about sanitising information storage media before reuse or disposal.
Rather than acting mainly as a device-by-device wiping manual, Rev. 2 places greater emphasis on establishing and operating an organisation-wide media sanitisation program based on information sensitivity, risk, appropriate techniques, verification, validation and documented outcomes.
NIST describes media sanitisation as a process that makes access to target data on the media infeasible for a given level of effort. The objective is confidentiality: an organisation should select a sanitisation approach that is appropriate to the information, the media and the intended disposition of the asset.
Rev. 2 shifts attention from individual hands-on sanitisation decisions to an agency or enterprise program. That means organisations should think beyond a single wipe command and define policy, responsibilities, approved methods, evidence and decision-making for the full asset lifecycle.
Except for cryptographic erase, NIST removed most specific sanitisation technique and tool details and instead recommends using standards such as IEEE 2883, applicable NSA specifications or another organisationally approved standard.
Successful sanitisation is not only about whether a tool completed. Organisations should distinguish between verification—checking that the sanitisation process completed as intended—and validation—deciding whether the resulting sanitisation is effective and acceptable for the confidentiality requirements and risk.
Rev. 2 expands and consolidates guidance around cryptographic erase, including key sanitisation and circumstances involving externally managed keys. Organisations using cryptographic erase should ensure its prerequisites and trust assumptions are satisfied rather than treating it as a universal shortcut.
The guidance uses the broader concept of information storage media and better accommodates logical storage and modern computing environments. Sanitisation policy therefore needs to account for more than traditional hard disk drives.
NIST continues to use the familiar sanitisation categories Clear, Purge and Destroy. The appropriate category depends on the sensitivity of the information, the media, available trusted techniques and what will happen to the asset next.
The correct choice should come from an organisation’s sanitisation policy and risk assessment, not simply from a preference for a particular number of overwrite passes.
A defensible IT asset disposition process should be able to show what asset was processed, the sanitisation decision made, the technique or approved standard used, the result, verification and validation outcomes where applicable, and who or what performed the process. Serial-level records and certificates make that evidence easier to retain and audit.
For larger ITAD programs, this evidence should connect with collection records, inventory, chain of custody and final reuse, recycling or destruction outcomes. See Recycle IT’s IT asset audit and reporting service.
Organisations should ask whether the sanitisation method is appropriate for the actual media, whether the implementation can be trusted, what current standard or certification supports it, and what evidence is produced for each asset.
For example, Blancco states that Drive Eraser v7.18.0 has received ADISA product assurance certification covering NIST SP 800-88 Rev. 2 and IEEE 2883 for specified HDD and SSD media, including NVMe. Organisations using any erasure product should verify the exact deployed product version, supported media and current certification rather than assuming every version has the same assurance.
Recycle IT Australia provides secure data sanitisation and destruction as part of IT asset disposal and e-waste services, with asset tracking and reporting to support an auditable chain of custody. Requirements vary by organisation and data classification, so the sanitisation method should be agreed as part of the project scope.
Request an ITAD or data sanitisation quote to discuss asset types, security requirements and reporting needs.
This article provides general information about the current NIST publication and is not a substitute for your organisation’s security policy, risk assessment or regulatory requirements.