The Complete Guide to NIST 800-88 Data Destruction

Some companies offer the NIST 800-88 Data Destruction standard, but what does that actually mean and how can you know you’re choosing the right company for the job? Learning about what this means helps to offer a comprehensive picture of what an ITAD company actually does.

1 - What is NIST 800-88?

  • NIST is part of the U.S. Dept. of Commerce. 800-88 is a publication dedicated to the Guidelines for Media Sanitization. It outlines the processes for secure sanitization, reuse, and disposal of hardware.

  • NIST 800-88 was first published in 2006 and was later revised in 2014 (Revision 1). The current version, Revision 2, was published in September of 2025.

  • Prior to the NIST 800-88 Guidelines, “delete” and “format” were treated as sufficient. However, many organizations didn’t distinguish between “the file isn’t on my screen anymore” and “the data is actually gone”. Furthermore, there was no unified data destruction standard across media types (ex. flash media, hard drives, and tapes).

  • The Guidelines for Media Sanitization allow organizations to have a repeatable way to prove data is unrecoverable before any piece of hardware can be reused, resold, or destroyed.

  • It’s the reference standard due to being one of the most widely used data sanitization standards requested or required by the U.S. Federal Government. This standard is now spreading into many private businesses.

2 - Clear vs. Purge vs. Destroy

Data destruction can consist of three main methods: clearing data, purging data, and destroying data. The “right” method all depends on each organization, how sensitive the data is, and where the device is going next (reused internally, resold, scrapped).

“Clearing” Data

  • “Clearing” data is a common method of removing files from a device; it is generally a logical technique that uses standard read and write operations to overwrite storage locations.

  • “Clearing” protects against recovery attempts using off-the-shelf file recovery software. However, it does not protect against more advanced, lab-based recovery techniques.

  • Typical use cases of this method are usually when a device is being re-deployed in the same organization.

“Purging” Data

  • “Purging” data is another widely used method of simple data destruction; it may include methods such as overwriting data, block erasing data, or cryptographic erasing.

  • This method can protect against advanced data recovery methods, such as lab-based techniques. Though depending on the security required, some organizations may find it inadequate.

  • Typical use cases of this method include a device leaving the organization it was previously a part of. It can also be used for machines going to resale, donation, or external reuse.

“Destroying” Data

  • “Destroying” data is exactly what it sounds like; generally this consists of physical elimination methods such as shredding or incineration.

  • This method guarantees what the other two methods don’t (no possibility of recovery, no possibility of reuse).

  • Typical use cases of this method include classified or highly regulated data, or drives that fail a standard purge process.

Choosing the right method depends on your data’s sensitivity and where the device is headed next. We assess both before recommending an approach. 

3 - Sanitization by Media Type

Clearing, Purging, and Destroying Data don’t apply the same way to each device. The right method of destruction depends on how the media actually stores data. Using the wrong method can fail to remove data or could damage the device for no benefit.

Hard Disk Drives (HDD)

  • Hard Drives store data through magnetic platters.

  • “Clearing” Hard Drives usually consists of a single-pass overwrite using a standard read/write command.

  • “Purging” Hard Drives usually consists of an “enhanced overwrite” (multiple read/write passes) or degaussing the drive (exposing the drive to a strong magnetic field which scrambles the magnetic platters). Note that even though degaussing a drive is categorized under purge, it does render the drive permanently unusable.

  • “Destroying” Hard Drives usually consists of physical shredding/disintegration. This is usually reserved for failed drives or the highest class of sensitive data.

Solid State Drives (SSD) and Flash Media

  • Overwriting data alone isn’t reliable on SSDs, due to the way flash storage manages data internally. Some overwrite commands cannot reach data due to the way data spread across the drive when it is written. Degaussing a drive also doesn’t work on SSDs because there isn’t a magnetic media to disrupt.

  • “Clearing” Flash Media is still possible with a standard overwrite process, but with the caveat that it may have incomplete coverage.

  • “Purging” Flash Media is usually done using a cryptographic erase (deleting an encryption key on a self-encrypting drive, which instantly renders all data unreadable). Data can also be securely erased with a vendor-specific secure erase command. However, not all manufacturers offer this feature with flash storage.

  • “Destroying” Flash Media is done with physical shredding to a specific particle size.

Mobile Devices and USB Drives

  • Both Mobile Devices and USB Drives generally follow the same logic as SSDs and Flash Media. However, there are many device specific nuances for various manufacturers and models.

  • Clearing/Purging are generally achieved using built-in encryption or cryptographic erase features, as well as manufacturer specific secure wipe tools.

  • “Destroying” Mobile Devices/USB Drives is also achieved with physical shredding for the highest sensitivity cases.

Matching media to a method isn’t optional; it’s the difference between compliant sanitization and a false sense of security. This is exactly why documentation and verification matter. Proof of the correct method that was actually used is crucial, not just that “something” was done.

4 - Why Compliance Requires Documentation

Knowing which method was used to secure your data isn’t enough. You need to be able to prove it. NIST 800-88 requires verification and validation as part of the sanitization process, not as an add-on.

Verification Isn’t Optional

  • Some companies don't distinguish between “we wiped it” and “we confirmed that the wipe worked”. This is an important gap in a lot of informal data destruction practices.

  • The NIST 800-88 standard expects confirmation that the sanitization actually succeeded, not just that a method was attempted.

What a compliant record actually contains

  • After data destruction is completed, each device must have its specific Certificate of Destruction. Each certificate should provide important information such as:

    • Device identifiers (serial numbers, asset tags)

    • Specific method used, stated precisely (eg. NIST Purge via cryptographic erase)

    • Date of destruction

    • Authorized signatures/personnel responsible

    • Chain-of-custody record (a continuous record tracking a device’s custody from the moment it leaves the client’s possession through the final disposition)

    • Facility where destruction occurred (includes any third-party facility, if applicable)

Why vague documentation isn’t good enough anymore

  • Simply recording “wiped” or “destroyed” without specifics doesn’t meet current documentation expectations. This shift reflects Revision 2’s broader emphasis on documentation, accountability, and evidence within an organization’s sanitization program.

  • Documentation isn’t just internal record-keeping. It’s what protects the organization if an audit or breach investigation occurs.

CHROMA Technology Services always provides device specific certification with every job, at no additional cost.

5 - The CHROMA Technology Services Process

Here’s what everything looks like in practice at CHROMA - the process we use, methods of destruction for each media type, and documentation.

Step 1: Hardware Pickup and Assessment

Our process begins with a scheduled pickup. Our team removes the equipment and provide proof of removal for recording purposes. Items are then transported and moved to the next stage of data destruction.

Step 2: Data Destruction

CHROMA offers two different methods of data destruction:

  • “Purge”

    • Purging drives is done using a custom hard drive destruction rig running ShredOS (a Linux-based operating system for securely erasing hard drives).

  • “Destroy”

    • Destroying drives consists of drive shredding involving a downstream partner.

After a method has been completed, a drive-specific record including the serial number will be issued.

Step 3: Hardware Refurbishment and Recycling

After data destruction has been completed, we assess each device to determine the potential for its next life.

Items are sorted into two different categories:

  • Devices that have a potential to be reused

  • Devices that will be broken down into their raw materials and recycled

We work with downstream partners who convert materials such as metals, circuit boards, and other electronic components into reusable raw materials. This keeps e-waste out of landfills and allows it to have a second life. Hardware that can be reused will be professionally repaired, which may involve replacing parts such as display, battery, keyboard, and memory. After repairs have been completed, devices will be sold and reused.

NIST 800-88 requires media-specific handling and documentation. Some companies do not follow this standard, which can result in mistreatment of confidential data, environmental harm due to improper data destruction, and harm to a company’s reputation. CHROMA Technology Services is committed to helping you avoid these risks. Call or email us to schedule a free consultation for your company today!