Phonecheck
Blog

What NIST 800-88 Rev. 2 Changes for Device Sanitization

Smartphone and SSD on a dark surface with three glowing paths diverging from them: one unbroken line, one dissolving into particles, one ending in shattered fragments — representing the Clear, Purge, and Destroy sanitization methods.

If your buyers, auditors, or compliance team reference “NIST 800-88,” the ground moved in September 2025. NIST published SP 800-88 Revision 2 and withdrew the 2014 Revision 1 that most ITAD contracts, RFPs, and certification checklists still quote [1][2]. The three method families you know — Clear, Purge, and Destroy — survived the update. How you pick a technique did not: Rev. 2 now points technique selection at IEEE 2883, the storage-sanitization standard the drive industry itself maintains [1][3].

Here is what changed, what stayed, and what it means if you process devices at volume.

What changed in September 2025

Revision 1 dated to December 2014, before NVMe was mainstream and before self-encrypting drives were the default in enterprise fleets. NIST withdrew it on September 26, 2025, and Revision 2 took its place as the current guideline [2].

The headline change is scope. Rev. 2 states that, except for cryptographic erase, technology-specific sanitization techniques are out of scope for the document [1]. Instead of maintaining its own per-media technique tables, NIST tells readers that sanitization techniques need regular updating as storage technology evolves, so the latest version of standards such as IEEE 2883 should be consulted [1]. In practice: NIST still defines the goal posts; IEEE 2883 now defines the plays. Where the methods below fit into a wider data sanitization program is its own topic; this page covers what the standard itself now says.

Clear, Purge, and Destroy under Rev. 2

The three sanitization methods carry over, with definitions worth reading closely.

Clear

Clear applies logical techniques to sanitize data in all user-addressable storage locations, protecting against non-invasive recovery through the same interface available to the user [1]. Think standard read/write commands: rewriting with a new value, or a factory-reset menu option where rewriting is not supported [1]. It is the baseline method, and it is not appropriate for hard copy media under any conditions [1].

Purge

Purge applies physical or logical techniques that make recovery of the target data infeasible using state-of-the-art laboratory techniques, while preserving the media in a potentially reusable state [1]. That last clause is why purge matters to anyone reselling devices: the asset survives.

Rev. 2 is direct about preference: when possible, the purge sanitization method should be used instead of the clear sanitization method [1]. For acceptable purge techniques, which can include overwrite, block erase, and cryptographic erase using dedicated device sanitize commands, the document again sends you to IEEE 2883 [1][3].

Destroy

Destroy renders target data recovery infeasible using state-of-the-art laboratory techniques and leaves the media unusable for future storage [1]. It remains appropriate for hard copy and most storage media, but not for logical or virtual storage [1].

One detail worth flagging to any operation still running magnets: at the time of Rev. 2’s writing, degaussing is not considered an approved destroy sanitization technique, with NIST pointing readers to IEEE 2883 and NSA/CSS Policy Manual 9-12 for clarification [1].

Request a demo to see purge-grade erasure run per device, with the method and technique recorded as it happens.

What this means for high-volume processors

Rev. 2 frames the stakes plainly: attackers who cannot beat access controls and encryption may focus on residual data on storage media that has left an organization’s control, so organizations should use approved sanitization methods to make sure no reconstructible residual representation of sensitive data leaves with the device [1].

For a refurbisher, buyback operator, or ITAD program, that translates to three operational requirements:

  • Technique selection tracks IEEE 2883, not a 2014 table. If your SOPs cite Rev. 1 technique guidance, they cite a withdrawn document [2][3].
  • Purge-first where the device is resold. The preference for purge over clear aligns the compliance answer with the commercial one: the drive stays usable [1].
  • Evidence beats assertion. Rev. 2 recommends completing a certificate of sanitization for each device, recording the method, technique, tool and version, verification, and a signature [1]. We cover the full field list in our guide to the certificate of data destruction. A sanitization program is only audit-defensible if that record exists for every device.

Start with the paperwork. Pull the erasure clauses in your customer contracts and the method references on your certificates, and replace any bare “800-88” or “Rev. 1” citations with Rev. 2 and, where techniques are named, the matching IEEE 2883 reference [2][3]. It is a small edit now. It is an awkward finding when an auditor makes it for you.

That evidence layer is the job Phonecheck’s platform does at scale: ADISA-certified erasure workflows aligned to the method families above, with a signed certificate of erasure and a Device History Report per device — recognized by major resale marketplaces, including Back Market, Amazon Renewed, and eBay Refurbished. The standards Phonecheck’s erasure aligns to are listed in full, and the certification artifact itself is covered on the Device History Report page. If your erasure tooling still cites Rev. 1, request a demo and see what Rev. 2-era workflows look like on your own inventory.

FAQ

Is NIST 800-88 Rev. 1 still valid?

No. NIST withdrew Revision 1 on September 26, 2025, and superseded it with Revision 2 [2]. Auditors and enterprise procurement teams should be expected to check against Rev. 2 going forward.

Does NIST certify erasure software against 800-88?

SP 800-88 is guidance for building a media sanitization program, not a product certification scheme [1]. Verification comes from your own program’s records and, where required, third-party certification programs. Treat any “NIST certified” product claim as a red flag.

Is degaussing still an approved way to destroy drives?

Per Rev. 2, at the time of its writing degaussing is not considered an approved destroy sanitization technique; NIST directs readers to IEEE 2883 and NSA/CSS Policy Manual 9-12 for clarification [1]. Degaussing can also fail silently on modern drives, which is exactly the audit gap the standard is closing.

What is the practical difference between Clear and Purge?

Clear protects against recovery through the device’s normal user interface; Purge protects against state-of-the-art laboratory recovery while keeping the media reusable [1]. Rev. 2 says to use Purge instead of Clear when possible [1].

Sources

  1. NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization. NIST, September 2025.
  2. NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization. December 2014; withdrawn September 26, 2025. NIST Computer Security Resource Center.
  3. IEEE 2883-2022, IEEE Standard for Sanitizing Storage. IEEE Standards Association, 2022.

Related articles

Certify devices at scale with Phonecheck

Diagnostics, data erasure, and Device History Reports — the gold-standard platform for used-device businesses.

Request a Demo