Why this update matters
Under Rev. 1, most teams worked from a table. They looked up the type of drive, ran the method the table listed and saved the report.
Rev. 2 expects more. An auditor will now want to see:
- a written sanitization policy
- the people responsible for it
- proof that every retired device went through the process
- proof that each erasure was checked
A folder of wipe reports from a free tool covers very little of this.
What changed from Rev. 1 to Rev. 2
| Topic | Rev. 1 (2014) | Rev. 2 (2025) |
|---|---|---|
| Choosing a method | Tables listed a method for each media type | Points to IEEE 2883 and other current standards |
| Focus | Decisions about each device | A sanitization program for the whole organization |
| Newer drives | Written before NVMe and self-encrypting drives were common | Covers flash, NVMe and self-encrypting drives through the standards it references |
| Crypto erase | Described, with little on keys | More detail on key handling, and moves to FIPS 140-3 |
| Verification | Recommended | A core part of the program |
| Clear / Purge / Destroy | Defined | Kept |
You now need two documents instead of one. NIST 800-88 Rev. 2 says what your program must do. IEEE 2883-2022 says which method gives you Clear or Purge on each type of drive, such as SATA, SAS, NVMe or eMMC.
If your policy or your vendor still cites a Rev. 1 table, it’s citing a withdrawn document.
A note on crypto erase. Rev. 2 says crypto erase is only as strong as the encryption and key handling behind it. For drives that held very sensitive data, consider running a block erase or an overwrite after the crypto erase, then verify the result.
What a sanitization program needs
Based on Rev. 2, your program should have five parts:
- A written policy. It says which data needs Clear, Purge or Destroy, and who can approve an exception.
- Named owners. It names who owns the policy, who runs erasures and who signs off the results.
- A link to your asset list. Each erasure record shows the asset ID and the drive serial number.
- Verification. Check every erasure by reading the drive back. Test your tools and process regularly.
- Records you can trust. Keep signed certificates and custody records for as long as your regulations require.
A four-week plan to update your process
Week 1: See where you are
- Find every policy, procedure and contract that mentions “NIST 800-88”. Update them to cite Rev. 2 and IEEE 2883.
- List every way storage leaves your company: staff leaving, hardware refreshes, warranty returns, lease returns, ITAD pickups and data center shutdowns.
Week 2: Check your tools
- Where you need Purge, check that your tool uses the drive’s own sanitize command (ATA Sanitize, NVMe Sanitize or Format, or TCG crypto erase). Overwriting alone isn’t enough for SSDs.
- Check that failed erasures are flagged for destruction and never get a certificate.
Week 3: Check your records
- Pick 20 recent certificates. Check that each one shows the asset, the operator, the method, the verification result and the time.
- Check that certificates can’t be changed after they’re issued. A digital signature or hash does this.
Week 4: Get sign-off
- Get the policy approved and name the owners.
- Schedule regular reviews of your tools and process.
If you use VaultRazer, each certificate of erasure already records the method, the standard and level reached, the operator and the verification result. For you, weeks 2 and 3 are mostly a settings review.
Common mistakes
- Using a 3-pass DoD overwrite on every drive. It takes hours on large hard drives. On SSDs it can’t reach hidden storage, so it doesn’t reach Purge.
- Treating a Windows reset as Purge. On modern phones, a factory reset does a crypto erase, which can be enough. Windows “Reset this PC” is not a Purge method and leaves no record.
- Certificates without an asset tag. A certificate with only a drive serial shows that a wipe ran. It doesn’t show that every retired asset was wiped.
Frequently asked questions
Is NIST SP 800-88 Rev. 1 still valid?
No. NIST withdrew Rev. 1 when it published Rev. 2 on 26 September 2025. Update any policies, contracts and vendor requirements that still cite Rev. 1.
Does NIST 800-88 Rev. 2 still use Clear, Purge and Destroy?
Yes. The three levels remain. Rev. 2 no longer lists a method for each type of media. It points to standards such as IEEE 2883 for that.
Is NIST 800-88 mandatory?
US federal agencies are expected to follow it. For other organizations it's guidance, but auditors, ISO 27001 assessors and enterprise customers often use it to judge whether disposal was done properly.
What's the difference between NIST 800-88 and IEEE 2883?
NIST 800-88 Rev. 2 explains how to run a sanitization program and what it must achieve. IEEE 2883-2022 sets out the technical methods for Clear and Purge on each type of drive.