Home / Compliance

Standards-based erasure your auditors will recognize

VaultRazer follows NIST SP 800-88 Rev. 2 and IEEE 2883-2022, supports more than 25 national and industry erasure standards, and produces evidence that maps to the regulations you report against.

NIST SP 800-88 Rev. 2

Which technique for which media

NIST's media sanitization guidelines set different requirements by media type. VaultRazer detects the media and applies the matching technique automatically.

MediaClearPurgeVaultRazer default
ATA / SATA hard driveOverwrite all user-addressable locationsATA Sanitize (overwrite) or Secure EraseOverwrite + verify
SAS / SCSI hard driveOverwrite all user-addressable locationsSCSI Sanitize (overwrite)Overwrite + verify
SATA SSDOverwrite all user-addressable locationsATA Sanitize block erase or crypto eraseSanitize + verify
NVMe SSDOverwrite all user-addressable locationsNVMe Sanitize (block erase or crypto erase), Format with secure eraseSanitize + verify
Self-encrypting drive (TCG Opal)OverwriteCryptographic erase of the media encryption keyCrypto erase + verify
Mobile device (iOS / Android)Factory resetCryptographic erase via device's secure resetCrypto reset + checks
USB flash / memory cardOverwrite all user-addressable locationsGenerally not supported by the media; destroy if Purge is requiredOverwrite, flag for Purge
Erasure standards

25+ standards from 8 jurisdictions

Choose a standard per policy, site or customer. The standard used is recorded on every certificate.

StandardIssuerMethodVerification
NIST SP 800-88 Rev. 2 ClearUS · NIST1 overwrite passFull read-back
NIST SP 800-88 Rev. 2 PurgeUS · NISTFirmware sanitize or crypto eraseFull read-back
IEEE 2883-2022 ClearIEEELogical overwriteFull read-back
IEEE 2883-2022 PurgeIEEESanitize command or crypto eraseFull read-back
DoD 5220.22-MUS · DoD3 passesFinal pass
DoD 5220.22-M ECEUS · DoD7 passesFinal pass
NSA 130-1US · NSA3 passesFinal pass
NCSC-TG-025US · NCSC3 passesFinal pass
US Air Force AFSSI-5020US · USAF3 passesFinal pass
US Army AR 380-19US · Army3 passesFinal pass
US Navy NAVSO P-5239-26US · Navy3 passesFinal pass
OPNAVINST 5239.1AUS · Navy3 passesFinal pass
HMG Infosec Standard 5, BaselineUK · NCSC1 passFinal pass
HMG Infosec Standard 5, EnhancedUK · NCSC3 passesFinal pass
BSI-GSDE · BSIFirmware erase + overwriteFull read-back
BSI-GSEDE · BSIExtended firmware erase + overwriteFull read-back
BSI-2011-VSDE · BSIOverwrite for classified dataFull read-back
ANSSI guidanceFR · ANSSIOverwrite or firmware eraseFull read-back
Australian ISMAU · ASD1 pass, media-dependentFinal pass
NZISMNZ · GCSB1 pass, media-dependentFinal pass
RCMP TSSIT OPS-IICA · RCMP7 passesFinal pass
TCG cryptographic eraseTCGDestroy media encryption keyRead-back sample
Firmware-based erasureATA / NVMeDrive sanitize commandFull read-back
Bruce Schneier's algorithmIndustry7 passesFinal pass
Peter Gutmann's algorithmIndustry35 passesFinal pass
Random overwrite (custom)Configurable1 to 99 passesConfigurable
Regulations

What the law asks for, and how VaultRazer answers

RegulationRequirementVaultRazer evidence
GDPR
EU · Art. 5, 17, 32
Keep personal data only as long as needed; erase on request; secure processing, including disposal.Per-asset certificate with method and timestamp; File Eraser for targeted erasure requests.
DPDP Act 2023
India · Sec. 8(7)
Data fiduciaries must erase personal data once the purpose is served or consent is withdrawn.Scheduled File Eraser jobs and device certificates to show erasure took place.
HIPAA
US · 164.310(d)(2)
Policies for final disposal of ePHI and its removal before media re-use.Signed certificate per device, plus an activity log of who erased what.
PCI DSS v4.0
Req. 9.4.7
Electronic media with cardholder data is destroyed when no longer needed, so data cannot be reconstructed.NIST Purge erasure with verification and a certificate for each POS, server or drive.
GLBA Safeguards Rule
US · 314.4(c)(6)
Securely dispose of customer information no later than two years after last use.Retention-based erasure schedules and searchable certificates.
ISO/IEC 27001:2022
A.7.14 · A.8.10
Verify storage media is erased before disposal or re-use; delete information when no longer required.Certificates and audit packs ready for certification and surveillance audits.
CCPA / CPRA
California · 1798.81, 1798.105
Destroy customer records so they are unreadable; honor deletion requests.Device and file erasure certificates tied to requests and assets.
Certificate anatomy

Six things every certificate proves

  1. Identity

    A unique certificate ID, linked to the asset tag and the drive's serial number.

  2. Hardware

    Make, model and capacity of each drive, captured directly from the device.

  3. Method and standard

    The technique used and the standard it satisfies, including the NIST level achieved.

  4. Time and place

    Start and end timestamps in UTC, the site and the operator who ran the job.

  5. Verification

    The verification method and its result. A failed verification never receives a certificate.

  6. Integrity

    A digital signature and hash. Any change to the record invalidates it.

Sample certificate

Certificate of Data Erasure

VR-CERT-2026-0042871
Drive
Samsung PM9B1 512 GB NVMe
Drive serial
S6VWNX0W305711
Method
NVMe Sanitize, crypto erase
Standard
NIST SP 800-88 Rev. 2, Purge
Completed
2026-10-06 14:03:48 UTC
Operator
j.mehta · BLR-IT-02
Verification
Full read-back, 0 errors
Result
Successful

Signed by VaultRazer Signing CA · SHA-256 9f2c41e8a7b05d3c6e1f84a2d97b0c35e6a18f4d2b7c903e15a6f80d4c2b7e91

For your auditors

Get a compliance mapping for your framework.