Data Security
NIST SP 800-88 Data Sanitization: What It Is and Why Your Business Needs It
NIST SP 800-88 is the federal standard for media sanitization. Learn the three levels of data destruction — Clear, Purge, and Destroy — and why your business needs certified sanitization certificates.
What Is NIST SP 800-88?
NIST Special Publication 800-88, titled "Guidelines for Media Sanitization," is a document published by the National Institute of Standards and Technology (NIST) that provides guidance on how to properly sanitize data from storage media. It is the most widely referenced standard for data destruction in the United States.
Originally published in 2006 and revised in 2014 (Revision 1), NIST SP 800-88 defines three levels of media sanitization, each progressively more thorough.
The Three Levels of Data Sanitization
Clear The Clear method uses standard read/write commands to overwrite data on the storage device. This is appropriate for media that will be reused within the same organization or sold to a known, trusted party.
- **Method**: Software-based overwriting (single or multi-pass)
- **When to use**: Low-sensitivity data, internal reuse
- **Limitation**: May not address all areas of the device (hidden sectors, bad blocks)
Purge The Purge method uses more advanced techniques that make data recovery infeasible using state-of-the-art laboratory techniques. This is the standard for most business applications.
- **Method**: Cryptographic erase, block erase, or enhanced overwriting
- **When to use**: Moderate to high-sensitivity data, equipment being sold or donated
- **Tools**: Active@ KillDisk, Blancco, DBAN (for HDDs)
Destroy The Destroy method physically renders the media unusable and unreadable. This is the only appropriate method for top-secret or classified data, or when media has failed sanitization.
- **Method**: Shredding, disintegration, incineration, or degaussing (for magnetic media)
- **When to use**: Highest-sensitivity data, failed sanitization, government/military
- **Result**: Media cannot be reused
Why NIST SP 800-88 Matters for Your Business
Regulatory Compliance Many regulations reference or require NIST SP 800-88 compliance:
- **HIPAA** — Healthcare organizations must follow "Administrative Safeguards" for PHI destruction
- **SOX (Sarbanes-Oxley)** — Financial records must be properly destroyed when no longer needed
- **FACTA** — Consumer data disposal rules reference appropriate destruction methods
- **State privacy laws** — California, New York, and many other states require documented data destruction
Liability Protection If your organization disposes of IT equipment without documented sanitization and a data breach occurs, you may be liable for:
- Notification costs to affected individuals
- Credit monitoring services
- Regulatory fines
- Litigation and settlement costs
- Reputational damage
A proper sanitization certificate provides documented evidence that you followed industry-standard procedures.
What Should a Sanitization Certificate Include?
A compliant certificate of data destruction should include:
1. Device identifiers — Make, model, serial number 2. Sanitization method — Clear, Purge, or Destroy 3. Software and version used — e.g., Active@ KillDisk v15 4. Result — Pass or Fail (with destruction path for failures) 5. Date and time of sanitization 6. Technician or operator identification 7. Standard referenced — NIST SP 800-88 Rev. 1
How SSTEK Handles Data Sanitization
At SSTEK, every data-bearing device that enters our Dearborn, Michigan facility follows a documented sanitization workflow:
1. Identification — All storage devices are identified and logged with serial numbers 2. Secure storage — Devices are held in camera-monitored, access-controlled areas 3. Sanitization — Software wiping using Active@ KillDisk following NIST SP 800-88 Purge guidelines 4. Verification — Each device is verified and a per-drive certificate is generated 5. Failure path — Devices that fail software sanitization are routed to physical destruction 6. Documentation — Complete sanitization reports are provided to clients
We serve businesses nationwide across the contiguous United States (48 states), excluding Alaska and Hawaii.
Need certified data sanitization? Request a quote and we'll provide a complete proposal within 24 hours.
Get a free IT equipment buyback quote · Read more SSTEK articles