Media Sanitization in 2026: NIST SP 800-88 Rev. 2 Guidelines & Best Practices
In This Article
In September 2025, the National Institute of Standards and Technology (NIST) published Special Publication 800-88 Revision 2, updating its widely used Guidelines for Media Sanitization. The revision reflects changes in storage technology and places greater emphasis on establishing an organization-wide media sanitization program for securely handling data-bearing devices when they are reused, redeployed, sold, recycled, or retired.
For businesses managing laptops, hard drives, solid-state drives (SSDs), mobile devices, and other storage media, deleting files or formatting a drive is not enough to protect sensitive company data. Organizations need defined policies for selecting appropriate sanitization methods, maintaining control of devices, verifying and validating results, and documenting what happens to data-bearing assets throughout the process.
This guide explains what media sanitization is, what changed with NIST SP 800-88 Rev. 2, the Clear, Purge, and Destroy sanitization methods, how to establish a media sanitization program, and best practices for securely managing data-bearing IT assets throughout their lifecycle.
What is Media Sanitization?
Media sanitization is the process of rendering access to target data on storage media infeasible for a given level of effort. Unlike simply deleting files or formatting a drive, proper sanitization uses methods designed to prevent data from being recovered based on the sensitivity of the information, the type of media, and what will happen to the device next.
Storage media can include hard disk drives (HDDs), solid-state drives (SSDs), USB flash drives, magnetic tapes, smartphones, tablets, and other devices that store organizational data. Depending on the circumstances, sanitization may allow the media to be safely reused or may require the media to be physically destroyed.
NIST SP 800-88 Rev. 2 organizes media sanitization around three methods: Clear, Purge, and Destroy. Selecting the appropriate method requires organizations to consider the confidentiality of the data, the storage technology involved, and whether the media will remain within the organization, leave organizational control, or be permanently retired.
What Changed in NIST SP 800-88 Rev. 2?
NIST SP 800-88 Rev. 2 updates the Guidelines for Media Sanitization to address changes in storage technology and place greater emphasis on establishing an organization-wide media sanitization program. Rather than treating sanitization primarily as a device-by-device technical decision, the revised guidance focuses more broadly on how organizations establish policies, responsibilities, procedures, and controls for sanitizing media throughout its lifecycle.
Key updates include:
Greater emphasis on establishing and maintaining an enterprise media sanitization program.
Updated guidance for selecting Clear, Purge, or Destroy based on the confidentiality of the information, the type of media, and its intended disposition.
Expanded guidance for cryptographic erase and considerations for determining when it is an appropriate sanitization technique.
Greater reliance on current standards and specifications, including IEEE 2883, NSA specifications, and organization-approved standards for specific sanitization techniques.
Additional emphasis on verification, validation, and documentation to determine whether sanitization was completed successfully and whether the result meets the organization’s security requirements.
Updated guidance designed to address modern storage technologies and IT environments.
For organizations, the revision reinforces that media sanitization should be managed as a repeatable program rather than an isolated end-of-life task. IT and security teams need processes for identifying data-bearing assets, selecting appropriate sanitization methods, maintaining control of those assets, validating results, and documenting what happens before equipment is reused, transferred, sold, recycled, or destroyed.
Why is Media Sanitization Important in Cybersecurity?
Media sanitization is important in cybersecurity because sensitive data can remain on storage media after files are deleted, devices are reset, or hardware is taken out of service. If a laptop, hard drive, SSD, mobile device, or other data-bearing asset leaves an organization without appropriate sanitization, information stored on that device may remain accessible.
This risk can arise when organizations offboard employees, replace aging hardware, redeploy devices, sell equipment, recycle electronics, or dispose of storage media. Depending on the device, retained data may include customer information, employee records, financial information, intellectual property, credentials, or other confidential business data.
A defined media sanitization process helps organizations determine how data-bearing assets should be handled based on the sensitivity of the information, the type of storage media, and what will happen to the device next. It also provides a consistent process for verifying, validating, and documenting sanitization before equipment is reused or leaves the organization’s control.
For remote and distributed workforces, secure device recovery is an important part of this process. An organization cannot sanitize a company laptop it has not recovered, making asset tracking, secure return logistics, and chain of custody important components of protecting data throughout the device lifecycle.
What are the Methods of Media Sanitization?
NIST SP 800-88 Rev. 2 defines three media sanitization methods: Clear, Purge, and Destroy. The appropriate method depends on factors such as the sensitivity of the data, the type and capabilities of the storage media, and whether the media will be reused, transferred, or permanently retired.
Each method provides a different level of protection against data recovery. Clear uses logical techniques to protect against simple, non-invasive recovery methods. Purge provides stronger protection by making recovery infeasible using state-of-the-art laboratory techniques while potentially allowing the media to remain usable. Destroy physically renders the media unusable and prevents subsequent use for data storage.
Clear
Clear is a media sanitization method that uses logical techniques to sanitize data in all user-addressable storage locations, protecting against simple, non-invasive data recovery techniques. Under NIST SP 800-88 Rev. 2, Clear may be appropriate when the organization determines that this level of protection is sufficient based on the confidentiality of the data and the intended disposition of the media.
The specific Clear technique depends on the type of storage media and should follow an applicable standard or organization-approved sanitization procedure. Because modern storage technologies vary in how data is stored and accessed, organizations should use techniques appropriate for the specific device rather than assuming that deleting files, formatting a drive, or using a generic overwrite process provides adequate sanitization.
Clear can allow storage media to remain usable after sanitization, making it an option when devices will be securely reused or redeployed and the organization’s risk assessment supports this method.
Purge
Purge uses physical or logical techniques that make recovery of target data infeasible using state-of-the-art laboratory techniques while potentially allowing the storage media to remain usable.
Depending on the media, Purge techniques may include cryptographic erase or other methods specified by an applicable standard or approved by the organization. Cryptographic erase sanitizes data by sanitizing the cryptographic keys required to access encrypted information, but organizations must determine whether the technology and implementation meet the requirements for using cryptographic erase effectively.
Because Purge can provide stronger protection than Clear without necessarily destroying the media, it can be appropriate when sanitized equipment will leave the organization’s control but is still suitable for reuse, resale, or redeployment.
Destroy
Destroy renders access to target data infeasible while also making the storage media incapable of storing data again. Unlike Clear and Purge, Destroy permanently prevents the media from being reused.
Destruction techniques can include methods such as shredding, pulverizing, disintegration, incineration, or other approved physical destruction processes appropriate for the media involved. Organizations may choose Destroy when the sensitivity of the data requires it, when other sanitization methods cannot be reliably applied, or when the storage media is damaged, obsolete, or no longer intended for reuse.
After destruction, organizations should handle the remaining material according to applicable electronic waste and environmental requirements.
Choosing the Right Sanitization Method by Device Type and Scenario
How Should Organizations Choose a Sanitization Method for Different Storage Media?
The appropriate sanitization method depends on the type of storage media, the sensitivity of the data, whether the device will be reused, and the sanitization capabilities supported by the device. NIST SP 800-88 Rev. 2 defines three sanitization methods: Clear, Purge, and Destroy. Organizations should select a method that provides an appropriate level of protection for the specific media and its intended disposition.
Hard disk drives (HDDs): HDDs use magnetic storage and may support Clear or Purge techniques depending on the device and the organization’s sanitization requirements. If the drive will be reused, an appropriate logical sanitization technique may allow the hardware to remain in service. If the drive cannot be reliably sanitized or will not be reused, physical destruction may be appropriate.
Solid-state drives (SSDs): SSD sanitization requires different considerations because flash-based storage does not behave like magnetic media. Organizations should use sanitization techniques supported by the specific SSD and applicable standards rather than assume that traditional overwrite methods used for HDDs will provide the same result. Purge techniques may include standardized device sanitize commands or cryptographic erase when the necessary conditions are met.
USB flash drives: USB drives also use flash memory, and their available sanitization capabilities vary by device. Organizations should evaluate whether the media supports an appropriate Clear or Purge technique. When reliable sanitization cannot be verified and the data requires stronger protection, physical destruction may be the appropriate option.
Smartphones and mobile devices: Mobile devices may contain flash storage as well as encryption and manufacturer-specific sanitization capabilities. Organizations should evaluate the sanitization mechanisms supported by the particular device and operating environment. A consumer factory reset should not automatically be assumed to satisfy an organization’s sanitization requirements.
Magnetic tape: Sanitization decisions for magnetic tape should account for the type of tape, available sanitization capabilities, data sensitivity, and whether the media will be reused. Organizations should follow applicable media-specific standards and manufacturer guidance when selecting an appropriate Clear, Purge, or Destroy technique.
The key is that NIST SP 800-88 Rev. 2 does not prescribe one sanitization technique for every storage device. Organizations need a documented decision process that considers the media type, available sanitization capabilities, confidentiality requirements, and what will happen to the device after sanitization.
When Should Organizations Sanitize Devices In-House vs. Use a Third-Party Vendor?
Organizations can perform media sanitization internally when they have the appropriate tools, trained personnel, documented procedures, and ability to verify and record the results. The decision should account for device volume, data sensitivity, regulatory or contractual requirements, available internal resources, and the type of media being sanitized.
In-house sanitization may make sense when an IT team regularly handles a manageable number of devices and has established procedures for selecting, performing, verifying, and documenting the appropriate sanitization method. Organizations should also have a process for handling devices that fail sanitization or cannot be processed using the intended method.
A third-party media sanitization or destruction vendor may be appropriate when organizations have large volumes of retired devices, highly sensitive data, limited internal resources, or documentation and chain-of-custody requirements that are difficult to manage internally. A vendor can also help when devices require specialized sanitization or physical destruction capabilities that the organization does not maintain in-house.
When evaluating a vendor, organizations should consider how devices are transported and tracked, which sanitization methods are used, how successful sanitization is verified, how exceptions are handled, and what documentation is provided after completion.
Regardless of whether sanitization is performed internally or by a third party, the organization remains responsible for establishing requirements appropriate to its data and maintaining records that demonstrate how retired media was handled.
How Should Remote and Distributed Companies Handle Media Sanitization?
Remote and distributed workforces create an additional challenge because company devices may be located with employees rather than under the physical control of IT. Before a laptop can be sanitized, the organization first needs a reliable process for recovering the device and maintaining visibility as it moves back into company control.
For remote employees, organizations can use a standardized retrieval process that includes appropriate packaging, prepaid shipping, clear return instructions, automated reminders, and shipment tracking. The device should remain associated with its asset record throughout the return so IT can confirm which equipment was expected and which device was actually received.
Once the device is recovered, IT can determine the appropriate sanitization method based on the storage media, sensitivity of the data, intended disposition, and organizational requirements. Devices being redeployed may require a sanitization method that preserves the hardware for reuse, while equipment leaving the organization may require a different level of sanitization or physical destruction.
Chain of custody is particularly important when devices are moving between remote employees, carriers, warehouses, and sanitization or ITAD providers. Organizations should document relevant transfers and maintain records showing what happened to each device after recovery.
For distributed companies managing equipment return at scale, combining device retrieval, tracking, sanitization, and documentation into a consistent process helps prevent retired hardware from becoming unaccounted for between employee offboarding and final disposition.
How Can Organizations Establish a Media Sanitization Program?
Organizations can establish a media sanitization program by creating documented policies and procedures for identifying data-bearing assets, selecting appropriate sanitization methods, maintaining secure control of media, validating results, and documenting each sanitization decision. NIST SP 800-88 Rev. 2 emphasizes managing sanitization as an organization-wide program rather than making isolated decisions for individual devices.
A media sanitization program should define who is responsible for each stage of the process and establish consistent requirements for devices that will be reused, redeployed, transferred, sold, recycled, or destroyed.
Asset Inventory and Classification
Organizations should maintain an accurate inventory of data-bearing assets and understand the types of information those assets may contain. Media and data should be classified according to the organization’s security requirements so IT and security teams can determine an appropriate sanitization method.
Policy Development
A media sanitization policy should define approved sanitization methods, roles and responsibilities, documentation requirements, validation procedures, and how exceptions or failed sanitization attempts will be handled.
Policies should also address different disposition scenarios, including internal reuse, employee offboarding, redeployment, resale, recycling, and physical destruction.
Secure Asset Retrieval and Chain of Custody
Secure chain of custody should continue from device recovery through sanitization and final disposition. Once recovered, devices should be stored and handled securely until the appropriate sanitization process is completed.
Verification, Validation, and Documentation
Organizations should verify that the selected sanitization technique completed successfully and validate that the result is appropriate for the organization’s security requirements. If the sanitization result does not meet those requirements, the media may need to undergo another sanitization attempt or a different method.
Organizations should also maintain records of the sanitization process, including the asset involved, sanitization method, results, disposition decision, and other information required by organizational policy. This documentation creates an auditable record of how data-bearing assets were handled throughout the sanitization process.
10 Essential Steps for Media Sanitization
Identify and inventory data-bearing assets across the organization.
Classify the sensitivity of the information stored on each asset.
Determine what will happen to the media after sanitization, such as internal reuse, redeployment, resale, recycling, or destruction.
Select the appropriate sanitization method, Clear, Purge, or Destroy, based on the data, media type, and disposition.
Maintain secure chain of custody when retrieving, transporting, and storing data-bearing devices.
Perform the selected sanitization technique using an applicable standard or organization-approved procedure.
Verify that the sanitization technique completed successfully.
Validate that the sanitization result meets the organization’s security requirements.
Document the sanitization method, results, asset information, and final disposition.
Update asset records and securely reuse, redeploy, sell, recycle, or dispose of the media according to organizational policy.
Common Media Sanitization Use Cases
Media sanitization is required in several common IT lifecycle scenarios, particularly when data-bearing equipment changes users, leaves an organization’s control, or reaches the end of its useful life. The appropriate sanitization method depends on the sensitivity of the data, the type of media, and what will happen to the equipment next.
Employee Offboarding
Problem: A departing remote employee has a company laptop containing corporate data, credentials, locally stored files, or other sensitive information.
Action: The organization retrieves the laptop through a documented return process, maintains chain of custody, and evaluates the device and data to determine the appropriate sanitization method before the laptop is redeployed, sold, recycled, or otherwise dispositioned.
Outcome: The company regains control of the data-bearing asset, sanitizes it according to organizational requirements, documents the process, and can safely determine the device’s next lifecycle stage.
Hardware Lifecycle Refresh
Problem: An organization is replacing a fleet of laptops or other devices but wants to preserve the value of equipment that is still usable.
Action: IT identifies devices suitable for reuse or resale and applies an appropriate Clear or Purge technique based on the media, data sensitivity, and disposition requirements. The sanitization results are then verified, validated, and documented.
Outcome: Properly sanitized equipment can be redeployed or sold when organizational requirements permit, allowing the business to protect its data without automatically destroying usable hardware.
Data Center Decommissioning
Problem: An organization is retiring physical servers and storage infrastructure during a data center closure, consolidation, or cloud migration.
Action: IT inventories the data-bearing media, classifies the information involved, and selects an appropriate Clear, Purge, or Destroy method for each asset based on its storage technology, confidentiality requirements, and intended disposition.
Outcome: Data-bearing media is sanitized or destroyed according to organizational requirements before the equipment leaves the organization’s control, with records maintained for the assets and sanitization decisions.
Regulatory and Audit Readiness
Problem: An organization needs evidence showing how sensitive information on retired or reassigned equipment was handled.
Action: The organization follows a documented media sanitization program and maintains records of the asset, sanitization method, verification and validation results, and final disposition.
Outcome: IT and security teams have an auditable record demonstrating that data-bearing assets were handled according to the organization’s established sanitization policies and procedures.
Frequently Asked Questions About Media Sanitization
What is a media sanitization program?
A media sanitization program is a documented set of policies, procedures, roles, and approved methods an organization uses to securely sanitize data-bearing media throughout its lifecycle. The program should define how media is identified and classified, how Clear, Purge, or Destroy methods are selected, how results are verified and validated, and how sanitization and final disposition are documented.
How do I securely dispose of old data storage devices?
To securely dispose of old data storage devices, first identify the type of media, the sensitivity of the data it contains, and what will happen to the device next. Organizations can then select an appropriate Clear, Purge, or Destroy method based on their security requirements and applicable sanitization standards. The process should be verified, validated, and documented before the media leaves the organization’s control.
What are the best practices for media sanitization?
Media sanitization best practices include maintaining an accurate inventory of data-bearing assets, classifying data based on sensitivity, selecting an appropriate sanitization method, maintaining secure chain of custody, using approved sanitization techniques, verifying and validating results, and documenting the sanitization and final disposition of each asset.
Can formatting a hard drive guarantee data sanitization?
No. Formatting a hard drive or deleting files does not by itself guarantee that the underlying data has been properly sanitized. Organizations should use an appropriate sanitization technique based on the storage media, confidentiality requirements, and intended disposition of the device.
What is NIST SP 800-88 Rev. 2?
NIST SP 800-88 Rev. 2 is the National Institute of Standards and Technology’s updated Guidelines for Media Sanitization, published in September 2025. It provides guidance for establishing an organization-wide media sanitization program and for selecting, implementing, verifying, validating, and documenting appropriate sanitization methods.
What is the difference between Clear, Purge, and Destroy?
Clear protects data against simple, non-invasive recovery techniques while generally allowing the media to remain usable. Purge provides a stronger level of protection intended to make data recovery infeasible using state-of-the-art laboratory techniques while potentially preserving the media for reuse. Destroy renders the media unusable and incapable of storing data again.
What is the difference between sanitization verification and validation?
Verification determines whether the selected sanitization technique completed successfully. Validation determines whether the resulting sanitization outcome is acceptable based on the organization’s security requirements. If validation fails, the organization may need to repeat the process or use a different sanitization method.
When should storage media be destroyed instead of sanitized for reuse?
Storage media may need to be destroyed when organizational security requirements call for physical destruction, when Clear or Purge cannot be reliably performed, when sanitization fails, or when damaged or obsolete media will not be reused. The appropriate decision depends on the sensitivity of the data, the media involved, and the organization’s sanitization and disposition requirements.
How should businesses sanitize laptops before resale or donation?
Businesses should sanitize laptops before resale or donation using a method appropriate for the storage media, sensitivity of the data, and intended disposition of the device. Laptop sanitization should be completed and documented before the device leaves the organization’s control. If the laptop will remain usable, the organization should select an appropriate Clear or Purge method rather than automatically destroying the media.
How should SSDs be sanitized?
SSD data destruction and sanitization require different considerations than traditional magnetic hard drives because SSDs use flash-based storage. Organizations should use sanitization techniques supported by the specific SSD and applicable standards rather than assume that conventional hard-drive overwrite methods will provide the same result. Depending on the device and security requirements, an appropriate Purge technique or physical destruction may be used.
What is cryptographic erase?
Cryptographic erase is a Purge technique that sanitizes encrypted data by sanitizing the encryption keys required to decrypt that data. When the necessary conditions are met, cryptographic erase can make the encrypted data inaccessible while allowing the storage media to remain usable. Organizations should verify that cryptographic erase is appropriate for the device and their sanitization requirements.
What records should businesses keep after media sanitization?
Businesses should maintain records identifying the media or device, the sanitization method and technique used, the date sanitization occurred, the results of verification and validation, and the final disposition of the asset. Depending on the process, documentation may also include chain-of-custody records and a Certificate of Data Destruction. Maintaining these records supports data sanitization compliance, internal security policies, and audit requirements.
What regulatory requirements apply to media sanitization?
Media sanitization requirements depend on the organization’s industry, jurisdiction, contractual obligations, and the type of information stored on the media. Organizations should identify the legal, regulatory, security, and contractual requirements that apply to their data and establish sanitization policies accordingly. NIST SP 800-88 Rev. 2 provides media sanitization guidance, but organizations should determine which specific requirements apply to them.
When should a business use a third-party media sanitization or destruction vendor?
A third-party vendor may be appropriate when an organization lacks the internal tools or expertise to perform and verify sanitization, has a large volume of devices, handles highly sensitive data, or requires specialized destruction, chain-of-custody controls, or documentation. When selecting a certified media destruction vendor, businesses should evaluate its sanitization methods, security controls, tracking procedures, verification process, and documentation.
Does media sanitization apply to cloud and virtual environments?
Media sanitization principles can apply when data is stored in cloud or virtual environments, but organizations may not have physical control over the underlying storage media. Responsibility for sanitizing physical media may therefore depend on the cloud service provider and the terms of the service agreement. Organizations should understand how their provider handles data deletion, storage reuse, media sanitization, and final disposition and incorporate those responsibilities into their data lifecycle and security policies.
What Are the Key Takeaways for Media Sanitization?
Media sanitization helps organizations protect sensitive information when data-bearing devices are reused, redeployed, sold, recycled, or retired.
NIST SP 800-88 Rev. 2 places greater emphasis on establishing an organization-wide media sanitization program with defined policies, responsibilities, and procedures.
Clear, Purge, and Destroy provide different levels of protection, and the appropriate method depends on the sensitivity of the data, the storage technology, and the intended disposition of the media.
Different storage media, including HDDs, SSDs, USB flash drives, mobile devices, and magnetic tape, may require different sanitization techniques based on the media’s capabilities and applicable standards.
Deleting files or formatting a drive is not the same as performing media sanitization using an appropriate sanitization technique.
Verification and validation help organizations determine whether a sanitization technique completed successfully and whether the resulting outcome meets their security requirements.
Maintaining asset records, secure chain of custody, and sanitization documentation helps organizations create an auditable record of how data-bearing assets were handled.
For remote workforces, recovering company devices is an important first step because data-bearing hardware must be brought back under organizational control before it can be properly sanitized and dispositioned.