Pass 1 — Character / Pattern
The applicable addressable storage locations are overwritten with the specified character or pattern.
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
DoD 5220.22-M Data Sanitization Method

DoD 5220.22-M is a historically recognized U.S. Department of Defense methodology associated with secure handling and sanitization of information on storage media.
The term remains widely used in the data erasure and IT asset disposition (ITAD) industry, particularly for DoD 5220.22-M wipe, DoD 3-pass wipe, DoD hard drive erasure and DoD data wiping software.
Data Sanitization Pro provides a dedicated DoD 5220.22-M Sanitization Method through the DSP Sanitization Engine, allowing organizations to execute the selected method, monitor processing, verify the result and generate an audit-ready certificate.
Current-status note: DoD 5220.22-M is a legacy/cancelled NISPOM policy. 32 CFR Part 117 replaced the NISPOM previously issued as DoD 5220.22-M. DCSA records the cancellation of DoD 5220.22-M on December 10, 2021.
DoD 5220.22-M was the former National Industrial Security Program Operating Manual (NISPOM) issued as DoD policy.
In the data sanitization industry, the name became strongly associated with a historical multi-pass overwrite approach for writable magnetic media.
Historical NIST documentation describes the DoD 5220.22-M approach as:
This is commonly referred to as the DoD 3-pass wipe.
DSP provides a dedicated implementation of the DoD 5220.22-M methodology through the DSP Sanitization Engine.
DSP records the actual sanitization operation performed on the selected device.
The applicable addressable storage locations are overwritten with the specified character or pattern.
The storage locations are overwritten with the complementary character or pattern.
The storage locations are overwritten with a random character or pattern.
The completed operation is checked according to the implementation to identify completion, errors or exceptions.
This historical sequence is documented by NIST in its earlier media-sanitization material.
Commercial data-erasure products have historically used terms such as:
These terms should not automatically be treated as one official fixed DoD specification.
The DoD 3-pass historical approach is documented in NIST material, while extended commercial profiles can differ in their pass count and pattern configuration.
For this reason, a professional sanitization certificate should identify the actual method and configuration executed by the software.
The historical overwrite methodology is primarily associated with magnetic hard disk drives.
DSP supports supported storage technologies including:
DSP can record:
Modern SSD and NVMe storage uses architectures such as:
Therefore, a historical multi-pass overwrite should not automatically be considered equivalent to a modern purge technique for SSD or NVMe media.
Current NIST guidance explicitly notes that multi-pass overwrite is not necessary for Clear and discusses why traditional overwrite practices can be unsuitable for certain modern flash media.
For modern storage, the sanitization method should be selected according to the device architecture and required level of assurance.
| DoD 5220.22-M | Modern Sanitization Frameworks | |
|---|---|---|
| Status | Legacy / cancelled | Current |
| Historical Association | Multi-pass overwrite | Technology- and risk-based methods |
| Magnetic HDD | Historically relevant | Technology-specific method selection |
| SSD/NVMe | Limited historical applicability | Media-specific sanitization |
| Current NISPOM | No | 32 CFR Part 117 |
| Current NIST Guidance | No | NIST SP 800-88 Rev. 2 |
The current NISPOM framework is 32 CFR Part 117, while current NIST media-sanitization guidance is provided by NIST SP 800-88 Rev. 2.
DSP can record relevant sanitization and media information, including:
This provides additional evidence about the actual device condition and sanitization process.
DSP generates an audit-ready sanitization certificate for its DoD 5220.22-M implementation.
The certificate can document:
The certificate documents the sanitization operation actually performed by DSP.
It is not certification issued by the U.S. Department of Defense.
DoD 5220.22-M may still appear in legacy customer specifications, ITAD procedures and procurement requirements.
DSP provides a controlled workflow:
Typical applications include:
DSP also supports offline sanitization workflows for controlled environments.
These should be maintained as separate DSP methods.
Historical DoD multi-pass sanitization methodology.
An extended commercial/industry implementation commonly referred to as Enhanced Character Erase.
The actual pass configuration should always be documented rather than assuming that every commercial ECE profile represents an official DoD specification.
The term continues to appear in:
DSP supports the historical method while also providing modern sanitization methodologies for current storage technologies.
DoD 5220.22-M is one of the dedicated sanitization methods implemented in the DSP Sanitization Engine.
Each supported method has its own implementation, allowing DSP to execute the selected methodology and generate corresponding audit-ready documentation.
This allows organizations to choose a method according to:
DoD 5220.22-M should not be described as a current U.S. Department of Defense data-sanitization standard.
DCSA states that 32 CFR Part 117 replaced the NISPOM previously issued as DoD policy under DoD 5220.22-M and DCSA records DoD 5220.22-M as cancelled on December 10, 2021.
Therefore:
DoD 5220.22-M=Legacy / Historical Methodology
32 CFR Part 117=Current NISPOM Framework
NIST SP 800-88 Rev. 2=Current NIST Media Sanitization Guidance
It was the former DoD NISPOM policy and is now a legacy/cancelled document. The name is also widely used in the data-wiping industry for its historical overwrite methodology.
The commonly referenced historical process uses a character/pattern, its complement, a random character/pattern and verification.
No. It was replaced by the 32 CFR Part 117 NISPOM Rule and cancelled in December 2021.
Yes. DSP provides a dedicated DoD 5220.22-M Sanitization Method through the DSP Sanitization Engine.
Yes. DSP generates an audit-ready certificate documenting the operation performed by its DoD 5220.22-M method.
No. It documents the sanitization operation performed by DSP and is not certification issued by the U.S. Department of Defense.
No universal assumption should be made. Modern SSD/NVMe architectures require appropriate technology-specific sanitization techniques. Current NIST guidance specifically addresses the limitations of traditional overwrite approaches.
Historical DoD Methodology • Dedicated DSP Sanitization Method • Verification • Audit-Ready Certification