CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 03 Of 25 · Modern And Device Aware

NIST SP 800-88 Rev. 1 — Purge

Advanced Media Sanitization For High-Assurance Data Erasure

United States3 PassesVerification Available
ITAD technician preparing drives for a NIST 800-88 Purge wipe

At A Glance

Published By
National Institute of Standards and Technology (NIST)
Reference
SP 800-88 Revision 1, December 2014
Region
United States
Passes
3
Verification
Available On Every Run
Relative Run Time
3× a single pass

What The Software Writes

  1. Pass 1 Random data
  2. Pass 2 Random data
  3. Pass 3 Random data
  4. Verify Read back of the final pass, available on every run.
  5. Certify Signed certificate with device, method, result and operator

NIST SP 800-88 Rev. 1 Purge was the higher-assurance sanitization category within the 2014 edition of NIST's Guidelines for Media Sanitization.

Unlike Clear, which was intended to protect against simple, non-invasive recovery through the normal user interface, Purge was intended to make recovery of Target Data infeasible using state-of-the-art laboratory techniques, while potentially allowing the media to remain usable depending on the technique selected.

NIST SP 800-88 Rev. 1 was published in December 2014 and was withdrawn on September 26, 2025, when NIST SP 800-88 Rev. 2 superseded it.

For organizations maintaining legacy policies, contracts, procedures or audit requirements based specifically on Rev. 1, Data Sanitization Pro (DSP) provides a dedicated NIST SP 800-88 Rev. 1 Purge method through the DSP Sanitization Engine.

Important: This page documents the historical Rev. 1 Purge methodology and DSP's implementation of that methodology. Rev. 1 is withdrawn and should not be represented as the current NIST guidance.

01

What Is NIST SP 800-88 Rev. 1 Purge?

NIST SP 800-88 Rev. 1 divided media sanitization into three categories:

  • Clear
  • Purge
  • Destroy

The central distinction was the level of protection against data recovery.

02

Clear

Applies logical techniques to user-addressable storage locations and is intended to protect against simple, non-invasive recovery techniques.

03

Purge

Applies physical or logical techniques intended to make Target Data recovery infeasible using state-of-the-art laboratory techniques.

04

Destroy

Makes Target Data recovery infeasible while also rendering the media unusable for future data storage.

Therefore:

Purge≠ordinary disk wiping

It represents a higher recovery-resistance objective than Clear while potentially preserving the storage device for reuse.

05

NIST Rev. 1 Purge — The Core Objective

The objective of Purge is not simply to make files disappear.

It is to address the underlying storage media in a manner intended to prevent recovery of the Target Data even when more advanced laboratory techniques are considered.

The appropriate method depends on factors including:

  • Information Confidentiality
  • Storage Technology
  • Device Architecture
  • Sanitization Capability
  • Intended Reuse Or Disposal
  • Organizational Risk Tolerance
  • Availability Of Appropriate Sanitization Technology

NIST Rev. 1 emphasized that sanitization decisions should be based on the confidentiality categorization of the information and the characteristics of the media.

06

Purge vs Clear

CharacteristicNIST Rev. 1 ClearNIST Rev. 1 Purge
Primary ObjectiveProtect against simple, non-invasive recoveryMake recovery infeasible using state-of-the-art laboratory techniques
TechniqueLogicalPhysical or logical
Media UsabilityGenerally preservedMay be preserved depending on technique
Assurance ObjectiveLowerHigher
Technology DependencyImportantCritical
Suitable For Sensitive DataDepends on riskUsed where stronger sanitization is required

The correct selection depends on the organization's information sensitivity, media technology and disposition requirements.

07

NIST SP 800-88 Rev. 1 Purge Methods

Rev. 1 did not define Purge as one universal multi-pass overwrite algorithm.

Instead, NIST provided technology-specific recommendations and recognized several categories of sanitization techniques.

Examples included:

  • Cryptographic Erase
  • Block Erase
  • ATA Sanitize
  • SCSI Sanitize
  • Dedicated device sanitization commands
  • Degaussing for applicable magnetic media
  • Other validated physical or logical techniques appropriate to the media

The Rev. 1 Appendix A tables provided minimum recommendations for specific media types, while also stating that other methods could satisfy the intent of Clear, Purge or Destroy when appropriately verified by the organization.

08

Cryptographic Erase

Cryptographic Erase (CE) was one of the important Purge techniques discussed in NIST SP 800-88 Rev. 1.

Where data is encrypted and the necessary conditions are satisfied, sanitizing the cryptographic keys can render the encrypted Target Data inaccessible.

However, cryptographic erase is not simply equivalent to deleting a key file.

An organization must consider:

  • Whether The Target Data Was Actually Encrypted
  • Encryption Architecture
  • Cryptographic Key Management
  • Whether All Relevant Keys Are Addressed
  • Device Implementation
  • External Versus Internally Managed Keys
  • Whether The Implementation Provides Sufficient Assurance

For this reason, CE should be selected based on the actual device and encryption architecture rather than treated as a universal method.

09

ATA Sanitize & Device-Level Sanitization

For supported ATA storage devices, device-level sanitization commands can provide an alternative to conventional host-based overwriting.

The important distinction is that the command is handled by the storage device's own firmware/controller rather than simply writing data through the operating system's normal filesystem interface.

This can be particularly relevant when the device has internal storage-management mechanisms that are not visible to the host.

DSP's device assessment can help identify available device information and capabilities before the sanitization operation is selected.

SCSI Sanitize

SCSI-based enterprise storage can provide device-level sanitization capabilities through the SCSI SANITIZE command family.

This is particularly relevant to environments containing:

  • SAS HDDs
  • SAS SSDs
  • Enterprise Storage
  • Servers
  • Data-Center Storage Systems

Where supported and appropriate, device-level sanitization can address storage through mechanisms implemented within the storage device.

The actual command capability depends on the specific device and its implementation.

10

Block Erase

Block Erase is another technology-specific technique discussed in the Rev. 1 guidance for applicable storage technologies.

Rather than performing conventional host-level overwriting of every logical block, a device-supported erase operation can instruct the storage technology to erase storage blocks through its native capabilities.

The applicability and assurance of such a technique depend on the device architecture and implementation.

11

Degaussing

Degaussing is a physical sanitization technique applicable to certain magnetic storage media.

A sufficiently strong magnetic field can disrupt the magnetic representation of stored information.

However, degaussing is not a universal storage sanitization technique.

It is not applicable to many modern non-magnetic technologies such as:

  • SSDs
  • NVMe SSDs
  • USB Flash Storage
  • SD Cards
  • microSD Cards
  • CFexpress
  • Other Solid-State Flash Media

Degaussing can also render magnetic storage unusable, meaning the operational outcome must be considered when the organization intends to reuse the media.

12

Why Storage Technology Matters

A critical principle behind NIST SP 800-88 Rev. 1 Purge is that different storage technologies cannot automatically be sanitized using the same technique.

HDD

Magnetic media can potentially use:

  • Device-Level Sanitization
  • Overwrite Where Applicable
  • Degaussing
  • Other Validated Physical Techniques

SSD

Flash storage introduces:

  • Flash Translation Layers
  • Wear Leveling
  • Spare Cells
  • Over-Provisioning
  • Garbage Collection
  • Controller-Managed Mapping

Consequently, a conventional overwrite may not provide the same assurance as a technology-specific sanitization mechanism.

13

NVMe

NVMe storage adds a controller and command architecture specifically designed for modern high-performance solid-state storage.

The appropriate sanitization technique should therefore consider the actual device capabilities rather than assuming an HDD-style overwrite is sufficient.

14

NIST Rev. 1 Purge For SSD & Flash Storage

NIST Rev. 1 specifically recognized the challenges associated with flash-based media.

A logical overwrite may not necessarily address:

  • Previously Used Physical Flash Cells
  • Spare Areas
  • Remapped Blocks
  • Over-Provisioned Regions
  • Controller-Managed Locations

This is one reason Purge is fundamentally different from simply executing a conventional disk wipe.

For flash storage organizations should evaluate device-supported sanitization techniques and the assurance available from the device implementation.

15

Purge Is Not A Universal "7-Pass" Or "35-Pass" Method

A common misconception is that NIST Purge means repeatedly overwriting a disk with a particular number of passes.

It does not.

NIST SP 800-88 Rev. 1 Purge is an assurance category, not a universal fixed pass-count algorithm.

A Purge operation could use an appropriate physical or logical technique depending on the storage technology.

This is also why methodologies such as:

  • Gutmann
  • Schneier
  • DoD 5220.22-M

should not automatically be described as equivalent to NIST Rev. 1 Purge.

They are separate sanitization methodologies or historical wiping profiles.

16

DSP NIST SP 800-88 Rev. 1 Purge

Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 1 Purge method through its DSP Sanitization Engine.

The software-controlled workflow is designed to distinguish the selected Purge methodology from generic disk wiping.

17

DSP Purge Workflow

  1. 01Identify Device
  2. 02Assess Storage Technology
  3. 03Select NIST SP 800-88 Rev. 1 Purge
  4. 04Select Applicable Purge Technique
  5. 05DSP Sanitization Engine
  6. 06Execute Sanitization
  7. 07Verify Result
  8. 08Validate Outcome
  9. 09Document Operation
  10. 10Audit-Ready Certificate
18

Technology-Aware Sanitization

DSP's sanitization workflow can work with multiple storage technologies supported by the platform, including:

  • SATA HDD
  • SATA SSD
  • SAS HDD
  • SAS SSD
  • NVMe
  • U.2
  • M.2
  • mSATA
  • Pata/ide
  • USB Storage
  • Pen Drives
  • SD Cards
  • microSD Cards
  • CompactFlash
  • CFexpress
  • RAID Storage
  • DAS
  • NAS
  • SAN
  • Server Storage

The selected sanitization approach should correspond to the actual storage technology and available sanitization capability.

19

Verification After Purge

Executing a sanitization command is not the end of the process.

A professional data erasure workflow should also determine whether the operation completed as intended.

DSP can record relevant verification information such as:

  • Sanitization Status
  • Device Response
  • Command/process Result
  • Completion Status
  • Errors
  • Exceptions
  • Verification Result
  • Process Timestamps
  • Device Identification

Where a device reports errors or cannot reliably complete the selected operation, the organization should be able to identify that condition rather than treating the device as successfully sanitized.

20

Verification vs Validation

These concepts should not be treated as identical.

Verification

Determines whether the sanitization operation produced the expected result.

Validation

Determines whether the sanitization result is acceptable for the organization's security requirement and intended disposition.

A device can therefore have a completed technical operation while still requiring organizational review when an error, exception or unusual condition is identified.

DSP reporting can preserve the evidence required for that decision.

21

Bad Sectors & Purge

Storage defects are especially important when performing sanitization.

Potential conditions include:

  • Logical Bad Sectors
  • Physical Media Errors
  • Uncorrectable Sectors
  • Read Failures
  • Remapped Sectors
  • Device Communication Errors

If a storage device cannot reliably address or process relevant storage areas, a conventional software sanitization operation may not provide the intended assurance.

DSP can record relevant storage-health and error information as part of the sanitization workflow.

For high-risk cases, the organization may determine that another sanitization technique or physical destruction is appropriate.

22

Device Health Before Sanitization

DSP can collect relevant storage-health information before and during the sanitization workflow.

Depending on device support, this may include:

  • SMART Health
  • Temperature
  • Power-On Hours
  • Firmware
  • Model
  • Serial Number
  • Capacity
  • Error Information
  • Performance-Related Information
  • Sector Condition

This creates additional operational context around the sanitization result.

23

Purge For IT Asset Disposition

Purge is particularly relevant when an organization wants to sanitize sensitive storage while potentially preserving the physical device for continued use.

Typical applications include:

  • Enterprise Hardware Reuse
  • Data-Center Decommissioning
  • ITAD
  • Refurbishment
  • Secure Resale
  • Hardware Transfer
  • Government Asset Disposition
  • Corporate Equipment Retirement
  • Storage-Device Reuse

The organization can select a sanitization method based on the confidentiality of the information and the intended disposition of the asset.

24

NIST Rev. 1 Purge For Enterprise IT

Enterprise environments may need to process large numbers of storage devices while maintaining consistent sanitization records.

DSP can support controlled workflows for:

  • Multiple HDDs
  • Multiple SSDs
  • NVMe Devices
  • SAS Storage
  • USB Media
  • Removable Media
  • Server Storage

Operational information can be recorded for each sanitization job.

This provides a repeatable process for enterprise IT and ITAD teams.

25

Offline Purge Operations

DSP can support offline sanitization workflows for environments where storage devices must be processed without relying on public internet connectivity.

This can be useful for:

  • Government Environments
  • Restricted Facilities
  • High-Security Operations
  • Air-Gapped Systems
  • Enterprise Data Centers
  • Controlled ITAD Facilities

The sanitization operation can be performed within the organization's controlled environment, with reports generated as part of the local workflow.

26

Audit-Ready Sanitization Certificate

NIST SP 800-88 Rev. 1 included a sample Certificate of Sanitization in Appendix G.

DSP provides its own audit-ready sanitization certificate documenting the operation performed by the software.

A certificate can include:

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Media type
  • Interface

Sanitization Information

  • Selected methodology
  • NIST SP 800-88 Rev. 1 Purge
  • Applicable technique
  • Start time
  • Completion time
  • Sanitization status

Verification

  • Verification status
  • Verification results
  • Errors
  • Exceptions
  • Relevant process information

Audit Metadata

  • Operator
  • System/workstation
  • Organization
  • Customer or asset owner
  • Case/ticket reference
  • Date/time
  • Report identification

Output

  • PDF
  • HTML
  • Print-ready documentation
27

What Does The DSP Certificate Mean?

The certificate documents the actual sanitization operation performed by Data Sanitization Pro.

It does not mean:

  • NIST Certified DSP;
  • NIST Approved DSP;
  • NIST Issued The Certificate;
  • The Storage Device Received An External NIST Certification.

The certificate is an audit record generated by DSP describing the selected method, execution, device information and verification results.

28

NIST Rev. 1 Purge vs DoD 5220.22-M

These methodologies should not be treated as interchangeable.

NIST SP 800-88 Rev. 1 PurgeDoD 5220.22-M
NIST Media Sanitization CategoryHistorical U.S. DoD policy/manual
Purge Is An Assurance ObjectiveCommonly associated with historical overwrite procedures
Physical Or Logical TechniquesHistorically defined sanitization procedures
Technology-SpecificPrimarily associated with legacy overwrite workflows
Can Include Device-Specific TechniquesOften implemented as multi-pass overwriting
Designed Around Recovery ResistanceCommonly encountered in legacy data-wiping software

The number of overwrite passes alone does not determine whether an operation satisfies the Rev. 1 Purge objective.

29

NIST Rev. 1 Purge vs Gutmann

The Gutmann Method is a historical 35-pass wiping methodology.

NIST Rev. 1 Purge is a media sanitization category with an objective of making recovery infeasible using state-of-the-art laboratory techniques.

Therefore:

Gutmann 35-pass≠NIST Rev. 1 Purge

A specific wiping methodology may be appropriate for a particular organizational requirement, but it should not automatically be relabeled as NIST Purge.

30

NIST Rev. 1 Purge vs NIST Rev. 1 Clear

Clear

Designed to protect against simple, non-invasive recovery through the normal user interface.

Purge

Designed to make recovery infeasible using state-of-the-art laboratory techniques.

Destroy

Designed to make recovery infeasible while making the media unusable.

The distinction is therefore based on the intended recovery-resistance level, not simply the number of overwrite passes.

31

NIST Rev. 1 Purge vs Rev. 2

NIST SP 800-88 Rev. 2 was published in September 2025 and superseded Rev. 1. NIST states that Rev. 2 shifts the focus toward establishing and maintaining an enterprise or agency media sanitization program and, except for Cryptographic Erase, replaces detailed sanitization technique/tool descriptions with recommendations to follow IEEE 2883, NSA specifications or an organizationally approved standard.

AreaRev. 1 PurgeRev. 2 Purge
StatusWithdrawnCurrent
ObjectiveLaboratory-recovery resistanceLaboratory-recovery resistance
Guidance StyleDetailed technique recommendationsProgram/risk-oriented
Technology TechniquesDetailed in Rev. 1Current technology-specific standards emphasized
IEEE 2883Supporting referenceGreater role in current technique selection
Cryptographic EraseIncludedExpanded guidance
DocumentationSanitization documentation and certificateProgram-level controls and documentation

For new sanitization programs organizations should evaluate the current Rev. 2 guidance and applicable current technology-specific standards.

32

Why Maintain A Rev. 1 Purge Method?

Although Rev. 1 is withdrawn organizations may still have:

  • Legacy SOPs
  • Existing ITAD Contracts
  • Customer Specifications
  • Procurement Requirements
  • Historical Audit Procedures
  • Archived Compliance Documentation
  • Existing Software Profiles
  • Internal Sanitization Procedures

A dedicated Rev. 1 Purge implementation can therefore be useful when an organization specifically needs to execute and document the historical methodology.

For new policies, the organization should assess the current NIST SP 800-88 Rev. 2 framework and applicable technology-specific standards.

33

DSP Sanitization Engine

The DSP Sanitization Engine separates individual sanitization methodologies rather than treating every operation as a generic disk wipe.

For NIST SP 800-88 Rev. 1 Purge:

  1. 01Select Method
  2. 02Identify Device
  3. 03Assess Storage
  4. 04Select Applicable Purge Technique
  5. 05Execute
  6. 06Verify
  7. 07Validate
  8. 08Document
  9. 09Certify

This provides a method-specific workflow for organizations maintaining Rev. 1 sanitization requirements.

34

25 Sanitization Methods In One Platform

35

Key Takeaways

NIST SP 800-88 Rev. 1 Purge was designed for a substantially higher recovery-resistance objective than Clear.

Its key characteristics include:

  • Physical Or Logical Sanitization
  • Protection Against State-Of-The-Art Laboratory Recovery
  • Technology-Specific Sanitization Approaches
  • Cryptographic Erase
  • Device-Level Sanitization Commands
  • Block Erase
  • Degaussing For Applicable Magnetic Media
  • Verification And Documentation
  • Potential Media Reuse Depending On The Selected Technique
  • Special Consideration For SSD And Flash Storage
  • Applicability To Enterprise And ITAD Workflows

NIST SP 800-88 Rev. 1 is now withdrawn, with Rev. 2 published in September 2025 as its successor.

FAQ

NIST Purge Questions

What Is NIST SP 800-88 Rev. 1 Purge?

It is the Purge category defined by the 2014 NIST SP 800-88 Rev. 1 for sanitizing media using physical or logical techniques intended to make Target Data recovery infeasible using state-of-the-art laboratory techniques.

Is NIST Rev. 1 Purge The Same As A 3-pass Or 7-pass Wipe?

No. Purge is an assurance category, not a universal fixed pass-count algorithm.

Can Purge Preserve A Hard Drive?

Yes. Depending on the technique used, Purge can potentially allow media to remain usable.

Is Degaussing A Purge Method?

For applicable magnetic media, degaussing can be used as a physical sanitization technique. It is not applicable to SSDs and other non-magnetic flash storage.

Is Cryptographic Erase A Purge Technique?

Yes. Cryptographic Erase was included among the Rev. 1 sanitization techniques for applicable encrypted media.

Is NIST SP 800-88 Rev. 1 Still Current?

No. NIST withdrew Rev. 1 on **September 26, 2025**. NIST SP 800-88 Rev. 2 is the current successor.

Does DSP Provide NIST Certification?

DSP generates an **audit-ready certificate documenting the sanitization operation performed by DSP**. This is not certification issued by NIST.

Should New Sanitization Programs Still Use Rev. 1 Purge?

Organizations creating new programs should evaluate the current NIST SP 800-88 Rev. 2 guidance and applicable current technology-specific standards. Rev. 1 remains relevant primarily where a legacy requirement specifically calls for it.

Run NIST Purge With A Certificate For Every Drive

Data Sanitization Pro runs all 25 standards offline and verifies the result.