Verification
Determines whether the sanitization operation produced the expected result.
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
Advanced Media Sanitization For High-Assurance Data Erasure

NIST SP 800-88 Rev. 1 Purge was the higher-assurance sanitization category within the 2014 edition of NIST's Guidelines for Media Sanitization.
Unlike Clear, which was intended to protect against simple, non-invasive recovery through the normal user interface, Purge was intended to make recovery of Target Data infeasible using state-of-the-art laboratory techniques, while potentially allowing the media to remain usable depending on the technique selected.
NIST SP 800-88 Rev. 1 was published in December 2014 and was withdrawn on September 26, 2025, when NIST SP 800-88 Rev. 2 superseded it.
For organizations maintaining legacy policies, contracts, procedures or audit requirements based specifically on Rev. 1, Data Sanitization Pro (DSP) provides a dedicated NIST SP 800-88 Rev. 1 Purge method through the DSP Sanitization Engine.
Important: This page documents the historical Rev. 1 Purge methodology and DSP's implementation of that methodology. Rev. 1 is withdrawn and should not be represented as the current NIST guidance.
NIST SP 800-88 Rev. 1 divided media sanitization into three categories:
The central distinction was the level of protection against data recovery.
Applies logical techniques to user-addressable storage locations and is intended to protect against simple, non-invasive recovery techniques.
Applies physical or logical techniques intended to make Target Data recovery infeasible using state-of-the-art laboratory techniques.
Makes Target Data recovery infeasible while also rendering the media unusable for future data storage.
Therefore:
Purge≠ordinary disk wiping
It represents a higher recovery-resistance objective than Clear while potentially preserving the storage device for reuse.
The objective of Purge is not simply to make files disappear.
It is to address the underlying storage media in a manner intended to prevent recovery of the Target Data even when more advanced laboratory techniques are considered.
The appropriate method depends on factors including:
NIST Rev. 1 emphasized that sanitization decisions should be based on the confidentiality categorization of the information and the characteristics of the media.
| Characteristic | NIST Rev. 1 Clear | NIST Rev. 1 Purge |
|---|---|---|
| Primary Objective | Protect against simple, non-invasive recovery | Make recovery infeasible using state-of-the-art laboratory techniques |
| Technique | Logical | Physical or logical |
| Media Usability | Generally preserved | May be preserved depending on technique |
| Assurance Objective | Lower | Higher |
| Technology Dependency | Important | Critical |
| Suitable For Sensitive Data | Depends on risk | Used where stronger sanitization is required |
The correct selection depends on the organization's information sensitivity, media technology and disposition requirements.
Rev. 1 did not define Purge as one universal multi-pass overwrite algorithm.
Instead, NIST provided technology-specific recommendations and recognized several categories of sanitization techniques.
Examples included:
The Rev. 1 Appendix A tables provided minimum recommendations for specific media types, while also stating that other methods could satisfy the intent of Clear, Purge or Destroy when appropriately verified by the organization.
Cryptographic Erase (CE) was one of the important Purge techniques discussed in NIST SP 800-88 Rev. 1.
Where data is encrypted and the necessary conditions are satisfied, sanitizing the cryptographic keys can render the encrypted Target Data inaccessible.
However, cryptographic erase is not simply equivalent to deleting a key file.
An organization must consider:
For this reason, CE should be selected based on the actual device and encryption architecture rather than treated as a universal method.
For supported ATA storage devices, device-level sanitization commands can provide an alternative to conventional host-based overwriting.
The important distinction is that the command is handled by the storage device's own firmware/controller rather than simply writing data through the operating system's normal filesystem interface.
This can be particularly relevant when the device has internal storage-management mechanisms that are not visible to the host.
DSP's device assessment can help identify available device information and capabilities before the sanitization operation is selected.
SCSI-based enterprise storage can provide device-level sanitization capabilities through the SCSI SANITIZE command family.
This is particularly relevant to environments containing:
Where supported and appropriate, device-level sanitization can address storage through mechanisms implemented within the storage device.
The actual command capability depends on the specific device and its implementation.
Block Erase is another technology-specific technique discussed in the Rev. 1 guidance for applicable storage technologies.
Rather than performing conventional host-level overwriting of every logical block, a device-supported erase operation can instruct the storage technology to erase storage blocks through its native capabilities.
The applicability and assurance of such a technique depend on the device architecture and implementation.
Degaussing is a physical sanitization technique applicable to certain magnetic storage media.
A sufficiently strong magnetic field can disrupt the magnetic representation of stored information.
However, degaussing is not a universal storage sanitization technique.
It is not applicable to many modern non-magnetic technologies such as:
Degaussing can also render magnetic storage unusable, meaning the operational outcome must be considered when the organization intends to reuse the media.
A critical principle behind NIST SP 800-88 Rev. 1 Purge is that different storage technologies cannot automatically be sanitized using the same technique.
Magnetic media can potentially use:
Flash storage introduces:
Consequently, a conventional overwrite may not provide the same assurance as a technology-specific sanitization mechanism.
NVMe storage adds a controller and command architecture specifically designed for modern high-performance solid-state storage.
The appropriate sanitization technique should therefore consider the actual device capabilities rather than assuming an HDD-style overwrite is sufficient.
NIST Rev. 1 specifically recognized the challenges associated with flash-based media.
A logical overwrite may not necessarily address:
This is one reason Purge is fundamentally different from simply executing a conventional disk wipe.
For flash storage organizations should evaluate device-supported sanitization techniques and the assurance available from the device implementation.
A common misconception is that NIST Purge means repeatedly overwriting a disk with a particular number of passes.
It does not.
NIST SP 800-88 Rev. 1 Purge is an assurance category, not a universal fixed pass-count algorithm.
A Purge operation could use an appropriate physical or logical technique depending on the storage technology.
This is also why methodologies such as:
should not automatically be described as equivalent to NIST Rev. 1 Purge.
They are separate sanitization methodologies or historical wiping profiles.
Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 1 Purge method through its DSP Sanitization Engine.
The software-controlled workflow is designed to distinguish the selected Purge methodology from generic disk wiping.
DSP's sanitization workflow can work with multiple storage technologies supported by the platform, including:
The selected sanitization approach should correspond to the actual storage technology and available sanitization capability.
Executing a sanitization command is not the end of the process.
A professional data erasure workflow should also determine whether the operation completed as intended.
DSP can record relevant verification information such as:
Where a device reports errors or cannot reliably complete the selected operation, the organization should be able to identify that condition rather than treating the device as successfully sanitized.
These concepts should not be treated as identical.
Determines whether the sanitization operation produced the expected result.
Determines whether the sanitization result is acceptable for the organization's security requirement and intended disposition.
A device can therefore have a completed technical operation while still requiring organizational review when an error, exception or unusual condition is identified.
DSP reporting can preserve the evidence required for that decision.
Storage defects are especially important when performing sanitization.
Potential conditions include:
If a storage device cannot reliably address or process relevant storage areas, a conventional software sanitization operation may not provide the intended assurance.
DSP can record relevant storage-health and error information as part of the sanitization workflow.
For high-risk cases, the organization may determine that another sanitization technique or physical destruction is appropriate.
DSP can collect relevant storage-health information before and during the sanitization workflow.
Depending on device support, this may include:
This creates additional operational context around the sanitization result.
Purge is particularly relevant when an organization wants to sanitize sensitive storage while potentially preserving the physical device for continued use.
Typical applications include:
The organization can select a sanitization method based on the confidentiality of the information and the intended disposition of the asset.
Enterprise environments may need to process large numbers of storage devices while maintaining consistent sanitization records.
DSP can support controlled workflows for:
Operational information can be recorded for each sanitization job.
This provides a repeatable process for enterprise IT and ITAD teams.
DSP can support offline sanitization workflows for environments where storage devices must be processed without relying on public internet connectivity.
This can be useful for:
The sanitization operation can be performed within the organization's controlled environment, with reports generated as part of the local workflow.
NIST SP 800-88 Rev. 1 included a sample Certificate of Sanitization in Appendix G.
DSP provides its own audit-ready sanitization certificate documenting the operation performed by the software.
A certificate can include:
The certificate documents the actual sanitization operation performed by Data Sanitization Pro.
It does not mean:
The certificate is an audit record generated by DSP describing the selected method, execution, device information and verification results.
These methodologies should not be treated as interchangeable.
| NIST SP 800-88 Rev. 1 Purge | DoD 5220.22-M |
|---|---|
| NIST Media Sanitization Category | Historical U.S. DoD policy/manual |
| Purge Is An Assurance Objective | Commonly associated with historical overwrite procedures |
| Physical Or Logical Techniques | Historically defined sanitization procedures |
| Technology-Specific | Primarily associated with legacy overwrite workflows |
| Can Include Device-Specific Techniques | Often implemented as multi-pass overwriting |
| Designed Around Recovery Resistance | Commonly encountered in legacy data-wiping software |
The number of overwrite passes alone does not determine whether an operation satisfies the Rev. 1 Purge objective.
The Gutmann Method is a historical 35-pass wiping methodology.
NIST Rev. 1 Purge is a media sanitization category with an objective of making recovery infeasible using state-of-the-art laboratory techniques.
Therefore:
Gutmann 35-pass≠NIST Rev. 1 Purge
A specific wiping methodology may be appropriate for a particular organizational requirement, but it should not automatically be relabeled as NIST Purge.
Designed to protect against simple, non-invasive recovery through the normal user interface.
Designed to make recovery infeasible using state-of-the-art laboratory techniques.
Designed to make recovery infeasible while making the media unusable.
The distinction is therefore based on the intended recovery-resistance level, not simply the number of overwrite passes.
NIST SP 800-88 Rev. 2 was published in September 2025 and superseded Rev. 1. NIST states that Rev. 2 shifts the focus toward establishing and maintaining an enterprise or agency media sanitization program and, except for Cryptographic Erase, replaces detailed sanitization technique/tool descriptions with recommendations to follow IEEE 2883, NSA specifications or an organizationally approved standard.
| Area | Rev. 1 Purge | Rev. 2 Purge |
|---|---|---|
| Status | Withdrawn | Current |
| Objective | Laboratory-recovery resistance | Laboratory-recovery resistance |
| Guidance Style | Detailed technique recommendations | Program/risk-oriented |
| Technology Techniques | Detailed in Rev. 1 | Current technology-specific standards emphasized |
| IEEE 2883 | Supporting reference | Greater role in current technique selection |
| Cryptographic Erase | Included | Expanded guidance |
| Documentation | Sanitization documentation and certificate | Program-level controls and documentation |
For new sanitization programs organizations should evaluate the current Rev. 2 guidance and applicable current technology-specific standards.
Although Rev. 1 is withdrawn organizations may still have:
A dedicated Rev. 1 Purge implementation can therefore be useful when an organization specifically needs to execute and document the historical methodology.
For new policies, the organization should assess the current NIST SP 800-88 Rev. 2 framework and applicable technology-specific standards.
The DSP Sanitization Engine separates individual sanitization methodologies rather than treating every operation as a generic disk wipe.
For NIST SP 800-88 Rev. 1 Purge:
This provides a method-specific workflow for organizations maintaining Rev. 1 sanitization requirements.
DSP provides dedicated implementations for supported sanitization methodologies within one data erasure platform.
Each method can have its own:
The certificate identifies the method actually executed rather than applying a generic "secure wipe" label.
NIST SP 800-88 Rev. 1 Purge was designed for a substantially higher recovery-resistance objective than Clear.
Its key characteristics include:
NIST SP 800-88 Rev. 1 is now withdrawn, with Rev. 2 published in September 2025 as its successor.
It is the Purge category defined by the 2014 NIST SP 800-88 Rev. 1 for sanitizing media using physical or logical techniques intended to make Target Data recovery infeasible using state-of-the-art laboratory techniques.
No. Purge is an assurance category, not a universal fixed pass-count algorithm.
Yes. Depending on the technique used, Purge can potentially allow media to remain usable.
For applicable magnetic media, degaussing can be used as a physical sanitization technique. It is not applicable to SSDs and other non-magnetic flash storage.
Yes. Cryptographic Erase was included among the Rev. 1 sanitization techniques for applicable encrypted media.
No. NIST withdrew Rev. 1 on **September 26, 2025**. NIST SP 800-88 Rev. 2 is the current successor.
DSP generates an **audit-ready certificate documenting the sanitization operation performed by DSP**. This is not certification issued by NIST.
Organizations creating new programs should evaluate the current NIST SP 800-88 Rev. 2 guidance and applicable current technology-specific standards. Rev. 1 remains relevant primarily where a legacy requirement specifically calls for it.
Data Sanitization Pro runs all 25 standards offline and verifies the result.