NIST SP 800-88 Rev. 1 — Clear
Secure Data Erasure & Media Sanitization

At A Glance
- Published By
- National Institute of Standards and Technology (NIST)
- Reference
- SP 800-88 Revision 1, December 2014
- Region
- United States
- Passes
- 1
- Verification
- Available On Every Run
- Relative Run Time
- 1× a single pass
What The Software Writes
- Pass 1 Fixed pattern 0x00
- Verify Read back of the final pass, available on every run.
- Certify Signed certificate with device, method, result and operator
NIST SP 800-88 Rev. 1 Clear was a widely referenced approach for logical media sanitization, designed to remove target data while allowing storage media to remain usable. Rev. 1 was published by NIST in December 2014 and was withdrawn on September 26, 2025, when NIST SP 800-88 Rev. 2 superseded it.
For organizations that still maintain legacy policies, historical procedures, contracts, audit requirements or software profiles based on NIST SP 800-88 Rev. 1, DSP provides a dedicated NIST SP 800-88 Rev. 1 Clear sanitization method through the DSP Sanitization Engine.
Important: NIST SP 800-88 Rev. 1 is now a withdrawn publication. This page documents its historical Clear methodology and DSP's implementation of that methodology; it does not represent Rev. 1 as the current NIST guidance.
What Is NIST SP 800-88 Rev. 1 Clear?
Under Rev. 1, Clear was one of three sanitization categories:
- Clear
- Purge
- Destroy
Clear was intended to sanitize user-accessible data while preserving the usability of the storage media.
For applicable storage technologies, Rev. 1 specified overwriting using an organizationally approved and tested overwriting technology, methodortool. For magnetic disks such as ATA HDDs, the minimum Clear pattern was generally at least one write pass using a fixed data value, such as all zeros. Multiple passes or more complex patterns could also be used. Verification of the overwritten data was required.
This made Rev. 1 Clear fundamentally different from simply deleting files or formatting a drive.
NIST SP 800-88 Rev. 1 Clear Method
Logical Data Sanitization
Clear was primarily concerned with making target data inaccessible through normal user interfaces while keeping the storage device usable.
For supported magnetic storage, the Rev. 1 approach centered on overwriting addressable storage with an approved sanitization pattern.
A typical workflow was:
- 01Identify
- 02Select Clear
- 03Overwrite
- 04Verify
- 05Document
The actual technique depended on the storage technology.
Clear Is Not The Same As File Deletion
Deleting a file normally removes or changes filesystem references to the file. The underlying sectors may still contain recoverable information.
Similarly, quick formatting generally changes filesystem structures rather than sanitizing every location containing previous data.
A proper sanitization operation addresses the target data according to the selected sanitization methodology.
File deletion≠Formatting≠Data Sanitization
NIST SP 800-88 Rev. 1 treated sanitization as a security process intended to make recovery of target data infeasible for the applicable level of effort.
Rev. 1 Clear For Hard Disk Drives
For ATA hard disk drives, including PATA, SATA and eSATA devices, Rev. 1 specified overwriting with an organizationally approved and validated technology, method or tool.
The Clear pattern was required to consist of at least one write pass using a fixed value such as zeros. Additional passes or more complex patterns could optionally be used.
DSP HDD Clear Workflow
1. Identify HDD Model, serial number, capacity and interface are identified.
2. Assess Device DSP can inspect available device information and storage health indicators.
3. Select NIST SP 800-88 Rev. 1 Clear
Monitor Sanitization
Verify Result
Generate Audit-Ready Certificate
This creates a controlled and documented workflow for organizations maintaining a Rev. 1-based sanitization policy.
NIST Rev. 1 Clear And SSDs
Clear under Rev. 1 requires greater care when applied to flash-based storage.
NIST specifically warned that overwriting flash media can:
- reduce the effective lifetime of the media;
- fail to sanitize data residing in unmapped physical locations;
- leave previous data in areas not directly accessible through the normal logical interface.
This is an important distinction between traditional magnetic HDDs and modern SSD/NVMe storage.
Traditional overwrite can address the magnetic storage surface through the drive's logical addressing system.
SSD / Flash
Flash storage uses technologies such as:
- Flash Translation Layers
- Wear Leveling
- Spare Cells
- Over-Provisioning
- Garbage Collection
- Controller-Managed Physical Mapping
Consequently, a conventional overwrite should not automatically be treated as equivalent to a complete physical sanitization of every underlying flash cell.
For higher assurance requirements, the appropriate Purge technique or another technology-specific sanitization approach should be evaluated.
NIST SP 800-88 Rev. 1 Clear For USB & Memory Cards
Rev. 1 provided technology-specific recommendations.
For USB removable media, the Clear procedure called for at least two passes: a pattern followed by its complement, with additional passes permitted.
For memory cards, including SD, SDHC, MMC, CompactFlash and similar flash media, Rev. 1 likewise specified a minimum two-pass Clear pattern consisting of an initial pattern followed by its complement.
These historical requirements are important when maintaining compatibility with legacy sanitization procedures.
Clear vs Purge vs Destroy
| Method | Rev. 1 Objective | Media Reuse |
|---|---|---|
| Clear | Protect against recovery through the applicable logical/user interface | Generally intended to remain usable |
| Purge | Make recovery infeasible using state-of-the-art laboratory techniques | May remain usable depending on technique |
| Destroy | Make data recovery infeasible while rendering the media unusable | No |
NIST Rev. 1 explicitly treated Clear, Purge and Destroy as different sanitization categories, with the appropriate choice depending on information sensitivity, media characteristics, risk and intended disposition.
NIST SP 800-88 Rev. 1 Clear In DSP
Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 1 Clear Method within its DSP Sanitization Engine.
DSP Execution Workflow
IDENTIFY DEVICE ↓ ASSESS STORAGE TECHNOLOGY ↓ SELECT NIST SP 800-88 REV. 1 CLEAR ↓ DSP SANITIZATION ENGINE ↓ EXECUTE CLEAR METHOD ↓ MONITOR PROCESS ↓ VERIFY RESULT ↓ DOCUMENT OPERATION ↓ AUDIT-READY CERTIFICATE
The method is designed for organizations that specifically require a Rev. 1 Clear workflow for historical, contractual, operational or internal policy reasons.
Sanitization Verification
Verification is an important part of the Rev. 1 process.
NIST Rev. 1 states that the goal of sanitization verification is to determine whether target data was effectively sanitized. The publication also discusses verification of the sanitization equipment, personnel competency and sanitization results.
DSP can document the sanitization operation together with relevant verification information.
Depending on the device and selected method, the workflow can record:
- Device Identification
- Manufacturer
- Model
- Serial Number
- Capacity
- Storage Technology
- Selected Sanitization Method
- Sanitization Status
- Verification Status
- Start Time
- Completion Time
- Operator Information
- System Information
- Process Events
- Verification Results
Device Health & Sanitization Assessment
A reliable data erasure workflow should not treat every storage device as identical.
Before sanitization, DSP can provide relevant device information such as:
- SMART Health Information
- Temperature
- Power-On Hours
- Firmware
- Model
- Serial Number
- Storage Capacity
- Device Errors
- Sector-Related Information
This can help identify devices that may require additional assessment before executing a sanitization operation.
Bad Sectors & Sanitization Risk
Bad sectors can affect the ability of an overwrite-based sanitization process to address storage locations.
DSP can identify and report relevant storage errors and bad-sector conditions as part of the device assessment and reporting workflow.
Where a device cannot reliably address the required storage area organizations should not automatically assume that a successful software completion message represents complete sanitization.
For higher-risk situations, the organization may need to select a stronger or technology-appropriate sanitization method or move to physical destruction.
NIST SP 800-88 Rev. 1 Clear & Cryptographic Erase
Rev. 1 also included guidance concerning Cryptographic Erase (CE).
Cryptographic Erase can be appropriate where the storage device uses encryption and the necessary cryptographic conditions and implementation characteristics provide sufficient assurance.
However, CE should not simply be assumed to be effective because a device supports encryption. The device's encryption architecture, key management and implementation characteristics must be considered.
DSP can separately support applicable sanitization methods rather than treating every storage device as a conventional overwrite target.
Audit-Ready Sanitization Certificate
NIST SP 800-88 Rev. 1 included Appendix G — Sample "Certificate of Sanitization" Form for documenting organizational sanitization activities.
DSP extends this operational concept with its own audit-ready sanitization certificate.
A DSP certificate can document information such as:
Device Information
- Manufacturer
- Model
- Serial number
- Capacity
- Media type
- Interface
Sanitization Information
- Selected standard/method
- NIST SP 800-88 Rev. 1 Clear
- Sanitization start time
- Completion time
- Sanitization status
Verification Information
- Verification status
- Verification results
- Relevant process information
- Exceptions or errors, where applicable
Audit Information
- Operator
- Workstation/system
- Date and time
- Organization/customer
- Case or ticket reference
- Report identification
Report Formats
DSP can generate professional PDF and HTML sanitization reports suitable for internal records, IT asset disposition workflows, refurbishment operations and audit documentation.
What Does The DSP Certificate Mean?
The DSP certificate documents the sanitization operation actually performed by Data Sanitization Pro.
It does not mean:
- NIST Has Certified DSP;
- NIST Has Approved DSP;
- The Certificate Was Issued By NIST;
- The Device Has Received An External NIST Certification.
The certificate is DSP's audit documentation showing the selected sanitization method, device information, execution details and verification information.
NIST SP 800-88 Rev. 1 Clear For ITAD
Secure data erasure is an important part of the IT Asset Disposition (ITAD) lifecycle.
Before computers, servers, HDDs, SSDs and removable media are:
- Reused;
- Refurbished;
- Resold;
- Transferred;
- Recycled;
- Returned To Inventory;
organizations need a controlled process for handling residual data.
A documented Rev. 1 Clear workflow can support legacy ITAD policies where this methodology remains specified by contract or organizational procedure.
DSP combines:
DEVICE IDENTIFICATION+SANITIZATION+VERIFICATION+REPORTING
into one software-controlled workflow.
Enterprise Data Erasure
For enterprise environments, DSP can support controlled sanitization of multiple devices and storage technologies.
Typical use cases include:
- Corporate IT Asset Retirement
- Data-Center Hardware Decommissioning
- Laptop And Desktop Refurbishment
- HDD Retirement
- SSD Retirement
- USB Media Sanitization
- Memory-Card Sanitization
- ITAD Operations
- Electronics Recycling Workflows
- Hardware Resale And Refurbishment
- Internal Media Reuse
Multiple devices can be processed according to the organization's selected workflow and licensing configuration.
Offline Data Sanitization
DSP can also be used in environments where sanitization systems should operate without depending on public internet connectivity.
This is particularly relevant for:
- High-Security Environments
- Government Facilities
- Enterprise IT Departments
- Restricted Networks
- Air-Gapped Environments
- Controlled ITAD Facilities
Offline operation allows sanitization activities to be performed within the organization's controlled infrastructure.
Rev. 1 Clear vs Rev. 2 Clear
| Area | NIST SP 800-88 Rev. 1 | NIST SP 800-88 Rev. 2 |
|---|---|---|
| Publication | December 2014 | September 2025 |
| Current Status | Withdrawn | Current |
| Clear Approach | Defined media-specific techniques | Program/risk-focused guidance |
| Overwrite | Explicitly described for applicable media | Not presented as a universal fixed technique |
| Technology-Specific Details | Extensive | Greater reliance on current standards/approved techniques |
| IEEE 2883 Relationship | Referenced as supporting material | Greater emphasis on current technology-specific standards |
| Verification | Explicitly addressed | Verification and validation remain important |
| Certificate Documentation | Sample certificate included | Program-level documentation emphasized |
NIST states that Rev. 2 supersedes Rev. 1 and substantially changes the publication's focus toward establishing an enterprise or agency media sanitization program.
Why Keep A Rev. 1 Clear Method?
Although Rev. 1 is withdrawn organizations may still encounter it in:
- Legacy Security Policies
- Existing ITAD Contracts
- Historical Procurement Specifications
- Internal SOPs
- Customer Requirements
- Older Compliance Documentation
- Existing Sanitization Workflows
- Archived Audit Requirements
DSP's dedicated Rev. 1 Clear method allows such organizations to maintain a documented workflow where continued use of the historical methodology is specifically required.
For new sanitization programs organizations should evaluate NIST SP 800-88 Rev. 2 and current technology-specific standards and organizational requirements.
DSP Sanitization Engine
The DSP Sanitization Engine provides a controlled execution layer for supported sanitization methodologies.
For NIST SP 800-88 Rev. 1 Clear, the workflow is:
- 01Select Method
- 02Select Device
- 03Execute Clear
- 04Verify
- 05Document
- 06Certify
The same DSP platform can provide separate dedicated methods for other supported sanitization methodologies.
This prevents different standards from being treated as a single generic "wipe" operation.
25 Sanitization Methods In One Platform
DSP brings multiple sanitization methodologies into a single data erasure software environment.
Depending on the selected method, DSP can provide:
Each certificate identifies the sanitization method actually executed by DSP.
- 01DSP-DPDP India
- 02NIST SP 800-88 Rev. 1 Clear
- 03NIST SP 800-88 Rev. 1 Purge
- 04NIST SP 800-88 Rev. 2 Clear
- 05NIST SP 800-88 Rev. 2 Purge
- 06IEEE 2883-2022
- 07ISO/IEC 27040:2024
- 08Random Overwrite
- 09DoD 5220.22-M
- 10DoD 5220.22-M ECE
- 11NSA/CSS Policy Manual 9-12
- 12HMG IS5 Baseline
- 13HMG IS5 Enhanced
- 14CSEC ITSG-06
- 15BSI-GSE
- 16BSI VSITR
- 17Gutmann Method
- 18Schneier Algorithm
- 19Pfitzner Method
- 20AFSSI-5020
- 21AR 380-19
- 22GOST R 50739-95
- 23NZISM
- 24NAVSO P-5239-26
- 25RCMP TSSIT OPS-II
NIST SP 800-88 Rev. 1 Clear — Key Takeaways
NIST SP 800-88 Rev. 1 Clear was a logical media sanitization methodology designed to protect against applicable data recovery while allowing media to remain usable.
Key characteristics include:
- Historical NIST media sanitization methodology
- Clear, Purge and Destroy framework
- Technology-specific recommendations
- Overwrite-based Clear procedures for applicable media
- Verification of sanitization results
- Risk-based sanitization decisions
- Documentation and certificate support
- Different treatment for HDD, SSD, USB and memory-card technologies
- Specific cautions for flash storage
- Support for controlled media reuse and disposition
Today, Rev. 1 is withdrawn and superseded by NIST SP 800-88 Rev. 2.
NIST Clear Questions
Is NIST SP 800-88 Rev. 1 Still Current?
No. NIST withdrew Rev. 1 on **September 26, 2025** and Rev. 2 superseded it.
What Is NIST 800-88 Rev. 1 Clear?
It is the Clear category defined in the 2014 revision of NIST SP 800-88 for sanitizing media while generally preserving its usability.
Was NIST Rev. 1 Clear A Multi-Pass Wipe?
Not universally. For applicable magnetic media, Rev. 1 specified at least one fixed-value overwrite pass, while allowing multiple passes or more complex patterns. Different media types had different recommendations.
Is NIST Clear The Same As Formatting?
No. Formatting or deleting files does not automatically constitute media sanitization.
Can NIST Rev. 1 Clear Be Used On SSDs?
Rev. 1 included Clear recommendations for flash-based storage but warned that conventional overwriting may not sanitize unmapped physical areas and may reduce flash media lifetime.
Does DSP Provide NIST Certification?
DSP provides an **audit-ready certificate documenting the sanitization operation performed by DSP**. It is not a certification issued by NIST.
Can Organizations Still Use The Rev. 1 Method?
Organizations may maintain legacy Rev. 1 procedures where their internal policy, contract or historical workflow specifically requires them. For new programs, the current NIST publication is SP 800-88 Rev. 2.
Related Standards
Run NIST Clear With A Certificate For Every Drive
Data Sanitization Pro runs all 25 standards offline and verifies the result.
