Device Information
- Manufacturer
- Model
- Serial number
- Capacity
- Media type
- Interface
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
Modern NIST Clear Method For Secure Data Erasure

NIST SP 800-88 Rev. 2 — Clear is the current NIST Clear sanitization method for logically sanitizing storage media while generally preserving the usability of the media.
Published on September 26, 2025, NIST SP 800-88 Rev. 2 supersedes Rev. 1 and significantly updates the approach to media sanitization. The current revision places greater emphasis on establishing an organizational media sanitization program, selecting appropriate techniques based on information sensitivity and storage technology and validating sanitization effectiveness.
For organizations implementing NIST-aligned data erasure workflows, Data Sanitization Pro (DSP) provides a dedicated NIST SP 800-88 Rev. 2 Clear method through the DSP Sanitization Engine.
Important: NIST SP 800-88 Rev. 2 does not define Clear as a single universal multi-pass overwrite algorithm. Technology-specific sanitization techniques should be selected according to applicable current standards organizational requirements and the capabilities of the storage technology.
NIST SP 800-88 Rev. 2 defines three primary sanitization methods:
Clear applies logical techniques to sanitize data in all user-addressable storage locations to protect against simple, non-invasive recovery techniques using the same interface available to the user, such as the host interface.
The objective is to remove the target data while normally leaving the information storage media usable.
In simple terms:
Clear=Logical Sanitization+User-Addressable Storage+Media Reuse
Clear is therefore different from ordinary file deletion, quick formatting or simply removing filesystem references.
One of the most important differences between NIST SP 800-88 Rev. 1 and Rev. 2 is the way sanitization techniques are addressed.
Rev. 2 does not prescribe one universal NIST overwrite pattern such as:
Instead, NIST Rev. 2 focuses on selecting an appropriate sanitization technique for the storage technology and organizational requirement.
NIST states that, except for Cryptographic Erase, detailed sanitization technique and tool descriptions have been replaced with recommendations to comply with IEEE 2883, NSA specifications or an organizationally approved standard.
Therefore:
NIST Clear is a sanitization method — not a universal pass-count algorithm.
| Item | Current Information |
|---|---|
| Publication | NIST SP 800-88 Rev. 2 |
| Title | Guidelines for Media Sanitization |
| Published | September 26, 2025 |
| Status | Current |
| Supersedes | SP 800-88 Rev. 1 |
| Clear | Current sanitization method |
| Purge | Current sanitization method |
| Destroy | Current sanitization method |
| Program Focus | Enterprise/organizational media sanitization |
NIST's official publication page identifies Rev. 2 as the current final publication and states that it supersedes Rev. 1.
NIST Rev. 2 defines Clear as a method that:
Logical sanitization techniques can use software or other tools through an interface to:
NIST describes logical sanitization as leaving the information storage media in a usable state.
A Clear operation can use appropriate logical techniques over the storage device's available interface.
NIST explains that Clear is typically applied using standard read/write commands, such as:
A Clear technique can also overwrite user-addressable storage with non-sensitive data using standard read/write commands.
The security objective is to replace the target data with non-sensitive data and prevent recovery through the applicable interface.
Deleting a file does not automatically constitute media sanitization.
A normal file deletion may only remove or modify filesystem references while the underlying storage locations continue to contain remnants of the original information.
Similarly:
Delete≠Format≠Secure Data Erasure
A proper Clear operation addresses the applicable user-addressable storage locations according to the selected sanitization technique.
A factory reset can sometimes be used as a Clear technique where the device supports an appropriate reset mechanism and rewriting is not supported.
However, a factory reset should not automatically be treated as secure sanitization for every storage technology.
The organization must evaluate:
Traditional magnetic HDDs are generally well suited to logical Clear techniques because their user-addressable storage can be accessed through standard storage interfaces.
For appropriate HDDs, logical sanitization can involve overwriting user-addressable storage with non-sensitive data.
DSP can provide a controlled workflow for:
Modern SSDs require additional consideration.
SSDs commonly use:
Because the host interface does not necessarily expose every physical flash location, a conventional overwrite should not automatically be treated as equivalent to sanitizing every physical location.
NIST Rev. 2 therefore emphasizes technology-appropriate sanitization techniques rather than defining one universal overwrite process.
For stronger recovery-resistance requirements organizations may need to evaluate Purge or another appropriate technology-specific technique.
NVMe storage introduces another important consideration for modern data erasure.
NVMe SSDs are controller-managed flash devices with sophisticated internal storage-management mechanisms.
A professional NVMe data erasure workflow should therefore consider:
NIST Rev. 2's technology-neutral program approach allows organizations to select appropriate current techniques rather than relying on an outdated universal overwrite recipe.
The fundamental challenge with modern storage is that the logical address visible to the operating system does not necessarily represent every physical location where previous data may have existed.
This is particularly relevant for:
For such devices organizations should evaluate whether Clear provides the required security outcome or whether a stronger technology-specific Purge technique is appropriate.
NIST SP 800-88 Rev. 2 places significantly greater emphasis on current technology-specific standards.
NIST states that, apart from Cryptographic Erase, detailed sanitization techniques and tool information have been replaced with recommendations to comply with IEEE 2883, NSA specifications or an organizationally approved standard.
This makes IEEE 2883 particularly relevant when determining how Clear or Purge should be technically implemented for a specific storage technology.
Therefore:
This relationship is important for modern enterprise data erasure.
Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 2 Clear Method through the DSP Sanitization Engine.
This workflow separates the NIST Clear method from unrelated generic wiping algorithms.
Depending on the selected technique and device capability, Clear is concerned with user-addressable storage locations.
This can include storage locations containing:
The actual scope depends on the storage technology and selected sanitization technique.
| Method | Primary Objective | Media Reuse |
|---|---|---|
| Clear | Protect against simple, non-invasive recovery through the applicable interface | Generally intended |
| Purge | Make recovery infeasible using state-of-the-art laboratory techniques | Potentially |
| Destroy | Render target data inaccessible and make media unusable | No |
NIST Rev. 2 maintains these three sanitization methods while placing greater emphasis on organizational decision-making and appropriate current techniques.
NIST Rev. 2 emphasizes selecting sanitization methods based on the sensitivity of the information and organizational requirements.
A device should not automatically receive the same sanitization treatment simply because it is an HDD, SSD or NVMe device.
Important considerations include:
This makes modern media sanitization a risk-based process rather than simply a pass-count selection.
One of the important characteristics of Clear is that the storage media is generally intended to remain usable.
This makes Clear relevant to:
However, reuse should only occur when the selected sanitization method provides the security outcome required by the organization.
Secure data erasure is a critical stage in the IT Asset Disposition (ITAD) lifecycle.
Before an asset is:
its stored information must be handled according to the organization's sanitization requirements.
DSP can provide a documented workflow for:
Verification determines whether the sanitization operation produced the expected technical result.
For a Clear operation, verification can consider:
NIST Rev. 2 emphasizes verification as part of the sanitization process and distinguishes verification from the broader question of whether the sanitization outcome is acceptable for the information's confidentiality requirements.
Validation goes beyond checking whether a technical operation completed.
It asks whether the resulting sanitization is acceptable for the organization's security requirement.
A simplified workflow is:
If the outcome is not acceptable, the organization can determine whether to:
This distinction is especially important for damaged, unusual or technology-complex storage devices.
DSP can provide storage-device information that helps operators understand the condition of the target media.
Depending on device support, this can include:
Device health information can be included in the overall sanitization record.
Bad sectors and storage errors can affect the reliability of a logical sanitization operation.
DSP can identify and report relevant conditions such as:
A device that cannot reliably address required storage locations should not automatically be treated as successfully sanitized merely because a software process terminates.
The appropriate response depends on the organization's sanitization policy and the required security level.
Modern flash storage can contain areas that are not directly accessible through the normal host interface.
Examples include:
This is one reason a conventional host-level overwrite may not be appropriate for every sanitization requirement.
If the organization requires protection against more advanced recovery techniques, it should evaluate a technology-specific Purge technique rather than assuming Clear provides the required assurance.
Modern storage devices can provide dedicated sanitization commands through their native interfaces.
These may provide a more technology-appropriate mechanism than repeatedly writing data through the host operating system.
However, NIST Rev. 2 specifically recognizes the need to establish trust in vendor implementations of sanitization techniques for Clear and Purge.
Therefore organizations should consider:
Cryptographic Erase (CE) is treated separately in NIST Rev. 2.
CE can be applicable where data is encrypted and sanitization of the relevant cryptographic keys makes the target data inaccessible.
NIST specifically expanded its Rev. 2 guidance around Cryptographic Erase, including additional consideration of cryptographic keys, key sanitization and externally managed keys.
CE may be appropriate as a Purge technique depending on the device and encryption architecture.
It should not automatically be represented as ordinary Clear.
DSP provides an audit-ready sanitization certificate for its supported sanitization methods.
For the NIST SP 800-88 Rev. 2 Clear method, the certificate can document:
The DSP certificate documents the sanitization operation actually performed by Data Sanitization Pro.
It does not mean:
The certificate is DSP's audit documentation of the operation performed, including device, method, execution and verification information.
DSP can support both online and offline operational environments.
Suitable for controlled environments such as:
Can support centralized operational environments where organizations require:
The selected deployment model can be aligned with organizational security requirements.
Enterprise and ITAD operations may need to sanitize multiple storage devices.
DSP can support controlled multi-device workflows for supported storage technologies, allowing operators to monitor:
Each device can maintain its own sanitization record and certificate.
Common applications include:
DSP provides a centralized software environment for executing and documenting supported sanitization methods.
Traditional wiping software often markets:
NIST Rev. 2 takes a different approach.
The current guidance does not define Clear as a universal pass-count algorithm. Instead, it focuses on choosing an appropriate sanitization technique based on the storage technology, confidentiality requirement and organizational sanitization program.
Therefore:
Modern NIST Clear≠"Run X overwrite passes."
| Area | Rev. 1 Clear | Rev. 2 Clear |
|---|---|---|
| Status | Withdrawn | Current |
| Publication | 2014 | 2025 |
| Approach | Detailed media-specific guidance | Program and risk-focused |
| Overwrite | Explicit techniques described | Not a universal prescribed algorithm |
| Technology-Specific Guidance | Detailed in publication | Current external standards emphasized |
| IEEE 2883 | Supporting reference | Greater importance |
| Verification | Included | Included |
| Validation | Less central | Greater emphasis |
| Organizational Program | Less central | Major focus |
NIST describes Rev. 2 as a substantial shift toward maintaining an enterprise or agency media sanitization program.
For modern storage devices, the relationship between NIST and IEEE 2883 is particularly important.
NIST SP 800-88 Rev. 2 establishes the broader sanitization framework and method selection.
IEEE 2883-2022 provides technology-specific sanitization methods and requirements for logical and physical storage.
NIST Rev. 2 specifically directs organizations toward IEEE 2883, NSA specifications or an organizationally approved standard for applicable sanitization techniques.
This provides a more practical framework for modern HDD, SSD and NVMe data erasure than relying on historical generic overwrite pass counts.
The DSP Sanitization Engine provides dedicated implementations of supported sanitization methodologies.
For NIST SP 800-88 Rev. 2 Clear:
This allows the sanitization method selected by the operator to remain visible throughout the process and in the final audit record.
DSP provides dedicated sanitization methods within a single data erasure platform.
Supported methods can have their own:
The result is a method-specific sanitization workflow rather than a generic "wipe completed" message.
NIST SP 800-88 Rev. 2 Clear is the current NIST Clear sanitization method for logically sanitizing user-addressable storage locations against simple, non-invasive recovery while generally preserving media usability.
Key points:
It is the current NIST Clear sanitization method that uses logical techniques to sanitize data in user-addressable storage locations against simple, non-invasive recovery.
No. Rev. 2 does not define Clear as a universal three-pass, seven-pass or 35-pass overwrite algorithm.
No universal pattern is prescribed. Rev. 2 emphasizes appropriate techniques based on storage technology organizational requirements and applicable current standards.
No. Purge has the stronger objective of making target-data recovery infeasible using state-of-the-art laboratory techniques. Clear is intended to protect against simple, non-invasive recovery through the applicable user interface.
Clear can be applicable to some SSD scenarios, but flash architecture must be considered. Wear leveling, over-provisioning and controller-managed storage can make conventional host-level overwriting inappropriate for stronger sanitization requirements.
NIST Rev. 2 recommends complying with IEEE 2883, NSA specifications or an organizationally approved standard for applicable sanitization techniques.
No. A factory reset can be an applicable Clear technique in certain circumstances, but its actual sanitization behavior must be evaluated for the specific device and security requirement.
DSP provides an **audit-ready certificate documenting the sanitization operation performed by DSP**. It is not a certification issued by NIST.
Yes. NIST published the final Rev. 2 on **September 26, 2025** and it supersedes Rev. 1.
Data Sanitization Pro runs all 25 standards offline and verifies the result.