CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 04 Of 25 · Modern And Device Aware

NIST SP 800-88 Rev. 2 — Clear

Modern NIST Clear Method For Secure Data Erasure

United States1 PassVerification Available
Data Sanitization Pro running a NIST 800-88 Rev. 2 Clear job

At A Glance

Published By
National Institute of Standards and Technology (NIST)
Reference
SP 800-88 Revision 2, 2025
Region
United States
Passes
1
Verification
Available On Every Run
Relative Run Time
1× a single pass

What The Software Writes

  1. Pass 1 Fixed pattern 0x00
  2. Verify Read back of the final pass, available on every run.
  3. Certify Signed certificate with device, method, result and operator

NIST SP 800-88 Rev. 2 — Clear is the current NIST Clear sanitization method for logically sanitizing storage media while generally preserving the usability of the media.

Published on September 26, 2025, NIST SP 800-88 Rev. 2 supersedes Rev. 1 and significantly updates the approach to media sanitization. The current revision places greater emphasis on establishing an organizational media sanitization program, selecting appropriate techniques based on information sensitivity and storage technology and validating sanitization effectiveness.

For organizations implementing NIST-aligned data erasure workflows, Data Sanitization Pro (DSP) provides a dedicated NIST SP 800-88 Rev. 2 Clear method through the DSP Sanitization Engine.

Important: NIST SP 800-88 Rev. 2 does not define Clear as a single universal multi-pass overwrite algorithm. Technology-specific sanitization techniques should be selected according to applicable current standards organizational requirements and the capabilities of the storage technology.

01

What Is NIST SP 800-88 Rev. 2 Clear?

NIST SP 800-88 Rev. 2 defines three primary sanitization methods:

  • Clear
  • Purge
  • Destroy

Clear applies logical techniques to sanitize data in all user-addressable storage locations to protect against simple, non-invasive recovery techniques using the same interface available to the user, such as the host interface.

The objective is to remove the target data while normally leaving the information storage media usable.

In simple terms:

Clear=Logical Sanitization+User-Addressable Storage+Media Reuse

Clear is therefore different from ordinary file deletion, quick formatting or simply removing filesystem references.

02

NIST Clear Is Not A Fixed Wiping Algorithm

One of the most important differences between NIST SP 800-88 Rev. 1 and Rev. 2 is the way sanitization techniques are addressed.

Rev. 2 does not prescribe one universal NIST overwrite pattern such as:

  • One-Pass Zero
  • Three-Pass Overwrite
  • Seven-Pass Overwrite
  • 35-pass Overwrite

Instead, NIST Rev. 2 focuses on selecting an appropriate sanitization technique for the storage technology and organizational requirement.

NIST states that, except for Cryptographic Erase, detailed sanitization technique and tool descriptions have been replaced with recommendations to comply with IEEE 2883, NSA specifications or an organizationally approved standard.

Therefore:

NIST Clear is a sanitization method — not a universal pass-count algorithm.

03

Current Status Of NIST SP 800-88 Rev. 2

ItemCurrent Information
PublicationNIST SP 800-88 Rev. 2
TitleGuidelines for Media Sanitization
PublishedSeptember 26, 2025
StatusCurrent
SupersedesSP 800-88 Rev. 1
ClearCurrent sanitization method
PurgeCurrent sanitization method
DestroyCurrent sanitization method
Program FocusEnterprise/organizational media sanitization

NIST's official publication page identifies Rev. 2 as the current final publication and states that it supersedes Rev. 1.

04

Technical Definition Of Clear

NIST Rev. 2 defines Clear as a method that:

  • Applies Logical Sanitization Techniques;
  • Addresses All User-Addressable Storage Locations;
  • Protects Against Simple, Non-Invasive Recovery;
  • Uses The Same Interface Available To The User;
  • Generally Leaves The Storage Media Usable.

Logical sanitization techniques can use software or other tools through an interface to:

  • Replace Data Systematically;
  • Issue Commands That Cause Data To Be Eliminated;
  • Eliminate Access To Data.

NIST describes logical sanitization as leaving the information storage media in a usable state.

05

How NIST Rev. 2 Clear Works

A Clear operation can use appropriate logical techniques over the storage device's available interface.

NIST explains that Clear is typically applied using standard read/write commands, such as:

  • Rewriting storage with a new value;
  • Using an appropriate device reset/factory-state mechanism where rewriting is not supported.

A Clear technique can also overwrite user-addressable storage with non-sensitive data using standard read/write commands.

The security objective is to replace the target data with non-sensitive data and prevent recovery through the applicable interface.

06

Clear vs File Deletion

Deleting a file does not automatically constitute media sanitization.

A normal file deletion may only remove or modify filesystem references while the underlying storage locations continue to contain remnants of the original information.

Similarly:

Delete≠Format≠Secure Data Erasure

A proper Clear operation addresses the applicable user-addressable storage locations according to the selected sanitization technique.

07

Clear vs Factory Reset

A factory reset can sometimes be used as a Clear technique where the device supports an appropriate reset mechanism and rewriting is not supported.

However, a factory reset should not automatically be treated as secure sanitization for every storage technology.

The organization must evaluate:

  • What Data The Reset Actually Removes;
  • Which Storage Locations Are Affected;
  • Whether Residual Data Remains Accessible;
  • The Device Implementation;
  • The Sensitivity Of The Information;
  • The Applicable Organizational Sanitization Requirement.
08

NIST Clear And HDDs

Traditional magnetic HDDs are generally well suited to logical Clear techniques because their user-addressable storage can be accessed through standard storage interfaces.

For appropriate HDDs, logical sanitization can involve overwriting user-addressable storage with non-sensitive data.

DSP can provide a controlled workflow for:

  • HDD Identification;
  • Storage Assessment;
  • Method Selection;
  • Sanitization Execution;
  • Progress Monitoring;
  • Verification;
  • Reporting.
09

NIST Clear And SSDs

Modern SSDs require additional consideration.

SSDs commonly use:

  • Flash Translation Layers
  • Wear Leveling
  • Garbage Collection
  • Spare Cells
  • Over-Provisioning
  • Controller-Managed Physical Mapping

Because the host interface does not necessarily expose every physical flash location, a conventional overwrite should not automatically be treated as equivalent to sanitizing every physical location.

NIST Rev. 2 therefore emphasizes technology-appropriate sanitization techniques rather than defining one universal overwrite process.

For stronger recovery-resistance requirements organizations may need to evaluate Purge or another appropriate technology-specific technique.

10

NIST Clear And NVMe

NVMe storage introduces another important consideration for modern data erasure.

NVMe SSDs are controller-managed flash devices with sophisticated internal storage-management mechanisms.

A professional NVMe data erasure workflow should therefore consider:

  • Device Capabilities;
  • Supported Sanitization Commands;
  • Controller Behavior;
  • User-Addressable Storage;
  • Encryption;
  • Device Health;
  • Errors And Inaccessible Regions;
  • Organizational Security Requirements.

NIST Rev. 2's technology-neutral program approach allows organizations to select appropriate current techniques rather than relying on an outdated universal overwrite recipe.

11

Modern Storage Architecture

The fundamental challenge with modern storage is that the logical address visible to the operating system does not necessarily represent every physical location where previous data may have existed.

This is particularly relevant for:

  • SSDs
  • NVMe
  • Flash Storage
  • USB Flash Drives
  • SD Cards
  • microSD Cards
  • CFexpress
  • Enterprise Flash Arrays

For such devices organizations should evaluate whether Clear provides the required security outcome or whether a stronger technology-specific Purge technique is appropriate.

12

NIST Clear & IEEE 2883

NIST SP 800-88 Rev. 2 places significantly greater emphasis on current technology-specific standards.

NIST states that, apart from Cryptographic Erase, detailed sanitization techniques and tool information have been replaced with recommendations to comply with IEEE 2883, NSA specifications or an organizationally approved standard.

This makes IEEE 2883 particularly relevant when determining how Clear or Purge should be technically implemented for a specific storage technology.

Therefore:

NIST SP 800-88 Rev. 2Sanitization Program & Method
IEEE 2883Technology-Specific Sanitization Techniques

This relationship is important for modern enterprise data erasure.

13

DSP NIST SP 800-88 Rev. 2 Clear

Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 2 Clear Method through the DSP Sanitization Engine.

14

DSP Workflow

  1. 01Identify Device
  2. 02Classify Storage Technology
  3. 03Assess Device
  4. 04Select NIST SP 800-88 Rev. 2 Clear
  5. 05Select Applicable Technique
  6. 06DSP Sanitization Engine
  7. 07Execute Sanitization
  8. 08Verify Result
  9. 09Validate Outcome
  10. 10Document Operation
  11. 11Audit-Ready Certificate

This workflow separates the NIST Clear method from unrelated generic wiping algorithms.

15

What Does DSP Sanitize?

Depending on the selected technique and device capability, Clear is concerned with user-addressable storage locations.

This can include storage locations containing:

  • User files
  • Filesystem data
  • File metadata
  • User-addressable blocks
  • Previously stored information accessible through the device interface

The actual scope depends on the storage technology and selected sanitization technique.

16

Clear vs Purge vs Destroy

MethodPrimary ObjectiveMedia Reuse
ClearProtect against simple, non-invasive recovery through the applicable interfaceGenerally intended
PurgeMake recovery infeasible using state-of-the-art laboratory techniquesPotentially
DestroyRender target data inaccessible and make media unusableNo

NIST Rev. 2 maintains these three sanitization methods while placing greater emphasis on organizational decision-making and appropriate current techniques.

17

Risk-Based Sanitization

NIST Rev. 2 emphasizes selecting sanitization methods based on the sensitivity of the information and organizational requirements.

A device should not automatically receive the same sanitization treatment simply because it is an HDD, SSD or NVMe device.

Important considerations include:

  • Information Sensitivity
  • Confidentiality Requirements
  • Storage Technology
  • Device Capabilities
  • Intended Disposition
  • Reuse Requirements
  • Organizational Policy
  • Applicable Technology-Specific Standards

This makes modern media sanitization a risk-based process rather than simply a pass-count selection.

18

Media Reuse

One of the important characteristics of Clear is that the storage media is generally intended to remain usable.

This makes Clear relevant to:

  • Enterprise Hardware Reuse
  • ITAD
  • Refurbishment
  • Resale
  • Internal Asset Reassignment
  • Data-Center Equipment Reuse
  • Laptop Refurbishment
  • Desktop Refurbishment
  • Storage-Device Reuse

However, reuse should only occur when the selected sanitization method provides the security outcome required by the organization.

19

Clear For IT Asset Disposition

Secure data erasure is a critical stage in the IT Asset Disposition (ITAD) lifecycle.

Before an asset is:

  1. 01Reused
  2. 02Refurbished
  3. 03Resold
  4. 04Transferred
  5. 05Recycled

its stored information must be handled according to the organization's sanitization requirements.

DSP can provide a documented workflow for:

  • Device Identification;
  • Sanitization Method Selection;
  • Secure Data Erasure;
  • Verification;
  • Reporting;
  • Audit Documentation.
20

Verification

Verification determines whether the sanitization operation produced the expected technical result.

For a Clear operation, verification can consider:

  • Completion Status;
  • Device Response;
  • Error Conditions;
  • Sanitization Process Status;
  • Relevant Device Health Information;
  • Verification Results.

NIST Rev. 2 emphasizes verification as part of the sanitization process and distinguishes verification from the broader question of whether the sanitization outcome is acceptable for the information's confidentiality requirements.

21

Validation

Validation goes beyond checking whether a technical operation completed.

It asks whether the resulting sanitization is acceptable for the organization's security requirement.

A simplified workflow is:

  1. 01Verify
  2. 02Assess Result
  3. 03Accept Or Reject

If the outcome is not acceptable, the organization can determine whether to:

  • Repeat Sanitization;
  • Select Another Technique;
  • Escalate From Clear To Purge;
  • Use Another Approved Method;
  • Destroy The Media.

This distinction is especially important for damaged, unusual or technology-complex storage devices.

22

Device Health Assessment

DSP can provide storage-device information that helps operators understand the condition of the target media.

Depending on device support, this can include:

  • SMART Health
  • Temperature
  • Power-On Hours
  • Firmware
  • Model
  • Serial Number
  • Capacity
  • Error Information
  • Storage Performance Information

Device health information can be included in the overall sanitization record.

23

Bad Sectors

Bad sectors and storage errors can affect the reliability of a logical sanitization operation.

DSP can identify and report relevant conditions such as:

  • Logical Bad Sectors
  • Physical Bad Sectors
  • Read Errors
  • Uncorrectable Sectors
  • Device Errors
  • Access Failures

A device that cannot reliably address required storage locations should not automatically be treated as successfully sanitized merely because a software process terminates.

The appropriate response depends on the organization's sanitization policy and the required security level.

24

Over-Provisioning & Unmapped Storage

Modern flash storage can contain areas that are not directly accessible through the normal host interface.

Examples include:

  • Spare NAND
  • Over-Provisioned Capacity
  • Remapped Locations
  • Controller-Managed Blocks

This is one reason a conventional host-level overwrite may not be appropriate for every sanitization requirement.

If the organization requires protection against more advanced recovery techniques, it should evaluate a technology-specific Purge technique rather than assuming Clear provides the required assurance.

25

Dedicated Device Sanitization Commands

Modern storage devices can provide dedicated sanitization commands through their native interfaces.

These may provide a more technology-appropriate mechanism than repeatedly writing data through the host operating system.

However, NIST Rev. 2 specifically recognizes the need to establish trust in vendor implementations of sanitization techniques for Clear and Purge.

Therefore organizations should consider:

  • Device Manufacturer;
  • Command Implementation;
  • Firmware;
  • Supported Standards;
  • Validation Evidence;
  • Organizational Approval;
  • Applicable Technology-Specific Guidance.
26

Cryptographic Erase

Cryptographic Erase (CE) is treated separately in NIST Rev. 2.

CE can be applicable where data is encrypted and sanitization of the relevant cryptographic keys makes the target data inaccessible.

NIST specifically expanded its Rev. 2 guidance around Cryptographic Erase, including additional consideration of cryptographic keys, key sanitization and externally managed keys.

CE may be appropriate as a Purge technique depending on the device and encryption architecture.

It should not automatically be represented as ordinary Clear.

27

Audit-Ready Sanitization Certificate

DSP provides an audit-ready sanitization certificate for its supported sanitization methods.

For the NIST SP 800-88 Rev. 2 Clear method, the certificate can document:

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Media type
  • Interface

Sanitization Information

  • Selected method
  • NIST SP 800-88 Rev. 2 Clear
  • Selected technique
  • Start time
  • Completion time
  • Sanitization status

Verification Information

  • Verification status
  • Verification result
  • Errors
  • Exceptions
  • Relevant process information

Operator & Audit Information

  • Operator
  • System/workstation
  • Organization/customer
  • Case/ticket reference
  • Date/time
  • Report ID

Output

  • PDF
  • HTML
  • Print-ready report
28

What Does The DSP Certificate Mean?

The DSP certificate documents the sanitization operation actually performed by Data Sanitization Pro.

It does not mean:

  • NIST Certified DSP;
  • NIST Approved DSP;
  • NIST Issued The Certificate;
  • IEEE Certified DSP;
  • The Storage Device Received An External NIST Certification.

The certificate is DSP's audit documentation of the operation performed, including device, method, execution and verification information.

29

Online & Offline Data Erasure

DSP can support both online and offline operational environments.

Offline

Suitable for controlled environments such as:

  • Government facilities
  • Restricted networks
  • Air-gapped systems
  • High-security environments
  • Controlled ITAD facilities

Online

Can support centralized operational environments where organizations require:

  • Centralized reporting
  • Multi-site workflows
  • Historical records
  • Administrative visibility
  • Centralized management

The selected deployment model can be aligned with organizational security requirements.

30

Multi-Device Sanitization

Enterprise and ITAD operations may need to sanitize multiple storage devices.

DSP can support controlled multi-device workflows for supported storage technologies, allowing operators to monitor:

  • Active Devices
  • Sanitization Progress
  • Completion Status
  • Verification Status
  • Errors
  • Processing Information

Each device can maintain its own sanitization record and certificate.

31

NIST Rev. 2 Clear For Enterprise IT

Common applications include:

  • Enterprise Laptop Erasure
  • Desktop Data Erasure
  • HDD Sanitization
  • SSD Data Erasure
  • NVMe Data Erasure
  • Data-Center Hardware Reuse
  • ITAD Operations
  • Refurbishment
  • Secure Equipment Resale
  • Government Asset Sanitization
  • Storage-Media Reuse

DSP provides a centralized software environment for executing and documenting supported sanitization methods.

32

NIST Rev. 2 Clear vs Historical Multi-Pass Wiping

Traditional wiping software often markets:

  • 3-pass Wipe
  • 7-pass Wipe
  • 35-pass Wipe
  • DoD Wipe
  • Gutmann Wipe

NIST Rev. 2 takes a different approach.

The current guidance does not define Clear as a universal pass-count algorithm. Instead, it focuses on choosing an appropriate sanitization technique based on the storage technology, confidentiality requirement and organizational sanitization program.

Therefore:

Modern NIST Clear≠"Run X overwrite passes."

33

NIST Rev. 1 Clear vs Rev. 2 Clear

AreaRev. 1 ClearRev. 2 Clear
StatusWithdrawnCurrent
Publication20142025
ApproachDetailed media-specific guidanceProgram and risk-focused
OverwriteExplicit techniques describedNot a universal prescribed algorithm
Technology-Specific GuidanceDetailed in publicationCurrent external standards emphasized
IEEE 2883Supporting referenceGreater importance
VerificationIncludedIncluded
ValidationLess centralGreater emphasis
Organizational ProgramLess centralMajor focus

NIST describes Rev. 2 as a substantial shift toward maintaining an enterprise or agency media sanitization program.

34

NIST Rev. 2 Clear & IEEE 2883

For modern storage devices, the relationship between NIST and IEEE 2883 is particularly important.

NIST SP 800-88 Rev. 2 establishes the broader sanitization framework and method selection.

IEEE 2883-2022 provides technology-specific sanitization methods and requirements for logical and physical storage.

NIST Rev. 2 specifically directs organizations toward IEEE 2883, NSA specifications or an organizationally approved standard for applicable sanitization techniques.

This provides a more practical framework for modern HDD, SSD and NVMe data erasure than relying on historical generic overwrite pass counts.

35

DSP Sanitization Engine

The DSP Sanitization Engine provides dedicated implementations of supported sanitization methodologies.

For NIST SP 800-88 Rev. 2 Clear:

  1. 01Select Method
  2. 02Select Device
  3. 03Assess Storage
  4. 04Select Applicable Technique
  5. 05Execute
  6. 06Verify
  7. 07Validate
  8. 08Document
  9. 09Certify

This allows the sanitization method selected by the operator to remain visible throughout the process and in the final audit record.

36

25 Sanitization Methods In One Platform

37

Key Takeaways

NIST SP 800-88 Rev. 2 Clear is the current NIST Clear sanitization method for logically sanitizing user-addressable storage locations against simple, non-invasive recovery while generally preserving media usability.

Key points:

  • Current NIST guidance
  • Published September 26, 2025
  • Supersedes Rev. 1
  • Uses a logical sanitization approach
  • Applies to user-addressable storage locations
  • Not a universal fixed-pass wiping algorithm
  • Requires technology-appropriate technique selection
  • Strongly connected with current technology-specific standards
  • IEEE 2883 is particularly relevant
  • Verification and validation are important
  • HDD, SSD and NVMe require technology-aware treatment
  • Clear is different from Purge
  • Clear is different from Destroy
  • Clear is different from ordinary deletion or formatting
  • DSP provides a dedicated Rev. 2 Clear method through the DSP Sanitization Engine
  • DSP provides an audit-ready certificate documenting the actual operation performed
FAQ

NIST Rev. 2 Clear Questions

What Is NIST SP 800-88 Rev. 2 Clear?

It is the current NIST Clear sanitization method that uses logical techniques to sanitize data in user-addressable storage locations against simple, non-invasive recovery.

Is NIST Rev. 2 Clear A 3-pass Wipe?

No. Rev. 2 does not define Clear as a universal three-pass, seven-pass or 35-pass overwrite algorithm.

Does NIST Rev. 2 Require A Specific Overwrite Pattern?

No universal pattern is prescribed. Rev. 2 emphasizes appropriate techniques based on storage technology organizational requirements and applicable current standards.

Is Clear Stronger Than Purge?

No. Purge has the stronger objective of making target-data recovery infeasible using state-of-the-art laboratory techniques. Clear is intended to protect against simple, non-invasive recovery through the applicable user interface.

Can Clear Be Used For SSDs?

Clear can be applicable to some SSD scenarios, but flash architecture must be considered. Wear leveling, over-provisioning and controller-managed storage can make conventional host-level overwriting inappropriate for stronger sanitization requirements.

Does NIST Rev. 2 Recommend IEEE 2883?

NIST Rev. 2 recommends complying with IEEE 2883, NSA specifications or an organizationally approved standard for applicable sanitization techniques.

Is Factory Reset Always Secure Data Erasure?

No. A factory reset can be an applicable Clear technique in certain circumstances, but its actual sanitization behavior must be evaluated for the specific device and security requirement.

Does DSP Provide NIST Certification?

DSP provides an **audit-ready certificate documenting the sanitization operation performed by DSP**. It is not a certification issued by NIST.

Is NIST SP 800-88 Rev. 2 Current?

Yes. NIST published the final Rev. 2 on **September 26, 2025** and it supersedes Rev. 1.

Run NIST Rev. 2 Clear With A Certificate For Every Drive

Data Sanitization Pro runs all 25 standards offline and verifies the result.