CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 05 Of 25 · Modern And Device Aware

NIST SP 800-88 Rev. 2 — Purge

High-Assurance Data Sanitization For Modern Storage

United States3 PassesVerification Available
Data centre engineer removing drives for NIST Rev. 2 Purge sanitization

At A Glance

Published By
National Institute of Standards and Technology (NIST)
Reference
SP 800-88 Revision 2, 2025
Region
United States
Passes
3
Verification
Available On Every Run
Relative Run Time
3× a single pass

What The Software Writes

  1. Pass 1 Random data
  2. Pass 2 Random data
  3. Pass 3 Random data
  4. Verify Read back of the final pass, available on every run.
  5. Certify Signed certificate with device, method, result and operator

NIST SP 800-88 Rev. 2 — Purge is the current NIST media sanitization method intended to make recovery of target data infeasible using state-of-the-art laboratory techniques, while potentially preserving the information storage media in a reusable condition.

Published on September 26, 2025, NIST SP 800-88 Rev. 2 supersedes Rev. 1 and updates the approach to modern media sanitization. Rev. 2 places greater emphasis on organizational sanitization programs, technology-appropriate techniques, validation and establishing trust in sanitization implementations.

For organizations implementing a NIST-aligned secure data erasure workflow, Data Sanitization Pro (DSP) provides a dedicated NIST SP 800-88 Rev. 2 Purge method through the DSP Sanitization Engine.

Important: NIST SP 800-88 Rev. 2 Purge is an assurance-oriented sanitization method, not a universal fixed 3-pass, 7-pass or 35-pass wiping algorithm. NIST directs organizations toward appropriate technology-specific techniques, including IEEE 2883, NSA specifications or an organizationally approved standard.

01

What Is NIST SP 800-88 Rev. 2 Purge?

NIST SP 800-88 Rev. 2 defines three primary media sanitization methods:

  • Clear
  • Purge
  • Destroy

Purge applies physical or logical techniques intended to make recovery of target data infeasible using state-of-the-art laboratory techniques, while preserving the storage media in a potentially reusable state.

This makes Purge a higher-assurance sanitization objective than Clear.

In simple terms:

ClearProtect Against Simple, Non-Invasive Recovery
PurgeProtect Against State-Of-The-Art Laboratory Recovery
DestroyMake The Media Unusable
02

Why Use Purge?

Purge becomes relevant when an organization needs a stronger level of protection than ordinary logical sanitization can provide.

The decision can depend on:

  • Information Sensitivity
  • Confidentiality Requirements
  • Storage Technology
  • Device Architecture
  • Sanitization Capabilities
  • Intended Reuse
  • Organizational Policy
  • Applicable Standards
  • Risk Associated With Residual Data

NIST Rev. 2 states that, when possible, Purge should be used instead of Clear because it provides the stronger recovery-resistance objective while potentially preserving the storage media.

03

Purge Is Not A Fixed Wiping Algorithm

A common misconception is that NIST Purge means a specific number of overwrite passes.

It does not.

NIST SP 800-88 Rev. 2 does not define Purge as:

  • 3-pass Wiping
  • 7-pass Wiping
  • 35-pass Wiping
  • A Universal Overwrite Pattern

Instead, Purge is defined by its security objective.

The selected technique must be appropriate for the storage technology and capable of achieving the required sanitization outcome.

NIST Rev. 2 states that logical Purge techniques can vary by information storage media type and directs organizations to IEEE 2883 for acceptable technology-specific techniques.

04

NIST SP 800-88 Rev. 2 Purge Techniques

Current NIST guidance identifies technology-appropriate logical and physical approaches.

Depending on the storage technology, logical Purge techniques can include:

  • Overwrite
  • Block Erase
  • Cryptographic Erase
  • Dedicated Standardized Device Sanitization Commands
  • Other Approved Technology-Specific Sanitization Techniques

NIST explains that dedicated device sanitization commands can apply storage-specific techniques that operate below the abstraction of ordinary read/write commands.

The appropriate technique depends on the actual device and the security requirement.

05

Purge & IEEE 2883

IEEE 2883 is particularly important under the current Rev. 2 framework.

NIST states that, except for Cryptographic Erase, detailed sanitization technique and tool descriptions were replaced with recommendations to comply with:

  • IEEE 2883
  • NSA Specifications
  • An Organizationally Approved Standard

This allows the technology-specific implementation to remain aligned with current storage architectures rather than relying on outdated universal wiping recipes.

06

Modern Relationship

NIST SP 800-88 Rev. 2

Defines the media sanitization framework and method selection.

IEEE 2883

Provides technology-specific storage sanitization methods and requirements.

DSP Sanitization Engine

Executes the selected supported sanitization method.

07

Purge For HDDs

Traditional magnetic hard disk drives can support multiple Purge approaches depending on the drive and environment.

Potential approaches include:

  • Device-Specific Sanitization
  • Appropriate Overwrite Techniques
  • Block-Level Sanitization Where Supported
  • Degaussing For Applicable Magnetic Media
  • Other Approved Physical Or Logical Techniques

NIST Rev. 2 notes that physical Purge techniques historically included degaussing for magnetic tapes, magnetic removable disks and magnetic hard disk drives.

Degaussing is not a general-purpose method for modern solid-state storage.

08

Purge For SSDs

Modern SSDs require technology-aware sanitization.

An SSD may contain:

  • Flash Translation Layer
  • Wear-Leveling Mechanisms
  • Spare Cells
  • Over-Provisioned Capacity
  • Remapped Blocks
  • Garbage Collection
  • Controller-Managed Storage

A host operating system does not necessarily expose every physical flash location.

Therefore, repeatedly overwriting logical blocks should not automatically be considered equivalent to a high-assurance Purge of the entire physical media.

A technology-specific sanitization mechanism may provide a more appropriate approach.

09

Purge For NVMe Storage

NVMe SSDs are similarly dependent on controller and flash architecture.

An effective NVMe data erasure strategy should consider:

  • Device Capabilities
  • Supported Sanitize Commands
  • Controller Implementation
  • Encryption
  • User-Addressable Storage
  • Media Architecture
  • Device Health
  • Errors
  • Intended Disposition

DSP can identify the target device and its available information before the selected sanitization workflow is executed.

10

Device-Specific Sanitization Commands

Modern storage devices may provide dedicated commands specifically designed to sanitize storage.

These commands can operate at the device/controller level rather than simply writing data through normal host read/write operations.

This distinction matters because device firmware can have access to storage-management functions that are not exposed through the normal operating-system interface.

NIST Rev. 2 also highlights the importance of trust establishment in vendor implementations of Clear and Purge techniques.

Organizations should therefore evaluate:

  • Device Manufacturer
  • Model
  • Firmware
  • Command Implementation
  • Applicable Standards
  • Vendor Documentation
  • Assurance Evidence
  • Organizational Approval
11

Cryptographic Erase

Cryptographic Erase (CE) is one of the most important Purge techniques in NIST SP 800-88 Rev. 2.

CE can rapidly sanitize encrypted storage by sanitizing the cryptographic keys needed to access the target data.

NIST Rev. 2 provides expanded guidance around CE, including:

  • Cryptographic Key Types
  • Key Sanitization
  • Key-Management Considerations
  • ISO/IEC 19790 Zeroization
  • Externally Managed Keys
  • Preconditions For Effective Cryptographic Erase

NIST specifically notes that the effectiveness of CE depends on the pedigree of the cryptographic capabilities and satisfaction of required preconditions.

Therefore:

Encrypted storage + key deletion alone does not automatically establish an effective Purge.

The encryption architecture and key-management implementation matter.

12

Purge For Logical & Virtual Storage

NIST Rev. 2 also considers modern logical/virtual storage environments.

For logical or virtual storage such as cloud storage, the underlying physical information storage media may be abstracted from the data owner.

In such environments, direct physical sanitization may not be possible.

NIST notes that Cryptographic Erase may be the only viable Purge option in some logical/virtual storage situations, depending on the architecture.

Organizations should therefore understand the actual sanitization capabilities available before placing highly sensitive information into an environment.

13

Purge vs Clear

CharacteristicNIST Rev. 2 ClearNIST Rev. 2 Purge
Primary ObjectiveProtect against simple, non-invasive recoveryMake recovery infeasible using state-of-the-art laboratory techniques
TechniqueLogicalLogical or physical
Media ReuseGenerally intendedPotentially possible
Assurance LevelLowerHigher
Technology-Specific SelectionImportantCritical
Fixed Pass CountNoNo
Typical UseStandard reuse scenariosHigher-sensitivity information and stronger recovery-resistance requirements

NIST states that Purge should be preferred over Clear when possible, while the appropriate method remains dependent on the organization's sanitization requirements and storage environment.

14

Purge vs Destroy

Purge and Destroy have different outcomes.

15

Purge

Attempts to make recovery infeasible while potentially preserving the media for reuse.

16

Destroy

Makes recovery infeasible while rendering the information storage media unusable.

Examples of destruction can include:

  • Shredding
  • Disintegration
  • Pulverization
  • Other Appropriate Physical Destruction Techniques

The choice depends on whether the storage asset needs to remain usable after sanitization.

17

NIST Rev. 2 Purge For Media Reuse

One of the major advantages of an effective Purge operation is the potential to retain the physical storage device.

This makes it relevant to:

  • Enterprise Hardware Reuse
  • ITAD
  • Refurbishment
  • Secure Resale
  • Data-Center Equipment Reuse
  • Hardware Reassignment
  • Government Asset Disposition

However, reuse should only occur when the selected technique provides the required security outcome.

18

DSP NIST SP 800-88 Rev. 2 Purge

Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 2 Purge method through the DSP Sanitization Engine.

19

DSP Purge Workflow

  1. 01Identify Device
  2. 02Classify Storage Technology
  3. 03Assess Device
  4. 04Select NIST SP 800-88 Rev. 2 Purge
  5. 05Select Applicable Technology-Specific Technique
  6. 06DSP Sanitization Engine
  7. 07Execute Sanitization
  8. 08Verify Result
  9. 09Validate Outcome
  10. 10Document Operation
  11. 11Audit-Ready Certificate

This separates the Purge methodology from generic disk-wiping profiles.

20

Technology-Aware Data Sanitization

DSP can support sanitization workflows across supported storage technologies including:

  • SATA HDD
  • SATA SSD
  • SAS HDD
  • SAS SSD
  • Pata/ide
  • NVMe
  • U.2
  • M.2
  • mSATA
  • NGFF
  • USB Storage
  • Pen Drives
  • SD Cards
  • microSD Cards
  • CompactFlash
  • CFexpress
  • RAID
  • DAS
  • NAS
  • SAN
  • Server Storage

The selected technique must remain appropriate to the actual storage architecture and available sanitization capabilities.

21

Verification After Purge

Verification determines whether the sanitization operation produced the expected technical result.

DSP can record relevant information such as:

  • Device Identification
  • Sanitization Method
  • Technique
  • Completion Status
  • Device Response
  • Errors
  • Exceptions
  • Verification Status
  • Process Timestamps
  • Relevant Device Information

A completed command or process should not automatically be treated as sufficient evidence when the device reports an error or unexpected condition.

22

Verification vs Validation

NIST Rev. 2 distinguishes the technical verification of sanitization from the broader validation of whether the result is acceptable.

23

Verification

24

Did The Sanitization Operation Complete And Produce The Expected Result?

25

Validation

26

Is The Resulting Sanitization Sufficient For The Confidentiality Requirement?

A simplified workflow is:

  1. 01Execute
  2. 02Verify
  3. 03Validate
  4. 04Accept / Reject

If the result is rejected, the organization can determine whether to:

  • Repeat The Operation;
  • Select Another Sanitization Technique;
  • Escalate From Clear To Purge;
  • Use Another Approved Technique;
  • Destroy The Media.
27

Device Health & Purge

Storage health can affect sanitization reliability.

DSP can provide relevant device information such as:

  • SMART Health
  • Temperature
  • Power-On Hours
  • Firmware
  • Model
  • Serial Number
  • Capacity
  • Device Errors
  • Storage Condition

This information can be retained as part of the sanitization record.

28

Bad Sectors & Failed Storage

Bad sectors and device errors require particular attention during secure data erasure.

Potential conditions include:

  • Logical Bad Sectors
  • Physical Bad Sectors
  • Read Failures
  • Uncorrectable Sectors
  • Remapped Sectors
  • Communication Failures
  • Device-Level Errors

If required storage cannot reliably be addressed or sanitized, the organization should evaluate whether the selected Purge technique remains sufficient.

For high-risk cases, another approved technique or physical destruction may be required.

29

Purge & IT Asset Disposition

Purge can play an important role in the IT Asset Disposition (ITAD) lifecycle.

Typical workflow:

  1. 01Retire Asset
  2. 02Identify Storage
  3. 03Classify Information
  4. 04Select Purge
  5. 05Sanitize
  6. 06Verify
  7. 07Validate
  8. 08Certify
  9. 09Reuse / Refurbish / Resale

This creates a documented path from asset retirement to potential reuse.

30

Enterprise Data Erasure

Enterprise organizations can use technology-specific Purge workflows for:

  • Data-Center Storage
  • Enterprise HDDs
  • Enterprise SSDs
  • NVMe Storage
  • Server Drives
  • Removable Media
  • Retired Laptops
  • Corporate Desktops
  • ITAD Inventory
  • Refurbishment Operations

DSP supports controlled sanitization workflows for supported devices and can maintain individual device-level records.

31

Offline Purge Operations

DSP can support offline data sanitization environments where storage devices must be processed without dependence on public internet access.

Relevant environments can include:

  • Government Facilities
  • Restricted Networks
  • Air-Gapped Environments
  • High-Security Facilities
  • Controlled ITAD Operations
  • Enterprise Data Centers

The sanitization process can be executed within the organization's controlled environment.

32

Multi-Device Purge

Large ITAD and enterprise environments may need to process multiple storage devices.

DSP can support multi-device sanitization workflows with monitoring of:

  • Active Devices
  • Sanitization Progress
  • Completion Status
  • Verification Status
  • Errors
  • Processing Information

Each target device can maintain its own sanitization record and certificate.

33

Audit-Ready Sanitization Certificate

DSP provides an audit-ready sanitization certificate documenting the operation performed through its software.

For NIST SP 800-88 Rev. 2 Purge, the report can include:

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Media type
  • Interface

Sanitization Information

  • Selected method
  • NIST SP 800-88 Rev. 2 Purge
  • Selected technique
  • Start time
  • Completion time
  • Sanitization status

Verification

  • Verification status
  • Verification results
  • Errors
  • Exceptions
  • Relevant process information

Audit Metadata

  • Operator
  • System/workstation
  • Organization/customer
  • Case/ticket reference
  • Date/time
  • Report ID

Report Formats

  • PDF
  • HTML
  • Print-ready documentation
34

What Does The DSP Certificate Mean?

The DSP certificate documents the actual sanitization operation performed by Data Sanitization Pro.

It does not mean:

  • NIST Certified DSP;
  • NIST Approved DSP;
  • NIST Issued The Certificate;
  • IEEE Certified DSP;
  • The Storage Device Received External NIST Certification.

The certificate is DSP's audit documentation of the selected method, execution, device information and verification results.

35

NIST Rev. 2 Purge vs Historical Multi-Pass Wiping

Traditional wiping methodologies often emphasize a fixed number of passes.

Examples include:

  • DoD-Style Multi-Pass Wiping
  • 7-pass Wiping
  • 35-pass Gutmann Wiping
  • Schneier 7-pass Wiping

NIST Rev. 2 Purge uses a different concept.

The key question is not:

36

"How Many Times Was The Disk Overwritten?"

The key question is:

"Does the selected sanitization technique make recovery infeasible using state-of-the-art laboratory techniques for the applicable storage technology?"

This is why modern storage sanitization increasingly relies on technology-specific techniques rather than generic pass counts.

37

NIST Rev. 1 Purge vs Rev. 2 Purge

AreaRev. 1 PurgeRev. 2 Purge
StatusWithdrawnCurrent
ObjectiveLaboratory-recovery resistanceLaboratory-recovery resistance
GuidanceDetailed technique recommendationsProgram and technology-focused
Technique DetailsMore extensive in publicationCurrent standards emphasized
IEEE 2883Supporting referenceStronger role
Cryptographic EraseIncludedExpanded guidance
ValidationPresent but less centralStronger program emphasis
Vendor Implementation TrustLess emphasizedExplicitly addressed

NIST says Rev. 2 shifts from primarily hands-on sanitization decisions toward maintaining an enterprise or agency media sanitization program and updates techniques to current practice.

38

NIST Rev. 2 Purge & IEEE 2883

For modern storage devices, NIST Rev. 2 and IEEE 2883 work at complementary levels.

39

NIST SP 800-88 Rev. 2

→ Defines the sanitization framework and method selection.

IEEE 2883

→ Provides technology-specific storage sanitization guidance.

40

DSP Sanitization Engine

→ Executes the selected supported sanitization method.

This is particularly relevant for modern:

  • HDDs
  • SSDs
  • NVMe
  • Enterprise Storage
  • Flash Media

NIST specifically recommends IEEE 2883, NSA specifications or organizationally approved standards for applicable sanitization techniques.

41

NIST SP 800-88 Rev. 2 Purge — Key Takeaways

NIST SP 800-88 Rev. 2 Purge is a current high-assurance media sanitization method intended to make target-data recovery infeasible using state-of-the-art laboratory techniques while potentially preserving the storage media for reuse.

Key points:

  • Current NIST sanitization method
  • Published September 26, 2025
  • Supersedes Rev. 1
  • Stronger recovery-resistance objective than Clear
  • Can use logical or physical techniques
  • Not a fixed pass-count algorithm
  • Technology-specific technique selection is critical
  • IEEE 2883 is an important source for current logical Purge techniques
  • Cryptographic Erase is a major Purge technique
  • Device-specific sanitization commands may be appropriate
  • HDD, SSD and NVMe require different technical considerations
  • Verification and validation are distinct
  • Device health and errors should be considered
  • Media may potentially remain reusable
  • Destroy remains the alternative when the media must be rendered unusable
  • DSP provides a dedicated Rev. 2 Purge method through the DSP Sanitization Engine
  • DSP provides an audit-ready certificate documenting the actual operation performed
FAQ

NIST Rev. 2 Purge Questions

What Is NIST SP 800-88 Rev. 2 Purge?

It is a current NIST sanitization method that applies physical or logical techniques intended to make recovery of target data infeasible using state-of-the-art laboratory techniques while potentially preserving the storage media for reuse.

Is NIST Purge A 7-pass Or 35-pass Wipe?

No. Purge is defined by its recovery-resistance objective, not by a universal number of overwrite passes.

Is Purge Stronger Than Clear?

Yes, in terms of the intended recovery-resistance objective. Clear addresses simple, non-invasive recovery through the applicable interface, while Purge targets recovery using state-of-the-art laboratory techniques.

Can Purge Preserve The Storage Device?

Yes. NIST defines Purge as potentially preserving the information storage media in a reusable state.

Is Cryptographic Erase A Purge Technique?

Yes. Cryptographic Erase is specifically addressed in Rev. 2 as a Purge technique where its required conditions are satisfied.

Does NIST Rev. 2 Recommend IEEE 2883?

Yes. NIST Rev. 2 directs organizations toward IEEE 2883, NSA specifications or an organizationally approved standard for applicable sanitization techniques.

Is Degaussing Suitable For SSDs?

No. Degaussing is a magnetic-media technique and is not applicable to SSD/NVMe flash storage.

Can Purge Be Used For Cloud Storage?

It depends on the architecture. NIST notes that for some logical/virtual storage environments, Cryptographic Erase may be the only viable Purge option because the underlying physical storage is abstracted from the data owner.

Does DSP Provide NIST Certification?

DSP provides an **audit-ready certificate documenting the sanitization operation performed by DSP**. It is not certification issued by NIST.

Is NIST SP 800-88 Rev. 2 Current?

Yes. The final Rev. 2 was published on **September 26, 2025**, superseding Rev. 1.

Run NIST Rev. 2 Purge With A Certificate For Every Drive

Data Sanitization Pro runs all 25 standards offline and verifies the result.