NIST SP 800-88 Rev. 2
Defines the media sanitization framework and method selection.
Provides technology-specific storage sanitization methods and requirements.
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
High-Assurance Data Sanitization For Modern Storage

NIST SP 800-88 Rev. 2 — Purge is the current NIST media sanitization method intended to make recovery of target data infeasible using state-of-the-art laboratory techniques, while potentially preserving the information storage media in a reusable condition.
Published on September 26, 2025, NIST SP 800-88 Rev. 2 supersedes Rev. 1 and updates the approach to modern media sanitization. Rev. 2 places greater emphasis on organizational sanitization programs, technology-appropriate techniques, validation and establishing trust in sanitization implementations.
For organizations implementing a NIST-aligned secure data erasure workflow, Data Sanitization Pro (DSP) provides a dedicated NIST SP 800-88 Rev. 2 Purge method through the DSP Sanitization Engine.
Important: NIST SP 800-88 Rev. 2 Purge is an assurance-oriented sanitization method, not a universal fixed 3-pass, 7-pass or 35-pass wiping algorithm. NIST directs organizations toward appropriate technology-specific techniques, including IEEE 2883, NSA specifications or an organizationally approved standard.
NIST SP 800-88 Rev. 2 defines three primary media sanitization methods:
Purge applies physical or logical techniques intended to make recovery of target data infeasible using state-of-the-art laboratory techniques, while preserving the storage media in a potentially reusable state.
This makes Purge a higher-assurance sanitization objective than Clear.
In simple terms:
Purge becomes relevant when an organization needs a stronger level of protection than ordinary logical sanitization can provide.
The decision can depend on:
NIST Rev. 2 states that, when possible, Purge should be used instead of Clear because it provides the stronger recovery-resistance objective while potentially preserving the storage media.
A common misconception is that NIST Purge means a specific number of overwrite passes.
It does not.
NIST SP 800-88 Rev. 2 does not define Purge as:
Instead, Purge is defined by its security objective.
The selected technique must be appropriate for the storage technology and capable of achieving the required sanitization outcome.
NIST Rev. 2 states that logical Purge techniques can vary by information storage media type and directs organizations to IEEE 2883 for acceptable technology-specific techniques.
Current NIST guidance identifies technology-appropriate logical and physical approaches.
Depending on the storage technology, logical Purge techniques can include:
NIST explains that dedicated device sanitization commands can apply storage-specific techniques that operate below the abstraction of ordinary read/write commands.
The appropriate technique depends on the actual device and the security requirement.
IEEE 2883 is particularly important under the current Rev. 2 framework.
NIST states that, except for Cryptographic Erase, detailed sanitization technique and tool descriptions were replaced with recommendations to comply with:
This allows the technology-specific implementation to remain aligned with current storage architectures rather than relying on outdated universal wiping recipes.
Defines the media sanitization framework and method selection.
Provides technology-specific storage sanitization methods and requirements.
Executes the selected supported sanitization method.
Traditional magnetic hard disk drives can support multiple Purge approaches depending on the drive and environment.
Potential approaches include:
NIST Rev. 2 notes that physical Purge techniques historically included degaussing for magnetic tapes, magnetic removable disks and magnetic hard disk drives.
Degaussing is not a general-purpose method for modern solid-state storage.
Modern SSDs require technology-aware sanitization.
An SSD may contain:
A host operating system does not necessarily expose every physical flash location.
Therefore, repeatedly overwriting logical blocks should not automatically be considered equivalent to a high-assurance Purge of the entire physical media.
A technology-specific sanitization mechanism may provide a more appropriate approach.
NVMe SSDs are similarly dependent on controller and flash architecture.
An effective NVMe data erasure strategy should consider:
DSP can identify the target device and its available information before the selected sanitization workflow is executed.
Modern storage devices may provide dedicated commands specifically designed to sanitize storage.
These commands can operate at the device/controller level rather than simply writing data through normal host read/write operations.
This distinction matters because device firmware can have access to storage-management functions that are not exposed through the normal operating-system interface.
NIST Rev. 2 also highlights the importance of trust establishment in vendor implementations of Clear and Purge techniques.
Organizations should therefore evaluate:
Cryptographic Erase (CE) is one of the most important Purge techniques in NIST SP 800-88 Rev. 2.
CE can rapidly sanitize encrypted storage by sanitizing the cryptographic keys needed to access the target data.
NIST Rev. 2 provides expanded guidance around CE, including:
NIST specifically notes that the effectiveness of CE depends on the pedigree of the cryptographic capabilities and satisfaction of required preconditions.
Therefore:
Encrypted storage + key deletion alone does not automatically establish an effective Purge.
The encryption architecture and key-management implementation matter.
NIST Rev. 2 also considers modern logical/virtual storage environments.
For logical or virtual storage such as cloud storage, the underlying physical information storage media may be abstracted from the data owner.
In such environments, direct physical sanitization may not be possible.
NIST notes that Cryptographic Erase may be the only viable Purge option in some logical/virtual storage situations, depending on the architecture.
Organizations should therefore understand the actual sanitization capabilities available before placing highly sensitive information into an environment.
| Characteristic | NIST Rev. 2 Clear | NIST Rev. 2 Purge |
|---|---|---|
| Primary Objective | Protect against simple, non-invasive recovery | Make recovery infeasible using state-of-the-art laboratory techniques |
| Technique | Logical | Logical or physical |
| Media Reuse | Generally intended | Potentially possible |
| Assurance Level | Lower | Higher |
| Technology-Specific Selection | Important | Critical |
| Fixed Pass Count | No | No |
| Typical Use | Standard reuse scenarios | Higher-sensitivity information and stronger recovery-resistance requirements |
NIST states that Purge should be preferred over Clear when possible, while the appropriate method remains dependent on the organization's sanitization requirements and storage environment.
Purge and Destroy have different outcomes.
Attempts to make recovery infeasible while potentially preserving the media for reuse.
Makes recovery infeasible while rendering the information storage media unusable.
Examples of destruction can include:
The choice depends on whether the storage asset needs to remain usable after sanitization.
One of the major advantages of an effective Purge operation is the potential to retain the physical storage device.
This makes it relevant to:
However, reuse should only occur when the selected technique provides the required security outcome.
Data Sanitization Pro provides a dedicated NIST SP 800-88 Rev. 2 Purge method through the DSP Sanitization Engine.
This separates the Purge methodology from generic disk-wiping profiles.
DSP can support sanitization workflows across supported storage technologies including:
The selected technique must remain appropriate to the actual storage architecture and available sanitization capabilities.
Verification determines whether the sanitization operation produced the expected technical result.
DSP can record relevant information such as:
A completed command or process should not automatically be treated as sufficient evidence when the device reports an error or unexpected condition.
NIST Rev. 2 distinguishes the technical verification of sanitization from the broader validation of whether the result is acceptable.
A simplified workflow is:
If the result is rejected, the organization can determine whether to:
Storage health can affect sanitization reliability.
DSP can provide relevant device information such as:
This information can be retained as part of the sanitization record.
Bad sectors and device errors require particular attention during secure data erasure.
Potential conditions include:
If required storage cannot reliably be addressed or sanitized, the organization should evaluate whether the selected Purge technique remains sufficient.
For high-risk cases, another approved technique or physical destruction may be required.
Purge can play an important role in the IT Asset Disposition (ITAD) lifecycle.
Typical workflow:
This creates a documented path from asset retirement to potential reuse.
Enterprise organizations can use technology-specific Purge workflows for:
DSP supports controlled sanitization workflows for supported devices and can maintain individual device-level records.
DSP can support offline data sanitization environments where storage devices must be processed without dependence on public internet access.
Relevant environments can include:
The sanitization process can be executed within the organization's controlled environment.
Large ITAD and enterprise environments may need to process multiple storage devices.
DSP can support multi-device sanitization workflows with monitoring of:
Each target device can maintain its own sanitization record and certificate.
DSP provides an audit-ready sanitization certificate documenting the operation performed through its software.
For NIST SP 800-88 Rev. 2 Purge, the report can include:
The DSP certificate documents the actual sanitization operation performed by Data Sanitization Pro.
It does not mean:
The certificate is DSP's audit documentation of the selected method, execution, device information and verification results.
Traditional wiping methodologies often emphasize a fixed number of passes.
Examples include:
NIST Rev. 2 Purge uses a different concept.
The key question is not:
The key question is:
"Does the selected sanitization technique make recovery infeasible using state-of-the-art laboratory techniques for the applicable storage technology?"
This is why modern storage sanitization increasingly relies on technology-specific techniques rather than generic pass counts.
| Area | Rev. 1 Purge | Rev. 2 Purge |
|---|---|---|
| Status | Withdrawn | Current |
| Objective | Laboratory-recovery resistance | Laboratory-recovery resistance |
| Guidance | Detailed technique recommendations | Program and technology-focused |
| Technique Details | More extensive in publication | Current standards emphasized |
| IEEE 2883 | Supporting reference | Stronger role |
| Cryptographic Erase | Included | Expanded guidance |
| Validation | Present but less central | Stronger program emphasis |
| Vendor Implementation Trust | Less emphasized | Explicitly addressed |
NIST says Rev. 2 shifts from primarily hands-on sanitization decisions toward maintaining an enterprise or agency media sanitization program and updates techniques to current practice.
For modern storage devices, NIST Rev. 2 and IEEE 2883 work at complementary levels.
→ Defines the sanitization framework and method selection.
→ Provides technology-specific storage sanitization guidance.
→ Executes the selected supported sanitization method.
This is particularly relevant for modern:
NIST specifically recommends IEEE 2883, NSA specifications or organizationally approved standards for applicable sanitization techniques.
NIST SP 800-88 Rev. 2 Purge is a current high-assurance media sanitization method intended to make target-data recovery infeasible using state-of-the-art laboratory techniques while potentially preserving the storage media for reuse.
Key points:
It is a current NIST sanitization method that applies physical or logical techniques intended to make recovery of target data infeasible using state-of-the-art laboratory techniques while potentially preserving the storage media for reuse.
No. Purge is defined by its recovery-resistance objective, not by a universal number of overwrite passes.
Yes, in terms of the intended recovery-resistance objective. Clear addresses simple, non-invasive recovery through the applicable interface, while Purge targets recovery using state-of-the-art laboratory techniques.
Yes. NIST defines Purge as potentially preserving the information storage media in a reusable state.
Yes. Cryptographic Erase is specifically addressed in Rev. 2 as a Purge technique where its required conditions are satisfied.
Yes. NIST Rev. 2 directs organizations toward IEEE 2883, NSA specifications or an organizationally approved standard for applicable sanitization techniques.
No. Degaussing is a magnetic-media technique and is not applicable to SSD/NVMe flash storage.
It depends on the architecture. NIST notes that for some logical/virtual storage environments, Cryptographic Erase may be the only viable Purge option because the underlying physical storage is abstracted from the data owner.
DSP provides an **audit-ready certificate documenting the sanitization operation performed by DSP**. It is not certification issued by NIST.
Yes. The final Rev. 2 was published on **September 26, 2025**, superseding Rev. 1.
Data Sanitization Pro runs all 25 standards offline and verifies the result.