CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 11 Of 25 · Government And Defence

NSA/CSS Policy Manual 9-12 — Storage Device Sanitization & Secure Data Erasure Software

NSA/CSS Storage Device Sanitization

United States3 PassesVerification Available
Hard drives set aside for NSA/CSS approved destruction after overwriting

At A Glance

Published By
National Security Agency / Central Security Service
Reference
NSA/CSS Policy Manual 9-12, Storage Device Sanitization and Destruction
Region
United States
Passes
3
Verification
Available On Every Run
Relative Run Time
3× a single pass

What The Software Writes

  1. Pass 1 Random data
  2. Pass 2 Random data
  3. Pass 3 Fixed pattern 0x00
  4. Verify Read back of the final pass, available on every run.
  5. Certify Signed certificate with device, method, result and operator

NSA/CSS Policy Manual 9-12 is the NSA/CSS Storage Device Sanitization Manual, providing guidance for the sanitization of information-system storage devices for disposal or recycling.

The current publicly released manual is dated 19 February 2026 and applies to NSA/CSS elements, contractors and personnel. It addresses storage devices containing information ranging from unclassified material through highly sensitive and classified information and provides information concerning NSA/CSS-evaluated sanitization equipment.

For organizations that require an NSA/CSS Policy Manual 9-12-based sanitization workflow, Data Sanitization Pro (DSP) provides a dedicated NSA/CSS Policy Manual 9-12 Sanitization Method through the DSP Sanitization Engine, with device assessment, controlled execution, verification and audit-ready documentation.

Important: NSA/CSS Policy Manual 9-12 should not be represented as an ordinary fixed-pass disk-wiping algorithm. It is a storage-device sanitization and destruction policy/manual whose applicable procedure depends on the storage technology, information sensitivity, disposition requirements and approved sanitization or destruction equipment.

01

What Is NSA/CSS Policy Manual 9-12?

NSA/CSS Policy Manual 9-12 provides guidance for the secure disposition of information-system storage devices.

The manual is associated with:

  • Storage-Device Sanitization
  • Secure Disposal
  • Recycling
  • Classified And Sensitive Information Protection
  • Media-Specific Sanitization
  • Sanitization Equipment
  • Destruction Procedures
  • NSA/CSS Evaluated Products Lists

The NSA's Center for Storage Device Sanitization Research (CSDSR) maintains guidance and evaluated-product information for storage-device sanitization and destruction.

Unlike historical wiping methodologies that are commonly described by a fixed number of software overwrite passes, NSA/CSS Policy Manual 9-12 is broader than a single overwrite sequence.

02

NSA/CSS Policy Manual 9-12 — Scope

The policy framework covers information-system storage devices used by NSA/CSS elements, contractors and personnel.

The publicly released policy documentation identifies storage formats including:

  • Magnetic Storage
  • Solid-State Storage
  • Optical Storage
  • Hard-Copy Media
  • Hybrid Storage Technologies

The associated policy statement describes processes for the sanitization and release of information-system storage devices, while the manual provides the detailed sanitization and disposition guidance.

This technology-specific approach is important because the correct sanitization technique depends on how information is physically and logically stored.

03

NSA/CSS Policy Manual 9-12 Is Not A Generic Multi-Pass Algorithm

A common misconception is to treat NSA/CSS 9-12 as another fixed multi-pass overwrite method such as Gutmann, Schneier, HMG IS5 or historical DoD overwrite profiles.

That is not the correct technical framing.

NSA/CSS Policy Manual 9-12 provides a broader framework around storage-device sanitization and destruction.

The appropriate process can depend on:

  1. 01Information Sensitivity
  2. 02Storage Technology
  3. 03Sanitization / Destruction Requirement
  4. 04Approved Technique Or Equipment
  5. 05Verification / Control
  6. 06Documentation

The NSA's current public guidance also maintains Evaluated Product Lists for equipment meeting NSA specifications, including categories such as HDD destruction devices, magnetic degaussers and solid-state disintegrators.

04

NSA/CSS 9-12 And The DSP Sanitization Engine

DSP provides a dedicated NSA/CSS Policy Manual 9-12 Sanitization Method within the DSP Sanitization Engine.

05

DSP Workflow

IDENTIFY Identify the target storage device.

CLASSIFY Determine storage technology and relevant device characteristics.

ASSESS Assess device accessibility, health, errors and applicable sanitization conditions.

SELECT Select the NSA/CSS Policy Manual 9-12 method.

EXECUTE Execute the applicable DSP sanitization operation.

VERIFY Verify the recorded sanitization result.

VALIDATE Determine whether the result satisfies the applicable organizational requirement.

DOCUMENT Record device, method, operator, system and verification information.

CERTIFY Generate an audit-ready sanitization certificate documenting the operation performed.

06

Storage Technology Matters

NSA/CSS 9-12 is particularly relevant because storage technologies do not all behave the same way.

07

Magnetic HDD

Traditional magnetic hard disk drives can support sanitization techniques based on their magnetic storage architecture and applicable organizational requirements.

DSP can record:

  • Manufacturer
  • Model
  • Serial Number
  • Capacity
  • Interface
  • Firmware
  • SMART Information
  • Health Condition
  • Read/write Errors
  • Bad Sectors
  • Sanitization Status
  • Verification Result
08

SSD And NVMe

Modern SSD and NVMe devices use controller-managed flash architectures.

Relevant characteristics can include:

  • Flash Translation Layer
  • Wear Leveling
  • Spare Blocks
  • Over-Provisioning
  • Garbage Collection
  • Remapped Storage
  • Controller-Level Sanitization Commands

Consequently, a conventional host-level overwrite should not automatically be presented as equivalent to complete physical sanitization of an SSD or NVMe device.

The applicable device-specific sanitization capability and organizational security requirement should be assessed before execution.

09

Optical And Other Media

NSA/CSS 9-12 also covers storage technologies beyond conventional HDDs. The NSA maintains evaluated equipment categories for multiple media types, including optical destruction and solid-state disintegration.

10

Sanitization vs Destruction

One of the most important characteristics of the NSA/CSS approach is the distinction between sanitization and physical destruction.

Sanitization attempts to render stored information inaccessible according to the applicable security requirement while potentially allowing the media to remain usable.

Destruction physically compromises the storage medium so that recovery of the information is prevented according to the applicable destruction requirement.

For certain high-security or technically unsuitable storage devices, destruction may be the required disposition rather than conventional software wiping.

The current NSA Evaluated Products Lists include dedicated categories for:

  • HDD Destruction
  • Magnetic Degaussing
  • Optical Destruction
  • Solid-State Disintegration
  • Paper Destruction
  • Other Media Destruction Equipment
11

NSA/CSS Evaluated Products Lists

NSA/CSS maintains Evaluated Products Lists (EPLs) identifying equipment that meets applicable NSA specifications.

The NSA explains that these lists apply to NSA/CSS elements, contractors and personnel and are used in connection with Policy Manual 9-12 disposal or recycling activities.

This creates an important distinction for DSP:

DSP software support for an NSA/CSS 9-12 workflow does not mean DSP itself is an NSA-evaluated sanitization device or that DSP software is automatically listed on an NSA EPL.

The website should never use phrases such as:

  • “NSA Certified Software”
  • “NSA Approved Software”
  • “NSA Evaluated DSP”
  • “NSA EPL Certified”

unless a separate official evaluation exists.

12

Device Assessment Before Sanitization

Professional sanitization begins with understanding the device being processed.

DSP can collect and document information such as:

Device Identity

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Firmware

Storage Characteristics

  • HDD
  • SSD
  • NVMe
  • SATA
  • SAS
  • USB
  • Removable media
  • Other supported storage

Device Condition

  • SMART health
  • Temperature
  • Power-on hours
  • Read/write errors
  • Reallocated sectors
  • Bad sectors
  • Device accessibility

This information helps establish an auditable relationship between the physical storage device and the sanitization operation.

Bad-Sector And Read-Error Detection

A damaged storage device introduces an important sanitization question:

13

Can The Required Storage Locations Actually Be Addressed, Processed And Verified?

DSP can identify and report:

  • Logical Bad Sectors
  • Physical/read Errors
  • Unreadable Regions
  • Reallocated Sectors
  • Write Failures
  • Verification Failures
  • Device-Health Anomalies

If the required sanitization operation cannot be reliably completed, the result should be evaluated against the organization's applicable security and disposition policy.

This is especially important for:

  • Failing HDDs
  • Damaged SSDs
  • Degraded Flash Media
  • Storage Devices With Inaccessible Areas
  • Devices Exhibiting Repeated Write Failures
14

Verification And Validation

DSP separates verification from validation.

Verification

Verification determines whether the selected sanitization operation completed as recorded.

DSP can document:

  • Operation status
  • Errors
  • Failed areas
  • Verification status
  • Completion information
  • Device condition

Validation

Validation determines whether the resulting condition satisfies the applicable organizational sanitization requirement.

This distinction is particularly important for high-security environments.

A completed software process does not automatically establish that the organization's required security outcome has been achieved in every storage architecture.

15

NSA/CSS 9-12 And Classified Information

The NSA/CSS policy documentation specifically addresses storage devices containing information ranging from UNCLASSIFIED to TOP SECRET, including compartmented, sensitive and limited-distribution information.

This makes the policy fundamentally different from consumer-oriented “delete” or “format” functionality.

A professional sanitization workflow must consider:

  • Information Sensitivity
  • Media Type
  • Sanitization Method
  • Device Condition
  • Verification
  • Release/disposition
  • Documentation
  • Applicable Organizational Controls
16

Secure Disposal And Recycling

NSA/CSS Policy Manual 9-12 specifically provides guidance for sanitization of storage devices intended for disposal or recycling.

This makes the methodology relevant to controlled asset-disposition environments where organizations need documented evidence that storage devices were processed before leaving their controlled environment.

Potential applications include:

  • Government IT Asset Disposal
  • Defense Organizations
  • Secure Data Centers
  • Enterprise ITAD
  • Government Contractors
  • Sensitive-Lab Environments
  • Controlled Equipment Recycling
  • Storage-Device Retirement
17

Audit-Ready NSA/CSS 9-12 Certificate

DSP can generate an audit-ready sanitization certificate documenting the operation performed by the DSP Sanitization Engine.

The certificate can include:

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Media type
  • Interface

Sanitization Information

  • Selected method
  • Sanitization operation
  • Start time
  • Completion time
  • Software version
  • Device status

Verification

  • Verification result
  • Errors
  • Failed areas
  • Device-health observations

Operator & Audit Information

  • Operator
  • System/workstation
  • Date/time
  • Audit metadata
  • Case/reference information where configured

Final Result

Sanitization Completed — Verified — Documented

The certificate documents the operation performed by DSP. It is not an NSA-issued certificate, NSA/CSS approval, NSA EPL listing or certification from the U.S. Government.

18

NSA/CSS 9-12 vs Fixed-Pass Wiping Methods

CharacteristicNSA/CSS Policy Manual 9-12Historical Multi-Pass Methods
Primary ConceptStorage-device sanitization & destructionDefined overwrite sequence
Fixed Pass CountNot the defining characteristicOften yes
Media-Specific Approach✓ YesOften limited
Physical DestructionIncluded in overall disposition frameworkUsually separate
Evaluated EquipmentNSA EPL frameworkGenerally not applicable
HDDApplicableCommon target
SSD/NVMeTechnology-specific considerationConventional overwrite limitations
Classified/sensitive InformationExplicitly addressedVaries
Audit DocumentationImportantDepends on implementation
Current NSA/CSS Framework✓ YesUsually historical methodology
19

NSA/CSS 9-12 vs NIST SP 800-88 Rev. 2

Both frameworks emphasize that storage sanitization must be considered in relation to the storage technology and security requirement, but they originate from different organizations and serve different policy environments.

AreaNSA/CSS Policy Manual 9-12NIST SP 800-88 Rev. 2
OrganizationNSA/CSSNIST
Primary FocusNSA/CSS storage-device sanitization & destructionMedia sanitization program/guidance
EnvironmentNSA/CSS and associated personnel/contractorsBroad organizational use
Storage TechnologyMedia-specificMedia-specific
Physical DestructionCoveredCovered as a sanitization category
Device-Specific MethodsImportantImportant
Evaluated EquipmentNSA EPL frameworkNIST does not create an equivalent NSA EPL
Fixed Multi-Pass AlgorithmNot the defining modelNot the defining model

NIST SP 800-88 Rev. 2 is a separate current media-sanitization publication and should not be represented as identical to NSA/CSS Policy Manual 9-12.

20

Offline Data Sanitization

Sensitive environments may require sanitization without Internet connectivity.

DSP supports controlled offline operation for environments such as:

  • Government
  • Defense
  • Law Enforcement
  • Secure Laboratories
  • Data Centers
  • ITAD Facilities
  • Restricted Enterprise Environments

Device processing and sanitization records can be generated locally without requiring the target device to be connected to the public Internet.

21

Multi-Device Sanitization

Enterprise and ITAD operations may involve multiple storage devices.

DSP can maintain device-specific records so that each processed device has its own:

  1. 01Device Identity
  2. 02Method
  3. 03Sanitization Operation
  4. 04Verification
  5. 05Result
  6. 06Certificate

This allows organizations to maintain individual device traceability rather than relying on a single batch-level record.

22

NSA/CSS Policy Manual 9-12 In DSP

DSP provides a dedicated workflow for organizations that need to document an NSA/CSS Policy Manual 9-12-based sanitization process.

23

DSP Capability

  • Dedicated NSA/CSS 9-12 Sanitization Method
  • Device Identification
  • Storage Technology Assessment
  • SMART/device Health
  • Bad-Sector Detection
  • Sanitization Monitoring
  • Verification
  • Validation Workflow
  • Offline Processing
  • Multi-Device Processing
  • Operator Tracking
  • Audit Metadata
  • PDF/HTML Reports
  • Audit-Ready Sanitization Certificate
24

Important Compliance Distinction

DSP should be positioned accurately:

NSA/CSS Policy Manual 9-12 is an NSA/CSS storage-device sanitization and destruction manual.

DSP provides a dedicated software sanitization method and documents the operation executed by its Sanitization Engine.

DSP certification documents the actual operation performed by DSP.

It does not mean:

  • NSA Certification
  • NSA/CSS Certification
  • NSA EPL Listing
  • U.S. Government Certification
  • Approval To Process Classified Information

unless such authorization or evaluation is separately established.

25

NSA/CSS Policy Manual 9-12 — Modern Storage Sanitization

Modern storage sanitization cannot be reduced to a simple “number of passes.”

A professional workflow considers:

WHAT DATA? WHERE IS IT STORED? WHAT STORAGE TECHNOLOGY IS USED? CAN THE REQUIRED AREAS BE ADDRESSED? WHICH SANITIZATION OR DESTRUCTION TECHNIQUE APPLIES? CAN THE RESULT BE VERIFIED? DOES THE RESULT SATISFY THE ORGANIZATION'S SECURITY REQUIREMENT?

This technology-aware approach is central to professional storage-device sanitization.

26

NSA/CSS Policy Manual 9-12 — Secure Data Sanitization With DSP

NSA/CSS Policy Manual 9-12 provides a structured framework for secure storage-device sanitization and destruction within the NSA/CSS environment.

DSP brings that policy reference into a modern software workflow with:

  1. 01Identify
  2. 02Classify
  3. 03Assess
  4. 04Select
  5. 05Execute
  6. 06Verify
  7. 07Validate
  8. 08Document
  9. 09Certify

The result is a controlled, traceable and documented sanitization operation.

NSA/CSS Policy Manual 9-12 Storage Device Sanitization Executed through the DSP Sanitization Engine Verified and Documented with an Audit-Ready Sanitization Certificate

FAQ

NSA/CSS 9-12 Questions

What Is NSA/CSS Policy Manual 9-12?

It is the NSA/CSS **Storage Device Sanitization Manual**, providing guidance for sanitizing storage devices for disposal or recycling and describing applicable sanitization/destruction procedures and evaluated equipment.

Is NSA/CSS 9-12 A Seven-Pass Wiping Standard?

No. It should not be presented as a universal fixed seven-pass overwrite algorithm. It is a broader storage-device sanitization and destruction framework.

Is NSA/CSS Policy Manual 9-12 Current?

Yes. The NSA publicly released a version dated **19 February 2026**.

Does NSA/CSS 9-12 Cover SSDs?

The policy framework covers storage devices including solid-state media. The appropriate sanitization or destruction approach depends on the specific storage technology and applicable requirements.

Does DSP Provide An NSA-Certified Sanitization Certificate?

No. DSP can generate an **audit-ready certificate documenting the operation performed by DSP**. That certificate is not an NSA/CSS-issued certification.

What Are NSA Evaluated Product Lists?

NSA Evaluated Product Lists identify equipment that meets applicable NSA specifications. Current NSA lists include categories such as HDD destruction devices, magnetic degaussers, optical destruction devices and solid-state disintegrators.

Can NSA/CSS 9-12 Be Used For ITAD?

The policy manual specifically addresses storage-device sanitization for disposal or recycling. Organizations using it should apply the requirements appropriate to their environment, information sensitivity and storage technology.

Is NSA/CSS 9-12 The Same As NIST SP 800-88?

No. They are separate publications from different U.S. organizations. NSA/CSS 9-12 is an NSA/CSS storage-device sanitization and destruction manual, while NIST SP 800-88 is NIST's media-sanitization guidance.

Run NSA/CSS 9-12 With A Certificate For Every Drive

Data Sanitization Pro runs all 25 standards offline and verifies the result.