P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Free tool

Clear, purge or destroy? A NIST SP 800-88r2 selector

Work out the right sanitisation method for any media under the 2025 revision, with the reasoning, the UK position, and a certificate you can export.

Almost everything written about NIST SP 800-88 describes a document that no longer exists. Revision 2 landed in September 2025 and deleted the per-media-type technique tables everyone quotes, moved technique selection out to IEEE 2883, demoted degaussing, and turned the guidance into a programme standard rather than a procedure. This walks the decision Revision 2 actually makes, tells you where it stops and who owns the rest, and sets out what changed so you can find out whether your disposal policy is citing a withdrawn appendix.

Nothing leaves your browser: A record of which assets held your most sensitive data, and how thoroughly it was destroyed, is a map of where you are weakest. It stays in this browser. There is no submission and no account, the page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon, and you export the certificate yourself. A policy inside the page cannot stop you copying the result somewhere else, so what you do with it afterwards is yours to protect. Refreshing the page loses your work.

Last reviewed:
Open data: download the full dataset as JSON

1. Describe the media

What is it?

How sensitive was the data it held?

Where is it going?

2. The method

Answer the first three questions and the method appears here, with the reasoning that produced it.

What changed in Revision 2, and what is still being reported wrongly

Revision 1 stood for eleven years and is the version the internet learned. It was withdrawn on , the day Revision 2 replaced it. Several of the changes below reverse advice that is still being published as current, which is worth checking against your own disposal policy and your supplier’s statement of method.

Per-media-type technique tables

Still widely misreported

Revision 1, withdrawn

An appendix set out, media type by media type, which technique satisfied each method: overwrite this, block erase that, degauss the other.

Revision 2, current

Deleted. Apart from cryptographic erase, technique and tool detail is explicitly out of scope, replaced by a direction to comply with IEEE 2883, an NSA specification, or a standard your own policy names as acceptable.

So what: If your disposal policy cites 800-88 for a technique, it now cites a document that no longer contains one. The policy needs to name the standard that does, and IEEE 2883 has to be bought, which is a procurement action rather than a drafting one.

What the document is for

Revision 1, withdrawn

A guide to making hands-on sanitisation decisions.

Revision 2, current

A guide to establishing an organisational media sanitisation programme: policy, scope, roles, verification, validation and records.

So what: The assessable unit moved. An auditor following Revision 2 asks to see a policy that maps your data classifications to minimum acceptable methods, and evidence the programme runs, rather than watching someone wipe a laptop.

What counts as media

Revision 1, withdrawn

Hard copy and electronic, or soft copy, media.

Revision 2, current

Hard copy and information storage media, or ISM, a term chosen to cover logical storage such as cloud, and emerging physical media including DNA, ceramic and glass.

So what: Cloud storage is now inside the frame, and it is the one case where destroy is unavailable: you cannot shred a bucket. Cryptographic erase, with keys you control, is the only method that reaches it.

Degaussing

Still widely misreported

Revision 1, withdrawn

Treated as a destruction technique for magnetic media, and widely written up as such.

Revision 2, current

Not considered an approved destroy technique at the time of writing. It sits with the physical purge techniques, and Revision 2 notes that many existing degaussers lack the force for modern magnetic media and can damage a drive's servo tracks while failing to sanitise the target data.

So what: Worst of both outcomes: an unusable drive and unsanitised data, recorded as destroyed. If you own a degausser, its rated field strength needs checking against the coercivity of the media you actually hold.

Shredding

Still widely misreported

Revision 1, withdrawn

A straightforward destruction technique, and the default mental image of secure disposal.

Revision 2, current

To be avoided for information storage media except at the lowest security categories. Rising areal density means a fragment can still hold a great deal.

So what: This inverts what most disposal contracts specify. If you are buying shredding as your highest assurance option for high-sensitivity data, Revision 2 disagrees, and a purge before the device leaves the building is the stronger control.

Checking the work

Revision 1, withdrawn

Verification, treated as one activity.

Revision 2, current

Verification and validation, separated. Verification asks whether the operation completed. Validation asks whether the outcome is acceptable for data of that sensitivity, and is where residual risk is formally accepted.

So what: A tool reporting success is verification. Nobody has done validation until someone with authority has looked at what the technique could not reach and accepted it in writing.

Cryptographic erase

Revision 1, withdrawn

Present, with less structure around when it can be relied on.

Revision 2, current

Given its own section with explicit conditions: the strength of the cryptography, whether CE applies to that device at all, sanitisation of the keys themselves, and the quality of the implementation. Key sanitisation is pointed at ISO/IEC 19790 zeroization.

So what: Cryptographic erase is fast and high assurance when the conditions hold and worthless when they do not. Self-encrypting drive claims are a vendor assurance question, which is why Revision 2 asks what guarantees the media vendor provides.

The three methods

Clear

Overwrite or factory-reset through the same interface a user has, so ordinary recovery tools find nothing.

When it is right: Reuse inside your own organisation, where the media never leaves your control and the data was not sensitive enough to justify a method that might shorten the device's life. It is the weakest of the three and Revision 2 is explicit that purge should be preferred wherever it is available.

Where it goes wrong: Trusting it on flash. A clear technique built on ordinary writes cannot reach a solid-state drive's overprovisioned area, so a substantial quantity of user data can survive untouched while the tool reports success. The report is accurate about what it did and silent about what it could not reach.

Purge

Use the device's own sanitise commands, or a physical technique, so that recovery is infeasible even in a laboratory.

When it is right: Most of the time. Revision 2 says plainly that where a purge technique exists it should be used instead of clear, and purge is frequently more appropriate than destroy once you account for lease obligations, the environmental cost, the residual value of the hardware and the practical difficulty of destroying some media properly.

Where it goes wrong: Assuming every device has one. Not all media offer a reliable purge technique, and the guidance says so. Where none exists you are choosing between accepting the residual risk of clear and destroying the device, and that is a decision to record rather than to make silently.

Destroy

Render the media unusable, and the data unrecoverable, by physical means.

When it is right: High-sensitivity data, media with no trustworthy purge technique, or a device that has already failed and cannot accept commands. A drive that will not spin up cannot be purged, and that is the honest reason most destruction happens.

Where it goes wrong: Treating shredding as the strongest option available. Revision 2 says pulverise and shred techniques for information storage media should be avoided for anything but the lowest security categories of data, because as areal density rises the fragments get large relative to the data they hold. Cutting or drilling a device may damage it only partly and leave portions readable in a laboratory.

Reading this in the UK

800-88 is a US federal document and the NCSC’s guidance is not a translation of it. Policies that cite both without saying which governs create an argument for later, usually during an incident.

The NCSC does not say clear, purge or destroy

It splits sanitisation into non-destructive, meaning the device can be reused, and destructive. There is no clean mapping onto NIST's three methods, so a policy citing both needs to state which vocabulary governs rather than assuming a reader will translate.

The NCSC treats all storage media the same way

Where NIST's structure invites a per-media-type answer, the NCSC guidance explicitly declines to differentiate, and applies one approach across drives, flash, tape and optical. That is a deliberate simplification for an OFFICIAL threat model, not an oversight.

It is scoped to OFFICIAL

The guidance is proportionate to the threat model for OFFICIAL data and states that it will not protect against a skilled, well-funded laboratory. Media that has held data classified SECRET or above falls under separate guidance entirely.

Six millimetres

Where destruction is required, the NCSC gives a particle size of 6 mm or less, and asks that the size be verified rather than assumed from the shredder's rating. NIST gives no equivalent figure, so a UK disposal specification is usually better written against this one.

Factory reset on encrypted devices

For encrypted devices the NCSC points at the manufacturer's factory reset, on the basis that it discards the encryption keys and leaves the data unreadable. That is cryptographic erase under another name, and it inherits the same dependency on the vendor having handled the keys properly.

Use the data

The methods, the revision comparison, the media classes, the certificate fields and the UK notes are published as JSON under CC BY 4.0, currently version 2026-08-03. The method definitions and certificate fields derive from NIST SP 800-88r2, Guidelines for Media Sanitization, a US Government work not subject to copyright. No IEEE 2883 content is included, here or anywhere on this page: that standard is copyrighted and you have to buy it.

What this cannot decide for you

The method, and only the method. It cannot tell you which command to issue, because Revision 2 does not either, and anything that claims to be giving you the 800-88 technique for a particular drive is quoting an appendix that was withdrawn. For the technique you need IEEE 2883, an NSA specification, or a standard your own policy names as acceptable, and naming one is a decision your policy has to make explicitly rather than inherit.

It also cannot validate anything. A tool reporting success tells you the operation completed. Whether the result is good enough for data of that sensitivity is a judgement someone with authority has to make and record, and Revision 2 separated those two words deliberately.

Common questions

Is NIST SP 800-88 Rev. 2 final, or still a draft?

Final. It was published on 26 September 2025, and Revision 1 was withdrawn the same day. The initial public draft had appeared on 21 July 2025 with comments closing on 29 August, and a good deal of commentary written during that window described it as forthcoming and was never updated.

What is the difference between clear, purge and destroy?

Clear applies logical techniques through the interface a user has, and resists ordinary recovery tools while leaving the device fully usable. Purge resists recovery even with state-of-the-art laboratory techniques, and still leaves the media in a potentially reusable state. Destroy renders the media itself unusable. Revision 2 is explicit that where a purge technique exists it should be preferred to clear, and that purge is often more appropriate than destroy once lease obligations, environmental cost and residual hardware value are counted.

Does Rev. 2 still tell me how to sanitise a specific drive?

No, and this is the change most often missed. Apart from cryptographic erase, technology-specific techniques are out of scope, and the document directs you to IEEE 2883, an NSA specification, or a standard your own policy names as acceptable. If your disposal policy cites 800-88 for a technique, it now cites a document that does not contain one, and IEEE 2883 has to be purchased, which makes this a procurement question rather than a drafting one.

Is degaussing still an approved way to destroy a drive?

Not as a destroy technique. Revision 2 places it among the physical purge techniques and notes that it is not considered an approved destroy technique at the time of writing. It also warns that many existing degaussers lack the force for modern magnetic media, and that degaussing can damage a drive's servo tracks, leaving it unusable while failing to sanitise the target data. That is the worst available outcome, recorded as a success.

Is shredding a hard drive enough?

Revision 2 says pulverise and shred techniques should be avoided for information storage media at anything but the lowest security categories, because rising areal density means a surviving fragment holds a great deal. This inverts what many disposal contracts specify. A purge performed while the device still responds, before it ever leaves the building, is the stronger control, and destruction then becomes a second layer rather than the only one.

How does the UK position differ?

The NCSC does not use NIST's vocabulary at all: it splits sanitisation into non-destructive and destructive, and deliberately declines to differentiate by media type. It is scoped to the threat model for OFFICIAL data and states plainly that it will not protect against a skilled, well-funded laboratory; SECRET and above falls under separate guidance. It also gives a figure NIST does not, a particle size of 6 mm or less where destruction is required, which usually makes it the better instrument to write a UK disposal specification against.

Does this reproduce IEEE 2883?

No, and it never will. IEEE 2883 is a copyrighted standard and you have to buy it. Nothing from it appears here. NIST publications are US Government works not subject to copyright, so the method definitions and the certificate field list are used freely, and every explanatory note, the revision comparison and the decision logic are original.

When you need more than a tool

ISO/IEC 27001 Implementation and Remediation

Full-cycle ISO/IEC 27001 consultancy: gap analysis, ISMS implementation, remediation of failed audits, and internal audit cycles, led by a Lead Auditor with six programmes taken through certification.

Plan your certification

Share this tool

Free, no sign-up, and nothing you type leaves your browser.

Related analysis

← All free tools