NIST SP 800-88 Rev. 2: What Changed for Business Media Sanitisation?
If your business handles retired laptops, servers, or drives, NIST SP 800-88 Rev. 2 probably already touches your compliance paperwork, even if nobody has said so out loud yet. Published on 26 September 2025, it’s the first update to the guidance since 2014, and it replaces the old revision entirely rather than sitting alongside it. For any UK organisation that works with US contracts, follows ISO/IEC 27040, or wants its data sanitisation programme to hold up under audit, the update is worth understanding properly rather than skimming.
This piece walks through what changed, why NIST made the shift, and what it means for how your business retires storage media going forward.
Why NIST Rewrote the Guidance After a Decade
The original 2014 version of NIST 800-88 was written for a simpler storage landscape. Hard drives were still the default, SSDs were a growing minority, and the guidance leaned heavily on specific overwrite instructions for specific device types.
Ten years on, that approach had aged badly. Flash storage, self-encrypting drives, mobile devices, and virtualised systems all sanitise differently, and a document trying to give device-by-device instructions couldn’t keep pace with how fast storage technology moves. NIST’s own summary of the changes puts it plainly: the guidance has moved away from prescribing hands-on sanitisation steps and toward building a proper sanitisation programme around confidentiality of information, no matter what the media looks like.
The Core Shift: From a Checklist to a Programme
This is the change that matters most. NIST 800-88 Rev 2 changes media sanitisation from a document you consult device by device into a framework your business runs continuously.
Under the old revision, an IT team could reasonably treat sanitisation as a task: identify the drive type, look up the recommended method, overwrite or destroy, done. Rev. 2 asks for something closer to a governance structure. Organisations are expected to run an actual media sanitisation programme, complete with documented policy, defined roles, and processes that tie into wider security frameworks such as SP 800-53 and ISO/IEC 27040.
For a business managing sanitisation in-house, that’s a meaningful jump in scope. It’s no longer enough to have a competent technician wiping drives correctly. Auditors and regulators will increasingly expect a written policy, a named owner, and evidence that the programme gets reviewed rather than left to run on habit.
Clear, Purge, Destroy Remain, but the Instructions Don’t
The three sanitisation categories from the original standard are still there. Clear removes data through standard read/write commands. Purge applies techniques that resist laboratory-level recovery attempts. Destroy physically renders the media unusable, which is where physical destruction for media that cannot be sanitised becomes the only sensible option.
What’s gone is the detailed, method-by-method instruction set that used to sit inside the document. Aside from cryptographic erase, Rev. 2 drops the specific technique tables and instead points organisations toward IEEE 2883 sanitisation standards, NSA specifications, or an internally approved equivalent. In practice, that means businesses can no longer treat 800-88 as a standalone technical manual. It works now as a policy framework that references other technical standards for the actual how-to.
This also raises the bar on vendor trust. Rev. 2 puts new weight on establishing confidence in how a vendor implements its clear and purge techniques, rather than assuming a certificate alone proves the job was done properly. If you’re outsourcing sanitisation, review your current data destruction best practices for UK businesses against that expectation, and check that whoever handles your certified data destruction services can demonstrate their method, not just claim it.
Cryptographic Erase Gets Its Own Rulebook
Cryptographic erase is the one technique that kept its detailed guidance, and it got a considerable expansion rather than a trim. Rev. 2 broadens the range of key types that qualify for cryptographic erase, pulls scattered references into one dedicated section, and introduces guidance on key sanitisation using ISO/IEC 19790 zeroization.
There’s also new clarity on externally managed keys. Businesses using cloud storage or third-party key management services now have a clearer answer on when cryptographic erase through an external key holder is acceptable, rather than being left to interpret the old guidance case by case. Given how much SSD and cloud storage sanitisation already leans on this method, this section is worth a proper read if your business handles either. Our blog on SSD wiping and sanitisation methods covers other options for solid-state drives.
Does This Apply to UK Businesses?
Technically, NIST 800-88 is a US federal standard, not a UK one. But it shapes practice well beyond US government contracts. It’s a common reference point in ISO/IEC 27040 storage security work, it turns up in vendor contracts and audit checklists across sectors, and plenty of UK data destruction providers benchmark against it because clients ask for it by name.
If your business works with US-linked suppliers, holds data for American clients, or wants a sanitisation policy that stands up to scrutiny, aligning with Rev. 2 now saves you from a scramble later. Multi-national contracts in particular tend to specify it directly, and a policy still written around the withdrawn 2014 version won’t satisfy that requirement.
Building a Sanitisation Programme That Meets Rev. 2
A few practical steps make the difference between a paper policy and one that would survive an audit:
- Write down who owns sanitisation decisions across the business, not just who carries them out.
- Map each type of media you retire against Clear, Purge, or Destroy, using IEEE 2883 or an equivalent standard for the technical method.
- Get proof from any vendor of exactly how they sanitise, not a certificate stating that they did.
- Review cryptographic erase procedures if your business relies on encrypted or cloud-based storage.
- Set a review cycle for the policy itself, since Rev. 2 expects programmes to stay current, not sit untouched for another decade.
For media that can’t be reliably sanitised through Clear or Purge, physical destruction remains the fallback, and it’s often the simpler, more defensible choice for highly sensitive drives.
Questions Businesses Are Asking About Rev. 2
What changed in NIST SP 800-88 Rev. 2?
NIST shifted the guidance from step-by-step sanitisation instructions to a programme-based approach. Businesses are now expected to run a documented sanitisation policy aligned with standards like IEEE 2883 or NSA specifications, rather than following device-specific instructions written directly into the document. Cryptographic erase is the exception, gaining expanded and more detailed guidance rather than being handed off to an external standard.
Does NIST 800-88 require multiple overwrite passes?
No. Rev. 2 doesn’t specify overwrite pass counts at all, since the detailed technical methods now sit in IEEE 2883 rather than in the NIST document itself. A single properly verified overwrite pass, following an approved method, satisfies most Clear or Purge requirements. What matters more under the new guidance is choosing a method appropriate to the media type and confirming it worked.
How should a business validate media sanitisation?
Validation now means more than a completed wipe. Businesses should confirm the sanitisation method matches the media type and sensitivity level, obtain documented evidence from any vendor showing how the process was carried out, and keep records as part of an ongoing sanitisation programme rather than treating each job as a one-off. For physically destroyed media, that evidence usually takes the form of a certificate of destruction tied to specific asset records.
Where to Go From Here
NIST SP 800-88 Rev. 2 isn’t a minor edit. It changes what a defensible sanitisation policy looks like, shifts responsibility toward documented programmes rather than one-off tasks, and pushes technical detail out to standards like IEEE 2883. Businesses still working from a 2014-era policy have a genuine gap to close, particularly around vendor verification and cryptographic erase.
If you’re reviewing how your business handles retired hardware, checking your current process against Rev. 2 now is a lot easier than fixing it after an audit flags the problem.