

Details
Date:
July 8, 2026
Author:
Mender Team
Outdated data sanitization practices create more than a technical problem. They can weaken audit readiness, increase exposure after assets leave organizational control, reduce recovery value, and make it harder to prove that sensitive data was handled correctly.
That is why IT leaders should pay attention to NIST 800-88 Rev. 2.
Published in September 2025, the revised guidance replaces the 2014 version of the standard. It shifts the focus from device-specific sanitization instructions toward a broader media sanitization program built around governance, documented decisions, verification, validation, and accountability.
For CIOs, security leaders, compliance teams, and ITAD program owners, data sanitization can no longer be treated as a technical task that happens quietly at the end of the asset lifecycle. It must operate as a documented business process that can withstand scrutiny.
Most executives will never perform a drive overwrite, operate a degausser, or inspect the output of a sanitization tool.
They are still responsible for the risk.
When retired equipment contains customer records, employee data, intellectual property, financial information, or regulated data, the organization needs to know:
The updated standard makes these responsibilities more explicit. It treats media sanitization as an enterprise program rather than a technical checklist.
According to one of the leaders in IT “Our vendor handles data sanitization” is not a complete governance answer. Your organization still needs clear policies, approved methods, defined responsibilities, reliable documentation, and a way to validate the outcome.
The previous version included detailed sanitization techniques for different media types. The revised guidance removes most of those device-specific instructions.
Apart from cryptographic erase, detailed technique and tool guidance has largely been replaced by recommendations to follow IEEE 2883, relevant NSA specifications, or another standard approved by the organization.
The new framework focuses more heavily on the structure of an effective media sanitization program, including:
This is an important change for organizations that outsource ITAD. Your provider may perform the work, but your organization still needs to establish the policy, risk tolerance, approval requirements, and evidence standards that govern the program.
NIST 800-88 Rev. 2 replaces “electronic media” with “information storage media,” expanding the standard to cover physical, virtual, and cloud-based storage.
This includes:
The revised guidance clarifies that multiple overwrite passes are unnecessary when Clear is the appropriate method.
However, overwriting is not suitable for every device. SSDs and flash storage use technologies such as wear leveling, which can prevent standard overwrite commands from reaching every location where data may have been stored.
Organizations should review contracts, RFPs, and internal policies that still require fixed multi-pass wiping. These requirements may add processing time and cost without improving security.
Learn more about the role of data sanitization in protecting retired assets.
Degaussing uses a magnetic field to disrupt data stored on magnetic media such as hard drives and tapes.
Under the updated standard:
ITAD providers should demonstrate that each sanitization technique matches the media type and technology.
A single fleet-wide process is unlikely to work across a mixed inventory of hard drives, SSDs, flash storage, mobile devices, and cloud-based environments.
Cryptographic erase protects data by making the encryption keys required to decrypt it unavailable.
When properly managed, it can sanitize media faster than overwriting while keeping devices reusable for redeployment, resale, donation, or refurbishment.
Physical destruction may remove data risk, but it also eliminates the opportunity to recover value from functioning equipment. A properly governed Purge method can protect sensitive information while keeping the asset eligible for reuse.
Organizations must confirm:
This process may require coordination across ITAD, security, cloud, infrastructure, encryption, and key-management teams.
Steward™ connects sanitization decisions with asset status, documentation, recovery outcomes, and final disposition across the IT asset lifecycle.
The revised guidance treats verification and validation as distinct responsibilities.
Verification confirms whether the sanitization process completed successfully. This may include reviewing tool output, completion status, device health, errors, and anomalies.
Validation determines whether the result is acceptable based on the media type, data sensitivity, method used, observed outcome, and remaining risk.
A tool reporting “complete” does not automatically prove that the result should be approved.
The updated Certificate of Sanitization reflects this distinction by recording:
The updated decision process considers reuse before selecting Clear, Purge, or Destroy.
Organizations should first determine whether the media is intended for:
This sequence matters because sanitization decisions directly affect recovery value.
Destroying every storage device may simplify one part of the process, but it can eliminate resale and redeployment opportunities. Selecting a suitable Clear or Purge method can support both data protection and responsible asset recovery.
Sanitization should be planned as part of the broader IT asset lifecycle, not decided only after equipment reaches a processing facility.
Organizations do not need to rebuild their entire ITAD program overnight. They should, however, review whether their current policies, vendor controls, and documentation reflect the updated standard.
Confirm that the policy:
Look for outdated requirements such as fixed multi-pass overwriting or generalized degaussing across all storage devices.
Contracts should require sanitization methods to match:
Explore mender’s global ITAD services for secure disposition, asset recovery, logistics, reporting, and lifecycle support.
Document which sanitization techniques are approved for:
The matrix should also explain when a method must be escalated from Clear to Purge or Destroy.
Identify all teams and systems involved in generating, storing, backing up, rotating, escrowing, and destroying encryption keys.
A cryptographic erase process should not be approved without understanding whether external copies of the relevant keys remain accessible.
Your ITAD workflow should show:
Each asset record should connect the physical device to its:
Mender’s data sanitization and destruction services provide onsite and offsite options along with documentation that records the sanitization outcome.
Steward™ extends that evidence trail across the asset lifecycle by connecting operational activity, asset status, documentation, and final disposition in one lifecycle view.
The revised guidance should operate alongside the other standards and controls relevant to your ITAD program.
Review how your provider approaches R2v3 certification and its role in ITAD, NAID AAA requirements, downstream accountability, and secure disposition.
These controls become especially important when assets move between locations, subcontractors, processing facilities, and downstream partners.
Use these questions during your next vendor review:
The answers should be documented, repeatable, and supported by evidence. A confident verbal explanation is not a substitute for a defensible process.
Organizations should also evaluate ITAD compliance and vendor liability as part of their third-party risk reviews.
NIST 800-88 Rev. 2 is the September 2025 revision of the National Institute of Standards and Technology’s Guidelines for Media Sanitization.
It helps organizations create a program for securely sanitizing and disposing of information storage media based on data sensitivity, media type, organizational control, and intended disposition.
No. Multiple overwrite passes are not required when Clear is the appropriate sanitization method.
The selected technique must still be suitable for the media type and storage technology.
Clear uses logical techniques to protect data against basic, non-invasive recovery through the standard device interface.
Purge uses physical or logical techniques to make recovery infeasible using advanced laboratory methods while potentially preserving the media for reuse.
Destroy makes data recovery infeasible and leaves the media unable to store data again.
No. Degaussing only works on magnetic media.
It should not be used for non-magnetic storage such as SSDs and flash devices. It is also classified as a Purge technique rather than a Destroy technique.
ITAD vendors need to demonstrate that their sanitization methods match the media type, data sensitivity, intended disposition, and organizational requirements.
They should also provide clear verification, validation, chain-of-custody, and asset-level documentation.
The organization remains responsible for establishing its policies, defining acceptable risk, approving methods, and maintaining oversight of the vendor relationship.
The most important question is not simply whether your provider claims to follow NIST guidance.
It is whether your organization can prove that its policies, sanitization decisions, vendor controls, documentation, and recovery strategy align with the revised standard.
Mender can help evaluate your current ITAD process, identify documentation or governance gaps, and build a more defensible approach to data sanitization, recovery, compliance, and final disposition.
Spot the sneaky risks and learn to outsmart them.
Get a free asset quote today and let's get mending.