Waste Carrier CBDU607333 ICO ZC018901 T11 EXP/KP3143JC Cyber Essentials Certified
Handbook contents

Home/Handbook/Standards

Chapter 02 · 9 min read

NIST 800-88, explained properly

Everyone in this industry cites it. Far fewer have read it. The useful part is short: three categories, chosen by media type and data sensitivity — not by how many passes sound impressive on a quote.

02.1What it is

NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization, is a US federal publication that has become the de facto international reference for wiping storage media. It is a guideline, not a law, and nothing in UK legislation names it. Its authority comes from being the thing auditors recognise.

02.2The three categories

Clear

Protects against recovery using standard system tools — the operating system, a recovery utility, anything that talks to the device through its normal interface. In practice this is a logical overwrite of all user-addressable space.

Appropriate when the media is staying within your organisation, or the data is genuinely low sensitivity. The media remains fully usable afterwards.

Purge

Protects against recovery using laboratory techniques — someone with the equipment and motivation to read the media directly rather than through its interface. On modern devices this means using the drive’s own firmware: ATA or SCSI SANITIZE, NVMe Format with secure erase, or a cryptographic erase on a self-encrypting drive.

This is the right level for anything confidential or personal on equipment leaving your control, and it is what we apply as standard. The media stays reusable, which is what makes resale possible.

Destroy

Physical destruction — shredding, disintegration, punching, incineration. The media cannot be reused and, done properly, no known technique recovers the data.

Required by some policies regardless of media type, and the correct answer for anything that fails sanitisation.

02.3The bit people get wrong: technique follows media

The central principle of the document is that the technique must suit the media. The same category means different commands on different hardware:

MediaClearPurge
Magnetic HDDSingle overwrite passOverwrite, or ATA/SCSI SANITIZE
SATA SSDOverwrite (limited value)ATA SANITIZE / SECURITY ERASE
SAS SSDOverwrite (limited value)SCSI SANITIZE, block erase
NVMe SSDOverwrite (limited value)NVMe Format, secure or crypto erase
Self-encryptingCryptographic erase
Magnetic tapeOverwriteDegauss, or destroy

Note the pattern: overwriting is listed under Clear for flash but is of limited value there, because wear levelling means the controller decides which physical cells actually receive the writes.

02.4The three-pass myth

The idea that data needs three, seven or thirty-five overwrite passes comes from DoD 5220.22-M and from Gutmann’s 1996 paper, both aimed at magnetic media with densities orders of magnitude lower than anything made this century.

NIST 800-88 is explicit that a single overwrite pass is sufficient for modern hard disks. Multi-pass overwriting on an SSD is actively counterproductive — it consumes write endurance, takes hours, and provides no additional assurance.

If a supplier is selling you a seven-pass wipe as a premium option, they are charging you for wear.

02.5Verification is not optional

The document is clear that sanitisation must be verified, and that the verification should be documented. A sanitise command can fail silently — a frozen security state, a firmware quirk, a failing device, a locked drive.

In practice that means confirming the drive’s own reported completion status and sampling a read-back, then recording both. Anything that fails should escalate to destruction, not be retried until it passes.

02.6What a compliant certificate should contain

If a certificate is missing these, it is not evidence of much:

  • Make, model and serial number of the device
  • The sanitisation category applied — Clear, Purge or Destroy
  • The specific technique or command, not just “wiped”
  • The tool used, and ideally its version
  • The verification result
  • Date, time and operator

You can see all of that on our sample certificate of erasure — it names the command issued, down to the service action.

02.7Where UK law sits

UK GDPR and the Data Protection Act 2018 require appropriate technical and organisational measures, which includes secure disposal, and require you to demonstrate compliance. Neither names a standard. NIST 800-88 is how the industry demonstrates the measure was appropriate.

For UK public sector work you may also see HMG Infosec Standard 5 (IS5) referenced, and for physical destruction BS EN 15713. Our certificates cite these alongside NIST where relevant.

Kamil Anwar

About the author

Kamil Anwar — Founder, ServerGear. Kamil runs ServerGear, the data centre asset recovery arm of PYCO RENEW LTD. He spends most of his week looking at asset lists, arguing about what a four-year-old server is really worth, and making sure the drives that come with it are dealt with properly.

Ask him about your decommission

Ready when you are

Tell us what you’re decommissioning

Send an asset list or a few photos. You’ll have a written valuation within one working day — no obligation, no charge.

WhatsApp us