NIST SP 800-88 Rev. 2 Media Sanitization Explained
What the federal data sanitization standard actually requires, how Clear, Purge, and Destroy differ, and what to ask a vendor before you sign a disposal contract.
- Clear, Purge & Destroy explained in plain language
- Certificate of Destruction with every engagement
- Free pickup for qualifying business volumes
A federal standard, not a marketing term
NIST SP 800-88 Rev. 2 is the National Institute of Standards and Technology's guideline for sanitizing media before reuse, resale, or disposal. It defines three sanitization categories (Clear, Purge, and Destroy), based on the confidentiality of the data and how the media will be handled afterward, and it points to IEEE 2883 for technique-level detail on how each category is implemented.
This page explains what the standard covers, how STS Electronic Recycling applies it, and the questions a compliance officer should ask any vendor claiming to follow it.
Ask about a free pickup
Clear, Purge, and Destroy are not interchangeable
NIST SP 800-88 Rev. 2 sorts sanitization methods into three categories based on how much protection the data needs and what happens to the media next.
Clear
Logical techniques, media stays in use
Purge
Resists lab-level data recovery
Destroy
Media is physically rendered unusable
Clear: Logical Sanitization
Clear uses standard read/write commands to overwrite addressable storage locations, protecting against simple, non-invasive data recovery methods. It's the appropriate category when media will be reused inside an organization's own control and the confidentiality requirement is moderate. Clear does not, by itself, address hidden or reallocated sectors on modern flash storage, which is one reason NIST separates it from Purge.
Standard Overwrite
Read/write commands applied to all user-addressable storage locations
Internal Reuse Fit
Appropriate when media stays inside the same organization's custody
Limitation
Does not reliably reach hidden or reallocated flash sectors
Documentation
Should still be logged with device identifiers for an internal record
Purge: Resists Laboratory Recovery
Purge applies physical or logical techniques, such as cryptographic erase, secure erase commands, or degaussing on magnetic media, designed to resist data recovery even with state-of-the-art laboratory equipment. Purge is the category most often specified before equipment leaves an organization's control for resale or donation, since the media is expected to be reused by someone outside the original chain of custody.
Cryptographic Erase
Sanitizes the media key so encrypted data becomes unrecoverable
Degaussing
Magnetic field erasure for legacy tape and hard disk media, not effective on flash
Fit for Resale
The category typically required before value-recovery or donation
Verification
NIST expects a verification pass confirming the technique was successful
Destroy: Physical Elimination
Destroy renders media unusable for its original purpose and prevents recovery of data even with advanced laboratory techniques, typically through shredding, disintegration, or incineration to a specified particle size. Destroy is the appropriate category for the highest-confidentiality data, for media types where Purge isn't feasible (some solid-state and flash media), or whenever an organization's policy simply calls for it.
Physical Shredding
Reduces media to a specified particle size, standard for hard drives
Solid-State Media
Flash and SSD media often require Destroy since Purge techniques are less reliable
Chain of Custody
Serial-number-specific tracking from intake through final destruction
Certificate of Destruction
Serialized per device, with sanitization method recorded, issued on completion
Adoption is rising, but a lot of organizations are still behind
According to the Sage Sustainable Electronics 2026 IT Asset Management Benchmarking Report (12th edition, via Resource Recycling, January 2026), 52% of surveyed organizations reported following NIST SP 800-88 Rev. 2 in 2025, up from 34% the year before, while roughly 25% still reported using the obsolete DoD 5220.22-M wiping method, a Department of Defense standard that predates SP 800-88 and is no longer the current federal reference.
Part of that adoption pressure is pace: SK tes reported in May 2026 that AI-driven data center refresh cycles now run as short as 10 to 18 months for GPU-dense servers, well below a typical multi-year hardware lifecycle. Faster refresh means more sanitization events per year, which raises the cost of getting Clear, Purge, and Destroy wrong.
Sanitization built around the standard, not around a slogan
STS Electronic Recycling has served businesses across all 50 states since 2010. Every device that passes through our process is matched to a sanitization method and a Certificate of Destruction, so the documentation you get maps directly to what NIST SP 800-88 Rev. 2 describes.
-
Facility-Based Processing
Our 250,000 sq ft R2v3 certified processing facility in Jacksonville, Texas handles sanitization and material recovery at scale, alongside our second R2v3 facility in Houston, Texas.
-
Certifications That Back the Process
STS holds RIOS certification, and ISO 9001, ISO 14001 and ISO 45001 held through the RIOS-integrated management system, alongside an A+ Better Business Bureau rating.
-
Documentation Per Device
Every device processed carries a serialized Certificate of Destruction recording the method used, matched to your internal asset records.
Sanitization applies across every device type
NIST SP 800-88 Rev. 2 applies to any media that stores data. Here's how it maps onto the equipment types STS processes most often.
Computing Equipment
Mobile and Network
The standards your auditor will ask about by name
Certifications and frameworks behind our sanitization and recycling process.
NIST SP 800-88 Rev. 2
Federal data sanitization standard applied through Clear, Purge, or Destroy depending on media type and confidentiality requirements, with verification and Certificate of Destruction on every device.
R2v3 Certified Processing
Our two R2v3 certified processing facilities, in Jacksonville, Texas and Houston, Texas, carry out the data destruction and material recovery covered on this page.
Supports HIPAA Disposal Procedures
Our sanitization and disposal process is designed to support a covered entity's media-disposal and media-reuse procedures under HIPAA: documented final disposition, serial-level destruction records, and chain-of-custody tracking, with BAA coverage available where applicable.
STS also holds RIOS certification, ISO 9001, ISO 14001 and ISO 45001 (held through the RIOS-integrated management system), and an A+ Better Business Bureau rating.
Request Compliance DocumentationWhat compliance officers ask before choosing a vendor
Straight answers on what NIST SP 800-88 Rev. 2 requires and how STS applies it.
What does NIST SP 800-88 Rev. 2 actually require?
It's a guideline, not a law: it defines Clear, Purge, and Destroy as sanitization categories and helps an organization match the right category to its data's confidentiality level and the media's next destination (reuse, resale, or disposal). It points to IEEE 2883 for technique-level detail.
What's the real difference between Clear, Purge, and Destroy?
Clear protects against basic recovery attempts and suits internal reuse. Purge is built to resist laboratory-grade recovery and is typical before resale. Destroy physically renders the media unusable and is required for the highest-confidentiality data or media types where Purge isn't reliable, like some flash storage.
Is my industry required to follow this standard?
NIST SP 800-88 Rev. 2 is a federal guideline, most directly binding on federal agencies and their contractors, but it has become the de facto industry reference that HIPAA, FERPA, GLBA, SOX, and FACTA disposal obligations are commonly measured against.
Does STS follow NIST SP 800-88 Rev. 2?
Yes. Sanitization is performed in accordance with NIST SP 800-88 Rev. 2: our methods, including verified overwrite, degaussing, and physical shredding, are matched to the Clear, Purge, or Destroy category appropriate for the device and data involved, with a serialized Certificate of Destruction for every device.
What documentation proves my organization is in compliance?
A serialized Certificate of Destruction naming the sanitization method used per device, plus chain-of-custody documentation from intake through final processing. Ask any vendor for this before you sign a disposal contract.
Why are so many organizations still behind on this?
Per the Sage Sustainable Electronics 2026 IT Asset Management Benchmarking Report, adoption rose to 52% in 2025, but roughly a quarter of organizations surveyed still reported relying on the outdated DoD 5220.22-M wipe standard, which SP 800-88 has effectively superseded as the current federal reference.
Is pickup free?
For qualifying business volumes, yes. Reach out and our team will confirm whether your equipment volume qualifies before anything is scheduled.
Still Have Questions?
Our team can walk through which sanitization category applies to your equipment and data.
Where Your Equipment Is Processed
STS Electronic Recycling, Inc. is headquartered in Jacksonville, Texas, and has served schools, businesses, healthcare systems, and government agencies across all 50 states since 2010.
Equipment collected nationwide is staged locally and transported to one of our two R2v3 certified processing facilities in Jacksonville, Texas and Houston, Texas, where all data destruction and material recovery takes place.
The Certificate of Destruction, issued on completion, lists each device by serial number with the sanitization method recorded against it.
Ready to Sanitize Your Retired IT Equipment the Right Way?
Free pickup for qualifying business volumes, a Certificate of Destruction for every device, and sanitization matched to NIST SP 800-88 Rev. 2.
