If your data destruction policy, your ITAD contract or your supplier's website still says "NIST 800-88", it is almost certainly pointing at a document that no longer exists. NIST 800-88 Rev 2 became the final version on 26 September 2025, and Revision 1 was formally withdrawn on the same day. In July 2026 NIST published an official FAQ that spells out the consequences, and several of them contradict how secure data destruction is routinely sold in the UK.
Key facts: NIST 800-88 Rev 2
- NIST 800-88 Rev 2 was published as final on 26 September 2025. Revision 1, dated December 2014, was withdrawn and superseded on that date.
- NIST published a supplementary FAQ for NIST 800-88 Rev 2 on 16 July 2026, covering thirteen questions across four focus areas.
- Revision 2 keeps the three sanitisation methods - clear, purge and destroy - but drops Revision 1's per-media technique tables.
- Multi-pass overwriting is explicitly declared unnecessary. The old seven-pass habit is no longer supported.
- Degaussing is reclassified as a purge technique for legacy magnetic media, not a destroy method.
- The new term "information storage media" (ISM) replaces "electronic (soft copy) media" to cover cloud, container and object storage.
- Revision 2 introduces sanitisation assurance as a two-stage process: verification, then validation.
What is NIST 800-88 Rev 2?
NIST 800-88 Rev 2 is the current edition of NIST Special Publication 800-88, Guidelines for Media Sanitization. It is US federal guidance, not UK law, but it is the standard most commonly named in UK data destruction certificates, tender documents and ITAD service descriptions - which is exactly why a change of edition matters commercially.
Revision 1 held that position for almost eleven years. It was written around magnetic hard drives and worked as a lookup table: find your media type, read off the approved technique. Storage moved on. Flash translation layers, over-provisioning, self-encrypting drives, cloud object storage and containerised volumes all broke the assumption that you can address every block you need to erase.
Revision 2 responds by changing what the document is for. Instead of prescribing techniques media by media, it tells organisations how to build and run a sanitisation programme, and defers the technique detail to evolving industry standards such as IEEE 2883, or to NSA Policy Manual 9-22 for highly sensitive government material.
What changed between Revision 1 and Revision 2?
The centre of gravity moved from technique to programme. NIST's own FAQ states that Revision 1 focused on hands-on, media-specific techniques delivered through tables, while Revision 2 focuses on maintaining confidentiality through an enterprise sanitisation programme, assurance, modern storage architecture and a decision flow.
| Area | Revision 1 (2014, withdrawn) | Revision 2 (2025, current) |
|---|---|---|
| Core purpose | Per-media technique tables | Enterprise sanitisation programme and decision flow |
| Terminology | Electronic (soft copy) media | Information storage media (ISM), covering virtual and logical storage |
| Technique detail | Specified in the document | Deferred to IEEE 2883 and NSA Policy Manual 9-22 |
| Overwriting | Multi-pass patterns widely inferred | Multi-pass declared unnecessary; single pass typical |
| Degaussing | Treated as a destructive option | A purge technique for legacy magnetic media only |
| Evidence | Certificate of sanitisation recommended | Verification and validation both required by policy |
None of this makes wiping weaker. It makes the paperwork and the policy carry more of the weight, because the document no longer hands you a technique to point at.
Does NIST 800-88 Rev 2 still require multi-pass overwriting?
No. NIST's FAQ answers this directly: multi-pass overwriting is unnecessary. For modern storage, legacy multi-pass practices achieve very little additional confidentiality protection and can significantly degrade the lifespan of flash-based media. Under the clear method, a single pass of standard read and write commands over user-addressable space is the norm.
That kills a claim still visible on UK supplier pages: the "DoD seven-pass wipe" as a premium option. It was never a NIST requirement, it does not improve the security outcome on modern drives, and on SSDs it burns write endurance for nothing. If a quotation charges more for extra passes, the extra passes are the product, not the protection.
The point that does still stand is verification. A single pass that completes and is checked is worth more than seven passes nobody looked at. Our comparison of data destruction versus data erasure sets out where each method belongs.
Is degaussing still a destroy method under NIST 800-88 Rev 2?
No. NIST now classifies degaussing as a physical purge technique for legacy magnetic media, and says it does not constitute a true destroy method. Degaussing a modern high-coercivity drive often disrupts the internal servo tracks and leaves the drive permanently inoperable, but that is a reliability outcome, not proof of sanitisation.
The failure modes NIST names are the ones that matter in practice. A degausser whose field strength is mismatched to the media's coercivity may not sanitise the data at all, and degaussing does nothing whatsoever to flash or hybrid components. Applied to an SSD, it is theatre. This is why degaussing plays only a minimal role in our own process, and why solid state media has to be handled on its own terms.
What does NIST 800-88 Rev 2 say about shredding?
It says less flattering things than the industry does. Section 3.1.3 of Revision 2 states that pulverise and shred techniques "should be avoided for anything but the lowest security categories of data". NIST's FAQ explains the reasoning: modern storage writes at densities, and with depth, that a fragment can still hold recoverable data at conventional particle sizes.
The FAQ goes further and cites IEEE 2883, which deprecates shredding and pulverising as approved destruction methods for all modern HDDs and SSDs, and lists melting as a destruct method instead. ISO/IEC 27040:2024 similarly recommends melting where high-sensitivity media leaves organisational control.
Two cautions before anyone rewrites their policy on the strength of that. First, this is US guidance describing US federal security categories; UK organisations handling government-classified material work to HMG Infosec Standard 5, which sets its own requirements for physical destruction and remains the benchmark we work to. Second, the practical consequence for most UK businesses is not "find a smelter". It is that physical destruction is no longer an automatic upgrade over verified erasure - it is a policy choice that has to be justified by data classification, and evidenced either way. Our guide to hard drive shredding versus wiping covers that trade-off for commercial data.
What is sanitisation assurance under NIST 800-88 Rev 2?
Sanitisation assurance is Revision 2's two-stage evidence requirement. Verification is the operational check that a technique completed successfully without errors or anomalies. Validation is the higher-level review, in which the organisation weighs that verification data against the sensitivity of the data and formally accepts any residual risk.
Most UK organisations do the first and skip the second. A wipe log lands in a folder, nobody with authority reviews it against the classification of what was on the drive, and there is no record of anyone accepting the residual risk. Under Revision 2, that is an incomplete process regardless of how good the wiping tool was.
NIST also lists what a formal sanitisation policy must contain: the alignment of your data classification scheme with acceptable methods, documentation and evidence requirements including certificates of sanitisation, defined roles and mandatory training, tool configuration with equipment calibration and testing, and specific validation and verification protocols. That is a policy document, not a supplier's certificate. What the certificate should contain is covered in our guide to data destruction certificates.
Book a Free Collection Call 0151 355 5482
How does NIST 800-88 Rev 2 handle cloud and virtual storage?
By admitting that you cannot reach the hardware. NIST's answer is that where physical media is abstracted away in a virtual or cloud environment, traditional physical destruction and overwrite commands are impossible for the data owner to execute, and cryptographic erase is often the only viable purge method available.
That shifts the burden into your contracts. NIST tells organisations to review cloud service agreements to confirm that keys are securely managed and that zeroisation can be traceably validated. Cryptographic erase only counts as a purge under Revision 2 if the cryptographic module is FIPS 140 validated, no sensitive data was ever written in plaintext before encryption was established, the algorithm carries at least 128-bit security strength with matching entropy, and the keys themselves are permanently zeroised.
The "no prior plaintext" condition is the one that catches people. A drive that ran unencrypted for six months before full-disk encryption was switched on cannot be safely purged by destroying the key, because the earlier data was never inside the encrypted boundary.
What should UK businesses update now?
Start with the references, because stale citations are the easiest thing for an auditor to find and the cheapest thing to fix. Then work outwards to the policy content that Revision 2 actually changed.
- Replace every reference to "NIST 800-88 Rev 1" in policies, contracts and certificate templates with Revision 2, and check whether your supplier has done the same.
- Remove multi-pass and "DoD seven-pass" language, and any pricing built on it.
- Stop describing degaussing as destruction. Reclassify it as a purge technique for legacy magnetic media.
- Map your data classification scheme explicitly to clear, purge and destroy, so each retirement decision follows a documented rule.
- Add a validation step with a named owner, separate from the technician-level verification you already have.
- Check cryptographic erase preconditions before relying on it, especially the requirement that no plaintext ever preceded encryption.
- Extend the policy to cloud and virtual storage, and confirm what your cloud contracts actually promise about key zeroisation.
NCSC guidance sets the UK-specific expectations that sit alongside NIST, and the two are compatible: both push you towards documented method selection and retained evidence rather than a single named technique.
What should you ask your ITAD supplier?
Five questions separate a supplier who has read NIST 800-88 Rev 2 from one still working to a 2014 document. None of them requires technical knowledge to ask, and the answers are checkable against the certificate you are handed at the end.
- Which edition of NIST 800-88 do your certificates cite, and when did you update the template?
- For each device, which method was applied - clear, purge or destroy - and what decided that?
- What verification output can you give me per drive, and what does it show when a drive fails?
- How are drives that fail verification handled, and is that recorded against the same serial number?
- Do the certificate and the asset report reconcile line by line against the serial numbers on my register?
The last one is the most revealing. Plenty of certificates are issued per collection rather than per device, which tells you a lorry arrived somewhere but says nothing about what happened to any individual drive. Under a Revision 2 policy, per-device evidence is what you validate against, so a batch certificate leaves you with nothing to review.
How Innovent handles sanitisation under NIST 800-88 Rev 2
Our default is verified erasure, because a drive that passes verification can be reused, and reuse is where the value and the carbon saving both live. Drives are wiped to NIST 800-88 and verified; drives that fail verification, or that are physically damaged, are destroyed at our facility by video-recorded shredding to HMG Infosec Standard 5 (Enhanced), or crushed on site at your premises where your policy requires witnessed destruction.
Innovent Recycling is ISO 27001 certified. Collection is free across the UK, and on the day our team provides a signed count of the items collected. Serial matching, wiping or destruction and reporting all happen at our facility, with serial-matched certificates and an asset report following so you can reconcile against your own register - which is precisely the verification evidence Revision 2 expects you to validate. Nothing we handle goes to landfill, and working devices are assessed for buyback rebates.
Collections run nationwide, including Manchester and London, from a single site or across a full estate.
Frequently asked questions
Is NIST 800-88 Rev 1 still valid?
No. NIST withdrew Revision 1 on 26 September 2025 and superseded it with Revision 2. Documents, contracts and certificates that still cite Revision 1 are referencing a withdrawn publication, which is an easy finding for an auditor and worth correcting at your next policy review.
Does NIST 800-88 Rev 2 apply to UK businesses?
NIST 800-88 Rev 2 is not UK law. It is US federal guidance, but it is the standard most often named in UK data destruction certificates, tenders and supplier documentation, so UK organisations inherit it contractually. UK-specific expectations come from NCSC guidance and, for government-classified material, HMG Infosec Standard 5.
Is a single-pass wipe really enough?
Under NIST 800-88 Rev 2, yes for the clear method on modern media. NIST states that multi-pass overwriting is unnecessary, achieves very little additional protection and can degrade flash media lifespan. What matters instead is that the pass completes, is verified for errors or anomalies, and is validated against data sensitivity.
What is an information storage media (ISM)?
ISM is the NIST 800-88 Rev 2 replacement for the older term "electronic (soft copy) media". It covers physical hardware such as SSDs and magnetic tape alongside virtual and logical storage such as cloud, container and object storage, where the underlying physical media is abstracted away from the data owner.
Should we still physically destroy drives?
Only where classification or policy requires it. NIST 800-88 Rev 2 treats destruction as one method among three rather than an automatic upgrade, and criticises fragmentation techniques for higher security categories. For most commercial data, verified erasure to NIST 800-88 is sufficient and keeps the asset reusable and worth something.