NIST published Revision 2 of SP 800-88 on 26 September 2025, just over a year ago. A lot of IT disposal copy still describes the world of Revision 1. Three habits in particular are no longer supported by the standard they cite: multi-pass overwriting, degaussing as destruction, and shredding as the top tier of security.
We sell onsite drive shredding, so weigh what follows accordingly. It is also why everything below is quoted from the documents rather than paraphrased.
What Revision 2 actually changed
Revision 1 was a manual. It told you which technique to apply to which type of media, mostly in tables. Revision 2 is a different kind of document. NIST's own FAQ describes the shift as moving away from hands-on technique tables towards establishing an enterprise media sanitization program.
The practical consequence is that the media-specific detail is gone. The summary of changes says the appendices "that described media-specific sanitization techniques and tools were removed to improve the document's longevity." For the specifics, NIST now points to IEEE 2883 and to NSA policy manuals.
The three methods survive: clear, purge and destroy. What changed is what the document will and will not say about how to achieve them. That is where several familiar claims stop having support.
Multi-pass overwriting is not needed
Older practice erased hard drives with multiple overwrite passes. The standard notes the number "ranged from a single pass to as high as 39", often citing a Department of Defense manual. NIST is now explicit that the requirement is obsolete. The summary of changes says the clear method was clarified "such that multi-pass overwrite is not needed. This counters the obsolete DoD 5220.22-M language."
The body of the standard goes further for flash storage. For certain media, such as SSDs with overprovisioning, multi-pass practices "should be avoided as very little confidentiality protection is achieved." A footnote adds that the Department of Defense itself removed overwriting specifications from its manual in 2006.
So a provider advertising multi-pass wiping as the rigorous option is describing a practice NIST now says buys very little, and on flash media may wear the device for no gain.
Degaussing is a purge for magnetic media, not destruction
Two statements matter here. First, degaussing "should not be used for non-magnetic ISM (e.g., flash storage, such as SSDs)." Second, and more pointedly:
At the time of this writing, degaussing is not considered an approved destroy sanitization technique
The reason is worth understanding. A degausser can make a drive inoperable, for example by damaging its servo tracks, and still fail to sanitise the data. NIST gives a blunt example of a process that reports success and achieves nothing: "a sanitization operation that degausses an SSD can complete successfully, but no sensitive data is sanitized."
Degaussing still has a place for magnetic media, provided the degausser's strength is matched to the drive. But a dead drive is not evidence of a clean one.
Shredding is the line NIST drew
This is the change with the most commercial weight, so here is the exact sentence:
Pulverize and shred techniques for ISM should be avoided for anything but the lowest security categories of data.
The preceding sentence explains why: "As the density of data and the hardness of the component materials increase on an ISM, certain destructive techniques can become ineffective." NIST's point is about density: the more data packed into less material, the less a purely mechanical technique can be relied on.
Two qualifications keep this honest. NIST is not saying destruction is never appropriate. It says destructive techniques "may be the only option when the ISM fails or is obsolete" and other methods cannot be applied. And it lists the techniques "commonly associated" with destruction: disintegrate, incinerate, melt, pulverize and shred, with the caveat above. It also warns that bending, cutting and "drilling a hole through a storage device" may only partly damage the media, "leaving portions of it accessible."
NIST's FAQ goes a step further, saying IEEE 2883 deprecates shredding and pulverising as approved destruction for modern hard drives and SSDs, and lists melting instead. IEEE 2883 is a paid standard and we have not read it, so treat that as NIST's description of it, not ours.
The UK view is different, and not contradictory
If you are a UK organisation, the more relevant document may be the National Cyber Security Centre's guidance on secure sanitisation and disposal of storage media. It describes physical destruction "to particles of 6mm or less", with the resulting particle size verified afterwards.
That looks like a direct clash with NIST. It is not, and the reason is the most useful thing in this article. The two documents defend against different adversaries.
| NIST SP 800-88 Rev. 2 (Sept 2025) | NCSC guidance (reviewed Feb 2025) | |
|---|---|---|
| Adversary | State-of-the-art laboratory techniques | Commercial recovery tools and forensic services. Explicitly not a skilled, well-funded laboratory |
| Data covered | Low, moderate and high confidentiality categories | OFFICIAL data |
| Overwriting | Multi-pass not needed. Avoid on overprovisioned flash | For unencrypted media, overwrite with a fixed value such as zeros. Caution if remapping or bad sectors |
| Degaussing | Purge for magnetic media only. Not a destroy technique | Acceptable for exclusively magnetic media, if the degausser is strong enough |
| Shredding | Avoid above the lowest security categories | Destruction to particles of 6mm or less, with size verified |
NCSC states its scope plainly: the guidance protects against "standard users with access to commercially available data-recovery tools, or ... forensic services" and will "not protect data from being read by a skilled, well-funded laboratory." NIST's benchmark is state-of-the-art laboratory techniques.
That is our reading, and the inference is simple. Destruction to 6mm can be reasonable for OFFICIAL data against commercial recovery, and still be the wrong answer for data that needs protection from a laboratory. The mistake is treating "shredded" as a single assurance level.
Cryptographic erase has conditions
NIST spends real effort on cryptographic erase, because it describes modern SSDs as self-encrypting, and says crypto erase can be done "with high assurance much faster than with other sanitization techniques." The conditions are what people miss.
The first is easy to break without noticing:
no sensitive data has previously been stored on the ISM in plaintext form (i.e., not encrypted) as CE can only sanitize keys related to encrypted data.
Our reading is that switching encryption on for a drive that already holds data does not make crypto erase valid for that drive. The earlier plaintext is still there. Always-on encryption from first use is a different situation from encryption added later.
There are two more. NIST says crypto erase "should not be trusted on ISM that have been backed up or escrowed" unless you have high confidence in how the keys were managed elsewhere. And for information that must stay confidential for decades, it may not be acceptable at all, because the data "still resides in the ISM as ciphertext" and could become recoverable if the cryptography weakens. The key sanitisation itself should follow ISO/IEC 19790 zeroization.
What a policy needs now
Because Revision 2 is about programs, the FAQ lists what a formal policy should contain. Five things, each of which is something you can ask a provider about:
Classification tied to method. Low, moderate and high confidentiality mapped to clear, purge or destroy, not one method for everything.
Evidence. Documentation and certificates of sanitization.
Roles and training. Named responsibilities and mandatory personnel training.
Tool control. Configuration, calibration, testing and maintenance of the equipment. NIST's own failure examples include a shredder used on an optical disc producing pieces 50 per cent larger than the organisation accepts.
Verification and validation. Worth noting that NIST removed almost all of the old verification language and says full or representative sampling is not needed "unless required by the organization." That makes your own requirement the thing that counts, so write it down.
The honest summary
None of this makes shredding or degaussing wrong. It makes them conditional. Destruction to 6mm is the route NCSC describes for OFFICIAL data, and destruction may be the only option for a failed drive. It is not a universal top tier, and NIST no longer treats it as one.
Three questions cut through most disposal proposals. Which data sensitivity is this method meant to protect? Against which adversary? And what evidence, tied to a serial number, shows it was done to that standard?
If the answer to the first two is "everything" and "everyone", the proposal is using a single word to cover several very different levels of assurance.
Nanosoft Team
Writer at Nanosoft - covering ITAD, data security, and sustainable technology lifecycle management.
Found this useful? Share it.



