What Is CMMC and Who Does It Apply To?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's framework for ensuring that defense contractors adequately protect sensitive information. CMMC 2.0, which began phased implementation in 2025, applies to every company in the defense industrial base (DIB) that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
This includes prime contractors, subcontractors, and any supplier in the DoD supply chain - from major aerospace companies to small machine shops. If your company touches DoD data, CMMC applies to you, and that includes how you dispose of the IT equipment that stored or processed that data.
CMMC 2.0 has three certification levels, each with increasing requirements for media sanitization:
Level 1 - Foundational (17 Practices)
Applies to:: Companies handling only FCIMedia requirement:: Basic safeguarding - must limit physical access to media and sanitize or destroy media before disposal or reuseDocumentation:: Self-assessment; no third-party audit requiredKey practice:: FAC L1-3.8.3 - Sanitize or destroy information system media containing FCI before disposal or release for reuseLevel 2 - Advanced (110 Practices)
Applies to:: Companies handling CUIMedia requirement:: Full implementation of NIST SP 800-171 Rev. 2 control MP-6 (Media Sanitization)Documentation:: Third-party assessment by a C3PAO (Certified Third-Party Assessment Organization) required for most contractsKey practices:MP-6: Sanitize or destroy media using NIST 800-88 compliant methods before disposal, release, or reuseMP-6(1): Track, document, and verify media sanitizationMP-6(2): Test sanitization equipment and procedures periodicallyLevel 3 - Expert (110+ Enhanced Practices)
Applies to:: Companies handling the most sensitive CUIMedia requirement:: Enhanced sanitization requirements from NIST SP 800-172Documentation:: Government-led assessment (DIBCAC)Additional requirements:: Non-repudiation of destruction, enhanced logging, continuous monitoring of media handling processesCMMC doesn't define its own data destruction methods - it references NIST Special Publication 800-88 Rev. 2 as the authoritative standard for media sanitization. This means your data destruction processes must align with the three sanitization categories defined in NIST 800-88:
Clear:: Logical overwrite techniques that protect against simple data recovery. Appropriate for low-sensitivity data on media that will be reused internally.Purge:: Advanced techniques (cryptographic erase, block erase, firmware-level sanitization) that protect against laboratory attack. Appropriate for CUI on media being transferred or repurposed.Destroy:: Physical destruction (shredding, disintegration, incineration) that renders media completely unusable. Required for highly sensitive CUI or when media cannot be reliably purged.For defense contractors handling CUI, Purge or Destroy is typically required. Clear alone is insufficient for CUI-bearing media.
DoD 5220.22-M vs NIST 800-88 - Which Standard Applies in 2026?
This is one of the most common points of confusion for defense contractors. DoD 5220.22-M (the National Industrial Security Program Operating Manual) previously included a widely-referenced 3-pass or 7-pass overwrite method for data destruction. However, this standard is now considered deprecated for media sanitization purposes.
As of 2026, the current requirements are:
NIST 800-88 Rev. 2 is the current standard.: The DoD, NIST, and CMMC all reference NIST 800-88 as the authoritative guide for media sanitization.DoD 5220.22-M overwrite patterns are no longer recommended.: NIST 800-88 Rev. 2 explicitly notes that a single overwrite pass is sufficient for modern magnetic media, and that multi-pass overwrite is unnecessary.For SSDs, NVMe, and flash storage,: traditional overwrite methods (including DoD 5220.22-M patterns) are unreliable. NIST 800-88 Rev. 2 recommends cryptographic erase, block erase, or physical destruction for these media types.Bottom line: If your data destruction policy still references DoD 5220.22-M, it needs to be updated to reference NIST 800-88 Rev. 2 before your next CMMC assessment.
During a CMMC Level 2 or Level 3 assessment, your C3PAO or DIBCAC assessor will look for:
Written media sanitization policy: - Documenting approved methods for each media type, roles and responsibilities, and verification proceduresMedia sanitization procedures: - Step-by-step instructions for each sanitization method usedSanitization records: - Serialized logs showing the device, media type, sanitization method used, date, verification result, and responsible individualCertificates of destruction: - For devices sent to a vendor for destruction, you need serialized CoDs from a certified providerVendor due diligence: - Evidence that your ITAD vendor holds relevant certifications (ISO 27001) and has been vetted for securityEquipment validation records: - Evidence that sanitization tools and equipment are tested and validated periodicallyEwaste Phoenix serves defense contractors across Arizona with CMMC-aligned ITAD and data destruction services built specifically for the documentation requirements of CMMC assessments:
NIST 800-88 Rev. 2 compliant sanitization: - We implement all three sanitization categories (Clear, Purge, Destroy) based on media type and sensitivity levelNIST 800-88 compliant processes: - Our data destruction processes are subject to unannounced audits by the National Association for Information Destruction, providing independent validation of our security proceduresSerialized certificates of destruction: - Every device receives its own certificate documenting the asset tag, serial number, media type, sanitization method, verification result, date, and responsible technicianChain-of-custody documentation: - GPS-tracked, bonded drivers with full documentation from pickup through final dispositionPhysical destruction option: - On-site or facility-based hard drive and SSD shredding with video verification availableDownstream accountability: - Full vetted downstream tracking for all materials, ensuring nothing is diverted to unauthorized channelsAssessment preparation support: - We help your team prepare the media sanitization evidence package for C3PAO assessmentsContact us at (877) 321-4823 or 877-321-ITAD to discuss your CMMC compliance requirements. We provide free consultations for defense contractors evaluating their data destruction and ITAD programs.