Skip to main content
    Back to Blog
    Compliance

    By Marcus Johnson at Ewaste Phoenix | April 8, 2026 | 7 min read

    CMMC Compliance and IT Asset Disposition: What Defense Contractors Need to Know

    Published April 8, 2026 7 min readLast updated: June 14, 2026

    What Is CMMC and Who Does It Apply To?

    The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's framework for ensuring that defense contractors adequately protect sensitive information. CMMC 2.0, which began phased implementation in 2025, applies to every company in the defense industrial base (DIB) that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

    This includes prime contractors, subcontractors, and any supplier in the DoD supply chain - from major aerospace companies to small machine shops. If your company touches DoD data, CMMC applies to you, and that includes how you dispose of the IT equipment that stored or processed that data.

    CMMC Data Destruction Requirements by Level

    CMMC 2.0 has three certification levels, each with increasing requirements for media sanitization:

    Level 1 - Foundational (17 Practices)

  1. Applies to:: Companies handling only FCI
  2. Media requirement:: Basic safeguarding - must limit physical access to media and sanitize or destroy media before disposal or reuse
  3. Documentation:: Self-assessment; no third-party audit required
  4. Key practice:: FAC L1-3.8.3 - Sanitize or destroy information system media containing FCI before disposal or release for reuse
  5. Level 2 - Advanced (110 Practices)

  6. Applies to:: Companies handling CUI
  7. Media requirement:: Full implementation of NIST SP 800-171 Rev. 2 control MP-6 (Media Sanitization)
  8. Documentation:: Third-party assessment by a C3PAO (Certified Third-Party Assessment Organization) required for most contracts
  9. Key practices:
  10. MP-6: Sanitize or destroy media using NIST 800-88 compliant methods before disposal, release, or reuse
  11. MP-6(1): Track, document, and verify media sanitization
  12. MP-6(2): Test sanitization equipment and procedures periodically
  13. Level 3 - Expert (110+ Enhanced Practices)

  14. Applies to:: Companies handling the most sensitive CUI
  15. Media requirement:: Enhanced sanitization requirements from NIST SP 800-172
  16. Documentation:: Government-led assessment (DIBCAC)
  17. Additional requirements:: Non-repudiation of destruction, enhanced logging, continuous monitoring of media handling processes
  18. How CMMC Relates to NIST 800-88 Media Sanitization

    CMMC doesn't define its own data destruction methods - it references NIST Special Publication 800-88 Rev. 2 as the authoritative standard for media sanitization. This means your data destruction processes must align with the three sanitization categories defined in NIST 800-88:

  19. Clear:: Logical overwrite techniques that protect against simple data recovery. Appropriate for low-sensitivity data on media that will be reused internally.
  20. Purge:: Advanced techniques (cryptographic erase, block erase, firmware-level sanitization) that protect against laboratory attack. Appropriate for CUI on media being transferred or repurposed.
  21. Destroy:: Physical destruction (shredding, disintegration, incineration) that renders media completely unusable. Required for highly sensitive CUI or when media cannot be reliably purged.
  22. For defense contractors handling CUI, Purge or Destroy is typically required. Clear alone is insufficient for CUI-bearing media.

    DoD 5220.22-M vs NIST 800-88 - Which Standard Applies in 2026?

    This is one of the most common points of confusion for defense contractors. DoD 5220.22-M (the National Industrial Security Program Operating Manual) previously included a widely-referenced 3-pass or 7-pass overwrite method for data destruction. However, this standard is now considered deprecated for media sanitization purposes.

    As of 2026, the current requirements are:

  23. NIST 800-88 Rev. 2 is the current standard.: The DoD, NIST, and CMMC all reference NIST 800-88 as the authoritative guide for media sanitization.
  24. DoD 5220.22-M overwrite patterns are no longer recommended.: NIST 800-88 Rev. 2 explicitly notes that a single overwrite pass is sufficient for modern magnetic media, and that multi-pass overwrite is unnecessary.
  25. For SSDs, NVMe, and flash storage,: traditional overwrite methods (including DoD 5220.22-M patterns) are unreliable. NIST 800-88 Rev. 2 recommends cryptographic erase, block erase, or physical destruction for these media types.
  26. Bottom line: If your data destruction policy still references DoD 5220.22-M, it needs to be updated to reference NIST 800-88 Rev. 2 before your next CMMC assessment.

    Documentation Requirements for CMMC Audits

    During a CMMC Level 2 or Level 3 assessment, your C3PAO or DIBCAC assessor will look for:

  27. Written media sanitization policy: - Documenting approved methods for each media type, roles and responsibilities, and verification procedures
  28. Media sanitization procedures: - Step-by-step instructions for each sanitization method used
  29. Sanitization records: - Serialized logs showing the device, media type, sanitization method used, date, verification result, and responsible individual
  30. Certificates of destruction: - For devices sent to a vendor for destruction, you need serialized CoDs from a certified provider
  31. Vendor due diligence: - Evidence that your ITAD vendor holds relevant certifications (ISO 27001) and has been vetted for security
  32. Equipment validation records: - Evidence that sanitization tools and equipment are tested and validated periodically
  33. How Ewaste Phoenix Helps Defense Contractors Achieve CMMC Compliance

    Ewaste Phoenix serves defense contractors across Arizona with CMMC-aligned ITAD and data destruction services built specifically for the documentation requirements of CMMC assessments:

  34. NIST 800-88 Rev. 2 compliant sanitization: - We implement all three sanitization categories (Clear, Purge, Destroy) based on media type and sensitivity level
  35. NIST 800-88 compliant processes: - Our data destruction processes are subject to unannounced audits by the National Association for Information Destruction, providing independent validation of our security procedures
  36. Serialized certificates of destruction: - Every device receives its own certificate documenting the asset tag, serial number, media type, sanitization method, verification result, date, and responsible technician
  37. Chain-of-custody documentation: - GPS-tracked, bonded drivers with full documentation from pickup through final disposition
  38. Physical destruction option: - On-site or facility-based hard drive and SSD shredding with video verification available
  39. Downstream accountability: - Full vetted downstream tracking for all materials, ensuring nothing is diverted to unauthorized channels
  40. Assessment preparation support: - We help your team prepare the media sanitization evidence package for C3PAO assessments
  41. Contact us at (877) 321-4823 or 877-321-ITAD to discuss your CMMC compliance requirements. We provide free consultations for defense contractors evaluating their data destruction and ITAD programs.

    MJ

    Written by

    Marcus Johnson

    ITAD Operations Manager

    NIST 800-88 compliant | 400,000+ Devices Destroyed | Since 2019

    Marcus Johnson has managed ITAD operations at EWaste Phoenix since 2019. He oversees all NIST 800-88 compliant data destruction processes, client chain-of-custody documentation, and technician training. Marcus holds NIST 800-88 compliance and has personally overseen the destruction of over 400,000 data-bearing devices.