By Marcus Johnson at Ewaste Phoenix | April 5, 2026 | 8 min read
NIST 800-88 Rev. 2: What the 2025 Update Means for Your Data Destruction Program
What Is NIST 800-88 and Why It Matters
NIST Special Publication 800-88, officially titled "Guidelines for Media Sanitization," is the definitive U.S. government standard for destroying data on electronic media. Published by the National Institute of Standards and Technology, it provides the technical framework that organizations across every industry use to ensure that sensitive data cannot be recovered from retired, repurposed, or recycled storage devices.
NIST 800-88 matters because virtually every major compliance framework references it:
When you see "data destruction" in a compliance requirement, NIST 800-88 is almost always the underlying standard that defines how to do it correctly.
What Changed in the September 2025 Rev. 2 Update
The original NIST 800-88 was published in 2006, with Rev. 1 following in December 2014. In the decade since Rev. 1, storage technology has evolved dramatically - NVMe drives, self-encrypting drives (SEDs), eMMC flash, UFS storage, and hybrid architectures have become standard. Rev. 2, published in September 2025, addresses these changes with updated guidance.
Key Changes in Rev. 2
1. NVMe Drive Sanitization
Rev. 1 was written primarily for SATA and SAS interfaces. Rev. 2 adds specific sanitization guidance for NVMe drives, including the NVMe Format command with Secure Erase and Cryptographic Erase options. It clarifies when each NVMe sanitization command achieves Clear vs. Purge level sanitization and notes that not all NVMe drives implement these commands identically.
2. Self-Encrypting Drive (SED) Guidance
Rev. 2 significantly expands guidance on SEDs, which use hardware encryption to protect data. The updated standard clarifies that cryptographic erase (destroying the encryption key) can achieve Purge-level sanitization - but only when the encryption implementation meets specific requirements (e.g., FIPS 140-3 validated, AES-256). It also warns that some SED implementations have been found to have vulnerabilities that could allow data recovery even after cryptographic erase.
3. Flash Storage Updates
Rev. 2 acknowledges the unique challenges of sanitizing flash-based storage (SSDs, USB drives, SD cards, eMMC, UFS). Because flash memory uses wear-leveling algorithms and maintains over-provisioned areas that are not accessible through standard interfaces, traditional overwrite methods cannot guarantee complete sanitization. Rev. 2 provides updated recommendations for each flash storage type.
4. Deprecation of Multi-Pass Overwrite
Rev. 2 formally confirms what Rev. 1 already suggested: multi-pass overwrite methods are unnecessary for modern magnetic media. The document explicitly states that a single overwrite pass is sufficient to prevent data recovery from current hard drives, effectively deprecating the DoD 5220.22-M 3-pass and 7-pass methods that many organizations still reference.
5. Verification Requirements
Rev. 2 strengthens the guidance on verification - the process of confirming that sanitization was successful. It introduces tiered verification approaches based on media type and sanitization method, acknowledging that verification of flash storage sanitization is inherently more challenging than verification of magnetic media sanitization.
The Three Sanitization Methods: Clear, Purge, Destroy
NIST 800-88 defines three categories of media sanitization, each providing increasing levels of assurance. Rev. 2 retains these categories but updates their definitions and recommended techniques:
Clear
Purpose: Protect against simple, non-invasive data recovery - e.g., using standard operating system tools or file recovery software.
Methods: Single-pass overwrite with a fixed pattern, firmware-level reset commands, factory reset on mobile devices.
When to use: Internal device reuse where the new user has similar access rights. Low-sensitivity data. Devices remaining within the organization's physical control.
Rev. 2 update: Clarifies that Clear is insufficient for any media containing regulated data (CUI, PHI, PCI) that will leave organizational control.
Purge
Purpose: Protect against laboratory-level data recovery using state-of-the-art techniques and equipment.
Methods: Cryptographic erase on SEDs, NVMe Sanitize or Format commands, degaussing of magnetic media, ATA Secure Erase Enhanced.
When to use: Devices being transferred, sold, donated, or sent to a recycler. Devices containing CUI, PHI, or other regulated data. Media being removed from a controlled environment.
Rev. 2 update: Adds NVMe-specific commands, clarifies SED cryptographic erase requirements, and notes that degaussing is ineffective on SSDs and flash storage.
Destroy
Purpose: Render media completely and irreversibly unusable. Provides the highest level of assurance that data cannot be recovered by any known means.
Methods: Shredding (to ≤2mm particles for SSDs), disintegration, incineration, chemical dissolution.
When to use: Highest-sensitivity data (classified, highly regulated). Media that cannot be reliably purged (damaged drives, unknown encryption status). When verification of purge methods is insufficient. End-of-life processing for compliance-critical assets.
Rev. 2 update: Specifies that SSD shredding must achieve ≤2mm particle size (previously unspecified) due to the small size of individual NAND flash chips.
New Guidance for NVMe Drives, SEDs, and Flash Storage
NVMe Drives
NVMe drives support the NVMe Sanitize command and NVMe Format command with User Data Erase or Cryptographic Erase options. Rev. 2 notes:
Self-Encrypting Drives (SEDs)
Rev. 2 provides detailed guidance on when cryptographic erase is acceptable:
Flash Storage (SSDs, USB, SD Cards)
Flash storage presents unique challenges because of wear-leveling, over-provisioning, and controller-managed remapping:
How Rev. 2 Affects SSD Destruction Requirements
The most practical impact of Rev. 2 for most organizations is the updated guidance on SSD sanitization. Here's what this means:
The ≤2mm particle size requirement is significant because it means that standard hard drive shredders (which typically produce 1-inch strips) are not compliant for SSD destruction under Rev. 2.
What Organizations Need to Update
If your data destruction policies were written under NIST 800-88 Rev. 1 (or earlier), here's what needs to change:
How Ewaste Phoenix Aligns with NIST 800-88 Rev. 2
Ewaste Phoenix updated all data destruction processes to align with NIST 800-88 Rev. 2 immediately upon publication in September 2025:
Contact us at (877) 321-4823 or 877-321-ITAD to discuss how NIST 800-88 Rev. 2 affects your data destruction program. We provide free assessments for organizations updating their media sanitization policies.
Written by
Marcus Johnson
ITAD Operations Manager
NIST 800-88 compliant | 400,000+ Devices Destroyed | Since 2019
Marcus Johnson has managed ITAD operations at EWaste Phoenix since 2019. He oversees all NIST 800-88 compliant data destruction processes, client chain-of-custody documentation, and technician training. Marcus holds NIST 800-88 compliance and has personally overseen the destruction of over 400,000 data-bearing devices.