
Table of Contents
When you retire a server, decommission a storage array, or clear out a rack of aging drives, the data on those devices still remains. NIST 800-88 is the federal guideline that tells you exactly how to make sure it’s gone for good.
What NIST 800-88 Actually Covers

NIST Special Publication 800-88 Rev. 2, “Guidelines for Media Sanitization,” is the benchmark for securely erasing and destroying data from storage media before disposal, reuse, or resale. Published by the National Institute of Standards and Technology, it defines how to remove sensitive data so it can never be reconstructed.
The standard applies to a wide range of media, including:
- Hard disk drives (HDDs) and solid-state drives (SSDs)
- Servers, storage arrays, and backup tapes
- Mobile devices and removable media like USB drives
- Networking gear that stores configuration or credential data
For any organization handling customer records, financial data, or proprietary information, alignment with NIST 800-88 is the difference between a clean audit and a costly breach.
The Three Methods of Sanitization
NIST 800-88 defines three levels of media sanitization, but the right choice depends on the sensitivity of your data and whether the device leaves your control or if you plan on reusing it internally.
1. Clear

The clear method involves overwriting data using standard read/write commands. Clear protects against basic recovery attempts and works well for devices staying within your organization.
2. Purge

Purge applies advanced techniques such as cryptographic erasure or block erasure that render data unrecoverable, even with laboratory tools. Purge is appropriate for devices staying within your organization for reuse internally, like clear.
3. Destroy

The destroy method involves physically destroying the media through shredding or disintegration so it can never be reused. Destroy is the highest assurance level and the standard for the most sensitive data.
The critical requirement across all three: verification. NIST 800-88 doesn’t just ask you to sanitize media, it asks you to prove it with documentation.
Why NIST 800-88 Compliance Matters for Your Business

A retired drive without verified sanitization is a liability sitting in your storage room. Here’s what proper compliance protects:
- Data security: Verified sanitization removes the risk of sensitive data resurfacing after equipment leaves your control.
- Regulatory alignment: NIST 800-88 supports compliance with broader data protection standards that govern how regulated industries handle information.
- Audit readiness: A documented sanitization process gives your security and compliance teams a clean paper trail to stand behind.
- Peace of mind: Certified destruction confirms that every device was handled to a defensible, repeatable standard.
How AIT Delivers NIST 800-88 Compliance

Knowing the standard is one thing, but executing it consistently across every device, every time, is where a certified partner earns its value.
At AIT, we build NIST 800-88 guidelines directly into our e-waste disposition workflow. Our certified data destruction services destroy storage devices to the exact assurance level your data requires, whether that’s on-site or off-site.
Our process includes:
- Serialized intake and tracking: Every device is individually scanned and reconciled against your asset list on arrival.
- Method-matched sanitization: We apply Clear, Purge, and Destroy based on your security preferences and media type.
- Certified destruction: Storage media that requires the highest assurance is shredded in accordance with NIST SP 800-88 Rev. 2 guidelines.
- Full documentation: You receive a Certificate of Data Destruction and complete chain-of-custody records for a clean audit trail.
For organizations retiring hardware at scale, our IT Asset Disposition (ITAD) program folds NIST 800-88 sanitization into a repeatable, end-to-end workflow, from secure logistics to value recovery and responsible recycling year over year.
Put NIST 800-88 to Work

NIST 800-88 sets the bar for secure media sanitization, and a certified partner makes sure you clear it, every time, with the documentation to prove it.
Whether you’re decommissioning a single storage array or an entire data center, AIT delivers certified data destruction aligned with NIST 800-88, full chain-of-custody tracking, and audit-ready documentation.