Skip to content

ITAD KNOWLEDGE CENTER

NIST SP 800-88 Explained: Clear, Purge and Destroy in Plain English

By TBR Trade Group · September 23, 2026

NIST SP 800-88 Revision 2 describes a program for media sanitization: selecting appropriate methods, checking their results and retaining evidence. It was published in September 2025 and supersedes Revision 1.

Clear, Purge and Destroy

  • Clear uses logical techniques to address user-accessible storage and protect against simple recovery through the normal device interface.
  • Purge targets resistance to advanced laboratory recovery while potentially preserving the media for reuse.
  • Destroy targets resistance to advanced laboratory recovery and leaves the media unusable for storing data.

These are outcomes and method categories. A tool name or number of overwrite passes alone does not establish that a device was purged.

Match the technique to the media

Magnetic drives and flash storage behave differently. Ordinary host overwriting can leave areas of flash storage inaccessible to the tool. Dedicated sanitize commands, block erase and cryptographic erase require appropriate device support and assurance.

Cryptographic erase depends on how encryption and keys were implemented and managed; it is not simply deleting a password. Degaussing is not a general solution for SSDs, and Revision 2 does not classify it as an approved Destroy technique.

Check the result, then approve the outcome

Verification checks whether the processing operation completed as intended. Validation evaluates whether the result is acceptable for the data and intended disposition. Failed or uncertain results need an exception decision, further processing or destruction rather than an automatic success certificate.

What to request in the record

Ask for media identifiers, method and technique, tool and version, processing date, verification results, validation decision and responsible personnel. NIST guidance is not a certification of a service provider.

Source: NIST SP 800-88 Rev. 2, especially sections 3, 4.5 and 4.6. Review the current guidance and device-specific requirements with your security team.

Learn about TBR’s data-handling service and current capabilities and certification status.

Put Your ITAD Plan Into Practice

Tell us the equipment, location and data requirements for your project.