NIST 800-88: Overwriting vs Degaussing vs Shredding Methods

NIST 800-88: Overwriting vs. Degaussing vs. Shredding

Last updated: July 15, 2026

Key takeaways for NIST-compliant data sanitization

  • NIST SP 800-88 Rev. 2, published Sept. 26, 2025, is the current federal standard. It requires organizations to match sanitization category to media type and data sensitivity.
  • Clear-level sanitization via single-pass overwriting applies only to HDDs. It is unreliable for SSDs because of wear-leveling and over-provisioning.
  • Purge methods such as cryptographic erase, block erase and degaussing for magnetic media make data recovery infeasible even for laboratory attacks while preserving media for reuse when conditions allow.
  • Shredding to the correct particle size is the only universal Destroy method for HDDs, SSDs, NVMe drives and tape.
  • Full Circle Electronics provides certified NIST-compliant sanitization services across multiple U.S. facilities. Contact us to schedule a consultation and confirm that a program aligns with Rev. 2 requirements.

NIST SP 800-88r2 sanitization categories in practice

NIST SP 800-88 Rev. 2 defines three escalating sanitization categories. Clear uses logical techniques such as overwriting user-addressable storage. It protects against simple noninvasive recovery but can leave data recoverable by laboratory methods. Purge uses stronger physical or logical techniques, including cryptographic erase and block erase, that make recovery infeasible even for advanced laboratory attacks while preserving media for reuse when possible. Destroy renders media permanently unusable through shredding, pulverizing, incinerating, disintegrating or melting.

Rev. 2 explicitly recommends Purge over Clear whenever conditions allow. The standard also shifts from device-specific technique lists to a governance model and directs organizations to IEEE 2883-2022 for current device-specific procedures.

How common sanitization techniques map to NIST categories

For HDDs, a single-pass zero overwrite satisfies Clear. Multi-pass overwriting does not add assurance under Rev. 2. Overwriting alone does not satisfy Purge on HDDs without firmware sanitize commands. For SSDs and NVMe drives, standard overwrite cannot reach all physical memory cells because of wear-leveling and over-provisioning. That limitation makes overwrite unreliable even at the Clear level for sensitive data.

Cryptographic erase and block erase via firmware sanitize commands are the preferred Purge methods for SSDs and NVMe drives. Degaussing applies only to magnetic media such as HDDs and tape as a Purge method. Rev. 2 downgrades degaussing from a Destroy technique to Purge and no longer recognizes it as a standalone Destroy method. Shredding to appropriate particle sizes remains the universal Destroy method for all media types.

Overwriting on HDDs and SSDs

Single-pass overwrite of fixed data followed by verification remains sufficient for Clear-level sanitization on HDDs. This method offers low cost, preserves the drive for reuse and fits many remarketing programs. Its limitations become significant in environments that include SSDs and high-sensitivity data.

Overwriting on HDDs has several advantages.

  • Satisfies NIST Clear for magnetic hard drives
  • Preserves media for remarketing and reuse
  • Uses low-cost tools that erasure software widely supports
  • Supports verification through sector read-back sampling

Overwriting on SSDs introduces serious drawbacks.

Verification for overwriting involves reading back a sample of sanitized sectors, confirming the expected overwrite pattern and documenting results in a sanitization record.

Degaussing for magnetic media

Degaussing exposes magnetic media to a powerful electromagnetic field that neutralizes the magnetic domains storing data. Modern HDDs typically require degaussers rated at 5,000 Oe or higher, and LTO tapes may require 7,000 Oe or more. When an NSA Evaluated Products List degausser is used correctly, degaussing achieves Purge-level sanitization on magnetic media.

Degaussing offers several advantages.

  • Processes media quickly
  • Reaches hidden sectors, bad blocks and firmware zones that software wiping cannot access
  • Works for HDDs and all generations of LTO, DLT and other magnetic tape formats
  • Produces drive inoperability, which serves as a functional verification indicator

Degaussing also carries important limitations.

In mixed-media environments, organizations must apply degaussing only to magnetic media and use separate methods for solid-state devices. Post-degauss verification involves confirming permanent drive inoperability and documenting the degausser model, field strength and operator.

Shredding for Destroy-level assurance

Physical shredding provides a universal Destroy method for HDDs, SSDs, NVMe drives, tape and optical media. HDDs are typically shredded to a 6 mm commercial particle size, while classified or high-security media requires a 2 mm particle size.

SSDs and NVMe drives require shredding to a maximum particle edge length of 2 mm and a maximum surface area of 4 mm² to destroy individual NAND flash chips. A coarser shred profile can leave flash packages intact and recoverable. Post-destruction verification relies on visual inspection of output material to confirm the required particle size. A serialized Certificate of Destruction must document the destruction method, particle size standard, date, location, operator and each device serial number.

Current status of DoD 5220.22-M

The DoD 5220.22-M three-pass overwrite method was removed from NISPOM after 2001 and no longer appears in current U.S. government frameworks. The U.S. Department of Defense formally retired the method for media sanitization in 2007. NIST SP 800-88 Rev. 2 now serves as the governing federal standard.

As established earlier, Rev. 2 requires only a single overwrite pass for Clear-level HDD sanitization. The multi-pass sequence specified by DoD 5220.22-M adds no security benefit on modern drives. Organizations that still reference DoD 5220.22-M in sanitization policies should update those policies to align with Rev. 2 and its media-specific guidance.

Verification steps for Clear, Purge and Destroy

NIST SP 800-88 Rev. 2 separates verification and validation into two distinct requirements. Verification confirms that the sanitization technique completed as expected. Validation confirms that the chosen method was sufficient for the data’s sensitivity level. Both steps are mandatory for compliance.

For Clear via overwriting, verification includes reviewing the tool’s completion status, checking for errors and sampling sectors to confirm the overwrite pattern. For Purge via cryptographic erase or block erase on SSDs, verification includes reading back sectors to confirm the expected pattern or confirming that drive firmware reports successful sanitization. For Destroy via shredding, verification requires inspecting remnants and confirming which equipment was used. Validation at every tier relies on a risk-based determination that the method matches the data’s FIPS 199 security category.

Media-specific decision framework

Effective method selection starts with media type, data sensitivity and whether the device will be reused or retired.

For HDDs, the sanitization method escalates with data sensitivity and disposition requirements. Non-sensitive to moderate-sensitivity data intended for reuse requires Clear via single-pass overwrite with sector read-back verification. When data sensitivity increases or the device exits organizational control, Purge via degaussing with an NSA EPL-listed degausser or ATA/SCSI sanitize commands becomes appropriate. At the highest sensitivity level or at end of life, Destroy via shredding to the applicable particle size standard provides the strongest assurance.

For SSDs and NVMe drives intended for reuse, the Purge method depends on the encryption configuration. When encryption was active since provisioning, the algorithm meets AES-256 or equivalent and key destruction is verifiable, cryptographic erase satisfies Purge requirements. If those conditions cannot be met, block erase via NVMe Sanitize or ATA Secure Erase commands provides an alternative Purge path. When the device reaches end of life or neither Purge method can be verified, Destroy via shredding to 2 mm particle size remains the compliant option.

For magnetic tape intended for retirement, Purge via degaussing with a coercivity-matched NSA EPL-listed degausser provides appropriate assurance. For the highest assurance level, combining degaussing with physical shredding achieves full Destroy classification. As noted in the degaussing section, magnetic sanitization methods cannot affect flash-based media.

Contact us to discuss a media-specific sanitization plan for a mixed-fleet environment across multiple sites.

Verification and documentation for audit readiness

NIST SP 800-88 Rev. 2 expands required fields for certificates of sanitization to include manufacturer, model and serial number, sanitization category and technique, tool name and version, verification method, operational status of the media, contact details of the person performing sanitization and validation status confirming that the method was preapproved for that media class.

A Certificate of Destruction that records the sanitization method, the NIST SP 800-88 category and the serialized device inventory provides objective evidence for compliance audits. Serialized tracking that captures each device serial number before, during and after sanitization forms the foundation of an audit-ready program. Provider certifications strengthen that foundation. NAID AAA certification requires background-checked personnel and witnessed destruction processes. R2v3 requires traceable records for each sanitization event. e-Stewards certification confirms environmentally responsible downstream handling.

Why many organizations select a certified ITAD partner

Executing NIST SP 800-88 Rev. 2 correctly across mixed HDD, SSD and tape fleets requires method-specific expertise, certified equipment and documented chain of custody at every transfer point. Full Circle Electronics holds NAID AAA, R2v3 and e-Stewards certifications, along with ISO 9001, ISO 14001, ISO 45001, HIPAA and PCI-DSS compliance across its facilities.

Full Circle Electronics operates certified processing facilities across the United States, including Arizona, California, Colorado, Florida, Georgia, Texas and Illinois, and maintains operations in Mexico and Colombia. The company delivers on-site and off-site sanitization under a single accountable chain of custody. On-site services include NIST-compliant wiping, degaussing and shredding performed by background-checked professionals at the client location. Off-site processing uses serialized asset tracking from pickup through final disposition, with every event documented in a secure real-time portal accessible 24/7.

Full Circle Electronics follows a reuse-first model. When Purge-level sanitization can be verified, assets are evaluated for remarketing and value recovery before physical destruction. This approach supports ESG circular-economy objectives and cost recovery for procurement and finance teams. For assets that require Destroy-level sanitization, in-house shredding maintains an unbroken chain of custody from intake through certificate issuance.

Conclusion: Matching methods to mixed-media environments

NIST SP 800-88 Rev. 2 requires organizations to align sanitization category with data sensitivity, media type and disposition outcome. Overwriting satisfies Clear for HDDs but remains unreliable for SSDs. Cryptographic erase and block erase provide Purge for flash-based media when conditions are met. Degaussing serves as a Purge method for magnetic media only. Shredding to the appropriate particle size remains the universal Destroy method. Every method requires documented verification and validation to support audit readiness.

No single method covers a mixed-media fleet. A certified ITAD partner with the right credentials, equipment and documentation infrastructure offers a practical path to compliant, audit-ready execution at scale.

Contact us to schedule a consultation and build a NIST SP 800-88 Rev. 2-aligned sanitization program for any fleet size or geography.

Frequently asked questions

What is the difference between Clear, Purge and Destroy under NIST SP 800-88 Rev. 2?

Clear uses logical techniques such as overwriting to remove data from user-addressable storage. It protects against recovery using standard software tools but can leave data recoverable by laboratory methods. Purge uses stronger physical or logical techniques, including cryptographic erase, block erase and degaussing for magnetic media, that make recovery infeasible even for advanced laboratory attacks while preserving media for potential reuse. Destroy renders the media physically incapable of holding data through shredding, pulverizing, incinerating, disintegrating or melting. Rev. 2 recommends using Purge over Clear whenever possible and directs organizations to select the category based on data sensitivity and whether the device will leave organizational control.

Why does overwriting fail to sanitize SSDs?

SSDs store data as electrical charge in NAND flash cells rather than as magnetic patterns on a platter. The SSD controller uses wear-leveling to distribute writes across flash cells, so a logical overwrite command can write to a new physical location while leaving original data intact in the prior cell. Over-provisioning reserves a portion of physical flash memory that remains invisible to the operating system and unreachable by host overwrite commands. The Flash Translation Layer creates a layer of indirection between logical block addresses and physical storage locations, so software tools lack direct control over where data is written. For these reasons, NIST SP 800-88 Rev. 2 does not recognize standard overwriting as a Purge method for SSDs. Cryptographic erase or block erase via firmware sanitize commands is required for Purge, and physical shredding to fine particle size is required for Destroy.

Can degaussing be used to sanitize SSDs?

Degaussing works by exposing magnetic media to a powerful electromagnetic field that disrupts the magnetic domains storing data. SSDs contain no magnetic storage components because data is stored as electrical charge in floating-gate transistors inside NAND flash chips. A degausser’s magnetic field does not affect this storage mechanism and does not alter or erase the data. NIST SP 800-88 Rev. 2, NSA Media Destruction Guidance and IEEE 2883-2022 all exclude degaussing from approved SSD sanitization methods. For SSDs, NIST-compliant options include Purge via cryptographic erase when encryption and key destruction conditions are met or Destroy via physical shredding to the appropriate particle size.

What must a Certificate of Data Destruction include to satisfy NIST SP 800-88 Rev. 2?

NIST SP 800-88 Rev. 2 requires that a certificate of sanitization include the device manufacturer, model and serial number, the sanitization category applied, the specific technique used such as overwrite, block erase, cryptographic erase or shredding, the tool name and version, the verification method applied after sanitization, the operational status of the media, the contact details of the person or organization performing sanitization and a validation notation confirming that the method was preapproved for that media class. For Destroy-level events, the certificate should also document the destruction equipment used, the particle size standard referenced, the date and location of destruction and the identity of any witnesses. Serialized tracking that links each certificate to a specific device serial number forms the foundation of an audit-ready program.

Is DoD 5220.22-M still an accepted standard for data sanitization?

DoD 5220.22-M no longer functions as an active or accepted standard for media sanitization. The three-pass overwrite method it specified was removed from NISPOM after 2001, and the Department of Defense formally retired it for sanitization purposes in 2007. It does not appear in current U.S. government frameworks including DAAPM, PCI DSS, ISO/IEC 27040 or R2v3. NIST SP 800-88 Rev. 2, published Sept. 26, 2025, serves as the current governing standard. Organizations that still reference DoD 5220.22-M in internal policies should update those policies to align with Rev. 2, which provides media-specific guidance for HDDs, SSDs, NVMe drives, tape, mobile devices and cloud storage environments.