NIST 800-88 is the standard that sits behind the phrase "destroyed to a recognised standard", and it is simpler than it sounds. Rather than naming one method, it defines three levels of sanitisation, Clear, Purge and Destroy, and helps you match the level to the sensitivity of the data. This guide explains what each level means and how to choose the right one.
NIST 800-88 is a guideline for media sanitisation published by the United States National Institute of Standards and Technology, and it has become the widely accepted benchmark for how data is destroyed. Instead of prescribing a single technique, it defines three levels of sanitisation, Clear, Purge and Destroy, and asks you to choose the level that matches the sensitivity of the data and what will happen to the device. Clear is a basic overwrite or reset that protects against simple recovery. Purge is stronger sanitisation, such as a verified cryptographic erase or firmware command, resistant to advanced laboratory recovery. Destroy is physical destruction of the media. Its value is that it reframes the question from "which method is best" to "what level of assurance does this data need", which is exactly the right question. It underpins credible data destruction.
When a data destruction provider says it works "to NIST 800-88", this is what it means: a structured, defensible way of deciding how thoroughly a given piece of media needs to be sanitised, and of doing it consistently. It is American in origin but international in use, and Australian businesses rely on it because it is clear, respected, and maps neatly onto the practical decisions of disposal. This guide unpacks the three levels and how a provider chooses between them.
NIST 800-88 defines sanitisation as three escalating levels of assurance. The right one depends on the data and the fate of the device.
Each level is harder to reverse than the last. You choose the lowest level that gives the assurance the data needs.
Source: levels per NIST Special Publication 800-88. A device can be reused after Clear or Purge; Destroy ends it.
A standard overwrite or reset using the device's normal write commands, protecting against recovery by ordinary means. It suits lower-sensitivity data on devices that will be reused within a controlled environment. It is the lightest level, and on modern media, particularly solid-state drives, a simple overwrite is not always sufficient on its own, which is where Purge comes in.
Stronger sanitisation designed to resist recovery even in a laboratory, using methods such as a verified cryptographic erase, a firmware sanitise command, or degaussing for magnetic media. Purge is the practical level for most business data on equipment that will be reused, because it renders the data unrecoverable while keeping the device usable, so its value can be recovered.
Physical destruction of the media itself, by shredding or comparable means, so the storage cannot be reconstructed. Destroy gives the highest assurance and is used for the most sensitive data, for media that cannot be verifiably purged, and where the device will not be reused. It ends the asset, which is why it is not applied to everything by default.
Two questions settle it: how sensitive is the data, and will the device be reused. A good provider applies the lowest level that meets the need.
The elegance of NIST 800-88 is that it does not push you toward destroying everything. It asks you to select the lowest level of sanitisation that provides adequate assurance for the sensitivity of the data, given what will happen to the device next. Ordinary business data on a laptop that will be securely refurbished and resold is well served by a Purge-level wipe, which protects the data and preserves the device's value. The most sensitive records, or a drive that will not be reused or cannot be verifiably purged, warrant Destroy. Clear has a narrower place, for lower-sensitivity data staying within a controlled environment. Matching the level to the need is what lets a business protect its data thoroughly while still recovering value from equipment that can be safely reused, rather than shredding assets that did not need it.
The other half of the standard, easy to overlook, is verification. A sanitisation is only complete when it has been confirmed to have worked, and NIST 800-88 treats verification and documentation as part of the process, not an optional extra. This is why a credible provider issues a certificate for each device recording the level applied and confirming the outcome. The certificate is what turns "sanitised to NIST 800-88" from a claim into evidence, which for a business is the point of using a recognised standard at all.
The same level can require a different technique on different media. A Purge on a magnetic hard drive might be a degauss or an overwrite; on a solid-state drive it is a verified cryptographic erase or firmware sanitise, because flash does not respond to the old methods. NIST 800-88 accounts for this by tying the technique to the media, which is why matching the method to the drive, covered in our guide to data destruction methods, sits at the heart of applying the standard correctly.
NIST 800-88 has become the shorthand for credible data destruction because it is clear, respected and outcome-based.
The reason a standard matters at all is that "we wiped it" means nothing without a definition of how thoroughly and to what assurance. NIST 800-88 supplies that definition in a way that is respected, auditable and sensible: it does not demand the destruction of everything, it demands the right level of assurance for the data in question, and it insists the result be verified. For a business, working to it is a way of demonstrating that disposal was done to a recognised, defensible standard rather than by guesswork. You can read the guideline itself on the NIST website. What turns the standard into protection, though, is applying it consistently and certifying every device, which is what a credible provider does as routine.
The questions people ask most about the media sanitisation standard.
No. It is a technical guideline published by the US National Institute of Standards and Technology, not a law. But it has become the widely accepted benchmark for media sanitisation, and working to it is a way of demonstrating that data was destroyed to a recognised, defensible standard. Australian privacy law requires personal information to be destroyed or de-identified when no longer needed; NIST 800-88 is a respected way of meeting that requirement in practice.
They are three escalating levels of assurance. Clear is a standard overwrite or reset, protecting against ordinary recovery. Purge is stronger sanitisation, such as a verified cryptographic erase or degauss, resistant to laboratory recovery, while keeping the device usable. Destroy is physical destruction of the media, the highest assurance, which ends the device. You choose the lowest level that gives the assurance the data needs.
It depends on the sensitivity of the data and whether the device will be reused. Most business data on reusable equipment is well served by Purge, which protects the data and preserves value. The most sensitive data, or drives that will not be reused or cannot be verifiably purged, warrant Destroy. A good provider selects the level for each device rather than applying one blanket method.
A factory reset is at best a weak form of Clear and often leaves data recoverable, so on its own it does not meet the assurance most business data needs. Meeting the standard means applying the appropriate level with a technique suited to the media, and verifying the result. That is why credible data destruction uses verified wiping or physical destruction rather than relying on a reset.
Yes, and it accounts for them. NIST 800-88 ties the technique to the media, so a Purge on a solid-state drive is a verified cryptographic erase or firmware sanitise rather than the overwrite used on a magnetic hard drive, and degaussing is not applied to flash at all. Applying the standard correctly means using the right method for each media type, which is essential for SSDs.
Through verification and a certificate. NIST 800-88 treats verification as part of sanitisation, so a credible provider confirms each sanitisation succeeded and issues a certificate for each device recording the level applied. That documentation, reconcilable to your asset register, is what lets a business demonstrate the data was destroyed to the standard rather than merely assert it.
See how ITC sanitises every device to the appropriate NIST 800-88 level, Purge for equipment that can be reused, Destroy for the rest, with a certificate confirming the level applied to each one.
Destroy it properly
Knowing the right method is only half of it. The other half is being able to prove what happened to each serial number. ITC works to the NIST 800-88 standard under ISO/IEC 27001:2022, records chain of custody from your desk to the shredder, and issues a Certificate of Data Destruction listing the devices processed.