Last year, the National Institute of Standards and Technology (NIST) published Revision 2 of NIST SP 800-88 and withdrew Revision 1 the same day. Shifting focus from per-device sanitization choices to running an enterprise media sanitization program, the updates change how companies must wipe, destroy, and handle retired data-containing hardware. The changes include removing static tables from Revision 1, adopting IEEE 2883 as the standard for modern hardware, focusing on logical sanitization, and requiring independent validation.
Core Methods of Data Erasure
ITAD facilities and other third-party end-of-life vendors often use three core data erasure methods: clear, purge, and destroy. Clearing securely erases data from a device so it can be reused, and it is the most widely used data erasure method. Purging is becoming increasingly common and is replacing software overwriting for SSDs. Software overwriting does not always reliably clear modern flash storage. Purging is an advanced erasure method that completely removes all data from a storage device. Because data storage and monitoring change so quickly, cryptographic erasure is becoming a more common erasure standard. Lastly, destroying renders media completely inoperable through physical destruction such as disintegration, shredding, or incineration.
Revision 2 Updates: What the Changes Mean
The new Revision 2 focuses on four main areas: program governance, standard outsourcing, verification and validation, and cryptographic erasure. The new revision moves away from standard isolated wipe actions and focuses on written corporate policies, a serialized chain of custody, and staff roles. Traditionally, NIST provided static, fast-aging technical hardware tables, but the updates instead direct organizations to external standards such as IEEE 2883 and NSA/CSS specifications. Revision 2 mandates verification and validation steps for every job and requires stricter documentation, including verifiable logs and formal Certificates of Destruction with dual-signatory requirements. This helps companies maintain compliance with auditing standards. Lastly, the new updates refine cryptographic erasure criteria to align with government security standards.
How The Revision 2 Updates Impact ITAD Processors
The Revision 2 updates specifically address modern, complex hardware such as NVMe SSDs, eMMC/UFS flash storage, and cloud instances. This renders the one-size-fits-all software wipe concept outdated. Rather than automating a uniform erasure script, as many ITAD facilities have done, processors must now match the sanitization method directly to the storage medium.
The removal of NIST’s static, device-specific hardware tables means ITAD vendors are expected to adhere to erasure standards aligned with IEEE 2883 or NSA specifications. Adopting IEEE 2883 means ITAD facilities must ensure their data erasure software has the certifications to prove it adequately performs the commands required by new storage protocols.
Gone are the days of confirming a successful wipe in a single step. The new updates require separating “verification” from “validation” into two distinct phases. This means ITAD facilities must update their quality assurance protocols to create distinct processes for both phases.
Revision 2 emphasizes Cryptographic erasure as a valid purge method, which means more preservation of hardware’s physical condition. For ITAD facilities that provide resale services, this means faster processing of high volumes of enterprise SSDs and servers while maintaining high device resale value.
It’s no secret that companies are tightening data security standards, but the NIST Revision 2 updates now require corporate clients to audit ITAD vendors more aggressively. ITAD providers must provide more documentation to ensure a tamper-proof audit trail, including device logs, techniques applied, chain-of-custody logs, certificates of destruction, and evidence of downstream material recycling.

Why Data Erasure is Critical at Every Level
The new revisions may seem like an overhaul of outdated erasure methods and a more uniform standard for a new digital storage era that requires more paperwork, but accelerating digital storage evolution demands updated security measures.
Data remains on devices even after asset decommissioning, and more complex storage methods require more stringent erasure methods and assurance. Accountability is extending to hardware owners, which means increased scrutiny of ITAD vendors to ensure they process assets in compliance, including erasure methods. Data breaches are at an all-time high, and hackers are evolving along with technology. In the digital era, maximum security protocols are essential for secure IT asset disposition.
How Companies Can Stay Ahead of the Curve
To ensure compliance with the NIST SP 800-88 Revision 2, companies must shift their internal media disposal policies from a checklist to a comprehensive data governance program, including:
- Technological “decoupling” to ensure policy stays compliant despite storage tech evolution.
- Clearly define data risk tiers to ensure sanitization methods match the sensitivity of the data and the asset destination.
- Clearly emphasize the separation of verification and validation as two separate phases.
- Overhaul ITAD vendor management and SLAs, and require ITAD vendors to hold active R2v3 or NAID AAA certifications.
- Establish a rigid chain-of-custody policy
HOBI’s 30 Year Zero-Breach Record
As an IT asset management and disposition provider with more than 30 years of industry experience and a zero-breach record, HOBI prioritizes client satisfaction through optimized data security services, including on-site data erasure to prevent data breaches during transport and secure point-to-point and chain-of-custody transportation options. HOBI prioritizes data protection at every step and processes all equipment in compliance with NIST standards. In addition to its R2v3, RIOS, and ISO 14001 certifications, HOBI is NAID AAA certified. HOBI’s internally developed proprietary data erasure tool, HOBI Shield, makes us uniquely qualified for secure data destruction.
Data storage is evolving, and so are industry standards. Don’t wait for a breach to update your policies. Contact HOBI today at 877-814-2620 or sales@hobi.com to request a sanitization policy review.