Reference Guide

NIST SP 800-88, Explained

The standard that defines what “certified data destruction” actually means: three sanitisation categories — Clear, Purge and Destroy — each with a different assurance level and a different effect on whether the device can be reused.

Full title: NIST Special Publication 800-88 — Guidelines for Media Sanitization.

The three categories at a glance

  • Clear

    Overwrite — drive reusable

  • Purge

    Firmware erase — drive reusable

  • Destroy

    Physical destruction — media unusable

What is NIST SP 800-88?

The benchmark for certifiable data destruction

Published by the US National Institute of Standards and Technology, NIST SP 800-88 is the most widely referenced framework for media sanitisation — securely removing data from hard drives, SSDs and other storage so it cannot be recovered. It defines three escalating categories and maps each media type to the methods that achieve them.

In the UK it is not a legal requirement, but it is the recognised benchmark that certifiable destruction is measured against, used alongside NCSC secure sanitisation guidance and BS EN 15713 for physical shredding.

Clear Purge Destroy
The Three Sanitisation Categories

From reusable to unusable

Three escalating levels of assurance — and three different outcomes for the device.

Hard drive cleared and reusable

Clear

Logical overwrite of all user-addressable storage locations so data cannot be recovered using standard software. Media stays intact and reusable.

  • Protects against basic recovery tools
  • Drive can be reused or resold
  • Typical for working office drives
Drive stays reusable
Secure erasure in progress

Purge

Firmware or cryptographic techniques — ATA Secure Erase, NVMe Sanitize, crypto-erase — that make recovery infeasible even to state-of-the-art laboratory methods. Media stays intact and reusable.

  • Defeats laboratory-grade recovery
  • Drive can be reused or resold
  • Preferred for SSDs & NVMe
Drive stays reusable
Media physically shredded and destroyed

Destroy

Physical destruction — shredding, crushing or disintegration — rendering the media unusable and the data unrecoverable. In the UK, shredding is typically to BS EN 15713 particle size.

  • Highest assurance level
  • Media cannot be reused
  • Used for failed or high-risk media
Media rendered unusable

How to Choose a Method

The right category depends on the media, its condition, and what you plan to do with it.

SituationRecommended categoryWhy
Working drives, resale or reuse intendedPurge or ClearKeeps the media intact so residual value is recovered, while meeting the assurance level required.
Failed, damaged or non-readable drivesDestroyA drive that cannot be verified as sanitised cannot be trusted — it is shredded instead.
High-security or regulated estatesPurge, with Destroy for exceptionsLaboratory-grade assurance for everything sanitised, with physical destruction for anything that fails.
SSDs & NVMePurge (firmware sanitise)Secure Erase or NVMe Sanitize is the reliable method; degaussing has no effect on flash storage.
TFix data sanitisation certificate showing the verified method applied
The one rule that matters

If it can’t be verified, it’s destroyed

A device is only “sanitised” if the method can be verified. If erasure cannot be confirmed, the device is physically destroyed — never resold, never exported, never assumed clean. That is the capability-led workflow TFix applies to every asset, and the per-device certificate is the evidence that verification actually happened.

In Practice

How TFix Applies NIST SP 800-88

Capability-led, per device

No two devices get the same treatment by accident. Every drive is assessed on arrival and routed through the most capable method it supports — never a weaker one just because it is faster or cheaper.

  • Purge where supported — controller-level NVMe Sanitize or ATA Secure Erase for SSDs, NVMe and supported HDDs.
  • Clear where policy permits — verified logical overwrite for working media destined for reuse or resale.
  • Destroy the rest — anything that cannot be reliably sanitised is physically shredded, never resold.

The outcome is one consistent rule across the whole estate: the strongest available method wins, and every result is evidenced on a per-device certificate.

Aligned with UK guidance

NIST SP 800-88 sits alongside NCSC secure sanitisation guidance and BS EN 15713 shredding, so the outcome is both technically robust and defensible under UK GDPR and the Data Protection Act 2018.

Serialised evidence

Every outcome — method, serial number, pass/fail status and date — is recorded on a per-device Certificate of Destruction, the audit evidence that proves sanitisation actually happened.

Source of the standard

Read the published guidance itself in the NIST SP 800-88 Rev.2 PDF we make available alongside our erasure workflow.

NIST SP 800-88 FAQs

Is NIST SP 800-88 a legal requirement in the UK?

No. NIST SP 800-88 is a US standard, not UK law. UK organisations adopt it as recognised good practice for certifiable data destruction, usually alongside NCSC secure sanitisation guidance and BS EN 15713 for physical shredding. The legal requirement comes from UK GDPR and the Data Protection Act 2018, which require that personal data be destroyed and that you can evidence it.

What is the difference between Clear, Purge and Destroy?

Clear applies logical overwrite so data cannot be recovered with standard software, keeping the media reusable. Purge uses firmware or cryptographic techniques so data cannot be recovered even by laboratory methods. Destroy physically breaks the media so it cannot be used at all. Clear and Purge preserve reuse value; Destroy provides the highest assurance for failed or high-risk media.

Does erasure keep the drive usable?

Yes. Clear and Purge leave storage media intact and reusable, which is what makes resale and asset recovery possible. Only the Destroy method renders media unusable. TFix applies the most capable method a device supports, and physically destroys anything that cannot be reliably sanitised.

Why do SSDs need Purge rather than simple overwrite?

Solid-state drives spread writes across hidden flash cells, so a simple overwrite may not reach every location. Firmware-level Purge — ATA Secure Erase or NVMe Sanitize — instructs the controller to sanitise the entire media, which is the reliable method for flash storage.

NIST 800-88 erasure, evidenced

Certified data destruction with a serialised certificate per device

Purge-level secure erase or BS EN 15713 shredding, with every device serialised and evidenced — from £10 per drive.