Industry Briefing

ITAD / Compliance

NIST’s updated media-sanitization guide shifts focus from tool lists to enterprise programs.

What SP 800-88 Revision 2 changes for data-center and IT-estate exits—and why a certificate alone is not a complete disposition program.

Published September 12, 20264 min read

When a facility closes a data hall or empties a server room, the last visible work is often de-racking and trucking. The last defensible work is proving that sensitive information on retired media cannot be recovered for a given level of effort. That is media sanitization—and in September 2025, NIST replaced its long-standing Revision 1 guidance with Special Publication 800-88 Revision 2.

NIST says the revision supersedes the December 2014 edition and moves away from a technique-by-technique decision aid toward an agency or enterprise program for disposal and reuse. It also places greater emphasis on current methods, trust in vendor implementations, and alignment with broader security controls.

For a facility-transition team, “we wiped the drives” is not a complete project story. A defensible package needs serialized inventory, a documented decision for each media class, evidence the method matches sensitivity, and a chain of custody into reuse, recycle, or destruction. This is an operational interpretation of the guidance—not a claim that NIST mandates a single commercial certification or ITAD provider.

Teams planning a colo exit, consolidation, or hardware refresh should start the sanitization-program discussion during the first assessment phase, before the removal calendar is fixed.