In September 2025, NIST published SP 800-88 Revision 2 and removed all device-specific sanitisation technique guidance from the standard. For that detail, NIST now explicitly directs organisations to IEEE 2883:2022.
The two standards operate at different levels of the same compliance requirement. Both are necessary. Neither is sufficient on its own.
Why NIST Removed the Technique Guidance
Revision 1 included detailed appendices mapping sanitisation techniques to specific media types. By 2025, those tables were outdated. NVMe drives, self-encrypting drives, cloud storage, and virtualised environments had all changed the landscape significantly since 2014.
Rather than update the tables with every technology shift, Revision 2 removed them and pointed permanently to IEEE 2883:2022, which is maintained specifically to stay current with storage technology. NIST covers governance, IEEE covers technique. That division is now explicit and permanent.
What Each Standard Does
NIST SP 800-88 Rev 2: The Governance Framework
Rev 2 tells organisations how to build and run a sanitisation programme. It covers:
- How to assess data sensitivity and select the appropriate sanitisation category. Clear, Purge, or Destroy
- What policies, roles, and processes a compliant programme requires
- How to verify and validate sanitisation outcomes
- What cryptographic erase requires. including cryptographic strength and key management
- How sanitisation decisions should be applied across the full asset lifecycle, from acquisition to disposal
Rev 2 does not specify which algorithm to run on a specific drive. That is IEEE’s job.
IEEE 2883:2022: The Technical Standard
IEEE 2883:2022 specifies exactly how to sanitise each type of storage device. It covers:
- Sanitisation techniques for HDDs, SSDs, NVMe drives, and flash-based storage
- Interface-specific guidance for ATA, SCSI, NVMe, and other storage interfaces
- Alternative compliant techniques where a primary method cannot be applied to a specific device
- Clear and Purge technique definitions that map directly to NIST’s sanitisation categories
How They Work Together
In practice, the two standards operate as a sequence:
- NIST SP 800-88 Rev 2 establishes that a device needs to be sanitised to Purge standard, based on the sensitivity of the data it held.
- IEEE 2883:2022 specifies the correct technique for that device type. block erase, cryptographic erase, overwrite with verification, or another method appropriate to the media and interface.
- NIST SP 800-88 Rev 2 requires the outcome to be validated, documented with a tamper-proof audit record, and retained as part of the organisation’s sanitisation programme.
Without IEEE, organisations have a governance framework but no technique guidance for modern media. Without NIST, they have technical methods but no programme structure, decision logic, or validation requirements.
What This Means for Enterprise IT
A compliant sanitisation programme now needs to satisfy both standards simultaneously:
- Sanitisation policy documented and tied to data classification (NIST)
- Erasure tools applying the correct technique for each specific media type (IEEE)
- Every erasure validated and recorded with a tamper-proof, device-level certificate (NIST)
- Audit trail demonstrating both the decision made and the outcome achieved
Tooling that claims NIST compliance but makes no reference to IEEE 2883:2022 needs scrutiny. Specifically, which techniques it applies and whether those align with the current standard.
What This Means for ITAD Providers
Enterprise clients under regulatory scrutiny need to demonstrate that their ITAD partner is operating to current standards, not 2014 ones. Explicit IEEE 2883:2022 compliance alongside NIST SP 800-88 Rev 2 alignment is a direct and verifiable proof point in that conversation.
Recoverable data from a device you processed is a liability. The question that follows will be whether your process met current standards. and “we followed Rev 1” is not an answer anyone wants to give.
Where Ziperase Fits
Ziperase is compliant with NIST SP 800-88 R1 & R2 and IEEE 2883:2022.
Our core products are ADISA Product Assurance L5 and Common Criteria EAL2 certified – independent, third-party validation that our erasure performs as claimed. Mobile Erase and Device Link hold ADISA Product Claims certification. Every erasure generates a digitally signed, tamper-proof certificate automatically, with centralised audit logging and verified outcomes at every step.
Built by a team with 20+ years in certified data erasure, we understand what these standards demand in practice, not just on paper.
Start a free trial and see certified, automated data erasure in action.