NIST 800-88 Explained: What Data Sanitisation Really Means for UK Businesses
All articles
Journal 2 August 2026 3 min read

NIST 800-88 Explained: What Data Sanitisation Really Means for UK Businesses

Clear, Purge and Destroy — what the three NIST 800-88 sanitisation levels actually mean, when each is appropriate, and why 'we wiped it' is not a compliance answer.

Why a US standard matters to a UK business

UK GDPR tells you that personal data must be protected with appropriate measures, but it deliberately does not prescribe a technical method. NIST Special Publication 800-88 ("Guidelines for Media Sanitization") fills that gap. It is the standard most UK IT disposal providers, auditors and insurers reference, because it defines verifiable outcomes rather than vague reassurance.

In practice, saying "we sanitise to NIST 800-88 Purge, verified, with a certificate" is a defensible answer. Saying "we format the drives" is not.

The three levels, in plain English

LevelWhat it doesRecovery riskTypical use
ClearOverwrites user-addressable storage using standard read/write commandsProtects against software-based recoveryDevice staying inside your organisation — reissued to another employee
PurgeUses firmware-level commands (ATA Secure Erase, NVMe Format, cryptographic erase) to render data infeasible to recover, even in a labProtects against state-of-the-art laboratory recoveryDevice leaving your organisation — resale, donation, lease return
DestroyPhysically shreds, disintegrates or incinerates the mediaMedia can no longer be used at allFailed, locked or unverifiable drives; highest-sensitivity data

The rule that catches people out: verification

NIST 800-88 does not treat sanitisation as complete when the wipe finishes. It requires verification — confirming the process actually did what it claimed — and documentation. A wipe that reports success on a drive with failing sectors has not necessarily sanitised those sectors.

This is why a serious process always ends one of two ways: a verified wipe with a pass result, or physical destruction when verification cannot be achieved. There is no third option where a drive is "probably fine".

Fragments of shredded hard drive platters and circuit boards
Where a drive cannot be verifiably wiped, destruction is the only defensible outcome.

SSDs are not hard drives

Overwriting works well on spinning magnetic disks. On SSDs it is unreliable, because wear levelling means the controller may write your overwrite pattern to entirely different physical cells, leaving the original data intact in spare blocks. For flash media, NIST points to:

  • Cryptographic erase — destroying the encryption key on a self-encrypting drive, making the ciphertext unreadable
  • Firmware sanitise commands — the drive's own block erase across all cells, including spares
  • Physical destruction — where the controller is unresponsive or the drive is out of warranty and locked

The same caution applies to eMMC storage soldered into thin laptops and tablets, and to the flash in modern printers and multifunction devices — a routinely overlooked source of scanned documents.

Don't forget these devices

  • Multifunction printers and copiers with internal drives
  • Network appliances, firewalls and NAS units
  • VoIP handsets and video conferencing systems
  • USB sticks, SD cards and external backup drives in desk drawers
  • Backup tapes — see our backup tape destruction service

What your evidence should look like

If the ICO, an auditor or a client asks how you disposed of a device, you should be able to produce a record showing:

  1. The device make, model and serial number
  2. The sanitisation method applied and the standard it maps to
  3. The verification result
  4. The date, the operator or organisation, and a signature
Compliance is not what happened to the drive. It is what you can prove happened to the drive.

How ByeByte handles it

Every data-bearing device we collect is sanitised to NIST 800-88. Healthy drives are purged and verified; anything that cannot be verified is physically destroyed. Both routes are recorded against the device serial and issued to you as a signed Certificate of Destruction — free of charge, as part of our collection service. Once data is removed, devices that are still functional or can be made functional are made available for charities and non-profits to receive free of charge; equipment that cannot be repurposed is scrapped down for its raw materials.

Items which cannot be repurposed are scrapped down for their raw materials. Devices which are still functional or can be made functional are made available for charities and non-profits to receive free of charge.

See our data destruction service or arrange a collection.

The Byebyte Team
Free UK collection · NIST 800-88 data destruction · Zero to landfill

Ready to clear out your old IT?

Free collection, secure data destruction, zero to landfill. No minimums, no cost — just get in touch.