If you handle Controlled Unclassified Information for the Department of Defense, the rules for retiring the media that holds it have not gotten looser this year, even though a headline deadline moved. This post walks through where the requirements stand as of September 2026, what the three governing documents actually say about sanitizing CUI media, and why our recommendation for CUI has hardened from "sanitize to NIST 800-88" to "destroy it, on your site, with a certificate."
Where things stand in September 2026
The CMMC program rule, 32 CFR Part 170, took effect December 16, 2024. The contracting rule that puts it into contracts, DFARS 252.204-7021, was published September 10, 2025 and took effect November 10, 2025. That started Phase 1: new solicitations began requiring Level 1 and Level 2 self-assessments, recorded in the Supplier Performance Risk System and backed by an affirmation from a senior company official. An inaccurate affirmation carries False Claims Act exposure.
Phase 2, which would have made third-party C3PAO certification a condition of award for most CUI contracts starting November 10, 2026, was suspended on July 13, 2026 while a CMMC Reform Task Force reviews the program. No replacement date has been set. What did not change: DFARS 252.204-7012 still requires you to implement NIST SP 800-171; Phase 1 self-assessments and affirmations remain in force; your prime's flow-down still binds you; and the Department of Justice's Civil Cyber-Fraud Initiative still treats a false cybersecurity attestation as a false claim.
Read that as a shift, not a reprieve. Under the original plan, an assessor would have checked your media sanitization evidence and signed off. Under the plan you actually have, a senior official at your company checks it and signs. The scrutiny did not go away. It moved from a third party's clipboard to your name.
The three documents that govern CUI media
1. NIST SP 800-171, requirement 3.8.3
The requirement is one sentence: sanitize or destroy system media containing CUI before disposal or release for reuse. (Revision 3 renumbers it 03.08.03 and adds "release out of organizational control"; CMMC assessments currently use Revision 2.) The assessment guide, NIST SP 800-171A, turns it into objectives an assessor tests: that media containing CUI is sanitized or destroyed before disposal, and before release for reuse. Two neighboring requirements matter for disposal too. Requirement 3.8.4 says media containing CUI must be marked, so it can be identified as CUI-bearing when it is retired. Requirement 3.8.7 controls removable media, which is where the drive you forgot about usually lives.
Notice what 3.8.3 does not do. It does not tell you how. For that it points to NIST SP 800-88.
2. 32 CFR 2002 and DoDI 5200.48
The federal CUI rule, 32 CFR 2002.14, requires that CUI be destroyed by a method that makes it unreadable, indecipherable, and irrecoverable, using either the guidance in NIST SP 800-88 or any method approved for the destruction of classified national security information. The Department's implementing instruction, DoDI 5200.48, carries the same standard into DoD and its contractors: when CUI is no longer needed, destroy it so it cannot be read, deciphered, or recovered, by a method aligned with NIST 800-88.
That second option is worth underlining. The rule explicitly accepts classified-grade destruction, meaning NSA/CSS Policy Manual 9-12 methods on Evaluated Products List equipment, as a way to sanitize CUI. Nothing you can do to a drive exceeds that bar.
3. DCSA's guidance for destroying CUI
The Defense Counterintelligence and Security Agency is the cognizant security office for cleared contractors, and its guidance for industry on destroying CUI is specific. For paper, cross-cut shredding to particles no larger than 1 mm by 5 mm, or a disintegrator with a 3/32-inch screen; an ordinary office shredder does not qualify. If you use a shredding service, confirm its particle size in writing and get certificates of destruction. For electronic media, DCSA points to NIST SP 800-88 and to NSA/CSS Policy Manual 9-12 for the sanitization decision. And for cleared facilities, CUI handling has become part of the conversation during DCSA security reviews, alongside the classified program.
What "sanitize" has to mean for CUI
NIST SP 800-88 Revision 2, final since September 2025, defines three methods. Clear defeats recovery with ordinary tools and is appropriate only when the media stays inside your organization. Purge defeats laboratory recovery and is the floor for media leaving your control. Destroy makes the media unusable. For CUI media that is leaving your control, which is every retired drive, the choice is Purge or Destroy.
A defensible Purge has four parts, and every one is an assessment objective in practice:
- The right technique for the media. Revision 2 no longer lists techniques; it points to IEEE 2883-2022. A SATA hard drive, a SATA SSD, an NVMe drive, and a hybrid drive with solid-state cache each need a different command, and some drives implement the command incorrectly or not at all. Degaussing purges a magnetic drive and does nothing to an SSD.
- Verification. A purge that was not verified is an assertion. You sample the media afterward with a tool that reads what is actually there.
- Documentation. A record per device: serial number, method, tool and version, verification result, operator, date.
- A plan for failures. Drives that fail verification, do not support the command, or are dead cannot be purged. They get destroyed. Decide that before the pile is on the bench.
If your program does all four on every device, every time, Purge is defensible for CUI. Most programs we see do two of them.
Why we now recommend destruction
For years our advice for CUI was "sanitize to NIST 800-88 and document it," which left the Purge option open. We have moved to recommending physical destruction for CUI media as the default, for six reasons.
- The evidence is the point, and destruction produces its own. An assessor, or the senior official signing your affirmation, needs to know that every CUI drive was sanitized. A purge program proves that with a log that must be complete and correct for every serial. A destruction program proves it with a certificate and a bin of particles. One of those can be wrong without anyone noticing.
- The media got harder to purge. Hybrid drives hide solid-state cache that a degausser cannot reach. The NSA's February 2026 reissue of Policy Manual 9-12 says hard drives made after 2020 may be heat-assisted magnetic recording drives, which no degausser can erase. Every new media type is another way for a purge to silently fail.
- Human error scales with volume. A refresh of two hundred laptops means two hundred correct commands, two hundred verifications, and two hundred records. Shredding two hundred drives is an hour on a truck, watched by your own staff.
- The rule already accepts it. 32 CFR 2002.14 names classified-grade destruction as an approved CUI method. Destroying CUI media on NSA-listed equipment is not over-engineering; it is the ceiling of what the rule contemplates, and the one an assessor never argues with.
- The affirmation is personal now. With Phase 2 suspended, no third party stands between your sanitization program and the signature in SPRS. The senior official who signs should be able to say how every CUI drive was handled without consulting a log they hope is complete.
- The economics changed. The reason to purge instead of destroy is resale value. A defense contract, and the False Claims Act exposure that comes with a bad affirmation, is worth more than the used-laptop market. Destruction costs a few dollars a drive. A finding costs the contract.
What we recommend for CUI media
- Mark and inventory. Every CUI-bearing device is marked (3.8.4) and its serial captured before it leaves service. Unmarked media gets the same treatment as marked media.
- Destroy on-site, witnessed. Magnetic drives degaussed on an EPL-listed degausser and shredded; solid-state media, including M.2 cards and hybrid-drive boards, disintegrated. We default CUI solid-state media to the 2 mm standard because it removes the question. Your staff watch.
- One certificate per job, one line per serial. Method, machine, date, operator, witness. This is the artifact 800-171A asks for and the one the affirming official should keep.
- Chain of custody for anything that travels. CUI is unclassified and may ship by tracked carrier under 32 CFR 2002. Tamper-evident packaging, a tracking number, and a photograph of the sealed box on arrival close the record. Classified media never ships.
- Paper to the DCSA specification. Cross-cut to 1 mm by 5 mm or disintegrated through a 3/32-inch screen, with a certificate. We do not shred paper ourselves; ask your paper vendor for the particle size in writing, and we can refer you to one we trust.
- Ask your vendor about their own program. A destruction vendor that holds your CUI media is part of your supply chain. Mansfield Technologies has completed the CMMC Level 1 self-assessment and affirmed it in SPRS, and we say so before you ask.
- Write it into the SSP. Your System Security Plan should say CUI media is physically destroyed to NIST 800-88 Destroy, name the standard for solid-state media, and point to where the certificates live. Assessors read the SSP first.
- If you purge anyway, meet the bar. Media-specific technique per IEEE 2883, verification, per-device records, and a destruction path for failures. If you cannot do all four, do not purge.
The short version
NIST 800-171 says sanitize or destroy CUI media before it leaves your control. 32 CFR 2002 and DoDI 5200.48 say the result must be irrecoverable and accept classified-grade destruction as a method. DCSA says confirm the particle size and keep the certificates. CMMC's third-party deadline is suspended, which means the person vouching for all of that is you. Destroy the media, keep the certificate, and the question never comes up. How we destroy to each standard, or tell us what you have.
