Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    contact@mansfieldtech.us

Data destruction standards

Deleting files or formatting a drive does not remove the data. Overwriting is slow, hard to scale, and fails silently on modern media. Physical destruction is the only method that gives you certainty, and the standard you are held to decides how small the pieces have to be and who has to watch.

Last reviewed September 2026.

Which standard is right for you?

A short guide. Your auditor, PSO, or security officer has the final word; we can help you make the case.

  • Classified or national security media
    NSA/CSS Policy Manual 9-12, reissued February 2026. Solid-state media disintegrated to 2 mm or smaller; magnetic media degaussed on an EPL degausser and then deformed; hybrid drives separated so the board is disintegrated; HAMR drives incinerated, because nothing else works on them (why). At your facility, in your custody, under the supervision of your cleared personnel. Very few mobile providers can do this. We can.
  • Special Access Program material
    DoDM 5205.07, the DoD (Department of War) SAP Security Manual reissued in January 2025. Section 4.9 requires NSA/CSS-approved equipment and procedures; two SAP-briefed people for accountable material, both signing a destruction certificate that itemizes each item by control and copy number; CA SAPCO approval before any commercial destruction service is used, under conditions no less restrictive than TS/SCI; and no SAP waste accumulating past 30 days. SAP IT equipment follows supplemental DoD SAPCO guidance, and SAP systems follow the JSIG. Our part: the NSA-listed equipment comes to your SAPF, your briefed personnel handle and witness, and nothing leaves the perimeter intact.
  • Federal agencies, contractors, and anyone citing NIST
    NIST SP 800-88 Rev. 2, final since September 2025. Choose Destroy for media leaving your control. The certificate documents the method, the equipment, and each device.
  • Anyone holding CUI
    NIST SP 800-171 requirement 3.8.3 and, for defense contractors, CMMC 2.0. Media holding CUI is sanitized or destroyed before disposal, with the evidence an assessor can follow. CUI is unclassified, so it can travel by tracked carrier; see Shred by Mail.
  • Healthcare
    HIPAA Security Rule disposal requirements, satisfied by NIST 800-88 destruction with documentation.
  • Law enforcement and courts
    CJIS Security Policy media disposal, witnessed and documented.
  • Banks, lenders, insurers
    GLBA and the FTC Safeguards Rule, plus the FACTA Disposal Rule for consumer report information.
  • State and local agencies with federal tax information
    IRS Publication 1075. FTI media is sanitized or destroyed to NIST 800-88 and the destruction is documented for the IRS Safeguards review.
  • Merchants and payment processors
    PCI DSS 4.0 Requirement 9.4: media with cardholder data is destroyed when no longer needed and electronic media is rendered unrecoverable.
  • Schools and universities
    FERPA and PPRA for student records, usually alongside HIPAA for campus health and GLBA for financial aid.

Three methods people ask about

"Wiping" (Clear and Purge)

Wiping is not a technical term. NIST 800-88 Rev. 2 defines Clear, Purge, and Destroy, each with a different level of assurance, and Purge techniques are media-specific: a SATA hard drive, a SATA SSD, an NVMe drive, and a phone each need a different command, and some drives do not implement it correctly. The standard now sends organizations to IEEE 2883 for that media-by-media guidance. Every step of a wipe is a place for human error; destruction removes the steps.

Encryption (cryptographic erase)

Cryptographic erase is fast, but it assumes the key was never exposed and that today's algorithm stays unbroken. NIST 800-88 Rev. 2 accepts it as a Purge technique only when the implementation and key handling can be verified. Australia's signals directorate has set 2030 as the date to retire many of the encryption standards in common use today. For anything with a long shelf life, we recommend physical destruction, even for private companies.

Overwriting (the "DoD 5220.22-M wipe")

The three-pass wipe people still cite comes from a manual that no longer exists. The NISPOM moved to 32 CFR Part 117 in 2021 and does not specify a wipe pattern, and NIST 800-88 Rev. 2 points technique selection at IEEE 2883. Overwriting works on some magnetic media and fails silently on others: bad sectors, SSD wear-leveling, and hidden areas keep data the software cannot reach. Destruction removes the question.


The standards, in one place

  • NSA/CSS Policy Manual 9-12
    Destruction of classified and national security media, using equipment on the NSA/CSS Evaluated Products Lists. Reissued February 19, 2026: magnetic drives are degaussed on a listed degausser and then deformed (any hard drive shredder qualifies for that step), solid-state media is disintegrated to 2 mm, hybrid drives have their circuit boards separated and disintegrated, and heat-assisted magnetic recording (HAMR) drives, which no degausser can erase, may only be incinerated. One of very few mobile providers able to do this on-site, on American-made, EPL-listed machines. Read our guide
  • DoD (Department of War) SAP Security Manual, DoDM 5205.07
    Reissued January 17, 2025 as a single manual. SAP material and the equipment holding it must be destroyed on NSA/CSS-approved equipment; accountable material by two SAP-briefed people who both sign a destruction certificate that itemizes control and copy numbers. Outside destruction services are permitted only with CA SAPCO approval, under conditions no less restrictive than TS/SCI, and SAP waste cannot sit for more than 30 days. We bring the listed equipment to your SAPF and work under your PSO's conditions; your briefed personnel handle the material and sign.
  • NIST SP 800-88 Rev. 2
    The federal baseline for media sanitization, final as of September 26, 2025, replacing the 2014 revision. Clear, Purge, and Destroy remain the three methods, and technique selection now points to IEEE 2883. Our Certificate of Destruction documents the Destroy method, the equipment used, and each device processed. Read our guide
  • CMMC 2.0 and NIST SP 800-171
    Requirement 3.8.3: sanitize or destroy system media containing CUI before disposal or release for reuse. Assessors want the method, the certificate, and the chain of custody. We give you all three, on-site or by mail. Read our guide
  • HIPAA
    Protected health information on drives, tapes, and imaging systems. On-site destruction under your supervision keeps PHI inside your building until it no longer exists. Read our guide
  • CJIS Security Policy
    The FBI's requirements for criminal justice information, including media disposal by authorized personnel with documented destruction.
  • GLBA, FTC Safeguards Rule, FACTA
    Financial and consumer-report data. FACTA's Disposal Rule requires reasonable measures to make the information unrecoverable. Read our guide
  • FERPA and PPRA
    Student records held by schools, districts, and universities.
  • IRS Publication 1075
    Federal tax information held by state and local agencies: revenue, child support, and human services departments most often. Publication 1075 requires FTI media to be sanitized or destroyed to NIST 800-88 and the destruction documented.
    Where it comes up: Martinsburg, Columbus, Charleston, Lansing
  • PCI DSS 4.0
    Requirement 9.4 covers media holding cardholder data: destroyed when no longer needed, with electronic media rendered unrecoverable. Retailers, processors, and anyone with a card terminal.

Primary sources

Read the documents themselves. Every rule on this page traces to one of these, the glossary defines the terms they use, the Certificate of Destruction is what you receive when we have met them, and the case studies show what happens when they are ignored.

Not sure which applies? Ask us.

Request a consultation