← All Resources
September 1, 2026 Vibrant Technologies Blog ITADNIST 800-88R2v3

"Are You NIST 800-88 Compliant?" Is Now the Wrong Question

"Are You NIST 800-88 Compliant?" Is Now the Wrong Question

It's the line every ITAD RFP contains, and for a decade it resolved cleanly. It doesn't anymore. Two standards that used to point at the same document now point at different ones, and the gap sits exactly where your compliance evidence comes from. 

Ask an ITAD vendor whether they're NIST 800-88 compliant and you'll get a yes. You'll have gotten a yes in 2018, too. The question feels like it does work, which is why it survives in procurement templates. 

Here's the problem. There are now two documents it could refer to, and the certification most enterprises use to vet ITAD vendors still points at the older one. 

That isn't a scandal, and it doesn't mean your vendor is doing anything wrong. But it does mean a yes to that question no longer tells you what you think it tells you, and there are better questions to ask instead. 

What Changed, Briefly 

NIST published SP 800-88 Revision 2 on September 26, 2025, and withdrew Revision 1 the same day. 

Clear, Purge, and Destroy survived intact. What changed is the shape of the guidance around them. Rev. 2 shifts focus from hands-on sanitization decisions toward establishing an enterprise media sanitization program, and aligns that program with broader security frameworks like SP 800-53 and ISO/IEC 27040. It also addresses establishing trust in a vendor's implementation of Clear and Purge techniques — an acknowledgment that the standard is only as good as the party executing it. 

The change with the longest reach: apart from cryptographic erase, the specific sanitization techniques and tool details are gone from the document. In their place, NIST points to IEEE 2883, NSA specifications, or a standard your organization has formally approved. 

Rev. 1 told you how to sanitize a drive. Rev. 2 tells you to have a program, and to follow a recognized technique standard that lives somewhere else. 

Where the Gap Opens 

R2v3 is the operating standard behind most certified ITAD facilities in North America, published by SERI. It's what a buyer is really relying on when they require a certified vendor, because it's independently audited and covers data security as a core requirement. 

R2v3's logical sanitization path for reuse lives in Appendix B. And SERI's own published guidance on that appendix explains the requirement by direct reference to Revision 1 — mapping the Appendix B(13) verification requirement to Rev. 1 Section 4.7.3, and characterizing R2v3 as setting logical sanitization between Clear and Purge as those terms are defined in Rev. 1 Section 2.5. 

So the certification points at a NIST revision that NIST has withdrawn. 

This is normal and worth saying plainly. Standards bodies revise on independent cycles. R2v3 was published well before Rev. 2 existed, and a certification scheme can't re-baseline every time an underlying reference updates — the audit infrastructure, the certification bodies, and every certified facility's documented procedures would all have to move together. Revision lag is the expected behavior of a functioning standards ecosystem, not evidence that something is broken. 

What it means practically is narrower, and it's this: "NIST 800-88 compliant" and "R2v3 certified" are no longer two ways of saying the same thing. A vendor can be entirely truthful in claiming both while operating to Rev. 1's technique definitions. 

Why This Matters to the Person Holding the Risk 

The R2v3 bar is specific, and it's worth understanding rather than glossing. 

Appendix B(13) requires that sanitized data not be recoverable by commercial data recovery software. SERI is explicit that this is deliberately not Purge — Purge means recovery is infeasible even with state-of-the-art laboratory techniques, and R2v3 does not require that level for reuse. The bar sits between Clear and Purge. 

For most commercial data, that's a reasonable and well-reasoned place to draw the line. It's what makes reuse possible at all, which is the entire environmental argument for ITAD. 

But if you're handling regulated data with a long confidentiality horizon — health records, CUI, financial data under a retention obligation, anything where a breach ten years out still counts — then "not recoverable by commercial software" may not be the standard you actually need. And you will not discover that by asking whether your vendor is NIST 800-88 compliant. You'll discover it by asking what level they sanitize to, and why. 

Six Better Questions 

Replace the yes/no question with these. Any competent provider can answer all six without hesitating. 

  1. 1. Which revision does your data sanitization plan cite? If the answer is Rev. 1, that's not disqualifying — but you want to know, and you want to know whether they've assessed what Rev. 2 changes for them. 
  2. 2. Under Rev. 2's framing, which technique standard do you follow? IEEE 2883, an NSA specification, or an internally approved standard. "We follow NIST" is now a circular answer, because Rev. 2 points outward. 
  3. 3. What level do you sanitize to for reuse, versus for destruction? These are different paths with different bars. A vendor who treats them as one answer hasn't thought about it. 
  4. 4. How do you verify, and separately, how do you validate? Verification confirms the process ran. Validation confirms it worked. Rev. 2 takes the distinction seriously and so should your vendor. 
  5. 5. What appears on the certificate, per device? Serial number, method, date of sanitization separate from date of pickup, and the technician. Aggregate counts — "1 pallet, 40 assets" — are not evidence. 
  6. 6. How do you handle SSDs, flash, and encrypted media specifically? Overwrite procedures built for spinning disks never mapped cleanly onto flash. Wear leveling and over-provisioning mean the blocks you think you overwrote may not be the blocks holding the data. If encrypted media is handled by cryptographic erase, ask how keys are sanitized. 

Where to Look in Your Own Documents 

Your policy and your RFP template. Search your information security policy, retention schedule, and disposal SOP for the string "800-88." Anything that says "Revision 1" is now citing a withdrawn document. This is the fastest thing on the list to fix and the most likely to be flagged. 

Your existing certificates. Pull the last three you received and check them against question five above. Most organizations discover their certificates are thinner than they remembered. 

Your contract language. If you're bidding out ITAD this year, write the six questions into the RFP rather than the yes/no version. You'll get materially more informative responses, and you'll be able to tell vendors apart. 

The Devices That Never Make It Into Any of This 

Worth saying while you have the policy open: the most common data exposure in a decommission isn't a badly sanitized drive. It's a device nobody put on the list. 

•   Multifunction printers and copiers. Modern MFPs hold an internal drive with images of everything scanned, faxed, and printed. They're leased, they get collected by the leasing company at end of term, and they rarely appear on an IT decommission inventory because nobody thinks of the copier as IT equipment. 

•   Drives sent back under warranty. A failed drive under RMA leaves your building with your data on it, goes to the manufacturer, and never touches your ITAD process at all. Many organizations have no policy covering this path. 

•   Loose drives already pulled. Drives removed from a chassis before pickup sit outside the chain of custody the moment they're separated from the asset they were tracked under. 

•   Backup tapes and lab gear. Both routinely fall outside the CMDB, which means they fall outside a decommission plan built from the CMDB. 

Where We Land on It 

We're R2v3 certified, and we think the standard is good. The multi-layer approach in Appendix B exists because logical sanitization is genuinely hard to get right, and the reuse path it enables is what keeps working equipment out of a shredder. 

We also think the honest answer to "are you NIST 800-88 compliant?" is a question back: which revision, and what are you trying to protect? A vendor who answers only yes is either not tracking the change or not interested in the distinction. Neither is what you want handling the drives. 

Talk To Us!

Vibrant Technologies has handled enterprise IT disposition since 1998 from an R2v3-certified facility in Eden Prairie, Minnesota. If you want a second set of eyes on your disposal documentation, or you want to know exactly what your certificates will say before you commit to a project, request a free ITAD assessment. We'll scope the work, answer the compliance questions, and show you the paperwork first. 

952-653-1700 | info@vibrant.com | vibrant.com 

Sources