Legal Cyber Academy
Standard or guidanceFreeCurrent

Guidelines for Media Sanitization

Ramaswamy Chandramouli, Eric Hibbard · National Institute of Standards and Technology · Revision 2, September 2025 · 2025

Identifier: NIST SP 800-88 Rev. 2

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

NIST's guidance on clearing, purging and destroying data on storage media, including media-specific techniques and verification. Revision 2 was published in September 2025 and supersedes Revision 1 (2014), which NIST withdrew on 26 September 2025.

Who it is for, and when

The reference to cite when you are assessing a wiping or destruction claim: whether a stated method would actually have removed the data, what residual data to expect, and what verification should have been documented. Relevant in spoliation and anti-forensics disputes, and in decommissioning policy review.

What it does not cover

It is a sanitization standard, not a recovery manual: it will not tell you how to carve or reconstruct data from partially wiped media, and it makes no claims about what a given commercial wiping tool actually does. Anyone citing Revision 1 after September 2025 is citing a withdrawn document.

Go to the source

Open at csrc.nist.gov (opens in a new tab)

https://csrc.nist.gov/pubs/sp/800/88/r2/final

Details

Type
Standard or guidance
Written for
Working examinerLawyers and courtsWorking examiner, Lawyers and courts
Author
Ramaswamy Chandramouli, Eric Hibbard
Publisher
National Institute of Standards and Technology
Version verified
Revision 2, September 2025
Year
2025
Identifier
NIST SP 800-88 Rev. 2
Topics
media-sanitization, anti-forensics, evidence-handling, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.

  • A short, dense book about the physics of digital evidence: the order of volatility, how long deleted data actually persists, what abstraction layers hide, and how to reason about an adversary who has had root. Examples come from Solaris, FreeBSD and Linux.

  • An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.

  • NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.

  • A pocket flipbook companion to NIJ's first responder guide, condensing device types, scene securing, documentation, collection and packaging into an on-scene quick reference, with digital evidence considerations by crime category.