Regulations & Standards Compliance

Federal, industry, and international standards for secure media sanitization and data destruction. Select a regulation for requirements, methods, audit documentation, and how Data Destruction Inc. maps services to each standard.

CMMC 2.0 Media Sanitization: Defense Contractor Requirements for CUI

Federal Framework

CMMC 2.0 Media Sanitization: Defense Contractor Requirements for CUI

The Cybersecurity Maturity Model Certification (CMMC) 2.0 program, codified at 32 CFR Part 170 and effective December 16, 2024, requires defense contractors handling Controlled Unclassified Information to implement media sanitization practices per NIST SP 800-88 r2. Failure to comply disqualifies a contractor from DoD contract awards. Data Destruction Inc. provides witnessed, documented NIST SP 800-88 r2 Destroy-level destruction for defense contractors at every CMMC level.

Learn more
DoD 5220.22-M Standard: History, Deprecation, and Modern Replacements

Federal Framework

DoD 5220.22-M Standard: History, Deprecation, and Modern Replacements

DoD 5220.22-M, the National Industrial Security Program Operating Manual, contains the historical three-pass overwrite methodology that became synonymous with "government-grade" data wiping. That methodology is no longer the federal standard for media sanitization. NIST SP 800-88 r2 (September 2025) supersedes it as the basis for all federal and defense contractor media sanitization requirements. This page explains what DoD 5220.22-M was, why it was replaced, and what organizations must use today.

Learn more
FACTA Disposal Rule: Secure Disposal of Consumer Report Information

Federal Law

FACTA Disposal Rule: Secure Disposal of Consumer Report Information

The FACTA Disposal Rule, 16 CFR Part 682, requires any person or company that maintains or possesses consumer information derived from a consumer report to take reasonable measures to protect against unauthorized access or use of that information when disposing of it. The rule applies to virtually every business in America that uses credit reports, background checks, or employment screening. Data Destruction Inc. provides NIST SP 800-88 r2 Destroy-level shredding that satisfies the "reasonable measures" standard.

Learn more
FISMA: Federal Information Security Requirements for Media Disposal

Federal Law

FISMA: Federal Information Security Requirements for Media Disposal

The Federal Information Security Modernization Act (FISMA) of 2014, at 44 U.S.C. §3551 et seq., requires federal agencies to implement information security programs that protect federal information systems. Media disposal is a required component of every FISMA program. FISMA does not define its own destruction methods; it directs agencies to follow NIST SP 800-88 r2 for media sanitization. Data Destruction Inc. provides NIST SP 800-88 r2 Destroy-level shredding with documentation structured for FISMA audit requirements.

Learn more
GLBA Safeguards Rule: Data Disposal Requirements for Financial Institutions

Federal Law

GLBA Safeguards Rule: Data Disposal Requirements for Financial Institutions

The Gramm-Leach-Bliley Act Safeguards Rule, 16 CFR Part 314, requires financial institutions to implement a written information security program that includes proper disposal of customer financial information. The amended rule, effective June 9, 2023, added explicit disposal requirements and applies to every financial institution under FTC jurisdiction regardless of size. Data Destruction Inc. provides NIST SP 800-88 r2 Destroy-level shredding that satisfies the disposal requirement.

Learn more
HIPAA Disposal Rule: Media Destruction Requirements for Covered Entities

Federal Law

HIPAA Disposal Rule: Media Destruction Requirements for Covered Entities

The HIPAA Security Rule at 45 CFR §164.310(d)(2) requires covered entities and business associates to implement policies that render electronic protected health information unreadable and unrecoverable before disposal. Data Destruction Inc. satisfies this requirement through shredding and crushing classified as NIST SP 800-88 r2 Destroy, with a serialized Certificate of Destruction issued within 24 hours.

Learn more
ISO 27001 and ISO 27040: International Standards for Data Destruction

International Standard

ISO 27001 and ISO 27040: International Standards for Data Destruction

ISO/IEC 27001:2022 is the international standard for information security management systems, with Annex A.7.14 requiring secure disposal or reuse of equipment. ISO/IEC 27040:2024 provides detailed technical requirements for storage security, including data destruction. Both are voluntary international standards, not US laws, but are increasingly required by multinational clients, procurement contracts, and organizations seeking ISO 27001 certification. Data Destruction Inc. provides NIST SP 800-88 r2 Destroy-level destruction consistent with ISO 27001 and ISO 27040 requirements.

Learn more
PCI DSS Media Disposal: Requirement 9.4 for Cardholder Data Protection

Industry Standard

PCI DSS Media Disposal: Requirement 9.4 for Cardholder Data Protection

PCI DSS v4.0.1 Requirement 9.4 requires any organization that stores, processes, or transmits cardholder data to securely store, distribute, and destroy media containing that data. Requirements 9.4.6 and 9.4.7 specifically address physical and electronic media destruction, requiring methods that meet accepted industry standards. Data Destruction Inc. provides NIST SP 800-88 r2 Destroy-level shredding with a Certificate of Destruction that satisfies Requirement 9.4 audit requirements.

Learn more