Hard Drive Shredding vs. Degaussing vs. Crushing

Hard drive shredding, degaussing, and crushing address different parts of an enterprise media-sanitization decision. Shredding cuts a hard disk drive into particles. Degaussing applies a magnetic field matched to the drive’s coercivity. Crushing deforms or breaks the drive, but its result depends on the equipment and damage produced.

The correct method depends on the drive technology, information sensitivity, required sanitization outcome, reuse decision, organizational policy, contract, service location, and evidence requirements. A method name alone does not establish that the target data was sanitized.

For executives, technology leaders, risk officers, records managers, and procurement teams, the decision can be summarized as follows:

  • Choose shredding when the organization requires a physical Destroy outcome and does not intend to reuse the drive.
  • Choose degaussing only for suitable magnetic media when the organization can verify that the degausser is matched to the media and the approved outcome is Purge.
  • Choose crushing only when the resulting damage and verification satisfy the organization’s policy. Bending or puncturing a drive does not automatically establish a Destroy outcome.
  • Use a combined process when an applicable policy or contract requires degaussing followed by physical destruction.
  • Use a different method for SSDs and flash media. Degaussing does not sanitize nonmagnetic storage.

Organizations that need project-specific execution can review hard drive destruction services after establishing the required sanitization method and evidence package.

What Is the Main Difference Between Shredding, Degaussing, and Crushing?

Shredding is a destructive fragmentation technique, degaussing is a magnetic Purge technique, and crushing is a physical damage technique whose result must be assessed. These methods differ in media compatibility, NIST outcome, verification, residual material, equipment requirements, and ability to support reuse.

Decision factor Shredding Degaussing Crushing
Primary action Cuts or tears the drive and internal media into particles Applies a reverse magnetic field matched to the media’s coercivity Deforms, bends, punctures, or breaks the drive and internal components
Suitable media HDDs and other media approved for the shredder Suitable magnetic HDDs and magnetic tape HDDs approved for the crusher; result depends on equipment and damage
SSD compatibility Physical shredding can be used with equipment suited to SSD construction Does not sanitize SSDs or flash media May damage an SSD, but the outcome must address all data-bearing components
Typical NIST method Destroy when the technique and result meet the organization’s approved requirement Purge when the field strength is correctly matched and the result is accepted Not determined by the word “crushing”; pulverization can support Destroy, while partial bending or puncturing may not
Drive reuse No Usually no practical reuse; degaussing may damage servo information No practical reuse
Verification focus Inspect remnants and identify equipment used Verify media identification, equipment suitability, operating result, and anomalies Inspect platter and component damage against the approved output requirement
Main decision risk Shred output does not meet the approved requirement Degaussing equipment is not suited to the drive’s coercivity or technology The drive appears damaged while readable platter areas remain accessible
Common enterprise use End-of-life drives requiring physical destruction Suitable magnetic drives under a verified Purge process Controlled physical damage when policy accepts the resulting output, or as a stage before further destruction

The comparison is not a ranking from weakest to strongest. Each method must be evaluated against the organization’s media-sanitization policy and the specific hard drives in scope.

How Does NIST SP 800-88 Rev. 2 Affect the Decision?

NIST Special Publication 800-88 Revision 2 defines Clear, Purge, and Destroy as sanitization methods and requires organizations to select, verify, validate, and document techniques suited to the media and confidentiality risk. It does not make every use of a shredder, degausser, or crusher acceptable by default.

The current NIST publication, issued in September 2025, supersedes Revision 1. NIST defines media sanitization as a process that renders access to target data infeasible for a given level of effort. It also directs organizations to consult current technology-specific standards because storage technologies and sanitization techniques change.

Clear, Purge, and Destroy are outcomes, not product labels

NIST separates sanitization into three methods:

  • Clear uses logical techniques to address data in user-addressable storage locations and protects against less capable recovery efforts.
  • Purge uses physical or logical techniques to make target data recovery infeasible against advanced laboratory capabilities.
  • Destroy makes target data recovery infeasible against advanced laboratory capabilities and leaves the media unable to store data.

This article compares physical methods used with magnetic hard disk drives. It does not replace an organization’s policy decision about whether Clear, Purge, or Destroy is required.

NIST treats degaussing as Purge, not Destroy

NIST SP 800-88 Rev. 2 states that degaussing has historically been used as a physical Purge technique for magnetic tapes, removable magnetic disks, and magnetic HDDs. The degausser’s field strength must be carefully matched to the media’s coercivity.

NIST also identifies two material risks:

  1. A degausser may lack sufficient force for newer magnetic recording technologies.
  2. A drive may become inoperable because servo information was damaged even though the target data was not successfully sanitized.

An inoperable drive is not proof of successful degaussing.

NIST recognizes shredding as a destructive technique

NIST describes shredding as cutting or tearing media into small particles. It places shredding among physical techniques associated with Destroy. The organization must still define an approved output and inspect the remnants during verification.

NIST does not set one universal particle size for every drive, data classification, contract, and destruction machine. The organization must use the current authority and technology-specific requirement that applies to its media and risk.

Crushing requires output-based assessment

NIST distinguishes pulverization from partial damage. Pulverization reduces media to powder or dust through crushing, grinding, or another mechanical process. By contrast, NIST warns that bending, cutting, shooting, or drilling may damage only part of a storage device and leave accessible portions.

A hydraulic press that bends a chassis or punctures a platter should not be called NIST Destroy merely because the equipment is marketed as a hard drive crusher. The organization must inspect the actual result and decide whether it meets the approved sanitization requirement.

Teams applying NIST guidance can use the NIST SP 800-88 Rev. 2 resource to connect policy, method selection, verification, validation, and documentation.

How Does Hard Drive Shredding Work?

Hard drive shredding feeds an HDD into industrial equipment that cuts, tears, or fractures the chassis, platters, electronics, and internal assemblies into smaller pieces. The resulting drive cannot be reused, and the remnants can be inspected against the project’s approved output requirement.

A magnetic HDD stores data on platter surfaces. Effective shredding must address the data-bearing material rather than only damage the enclosure or connector. Equipment configuration, drive construction, feed orientation, cutting mechanism, throughput, and maintenance affect the resulting fragments.

When does shredding fit an enterprise policy?

Shredding fits organizations that have decided to destroy the media rather than preserve it for reuse. Common conditions include:

  • The drive held restricted, regulated, classified, contract-controlled, or proprietary information.
  • The drive is damaged, obsolete, unsupported, or inaccessible through its interface.
  • The organization does not permit the drive to leave its control in reusable form.
  • The organization requires visible physical destruction.
  • The client wants the event performed at its facility.
  • The project involves a high volume of drives that can be processed through an approved workflow.
  • The policy requires a Destroy outcome rather than a reusable Purge outcome.

These conditions do not mean shredding is the only valid method. They explain why an organization may select it after completing a risk assessment.

What are the main strengths of shredding?

Shredding provides four decision advantages:

  1. Visible physical output. Authorized personnel can inspect fragments after the event.
  2. Compatibility with failed drives. The process does not depend on a working interface or operating system.
  3. On-site service availability. Mobile equipment can process approved drives at the client location where access, power, safety, and site conditions permit.
  4. Direct support for a Destroy decision. The method leaves the media unable to function as storage when the approved destructive result is achieved.

Organizations that require observation can combine on-site hard drive shredding with witnessed destruction and asset reconciliation.

What are the limitations of shredding?

Shredding also creates policy and operating constraints:

  • The drive cannot be reused or resold.
  • Material value may be lower than it would be after a reusable sanitization method.
  • Shred output must be defined and verified.
  • Equipment must be suited to the drive type and construction.
  • On-site operations require space, power, safety controls, access, noise management, and material handling.
  • A batch-level record may be insufficient when the organization requires serial-number accountability.
  • Mixed loads can create errors if HDDs, SSDs, tapes, batteries, and devices are not identified before processing.

The correct question is not whether a provider owns a shredder. The correct question is whether the provider can demonstrate that the equipment, process, output, custody, and records meet the approved requirement.

How Does Hard Drive Degaussing Work?

Degaussing exposes suitable magnetic media to a reverse magnetic field intended to reduce recorded magnetic flux and make target data recovery infeasible. The process can support Purge only when the degausser is matched to the media and the operation is verified and accepted.

Hard disk drives store data by changing magnetic states on platter surfaces. A degausser applies a field intended to disrupt those states. Modern magnetic recording technologies can use higher coercivity, which means an older or underpowered degausser may not provide the required result.

Which drives can be degaussed?

Degaussing applies to suitable magnetic storage. It does not sanitize:

  • Solid-state drives
  • NVMe drives
  • USB flash drives
  • Memory cards
  • Optical discs
  • Other nonmagnetic storage components

Hybrid devices and equipment with several storage technologies require component-level identification. An operation can report successful completion while leaving data on an SSD untouched. NIST uses this type of mismatch as an example of failed validation.

Why does coercivity matter?

Coercivity describes the resistance of magnetic media to demagnetization. The degausser must produce a field suited to the target media. A device model, recording technology, or drive generation may have different requirements from older equipment.

An enterprise process should not rely on statements such as “high-powered degausser” without evidence. Procurement and risk teams should require:

  • Degaussing equipment make and model
  • Current maintenance and calibration records
  • Media compatibility information
  • Operating procedure
  • Personnel qualification
  • Cycle completion record
  • Exception handling
  • Verification and validation criteria

Does degaussing destroy the hard drive?

Degaussing often makes an HDD unusable because it can damage servo information required for normal operation. That operational failure does not convert degaussing into a Destroy method. NIST states that degaussing is not an approved Destroy technique at the time of Revision 2.

This distinction matters in policies and audit records:

  • Record Purge when an approved degaussing technique supports Purge.
  • Do not record Destroy solely because the drive no longer starts.
  • Apply a separate physical destruction step if policy or contract requires Destroy.

Organizations considering this method can review hard drive degaussing services and require a media-equipment compatibility review before approving the project.

When does degaussing fit an enterprise policy?

Degaussing can fit when:

  • The assets are confirmed magnetic HDDs.
  • The organization requires Purge.
  • The degausser is suited to each approved drive type.
  • The process includes equipment, operator, cycle, verification, and validation records.
  • The organization accepts that the drives may become unusable.
  • A contract or policy requires degaussing before shredding or another destructive step.

Degaussing is not the correct default for a mixed-media project. The inventory must separate magnetic HDDs from SSDs, hybrid devices, and other media before processing.

How Does Hard Drive Crushing Work?

Hard drive crushing uses mechanical force to bend, puncture, break, or compress a drive and its internal components. Whether the result satisfies a Destroy requirement depends on the equipment, the damage to data-bearing surfaces, the approved output specification, and verification.

The word “crushing” can describe materially different outputs. One machine may puncture the drive housing and one area of the platter. Another may break platters or reduce components further. These results do not carry the same recovery risk.

Why is visible damage not enough?

A damaged enclosure does not prove that all platter surfaces were addressed. If substantial platter areas remain intact, a capable laboratory may be able to access data-bearing material. NIST warns that partial techniques, including bending or drilling, may leave accessible portions.

An organization evaluating crushing should ask:

  • Does the machine only bend the chassis?
  • Does it puncture one point or several points?
  • Does it break, fracture, or reduce all platters?
  • How is the output inspected?
  • What constitutes a failed result?
  • Is a second pass required?
  • Is crushing followed by shredding or pulverization?
  • Which sanitization method is recorded on the certificate?

When can crushing fit a project?

Crushing may fit when organizational policy accepts the defined result and the process is verified. It can also be used as an intermediate control before material is transferred to a shredder or pulverizer.

Potential use cases include:

  • Low-volume on-site projects where approved crushing equipment is practical.
  • Emergency containment followed by controlled final destruction.
  • Drives that must be disabled before leaving a restricted area.
  • Projects that specify platter breakage and inspection.
  • A two-stage process where crushing precedes shredding.

The company and client should not label the outcome as Destroy until the result has been validated against the approved requirement. Buyers can review hard drive crushing services to define the equipment, output, and documentation before scheduling service.

Which Method Provides the Strongest Result?

No method is strongest without reference to the required outcome, media, equipment, and evidence. Shredding directly supports a physical Destroy decision when the approved output is achieved. Degaussing can support Purge for suitable magnetic drives. Crushing ranges from partial damage to pulverization, so its result requires precise definition.

Decision matrix for enterprise buyers

Project condition Preferred direction Reason
Physical Destroy is required Shredding or another approved destructive technique Leaves the HDD unable to store data when the approved result is achieved
Magnetic HDD requires Purge Verified degaussing may be considered Applies a physical Purge technique when field strength matches media coercivity
SSDs are mixed with HDDs Separate the inventory; do not degauss the SSDs Flash storage is nonmagnetic and needs a different method
Drives are failed or inaccessible Physical destruction Logical techniques may not reach the target data
Drives may be reused Do not shred, crush, or rely on degaussing Evaluate a validated logical Clear or Purge technique instead
Drives must remain on-site On-site shredding, approved crushing, or suitable degaussing Reduces transport while preserving client observation and custody
Contract requires two-stage sanitization Degauss, then shred or otherwise destroy as specified Meets the defined sequence when equipment and media are suitable
High volume with serial accountability Shredding or another approved method with reconciliation Supports batch processing while preserving asset records
Crusher only punctures one area Do not assume Destroy Partial platter areas may remain accessible
Evidence package is required Any approved method with verification, validation, and documentation The record must identify what happened, not only the vendor’s service name

Should an organization degauss and then shred?

A two-stage process can be appropriate when a policy, contract, or data classification requires both Purge and Destroy controls. The sequence can reduce magnetic data exposure before physical fragmentation, but it adds equipment, time, handling, verification, and cost.

Do not prescribe degaussing before shredding for every HDD. The organization should require it only when the governing policy, contract, or risk decision supports the added control. For classified information, consult the current applicable agency policy and approved product requirements rather than relying on a general commercial claim.

Is crushing safer than shredding?

Crushing is not inherently safer or less safe. Its adequacy depends on the output. A process that reduces media to powder is materially different from one that bends a chassis. Shredding is easier to associate with NIST’s definition of cutting or tearing into particles, but the shred size and equipment still require approval and inspection.

Is degaussing safer than shredding?

Degaussing and shredding produce different sanitization outcomes. Degaussing can support Purge on suitable magnetic media. Shredding can support Destroy. If the organization requires unusable physical remnants and visual verification, shredding is the clearer fit. If it requires Purge and has verified magnetic-media compatibility, degaussing may fit.

How Should Data Sensitivity Affect Method Selection?

Data sensitivity determines the minimum acceptable sanitization method, verification standard, custody control, and evidence package. A public-sector agency retiring restricted drives and a business retiring routine internal drives may select different controls even when the hardware is identical.

A defensible decision process starts with data classification:

  1. Identify the highest confidentiality category stored on each asset group.
  2. Determine whether reuse is permitted.
  3. Determine whether the media will leave effective organizational control.
  4. Identify legal, regulatory, agency, and contract requirements.
  5. Assign the minimum acceptable method: Clear, Purge, or Destroy.
  6. Select a technique suited to the drive technology.
  7. Define verification, validation, exceptions, and records.
  8. Approve the release or final disposition of the remnants.

The method decision should be written into policy before a project begins. A technician at the loading dock should not decide whether an asset requires Purge or Destroy.

Government and defense environments

Federal agencies, defense contractors, aerospace organizations, and CUI holders may operate under agency policy, contract clauses, security classification rules, or approved product requirements. The contract can require a specific sequence, equipment list, witnessing process, or output specification.

The organization should identify the controlling authority before issuing an RFP. “NIST compliant” is not a substitute for the exact method, technique, media, equipment, and evidence requirements.

Healthcare environments

The HIPAA Security Rule requires covered entities to address final disposition of ePHI and the hardware or electronic media on which it is stored. HHS guidance states that ePHI must be removed before media reuse or disposal, or the media must be destroyed before disposal.

Healthcare buyers should connect the method decision to asset inventory, authorized disposition, business associate requirements, custody, and evidence. Hiring a destruction provider does not determine the healthcare organization’s complete HIPAA compliance.

Financial, legal, research, and technology environments

Financial institutions, law firms, research organizations, cloud operators, telecommunications providers, and technology companies can hold customer information, privileged records, intellectual property, credentials, encryption material, source code, and research data on retired drives.

These organizations should not use a single default method for every asset. A classification-based matrix can separate reusable drives, failed drives, contract-controlled drives, and drives that require witnessed physical destruction.

How Do On-Site and Off-Site Services Change the Risk?

On-site service reduces transport exposure and supports direct observation, while off-site service can support larger workflows when custody, containment, transport, storage, and reconciliation are controlled. The method remains important, but service location changes the risk path before destruction occurs.

On-site execution

On-site data destruction can fit organizations that require:

  • Media to remain at the client facility until processing
  • Client witnessing
  • Restricted-area control
  • Immediate reconciliation
  • Limited transport of unsanitized assets
  • A defined destruction event for audit or contract purposes

The site must support equipment access, power, safety, ventilation where applicable, noise controls, asset staging, and remnant removal.

Off-site execution

Off-site data destruction can fit high-volume or scheduled programs when the provider controls:

  • Collection authorization
  • Container identification
  • Tamper-evident seals
  • Custody transfers
  • Vehicle monitoring
  • Facility access
  • Pre-processing storage
  • Asset reconciliation
  • Exception reporting
  • Final records

Off-site service should not be evaluated only by the destruction machine. The unsanitized drives remain an information risk from collection until the approved method is completed.

What Evidence Should a Buyer Require?

A defensible evidence package identifies the assets, approved method, applied technique, equipment, verification, validation, responsible personnel, date, location, and outcome. A generic receipt stating “hard drives destroyed” may not support asset-level accountability or an audit.

NIST SP 800-88 Rev. 2 includes a sample Certificate of Sanitization and states that documentation should be completed according to organizational policy. Its example fields include media type, source, classification, method, technique, tool, verification, personnel, date, location, and signatures.

An enterprise project may require:

  • Client and project identifier
  • Asset or property number
  • Manufacturer, model, and serial number
  • Media type and storage technology
  • Operational or damaged status
  • Pre-sanitization confidentiality category
  • Approved method: Clear, Purge, or Destroy
  • Applied technique: shred, degauss, crush, pulverize, or another approved technique
  • Equipment make, model, and applicable setting
  • Date, time, and service location
  • Personnel responsible for execution
  • Verification result
  • Validation decision
  • Witness identity where applicable
  • Exceptions and reprocessing actions
  • Final disposition of remnants

A documented chain of custody records possession and transfer before the event. A Certificate of Destruction records completion of the approved destruction service. These records serve different functions and should not be treated as interchangeable.

Verification and validation are separate decisions

NIST distinguishes verification from validation:

  • Verification inspects whether the technique completed successfully. For destruction, this includes inspecting the remnants and identifying the equipment used.
  • Validation decides whether the target data was effectively sanitized after considering the verification result, errors, anomalies, and confidentiality risk.

A machine cycle that completes without an error does not prove that the wrong media was sanitized by the right machine. The process must confirm media identity, method suitability, output, and risk acceptance.

What Should an RFP Require From a Hard Drive Destruction Provider?

An RFP should define the required sanitization outcome, media inventory, service location, custody controls, equipment evidence, verification, documentation, exceptions, and downstream handling. A vendor comparison based only on price per drive leaves material risk decisions undefined.

Use the following procurement checklist.

Scope and media

  • Identify HDD quantity, form factor, interface, manufacturer, model, and condition where available.
  • Separate HDDs from SSDs, hybrid devices, tapes, optical media, batteries, and complete equipment.
  • Identify drives that are encrypted, damaged, failed, leased, or subject to legal hold.
  • Define the highest data classification in each asset group.

Method and equipment

  • State the required NIST method: Purge or Destroy.
  • State the approved technique or require the provider to propose one with evidence.
  • Require degausser compatibility with target HDD coercivity.
  • Require the make, model, maintenance, and calibration status of equipment.
  • Define shred, crush, fracture, or pulverization output in measurable terms where the governing requirement supplies them.
  • State whether two-stage degaussing and destruction is required.

Service and custody

  • Define on-site or off-site execution.
  • Define witnessing requirements.
  • Define container, seal, transport, staging, and facility controls.
  • Require named custody transfers and exception reporting.
  • Define the maximum time permitted before processing.

Verification and evidence

  • Define asset-level or batch-level reconciliation.
  • Require inspection criteria for remnants.
  • Require cycle and equipment records for degaussing.
  • Require failed-result and reprocessing procedures.
  • Define certificate fields, delivery timing, signatures, and retention.
  • Require a sample chain-of-custody record and Certificate of Destruction before award.

Downstream handling

  • Define ownership of remnants.
  • Identify approved downstream processors.
  • Require environmental and material-handling records where policy calls for them.
  • Prohibit resale or reuse of drives assigned to Destroy.

Procurement teams can use witnessed hard drive destruction when the contract requires direct observation and asset-level accountability.

Which Method Should Your Organization Choose?

Choose the method that satisfies the approved outcome for the actual drive technology and produces evidence your organization can validate. For most end-of-life HDD projects requiring Destroy, shredding offers a direct physical result. Degaussing fits verified magnetic-media Purge. Crushing requires a precisely defined and inspected output.

Use this decision sequence:

  1. Confirm the asset is an HDD. Do not apply the decision to an SSD by appearance alone.
  2. Identify the data category. Use the highest confidentiality category stored on the drive.
  3. Resolve reuse. If reuse is required, evaluate a logical Clear or Purge method instead of physical destruction.
  4. Assign the NIST method. Select Purge or Destroy according to policy and risk.
  5. Choose a valid technique. Match degaussing equipment to magnetic media, or define the required destructive output.
  6. Choose service location. Evaluate on-site observation against controlled off-site logistics.
  7. Define verification and validation. State how the organization will approve or reject the result.
  8. Define evidence. Require records that connect each asset or batch to the event and outcome.
  9. Define exceptions. Specify what happens when equipment fails, media is misidentified, or output is rejected.
  10. Approve downstream disposition. Control remnants after destruction.

Data Destruction Inc. provides hard drive shredding, hard drive degaussing, and hard drive crushing for approved enterprise projects. The project scope defines the media, method, equipment, location, witnessing, custody, verification, and records before processing begins.

Frequently Asked Questions

Is shredding better than degaussing for hard drives?

Shredding and degaussing support different outcomes. Shredding can support Destroy when the approved fragment result is achieved. Degaussing can support Purge for suitable magnetic HDDs when the field strength is matched to the media and the result is accepted. The required outcome determines the better fit.

Does degaussing permanently erase a hard drive?

Degaussing can make recovery infeasible on a suitable magnetic HDD when approved equipment is matched to the drive’s coercivity. The process can also make a drive inoperable without successfully sanitizing the target data, so equipment suitability, verification, and validation are required.

Does degaussing count as physical destruction?

No. NIST SP 800-88 Rev. 2 treats degaussing as a physical Purge technique and states that it is not an approved Destroy technique at the time of publication. A separate destructive technique is required when policy calls for Destroy.

Is crushing a NIST Destroy method?

Crushing is not automatically a Destroy method. Pulverization through crushing or grinding can support Destroy, but partial bending or puncturing may leave accessible data-bearing areas. The organization must define, inspect, and validate the output.

Can an SSD be degaussed?

No. SSDs store data in nonmagnetic flash memory. A degausser can complete its cycle without sanitizing the SSD. Use an SSD-specific logical or physical method and review why degaussing does not work on SSDs.

Can a shredded hard drive be recycled?

Eligible metal and electronic remnants can enter approved material-recovery channels after destruction. The organization should verify the downstream process, ownership, recordkeeping, and environmental requirements before approving the vendor.

Should drives be wiped before shredding?

Wiping before shredding is not required for every project. It may add value when policy requires a two-stage process or when operational controls reduce exposure before final destruction. It can also add time without changing the required Destroy outcome. The organization should document why both stages are necessary.

What is the difference between a Certificate of Destruction and a Certificate of Sanitization?

A Certificate of Sanitization records a sanitization activity and can identify the method, technique, tool, verification, validation, personnel, date, and location. A Certificate of Destruction records completion of a physical destruction service. The approved document name and required fields should be defined in policy and contract.

Which method works for damaged hard drives?

Physical destruction is often appropriate when a failed or damaged drive cannot support a reliable logical technique. Shredding can process approved failed drives without relying on the interface. Degaussing may fit suitable magnetic media, while crushing requires output-based assessment.

What is the safest method for classified hard drives?

The controlling agency policy, classification guide, contract, and approved equipment requirements determine the method. Classified-media decisions should not rely on a general commercial comparison. Some requirements may specify degaussing followed by physical destruction with listed equipment and defined output.

Request a Method and Evidence Assessment

Provide the drive type, quantity, condition, data classification, location, reuse decision, witnessing requirement, and required records. Data Destruction Inc. will review the project scope and identify the applicable service options.

Request a Hard Drive Destruction Quote

Call: (866) 850-7977

Sources

  1. National Institute of Standards and Technology, NIST Special Publication 800-88 Revision 2, Guidelines for Media Sanitization, September 2025.
  2. National Institute of Standards and Technology, NIST SP 800-88 Rev. 2 PDF, including Sections 3.1, 4.5, 4.6, the glossary, and the sample Certificate of Sanitization.
  3. US Department of Health and Human Services, May a covered entity reuse or dispose of computers or other electronic media that store electronic protected health information?.

Need compliant data destruction support for your team?

Talk with our specialists about destruction methods, witness options, and the documentation your auditors expect.