Questions
The questions, answered directly
Every question we answer anywhere, in one place. Search it, or read the article behind any answer.
All answers are written against United States requirements and drawn from articles that carry their sources.
16 questions
Nothing matches that. Try a shorter word, or browse the groups below.
NIST SP 800-88
Is NIST SP 800-88 Revision 1 still current?
No. NIST withdrew Revision 1 on September 26, 2025 and published Revision 2 the same day. A policy, contract or certificate template that still cites Rev. 1 is citing a withdrawn document.
What changed in NIST SP 800-88 Revision 2?
Four things matter to an operator. It describes a sanitization programme rather than a list of techniques. Device-level technique guidance moved to IEEE 2883-2022. Verification and validation became separate, separately recorded obligations. And it formalises the expectation that every sanitization event produces a durable, per-item record.
Does NIST 800-88 still tell me which wipe method to use?
Not any more. Revision 2 aligns with IEEE 2883-2022, which now carries the detailed, media-specific methods. Your policy should cite both: NIST for the programme, IEEE 2883 for the technique.
Is multi-pass overwriting still required?
No. Multi-pass overwriting was the folk standard for years and has been unnecessary on modern media for most of them. Revision 2 retires it.
Can we say we are "NIST 800-88 certified"?
No, and neither can anyone else. NIST does not certify anyone against SP 800-88 — it is guidance, not a certification scheme. You can say you follow it, and you can evidence that you run the programme it describes.
Verification and validation
What is the difference between verification and validation?
Verification is per device: did the sanitization actually run correctly on this one? Validation is per method: is this method demonstrably effective on this class of media at all? Revision 2 expects both, recorded separately.
Can you verify without validating?
Yes, and most operations do. Every drive has a record saying the wipe completed, and nobody can show why that method is appropriate for that media. It is the most common gap an assessor finds.
What counts as evidence of validation?
Three forms are accepted. Testing you performed, with the sample size and examination method documented. Vendor documentation, kept with its version. Or independent attestation. None has to be elaborate; all of them have to exist and be findable.
Who signs off validation?
Whoever owns the sanitization programme. Revision 2 expects defined roles, so if nobody is named that is itself the finding.
Is a batch record enough for verification?
No. Verification is per device, so a line covering forty drives cannot carry a result for any one of them. If your record is per batch, you have a summary rather than verification.
Certificates and retention
How long must you keep a certificate of destruction?
Three to seven years covers most cases. Six years if the device held protected health information, seven if the client is a publicly traded company or a law firm, and seven as a safe default when you cannot establish which applies.
How long does HIPAA require destruction records to be kept?
Six years, running from creation or the last effective date, whichever is later. A record attached to a policy that was current until 2028 starts its six years in 2028.
Does PCI DSS set a retention period for destruction records?
No. It requires you to define, document and justify your own period, which is a different and slightly harder thing than being given a number. Log retention is at least twelve months.
Whose retention obligation is it — ours or the client's?
The client's. An ITAD operator does not have a retention period of its own; the obligation belongs to whoever owned the data and is set by their regulator. You are holding a record on their behalf.
Do we keep the evidence, or just the certificate?
Both, for the same period. A certificate is a summary; what makes it hold up is the per-device record behind it. Keep the PDF for seven years and let the underlying records roll off after one, and you have kept the claim and discarded the proof.
What does an auditor actually test?
One device, chosen at random off a certificate you already issued. They ask you to produce its history — the capture, the reading, the method, the date and who confirmed it. The question is not whether you follow a standard; it is whether you can show what happened to that one asset.
Not answered here?
Ask us. If it is a good question we will answer it properly and add it to this page.
We're on a mission to bring automation to ITAD
Interested in hearing more, or got something you'd like to talk through? Get in touch.