Media sanitization is one of the most procedure-heavy CMMC practices because it requires a per-media-type decision and a documentation trail. The standard is NIST SP 800-88 Rev 1.
The CMMC requirement
CMMC practice MP.L2-3.8.3 (NIST SP 800-171 Rev 2 § 3.8.3): "Sanitize or destroy information system media containing CUI before disposal or release for reuse."
The three sanitization methods (NIST SP 800-88 Rev 1)
| Method | Goal | Recovery resistance |
|---|---|---|
| Clear | Sanitize using standard read/write commands. | Resists keyboard-based recovery using common system tools and utilities. |
| Purge | Sanitize using physical or logical techniques that render recovery infeasible using state-of-the-art laboratory techniques. | Resists laboratory recovery. |
| Destroy | Sanitize by physically destroying the media so the media cannot be reused at all. | Recovery is infeasible by any means. |
Method selection for CUI
- Clear may be appropriate for media that will be reused within the same security boundary by users with the same authorization.
- Purge is typical for CUI media being released outside the security boundary for reuse.
- Destroy is typical for end-of-life media or media that cannot be reliably purged.
For most CUI scenarios, Purge or Destroy is the defensible choice.
Specific techniques by media type
| Media type | Clear | Purge | Destroy |
|---|---|---|---|
| Magnetic hard drive (HDD) | Single-pass overwrite | Degauss with NSA/CSS-evaluated degausser, OR ATA Secure Erase | Shred, pulverize, incinerate, or disintegrate |
| Solid-state drive (SSD) | Single-pass overwrite (limited effectiveness due to wear leveling) | Cryptographic erase, NVMe Format with crypto erase, or vendor-supplied secure erase | Shred to particles smaller than the largest memory chip |
| Optical media (CD, DVD, Blu-ray) | Not applicable | Not applicable | Shred or destroy |
| Paper | Not applicable | Not applicable | Cross-cut shred to specified particle size, pulp, or incinerate |
| Mobile devices | Factory reset | Cryptographic erase plus factory reset | Physical destruction of memory components |
| Tape | Overwrite | Degauss | Shred or incinerate |
Documentation required
Every sanitization event should record:
- Media identifier (serial number, asset tag).
- Method (Clear / Purge / Destroy) and specific technique.
- Date of sanitization.
- Operator who performed the sanitization.
- Verification that sanitization was successful (where applicable).
- Disposition (reuse, donate, dispose) and chain of custody to the receiving party.
Cryptographic erase notes
For self-encrypting drives (SED) and similar cryptographically-protected media, NIST SP 800-88 Rev 1 accepts cryptographic erase (deletion of the encryption key) as a Purge technique. The encryption key must be deleted using the manufacturer's supported method, and the result must be verified.
Common errors
- Overwriting an SSD as if it were an HDD. Wear leveling means overwrite doesn't reliably reach all storage cells. Use crypto erase or destroy.
- Throwing a working drive in the trash because it was "wiped." A wipe without verification is not a sanitization that survives assessment scrutiny.
- No sanitization log. Without per-media records, the assessor cannot verify the practice operates.
- Outsourcing destruction without chain-of-custody documentation. A vendor's certificate of destruction without per-media reconciliation is incomplete.
- Overlooking mobile devices, removable media, and paper. The MP family covers all media types, not just hard drives.
Sources
Track every media lifecycle event against MP.L2-3.8.3.
The CMMC Compliance Engine includes the MP-LOG-01_Media_Lifecycle_Event_Log and the MP-MAT-01_Media_Inventory_Accountability_Matrix for managing media chain of custody.
Get the CMMC Compliance Engine