NIST 800-88 vs. DoD 5220.22-M: What's the Difference?
Both names appear on nearly every data destruction certificate. They are not interchangeable. A practical guide to what each standard actually specifies — and when each applies.
Two standards, two eras
DoD 5220.22-M is the older of the two — a multi-pass overwrite specification (commonly three passes: write, complement, random, then verify) that became the de facto benchmark for magnetic hard drives. It is simple, conservative, and widely recognized.
NIST SP 800-88 Rev.1 is the modern framework. Rather than prescribing one technique, it defines three outcome levels — Clear, Purge, and Destroy — and instructs practitioners to select the method based on media type and data confidentiality. It is the standard referenced by most current regulatory frameworks.
Why media type changes the answer
Multi-pass overwriting was designed for spinning magnetic platters. Solid-state drives complicate the picture: wear-levelling and over-provisioned cells mean a naive overwrite may never touch every physical block. For SSDs and NVMe media, NIST-aligned Purge techniques (such as cryptographic erase or firmware-level sanitize commands) are the defensible choice.
This is why 'one wipe method for everything' is a red flag on any vendor's certificate. Sanitization must be media-specific to be verifiable.
Which should you require?
For most regulated organizations in India, NIST SP 800-88 Rev.1 is the baseline to specify, with DoD 5220.22-M multi-pass applied where policy or counterparty requirements demand it — typically high-sensitivity BFSI media such as ATM and financial terminal drives.
Whatever the method, the certificate matters as much as the wipe: it should record the device serial, media type, method used, verification result, operator, and timestamp — signed so it cannot be quietly edited later.
