Standards anatomy · NSA/CSS 9-12 · Evaluated Products Lists · 32 CFR 117 · 32 CFR 2001

The NSA/CSS 9-12 & NISPOM Field Guide: How Classified and Defense-Contractor Media Actually Get Destroyed

Above the commercial sanitization standards sits a stricter layer written for information whose disclosure could damage national security. It has three parts that are routinely confused: NSA/CSS Policy Manual 9-12, the storage device sanitization manual that says what must physically happen to each media type; the NSA/CSS Evaluated Products Lists, which name the degaussers, shredders, and disintegrators tested to those requirements — and which, under 32 CFR 2001.42(b), are the only equipment that may destroy classified information; and 32 CFR Part 117, the NISPOM rule that since 2021 governs cleared defense contractors and replaced the DoD 5220.22-M manual that sanitization software still cites. This guide explains each, how they connect, why overwriting has no place in the classified tier, and why the NSA specifications have become the de facto benchmark for serious unclassified destruction too. For the commercial standards underneath, see the 800-88 Rev. 2 and IEEE 2883 guides; for the CMMC/CUI layer, the CMMC & ITAD guide.

Reading time: ~17 min Published: September 1, 2026 Author: Brian Boynton Applies to: NSA/CSS PM 9-12; 32 CFR 2001; 32 CFR Part 117

STRAIGHT ANSWER

How must classified and defense-contractor media be destroyed?

By physical destruction or degaussing to NSA/CSS specifications, never by overwriting. NSA/CSS Policy Manual 9-12 sets device-by-device requirements, such as disintegrating hard drives and SSDs to nominally 2 mm particles or degaussing magnetic drives with an evaluated degausser, and under 32 CFR 2001.42(b) only equipment on an NSA/CSS Evaluated Products List may destroy classified information. Cleared contractors follow 32 CFR Part 117, the NISPOM rule that replaced DoD 5220.22-M.

TL;DR

Three documents, one chain. NSA/CSS Policy Manual 9-12 says what must happen to each media type holding classified information: magnetic hard drives degaussed with an evaluated degausser (and preferably deformed) or disintegrated to nominally 2 mm particles or incinerated; solid-state drives disintegrated to nominally 2 mm with an evaluated device or incinerated; optical media shredded or disintegrated with evaluated equipment; paper reduced to 5 mm squares or smaller. Overwriting is not a classified-media option. The Evaluated Products Lists name the equipment that meets those specifications, and 32 CFR 2001.42(b) makes them mandatory: since January 1, 2011, only EPL-listed equipment may destroy classified information. 32 CFR Part 117 — the NISPOM rule, effective February 24, 2021 — binds cleared contractors to that framework and replaced DoD 5220.22-M, which no longer exists as a standard despite what wiping software says on the box.

Section 01

Three documents, one chain

Manual, list, rule. Most confusion about classified media destruction comes from treating them as interchangeable.

NSA/CSS Policy Manual 9-12 — the Storage Device Sanitization Manual (the edition posted publicly on defense.gov is dated December 2014; NSA revises it and the lists periodically) — is the technical document. It applies to “all NSA/CSS elements and pertains to all IS storage devices utilized by NSA/CSS elements, contractors, and personnel,” and it defines sanitization as “the removal of information from the storage device such that data recovery using any known technique or analysis is prevented.” Its body is a device-by-device set of requirements.

The NSA/CSS Evaluated Products Lists (EPLs) are the procurement documents: lists of specific models of degaussers, paper shredders and disintegrators, optical media destruction devices, punched tape destroyers, and solid-state destruction devices that NSA has tested against the 9-12 specifications. They are published on nsa.gov and updated as devices are evaluated or removed.

32 CFR Part 2001 — the Information Security Oversight Office’s implementing directive for classified national security information — is what makes the lists mandatory. Section 2001.47 requires classified information to be “destroyed completely to preclude recognition or reconstruction,” naming burning, cross-cut shredding, wet-pulping, melting, mutilation, chemical decomposition, and pulverizing as acceptable methods; Section 2001.42(b) states that as of January 1, 2011, “only equipment listed on an Evaluated Products List (EPL) issued by the National Security Agency (NSA) may be utilized to destroy classified information.”

32 CFR Part 117 — the National Industrial Security Program Operating Manual as a federal rule — is what carries all of this to the private sector. Cleared contractors must destroy classified material per their contract security classification specification, following 2001.47 and the 2001.42(b) equipment standard, with the NSA media-destruction guidance referenced directly in the rule.

Bottom line

9-12 says what must happen. The EPLs say which machines can do it. 2001.42(b) says nothing else may. Part 117 says that applies to contractors. Read them in that order and the framework is simple.

Section 02

NSA/CSS Policy Manual 9-12, device by device

The manual’s requirements are specific enough to be checked with a ruler, which is the point.

MediaAccepted sanitization / destructionNot accepted
Magnetic hard drivesDegauss with an NSA/CSS evaluated degausser (after which it is “highly recommended to physically damage the hard disk drive by deforming the internal platters”); or disintegrate to particles “nominally 2 millimeter edge length in size”; or incinerate until “internal platter coating must be reduced to ash”Overwriting; degaussing with unevaluated equipment
Solid-state drivesDisintegrate to particles “nominally 2 millimeter edge length in size using an NSA/CSS evaluated solid state disintegrator”; or incinerate to ashDegaussing (no effect on flash); overwriting; crypto erase
Volatile memoryRemove all power, including backup batteries
Optical media (CD/DVD/BD)NSA/CSS evaluated shredders, disintegrators, or grinders; or incinerate to ashScratching, breaking by hand
PaperResidue “reduced to pieces 5 millimeters square or smaller” by crosscut shredding, chopping, or disintegration; or burn to ashStrip-cut shredding

Two features of the table explain the whole classified tier. First, no software technique appears in it. The manual’s definition of sanitization — recovery prevented by any known technique — is a higher bar than the commercial standards’ “infeasible using state-of-the-art laboratory techniques,” and the manual meets it with physics rather than commands. Second, the requirements are tied to evaluated equipment: it is not enough to reach 2 mm particles; the device that produced them must be one NSA has tested, because particle size is only meaningful if the machine achieves it consistently across the media types it is rated for.

Mobile devices are not separately specified in the posted edition; in practice they are treated as the embedded flash they contain and destroyed accordingly.

Freshness note

NSA/CSS updates Policy Manual 9-12 and the EPLs periodically. The requirements summarized here are from the edition publicly posted on defense.gov; before citing a specific figure in a policy or contract, verify the current edition and the current lists at nsa.gov. The 2 mm SSD requirement in particular has been discussed for revision as flash densities rise.

Section 03

The Evaluated Products Lists and the 2001.42(b) rule

The EPLs turn a specification into a procurement decision — and a federal rule turns the procurement decision into a mandate.

NSA publishes separate lists for the equipment classes 9-12 relies on: degaussers (rated by the coercivity of media they can sanitize), paper shredders and disintegrators, optical media destruction devices, punched tape destroyers, and solid state destruction devices. A listing means the specific model was evaluated by NSA against the manual’s requirements for the media type; it is not a general endorsement of a manufacturer.

Section 2001.42(b) is short and absolute: since January 1, 2011, only EPL-listed equipment may be used to destroy classified information. The section also manages the lifecycle of a listing — equipment approved before 2011 but never listed could be used only until the end of 2016; equipment removed from an EPL may generally continue in service for up to six years after removal unless NSA determines otherwise, except that units needing replacement of a critical assembly must come out of service immediately. The General Services Administration is directed to make EPL equipment available through the federal supply system.

For an organization that does not handle classified information, the EPLs still matter for one practical reason: they are the only public, government-tested benchmark for destruction equipment. “Our shredder is on the NSA EPL for solid-state devices” is a verifiable claim in a way that “our shredder is industrial-grade” is not. That is why the commercial standard itself — NIST SP 800-88 Rev. 2 — cites 9-12 for degaussing and destruction and allows NSA/CSS policy as an organizational alternative.

Bottom line

An EPL listing is a tested, model-specific, media-specific claim. For classified information it is mandatory; for everything else it is the best available benchmark, which is why the commercial standard points to it.

Section 04

NISPOM: 32 CFR Part 117 and the cleared contractor

The National Industrial Security Program is how the government extends its classified-information rules to the companies that hold clearances — and in 2021 its operating manual became a regulation.

The National Industrial Security Program (NISP) governs how private-sector contractors safeguard classified information under contracts with federal agencies. For decades its rulebook was DoD 5220.22-M, the National Industrial Security Program Operating Manual, issued as a Department of Defense manual. On February 24, 2021, the NISPOM took effect as a federal regulation at 32 CFR Part 117; Section 117.1(b)(3) gave contractors six months from that date to implement most provisions. The manual was superseded by the rule.

Part 117 assigns oversight through cognizant security agencies, with the Defense Counterintelligence and Security Agency (DCSA) administering the program on behalf of DoD and serving as its cognizant security office. Section 117.15 covers safeguarding classified information; its paragraph (g) requires contractors to “destroy classified material in their possession based on the disposition instructions in the contract security classification specification or equivalent,” following the destruction methods in 32 CFR 2001.47 and the destruction equipment standard in 32 CFR 2001.42(b) — that is, the EPL mandate — and it points directly to NSA’s media-destruction guidance for approved methods. Section 117.18 covers information system security for classified systems, where media sanitization and destruction follow the same chain.

For a cleared contractor’s IT and facility security officers, the practical structure is: your contract’s classification specification tells you what to destroy and when; 2001.47 tells you the acceptable methods; 2001.42(b) and the EPLs tell you which equipment; 9-12 tells you the per-media result; and DCSA inspects the records. Destruction of classified material is a contractor obligation that cannot be delegated away — a vendor may perform it under the contractor’s program and supervision, using EPL equipment, with the contractor’s records, but the contractor remains responsible to its cognizant security agency.

Scope caution

This section describes the framework at the pattern level from the published rule. Contract security classification specifications (DD Form 254 and equivalents), agency-specific supplements, and DCSA guidance add requirements that vary by contract and classification level. Facility security officers should work from the current 32 CFR Part 117, their CSA’s guidance, and their contract documents, not from any summary.

Section 05

The “DoD 5220.22-M three-pass wipe” myth

Ask a sanitization tool what standard it wipes to and it will often say “DoD 5220.22-M.” That citation has been stale for a long time, and understanding why clarifies the whole tier.

DoD 5220.22-M was the NISPOM manual. An older edition included a clearing-and-sanitization matrix that listed overwriting patterns for some media, and from that matrix the software industry extracted a “DoD three-pass wipe” and, later, a “seven-pass” variant, both of which became marketing labels. But the manual’s later editions removed the matrix, the manual itself was superseded by 32 CFR Part 117 in 2021, and neither the current NISPOM rule nor NSA/CSS Policy Manual 9-12 accepts overwriting as a method for classified media at all. There is no current federal standard for classified information that endorses an overwrite pattern.

For unclassified data the situation is different but no kinder to the label: NIST SP 800-88 Rev. 2 and IEEE 2883 specify device-internal sanitize operations and cryptographic erase for modern media, and they do so because host-side pattern overwriting — however many passes — cannot reach the spare, over-provisioned, and remapped areas of a flash device. A tool advertising “DoD 5220.22-M compliant” erasure is advertising conformance to a document that no longer exists, using a technique the current standards do not rely on.

Bottom line

“DoD 5220.22-M” is a superseded manual, not a live standard, and it never governed unclassified enterprise data. Cite 32 CFR 117 and NSA/CSS 9-12 for classified media; cite NIST 800-88 Rev. 2 and IEEE 2883 for everything else.

Section 06

Using the NSA tier as a benchmark for unclassified destruction

Most organizations reading this will never hold classified information. The classified tier is still the most useful yardstick they have.

Commercial destruction claims are hard to evaluate because “shredded” has no fixed meaning: a hard drive shredded to 40 mm strips leaves platter fragments a laboratory can read; a flash chip that survives a shredder intact is a data-bearing device that happens to be loose. The NSA tier supplies the two things a buyer otherwise lacks — a particle-size specification per media type and a tested equipment list — and the commercial standard endorses using them: 800-88 Rev. 2 cites 9-12 for degaussing and destruction and permits NSA/CSS policy as an organizational alternative.

The practical translation for an enterprise or a regulated organization under CMMC, HIPAA, or GLBA: you are not required to destroy to 2 mm, but you are entitled to ask a vendor what particle size its equipment achieves for SSDs versus hard drives, whether its degaussers are EPL-listed and rated for the coercivity of modern drives, and how it verifies destruction. A vendor that benchmarks against the NSA specifications can answer in numbers; one that cannot is asking you to trust an adjective.

For CUI specifically — the controlled unclassified information that defense contractors hold outside the classified boundary — the governing framework is NIST SP 800-171 and CMMC, whose media sanitization control (3.8.3) is satisfied by NIST 800-88 methods; the classified tier is not required, but its equipment benchmark is the natural answer to an assessor’s “how do you know it was destroyed?” Our CMMC & ITAD guide covers that boundary.

Section 07

What to verify: contractors and their vendors

Whether you hold clearances or simply want classified-grade assurance for regulated data, the verification list is short and concrete.

  • For classified material: your program, your records. Destruction follows the contract security classification specification, 2001.47 methods, and 2001.42(b) equipment; a vendor performs it only under your program and supervision, and DCSA inspects your records, not the vendor’s brochure.
  • Ask for EPL model numbers. Degausser, shredder, disintegrator, and solid-state destruction device — the listing is model-specific and media-specific. Check it against the current list on nsa.gov.
  • Ask for particle size by media type. Hard drives and SSDs are different problems; the answer should distinguish them and, for classified-grade work, land at nominally 2 mm for both.
  • Confirm degausser coercivity ratings. Modern high-coercivity drives defeat older degaussers; an evaluated degausser’s rating should cover the media you retire — and 9-12 still recommends deforming the platters afterward.
  • Refuse overwrite claims for classified media. No current federal standard accepts them. For unclassified media, expect IEEE 2883 device-internal techniques or destruction, not pattern wipes.
  • Retire the 5220.22-M citation. In your SOP, your vendor’s SOP, and your tool configuration. Cite 32 CFR 117 and NSA/CSS 9-12 for classified; 800-88 Rev. 2 and IEEE 2883 for everything else.
  • Document to the stricter form. Serialized destruction records with method, equipment, particle specification, date, and named personnel satisfy both the commercial certificate (800-88 Section 4.6) and a security officer’s file.

CyberCrunch’s practice statement: destruction equipment benchmarked to NSA/CSS specifications, sanitization technique per IEEE 2883, program and certificate per NIST SP 800-88 Rev. 2, with serialized documentation per device and NAID AAA-audited destruction security. The certification field guide covers the audit layer around that practice.

Bottom line

EPL model numbers, particle size by media type, degausser coercivity, no overwrite for classified, no 5220.22-M citations, serialized records. That list separates a classified-grade destruction program from a shredder with a logo on it.

Section 08

Frequently asked questions

What is NSA/CSS Policy Manual 9-12?

It is the National Security Agency / Central Security Service Storage Device Sanitization Manual, the document that specifies how storage devices holding classified information must be sanitized or destroyed, device type by device type. It defines sanitization as removing information such that recovery by any known technique is prevented, and it meets that bar with physical methods: degaussing magnetic drives with an evaluated degausser, disintegrating hard drives and solid-state drives to nominally 2 mm particles with evaluated equipment, incineration to ash, and cross-cut destruction of paper to 5 mm squares or smaller. Overwriting is not an accepted method for classified media.

What is the NSA Evaluated Products List and who has to use it?

The NSA/CSS Evaluated Products Lists name specific models of degaussers, paper shredders and disintegrators, optical media destruction devices, punched tape destroyers, and solid-state destruction devices that NSA has tested against Policy Manual 9-12 requirements. Under 32 CFR 2001.42(b), since January 1, 2011 only EPL-listed equipment may be used to destroy classified information, and 32 CFR Part 117 carries that requirement to cleared contractors. Organizations without classified information are not bound by it but commonly use the lists as a benchmark, which NIST SP 800-88 Rev. 2 endorses by citing 9-12 for degaussing and destruction.

What is NISPOM and what happened to DoD 5220.22-M?

NISPOM is the National Industrial Security Program Operating Manual, the rulebook for private-sector contractors that hold classified information under federal contracts. It was long issued as DoD Manual 5220.22-M; on February 24, 2021 it took effect as a federal regulation at 32 CFR Part 117, which superseded the manual, with most provisions to be implemented within six months. Section 117.15(g) requires contractors to destroy classified material per their contract security classification specification, using the methods in 32 CFR 2001.47 and the EPL equipment standard in 32 CFR 2001.42(b).

Is a 'DoD 5220.22-M three-pass wipe' a valid data destruction standard today?

No. The three-pass and seven-pass overwrite patterns marketed under that name trace to a clearing-and-sanitization matrix in an older edition of the NISPOM manual. Later editions removed the matrix, the manual was superseded by 32 CFR Part 117 in 2021, and no current federal standard accepts overwriting for classified media. For unclassified data, NIST SP 800-88 Rev. 2 and IEEE 2883 rely on device-internal sanitize operations and cryptographic erase, because host-side overwriting cannot reach the spare and over-provisioned areas of modern flash media.

Do I need NSA-grade destruction if my data isn't classified?

Not as a requirement. Unclassified data, including CUI under CMMC and regulated data under HIPAA or GLBA, is governed by NIST SP 800-88 methods rather than the classified tier. But the NSA specifications and Evaluated Products Lists are the only public, government-tested benchmark for destruction equipment and particle size, and NIST 800-88 Rev. 2 itself cites Policy Manual 9-12 for degaussing and destruction. Asking a vendor for EPL model numbers and particle size by media type is the most concrete way to evaluate a destruction claim, whatever the classification of your data.

BENCHMARKED TO THE STRICTER TIER

Destruction you can check with a ruler and a list

CyberCrunch benchmarks its destruction equipment to NSA/CSS specifications, selects sanitization techniques per IEEE 2883, and documents every device to NIST SP 800-88 Rev. 2’s certificate — under NAID AAA-audited destruction security. Ask for the equipment list and a sample certificate.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects publicly available sources as of September 2026: NSA/CSS Policy Manual 9-12 as publicly posted, the NSA/CSS Evaluated Products List program pages, 32 CFR Part 2001 (Sections 2001.42 and 2001.47), and 32 CFR Part 117 as published in the Electronic Code of Federal Regulations. It describes the framework at the pattern level and does not reproduce classified or controlled guidance. Requirements for a specific contract are set by the contract security classification specification, the cognizant security agency, and agency supplements, and NSA revises its manual and lists periodically; cleared contractors must work from current official sources and their facility security officer, not from this summary. It is not legal or security advice, and CyberCrunch practice statements reflect its procedures at the time of publication.