Three documents, one chain
Manual, list, rule. Most confusion about classified media destruction comes from treating them as interchangeable.
NSA/CSS Policy Manual 9-12 — the Storage Device Sanitization Manual (the edition posted publicly on defense.gov is dated December 2014; NSA revises it and the lists periodically) — is the technical document. It applies to “all NSA/CSS elements and pertains to all IS storage devices utilized by NSA/CSS elements, contractors, and personnel,” and it defines sanitization as “the removal of information from the storage device such that data recovery using any known technique or analysis is prevented.” Its body is a device-by-device set of requirements.
The NSA/CSS Evaluated Products Lists (EPLs) are the procurement documents: lists of specific models of degaussers, paper shredders and disintegrators, optical media destruction devices, punched tape destroyers, and solid-state destruction devices that NSA has tested against the 9-12 specifications. They are published on nsa.gov and updated as devices are evaluated or removed.
32 CFR Part 2001 — the Information Security Oversight Office’s implementing directive for classified national security information — is what makes the lists mandatory. Section 2001.47 requires classified information to be “destroyed completely to preclude recognition or reconstruction,” naming burning, cross-cut shredding, wet-pulping, melting, mutilation, chemical decomposition, and pulverizing as acceptable methods; Section 2001.42(b) states that as of January 1, 2011, “only equipment listed on an Evaluated Products List (EPL) issued by the National Security Agency (NSA) may be utilized to destroy classified information.”
32 CFR Part 117 — the National Industrial Security Program Operating Manual as a federal rule — is what carries all of this to the private sector. Cleared contractors must destroy classified material per their contract security classification specification, following 2001.47 and the 2001.42(b) equipment standard, with the NSA media-destruction guidance referenced directly in the rule.
9-12 says what must happen. The EPLs say which machines can do it. 2001.42(b) says nothing else may. Part 117 says that applies to contractors. Read them in that order and the framework is simple.
NSA/CSS Policy Manual 9-12, device by device
The manual’s requirements are specific enough to be checked with a ruler, which is the point.
| Media | Accepted sanitization / destruction | Not accepted |
|---|---|---|
| Magnetic hard drives | Degauss with an NSA/CSS evaluated degausser (after which it is “highly recommended to physically damage the hard disk drive by deforming the internal platters”); or disintegrate to particles “nominally 2 millimeter edge length in size”; or incinerate until “internal platter coating must be reduced to ash” | Overwriting; degaussing with unevaluated equipment |
| Solid-state drives | Disintegrate to particles “nominally 2 millimeter edge length in size using an NSA/CSS evaluated solid state disintegrator”; or incinerate to ash | Degaussing (no effect on flash); overwriting; crypto erase |
| Volatile memory | Remove all power, including backup batteries | — |
| Optical media (CD/DVD/BD) | NSA/CSS evaluated shredders, disintegrators, or grinders; or incinerate to ash | Scratching, breaking by hand |
| Paper | Residue “reduced to pieces 5 millimeters square or smaller” by crosscut shredding, chopping, or disintegration; or burn to ash | Strip-cut shredding |
Two features of the table explain the whole classified tier. First, no software technique appears in it. The manual’s definition of sanitization — recovery prevented by any known technique — is a higher bar than the commercial standards’ “infeasible using state-of-the-art laboratory techniques,” and the manual meets it with physics rather than commands. Second, the requirements are tied to evaluated equipment: it is not enough to reach 2 mm particles; the device that produced them must be one NSA has tested, because particle size is only meaningful if the machine achieves it consistently across the media types it is rated for.
Mobile devices are not separately specified in the posted edition; in practice they are treated as the embedded flash they contain and destroyed accordingly.
NSA/CSS updates Policy Manual 9-12 and the EPLs periodically. The requirements summarized here are from the edition publicly posted on defense.gov; before citing a specific figure in a policy or contract, verify the current edition and the current lists at nsa.gov. The 2 mm SSD requirement in particular has been discussed for revision as flash densities rise.
The Evaluated Products Lists and the 2001.42(b) rule
The EPLs turn a specification into a procurement decision — and a federal rule turns the procurement decision into a mandate.
NSA publishes separate lists for the equipment classes 9-12 relies on: degaussers (rated by the coercivity of media they can sanitize), paper shredders and disintegrators, optical media destruction devices, punched tape destroyers, and solid state destruction devices. A listing means the specific model was evaluated by NSA against the manual’s requirements for the media type; it is not a general endorsement of a manufacturer.
Section 2001.42(b) is short and absolute: since January 1, 2011, only EPL-listed equipment may be used to destroy classified information. The section also manages the lifecycle of a listing — equipment approved before 2011 but never listed could be used only until the end of 2016; equipment removed from an EPL may generally continue in service for up to six years after removal unless NSA determines otherwise, except that units needing replacement of a critical assembly must come out of service immediately. The General Services Administration is directed to make EPL equipment available through the federal supply system.
For an organization that does not handle classified information, the EPLs still matter for one practical reason: they are the only public, government-tested benchmark for destruction equipment. “Our shredder is on the NSA EPL for solid-state devices” is a verifiable claim in a way that “our shredder is industrial-grade” is not. That is why the commercial standard itself — NIST SP 800-88 Rev. 2 — cites 9-12 for degaussing and destruction and allows NSA/CSS policy as an organizational alternative.
An EPL listing is a tested, model-specific, media-specific claim. For classified information it is mandatory; for everything else it is the best available benchmark, which is why the commercial standard points to it.
NISPOM: 32 CFR Part 117 and the cleared contractor
The National Industrial Security Program is how the government extends its classified-information rules to the companies that hold clearances — and in 2021 its operating manual became a regulation.
The National Industrial Security Program (NISP) governs how private-sector contractors safeguard classified information under contracts with federal agencies. For decades its rulebook was DoD 5220.22-M, the National Industrial Security Program Operating Manual, issued as a Department of Defense manual. On February 24, 2021, the NISPOM took effect as a federal regulation at 32 CFR Part 117; Section 117.1(b)(3) gave contractors six months from that date to implement most provisions. The manual was superseded by the rule.
Part 117 assigns oversight through cognizant security agencies, with the Defense Counterintelligence and Security Agency (DCSA) administering the program on behalf of DoD and serving as its cognizant security office. Section 117.15 covers safeguarding classified information; its paragraph (g) requires contractors to “destroy classified material in their possession based on the disposition instructions in the contract security classification specification or equivalent,” following the destruction methods in 32 CFR 2001.47 and the destruction equipment standard in 32 CFR 2001.42(b) — that is, the EPL mandate — and it points directly to NSA’s media-destruction guidance for approved methods. Section 117.18 covers information system security for classified systems, where media sanitization and destruction follow the same chain.
For a cleared contractor’s IT and facility security officers, the practical structure is: your contract’s classification specification tells you what to destroy and when; 2001.47 tells you the acceptable methods; 2001.42(b) and the EPLs tell you which equipment; 9-12 tells you the per-media result; and DCSA inspects the records. Destruction of classified material is a contractor obligation that cannot be delegated away — a vendor may perform it under the contractor’s program and supervision, using EPL equipment, with the contractor’s records, but the contractor remains responsible to its cognizant security agency.
This section describes the framework at the pattern level from the published rule. Contract security classification specifications (DD Form 254 and equivalents), agency-specific supplements, and DCSA guidance add requirements that vary by contract and classification level. Facility security officers should work from the current 32 CFR Part 117, their CSA’s guidance, and their contract documents, not from any summary.
The “DoD 5220.22-M three-pass wipe” myth
Ask a sanitization tool what standard it wipes to and it will often say “DoD 5220.22-M.” That citation has been stale for a long time, and understanding why clarifies the whole tier.
DoD 5220.22-M was the NISPOM manual. An older edition included a clearing-and-sanitization matrix that listed overwriting patterns for some media, and from that matrix the software industry extracted a “DoD three-pass wipe” and, later, a “seven-pass” variant, both of which became marketing labels. But the manual’s later editions removed the matrix, the manual itself was superseded by 32 CFR Part 117 in 2021, and neither the current NISPOM rule nor NSA/CSS Policy Manual 9-12 accepts overwriting as a method for classified media at all. There is no current federal standard for classified information that endorses an overwrite pattern.
For unclassified data the situation is different but no kinder to the label: NIST SP 800-88 Rev. 2 and IEEE 2883 specify device-internal sanitize operations and cryptographic erase for modern media, and they do so because host-side pattern overwriting — however many passes — cannot reach the spare, over-provisioned, and remapped areas of a flash device. A tool advertising “DoD 5220.22-M compliant” erasure is advertising conformance to a document that no longer exists, using a technique the current standards do not rely on.
“DoD 5220.22-M” is a superseded manual, not a live standard, and it never governed unclassified enterprise data. Cite 32 CFR 117 and NSA/CSS 9-12 for classified media; cite NIST 800-88 Rev. 2 and IEEE 2883 for everything else.
Using the NSA tier as a benchmark for unclassified destruction
Most organizations reading this will never hold classified information. The classified tier is still the most useful yardstick they have.
Commercial destruction claims are hard to evaluate because “shredded” has no fixed meaning: a hard drive shredded to 40 mm strips leaves platter fragments a laboratory can read; a flash chip that survives a shredder intact is a data-bearing device that happens to be loose. The NSA tier supplies the two things a buyer otherwise lacks — a particle-size specification per media type and a tested equipment list — and the commercial standard endorses using them: 800-88 Rev. 2 cites 9-12 for degaussing and destruction and permits NSA/CSS policy as an organizational alternative.
The practical translation for an enterprise or a regulated organization under CMMC, HIPAA, or GLBA: you are not required to destroy to 2 mm, but you are entitled to ask a vendor what particle size its equipment achieves for SSDs versus hard drives, whether its degaussers are EPL-listed and rated for the coercivity of modern drives, and how it verifies destruction. A vendor that benchmarks against the NSA specifications can answer in numbers; one that cannot is asking you to trust an adjective.
For CUI specifically — the controlled unclassified information that defense contractors hold outside the classified boundary — the governing framework is NIST SP 800-171 and CMMC, whose media sanitization control (3.8.3) is satisfied by NIST 800-88 methods; the classified tier is not required, but its equipment benchmark is the natural answer to an assessor’s “how do you know it was destroyed?” Our CMMC & ITAD guide covers that boundary.
What to verify: contractors and their vendors
Whether you hold clearances or simply want classified-grade assurance for regulated data, the verification list is short and concrete.
- For classified material: your program, your records. Destruction follows the contract security classification specification, 2001.47 methods, and 2001.42(b) equipment; a vendor performs it only under your program and supervision, and DCSA inspects your records, not the vendor’s brochure.
- Ask for EPL model numbers. Degausser, shredder, disintegrator, and solid-state destruction device — the listing is model-specific and media-specific. Check it against the current list on nsa.gov.
- Ask for particle size by media type. Hard drives and SSDs are different problems; the answer should distinguish them and, for classified-grade work, land at nominally 2 mm for both.
- Confirm degausser coercivity ratings. Modern high-coercivity drives defeat older degaussers; an evaluated degausser’s rating should cover the media you retire — and 9-12 still recommends deforming the platters afterward.
- Refuse overwrite claims for classified media. No current federal standard accepts them. For unclassified media, expect IEEE 2883 device-internal techniques or destruction, not pattern wipes.
- Retire the 5220.22-M citation. In your SOP, your vendor’s SOP, and your tool configuration. Cite 32 CFR 117 and NSA/CSS 9-12 for classified; 800-88 Rev. 2 and IEEE 2883 for everything else.
- Document to the stricter form. Serialized destruction records with method, equipment, particle specification, date, and named personnel satisfy both the commercial certificate (800-88 Section 4.6) and a security officer’s file.
CyberCrunch’s practice statement: destruction equipment benchmarked to NSA/CSS specifications, sanitization technique per IEEE 2883, program and certificate per NIST SP 800-88 Rev. 2, with serialized documentation per device and NAID AAA-audited destruction security. The certification field guide covers the audit layer around that practice.
EPL model numbers, particle size by media type, degausser coercivity, no overwrite for classified, no 5220.22-M citations, serialized records. That list separates a classified-grade destruction program from a shredder with a logo on it.
Frequently asked questions
What is NSA/CSS Policy Manual 9-12?
It is the National Security Agency / Central Security Service Storage Device Sanitization Manual, the document that specifies how storage devices holding classified information must be sanitized or destroyed, device type by device type. It defines sanitization as removing information such that recovery by any known technique is prevented, and it meets that bar with physical methods: degaussing magnetic drives with an evaluated degausser, disintegrating hard drives and solid-state drives to nominally 2 mm particles with evaluated equipment, incineration to ash, and cross-cut destruction of paper to 5 mm squares or smaller. Overwriting is not an accepted method for classified media.
What is the NSA Evaluated Products List and who has to use it?
The NSA/CSS Evaluated Products Lists name specific models of degaussers, paper shredders and disintegrators, optical media destruction devices, punched tape destroyers, and solid-state destruction devices that NSA has tested against Policy Manual 9-12 requirements. Under 32 CFR 2001.42(b), since January 1, 2011 only EPL-listed equipment may be used to destroy classified information, and 32 CFR Part 117 carries that requirement to cleared contractors. Organizations without classified information are not bound by it but commonly use the lists as a benchmark, which NIST SP 800-88 Rev. 2 endorses by citing 9-12 for degaussing and destruction.
What is NISPOM and what happened to DoD 5220.22-M?
NISPOM is the National Industrial Security Program Operating Manual, the rulebook for private-sector contractors that hold classified information under federal contracts. It was long issued as DoD Manual 5220.22-M; on February 24, 2021 it took effect as a federal regulation at 32 CFR Part 117, which superseded the manual, with most provisions to be implemented within six months. Section 117.15(g) requires contractors to destroy classified material per their contract security classification specification, using the methods in 32 CFR 2001.47 and the EPL equipment standard in 32 CFR 2001.42(b).
Is a 'DoD 5220.22-M three-pass wipe' a valid data destruction standard today?
No. The three-pass and seven-pass overwrite patterns marketed under that name trace to a clearing-and-sanitization matrix in an older edition of the NISPOM manual. Later editions removed the matrix, the manual was superseded by 32 CFR Part 117 in 2021, and no current federal standard accepts overwriting for classified media. For unclassified data, NIST SP 800-88 Rev. 2 and IEEE 2883 rely on device-internal sanitize operations and cryptographic erase, because host-side overwriting cannot reach the spare and over-provisioned areas of modern flash media.
Do I need NSA-grade destruction if my data isn't classified?
Not as a requirement. Unclassified data, including CUI under CMMC and regulated data under HIPAA or GLBA, is governed by NIST SP 800-88 methods rather than the classified tier. But the NSA specifications and Evaluated Products Lists are the only public, government-tested benchmark for destruction equipment and particle size, and NIST 800-88 Rev. 2 itself cites Policy Manual 9-12 for degaussing and destruction. Asking a vendor for EPL model numbers and particle size by media type is the most concrete way to evaluate a destruction claim, whatever the classification of your data.
Destruction you can check with a ruler and a list
CyberCrunch benchmarks its destruction equipment to NSA/CSS specifications, selects sanitization techniques per IEEE 2883, and documents every device to NIST SP 800-88 Rev. 2’s certificate — under NAID AAA-audited destruction security. Ask for the equipment list and a sample certificate.
This guide is informational only and reflects publicly available sources as of September 2026: NSA/CSS Policy Manual 9-12 as publicly posted, the NSA/CSS Evaluated Products List program pages, 32 CFR Part 2001 (Sections 2001.42 and 2001.47), and 32 CFR Part 117 as published in the Electronic Code of Federal Regulations. It describes the framework at the pattern level and does not reproduce classified or controlled guidance. Requirements for a specific contract are set by the contract security classification specification, the cognizant security agency, and agency supplements, and NSA revises its manual and lists periodically; cleared contractors must work from current official sources and their facility security officer, not from this summary. It is not legal or security advice, and CyberCrunch practice statements reflect its procedures at the time of publication.