Media sanitization is not the same thing as deleting a file. NIST SP 800-171 Rev. 2 requires sanitizing or destroying system media containing CUI before disposal or release for reuse, and the current NIST media-sanitization guidance is SP 800-88 Rev. 2, published in September 2025.
CUI can outlive the business workflow that created it. A laptop is reassigned, an SSD fails, a printer lease ends, a copier goes back to the vendor, backup media is retired, or paper drawings are discarded. NIST SP 800-171 Rev. 2 requirement 3.8.3 requires sanitizing or destroying system media containing CUI before disposal or release for reuse. Requirement 3.7.3 separately requires ensuring equipment removed for off-site maintenance is sanitized of CUI.
SP 800-88 Rev. 2 shifts emphasis toward a managed sanitization program and validation of the outcome rather than a one-size-fits-all list of old wiping recipes. For contractors, that is a useful framing: choose a method appropriate to the media and confidentiality need, use a recognized technique or standard, and keep evidence that the operation was completed and validated.
The inventory also has to reach beyond obvious disks. Printers, multifunction devices, mobile devices, removable media, embedded flash, test equipment, virtual/cloud storage, and equipment sent off site for maintenance can all create disposition decisions.
Inventory media beyond laptops and hard drives
Build the sanitization population from systems and workflows that can retain CUI. Include workstation and server drives, SSDs, removable storage, backup media, mobile devices, printer and multifunction-device storage, scanners, copiers, embedded storage in appliances, removable cards, test equipment, and paper records. Cloud services also need a lifecycle process even when the provider performs the underlying media destruction.
For each class, identify the custodian, data type, normal disposition, approved sanitization or destruction method, and evidence expected. A single method rarely fits every technology. Solid-state storage, magnetic disks, optical media, paper, and embedded flash have different practical characteristics.
Do not assume a factory reset equals sanitization for every device. Determine what the reset actually does, whether encryption keys are destroyed, whether data areas remain recoverable, and whether the method matches the organization's chosen sanitization standard and risk.
Include paper in the inventory where the workflow produces printed CUI. Paper does not have firmware or a secure-erase command, so the approved outcome is normally physical destruction appropriate to the information and the organization’s procedure. Track secure collection bins, shredding or destruction service custody, and any off-site destruction vendor separately from electronic-media sanitization. This prevents an otherwise strong device-disposal program from ignoring engineering drawings, traveler packets, or printed reports that leave the same CUI behind in another medium.
Choose and validate the sanitization method
Do not turn clear, purge, destroy, or cryptographic erase into labels on a form without understanding the media. Select a method appropriate to the storage technology, sensitivity, reuse destination, and organizational standard. SP 800-88 Rev. 2 points organizations toward a program that uses current recognized standards and validates whether sanitization achieved the intended confidentiality outcome.
Record the method, tool or service, operator, media identifier, date, result, and validation evidence. When cryptographic erase is used, make sure the design actually addresses the relevant keys and encrypted data rather than assuming that deleting a user account automatically sanitizes the storage.
For third-party destruction or sanitization, retain chain-of-custody and service evidence and verify that the provider's process matches the organization's required method. A certificate with no media identifier or method description is weak evidence.
- Media type and identifier
- Chosen sanitization technique or standard
- Operator or service provider
- Validation/result
- Disposition or reuse destination
Handle equipment that leaves for maintenance before it leaves
Requirement 3.7.3 specifically addresses equipment removed for off-site maintenance. Before a laptop, server, printer, drive, or other device leaves the controlled environment, determine whether it contains CUI and whether that CUI can be removed or sanitized. Record the decision before handing the asset to the carrier or vendor.
If operational constraints prevent normal sanitization, evaluate an alternative such as removing the storage device, using an approved on-site maintenance option, replacing the component internally, or applying other safeguards consistent with the contract and security plan. Do not ship first and document later.
Track custody: asset ID, serial number, service ticket, storage components removed or retained, sanitization evidence, vendor destination, departure and return dates, and post-maintenance validation. Maintenance records should reconcile with the asset inventory so equipment does not quietly disappear from scope.
Treat printers, copiers, and embedded storage as real media
Multifunction devices may cache scanned documents, print jobs, address books, or other content on internal storage. When a lease ends or a device is repaired, determine whether storage is present and what the vendor's return process does with it. A generic promise that the copier company 'wipes everything' should be backed by contract terms or disposition evidence relevant to the device.
The same issue appears in network appliances, lab equipment, mobile devices, and specialized systems with embedded flash. Ask what data can persist, how to export needed records, how to clear configuration or CUI, and whether the vendor provides a documented sanitize or destroy procedure.
Where the technology cannot be reliably sanitized, remove and destroy the storage component if feasible or choose a disposal method that protects the information. Capture the rationale and asset disposition rather than treating embedded media as invisible.
Keep decontrol separate from sanitization and public release
NARA's CUI framework provides for decontrol when the information no longer requires CUI safeguarding under the applicable authority. Decontrol should be performed by an authorized party and documented according to the applicable process. It does not automatically mean the information is approved for public release or that other legal, contractual, export-control, privacy, or records obligations disappear.
If media is being reused or disposed of, make a separate sanitization decision based on what remains stored and the destination. A document that was properly decontrolled yesterday may still be proprietary, export controlled, or otherwise unsuitable for release on a discarded drive. Conversely, sanitizing a drive does not change the classification or control status of copies elsewhere.
Keep decontrol records with information-governance evidence and sanitization records with asset/media disposition evidence. The separation makes it easier to explain which authority changed the information status and which technical action removed data from a device.
Include logical and cloud storage in the disposition conversation
Modern CUI may reside in storage that the contractor never physically touches. When a cloud tenant, SaaS workspace, virtual disk, or managed backup is retired, identify what deletion or sanitization capabilities the provider exposes, what retention or recovery copies remain, and what contractual evidence is available.
The practical goal is not to pretend a cloud disk can be put through the same process as a physical SSD. It is to document how the organization renders access to the retired CUI infeasible within that service model and how it verifies completion through provider controls, configuration, or contractual mechanisms.
Create a disposition record that survives personnel turnover
For representative media, record asset or media ID, description, whether CUI was present or possible, disposition reason, sanitization or destruction method, date, operator, verifier where required, destination, and supporting evidence such as tool output or destruction certificate. Avoid storing live encryption keys or sensitive recovery secrets in the evidence record.
Reconcile disposition records to the asset and media inventories. If an asset is marked disposed but there is no sanitization record, investigate before closing the inventory entry. If a destruction certificate lists 20 serial numbers, verify they correspond to the devices actually removed from the environment.
Periodically test the process with a normal lifecycle event, not only before assessment. Retire one old endpoint or reusable drive through the documented workflow and review whether operators could follow it without improvisation. Fix unclear steps while the evidence is fresh.
A short working check
- ✓Inventory all media types that can retain CUI
- ✓Define approved sanitization or destruction methods by media class
- ✓Sanitize equipment before off-site maintenance where required
- ✓Track custody and storage components for vendor repair
- ✓Include printers, copiers, mobile devices, and embedded storage
- ✓Separate CUI decontrol decisions from media sanitization
- ✓Record operator, date, method, media ID, and disposition
- ✓Reconcile disposal records to the asset and media inventories
Common questions
Is deleting files or performing a normal format enough for CMMC sanitization?
Not necessarily. The organization should use an approved sanitization or destruction method appropriate to the media, technology, data, and disposition and be able to show that the method was performed.
Does decontrolled CUI automatically become public information?
No. Decontrol removes CUI handling under the CUI Program when authorized, but it is not itself an authorization for public release and does not erase other legal, contractual, proprietary, privacy, export, or records obligations that may apply.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.

