Certified Secure Data Wiping in Sweden and the Nordics: NIST SP 800-88 Rev. 2 Sanitization With a Per-device Certificate
Quick answer
TYTEC AB now provides certified secure data wiping across Sweden and the Nordics for laptops, servers, workstations and loose storage devices. We sanitize every device against NIST SP 800-88 Rev. 2 and IEEE 2883-2022. We also provide a Certificate of Data Sanitization for each device, recording the host asset tag or serial number, the storage device serial number, the precise command issued, the verification result and SHA-256 hashes of the underlying technical evidence. The service is performed on site, so media never has to leave your premises.
Wiping the drive was never the hard part
Any competent engineer can erase a disk. What organizations struggle to produce, eighteen months later when an auditor asks, is proof that a named person erased a drive in a machine on a date, using a method that met the applicable standard, with unaltered evidence.
That gap is where the risk resides. A wipe with no defensible record is, from a compliance standpoint, indistinguishable from no wipe at all. It’s also where most disposal arrangements quietly fail: a pallet of hardware leaves the building, a single-page certificate arrives covering “48 assets,” and nothing in that document ties any serial number to any outcome.
TYTEC built its new sanitization service around solving the evidence problem rather than the erasure problem. The erasure is straightforward. The record is the product.
What TYTEC now offers
The service covers laptops and desktop workstations, servers and blades, including RAID sets and boot drives. It also covers loose storage media across HDD and SATA formats, SAS, NVMe and M.2 formats, network and infrastructure equipment holding configuration or log data, and removable or embedded media such as memory cards and USB devices.
We carry out work on site at your data center or office anywhere in Sweden, Norway, Denmark or Finland. Because our technicians bring the capability to you, no chain of custody with a third party forms, and no hardware leaves your control while it still holds recoverable data. For most customers this removes the single largest source of disposal risk in one decision.
Every sanitized device receives a certificate tied to its serial number. Not one certificate per batch, per pallet or per project.
The standard changed in September 2025, and most vendors haven’t caught up
This matters more than it sounds, because it affects the language in your policies and contracts.
NIST Special Publication 800-88 Revision 1, published in December 2014, formally withdrew on 26 September 2025, and Revision 2 replaced it the same day. It was the first substantive update to the United States media sanitization standard in more than a decade. If your data disposal policy, your supplier agreements or your procurement templates still specify “NIST 800-88 Rev.1” they now reference a document that is no longer an active standard, and a thorough auditor will notice.
Revision 2 retains the familiar three-category framework, but changes how organizations should choose, execute, verify and document sanitization.
Clear
What it achieves:
Overwrites or resets user-addressable storage using standard read, write or format commands.
When it applies:
Media remaining within your organization’s control, or where the device doesn’t expose stronger sanitization capability.
Device reusable:
Yes.
Purge
What it achieves:
Applies techniques that defeat laboratory-grade recovery, such as cryptographic erase, block erase or a controller sanitize operation.
When it applies:
Media leaving your organization’s control through resale, lease return, RMA or transfer to another tenant.
Device reusable:
Yes.
Destroy
What it achieves:
Physically renders the media and the data unrecoverable through shredding, disintegration or incineration.
When it applies:
The highest sensitivity classifications, and any drive that can’t accept or complete a sanitize operation.
Device reusable:
No.
Four changes in Revision 2 carry real commercial weight.
The first is a shift in emphasis from sanitization decisions toward maintaining an ongoing sanitization program. Auditors increasingly want to see a documented, repeatable process rather than evidence that somebody once erased some drives.
The second is that NIST stopped defining sanitization techniques itself. Revision 2 instead directs organizations to current storage industry standards, principally IEEE 2883-2022, for the method definitions. A vendor claiming NIST compliance in 2026 should be able to show you that chain, and their certificates should name both documents.
The third is the formal introduction of sanitization validation. Performing an erasure is no longer sufficient on its own. The outcome has to be verified, and the verification has to be recorded.
The fourth is that the certificate of sanitization itself was updated and is now a defined output of the process rather than an optional courtesy from the supplier.
We built TYTEC’s service against Revision 2 from the start, and every certificate we issue names both NIST SP 800-88 Rev. 2 and IEEE 2883-2022 as its standards basis.
What is actually on a TYTEC certificate
It’s worth describing this in detail, because “we issue a certificate” is a claim every disposal vendor makes, and almost none of them mean the same thing by it.
Each certificate carries a unique identifier and opens with a plain-language executive summary and an unambiguous pass or fail result. Below that sits the standards basis, the sanitization classification applied, and the technique used, so the compliance position is legible on the first page without technical interpretation.
The asset identification section records the host device and the storage device separately. This distinction matters, and people frequently miss it. Your asset register tracks the laptop by its service tag; the data lived on a drive with an entirely different serial number. Recording only one of the two leaves a gap that an auditor can drive through. The system captures both the interface type and the precise byte-level capacity.
The sanitization summary gives the start and completion timestamps, the duration, the total bytes sanitized as a figure and a percentage, the verification method and its outcome, and an explicit error count. Then, the named TYTEC project manager, who performed the work with a timestamp, signs the certificate.
A second page carries the full technical record. This includes the precise command issued to the device, the controller model, serial and firmware revision, the sanitize action code, whether the device accepted the command, and the reported sanitize status. It also records the checks that auditors found not to apply, which is a subtler point but an important one. An auditor reading that a hidden protected area or device configuration overlay was checked and found not applicable is looking at a more trustworthy document than one that omits the question.
The section that genuinely differentiates the record is the evidence integrity block. Each certificate carries SHA-256 hashes of the underlying raw technical source report, the device evidence output and the controller identity data. This means the evidence behind the certificate is cryptographically verifiable and any subsequent alterations to its detectable. Few sanitization certificates in this market carry integrity hashes at all. It converts the document from an assertion into something closer to a forensic artifact.
Finally, an appendix reproduces the drive health and device information captured during sanitization, including the raw diagnostic output from the tooling rather than a summarized interpretation of it. This is deliberate. Verbatim tool output is something that an auditor or a buyer can assess without outside help. It is also useful in business, because the same appendix records firmware revision, power-on hours, wear percentage, available spare capacity and integrity error counts, which is precisely the data a resale channel needs to grade the asset. A drive at two percent wear with no logged errors is worth materially more than an ungraded one, and the grading evidence arrives as a by-product of the sanitization you did anyway.
Honest classification, not marketing classification
One aspect of how the service works deserves stating plainly, because it runs against the grain of how this industry usually markets itself.
Not every storage device supports every sanitization method. Some drives, including older NVMe devices, don’t expose the controller sanitize command at all. When that happens, our tooling detects the capability of the device, applies the strongest method that the hardware can support, and records the resulting classification accurately, whether that is Clear or Purge. The certificate reports what the device did, including capability fields that returned nothing.
The alternative, which is common, is to run whatever the drive accepts and print a higher classification on the certificate regardless. That produces a better-looking document and a worse compliance position, because the moment anyone examines the technical record, the claim collapses.
The practical implication is that classification should be a scoping conversation before the work starts, not a discovery afterwards. If devices are leaving your organization’s control through resale or lease return, Purge is the level NIST associates with that scenario. We will tell you up front which devices in your fleet can achieve it, which can’t, and what the options are for the remainder. Usually, certified physical destruction serves as the answer for the remainder, which brings us to the next point.
Wipe or destroy
Both are legitimate, and most real decommissioning projects need both.
Certified erasure preserves the asset. The hardware retains resale value, remains eligible for lease return and RMA, where physical destruction would breach the agreement, and stays in service rather than becoming waste, which is the outcome your sustainability reporting wants. Physical destruction is the correct answer for the highest sensitivity classifications, and it’s the only answer for drives that have failed, become unresponsive, or can’t complete a sanitize operation to the required level.
The sensible operating model is to sanitize and verify everything that can be verified, route everything that fails to certified destruction, and produce matched evidence for both paths under one project reference. TYTEC already operates NSA-standard disk destruction capability across Sweden, Norway, Finland and Denmark, so a single engagement can handle the whole fleet and reconcile it in a single register.
Why Nordic organizations are asking for this now
Three regulatory pressures have converged on end-of-life data, and they arrived close together.
Sweden’s Cybersecurity Act, the Cybersäkerhetslag (SFS 2025:1506), together with the accompanying Cybersecurity Ordinance (SFS 2025:1507), entered into force on 15 January 2026, transposing the EU NIS2 Directive into Swedish law and repealing the earlier Information Security Act. It applies on an entity-wide basis across eighteen designated sectors, carries explicit management accountability, and reaches penalties measured in millions of euros. For most readers the decisive provision is the supply chain security obligation, which means your suppliers may need to demonstrate how they manage risk even when those suppliers aren’t themselves directly in scope. A disposal arrangement you can’t evidence is now a documented gap in your compliance posture rather than someone else’s problem.
The GDPR position is unchanged but under sharper scrutiny. Article 17 establishes the right to erasure, and Article 32 requires appropriate technical measures for the security of processing. An undocumented wipe doesn’t discharge either obligation because the evidence is the control.
ISO/IEC 27001:2022 addresses the same ground through Annex A control 7.14, covering secure disposal or reuse of equipment, and 7.10, covering storage media. Both come up routinely during certification and surveillance audits, and they best evidence themselves with per-device certificates that an auditor can reconcile against your asset register without asking follow-up questions.
How an engagement runs
We begin by scoping the estate: device counts, media types, data classification and, critically, which sanitization level each class of device actually needs and can achieve. We reconcile asset registers at this stage rather than at the end, because that is when discrepancies are cheap to resolve.
Technicians then attend your site. Our engineers hold the access credentials that Swedish facilities require, including ID06. This means that we can begin working daily inside hyperscale, colocation and enterprise facilities across the region.
We sanitize each device using the strongest method its hardware genuinely supports, then verify it, with the verification result recorded against its serial number. We issue certificates individually and accompany them with a consolidated project register, so we can reconcile every asset tag against its outcome in one view. Devices then return to your stock for redeployment or resale, or are routed to certified destruction where verification failed or your policy requires it.
Working with a single accountable partner
TYTEC AB is an ISO 9001:2015 certified technical services provider headquartered in Kista, Stockholm, operating throughout Sweden and the Nordics. Sanitization sits alongside services we already deliver daily, including decommissioning, site surveys, structured cabling, fiber and Ethernet testing, and remote hands. For most customers that means one accountable partner across the entire hardware retirement lifecycle, from rack teardown through certified erasure to verified disposal, with a single evidence trail at the end of it.
Frequently asked questions
Does a certified wipe destroy the device?
No. Both the Clear and Purge categories leave the device operating at peak performance and resealable. Only the Destroy category physically renders media unusable.
What is the difference between Clear and Purge, and which will my devices get?
Clear resets user-addressable storage using standard commands and is appropriate for media remaining within your organization’s control. Purge applies techniques that resist laboratory-grade recovery and is the level NIST associates with media leaving your control. Which one a device can achieve depends on the capability its controller exposes, which we assess during scoping and record accurately on the certificate.
Can SSDs and NVMe drives be securely sanitized?
Yes, but not using the multi-pass overwrite patterns designed for magnetic disks. Flash media requires controller-level operations, such as cryptographic erase, block erase or format with secure erase settings. Applying legacy overwrite methods to flash is a common and serious error, because data can persist in overprovisioned or reallocated blocks that the host can’t address.
Is DoD 5220.22-M still the standard?
No. The DoD overwrite pattern remains widely quoted in marketing but isn’t the applicable reference for media sanitization. NIST SP 800-88 supersedes it, and Revision 2 defers technical definitions to current storage industry standards, including IEEE 2883-2022.
Do you issue one certificate per device or per batch?
One per device, tied to that device’s own serial number, plus a consolidated register for the project. Batch certificates are difficult to defend in an audit because they can’t demonstrate which assets the system processed.
How do I know the certificate hasn’t been altered?
Each certificate carries SHA-256 hashes of the underlying raw technical evidence, including the source report and the controller identity data. Any alteration to that evidence is detectable by recomputing the hash.
Can sanitization be performed on site?
Yes. Our technicians work at your facility, so media stays under your control, and we create no external chain of custody.
What happens if a drive fails sanitization?
It’s quarantined, recorded as failed on the project register, and routed to certified physical destruction. A device that lacks verification never receives certification as sanitized.
Which locations do you cover?
Sweden, Norway, Denmark and Finland, including Stockholm, Gothenburg, Malmö, Oslo, Copenhagen and Helsinki, with coverage extending to regional data center clusters, including all of Europe.
Does certified erasure support sustainability reporting?
Yes. Sanitizing rather than shredding keeps functional hardware in service, extends asset life and avoids the embodied carbon of premature replacement. The drive health data captured during sanitization also provides the condition evidence a resale channel needs to grade the asset.
Get an audit-ready sanitization plan
If you’re decommissioning a site, returning leased hardware, refreshing a fleet or preparing for a NIS2 or ISO 27001 audit, TYTEC can scope your sanitization requirement and produce evidence your auditors will accept without follow-up questions.
Contact TYTEC AB to discuss your requirements.

