The way organizations approach data sanitization is evolving.

For years, many organizations viewed data sanitization as a technical task performed at the end of a device’s life. Today, new standards and regulatory expectations recognize that effective data sanitization requires something much larger: a documented, risk-based program that spans the entire asset lifecycle.

A new white paper from CDI member Revert, From Tools to Programs: A Compliance Framework for Enterprise Data Sanitization, explores this shift and provides practical guidance for organizations seeking to align with today’s regulatory landscape.

A Program, Not Just a Process

Recent updates to NIST SP 800-88 Rev. 2, together with IEEE 2883, IEEE 2883.1, ISO/IEC 27040, and other industry frameworks, have changed expectations around media sanitization. Rather than focusing solely on technical commands or overwrite methods, organizations are expected to establish formal programs that include:

  • Risk assessment
  • Method selection based on data sensitivity
  • Independent verification
  • Documentation and certification
  • Continuous improvement

These changes recognize that successful data sanitization depends on governance, repeatable processes, and accountability.

CDI’s Eight-Stage Lifecycle Provides the Foundation

One of the central themes of the paper is the importance of the Circular Drive Initiative’s Eight-Stage Data Sanitization Lifecycle.

The lifecycle guides organizations through every phase of secure data sanitization: from identifying and classifying data through risk assessment, sanitization method selection, verification, certification, and continuous improvement. By taking this lifecycle approach, organizations can build programs that are aligned with today’s evolving standards while supporting both security and sustainability goals.

Rather than treating sanitization as a single event, CDI encourages organizations to view it as an integrated part of responsible IT asset management.

Supporting a Circular Economy

Effective data sanitization is also a critical enabler of the circular economy.

Organizations are increasingly looking to extend the useful life of storage devices through reuse, redeployment, resale, and responsible recycling. Achieving those goals requires confidence that sensitive data has been properly removed before assets leave an organization’s control.

By combining sound technical methods with documented processes and verification, organizations can reduce security risk while maximizing the value of existing storage assets.

Learn More

Revert’s white paper provides a detailed look at today’s data sanitization landscape, including regulatory developments, verification requirements, cloud considerations, risk-based method selection, and program maturity.

As a CDI member, Revert’s work demonstrates how organizations across the industry are contributing practical guidance that advances secure, sustainable storage practices.

Download the white paper to learn how enterprise data sanitization is evolving from individual tools into comprehensive, standards-based programs—and why that matters for both compliance and circularity.