Three standards come up in almost every UK data destruction tender, and they are not
alternatives to one another. One is an American guideline, one is a British and European code of
practice, and one is a UK government standard. A supplier can be measured against all three at
once, and buyers routinely ask for the wrong one.
This is what each covers, who sets it, and when it applies.
NIST SP 800-88, the method vocabulary everyone borrows
NIST SP 800-88 Revision 1, Guidelines for Media Sanitization, was published in
December 2014 by the United States National Institute of Standards and Technology. It is guidance
rather than a certification, and there is no such thing as being audited as NIST 800-88 certified.
Its value is that it gave the industry a shared vocabulary.
It defines three levels of sanitisation.
- Clear applies logical techniques such as a standard overwrite. It defeats
casual recovery using ordinary tools. - Purge applies stronger techniques, including cryptographic erase and firmware
level commands, so that data cannot be recovered even in a laboratory using the media’s own
interfaces. - Destroy renders the media physically unusable, by shredding, disintegration or
incineration.
Most software erasure sold in the UK maps to Purge. Most shredding maps to Destroy. When a
supplier says a drive was sanitised to NIST 800-88, ask which of the three they mean, because the
difference between Clear and Purge decides whether the drive can safely leave your building.
BS EN 15713:2023, how the destruction is actually carried out
BS EN 15713:2023 is the British and European code of practice for the secure
destruction of confidential material. It replaced the 2009 edition, and unlike NIST 800-88 it is
certifiable, so a supplier can be independently audited against it.
Its scope is the process rather than the drive. It covers how material is collected, how it is
transported, how staff are screened, how premises are secured, how destruction is carried out and
how it is documented. That makes it the standard that governs the parts of a disposal a customer
never sees, which is where most real risk sits.
The standard sets maximum particle sizes for different categories of material. The specific
figures are published by BSI and we do not reproduce them here. A supplier claiming compliance
should be able to state which category your media falls into and the size it will be reduced to.
HMG IA Standard No. 5, the government one
The standard usually called IS5 is HMG IA Standard No. 5, Secure Sanitisation.
The IA stands for Information Assurance, although the industry almost universally writes it as
Infosec Standard 5. It is owned by the National Cyber Security Centre, and it is not withdrawn.
Version 5.0 onwards was updated to reflect the Government Classification Scheme and abandoned the
older Business Impact Levels.
IS5 matters if you hold government data. It is the reference point behind the NCSC’s assured
service scheme for sanitisation, known as CAS-S. In the NCSC’s own words, CAS
assessment against the sanitisation service requirement is a certification scheme to which
commercial sanitisation services may subscribe, demonstrating compliance with IS5 when serving
government customers. If you are placing government work and your contract specifies IS5, the
question to ask a supplier is whether they hold CAS-S, not whether they have heard of the
standard.
What the NCSC actually recommends today
The NCSC publishes current guidance on the secure sanitisation of storage media, and it is
shorter and blunter than most commercial material on the subject. It describes two routes.
Non-destructive sanitisation overwrites the media and verifies the result, and is appropriate where
equipment is going to be re-used. Destructive sanitisation reduces the media to particles of 6mm or
less. Degaussing is listed as an option for magnetic media only, which rules it out for solid-state
storage.
The guidance carries a scope limit worth quoting to anyone who believes destruction is absolute.
It applies to material classified at OFFICIAL, and the NCSC states plainly that it will not protect
data from being read by a skilled, well-funded laboratory. No commercial supplier can honestly
promise more than the standard itself does.
Which one applies to you
If you are a commercial organisation with no government data, BS EN 15713:2023 is the one that
tells you whether the supplier’s process is sound, and NIST 800-88 is the vocabulary you will use
to specify what happens to each drive.
If you hold government data, IS5 governs, and the practical test is whether the supplier holds
CAS-S for the classification you are working at.
If your obligation comes from an information security management system rather than a
government contract, the requirement usually traces to ISO 27001 Annex A, which obliges you to
verify that data has been removed before equipment leaves your control. That is a documentation
requirement as much as a technical one, and it is why a certificate of destruction naming the
serial number matters more than the method used.
What Surplex UK Limited holds
Certified to BS EN 15713:2023 for secure destruction. Mechanical shredding of
hard drives and solid-state media, which is the Destroy method defined by NIST
800-88, and Certus certified software erasure to the same standard’s
Purge method where value is recovered from hardware. Environment Agency licensed carrier including
hazardous waste, certified to ISO 14001:2015, registered with the Information Commissioner’s Office
under number Z9955515, and staff vetted to BS 7858. Media awaiting destruction is held in a BS EN
1143-1 rated strong room.
Every collection produces a certificate of destruction against each device serial number,
whichever method was used. Most customers find their collection is free, and there is no minimum
quantity. Where the recovered value does not cover the work, a small logistics and processing fee
is payable, quoted and agreed upfront.
Frequently asked questions
No. NIST SP 800-88 Revision 1 is a guideline published by the United States National Institute of Standards and Technology in December 2014, and there is no audit or certificate against it. A supplier can work to its methods, and should tell you which of the three it applied, but nobody is certified to it. Certification in the UK comes from BS EN 15713:2023 for the destruction process, or CAS-S where government data is involved.
They are the three levels of sanitisation defined by NIST 800-88. Clear uses a standard overwrite and defeats recovery with ordinary tools. Purge uses stronger techniques such as cryptographic erase or firmware level commands, so data cannot be recovered through the media’s own interfaces. Destroy renders the media physically unusable by shredding, disintegration or incineration. Software erasure normally maps to Purge and shredding to Destroy.
No. HMG IA Standard No. 5, Secure Sanitisation, is owned by the National Cyber Security Centre and remains the government reference for sanitisation. Version 5.0 onwards was updated to reflect the Government Classification Scheme and abandoned the older Business Impact Levels. It is frequently written as Infosec Standard 5, although the document’s own title uses Information Assurance.
CAS-S is the National Cyber Security Centre’s assured service scheme for sanitisation. The NCSC describes it as a certification scheme to which commercial sanitisation services may subscribe, demonstrating compliance with IS5 when serving government customers. If your contract specifies IS5 and you are handling government data, ask whether the supplier holds CAS-S at the classification you work at.
NCSC guidance on secure sanitisation describes destructive sanitisation as reducing media to particles of 6mm or less. It also notes that degaussing applies only to magnetic media, so it is not an option for solid-state storage, and that the guidance covers material classified at OFFICIAL and will not protect data from a skilled, well-funded laboratory.
For commercial data with no government involvement, specify BS EN 15713:2023 for the destruction process and use NIST 800-88 terms to say what should happen to each drive. For government data, IS5 governs and CAS-S is the practical test. If your obligation comes from ISO 27001 rather than a contract, what matters most is the evidence, which means a certificate of destruction naming each device serial number.
Focused Disposal & Data Security
Comprehensive IT Solutions

Get in Touch About Your IT Recycling Needs
We provide IT recycling services for organisations of all sizes across England, Wales and Scotland.
Whether you’re recycling a few old laptops, decommissioning a data centre, or need secure data destruction, our team will help you dispose of IT equipment compliantly and responsibly.
Prefer to speak with us directly?
Call: +44 (0)1684 252583
Email: info@surplex.co.uk
Monday-Friday, 9am-5pm




