Knowledge
Security standards
Which standard applies to you determines the method, the equipment and the proof you need. Three frameworks come up most often in data destruction.
Security standards
- NIST SP 800-88NIST SP 800-88 Rev. 2US guideline for media sanitisation. Distinguishes between clear, purge and destroy.Read more →
- ISO/IEC 21964ISO/IEC 21964 (formerly DIN 66399)International standard for destroying data carriers, formerly DIN 66399. Works with security levels and particle sizes.Read more →
- NSA/CSS EPLNSA/CSS Policy Manual 9-12Binding manual for classified media, with lists of evaluated equipment (EPL). We check each model against the current list.Read more →
How the standards relate
NIST SP 800-88 is a guideline: it describes how an organisation sets up media sanitisation and which methods (clear, purge, destroy) fit which situation. ISO/IEC 21964 is an international standard for the destruction of data carriers, with protection classes and security levels per type of media. NSA/CSS Policy Manual 9-12 is binding for classified US government information and prescribes listed equipment.
None of these frameworks certifies a machine for your organisation. They describe what the process must achieve. The right equipment depends on your media, the sensitivity of the data and the evidence you need to provide. We are happy to help you translate a standard into a choice of machine.
Which machine fits your situation?
A specialist looks at your media, your volume and the standard you need to demonstrate.




