By Prashant Saini, D-Secure Technologies | Last updated: August 2026
We get this question from prospects almost every week: "Do you support DoD wipes?" Usually the answer is yes — but then I have to ask what they're actually erasing, because for a lot of the hardware sitting in Indian data centers and offices today, DoD 5220.22-M isn't the right tool anymore, and handing over that certificate for an SSD can create more problems than it solves.
DoD 5220.22-M and IEEE 2883-2022 are the two names that come up most in sanitization conversations, but they were built almost 30 years apart, for storage technology that barely resembles each other. DoD is a legacy multi-pass overwrite method designed for spinning magnetic disks. IEEE 2883-2022 is newer, media-aware, and built for the SSD-and-NVMe world most of us actually work in now.
Here's how they compare, where each one still makes sense, and — more usefully — what different auditors actually expect to see when they show up.
DoD 5220.22-M comes from the U.S. Department of Defense's National Industrial Security Program Operating Manual (NISPOM). It dates back to 1995 and has been revised a few times since, and honestly, its name still carries more weight in procurement conversations than its technical relevance justifies.
In 2001 the DoD extended this into a 7-pass "ECE" process: passes 1–3 run the standard 3-pass wipe, pass 4 overwrites with a specific random pattern, and passes 5–7 repeat the 3-pass wipe again. It's thorough. It's also slow enough to wear out modern drives for no real security gain, which is why you mostly see it now in legacy military contracts and not much else.
Where it holds up: name recognition, government pedigree, still common in US procurement paperwork.
Where it doesn't: it was built for HDDs, the pass counts are excessive for what modern drives need, and it has no formal answer for SSDs at all.
IEEE 2883-2022, published in 2022, was built specifically to close the gaps DoD leaves open. It treats different storage types differently instead of applying one overwrite pattern everywhere.
Where it holds up: genuinely comprehensive media coverage, verification baked into the process, growing traction with bodies like ADISA.
Where it's still catching up: it's newer, so some legacy systems and contracts still name DoD by default, and implementing it properly takes a bit more care.
| Aspect | DoD 5220.22-M | IEEE 2883-2022 |
|---|---|---|
| Overwrite passes | 3 (standard) or 7 (ECE) | 1 pass, adequate for modern drives |
| Media coverage | HDDs only — SSDs not formally supported | HDDs, SSDs, NVMe, flash, optical, mobile |
| Verification | Only after the final pass | Built into every sanitization level |
| Certificate | Standard, often no cryptographic proof for SSDs | Cryptographic erase (CE) certificates, cryptographically validated |
| Who wants it | Legacy military contracts, older internal policy | NIST 800-88 auditors, HIPAA/GDPR frameworks, ADISA, enterprise IT |
DoD's multi-pass requirement made sense on drives from the '90s. It doesn't anymore. NIST's own research backs this: on modern high-density media, one properly executed, verified overwrite is enough to make data unrecoverable. IEEE 2883-2022 builds on that — faster erasure, same security outcome. More passes at this point mostly just burns time and shortens drive life.
DoD 5220.22-M was written when HDDs were basically the only game in town. It has nothing meaningful to say about:
IEEE 2883-2022 has dedicated guidance for each, which is really the whole point of the standard.
The DoD's own NISPOM documentation now tells organizations to follow NIST SP 800-88 for sanitization decisions. So functionally, DoD and IEEE both end up mapping onto the same three NIST categories:
NIST Purge is the modern default for anything holding sensitive data — it uses media-specific firmware commands that reach the full logical storage space, including areas like HPA, DCO, and remapped sectors that a plain software overwrite tends to miss entirely.
US federal and defense: DoD 5220.22-M started here, but even the NISPOM update now points to NIST SP 800-88 and IEEE 2883. Some older sub-contracts still spell out DoD 3-pass explicitly on paper — worth checking the fine print rather than assuming.
Healthcare (HIPAA): HIPAA itself doesn't name a technical standard, but auditors expect NIST 800-88 alignment in practice. Hospitals run heavily on SSDs and NVMe now, and DoD-style wiping can leave hidden sectors untouched on that hardware — so IEEE 2883 has become the de facto answer here, even without HIPAA saying so directly.
Financial services (PCI DSS): these auditors want cryptographic proof, full stop. IEEE 2883's cryptographic erase procedures are built to produce exactly that kind of tamper-evident trail.
ITAD: the shift toward IEEE 2883 here is happening fast, and certification bodies like ADISA have already folded it into their testing matrices. If a vendor is still offering DoD-only wipes for SSDs, that's a sign they haven't caught up.
We support DoD 5220.22-M and IEEE 2883-2022 side by side, along with 24+ other international standards, so the method matches whatever the contract or auditor actually asks for:
DoD 5220.22-M still shows up in legacy contracts and still carries name recognition, but a 3-pass overwrite was never actually a technical requirement — NIST has confirmed a single verified pass gets the job done on modern drives. IEEE 2883-2022 is where the industry and the auditors are heading: media-specific methods, verification built in, and cryptographic proof that actually holds up. Which one you use in practice comes down to your media mix and what the person asking for the certificate actually expects to see on it.
Not sure which standard fits your current fleet? Talk to D-Secure's team — we'll help you figure out DoD and IEEE 2883 compliant erasure from one platform, with certificates ready for whoever asks.
It's valid for legacy HDD environments and contracts that still name it specifically, but its scope is narrowing. The DoD's own guidance now points to NIST SP 800-88, and neither the 3-pass nor 7-pass DoD method formally covers SSDs.
Not formally, no — but in practice, it's what modern auditors and certification bodies increasingly expect, especially anywhere SSD, NVMe, or flash media is involved.
No. On modern high-density drives, one well-executed, verified pass is enough for irretrievable erasure. Extra passes mostly cost you time and drive wear without adding real security.
Cryptographic proof of erasure, generally. IEEE 2883-2022's cryptographic erase (CE) procedures are designed specifically to produce that kind of tamper-evident audit trail.
Yes — enterprise erasure software like D-Secure supports DoD 5220.22-M and IEEE 2883-2022 in the same platform, so you're not choosing between them at the tooling level, only at the compliance level.
About the author: Prashant Saini writes on data sanitization compliance and ITAD standards for D-Secure Technologies, covering NIST 800-88, IEEE 2883, and global data privacy regulation.
Related reading:
Explore the full D-Secure data security suite
Meeting NIST 800-88 and GDPR standards with full audit trails.
Scalable solutions for ITAD partners and large organizations.
Trusted by global enterprises for zero-leakage data sanitization.
Your email address will not be published. Providing an email is optional.
Send us an enquiry regarding: DoD vs IEEE Standards Comparison
No comments yet. Be the first to comment.