By D-Secure Editorial Team | Last updated: August 2026
A procurement checklist lands on your desk with "DoD-compliant wipe" as a hard requirement. It sounds authoritative — Department of Defense, three overwrite passes, decades of use across industries. But dig one layer deeper and the picture gets more complicated: the DoD itself stopped treating this as its primary sanitization guidance back in 2014.
That gap between reputation and current relevance causes real confusion during procurement and audits. This article covers what DoD 5220.22-M actually specifies, where it still holds up, where it falls short on modern drives, and what replaced it as the go-to standard.
DoD 5220.22-M comes from the National Industrial Security Program Operating Manual (NISPOM), a media sanitization standard originally established by the U.S. Department of Defense for wiping storage media that held classified information.
The core method: overwrite every addressable memory location with a character, then its complement, then a random character, followed by a verification pass to confirm the sanitization completed.
The standard implementation runs three overwrite passes plus a full verification pass:
In 2001, a DoD memo introduced an extended seven-pass variant — DoD 5220.22-M (ECE) — which runs the standard three-pass sequence twice with an extra pass sandwiched in between. It still shows up in some legacy procurement language, but it's rarely used today outside narrow legacy military contexts, since it adds significant time and drive wear for minimal additional benefit on the media it was designed for.
DoD 5220.22-M specifies different clear and sanitize methods depending on the storage media:
| Method | Description | Applicable media |
|---|---|---|
| Destroy | Disintegrate, incinerate, pulverize, shred or melt | All media types |
| Overwrite | Pattern, complement and random pass, then verify | Magnetic media |
| Full chip erase | Per manufacturer datasheet procedure | EEPROM, EAPROM |
Notice what's missing here: there's no dedicated method for flash-based SSDs or NVMe drives, because the standard predates their widespread enterprise use.
For traditional magnetic hard disk drives, the three-pass overwrite-and-verify process is genuinely solid. It's efficient relative to older, more extreme methods like the 35-pass Gutmann standard — a meaningful factor when processing large volumes of drives — and the built-in verification pass gives real assurance that every location was actually overwritten, not just attempted.
DoD 5220.22-M is a legacy standard built around magnetic media assumptions. It has no defined method for flash-based storage — SSDs, hybrid drives, and other modern technologies use wear levelling and block remapping that a sector-based overwrite simply can't reach the way it can on an HDD.
This isn't a minor caveat. Multiple overwrite passes are no longer recommended by NIST SP 800-88 or IEEE 2883:2022 for these media types — the sanitization technique needs to match the storage technology, not the other way around.
Since 2014, NISPOM itself has pointed to NIST SP 800-88 as the primary media sanitization guidance document. The Department of Defense no longer treats DoD 5220.22-M as the sole method for secure HDD wiping — it's now one option among several, and not the recommended one for anything beyond magnetic media.
This matters for procurement teams: requiring "DoD wiping" as a blanket standard for an entire mixed-media fleet — HDDs, SSDs, and NVMe drives together — misses the more current and more precise guidance that NISPOM itself now points to.
No — there's no official DoD Certificate of Destruction issued by the Department of Defense. That specific document doesn't exist as an official artifact.
What does exist: DoD-compliant data wiping software can generate its own certificate of erasure — documenting the method used, the device, and the verification result — that serves as auditable proof the wipe was performed correctly. It's a vendor-generated record referencing the standard, not a certificate issued by the DoD itself. Worth knowing before an auditor asks for one by that exact name.
A "DoD wipe" means overwriting all addressable locations on a drive following the steps in the DoD 5220.22-M algorithm. D-Secure Drive Eraser supports this method alongside NIST SP 800-88, IEEE 2883, and 27+ other international sanitization standards, so the same platform can apply the right method per device rather than forcing one standard across an entire mixed-media fleet.
D-Secure's DoD wiping capability includes:
For organizations handling sensitive or regulated data, disposal isn't a formality — it's a control that protects the business and its customers. DoD 5220.22-M remains a recognizable, well-documented method for magnetic media, and referencing it still carries weight in procurement conversations, particularly in sectors like government, defense-adjacent contracting, and legacy IT environments still running significant HDD fleets.
The practical move for most organizations today is to keep DoD 5220.22-M available for HDDs where it's genuinely appropriate, while defaulting to NIST SP 800-88 and IEEE 2883 for SSDs, NVMe drives, and any mixed-media disposal program — which is exactly what NISPOM itself now recommends.
It's a media sanitization method from the National Industrial Security Program Operating Manual, originally used by the U.S. Department of Defense, that overwrites data using a three-pass sequence — zeros, ones, then a random pattern — followed by verification.
Not reliably. The standard was built for magnetic media and has no defined method for flash-based storage. SSDs use wear levelling and block remapping that a sector-based overwrite can't fully address — NIST SP 800-88 and IEEE 2883:2022 are the more appropriate standards for SSDs and NVMe drives.
Not as the primary method. Since 2014, NISPOM has pointed to NIST SP 800-88 as the primary media sanitization guidance, and the DoD no longer treats 5220.22-M as the sole method for secure HDD wiping.
DoD 5220.22-M is a fixed, pass-count-based method designed for magnetic media. NIST 800-88 is a broader, risk-based framework — Clear, Purge, Destroy — that selects a sanitization technique based on the specific media type, making it applicable to HDDs, SSDs, and NVMe drives alike.
For HDDs, yes — the three-pass DoD method with verification is generally considered thorough. For SSDs and NVMe drives, pass count isn't the relevant factor at all; what matters is whether the sanitization technique can reach the areas where data may actually be stored, which overwriting alone often can't guarantee on flash media.
Need a workflow that applies the right standard per device instead of one method across your whole fleet?
Talk to the D-Secure team about DoD, NIST 800-88, and IEEE 2883 support in one platform.
Explore the full D-Secure data security suite
Meeting NIST 800-88 and GDPR standards with full audit trails.
Scalable solutions for ITAD partners and large organizations.
Trusted by global enterprises for zero-leakage data sanitization.
Your email address will not be published. Providing an email is optional.
Send us an enquiry regarding: DoD 5220.22-M Wiping Standard
No comments yet. Be the first to comment.