A single device retirement event now triggers three simultaneous compliance obligations under federal law — and the standard that governed data destruction for eleven years was officially withdrawn last September. If your IT disposal program hasn’t been updated since 2024, it may already be out of compliance.
Earlier this year, a mid-size defense contractor in California was preparing for its CMMC 2.0 Level 2 assessment — the federal cybersecurity certification now required for any company doing business with the Department of Defense.
The assessment team reviewed their IT asset disposal procedures. The contracts referenced DoD 5220.22-M overwrite methodology — the standard that had governed data destruction for decades. Clean, documented, familiar.
There was one problem. DoD 5220.22-M is a deprecated standard. It does not satisfy NIST SP 800-171 Practice MP.L2-3.8.3, which CMMC 2.0 requires. The contractor’s disposal program — perfectly adequate by 2023 standards — was non-compliant with the framework their federal contracts now demanded.
This is not an isolated case. It is happening across California right now, in organizations that have done everything right by the old rules — and haven’t yet caught up with the new ones.
What changed — and when
On September 26, 2025, the National Institute of Standards and Technology officially withdrew NIST SP 800-88 Revision 1 — the federal media sanitization standard that had been in place since 2014. It was superseded entirely by NIST SP 800-88 Revision 2. No grace period. No grandfather clause. The old standard is gone.
But that’s only the first layer of what changed. In 2026, a single device retirement event — one laptop leaving your organization — now triggers obligations under three parallel federal frameworks simultaneously:
Layer 1
FISMA + NIST SP 800-88 Rev. 2Federal agencies and their contractors must demonstrate compliant media sanitization under NIST SP 800-53 Control MP-6 in every annual security authorization review. Non-compliant sanitization discovered in Inspector General audits must be reported to OMB and can trigger system authorization suspension.
Layer 2
Executive Order 14057 + FAR SustainabilitySigned December 8, 2021 and now fully active, EO 14057 requires federal agencies to pursue net-zero emissions — including responsible critical minerals recovery from retiring IT hardware. Federal Acquisition Regulation sustainability provisions now require R2v3 certification from electronics recycling vendors in federal procurement contracts.
Layer 3
CMMC 2.0 + California SB 1215CMMC 2.0, finalized by DoD in 2024, requires Level 2+ defense contractors to implement NIST SP 800-171 Practice MP.L2-3.8.3 for all CUI-bearing media. And California’s SB 1215, effective January 1, 2026, expanded e-waste coverage to battery-embedded devices — adding a state-level obligation on top of the federal stack.
Three frameworks. Three sets of documentation requirements. All triggered by the same physical event: a device leaving your organization’s custody.
A single device retirement event in 2026 now triggers obligations under three parallel compliance frameworks simultaneously. Most organizations are managing these as separate activities — and creating documentation gaps in the spaces between them.
What NIST SP 800-88 Rev. 2 actually requires — in plain language
The shift from Revision 1 to Revision 2 is more than a version number update. It represents a fundamental change in what “compliant data destruction” means.
Revision 1 was technique-focused: choose a sanitization method, apply it, document it. Standard overwrite passes were widely accepted. The 2014 standard was built for a world of spinning hard drives with predictable magnetic storage architectures.
Revision 2 is program-focused. It requires organizations to build a formal sanitization governance program — with policies, validated procedures, trained personnel, vendor trust verification, and device-level evidence. And critically, it explicitly addresses the storage architectures that have become standard across enterprise fleets in the decade since Rev. 1 was published.
Critical for California IT teams: Standard overwrite procedures do NOT satisfy the Purge requirement for SSD architectures with over-provisioned storage regions under NIST SP 800-88 Rev. 2. If your organization is wiping SSDs, NVMe drives, or M.2 form-factor media using the same overwrite methods used for spinning drives, that process does not meet the current federal standard — regardless of what your vendor’s certificate says.
Revision 2 points technique requirements to IEEE 2883-2022 and NSA specifications — not to overwrite pass counts. If your vendor contracts, internal policies, or System Security Plans still reference DoD 5220.22-M or specific wipe pass counts, those references describe a deprecated methodology. An IG auditor, a CMMC assessor, or a FISMA authorization reviewer will catch that gap.
Why this hits California organizations harder than most
California sits at the center of this compliance shift for reasons that are structural, not incidental.
The state hosts more federal contractors, defense suppliers, and government-adjacent technology organizations than almost anywhere else in the country. Silicon Valley supplies hardware and software to virtually every federal agency. Southern California’s defense industrial base — from aerospace to cybersecurity — runs directly through CMMC 2.0 territory. Healthcare organizations across the state operate under HIPAA, which references NIST SP 800-88 as its benchmark for lawful device disposal. Financial institutions must satisfy GLBA and FACTA, both of which point to the same standard.
And then there’s the state layer on top of all of it. California SB 1215, effective January 1, 2026, expanded e-waste coverage to battery-embedded devices — meaning most modern laptops and tablets now carry a California disposal obligation in addition to whatever federal frameworks apply. For a California organization retiring a fleet of federal-contractor-issue laptops, that’s four frameworks touching one device.
The documentation problem most organizations miss: Under NIST SP 800-88 Rev. 2, documentation is not a recommendation — it is a governance requirement. You need serial-number-level chain-of-custody evidence for every sanitized device: what the device was, what sanitization method was applied, why that method was appropriate for that media type, validation evidence that it worked, and downstream disposition records. A generic Certificate of Destruction with a batch number does not satisfy this requirement. Neither does a recycler’s pickup receipt.
The dual-axis problem most IT teams don’t see coming
Here’s the compliance trap that is catching organizations off guard in 2026: data security and environmental sustainability are no longer separate conversations in IT disposal. They are simultaneous obligations — and they require simultaneous documentation from a single certified vendor relationship.
An ITAD vendor certified only for data destruction cannot satisfy the EO 14057 sustainability axis. A vendor certified only for environmental recycling cannot satisfy the NIST SP 800-88 data security axis. Organizations sourcing these services from separate vendors — or from a vendor that holds one certification but not the other — create a chain-of-custody gap that IG audits and FISMA authorization reviews are specifically designed to detect.
The compliance standard in 2026 is a single vendor engagement that produces documentation satisfying data security, sustainability, and chain-of-custody requirements simultaneously — with NAID AAA certified destruction and R2v3 certified recycling from the same partner, on the same device, in the same documented event.
In 2026, ‘we sent it to a recycler’ and ‘we sent it to a data destruction company’ are both incomplete answers. The question federal auditors are asking is: can you show me one document that proves both happened, for every device, with serial-level evidence?
What your organization needs to do before your next compliance review
Audit your ITAD vendor contracts and internal policies for Rev. 1 language. Any reference to NIST SP 800-88 Rev. 1, DoD 5220.22-M, or specific overwrite pass counts describes a deprecated standard. Those references need to be updated before your next FISMA review, CMMC assessment, or IG audit cycle.
Confirm your vendor’s SSD and NVMe sanitization methodology. Ask specifically: what method do you apply to SSDs with over-provisioned storage regions? How is the result validated? What IEEE 2883 or NSA specification does your process align to? Vague answers are a compliance gap.
Require serial-level Certificates of Destruction — not batch certificates. Rev. 2 requires device-level evidence. Every device needs its own documentation: serial number, media type, sanitization method, validation result, and chain of custody from pickup to final processing.
Verify your vendor holds both NAID AAA and R2v3 certification. For federal contractors and agencies, both certifications are now functionally required to satisfy the dual data security and sustainability obligations of a compliant 2026 IT disposal program.
Account for California SB 1215 on top of your federal obligations. Battery-embedded devices — virtually every modern laptop and tablet — carry a California e-waste disposal requirement in addition to federal frameworks. Your disposal documentation needs to satisfy both simultaneously.
The bottom line for California IT and compliance teams
The federal bar on IT disposal has moved. It moved in September 2025 when NIST withdrew Rev. 1. It moved again when CMMC 2.0 came into full effect across 300,000+ defense contractor entities. It moved when EO 14057 sustainability provisions embedded themselves into federal procurement. And it moved on January 1, 2026 when California SB 1215 expanded the state’s e-waste program.
None of these changes announced themselves loudly. Most organizations find out about compliance gaps when an auditor finds them first — which is the most expensive way to learn.
At Reboot Tech Recycling, we process retiring IT assets across California with certified data destruction aligned to NIST SP 800-88 Rev. 2, DTSC-licensed e-waste processing, and serial-level chain-of-custody documentation on every qualifying device. For California organizations navigating the intersection of federal compliance and state e-waste law, we provide the single-vendor documentation package that satisfies both — from pickup through final processing.
The bar has been raised. The question is whether your current program has kept pace with it.
Want to confirm your IT disposal program is aligned to NIST SP 800-88 Rev. 2 and California SB 1215? Let’s review your current process.