Over 2,100 IT asset disposition professionals are gathering at the Bellagio right now for ITAD Summit 2026. The conversation dominating the agenda isn’t AI or the circular economy. It’s a compliance shift that quietly took effect ten months ago — and most organizations still haven’t caught up.
This week, the Bellagio in Las Vegas is hosting the largest gathering of IT asset disposition professionals in the industry — ITAD Summit 2026. Over 2,100 attendees. More than 180 exhibitors. Fifty speakers from the companies shaping the future of how organizations retire, recover, and responsibly dispose of their technology.
I want to tell you about the conversation happening on that floor right now. Because it directly affects how every organization in California — and across the country — should be managing their retiring IT hardware today.
The headline topic isn’t GPU buyback, though that market is as hot as it has ever been. It isn’t circular economy or ESG reporting, though both are reshaping procurement conversations everywhere. The topic that keeps coming up — in panel sessions, in one-on-one meetings, in the hallways between keynotes — is a compliance update that took effect ten months ago and that most organizations still haven’t fully processed.
NIST SP 800-88 Revision 1 was withdrawn on September 26, 2025. It has been superseded by Revision 2. And if your data destruction program still references the old standard, you have a problem you may not know about yet.
What changed — and why it matters more than most people realize
NIST SP 800-88 is the federal standard for media sanitization — the guidelines that define what “properly wiped” actually means for data-bearing devices. It’s the foundation that HIPAA, CCPA, GLBA, FISMA, and CMMC 2.0 compliance programs build their data destruction requirements on. When NIST updates it, the compliance landscape shifts underneath every organization that retires IT hardware.
Revision 1, published in 2014, was built for a world of spinning hard drives and traditional magnetic media. Eleven years later, the storage landscape looks completely different — SSDs, NVMe drives, M.2 form-factor media, embedded flash storage, and encrypted drives are now standard across enterprise fleets. Revision 2, effective September 2025, addresses that reality.
The shift is significant. Under Revision 2, data destruction is no longer a technical task performed on a device. It’s a governance control — something that has to be designed, documented, validated, and defensible. The question an auditor asks is no longer “did you wipe it?” It’s “can you prove, at the device level, that the sanitization method you used was appropriate for that media type — and that it worked?”
“Standard overwrite procedures do not satisfy the Purge requirement for SSD architectures with over-provisioned storage regions. If your ITAD vendor is wiping SSDs the same way they wiped spinning drives in 2018, that is not a compliant data destruction program under the current standard.”
Why this hits California organizations especially hard
The NIST SP 800-88 Rev. 2 update matters to every organization that handles data. But for California businesses operating in regulated industries — healthcare, finance, education, government, defense supply chain — the stakes are particularly high right now.
California’s CCPA and its expanded CPRA regulations require demonstrable data destruction practices for consumer data. HIPAA requires covered entities to have documented, defensible media sanitization programs. FISMA — which applies to any organization doing business with federal agencies — now explicitly requires Rev. 2 compliance in annual authorization reviews. Security authorization packages that still cite Rev. 1 as the governing framework may generate inspector general findings even if the sanitization performed was technically adequate — because the documentation doesn’t reference the current controlling standard.
The five trends shaping ITAD in 2026 — from the summit floor
Beyond the NIST compliance conversation, here’s what the industry is wrestling with at this week’s summit — and what it means for organizations managing IT asset retirement in California:
- AI is compressing hardware refresh cycles.GPU generations and memory bandwidth requirements are changing year to year. Procurement teams that once planned five-to-six year refresh horizons are piloting two-to-three year cycles. More hardware retiring faster means ITAD programs need to scale — and documentation needs to keep pace.
- Legislation is turning disposition data into a compliance necessity. Supply tightening, pricing volatility, and new regulatory requirements are making asset-level disposition documentation a compliance necessity — not just for the enterprise, but for OEMs and GHG reporting. Chain of custody is now a board-level conversation.
- The circular lifecycle model is replacing the disposal model. The most forward-thinking ITAD operators are transforming from disposal services into fully integrated circular lifecycle platforms — where value recovery, refurbishment, and materials recovery are part of one documented program rather than separate conversations.
- Secondary market device value has never been higher. With GPU and RAM prices at historic highs, retiring enterprise hardware is entering the secondary market at premium valuations. Organizations with a certified ITAD program are capturing that value. Those without one are leaving it on the table — or worse, sending it to a recycler without knowing what it was worth.
- Tool consolidation is the operational priority. The panel “Stop Paying for the Gaps Between Your Tools” reflects a real pressure point — ITAD operations that run on disconnected systems are slower, more expensive, and more prone to documentation gaps. Integrated workflows that reduce labor touchpoints while improving audit trails are the operational standard being set at this summit.
What your organization should do before the end of this month
- Audit your data destruction documentation for Rev. 1 references. If your System Security Plan, ITAD vendor contracts, or internal policies cite NIST SP 800-88 Rev. 1 or DoD 5220.22-M overwrite methods, those references need to be updated to Rev. 2 before your next compliance review.
- Confirm your ITAD vendor’s SSD and NVMe sanitization methods. Ask specifically: how do you handle SSDs with over-provisioned storage regions? What method do you use for NVMe drives? How is the result validated and documented? Vague answers are the compliance gap Rev. 2 was designed to close.
- Require device-level Certificates of Destruction. Rev. 2 elevates documentation from a recommendation to a governance requirement. Generic destruction certificates don’t satisfy the standard. You need item-level records — serial number, media type, sanitization method applied, validation result, and chain of custody — for every device.
- Assess secondary market value before anything is destroyed. In the current hardware market, destruction should be the last resort — not the default. A certified ITAD partner assesses every device for resale and refurbishment value first, then applies the appropriate sanitization method based on data sensitivity and media type.
What this means for how you choose an ITAD partner
The ITAD Summit conversation this week is ultimately about one thing: the bar for what responsible IT asset disposition looks like is rising. Faster refresh cycles, elevated hardware values, tightening regulations, and a new data sanitization standard have combined to make ITAD a strategic business function — not a logistics problem solved by whoever offers the cheapest pickup.
At Reboot Tech Recycling, we process retiring IT assets across California with certified data destruction aligned to NIST SP 800-88 Rev. 2, item-level audit reports, full chain-of-custody documentation, and Certificates of Destruction for every qualifying device. As the industry raises its standards — this week in Las Vegas and in compliance reviews across California — we make sure our clients’ programs rise with it.
The industry gathered this week to talk about where ITAD is going. The organizations that will be ahead of it are already asking the right questions of their partners today.
Want to confirm your data destruction program is aligned to NIST SP 800-88 Rev. 2? Let’s review your current process — no obligation.