Table of Contents
If your organization holds a DoD contract in 2026, the CMMC 2.0 clock has stopped being theoretical. Assessments are happening, prime contractors are cascading flow-down requirements, and the Media Protection (MP) family of controls is one of the fastest ways a Level 2 assessment goes sideways. It's also — for most defense contractors — the control family that has been handled the most informally for the longest time.
This guide walks through exactly what CMMC 2.0 requires for data destruction, how NIST SP 800-88 maps to the MP controls, what evidence a C3PAO assessor is going to want to see, and how to structure a CMMC-ready ITAD program that survives an audit without last-minute scrambling.
What CMMC 2.0 Requires for Media Sanitization
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors and subcontractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) implement the security controls in NIST SP 800-171. Media sanitization sits in the Media Protection (MP) family — one of 14 domains — and applies to Level 2 (Advanced) and Level 3 (Expert) certifications.
The relevant NIST 800-171 control (MP.L2-3.8.3) states plainly: "Sanitize or destroy system media containing CUI before disposal or release for reuse." The word "sanitize" points directly to NIST SP 800-88 Rev. 1, which defines Clear, Purge, and Destroy as the three permissible methods.
The MP Family of Controls, Line by Line
- MP.L2-3.8.1 — Protect system media containing CUI. Applies to media in storage and in transit.
- MP.L2-3.8.2 — Limit access to CUI on system media to authorized users.
- MP.L2-3.8.3 — Sanitize or destroy system media containing CUI before disposal or release for reuse. This is the ITAD control.
- MP.L2-3.8.4 — Mark media with necessary CUI markings and distribution limitations.
- MP.L2-3.8.5 — Control access to media during transport.
- MP.L2-3.8.6 — Implement cryptographic mechanisms for CUI on digital media during transport unless otherwise protected.
- MP.L2-3.8.9 — Protect the confidentiality of backup CUI at storage locations.
Approved Destruction Methods Under CMMC
Practical mapping of NIST 800-88 methods to common CMMC media types:
- HDDs holding CUI: Purge (degaussing followed by verification) or Destroy (shredding to ≤2mm particles).
- SSDs / NVMe holding CUI: Purge via manufacturer-supported cryptographic erase, or Destroy via physical shredding. Do not rely on multi-pass overwrites.
- Magnetic tape backups: Degauss with an NSA-listed degausser, then shred.
- Optical media (BD, DVD): Destroy — cross-cut shredding to fragment size specified by NSA/CSS Policy 9-12.
- Mobile devices with CUI: Manufacturer secure wipe (Purge) followed by physical destruction of the storage IC for high-sensitivity CUI.
- Paper CUI: Cross-cut shredding to 1mm × 5mm particles per NSA/CSS 02-01.
The Documentation Auditors Actually Ask For
A C3PAO assessor is going to ask for evidence of policy, process, and per-event execution. In a CMMC Level 2 assessment, the ITAD evidence package we consistently see requested is:
- Written media sanitization policy that references NIST 800-88.
- Documented procedure defining who executes destruction, using what tools, and how it's witnessed.
- Vendor certifications: NAID AAA (data destruction), R2v3 (recycling), and preferably ISO 27001.
- Signed MSA and NDA with the ITAD provider (and CUI-handling flow-down where applicable).
- Serialized, per-device Certificates of Destruction for the assessment window.
- Chain-of-custody logs from pickup through final disposition.
- Sanitization tool verification records (degausser calibration, shredder maintenance).
How to Pick a CMMC-Ready ITAD Provider
Non-negotiables when vetting an ITAD partner for a CMMC 2.0 environment:
- Independently audited NAID AAA and R2v3 certifications.
- Documented NIST 800-88 procedures with method mapping.
- Per-device serialized Certificates of Destruction.
- GPS-tracked, tamper-evident chain of custody.
- Willingness to sign a CUI-handling addendum and support your SSP.
- On-site destruction capability for the most sensitive CUI.
- US-owned and operated, with US-based data handling.
Phoenix ITAD supports defense contractors across Arizona with CMMC-ready ITAD — including NIST 800-88 media sanitization, on-site witnessed shredding, and per-device Certificates of Destruction formatted for C3PAO evidence.
Frequently Asked Questions
Does CMMC 2.0 require NIST 800-88 for data destruction?
CMMC 2.0 Media Protection controls (MP.L2-3.8.3) require sanitization or destruction of information system media before disposal or reuse using methods commensurate with the sensitivity of the information. The DoD's authoritative reference for those methods is NIST SP 800-88 Rev. 1 (soon Rev. 2), so in practice a CMMC-compliant ITAD program uses NIST 800-88 Purge or Destroy for every device that has stored CUI.
Which CMMC level requires data destruction?
Media protection is required at CMMC Level 2 and Level 3. Level 1 (Federal Contract Information only) has a lighter media protection requirement. Any contractor handling Controlled Unclassified Information (CUI) must implement the MP family of controls at Level 2 or above.
Can I use an internal team for CMMC data destruction or do I need a certified vendor?
CMMC does not mandate an external vendor, but auditors want to see documented, repeatable process and evidence — which is much harder to produce internally. Most defense contractors use a NAID AAA and R2v3 certified ITAD partner because the certifications provide independent audit evidence that satisfies CMMC assessors.
What is a Certificate of Destruction under CMMC?
A CMMC-appropriate Certificate of Destruction identifies the device (serial number, model), the destruction method (NIST 800-88 Purge or Destroy), the date and location, the technician, and the certifications the provider holds. Phoenix ITAD's per-device Certificates of Destruction are formatted specifically for CMMC assessment evidence.
Are SSDs handled differently than HDDs under CMMC?
Yes. NIST 800-88 requires cryptographic erase or physical destruction for SSDs and NVMe drives — traditional multi-pass overwrites are not effective on flash. CMMC-compliant destruction of SSDs typically uses either firmware-level Purge or physical shredding to ≤2mm particles.
Does CMMC allow off-site destruction?
Yes, provided chain-of-custody is documented from your facility to the destruction facility with tamper-evident containers, GPS-tracked transport, and serialized manifests. For the highest-sensitivity CUI, many contractors specify on-site witnessed shredding to eliminate transit risk.
Need CMMC-Ready ITAD?
Phoenix ITAD provides NIST 800-88 media sanitization, NAID AAA certified destruction, and C3PAO-audit-ready documentation for Arizona defense contractors.
Request a CMMC ITAD Assessment