
NSA Rules for Data Destruction
Is Your Classified Data Secure? The NSA's must follow Rules for Data Destruction You Can't Ignore!

Classified IT Sanitization:What Changed in 2026
In today's world, data is a valuable asset, and its security is of utmost importance, particularly when it involves sensitive national security information. The National Security Agency (NSA) plays a critical role in protecting our nation’s data, and its guidelines on data destruction are integral to ensuring that national security classified information is kept secure and out of unauthorized hands.
One of the primary ways the United States Federal Government uses to enforce data destruction standards for classified data is the NSA Policy Manual 9-12, which outlines strict procedures for destroying of classified and sensitive IT hardware such as hard disk drives. These guidelines are designed to prevent access of classified data even by exotic laboratory style attacks by nation state actors such as the Russian GRU or Chinese MSS. Let’s take a closer look at the key data destruction requirements set forth in the NSA Policy Manual 9-12.
Overview
What Is NSA/CSS Policy Manual 9-12?
NSA/CSS Policy Manual 9-12 is the National Security Agency's authoritative guidance for the routine sanitization of information system (IS) storage devices prior to disposal or recycling. It governs how every type of classified storage media — from paper documents to hard disk drives to solid-state memory — must be handled to prevent classified data recovery by any known technique.
The manual applies to all NSA/CSS elements, contractors, and personnel and covers storage devices that may contain information ranging from unclassified to Top Secret, including compartmented, sensitive, or limited-distribution material. Compliance is not optional — it is a legal and regulatory requirement for anyone operating within the NSA/CSS ecosystem.
VERSION: FEBRUARY 2026
Storage Device Sanitization Manual
The 2026 reissuance introduces expanded guidance for emerging storage technologies — most notably Heat-Assisted Magnetic Recording (HAMR) drives — and updates regulatory references to reflect current DoD and Intelligence Community standards.
VERSION: DECEMBER 2020
Storage Device Sanitization & Destruction Manual
The 2020 edition established the baseline framework for sanitization procedures across hard-copy, magnetic, optical, and solid-state media. It referenced DoD Manual 5200.01 Vol. 3 and IC Standard 500-34 (2015 edition).
Sanitize
Apply approved method for the specific device type: degauss, disintegrate, incinerate, or power removal as appropriate.
Administrative Declassification
The responsible owner performs a risk-based review per NSA/CSS Policy 6-22 and administratively downgrades remains to unclassified.
Release for Disposal
Only after both steps above are complete may the device be released for disposal or recycling — unless the IS security officer specifies otherwise.
HERITAGE ASSET REVIEW
Before destroying any IS storage device, NSA/CSS entities must contact the National Cryptologic Museum to determine whether the device carries historical value, per the Deletion of Heritage Assets Standard Operating Procedure. This requirement was formalized in the 2026 edition.
Understanding the Importance of Secure Data Destruction
The NSA's policy on data destruction is not just about cleaning up storage devices; it’s about protecting national security. Improper disposal of sensitive information can lead to devastating consequences, including the unauthorized release of classified data, which could jeopardize both national defense and intelligence efforts. Therefore, adhering to the NSA's data destruction standards is a crucial aspect of maintaining operational security (OPSEC), protecting classified data, and often meeting contractual obligations.
The guidelines in NSA Policy Manual 9-12 help ensure that all information, whether in electronic or physical form, is securely destroyed to prevent any possibility of recovery or exploitation by adversaries.
SANITIZATION REQUIREMENTS BY DEVICE TYPE
Approved Procedures for Every Storage Medium
NSA/CSS PM 9-12 prescribes specific sanitization methods for each class of IS storage device. All procedures must use equipment listed on the relevant NSA/CSS Evaluated Products List (EPL), published quarterly at nsa.gov/resources/media-destruction-guidance/. Sanitization of materials must be done in bulk when feasible, with debris mixed after the process.
Paper
| Toner-Based Printers
|
CRT & Plasma Monitors
| Magnetic Tapes
|
Magnetic Hard Disk Drives (HDDs)
| Hybrid Drives
Laptop HDDs after 2005 and Enterprise HDDs after 2012 may be hybrid. |
HAMR Hard Drives NEW 2026
Hard drives manufactured after 2020 may be HAMRs. | Optical Media (CDs, DVDs, Blu-ray)
|
Solid-State Devices (SSDs, USB, SD, NVMe, etc.)
| MRAM (Magneto-Resistive RAM)
|
⚠ CRITICAL: HARD DRIVE IDENTIFICATION
Some HDDs and SSDs may appear physically identical. Always verify by manufacturer and model number before applying sanitization procedures. Applying the wrong method — particularly degaussing a solid-state or HAMR drive — will not achieve sanitization and may violate NSA/CSS policy. When in doubt, contact CSDSR at CSDSR_NSA@nsa.gov.
2026 POLICY REISSUANCE
Key Changes from 2020 to 2026
The February 2026 reissuance of NSA/CSS PM 9-12 reflects significant changes in storage technology, updated regulatory references, and refined procedural guidance. Organizations that established compliance programs under the 2020 edition must review these changes carefully.
HAMR Drive Guidance Added NEW The 2026 manual introduces formal sanitization procedures for Heat-Assisted Magnetic Recording (HAMR) hard drives — a technology absent from the 2020 document. Hard drives manufactured after 2020 may be HAMRs and require special handling: incineration at temperatures greater than 670°C is currently the only approved sanitization method. |