Skip to main content
De-NISTing in eDiscovery: Five Myths That Cost You MoneyeDiscovery & Legal Holds
4 min readFor eDiscovery Specialists

De-NISTing in eDiscovery: Five Myths That Cost You Money

You've seen it in model orders: "Parties shall de-NIST all forensic collections prior to production." It sounds technical and thorough. But if you're not careful, it'll add weeks and thousands of dollars to your collection costs without any evidentiary benefit.

De-NISTing persists in eDiscovery orders because it sounds diligent. Judges who aren't eDiscovery specialists see it in other orders and assume it's a requirement. Service providers who bill by the gigabyte have every reason to keep it there. Legal teams who learned eDiscovery in the full-disk-imaging era treat it as gospel. But this practice rests on assumptions that haven't been true since the 2015 amendments to Federal Rule of Civil Procedure 26(b)(1). Let's dismantle the myths that keep this costly provision alive.

Myth 1: De-NISTing Is a Standard Technical Requirement

Reality: De-NISTing is only necessary if you're doing full-disk imaging, which often violates proportionality principles in most civil litigation.

The National Institute of Standards and Technology maintains a reference database of known file signatures for operating system files, executables, DLL files, and other system-generated data. De-NISTing filters these files out of a forensic collection so reviewers don't wade through irrelevant system data. But if you need to de-NIST, you've already over-collected.

Federal Rule of Civil Procedure 26(b)(1) requires you to consider the importance of the issues, the amount in controversy, the parties' resources, and whether the burden or expense outweighs the likely benefits. Full-disk imaging often fails that test. As early as Deipenhorst v. City of Battle Creek in 2006, courts warned that imaging a hard drive produces massive amounts of irrelevant and potentially privileged information. A properly scoped collection never touches the system files that de-NISTing removes.

Myth 2: Model Court Orders Reflect Effective Practice

Reality: Some model orders reflect the business models of service providers who profit from over-collection, not the proportionality framework in the Federal Rules.

When a model eDiscovery order includes a de-NISTing provision, it's endorsing a collect-everything methodology. That methodology benefits vendors who charge per gigabyte. More data collected means more data processed, hosted, and billed. This volume-based pricing has shaped what the industry calls "effective practices" in ways that favor excess.

The 2015 amendments to Rule 26(b)(1) established a clear proportionality framework. Courts have taken it seriously, consistently limiting overbroad discovery requests. A blanket requirement to de-NIST contradicts that framework by assuming you'll be doing full-disk imaging in the first place. Your job isn't to manage the mess created by over-collection; it's to avoid creating that mess.

Myth 3: You Need Full-Disk Images for Forensic Soundness

Reality: Targeted collection tools can preserve full metadata integrity and chain of custody without capturing system-level data.

Forensic soundness requires documented chain of custody, preserved metadata, and defensible collection methods. It doesn't require capturing every DLL file and system executable on a custodian's hard drive. Tools like X1 Enterprise enable remote, targeted collections that capture only user-generated ESI within defined parameters while maintaining forensic integrity.

You scope by search terms, date ranges, file types, and data sources. You collect what's potentially relevant. You preserve metadata. You document the process. You never touch the operating system files that would require de-NISTing. This approach satisfies every requirement for forensic soundness without the bloat and expense of full-disk imaging.

Myth 4: De-NISTing Protects Against Producing Privileged Information

Reality: If you're relying on de-NISTing to avoid privilege issues, you've already failed to scope your collection properly.

De-NISTing removes system files. It doesn't identify privileged documents, attorney-client communications, or work product. If your collection methodology is so broad that you're worried about inadvertent privilege production, the problem isn't that you need better filtering downstream. The problem is that you're collecting data you have no business touching in the first place.

Privilege protection happens through proper scoping: identifying custodians likely to have relevant ESI, defining appropriate search parameters, and collecting from specific data sources. When you start with a full-disk image, you're guaranteed to capture privileged information along with everything else. De-NISTing won't save you from that.

Myth 5: Judges Require De-NISTing Because It's Legally Necessary

Reality: Judges include de-NISTing provisions because they've seen them in other orders, not because case law supports the practice.

In Motorola Solutions v. Hytera Communications Corp., the court emphasized that forensic examination of a party's computers "is no routine matter" and that courts must use caution to avoid unduly impinging on privacy interests. That's the opposite of a blanket requirement for full-disk imaging and de-NISTing.

When a respected judge includes a de-NISTing provision in a model order, it reflects how deeply the over-collection mindset has penetrated judicial thinking. It doesn't reflect the law. The law, consistently since 2006 and emphatically since the 2015 amendments, points toward targeted, proportional collection.

What to Do Instead

Stop accepting de-NISTing provisions in court orders without questioning the assumptions behind them. When you see a model order that requires de-NISTing, propose language that focuses on proportional collection methodology instead.

Scope your collections properly from the start. Identify custodians who are likely to have relevant ESI. Define search parameters based on the issues in dispute. Limit collections to specific date ranges and file types. Use remote collection tools that capture only user-generated data within those parameters.

Document your collection methodology. Show that you've applied the six-pronged proportionality framework from Rule 26(b)(1). Demonstrate that your targeted approach captures potentially relevant ESI while avoiding the over-collection that makes de-NISTing necessary.

And when opposing counsel or a service provider insists that you need full-disk imaging and de-NISTing, ask them to cite the case law that requires it. They won't find it. What they'll find is two decades of courts warning against exactly that approach.

You Might Also Like