What a certificate of destruction has to contain
Almost every vendor hands you one. Almost none of them will survive being read against your asset register, and nobody finds that out until somebody asks to see it.
The sentence that decides whether the document is worth anything
A certificate that states a quantity proves a quantity. If it says 340 drives were destroyed, it says 340 things left a building. It says nothing about which 340, and therefore nothing about your data.
A certificate listing 340 serial numbers, each matched to a method and to evidence that the method worked, can be read line by line against your asset register. That is a different document, and the two look almost identical until the day one of them is examined.
The eight things it has to carry
Each of these is here because its absence is a known way to end up holding a document that proves less than it appears to.
1. The serial number of every device, one by one
A certificate saying “340 drives” and not which ones reconciles against no asset register. It attests to a quantity, not to your data. It is the commonest omission and the most expensive.
2. The method applied, device by device
Clearing, purging and physical destruction are not equivalent and do not suit the same data. A certificate giving one method for a mixed lot is describing a procedure rather than what happened.
3. The date, and where the work took place
On site or off site changes the chain of custody. If media left your building before being processed, the interval between the two has to be covered by something other than good faith.
4. The operator by name, and the witness where there was one
A company signature is not a person's signature. Where destruction is witnessed, the witness appears on the document, or the witnessing did not happen in any way you can later show.
5. Evidence of validation, not the assertion of it
This is the point Revision 2 moves to the front. An erasure log, a verification report, a documented sample: something showing the method produced its effect.
6. What became of each device afterwards
Resold, recycled, destroyed. A drive wiped and resold and a drive shredded raise different questions, and a certificate that stops at erasure leaves the second half of the story unwritten.
7. The vendor's identity and credentials, verifiable
Certifications in this trade are easy to claim. They are verifiable with the issuing body in minutes, and that is the only check that does not rest on the vendor's word.
8. What the certificate does not cover
Devices pulled from the lot, those found unreadable, those that could not be processed. A lot of 340 drives with 6 dead ones has to produce a document that says what became of the 6.
The standard moved, and most pages have not noticed
NIST SP 800-88 Revision 2, Guidelines for Media Sanitization reached final status on 26 September 2025. A great deal of what is written about media sanitization still describes Revision 1, which is a reasonable thing to check before accepting anybody’s summary, including this one.
What moved matters here, because it moved toward exactly the thing a certificate is supposed to establish.
- The subject is now the program, not the technique
- Revision 1 read as a catalog of methods. Revision 2 shifts the focus toward establishing an agency or enterprise media sanitization program. The question stops being how a given drive gets wiped and becomes who decided what, under which rule, and where that is written down.
- What that means for you. A vendor who sells you a method without asking for your data classification is selling a technique where a program is expected.
- Technique descriptions give way to current standards
- Rather than describing procedures in the text, Revision 2 points to compliance with the latest relevant standards. That is a maintenance decision: storage media change faster than a reference document can.
- What that means for you. Work sold as being “to NIST 800-88” without naming the execution standard it actually follows now says considerably less than it used to.
- Validation enters the text
- Revision 2 introduces sanitization validation: checking that the erasure achieved what it was supposed to achieve, judged against the confidentiality and sensitivity of the data involved.
- What that means for you. That is the difference between asserting that media were wiped and demonstrating it. Across several thousand drives, that difference is the only thing an auditor examines.
- Logical sanitization and cloud are in scope
- The text now covers modern storage environments, where sanitization does not involve holding a device in your hand.
- What that means for you. An exit that leaves data sitting in an associated cloud service is not finished, and the exit plan has to say so rather than assume it.
Summarised from the publication notice. The document itself is the authority, it is free, and anybody selling you sanitization has read it or should have.
Four questions before anything leaves the building
A certificate is written at the end. Everything that decides whether it will be worth reading is settled at the beginning.
1. Who wrote the data classification?
The choice between erasing and destroying follows from it, and it belongs to you. A vendor who proposes it is deciding, on your behalf, about a risk you carry.
2. Do the media leave the site before processing?
If so, the chain of custody starts at the loading dock and not at the facility. Ask how it is held in between, in writing.
3. Will the certificate reconcile against my asset register?
A useful certificate is read against your inventory line by line. If the vendor never asks for the register, they will not be able to reconcile anything to it.
4. What happens to a device that will not read?
A drive that does not initialise does not get wiped. The rule has to be written before, or it gets decided on the dock.
Why this page exists on a site that sells none of it
Most of what is written about certificates of destruction is published by companies that shred drives. That is not a reason to distrust them, and they generally know the trade better than anybody. It does mean the writing tends to end where the shredding ends, which is one step before the question you actually have: does this document hold up.
This site destroys nothing and sells nothing that appears on a certificate, which is the only reason it can say which certificates are worth having.
What secure destruction involves at each stage is on secure data destruction, what happens to the hardware afterwards is on IT asset disposition, and the order a whole exit has to run in is on the decommissioning checklist. Who can be trusted to issue one of these in the first place is on the ITAD page.