A certificate of destruction proves the data on a retired device is gone. Most of the ones companies file prove considerably less, because they certify a quantity rather than a set of machines.

TL;DR

  • The certificate is the product. The physical destruction is commodity work that many suppliers can do.
  • A certificate listing a count and a date cannot be connected to any specific machine, which is the question you will eventually be asked.
  • Six fields make one usable: serial numbers, method per device, the named standard, the destruction date, the issuing entity and the outcome.
  • Ask for a sample certificate before you ask for a price. It tells you more about a vendor than the quote will.
  • Store it against the asset record, not in a folder. A certificate you cannot find from a serial number is doing a fraction of its job.
  • Read the first one line by line. Nobody reads the fourteenth, so the first is your only real chance to catch a problem.

What a certificate is actually for

It answers one question, asked at an unpredictable moment by somebody outside your team: can you show the data on this particular device was destroyed.

That question is always about a specific machine, because the people who ask it are working from an asset register, an incident, or a person’s name. A document stating that 180 units were processed on a given date cannot answer it, however reputable the supplier and however genuinely the work was done.

So the test for any certificate is simple. Pick a serial number from your register and see whether the document says anything about it. If it does not, the certificate is a receipt rather than evidence.

The six fields that make one usable

Serial numbers, individually listed. Not a quantity. This is the field most often missing and the one everything else depends on.

The method applied to each device. Different machines in one batch legitimately get different treatment, and a certificate showing one method for a mixed batch is describing a process that did not happen.

The standard, named rather than alluded to. “Industry standard” is not a standard.

The date of destruction, not collection. The gap between the two is the window in which your devices existed outside your control and had not yet been destroyed, and it is worth knowing how long that typically runs.

The issuing entity. If a subcontractor did the processing, their name belongs here, not just the company you contracted with.

The outcome per device. Recycled, resold or destroyed. This is what connects your register closure to a real end state.

The method field only helps if you know what the names mean, so here are the four you will see and where each applies.

OverwriteWrites patterns across the driveConventional hard drives. Weak on solid-state, where wear levelling can leave blocks untouched
Cryptographic eraseDestroys the encryption keyModern self-encrypting drives. Seconds regardless of capacity, and it requires the device to have been encrypted
DegaussingMagnetic field destroys the mediumMagnetic media only. Does nothing at all to a solid-state drive, which is a recurring and serious error
Physical destructionShredding or disintegrationFailed drives that will not power on, and anything where the data warrants it. No resale value afterwards

A drive that will not power on cannot be overwritten or cryptographically erased, so every batch contains a few that must be physically destroyed. A certificate that lists one method for every device in a mixed batch is worth querying.

A worked example

A company retired 180 machines after a refresh, engaged a reputable disposal vendor, and received a certificate eleven days later stating that 180 units had been processed and data destroyed to a recognised standard.

Fourteen months on, a security review asked whether the data on one specific asset tag had been destroyed. There was no way to connect the certificate to that device, or to any device. The register still showed 180 rows marked sent for disposal with nothing behind any of them.

Nothing had gone wrong physically. The devices were destroyed. The company had bought a disposal service when it needed an evidence trail, and the difference was one line in the statement of work asking for serialised reporting.

Chain of custody, and where it breaks

The hole is almost always at collection. A driver loads a pallet and signs a docket naming a number of units, and from then until the devices are booked into a facility your evidence is a count. If three machines disappeared in transit, nothing would reveal it.

Make the handover serialised rather than numeric. Produce a list of serials, have the collecting party sign against the list, keep your copy. Twenty minutes per collection, and it is the difference between a chain and a gap.

Your internal half is usually weaker than the vendor half. Devices move from a user to a desk to a storeroom to a pallet over several weeks with no record of any transfer, so by the time the vendor’s chain starts, yours has already had four unrecorded handovers.

What to do before the van arrives

Checklist:

  • Capture every serial into a list. Without it serialised certification is impossible.
  • Release devices from management and clear activation locks, or a refurbisher can only break them for parts.
  • Wipe on arrival into storage rather than at disposal, and record the date and method against the asset.
  • Note missing components and damage, so there is no dispute about what you sent.
  • Have the collecting driver sign against the serial list rather than a total.
  • Ask for the intake reconciliation, meaning what the facility counted on receipt against what you sent.

The wipe-on-arrival step changes your negotiating position as much as your risk position. With the data obligation already closed, disposal becomes a logistics decision you can take your time over rather than something done under pressure.

Who can actually issue one

Certified disposition specialists are the only suppliers whose product is the certificate, and they are built around pallets arriving at a facility. Most will not collect a single laptop from somebody’s flat, which is the constraint for a distributed fleet.

Blancco addresses the evidence problem at the point of erasure rather than afterwards, producing its own reports, which suits companies keeping hardware in-house. It publishes no price and is quote-based, confirmed on its own site 9 October 2026.

Disclosure: RemoAsset is owned by the same people who publish PeopleOpsHQ. It recovers devices from people in places you have no office and wipes them on arrival, which is the half specialists will not touch. It is not a certified IT asset disposition vendor and does not issue disposition certification, and it publishes no price and requires a demo. For certification it sits alongside a certified specialist rather than instead of one. The specialists are compared in our IT asset disposition comparison.

Final thoughts

Disposal is a commodity and evidence is not. Any number of suppliers will take hardware away and destroy it properly, and only some of them will hand you a document that answers a question about one machine fourteen months later.

Ask for a sample certificate before you ask for a price, check it against the six fields, and put serialised reporting into the statement of work. Then store each one against the asset record so that somebody starting from a serial number can reach the evidence in two clicks, because that is the shape every future question takes.

Frequently asked questions

What should a certificate of destruction contain?

Six things: individually listed serial numbers rather than a quantity, the destruction method applied to each device, the named standard rather than a reference to industry practice, the date of destruction rather than collection, the issuing entity including any subcontractor who did the processing, and the outcome per device. Ask any prospective vendor for a sample before discussing price, because a certificate that states a count and a date cannot be connected to a specific machine later, which is exactly what somebody will eventually ask about.

Is a certificate of destruction legally required?

What evidence you are obliged to hold, and for how long, depends on the jurisdiction you operate in, the nature of the data and your own sector obligations, so that is a question for local advice rather than a general rule. What is true regardless is practical: an unevidenced destruction is indistinguishable from no destruction to anybody assessing you afterwards, and reconstructing it a year later is difficult and sometimes impossible once the vendor’s records have aged and the people involved have moved on.

Does degaussing work on SSDs?

No, and this is one of the more serious recurring errors in device disposal. Degaussing applies a magnetic field strong enough to destroy data on magnetic media, and a solid-state drive stores nothing magnetically, so a degaussed SSD is an entirely intact SSD with all its data still present. For solid-state media the appropriate methods are cryptographic erase where the drive was encrypted, or physical destruction where it was not or where the drive has failed.

Should we wipe devices ourselves before sending them?

Yes, as part of receiving them into storage rather than as part of sending them away. Wiping on arrival closes the data obligation at the moment the device enters your custody, which means anything later lost or stolen from your own storeroom carries no exposure, and it removes the time pressure from choosing a disposal vendor. Record the wipe with a date, a method and the person who performed it, since an undocumented destruction is close to one that did not happen.

Can a device lifecycle platform issue certification?

Most will collect devices and wipe them, which is genuinely the harder logistics problem when hardware is with people rather than on a pallet, and most cannot issue disposition certification themselves. Ask directly whether the vendor holds a recognised certification or routes material to a partner who does, and ask whose name appears on the certificate you receive. Subcontracting is entirely normal in this industry, and vagueness about who actually processes the material is the warning sign.

How should certificates be stored?

Against the asset record rather than in a shared folder, with at minimum a document reference and a link recorded on each device’s row. The test is whether somebody starting from a serial number can reach the evidence in two clicks, because every question you will be asked arrives in that form. Keep your own pre-collection serial list and the signed handover alongside it, since those three documents together form a complete chain and the first is the one companies throw away for feeling like working paper.