Certified Data Destruction Services
NIST 800-88 compliant data wiping, degaussing, and physical destruction
Data destruction is the most critical step in IT asset disposition. When your organization retires computers, servers, mobile devices, and storage media, the sensitive data on those devices must be completely and permanently destroyed. A single improperly wiped hard drive can expose thousands of customer records, employee data, or proprietary information — resulting in regulatory fines, lawsuits, and irreparable reputational damage.
Data Destruction Methods
Data Wiping / Overwriting
Software-based overwriting of all storage sectors using DoD 5220.22-M, Blancco, or similar algorithms. NIST 800-88 Clear level. Allows drive reuse. Best for functional drives in asset recovery scenarios.
Degaussing
High-powered magnetic field destroys magnetic storage (HDDs, tapes, floppy disks). NIST 800-88 Purge level. Renders drives non-functional. NSA/CSS EPL-listed degaussers required for classified data.
Physical Shredding
Industrial shredders reduce drives, SSDs, circuit boards, and other media to particles ≤2mm. NIST 800-88 Destroy level. Certificate of destruction provided. Required for failed drives and classified data.
NIST 800-88 Standards Explained
NIST Special Publication 800-88 (Guidelines for Media Sanitization) is the US federal government's definitive guide to data destruction. Published by the National Institute of Standards and Technology, it defines three levels of sanitization:
NIST 800-88: Clear
Logical techniques (overwriting) applied to user-addressable storage. Appropriate for low-sensitivity data where hardware remains within your organization.
NIST 800-88: Purge
More robust techniques like degaussing, cryptographic erase, or block erase. Applied to media being released outside organizational control, such as for resale or donation.
NIST 800-88: Destroy
Physical destruction — shredding, disintegration, incineration. Required for highly sensitive data or when Purge-level methods cannot be confirmed effective. Media cannot be reused.
What Media Requires Certified Data Destruction?
On-Site vs. Off-Site Data Destruction
On-Site (Mobile) Destruction
A certified mobile shredding unit comes to your location and destroys drives while you watch. Provides maximum chain-of-custody security since drives never leave your premises. Ideal for highly sensitive or classified data environments.
- ✓ Witnessed destruction
- ✓ No transportation risk
- ✓ Immediate certificate issued
- ✗ Higher per-unit cost
Off-Site (Plant) Destruction
Drives are transported securely (GPS-tracked, tamper-evident containers) to a certified facility for destruction. More cost-effective for large volumes. Certified chain-of-custody documentation provided throughout.
- ✓ Cost-effective for large volumes
- ✓ Industrial-grade equipment
- ✓ Serialized tracking
- ✗ Drives transported off-site
Why SSDs Need Different Treatment Than Hard Drives
This is the single most common technical mistake in data destruction, and it is worth understanding before you approve a vendor's method sheet. The overwrite techniques that work reliably on spinning hard drives do not translate cleanly to solid state media.
An SSD controller spreads writes across its memory cells to stop any one cell wearing out early, a behaviour called wear leveling. Drives also hold back a reserve of cells the operating system never sees, known as over-provisioning. Together these mean a software overwrite aimed at the addresses the OS reports may leave the original data sitting intact in cells the overwrite never touched. The drive reports success. The data is still there.
Degaussing does not solve this either. A degausser works by scrambling a magnetic field, and flash memory stores nothing magnetically — running an SSD through a degausser accomplishes precisely nothing while producing a very convincing-looking service record. If a vendor offers to degauss your SSDs, that single sentence tells you what you need to know about them.
The methods that do work are the drive's own firmware-level sanitize commands — ATA Secure Erase, NVMe Format — or a cryptographic erase, where a self-encrypting drive discards its encryption key and renders every cell unreadable at once. Both are recognised Purge-level techniques. Where neither can be confirmed, physical destruction is the honest fallback. Ask any vendor specifically how they handle flash media, and treat “we overwrite everything the same way” as a red flag.
Verification: The Step Most Often Skipped
Sanitization and verified sanitization are not the same deliverable. Running a wipe produces a log saying the wipe ran. Verification means somebody afterwards read back from the media and confirmed the data is genuinely gone — and NIST 800-88 treats that as part of the process, not an optional extra.
For a large batch, full verification of every drive is not always practical, and a documented sampling approach is normal and defensible. What is not defensible is a vendor who cannot tell you which approach they use. Ask whether verification is full or sampled, what the sample rate is, who performs it, and what happens to a drive that fails. A drive that cannot be verified should be physically destroyed rather than quietly passed through to resale.
The Media People Forget
Most data exposure at disposal does not come from the servers anyone was watching. It comes from storage nobody remembered was storage:
- Copiers and multifunction printers. Nearly every office MFP has an internal drive holding images of what it scanned, copied, and faxed. They are routinely returned to leasing companies untouched.
- Networking and security gear. Firewalls, routers, and VoIP systems store configurations and credentials that are useful to an attacker.
- Equipment with embedded storage. Medical devices, point-of-sale terminals, badge and access-control systems, industrial controllers.
- Drives already pulled from service. The failed drives sitting in a box in the server room are the ones that could not be wiped, which makes them the highest-risk media you own.
- Loose media. Backup tapes, USB sticks in desk drawers, and the laptops of departed employees.
Build the inventory before you request quotes. It changes the price, and more importantly it is the difference between disposing of what you tracked and disposing of what you actually have.
What Your Certificate of Destruction Must Contain
The certificate is the artifact an auditor will ask for, so it needs to be specific enough to stand on its own years later. At minimum it should list:
- Every device by serial number, not a lot count or a carton total
- The sanitization method applied to each device, and the standard it maps to
- The date of destruction and the physical location where it occurred
- A named individual who performed or supervised the work
- The certification the provider held at the time the work was done
A single page certifying that “one pallet of assorted equipment” was destroyed is not evidence of anything. Ask to see a sample certificate before you sign, and check that the serial numbers on it can be reconciled against the inventory you handed over.
Data Destruction FAQs
What is NIST 800-88 data sanitization?▾
What is the difference between data wiping and shredding?▾
How much does certified data destruction cost?▾
What is a certificate of data destruction?▾
Find Certified Data Destruction Providers
Browse our directory of R2 and e-Stewards certified facilities offering data destruction services near you.