IT Asset Disposition (ITAD) Services

IT asset disposition (ITAD), also called IT asset disposal, is the process of retiring end-of-life IT equipment in a way that is secure, compliant, and environmentally responsible. ITAD goes beyond basic recycling — it includes data destruction, asset remarketing, value recovery, and compliance documentation. Below, learn how it works and find certified ITAD providers near you.

What Does an ITAD Company Do?

A certified ITAD provider manages the full lifecycle of your retired IT assets. This typically includes:

  • Inventory and asset tagging — cataloging equipment with serial numbers, condition, and location
  • Secure logistics — GPS-tracked pickup with chain of custody documentation
  • Data destruction — certified wiping or physical destruction of all storage media
  • Remarketing and resale — recovering value from equipment that still has market life
  • Recycling — responsible processing of components that cannot be reused
  • Compliance reporting — certificates of destruction, recycling documentation, and audit trails

Why ITAD Matters for Your Business

Every organization with IT infrastructure eventually faces equipment retirement. The risks of handling it incorrectly are significant:

  • Data breach exposure: Improperly wiped drives are a leading cause of data breaches. A single hard drive containing customer records can result in regulatory fines and lawsuits.
  • Environmental liability: Improper disposal of electronics violates EPA regulations and state e-waste laws. Companies can be held liable for cleanup costs.
  • Lost value: Equipment with remaining useful life has resale value. A good ITAD provider can offset disposal costs through remarketing.

How to Choose an ITAD Vendor

The most important factor is certification. Look for vendors with R2 or e-Stewards certification, which are the two recognized standards for responsible electronics recycling and ITAD operations. Beyond certification, consider:

  • Geographic coverage — can they service all your locations?
  • Data destruction methods — do they offer on-site destruction if required?
  • Reporting capabilities — what documentation and audit trails do they provide?
  • Value recovery — do they offer remarketing with transparent revenue sharing?
  • Insurance and liability coverage
  • References from companies in your industry

ITAD vs. Electronics Recycling

While electronics recycling focuses on material recovery and responsible disposal, ITAD is a broader service that prioritizes data security, compliance, and value recovery first, with recycling as the final step for equipment that cannot be remarketed. For enterprise IT departments, ITAD is usually the right choice because it addresses the full risk and value picture.

The ITAD Process, Step by Step

Most enterprise ITAD engagements follow the same eight stages. Knowing them makes it much easier to tell a thorough vendor from one that is quietly skipping steps.

  1. Scoping and quoting. The vendor establishes what is being retired, where it sits, and whether drives leave the building intact. Pricing that arrives before anyone has asked those questions is a guess, not a quote.
  2. Decommissioning. Equipment is powered down, unracked, and disconnected. For live data center gear this is usually the longest stage and the one most often underestimated.
  3. Inventory and serialization. Every asset is recorded by make, model, and serial number before it moves. Without this, no later report can be reconciled against what you actually sent.
  4. Secure transport. Sealed, tracked vehicles with a signed manifest at pickup and delivery. Chain of custody either exists as paperwork or it does not exist at all.
  5. Receiving and reconciliation. The vendor counts what arrives against the manifest and reports discrepancies. Ask how variances are handled before you sign, not after one appears.
  6. Data sanitization. Drives are wiped or destroyed and the result is recorded per serial number.
  7. Disposition. Assets are remarketed, harvested for parts, or sent to downstream recyclers, depending on remaining value.
  8. Reporting and settlement. You receive certificates of destruction, a disposition report, and any resale revenue owed.

Data Sanitization Methods Under NIST 800-88

NIST Special Publication 800-88 is the reference most ITAD contracts point to, and it defines three levels of media sanitization. The right one depends on how sensitive the data is and whether the drive still has resale value worth preserving.

LevelWhat it doesDrive reusable?
ClearOverwrites user-accessible storage using standard read/write commands. Defeats ordinary recovery software.Yes
PurgeApplies stronger techniques such as cryptographic erase or firmware-level sanitize commands, targeting data that a simple overwrite can miss.Yes
DestroyPhysically renders the media unusable — shredding, disintegration, or melting.No

Destroy is the most intuitive choice but it is not automatically the correct one. Shredding a three-year-old SSD eliminates a drive that may still be worth real money, and a documented Purge is accepted under most compliance regimes. Reserve physical destruction for media that failed, that cannot be verified, or that your own policy requires be destroyed.

Compliance Frameworks That Drive ITAD Requirements

Very few organizations buy ITAD because they want to. Usually a specific obligation forces the question, and which one applies changes what you need your vendor to prove:

  • HIPAA — healthcare organizations and their business associates must protect electronic health information through the end of the media lifecycle, which means disposal is in scope.
  • GLBA and FACTA — financial institutions face explicit obligations around disposing of consumer financial information.
  • SOX — publicly traded companies need auditable records, and asset disposition is part of the trail auditors follow.
  • State e-waste laws — most states restrict landfilling electronics, and requirements differ enough that multi-site companies should confirm coverage state by state.
  • GDPR — if you hold data on EU residents, disposal is a processing activity like any other and needs to be documented.

None of these name a specific vendor or certification. What they have in common is a demand for evidence, which is why serialized reporting matters more than any single destruction method.

On-Site vs. Off-Site Destruction

On-site destruction means drives are shredded or degaussed in your parking lot, usually in a mobile unit, and never leave as readable media. It costs more per drive and eliminates resale value, but it removes the transport window entirely and lets your staff witness the process.

Off-site destruction is cheaper, preserves the option of remarketing working drives, and is entirely defensible provided the chain of custody is real and documented. Most organizations do not need on-site destruction. The ones that do usually have a policy requiring it, a regulator who expects it, or data sensitive enough that the transport window is genuinely unacceptable.

Documentation to Require From Any Vendor

The deliverable that protects you is paperwork, not the physical process. Ask to see samples before signing:

  • A certificate of destructionlisting serial numbers, the sanitization method used, dates, and a named responsible party — not a single page certifying “one lot of equipment.”
  • A settlement or disposition report showing what happened to each asset: resold, harvested, or recycled.
  • Chain of custody records with signatures at every transfer point.
  • Downstream disclosure naming where material goes after it leaves the vendor, since your liability does not necessarily stop at their gate.
  • Proof of insurance, including environmental and cyber liability coverage.

Warning Signs When Vetting a Provider

  • Certification claimed but not verifiable on the official registry, or a certificate that has quietly expired.
  • Reporting offered only at the lot level, with no serial numbers.
  • Unwillingness to name downstream partners.
  • A quote produced without any questions about volume, location, or data sensitivity.
  • Resale revenue promised as a percentage with no itemized breakdown of what sold and for how much.

Every facility in this directory is checked against the official SERI (R2) and BAN (e-Stewards) registries, so the first item on that list is one you can settle before you ever pick up the phone.

ITAD FAQs

What is IT asset disposition (ITAD)?
IT asset disposition is the process of securely retiring end-of-life IT equipment — covering data destruction, value recovery through resale or parts harvesting, and environmentally compliant recycling of what remains. Certified ITAD providers document every step for compliance purposes.
How much does ITAD cost?
Typical per-unit costs are $5–$15 for laptops, $8–$20 for desktops, and $15–$50 for servers, plus $5–$15 per drive for data destruction. Equipment under 4–5 years old often has resale value that offsets these costs — large refresh projects can even be revenue-positive.
Can old IT equipment be worth money?
Yes. Laptops under 4 years old typically resell for $50–$200+, and enterprise servers and networking gear can be worth hundreds to thousands per unit. Good ITAD vendors remarket functional equipment and share 30–70% of resale revenue with you, documented in itemized reports.
What should I look for in an ITAD vendor?
Require current R2 or e-Stewards certification, NIST 800-88 compliant data destruction with serialized certificates, documented chain of custody, environmental liability insurance, and transparent value-recovery terms. Verify certification status on the official registries before signing.

Compare Certified ITAD Providers

Search our directory of R2 and e-Stewards certified ITAD companies by location and services.

Find ITAD Companies