A certificate of destruction with the wrong method listed on it will still get signed, filed, and forgotten.
Nobody checks the method line against the media type before it goes in a drawer. That’s the actual failure point in most data destruction programs.
A certificate is a vendor’s written claim about a process, not independent proof that the process was carried out correctly on your specific devices. There’s no single certifying body that audits the document itself, which means the vendor’s internal process matters far more than the letterhead or the signature at the bottom.
Fast Facts: What You Need To Know About Certificates Of Destruction
- A certificate of destruction is a vendor’s written record of a process: what method was used, when, and where. It does not automatically prove your specific devices went through that process correctly.
- There is no single certifying authority for the certificate itself. Anyone can issue one, which means the vendor’s actual process matters more than the document’s letterhead.
- Physical destruction methods like degaussing and shredding aren’t equally verifiable after the fact.
- Some methods don’t work at all on certain media types.
- R2v3 requires downstream vendors performing data sanitization to provide records of proof of sanitization for every data-bearing device.
- A batch certificate covering thousands of devices under one job number can’t tell you what happened to any single device inside that batch.
What Is A Certificate of Destruction, And What Does It Include?
A certificate of destruction is a document a vendor issues confirming that data-bearing media was sanitized or physically destroyed using a stated method, on a stated date, at a stated facility. A complete one should include the following, at minimum:
- Device identification. Serial numbers or asset tags for every device covered, not just a total unit count.
- Method used. The specific sanitization or destruction technique, matched correctly to the media type.
- Verification. Confirmation that destruction was checked after the fact, not just started.
- Result per device. Pass, fail, destroyed, or exception, logged individually rather than as one blanket outcome for the whole batch.
- Date and facility address. The exact date and physical location where the work happened.
- Provider identification. The vendor’s name, address, and any relevant certifications, such as NAID AAA or R2v3.
Anyone with a printer can create a certificate of destruction, so you’ll need to pay close attention to what the certificate tells you and whether anything is missing.
How to Read a Certificate of Destruction Before You Sign Off
Before filing a certificate away, check it against this list. If more than one item is missing, it’s worth asking your vendor to explain why.
| Certificate of Destruction Element | What to look for |
|---|---|
| Device identification | Serial numbers or asset tags for every unit |
| Methode | Destruction or sanitization method, correctly matched to media type |
| Verification | Confirmation the result was checked, not just attempted |
| Result status | Individual pass, fail, destroyed, or exception per device |
| Date and location | Exact date and facility address |
| Bewakingsketen | A documented link from pickup through final destruction |
Understanding The Different Destruction Methods
Not all destruction methods are created equal, and the method needs to align with the type of IT hardware.
For example, degaussing disrupts magnetic storage. It has no effect on solid-state drives, because SSDs don’t store data magnetically.
Standard shredding is a common approach for storage drives, but it can leave particle fragments large enough for forensic recovery. Newer guidance such as IEEE 2883 moves away from treating physical destruction alone as the default proof of veilige gegevensopschoning. Instead, it defines multiple validated sanitization methods (Clear, Purge, and Destruct) and emphasizes using appropriate, verifiable techniques for the storage technology involved.
Verifying that shredded media is actually unrecoverable requires knowing the resulting particle size, not just the fact that a shredder was involved.
Logical sanitization, meaning software-based erasure, has a different verification path. R2v3’s Appendix B requires a minimum of 5% of logically sanitized media to be independently sampled to confirm the data can’t be recovered, with sampling increased if problems turn up. A certificate that names an erasure tool without any reference to sampling or verification simply doesn’t go far enough.
The method line on a certificate is the single most useful thing to check before you accept it, because it’s also the easiest thing for a vendor to get wrong without anyone noticing.
Batch Certificates vs. Per-Asset Verification
Batch certificates tell you what happened with a truck shipment. Only per-asset verification tells you what happened down to the device.
The batch certificate is easier to get your hands on, but most of the time it’s not enough. Picture 4,000 drives shipped in one job. If three get misrouted, delayed, or set aside before processing, a batch certificate still closes the whole job as complete. From the vendor’s operational view, the shipment was handled.
If one of those three resurfaces later, there’s no serial number on the certificate to check it against, no per-device timestamp, no way to confirm which units were actually destroyed versus which were assumed destroyed because they were part of the shipment.
A certificate built around per-asset verification, logging each serial number against its own destruction timestamp and method, closes that gap. It costs more to produce. It’s also the only version that gives you something to investigate with if a device ever turns up somewhere it shouldn’t.
Ask your vendor whether they can pull a per-serial destruction record for a specific device shipped eighteen months ago. If they can’t find it for you, it’s worth learning why.
Evaluate The Quality Of Your Certificate Of Destruction
A certificate of destruction is only as good as the process behind it, and most companies never see that process. They see a document.
The fix is a vendor who can produce a per-serial destruction record for any device, on demand, months or years after the job closed.
Before your next refresh cycle ships, ask your ITAD vendor for a sample certificate showing per-device serial tracking and what destruction method goes with each.