Certificate of Data Destruction: What It Must Include

A certificate of data destruction is the per-device record proving that the data on a drive, phone, laptop, or tablet was sanitized: which method was used, which tool ran it, how the result was verified, and who signed off. NIST SP 800-88 Rev. 2, the U.S. government’s media sanitization guideline, recommends completing a certificate of sanitization for each storage device an organization sanitizes, per its own policies [1]. If you process used devices in volume, this certificate is the artifact your auditors, enterprise clients, and downstream buyers will ask to see.
The document goes by several names. NIST calls it a certificate of sanitization. Erasure software vendors call it a certificate of erasure. Shredding and recycling operations issue a certificate of destruction. Different labels, same job: a signed, per-device record that data is gone.
What the certificate proves (and what it does not)
The certificate documents a process. It does not, by itself, make data unrecoverable. A certificate stapled to a device that was only factory reset proves nothing except that someone printed a certificate. Its value comes from the method it records and the verification behind it.
That is why the current standards landscape matters. NIST published SP 800-88 Rev. 2 in September 2025, superseding the 2014 Revision 1 that many contracts and checklists still cite [2]. Rev. 2 keeps the three sanitization methods but, except for cryptographic erase, treats technology-specific techniques as out of scope and points technique selection at IEEE 2883 [1], the IEEE Standard for Sanitizing Storage covering methods for sanitizing logical and physical storage [3]. A certificate that names a withdrawn revision or a vague “DoD wipe” invites questions. One that names the method, the technique, and the current standard answers them. For the full picture of what changed, see our breakdown of NIST 800-88 Rev. 2’s Clear, Purge, and Destroy methods.
The fields NIST says a certificate should record
Section 4.6 of SP 800-88 Rev. 2 lists what a certificate of sanitization should capture, and it doubles as a working certificate of data destruction template [1]:
- Manufacturer, model, and serial number
- Organizationally assigned media or property number, where one exists
- Media type and media source (for example, which user or computer it came from)
- Pre-sanitization confidentiality categorization (optional)
- Sanitization method: clear, purge, or destroy
- Sanitization technique: for example degauss, overwrite, block erase, or cryptographic erase
- The tool used, including its version
- The verification method
- Personnel details: name, position, date, location, contact information, and signature
Two of these fields separate a defensible certificate from a decorative one: the tool version and the verification method. Method names are easy to print. A named tool at a named version, with a stated verification step, is what an auditor can test against.
If your operation resells devices rather than shredding them, the method field matters commercially too. Under Rev. 2, purge techniques make data recovery infeasible with state-of-the-art laboratory methods while leaving the media in a potentially reusable state, and destroy techniques leave the media unusable [1]. A certificate that records purge is also a record that the asset survived to be sold.
Request a demo to see per-device erasure certificates generated as part of the processing workflow.
Verification: the part auditors read first
Rev. 2 is direct about the purpose of verification: the goal is to determine the outcome of the sanitization technique used during the sanitization operation [1]. What that looks like depends on the method. Destructive techniques get verified by inspecting the remnants. Non-destructive techniques get verified by checking tool completion status and device health [1].
The certificate is where that verification gets recorded per device. The organization-level habit NIST recommends alongside it is tracking: maintaining records across the media lifecycle so sanitization can be confirmed across the whole enterprise, not one device at a time [1]. How you sanitize is a data sanitization program question; the certificate is that program’s paper trail.
Who will ask for your certificates
Three groups, in practice.
Certification auditors. R2v3, the SERI standard for electronics recyclers and refurbishers, requires quality controls “to assess and verify the effectiveness of the data sanitization processes” on an ongoing basis under Appendix B, including records showing devices were processed as intended [4]. Per-device sanitization records are the evidence layer those quality controls run on.
Regulated clients. HIPAA’s Security Rule makes device and media controls explicit. Covered entities must “implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored,” and must implement procedures for removing ePHI before media re-use. Both are Required implementation specifications, not addressable ones [5]. A healthcare client handing you retired devices will expect documentation that maps to those obligations.
Downstream buyers. Marketplaces and wholesale buyers of used devices want proof that inventory was processed cleanly. A certificate tied to each serial number, plus a device history they can check, is what makes that proof portable.
Certificates at volume: where manual processes break
Producing one certificate is a form-filling exercise. Producing ten thousand a month, each with the right serial number, tool version, and verification result, is a data pipeline problem. Manual certificate generation at that scale produces exactly the failure an auditor looks for: devices that shipped before their paperwork existed.
This is the problem Phonecheck was built around. The platform runs diagnostics, erasure, and certification as one workflow, generating a signed certificate of erasure for each device as it is processed, with chain of custody maintained from intake to resale. Each device also gets a Device History Report — the per-device certification record recognized by major resale marketplaces, including Back Market, Amazon Renewed, and eBay Refurbished. More than 1B checks have run through Phonecheck. The platform’s erasure is ADISA certified and aligns to NIST SP 800-88 and IEEE 2883 — the sanitization standards your auditors will check certificates against; the full list is on our standards page.
If your certificates currently live in a spreadsheet, request a demo and watch a certificate get generated per device, automatically, at line speed.
FAQ
Is a certificate of data destruction legally required?
Usually not by that name. What regulations require is the underlying control: HIPAA, for example, requires policies and procedures for media disposal and re-use as Required implementation specifications [5]. NIST recommends the certificate as the per-device record of sanitization [1]. The certificate is how you demonstrate the required controls ran.
What is the difference between a certificate of destruction and a certificate of erasure?
The method recorded. Under NIST SP 800-88 Rev. 2, destroy techniques leave media unusable, while purge techniques make recovery infeasible but preserve the media in a potentially reusable state [1]. A certificate of destruction typically records physical destruction; a certificate of erasure records that data was removed and the device survived for reuse or resale.
Who signs a certificate of sanitization?
The person who performed or verified the sanitization. NIST’s field list includes the personnel’s name, position, date, location, contact information, and signature [1]. In volume operations, a system-signed certificate tied to an operator account serves the same function with a cleaner audit trail.
How long should you keep certificates of data destruction?
NIST recommends maintaining tracking records across the media lifecycle [1], but neither Rev. 2 nor the major frameworks set one universal retention number. Retention follows your policy and your clients’ regulatory context. Keep them at least as long as the disposal decisions they document can be questioned.
Sources
- NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization. NIST, September 2025.
- SP 800-88 Rev. 2 publication record. NIST Computer Security Resource Center.
- IEEE 2883-2022, IEEE Standard for Sanitizing Storage. IEEE Standards Association, 2022.
- Guidance for Developing an R2v3 Data Sanitization Plan. SERI (R2v3 knowledge base).
- 45 CFR § 164.310, Physical safeguards. Electronic Code of Federal Regulations.