What Is IT Asset Disposition (ITAD)? Process, Standards, and Software

IT asset disposition, or ITAD, is the discipline of retiring IT equipment the right way: getting the data off every device so it cannot be recovered, documenting that it happened, and recovering whatever value the hardware still holds through reuse, resale, or responsible recycling. It sits at the junction of two problems that pull in opposite directions. Security wants retired devices treated as radioactive. Finance wants them treated as inventory. A working ITAD program satisfies both.
The stakes on each side are concrete. On the security side, NIST warns that attackers who cannot beat access controls and encryption may go after residual data on storage media that has left an organization’s control, which is why approved sanitization methods exist [1]. On the waste side, the world produced a record 62 million tonnes of e-waste in 2022, and only 22 per cent of it was formally recycled [2]. Every device an ITAD program returns to use is a device that stays out of that number for another cycle.
The ITAD process, step by step
The shape of the process is consistent whether you run it in-house or hand it to a vendor.
1. Intake and chain of custody. Every device gets identified (make, model, serial) and tracked from the moment it leaves service. Custody gaps are where audits fail and where devices with live data go missing.
2. Audit and diagnostics. Each unit gets tested to establish condition and resale potential. This is where the reuse-versus-recycle fork gets decided, per device rather than per pallet.
3. Data sanitization. The core of ITAD. NIST SP 800-88 Rev. 2 defines the three method families: clear, purge, and destroy. Purge techniques make data recovery infeasible with state-of-the-art laboratory methods while preserving the media in a potentially reusable state, and destroy techniques leave the media unusable [1]. When possible, NIST says purge should be used instead of clear [1]. The standard itself — and what changed in the 2025 revision — is covered in our breakdown of NIST 800-88 Rev. 2.
4. Documentation. Rev. 2 recommends a certificate of sanitization for each device, recording the method, technique, tool and version, verification, and a signature [1]. The certificate of data destruction is the artifact auditors and downstream buyers will ask for.
5. Value recovery or recycling. Sanitized devices with resale value go back to market. The rest are recycled through certified processors.
Request a demo to see steps 2 through 4 run as one automated workflow.
Why the “purge, don’t shred” decision is a financial one
Shredding every drive is the easy compliance answer and the expensive one. Because purge leaves media in a potentially reusable state [1], a purged laptop or phone is still an asset; a shredded one is scrap. For organizations retiring thousands of devices, the resale value recovered by purge-first processing is what turns ITAD from a cost center into a revenue line. The compliance case and the commercial case point the same direction, which is rare enough to be worth noticing.
Standards and certifications that govern ITAD
Four references come up in nearly every ITAD contract or RFP.
NIST SP 800-88 Rev. 2 is the U.S. government’s media sanitization guideline, current as of September 2025, and the default reference for method selection [1]. IEEE 2883-2022, the IEEE Standard for Sanitizing Storage, is where Rev. 2 now points readers for technology-specific sanitization techniques [1][3].
On the facility side, R2v3 is SERI’s standard: it “provides a common set of criteria to recognize responsible reuse and recycling practices, all along the used portion of the electronics lifecycle” [4]. NAID AAA Certification, run by i-SIGMA, is “a voluntary program for member companies providing secure information destruction” [5].
Regulation adds a floor under all of it for certain data types. HIPAA’s Security Rule, for example, requires covered entities to implement policies and procedures for the final disposition of electronic protected health information and for removing ePHI from media before re-use; both are Required implementation specifications [6]. If your ITAD program touches healthcare clients, those obligations flow down to you.
ITAD software vs. ITAD services
There are two ways to run the process. ITAD services means shipping retired assets to a specialist vendor who processes them and returns reports. ITAD software means running intake, diagnostics, sanitization, and certification on your own line, with tooling that records each step.
The trade is control and margin against convenience. A service is one contract and zero operational lift. Software keeps the resale margin in-house and puts the evidence trail under your own roof, which matters once volume is high enough that per-device service fees outrun the cost of running the line yourself. Refurbishers, buyback operators, and processors who already touch every device tend to land on the software side, because the marginal cost of sanitizing and certifying during existing handling is small. The two models are not rivals so much as the same line under different roofs: most ITAD service providers run exactly this class of software on their own floors. The question is who runs the line, and who keeps the margin.
Where Phonecheck fits
Phonecheck is the device lifecycle platform for the software side of that decision: diagnostics, erasure, and certification for mobile devices, Macs, Chromebooks, and Windows machines in one workflow. Each processed device gets audit-grade erasure with a signed certificate of erasure, a maintained chain of custody, and a Device History Report — the per-device certification record recognized by major resale marketplaces, including Back Market, Amazon Renewed, and eBay Refurbished. More than 1B checks have run through Phonecheck. The platform’s erasure is ADISA certified and aligns to the sanitization standards above — NIST SP 800-88 and IEEE 2883; the full list is on our standards page.
If you are standing up an ITAD capability, or replacing per-device service fees with your own line, request a demo and run your own inventory through it.
FAQ
What does ITAD stand for?
IT asset disposition (sometimes IT asset disposal). It covers the secure retirement of IT equipment: data sanitization, documentation, and reuse, resale, or recycling of the hardware.
What is the difference between ITAD and e-waste recycling?
Recycling is one exit path inside ITAD, and the last resort. An ITAD program tests and sanitizes devices first so that working hardware can be resold or redeployed; only what cannot be reused gets recycled. Recycling destroys the asset’s remaining value, and formal recycling captured only 22 per cent of the world’s e-waste in 2022 anyway [2].
Does an ITAD program require physical destruction of drives?
Not by default. NIST recognizes purge techniques that make recovery infeasible while leaving media reusable, and recommends purge over clear when possible [1]. Destruction is the right call for media that cannot be purged with verification, or where policy demands it.
What should ITAD documentation include per device?
NIST’s certificate of sanitization fields are the working checklist: device identifiers, media type, sanitization method and technique, tool and version, verification method, and the responsible person’s details and signature [1].
Sources
- NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization. NIST, September 2025.
- The world generated 62 million tonnes of electronic waste in just one year. ITU (Global E-waste Monitor 2024, ITU/UNITAR), April 2024.
- IEEE 2883-2022, IEEE Standard for Sanitizing Storage. IEEE Standards Association, 2022.
- What is R2? SERI (Sustainable Electronics Recycling International).
- Certifications. i-SIGMA (NAID AAA Certification).
- 45 CFR § 164.310, Physical safeguards. Electronic Code of Federal Regulations.