Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    contact@mansfieldtech.us

Is Reselling Old IT Hardware Online Safe? How We Do It, and When Wiping Is Enough

Organizations retire hardware constantly, and a working laptop is worth money. So the question comes up in every IT department eventually: is it safe to resell old IT hardware online? The honest answer is that it depends on two things: what data the hardware held, and what your auditor, regulator, or contracting officer will ask you to prove afterward. There are two defensible paths. This post explains how we take the first one, and when the second is a reasonable choice for you.

What is actually at risk

A resold device that still holds recoverable data is a breach, and it is a breach that surfaces months later, from a buyer you never met, with no way to contain it. IBM's 2025 Cost of a Data Breach report put the average U.S. breach at $10.22 million. Studies of secondhand drives bought online have found personal and corporate data on a meaningful share of them for as long as people have been running those studies, and the pattern has not changed.

The risk is not that wiping does not work. Done correctly on the right media, it does. The risk is that "done correctly" has several steps, each of them can be skipped or botched, and the person who finds the mistake is a stranger with a screwdriver.

How Mansfield Technologies does it

We do not resell whole computers, phones, or tablets. Every one that comes to us is physically disassembled. Storage is destroyed to NIST 800-88 Destroy or NSA/CSS 9-12: hard drives are degaussed and shredded, solid-state media is disintegrated to 2 mm particles. Circuit boards go to a domestic smelter for their gold, silver, copper, and palladium. Parts that never held data (displays, keyboards, batteries, power supplies, memory, processors, chassis) are tested and resold as parts. What comes out of the shredder is recycled too.

We built the business this way on purpose. A wiped laptop sells for many times what its parts do, which is why most of the industry wipes and resells. We give that money up because our clients are hospitals, banks, defense contractors, and government offices, and for them the question is never "did the wipe probably work?" It is "can you prove the data no longer exists?" A shredded platter answers that. A log file asks you to trust it.

That approach is not for everyone, and we say so.

When wiping is enough

If your retired hardware never held regulated or classified data, a verified wipe followed by resale is a legitimate path under NIST SP 800-88 Revision 2, and it keeps working hardware in service. Here is what "verified wipe" has to mean for it to hold up:

  1. Purge, not Clear. NIST 800-88 defines three levels. Clear protects against casual recovery and is fine for a laptop moving between your own employees. For anything leaving your control, Purge is the floor: cryptographic erase on self-encrypting drives, the drive's own sanitize command, or block erase, depending on the media.
  2. Match the technique to the media. NIST 800-88 Rev. 2 no longer lists techniques itself; it points to IEEE 2883-2022 for the media-specific ones. A SATA hard drive, a SATA SSD, an NVMe drive, and a phone each need a different command, and some drives implement the command badly or not at all. Someone has to look each model up.
  3. Verify. A wipe that is not verified is a hope. Sample the drive afterward with a tool that reads what is actually there, and keep the log.
  4. Document. A Certificate of Sanitization for every device: serial number, method, tool and version, verification result, who did it, and when. This is what an auditor asks for, and "we ran the software" is not it.
  5. Plan for the failures. Drives that fail verification, drives that do not support the command, and drives that are dead cannot be wiped. They get destroyed. Decide that before the pile is on the bench.
  6. Check your obligations first. HIPAA, GLBA, CJIS, IRS 1075, and CMMC each have disposal language, and contracts often add more. If any of them apply to the data, the calculus above changes, and usually the answer is destruction.

If you can do all six, consistently, on every device, resale after wiping is defensible. If you cannot, the money you make on the laptop is not worth what the wipe you skipped could cost.

If you outsource it

Most organizations do not run the six steps themselves; they hand the hardware to a vendor. When you evaluate one, ask four questions:

  • What certifications? R2 or e-Stewards for the recycling side, NAID AAA for the destruction side. Ask to see the certificate, not the logo.
  • Do you resell whole devices? Any answer is acceptable, but you need to know it, because it tells you where the vendor's incentive sits when a wipe fails.
  • What happens to a drive that fails verification? The only good answer is "we destroy it and it appears on your certificate."
  • Show me the certificate. A sample Certificate of Sanitization or Destruction. If it does not list serial numbers and the method, keep looking.

Practices that hold up either way

  • Inventory before you retire. Know which devices held what. A device with no record of its data gets treated as if it held the worst of it.
  • Write the policy down. Which data classes get Clear, Purge, or Destroy; which media get which technique; who signs. Align it with NIST 800-88 Rev. 2 and, in Ohio, with the state's own disposal policies.
  • Pull the drives before anything is surplused. A chassis with no storage is a chassis. A chassis with a forgotten drive is a lawsuit.
  • Keep the records. Certificates, serial logs, and chain-of-custody signatures, for as long as your retention schedule says and then some.
  • Train the people who touch it. Procurement, IT, and the surplus team all need to know why the drive comes out first.

Final thoughts

Reselling old IT hardware can be safe. It requires a written policy, media-specific technique, verification, documentation, and a plan for what fails, and it requires that none of the data was the kind a regulator cares about. If that describes you, wipe it right and sell it.

If it does not, or if you would rather not run that program yourself, this is what we do: the storage is destroyed in front of you, the parts that never held data go back into service, and you get a certificate that says exactly what happened to every serial number. Tell us what you have.

About the author. Christopher McDevitt is the founder of Mansfield Technologies, a service-disabled veteran-owned company that performs on-site data destruction to NSA/CSS 9-12 and NIST 800-88. He spent ten years in the U.S. Army Signal Corps and six years supporting the U.S. Intelligence Community. More about the company.

More from the blog

Retiring hardware? Start with the destruction.

Request a custom quote