The Certificate of Destruction
Two documents, issued for every job: a digitally signed letter that names the client, the date, and the standard achieved, and a media log with one row for every item, down to the serial number and the two technicians who destroyed it. Here is a real one, with the client redacted, and what every field means.

Part one: the letter
- Date, COD number, invoice numberThe certificate number and the invoice number are the same, so the record ties to the transaction with no lookup.
- ClientThe organization the letter is issued to, and the party the audit clause protects.
- Standard achievedThe sanitization standard the whole job was destroyed to, in the box: NIST 800-88 at the security level you specified, or NSA/CSS 9-12 for classified media. One standard per certificate; a mixed job gets two.
- Confidentiality clauseOur acknowledgment that the material was confidential, our commitment that it was protected until destroyed, and our statement that we did not read, copy, sell, or disclose it.
- GuaranteeThat the process met or exceeded NSA/CSS 9-12, NIST 800-88, HIPAA, SOX, PCI, GLBA, and the Privacy Act, with the recycling disposition stated.
- Audit rightYour organization may audit the destruction of any item on the certificate for three years.
- Digital signatureSigned by the founder with a timestamped digital certificate. Any change to the file after signing breaks the signature.
Part two: the media log
One row per item, in a spreadsheet you can drop into your asset system. The columns follow the sanitization record NIST 800-88 Rev. 2 describes and the administrative declassification details NSA/CSS Policy Manual 6-22 calls for. The rows below are illustrative; the columns are exactly what you receive.
| Asset Tag # | Media SN | Make | MPN | Media Type | Media Source | Destruction Equipment | Tech 1 | Tech 2 | Date | Tote # | Seal 1 / Seal 2 | Customer Approval | Reason for Release | Data Sensitivity | Recycling Partner |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| A-0141 | WD-WX21A8C0K4LT | Western Digital | WD5000AAKX | HDD | Storage room | LM-1 degausser, 5HD3 shredder | MT-01 | MT-02 | 2026-05-27 | T-07 | 0048211 / 0048212 | J. Reyes | End of life | HIPAA PHI | R2-certified partner |
| A-0142 | S3Z9NX0M604512 | Samsung | MZ-77E500 | SSD, 2.5-inch | Storage room | GigaBiter GB12 | MT-01 | MT-02 | 2026-05-27 | T-07 | 0048211 / 0048212 | J. Reyes | End of life | HIPAA PHI | R2-certified partner |
| A-0157 | None found | N/A | Storage room | Chassis inspected, no media | MT-01 | MT-02 | 2026-05-27 | J. Reyes | End of life | HIPAA PHI | R2-certified partner | ||||
| A-0160 | PHKS2101003D512 | Intel | SSDPEKNW512G8 | M.2 NVMe | Rack 3 | GigaBiter GB12 | MT-01 | MT-02 | 2026-05-27 | T-08 | 0048213 / 0048214 | J. Reyes | Migration | HIPAA PHI | R2-certified partner |
| LIB-22 | L40113L6 | IBM | LTO-6 | Tape | Tape library | LM-1 degausser, 5HD3 shredder | MT-01 | MT-02 | 2026-05-27 | T-08 | 0048213 / 0048214 | J. Reyes | Retention expired | HIPAA PHI | R2-certified partner |
What each column is for
- Asset Tag #Your inventory number for the parent device, so the row matches your asset system.
- Media SNThe serial number of the drive, SSD, or tape itself, read from the label before destruction. “None found” means we opened the device and it held no media.
- Make and MPNManufacturer and part number of the media, which is what NIST 800-88 asks for and what an assessor uses to confirm the method fit the media.
- Media TypeHDD, SSD, M.2, tape, phone, and so on. Decides which machine the item goes to.
- Media SourceWhere it came from on your site: a storage room, a rack, a closet. Establishes the start of the chain of custody.
- Destruction EquipmentThe machine or machines used: the LM-1 degausser and the shredder for magnetic media, the GigaBiter for solid-state. The certificate names the equipment, not just the method.
- Tech 1 and Tech 2Two technician IDs on every row. Two-person handling is what the DoD SAP manual requires for accountable material, so we do it for everyone.
- DateThe day the item was destroyed.
- Tote # and Seal #For media that is staged before destruction, the container and the two tamper-evident seals that closed it, so custody is unbroken while it waits.
- Customer ApprovalThe name of your representative who released the media for destruction and witnessed it.
- Reason for ReleaseEnd of life, failed drive, migration, or whatever your records say.
- Data SensitivityThe classification or regulatory category you told us applied: PHI, CJIS, CUI, PII, or a classification level. It drives the method and the particle size.
- Intended Recycling PartnerWhere the destroyed material went next, by name, for downstream due diligence.
Using it in an audit
The letter answers the question every reviewer asks first: was the media destroyed, to what standard, and who says so. The log answers the follow-ups: which media, which machine, which two people, and where the pieces went. Together they cover NIST 800-88 Rev. 2's documentation requirement, the media disposal objectives in NIST 800-171A for CUI, HIPAA's device and media controls, the CJIS Security Policy's disposal record, and IRS Publication 1075's sanitization documentation. Keep both with the asset records for the retention period your policy sets, and keep the COD number; that is how you ask us for a copy.
The row that says “none found” deserves a mention. A computer that arrives with no drive is not a computer with no data; it is a question. We open it, confirm it, and write it down, so nobody has to wonder later whether the drive was pulled before it reached us.
Questions
Do auditors accept it?
It is written to be the record NIST 800-88 Rev. 2 describes: what was destroyed, how, on what equipment, by whom, when, and where it went. HIPAA, CJIS, CMMC, IRS 1075, and GLBA reviewers have all accepted it, and the audit clause in the letter gives your organization the right to audit the destruction for three years.
Is every serial number on it?
Every item gets a row, including devices that turned out to hold no media, which are recorded as “none found.” That row is the proof that the chassis was opened and checked rather than assumed empty.
Can you match our asset tags?
Yes. Give us your inventory export, or let our technicians read the tags, and the Asset Tag column matches your system line for line.
What does the digital signature do?
The letter is signed with a digital certificate that stamps the signer, the date, and the time, and that fails validation if the document is altered afterward. Open it in any PDF reader and the signature panel shows whether it is intact.
What about Special Access Program material?
DoDM 5205.07 requires an itemized certificate signed by two SAP-briefed people. The two-technician columns are already there; for SAP jobs your briefed personnel sign as the witnesses, under your PSO’s conditions.
How long do you keep your copy?
We retain the letter and the media log for the length of the audit period in the letter, and longer on request. Ask for a copy at any time by COD number.
