By W. Miller, TetraCore
The certificate is only as good as its specificity. A letter saying "all equipment received was securely wiped" is a courtesy, not evidence. One that lists every serial number, the method applied, the result, and who did it — backed by a chain-of-custody record — is what a customer's auditor, and an R2v3 certification body, actually accept.
What a data destruction certificate must contain
Eleven fields. If your template is missing any of them, a customer's auditor will eventually ask the obvious follow-up.
| Field | Why it is there | Example |
|---|---|---|
| Certificate number | Makes the document unique and citable in the customer's records; prevents a template from being passed off as a real certificate. | CDD-2026-09-0417 |
| Issuing company | Legal name, address, contact, and relevant certifications (R2v3 facility, NAID AAA, ISO) so the customer can verify who is attesting. | Acme ITAD LLC, R2v3 certified facility, Dallas TX |
| Customer and job reference | Ties the certificate to the engagement — customer name, site, contact, PO or work-order number. | Northwind Health — Plano DC decommission, PO 88213 |
| Asset list (one line per device) | Serial number or asset tag, make, model, media type, capacity. A certificate that says '1 pallet of drives' proves nothing about any particular drive. | S/N WX21A8… · Seagate ST4000 · HDD · 4 TB |
| Method and technique | What was done — overwrite, cryptographic erase, degauss, shred, disintegrate — and with what software or equipment, including version. | Purge — cryptographic erase, Blancco 7.x |
| Standard referenced | The framework the method was chosen from, normally NIST SP 800-88 Guidelines for Media Sanitization, with the category (clear, purge, destroy). | NIST SP 800-88, Purge |
| Result per device | Pass, fail, or destroyed — and for failures, the escalation path (typically physical destruction) and its own record. | Pass (verified) / Fail → shredded 2026-09-12 |
| Date and location | When and where sanitization or destruction took place. Dates should come from the system that recorded the event, not be typed in later. | 2026-09-12, Dallas facility, sanitization bench 3 |
| Technician and verifier | Who performed the sanitization and, where a verification or sampling program applies, who independently verified it. | Operator: J. Ortiz · Verifier: M. Chen |
| Chain-of-custody reference | The custody record ID and transfer dates — pickup, transport, receipt — that connect this certificate to the device's full history. | CoC record 2026-0917-Northwind · received 2026-09-10 |
| Attestation and signature | A plain statement that the listed devices were sanitized as described, signed by an authorized representative with name, title, and date. | Signed: R. Patel, Compliance Manager |
The NIST SP 800-88 categories, briefly
Most certificates reference NIST Special Publication 800-88, Guidelines for Media Sanitization, because it gives the industry a shared vocabulary for how thoroughly data was removed. Clear applies logical techniques — typically overwriting — that protect against simple, non-invasive recovery. Purge applies techniques such as cryptographic erase, firmware secure erase, or degaussing that make recovery infeasible even with laboratory methods. Destroy physically destroys the media — shredding, disintegrating, incinerating — so it can neither be reused nor recovered. Name the category as well as the technique; "wiped" alone does not say which one applied.
Certificate of data destruction template
Rendered here rather than offered as a download so you can adapt it to your own letterhead and records system. Use it as the checklist your template has to satisfy.
- Document title: Certificate of Data Destruction
- Certificate number (unique, sequential or system-generated)
- Issue date
- Issuing company: legal name, facility address, contact, certifications held
- Customer legal name and site the assets came from
- Customer contact who authorized the disposition
- Work-order, PO, or job reference
- Chain-of-custody record ID, pickup date, transport, and date received at the facility
| Serial / asset tag | Make / model | Media type · capacity | Category · technique · tool | Date | Operator / verifier | Result |
|---|---|---|---|---|---|---|
| WX21A8K4… | Seagate ST4000 | HDD · 4 TB | Purge · crypto erase · Blancco 7.x | 2026-09-12 | J. Ortiz / M. Chen | Pass |
| S4EVNX0M… | Samsung PM883 | SSD · 960 GB | Purge · secure erase · Blancco 7.x | 2026-09-12 | J. Ortiz / M. Chen | Fail → Destroy |
| S4EVNX0M… | Samsung PM883 | SSD · 960 GB | Destroy · shred · SEM 0301 | 2026-09-12 | D. Okafor / — | Destroyed |
For loose media processed as a lot, list the lot ID, quantity, media type, and attach the serial list as a schedule. Never summarize serials away.
- Standard referenced (e.g., NIST SP 800-88) and category applied
- Software or equipment used, with version or model
- Verification method and sampling program, if any (who verifies, how selected, independence from the operator)
- Escalation path for failed sanitization and where it is recorded
- Statement: the devices listed above were sanitized or destroyed as described, and records supporting each line are retained and available for audit
- Authorized signatory: name, title, signature, date
- Optional: witness signature; reference to photo or video evidence
Common mistakes that get certificates rejected
- No serial numbers. "Approximately 240 hard drives" is a shipping manifest, not a destruction certificate. Every device, every serial.
- A vague method. "Securely wiped" without the technique, the tool, or the NIST category leaves an auditor unable to judge whether the method was adequate for the media.
- Dates typed in after the fact. The date should be the one the sanitization system recorded, not the one someone filled in on the form.
- Mixed outcomes on one line. A device that failed logical sanitization and was then shredded has two events. Record both.
- No chain-of-custody link. A certificate that cannot be tied to the receiving record and intake serial scan is an assertion floating free of its evidence.
- No unique number. Nothing then distinguishes the real certificate from a draft, a duplicate, or a sample.
How ItemStage produces the evidence behind the certificate
ItemStage does not perform data erasure or destruction; it is the system of record around your erasure tooling and physical processes, producing the per-device evidence a defensible certificate rests on. Every sanitization attempt is an append-only event record carrying media type, method, technique, software, pass/fail result, and operator, with the completion time enforced server-side. Erasure-tool certificates import by CSV and are matched to serials, with unmatched serials reported rather than dropped. A database-enforced gate keeps any unit from leaving the sanitization stage without a passing record, and automated sampling selects at least 5% of logically sanitized media each month for verification by someone other than the operator.
The chain-of-custody PDF export turns that history into a document: one item for a per-item certificate, or a job for a per-job package with each item as its own section — every stage transition with server time and team member, a photo summary per stage, checklist answers, and each sanitization event's fields. Every timestamp is the server-recorded value; the export never accepts a device-supplied time. Many facilities issue the customer-facing certificate on their own letterhead and attach the ItemStage per-item record as the supporting evidence. For the wider certification context, see the R2v3 certification guide and the ITAD overview.
Frequently asked questions
What is a certificate of data destruction?
A formal document issued by the organization that sanitized or destroyed data-bearing media, attesting that specific, individually identified devices were rendered unrecoverable by a stated method, on a stated date, by a named technician, under a referenced standard such as NIST SP 800-88. It is the customer's evidence that their data-protection obligations were discharged when the equipment left their control.
What must a data destruction certificate include?
A unique certificate number; the issuing company's details and certifications; the customer and job reference; every device by serial number or asset tag with make, model, and media type; the sanitization method and technique, the NIST SP 800-88 category (clear, purge, or destroy), and the software or equipment used; the verification result per device; the date and location; the technician and, where applicable, the independent verifier; a reference to the chain-of-custody record; and an authorized signature with an attestation statement.
Is a certificate of data destruction legally required?
No single law names the document, but most privacy and security regimes require organizations to dispose of data securely and to be able to demonstrate it. A certificate that identifies each device and the method used is the standard way ITAD customers meet that demonstration requirement — and it is what auditors, both the customer's and an R2v3 certification body's, expect to see.
Is a certificate of destruction the same as a certificate of recycling?
No. A certificate of destruction (or sanitization) attests that the data on specific devices was rendered unrecoverable. A certificate of recycling attests that material was processed through a responsible downstream chain. An ITAD job often produces both, and a certificate that only says equipment was recycled says nothing about what happened to the data.