{"industry":{"id":"827514c6-e279-422b-b56a-f1cba07d8bd6","slug":"cybersecurity","label":"Cybersecurity","description":"SIEM, endpoint protection, and identity security"},"topic":{"slug":"itad-data-destruction","label":"ITAD & Data Destruction","description":"IT asset disposition, secure data destruction, and end-of-life electronics: certifications, chain of custody, documentation, and compliance.","schemaKind":null},"answer":{"id":"7c6e4179-220c-4c45-97ad-a72d0ee0b09a","slug":"what-documentation-should-a-mid-market-itad-engagement-produce","question":"What documentation should a mid-market ITAD engagement produce?","answerMarkdown":"A mid-market ITAD engagement should produce seven linked records: a serialized inventory of every asset collected, chain-of-custody documentation for each handoff, a certificate of data destruction or sanitization that names individual serial numbers, an exception report covering any device that failed sanitization or never arrived, a certificate of recycling showing material weights and downstream disposition, a settlement statement for resold assets, and a final disposition report that reconciles back to the submitted inventory. NIST SP 800-88 Rev. 2 specifies what belongs on the destruction record itself, including manufacturer, model, serial number, media type, the sanitization method and technique, the tool and its version, the verification method, and the identity and signature of whoever performed and validated the work [1]. NAID AAA certification separately requires a provider to record the serial numbers of hard drives it destroys and return that log to the customer, and to leave written documentation naming any drive that failed a wipe [3]. Reconciliation is the step buyers skip most often and the step that surfaces losses: a records reconciliation run during one Morgan Stanley decommissioning found 42 servers missing, all potentially holding unencrypted customer data [8].","answerText":"A mid-market ITAD engagement should produce seven linked records: a serialized inventory of every asset collected, chain-of-custody documentation for each handoff, a certificate of data destruction or sanitization that names individual serial numbers, an exception report covering any device that failed sanitization or never arrived, a certificate of recycling showing material weights and downstream disposition, a settlement statement for resold assets, and a final disposition report that reconciles back to the submitted inventory. NIST SP 800-88 Rev. 2 specifies what belongs on the destruction record itself, including manufacturer, model, serial number, media type, the sanitization method and technique, the tool and its version, the verification method, and the identity and signature of whoever performed and validated the work [1]. NAID AAA certification separately requires a provider to record the serial numbers of hard drives it destroys and return that log to the customer, and to leave written documentation naming any drive that failed a wipe [3]. Reconciliation is the step buyers skip most often and the step that surfaces losses: a records reconciliation run during one Morgan Stanley decommissioning found 42 servers missing, all potentially holding unencrypted customer data [8].","answerHtml":"<p>A mid-market ITAD engagement should produce seven linked records: a serialized inventory of every asset collected, chain-of-custody documentation for each handoff, a certificate of data destruction or sanitization that names individual serial numbers, an exception report covering any device that failed sanitization or never arrived, a certificate of recycling showing material weights and downstream disposition, a settlement statement for resold assets, and a final disposition report that reconciles back to the submitted inventory. NIST SP 800-88 Rev. 2 specifies what belongs on the destruction record itself, including manufacturer, model, serial number, media type, the sanitization method and technique, the tool and its version, the verification method, and the identity and signature of whoever performed and validated the work <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. NAID AAA certification separately requires a provider to record the serial numbers of hard drives it destroys and return that log to the customer, and to leave written documentation naming any drive that failed a wipe <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. Reconciliation is the step buyers skip most often and the step that surfaces losses: a records reconciliation run during one Morgan Stanley decommissioning found 42 servers missing, all potentially holding unencrypted customer data <a href=\"https://www.sec.gov/newsroom/press-releases/2022-168\" class=\"citation-ref\" data-citation-index=\"8\" target=\"_blank\" rel=\"noreferrer\">[8]</a>.</p>\n","summary":"Seven records, not one certificate: a serialized inventory, chain-of-custody receipts, per-serial destruction certificates, an exception report naming failed or missing drives, a recycling certificate with weights and downstream disposition, a resale settlement statement, and a final disposition report that reconciles to what you shipped. NIST SP 800-88 Rev. 2 defines the certificate fields, and NAID AAA requires the serial number log be returned to the customer.","publishedAt":"2026-08-11T19:23:00","verifiedAt":"2026-08-11T00:00:00","editorialStatus":"APPROVED","lastReviewedAt":"2026-08-11T00:00:00","nextReviewDueAt":"2026-11-11T00:00:00","templateVersion":"v2","aliases":["What documents should an ITAD vendor provide?","ITAD documentation checklist","What should a certificate of data destruction include?","What paperwork do you get from an ITAD provider?","ITAD deliverables for a mid-market company","What reports should an IT asset disposition project produce?","Certificate of destruction requirements","ITAD audit trail requirements","What documentation do auditors expect from IT asset disposal?","IT asset disposition reporting requirements","Chain of custody documentation for IT asset disposal","How do you verify an ITAD vendor destroyed your drives?"],"confidenceScore":90,"confidenceLabel":"High","canonicalUrl":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"contributorOrganizationProfile":{"entityId":"ec39deab-44fe-48d8-9029-fefe993ab85a","legalName":null,"description":null,"websiteUrl":null,"imageUrl":null,"slogan":null,"subtitle":null,"facts":[],"coiNote":null,"foundingDate":null,"numberOfEmployeesText":null,"contactPoint":null,"address":null,"headquartersText":null,"organizationType":null},"contributorPerson":{"slug":"answerstack-editorial-team","displayName":"AnswerStack Editorial Team"},"sections":[{"id":"6c6106ca-38d5-4dac-a92b-7c6a3b9442fd","sectionKey":"what_the_paper_trail_must_prove","sectionType":"markdown_section","heading":"What does an ITAD paper trail actually have to prove?","introMarkdown":"ITAD documentation exists to answer two questions an auditor asks separately: whether the data on each specific device is unrecoverable, and where each specific device physically ended up. Underneath both sits a third: whether the count you shipped matches the count you can account for. The HIPAA Security Rule treats that tracking as a control in its own right, requiring a covered entity to maintain a record of the movements of hardware and electronic media and any person responsible for them [10]. The Office of the Comptroller of the Currency's October 2020 action against two Morgan Stanley banking entities, which carried a $60 million civil money penalty, named the banks' failure to maintain appropriate inventory of customer data stored on the decommissioned hardware devices [9].\n\n### The unit of documentation is the device, not the pickup\n\nEngagements go wrong on paperwork when the records are organized around the shipment instead of the asset. NIST SP 800-88 Rev. 2, published in September 2025, directs that a certificate of sanitization be completed for each item of storage media that has been sanitized, and it lists the fields that certificate should carry [1]. SERI, which owns the R2 standard, raises a related concern about record accuracy in its published R2v3 sanitization guidance: spreadsheets, it notes, \"lend themselves to errors in transcribing information, and copying and pasting records, which leads to a lack of accuracy and accountability for each media/device sanitized\" [7]. A batch signoff covering a pallet and a per-device record are different artifacts, and an auditor reading both will not give them equal weight.\n\n### Some of the documents are due before the truck arrives\n\nPart of the set is pre-engagement and appears only if the contract asks for it. NAID AAA certification requires a provider to give the customer a written description of its hard drive destruction process before any destruction happens [3]. The same specifications require written notice when custody of media passes to a subcontractor, including that subcontractor's name and the service it provides, plus written notice if a purchased service falls outside the provider's certification [3]. Mid-market buyers usually discover these entitlements after the fact, because nothing in a standard quote surfaces them.","introHtml":"<p>ITAD documentation exists to answer two questions an auditor asks separately: whether the data on each specific device is unrecoverable, and where each specific device physically ended up. Underneath both sits a third: whether the count you shipped matches the count you can account for. The HIPAA Security Rule treats that tracking as a control in its own right, requiring a covered entity to maintain a record of the movements of hardware and electronic media and any person responsible for them <a href=\"https://www.ecfr.gov/current/title-45/section-164.310\" class=\"citation-ref\" data-citation-index=\"10\" target=\"_blank\" rel=\"noreferrer\">[10]</a>. The Office of the Comptroller of the Currency&#39;s October 2020 action against two Morgan Stanley banking entities, which carried a $60 million civil money penalty, named the banks&#39; failure to maintain appropriate inventory of customer data stored on the decommissioned hardware devices <a href=\"https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-134.html\" class=\"citation-ref\" data-citation-index=\"9\" target=\"_blank\" rel=\"noreferrer\">[9]</a>.</p>\n<h3>The unit of documentation is the device, not the pickup</h3>\n<p>Engagements go wrong on paperwork when the records are organized around the shipment instead of the asset. NIST SP 800-88 Rev. 2, published in September 2025, directs that a certificate of sanitization be completed for each item of storage media that has been sanitized, and it lists the fields that certificate should carry <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. SERI, which owns the R2 standard, raises a related concern about record accuracy in its published R2v3 sanitization guidance: spreadsheets, it notes, &quot;lend themselves to errors in transcribing information, and copying and pasting records, which leads to a lack of accuracy and accountability for each media/device sanitized&quot; <a href=\"https://sustainableelectronics.org/knowledge-base/discussion-on-logical-data-sanitization-in-r2v3/\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a>. A batch signoff covering a pallet and a per-device record are different artifacts, and an auditor reading both will not give them equal weight.</p>\n<h3>Some of the documents are due before the truck arrives</h3>\n<p>Part of the set is pre-engagement and appears only if the contract asks for it. NAID AAA certification requires a provider to give the customer a written description of its hard drive destruction process before any destruction happens <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. The same specifications require written notice when custody of media passes to a subcontractor, including that subcontractor&#39;s name and the service it provides, plus written notice if a purchased service falls outside the provider&#39;s certification <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. Mid-market buyers usually discover these entitlements after the fact, because nothing in a standard quote surfaces them.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":10},{"id":"c69b8513-be69-452d-bfde-dc121f38c7c3","sectionKey":"document_set_table","sectionType":"table_section","heading":"Which documents should a mid-market ITAD engagement produce?","introMarkdown":"Seven records cover a typical mid-market engagement that mixes destruction, recycling, and resale. Six trace back to a published standard or regulation. One exists only because you negotiated it.","introHtml":"<p>Seven records cover a typical mid-market engagement that mixes destruction, recycling, and resale. Six trace back to a published standard or regulation. One exists only because you negotiated it.</p>\n","outroMarkdown":"The settlement statement is the one row here that no data destruction or recycling standard governs. Nothing in NIST SP 800-88, the NAID AAA certification specifications, or R2v3 obliges a provider to show you how a resold laptop was priced [1][3][6]. If resale value is part of the business case, the reporting format belongs in the contract rather than on a wish list.","outroHtml":"<p>The settlement statement is the one row here that no data destruction or recycling standard governs. Nothing in NIST SP 800-88, the NAID AAA certification specifications, or R2v3 obliges a provider to show you how a resold laptop was priced <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a><a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a><a href=\"https://sustainableelectronics.org/wp-content/uploads/2021/05/Summary-of-R2v3-Requirements.pdf\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. If resale value is part of the business case, the reporting format belongs in the contract rather than on a wish list.</p>\n","contentJson":{"rows":[{"cells":["Serialized asset inventory","Every unit you handed over was counted at the point of transfer","Make, model, serial number or asset tag, and condition for each unit [1]"]},{"cells":["Chain-of-custody records","Custody moved hand to hand with a named party responsible at each step","Pickup manifest, dated receipts showing type and quantity, driver and recipient identity, written subcontractor disclosure [3][10]"]},{"cells":["Certificate of data destruction or sanitization","The data on each named device was destroyed by a stated method","Serial number, media type, method, technique, tool and version, verification method, operator name and signature, date [1]"]},{"cells":["Exception report","Failed drives and missing units are named rather than absorbed","Unique identifiers of failed drives, custody status of anything returned to you, count variances [3]"]},{"cells":["Certificate of recycling","Residual material entered a legitimate downstream chain","Weight by material stream, processing facility, downstream vendor, final disposition [6]"]},{"cells":["Resale settlement statement","Resale proceeds and deductions tie back to identified assets","Per-asset or per-lot sale price, fees deducted, revenue-share basis, settlement date"]},{"cells":["Final disposition report","Units submitted equal units accounted for","Per-serial final status, totals reconciled against the submitted inventory, every variance named [1][8]"]}],"columns":["Document","What it proves","Contents to require in writing"]},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":20},{"id":"6d5485a2-6b7d-4038-9ffd-e624665e724f","sectionKey":"data_security_documents","sectionType":"markdown_section","heading":"Which documents prove the data is gone?","introMarkdown":"Four records carry the data-security half of the engagement, and each closes a gap the other three leave open.\n\n### The serialized asset inventory\n\nCapture make, model, serial number, and condition for every unit before it leaves your control, then treat that file as the baseline every later document gets measured against. NIST SP 800-88 Rev. 2 ties this to record-keeping at both ends of the asset's life. Without a front-end record, it notes, sanitization records \"will only show that specific ISM were sanitized and not whether the organization is effectively sanitizing all ISM that have been introduced into the operating environment\" [1]. Build the inventory from your own asset management system rather than adopting the vendor's receiving count, which cannot detect anything lost between your rack and their truck.\n\n### Chain-of-custody records\n\nRequire a dated receipt at every custody transfer showing the type and quantity of material moved plus an acknowledgement of the service performed, which is what NAID AAA certification obliges a certified provider to hand over when custody passes from your staff to theirs [3]. The HIPAA Security Rule asks for the same thing through its accountability specification: a record of the movements of hardware and electronic media and any person responsible for them [10]. Two details are worth writing into the contract. If a subcontractor touches the load, you are entitled in writing to that subcontractor's name and the service it performs [3]. And if the provider routes material through a transfer processing station rather than straight to a destruction facility, NAID AAA specifications require it to reach a facility-based destruction operation within 15 business days, a defensible timeline to hold them to [3].\n\n### The certificate of data destruction or sanitization\n\nInsist the certificate name individual serial numbers and state the method applied, because a certificate that names only a customer and a date proves nothing about any particular drive. NIST SP 800-88 Rev. 2 lists what the record should carry: manufacturer, model, serial number, any internal property number, media type, media source, the sanitization method chosen from clear, purge, or destroy, the specific technique used, the tool and its version, the verification method, and the name, title, date, location, and signature of the people performing verification and validation [1]. Its Appendix C sample form adds a destination block distinguishing internal reuse, external reuse, a recycling facility, and return to a manufacturer, plus a second signature for concurrence [1]. Blancco, whose erasure software is used widely across the ITAD market, publishes a comparable vendor-side list that adds the software version, the erasure start and end time, a pass or fail status, and a digital signature with a report identifier [12]. NAID AAA certification adds an entitlement buyers rarely invoke: a provider destroying hard drives records the serial numbers and returns that log to the customer on completion, and a customer who declines has to sign an opt-out agreement stating that recordation is a certification requirement [3].\n\n### The exception report\n\nRequire a named list of anything that did not go to plan, since this is the document most likely to be left out and the first one an investigation will ask for. Under NAID AAA specifications, a provider holding the overwriting endorsement must leave the customer documentation identifying any drives that failed the wiping process, with those drives' unique identifiers included regardless of any opt-out agreement in place. If a non-erased drive stays behind with the customer, that document also has to state that custody is being transferred back [3]. The same specifications require the verification software to differ from the wiping software, which is the control that makes a failure detectable at all [3]. Ask for it even when there is nothing to report, because a signed statement that zero drives failed is itself a record you can produce later.","introHtml":"<p>Four records carry the data-security half of the engagement, and each closes a gap the other three leave open.</p>\n<h3>The serialized asset inventory</h3>\n<p>Capture make, model, serial number, and condition for every unit before it leaves your control, then treat that file as the baseline every later document gets measured against. NIST SP 800-88 Rev. 2 ties this to record-keeping at both ends of the asset&#39;s life. Without a front-end record, it notes, sanitization records &quot;will only show that specific ISM were sanitized and not whether the organization is effectively sanitizing all ISM that have been introduced into the operating environment&quot; <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Build the inventory from your own asset management system rather than adopting the vendor&#39;s receiving count, which cannot detect anything lost between your rack and their truck.</p>\n<h3>Chain-of-custody records</h3>\n<p>Require a dated receipt at every custody transfer showing the type and quantity of material moved plus an acknowledgement of the service performed, which is what NAID AAA certification obliges a certified provider to hand over when custody passes from your staff to theirs <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. The HIPAA Security Rule asks for the same thing through its accountability specification: a record of the movements of hardware and electronic media and any person responsible for them <a href=\"https://www.ecfr.gov/current/title-45/section-164.310\" class=\"citation-ref\" data-citation-index=\"10\" target=\"_blank\" rel=\"noreferrer\">[10]</a>. Two details are worth writing into the contract. If a subcontractor touches the load, you are entitled in writing to that subcontractor&#39;s name and the service it performs <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. And if the provider routes material through a transfer processing station rather than straight to a destruction facility, NAID AAA specifications require it to reach a facility-based destruction operation within 15 business days, a defensible timeline to hold them to <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</p>\n<h3>The certificate of data destruction or sanitization</h3>\n<p>Insist the certificate name individual serial numbers and state the method applied, because a certificate that names only a customer and a date proves nothing about any particular drive. NIST SP 800-88 Rev. 2 lists what the record should carry: manufacturer, model, serial number, any internal property number, media type, media source, the sanitization method chosen from clear, purge, or destroy, the specific technique used, the tool and its version, the verification method, and the name, title, date, location, and signature of the people performing verification and validation <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Its Appendix C sample form adds a destination block distinguishing internal reuse, external reuse, a recycling facility, and return to a manufacturer, plus a second signature for concurrence <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. Blancco, whose erasure software is used widely across the ITAD market, publishes a comparable vendor-side list that adds the software version, the erasure start and end time, a pass or fail status, and a digital signature with a report identifier <a href=\"https://blancco.com/resources/blog-must-have-elements-of-a-data-destruction-certificate/\" class=\"citation-ref\" data-citation-index=\"12\" target=\"_blank\" rel=\"noreferrer\">[12]</a>. NAID AAA certification adds an entitlement buyers rarely invoke: a provider destroying hard drives records the serial numbers and returns that log to the customer on completion, and a customer who declines has to sign an opt-out agreement stating that recordation is a certification requirement <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</p>\n<h3>The exception report</h3>\n<p>Require a named list of anything that did not go to plan, since this is the document most likely to be left out and the first one an investigation will ask for. Under NAID AAA specifications, a provider holding the overwriting endorsement must leave the customer documentation identifying any drives that failed the wiping process, with those drives&#39; unique identifiers included regardless of any opt-out agreement in place. If a non-erased drive stays behind with the customer, that document also has to state that custody is being transferred back <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. The same specifications require the verification software to differ from the wiping software, which is the control that makes a failure detectable at all <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. Ask for it even when there is nothing to report, because a signed statement that zero drives failed is itself a record you can produce later.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":30},{"id":"e68b2ab5-ba60-4fea-b3d6-045a085c721e","sectionKey":"disposition_and_value_documents","sectionType":"markdown_section","heading":"Which documents prove where the hardware and the proceeds went?","introMarkdown":"Two records cover the physical and financial tail of the engagement, and they are governed very differently: one traces to a recycling standard with audited requirements behind it, while the other exists at whatever level of detail your contract specifies.\n\n### The certificate of recycling and downstream disposition\n\nAsk for weight by material stream plus the downstream vendor's identity, because a recycling certificate reporting one aggregate tonnage cannot be checked against anything. R2v3 handles this through Appendix A, which requires tracking and documenting the flow of equipment and materials through the downstream chain until final disposition [6]. One nuance changes what a provider can honestly give you: under R2v3, downstream tracking may stop at the first R2v3-certified downstream vendor, since that vendor has already been audited, provided the facility registers its chain with SERI [6]. A provider declining to name every tier is not necessarily being evasive, though it should still name the first tier and show that registration. NAID AAA certification reaches the same ground from the security side, requiring a certified provider to keep a list of the recipients of destroyed hard drives showing final disposition, and requiring those recipients to hold verified ISO 14001 certification [3].\n\n### The resale settlement statement\n\nDefine this document in the contract, because no destruction or recycling standard requires it. Specify per-asset or per-lot pricing, the fees deducted before your share is calculated, and a settlement date, all mapped to the same serial numbers used everywhere else. Provider-published deliverable lists are a practical way to see the shape of the category before drafting requirements. Greentec, an Ontario ITAD and electronics recycler, describes its engagements as producing certificates of destruction for every data-bearing device serial number plus carbon impact and exportable ESG data, with each device logged and serialized into asset management tools [13]. A vendor's stated deliverables are a commercial commitment rather than an audited one, so lists like that are useful for drafting while the binding requirements stay anchored to the standards [1][3].","introHtml":"<p>Two records cover the physical and financial tail of the engagement, and they are governed very differently: one traces to a recycling standard with audited requirements behind it, while the other exists at whatever level of detail your contract specifies.</p>\n<h3>The certificate of recycling and downstream disposition</h3>\n<p>Ask for weight by material stream plus the downstream vendor&#39;s identity, because a recycling certificate reporting one aggregate tonnage cannot be checked against anything. R2v3 handles this through Appendix A, which requires tracking and documenting the flow of equipment and materials through the downstream chain until final disposition <a href=\"https://sustainableelectronics.org/wp-content/uploads/2021/05/Summary-of-R2v3-Requirements.pdf\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. One nuance changes what a provider can honestly give you: under R2v3, downstream tracking may stop at the first R2v3-certified downstream vendor, since that vendor has already been audited, provided the facility registers its chain with SERI <a href=\"https://sustainableelectronics.org/wp-content/uploads/2021/05/Summary-of-R2v3-Requirements.pdf\" class=\"citation-ref\" data-citation-index=\"6\" target=\"_blank\" rel=\"noreferrer\">[6]</a>. A provider declining to name every tier is not necessarily being evasive, though it should still name the first tier and show that registration. NAID AAA certification reaches the same ground from the security side, requiring a certified provider to keep a list of the recipients of destroyed hard drives showing final disposition, and requiring those recipients to hold verified ISO 14001 certification <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</p>\n<h3>The resale settlement statement</h3>\n<p>Define this document in the contract, because no destruction or recycling standard requires it. Specify per-asset or per-lot pricing, the fees deducted before your share is calculated, and a settlement date, all mapped to the same serial numbers used everywhere else. Provider-published deliverable lists are a practical way to see the shape of the category before drafting requirements. Greentec, an Ontario ITAD and electronics recycler, describes its engagements as producing certificates of destruction for every data-bearing device serial number plus carbon impact and exportable ESG data, with each device logged and serialized into asset management tools <a href=\"https://www.greentec.com/blog/enterpriseit-asset-disposition\" class=\"citation-ref\" data-citation-index=\"13\" target=\"_blank\" rel=\"noreferrer\">[13]</a>. A vendor&#39;s stated deliverables are a commercial commitment rather than an audited one, so lists like that are useful for drafting while the binding requirements stay anchored to the standards <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a><a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":40},{"id":"f36f97f5-8d3c-48a2-a7f8-42e519fbd950","sectionKey":"reconciliation","sectionType":"markdown_section","heading":"How should the final disposition report reconcile to your inventory?","introMarkdown":"Line by line against serial numbers, with every variance named and explained in writing. A final disposition report that presents totals only lets losses hide inside rounding, and the failure mode is documented at the highest level. In the SEC's September 2022 order against Morgan Stanley Smith Barney, which carried a $35 million penalty, a records reconciliation exercise the firm ran during a decommissioning \"revealed that 42 servers, all potentially containing unencrypted customer PII and consumer report information, were missing\" [8]. That reconciliation surfaced the gap, which no certificate set would have done on its own, since certificates only describe the devices a provider actually processed.\n\nA workable reconciliation compares four numbers and demands an explanation wherever they disagree: units on your submitted inventory, units the provider acknowledged receiving, units covered by a destruction or sanitization certificate, and units carrying a final disposition status such as recycled, resold, or returned. The last three should sum to the first.\n\nRun that comparison yourself instead of accepting the provider's own reconciliation summary, because a reconciliation performed against the receiving count rather than your shipping count cannot detect an in-transit loss. Where a variance turns out to be real, the artifact worth having is a dated written explanation naming the specific serial numbers rather than an adjusted total.","introHtml":"<p>Line by line against serial numbers, with every variance named and explained in writing. A final disposition report that presents totals only lets losses hide inside rounding, and the failure mode is documented at the highest level. In the SEC&#39;s September 2022 order against Morgan Stanley Smith Barney, which carried a $35 million penalty, a records reconciliation exercise the firm ran during a decommissioning &quot;revealed that 42 servers, all potentially containing unencrypted customer PII and consumer report information, were missing&quot; <a href=\"https://www.sec.gov/newsroom/press-releases/2022-168\" class=\"citation-ref\" data-citation-index=\"8\" target=\"_blank\" rel=\"noreferrer\">[8]</a>. That reconciliation surfaced the gap, which no certificate set would have done on its own, since certificates only describe the devices a provider actually processed.</p>\n<p>A workable reconciliation compares four numbers and demands an explanation wherever they disagree: units on your submitted inventory, units the provider acknowledged receiving, units covered by a destruction or sanitization certificate, and units carrying a final disposition status such as recycled, resold, or returned. The last three should sum to the first.</p>\n<p>Run that comparison yourself instead of accepting the provider&#39;s own reconciliation summary, because a reconciliation performed against the receiving count rather than your shipping count cannot detect an in-transit loss. Where a variance turns out to be real, the artifact worth having is a dated written explanation naming the specific serial numbers rather than an adjusted total.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":50},{"id":"18972d49-49fa-4c88-87ad-b9c71da85c03","sectionKey":"contributor_perspective","sectionType":"markdown_section","heading":"How this answer was researched","introMarkdown":"This answer was assembled from primary standards and regulatory sources rather than vendor marketing, because documentation requirements are an area where the two diverge sharply. The certificate field lists come from NIST SP 800-88 Rev. 2 and from the i-SIGMA Certification Specifications Reference Manual, revision 0925M, which is the document NAID AAA auditors work from. The enforcement details come from the OCC and SEC actions themselves rather than secondary coverage of them. Where a widely repeated requirement could not be traced to a published standard, the answer says so: the resale settlement statement is the clearest example, since it is a contract term rather than a certification obligation.\n\nPractitioners who audit ITAD engagements or run the provider side are invited to submit corrections, particularly on record retention practice and on how certificate formats differ between certification schemes.","introHtml":"<p>This answer was assembled from primary standards and regulatory sources rather than vendor marketing, because documentation requirements are an area where the two diverge sharply. The certificate field lists come from NIST SP 800-88 Rev. 2 and from the i-SIGMA Certification Specifications Reference Manual, revision 0925M, which is the document NAID AAA auditors work from. The enforcement details come from the OCC and SEC actions themselves rather than secondary coverage of them. Where a widely repeated requirement could not be traced to a published standard, the answer says so: the resale settlement statement is the clearest example, since it is a contract term rather than a certification obligation.</p>\n<p>Practitioners who audit ITAD engagements or run the provider side are invited to submit corrections, particularly on record retention practice and on how certificate formats differ between certification schemes.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":"This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.","noteHtml":"<p>This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.</p>\n","sortOrder":60},{"id":"b02db243-5083-4329-9685-67ba26915a89","sectionKey":"documentation_red_flags","sectionType":"markdown_section","heading":"Which documentation red flags should make you push back?","introMarkdown":"A certificate with no serial numbers on it is the first one, and it is common enough that you should expect it rather than treat it as an outlier. Several others are worth naming before the engagement starts.\n\n- A blanket certificate covering a weight, a pallet count, or a date range instead of identified devices. NIST SP 800-88 Rev. 2 contemplates a record per item of media, so one certificate for a truckload is a summary of work rather than evidence of it [1].\n- A certificate citing DoD 5220.22-M and a set number of overwrite passes. The change log for Rev. 2 states that the clear method was clarified so multi-pass overwrite is not needed, and describes the DoD language mandating passes and patterns as obsolete [1]. A provider still selling passes as a security tier is quoting a retired specification.\n- No exception report, and no signed statement that there were no exceptions to report [3].\n- A reconciliation prepared against the provider's receiving count rather than your shipping count, which by construction cannot surface an in-transit loss [8].\n- Sanitization records maintained in a spreadsheet rather than produced by software that records each device. SERI's own R2v3 guidance describes spreadsheet records as subject to alteration or falsification, and notes that a software-generated record is more than a spreadsheet [7].","introHtml":"<p>A certificate with no serial numbers on it is the first one, and it is common enough that you should expect it rather than treat it as an outlier. Several others are worth naming before the engagement starts.</p>\n<ul>\n<li>A blanket certificate covering a weight, a pallet count, or a date range instead of identified devices. NIST SP 800-88 Rev. 2 contemplates a record per item of media, so one certificate for a truckload is a summary of work rather than evidence of it <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>.</li>\n<li>A certificate citing DoD 5220.22-M and a set number of overwrite passes. The change log for Rev. 2 states that the clear method was clarified so multi-pass overwrite is not needed, and describes the DoD language mandating passes and patterns as obsolete <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a>. A provider still selling passes as a security tier is quoting a retired specification.</li>\n<li>No exception report, and no signed statement that there were no exceptions to report <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>.</li>\n<li>A reconciliation prepared against the provider&#39;s receiving count rather than your shipping count, which by construction cannot surface an in-transit loss <a href=\"https://www.sec.gov/newsroom/press-releases/2022-168\" class=\"citation-ref\" data-citation-index=\"8\" target=\"_blank\" rel=\"noreferrer\">[8]</a>.</li>\n<li>Sanitization records maintained in a spreadsheet rather than produced by software that records each device. SERI&#39;s own R2v3 guidance describes spreadsheet records as subject to alteration or falsification, and notes that a software-generated record is more than a spreadsheet <a href=\"https://sustainableelectronics.org/knowledge-base/discussion-on-logical-data-sanitization-in-r2v3/\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a>.</li>\n</ul>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":70},{"id":"40247213-cbf9-43a3-bbf9-05d6c4ede036","sectionKey":"retention","sectionType":"markdown_section","heading":"How long should you keep ITAD documentation?","introMarkdown":"Six years is the practical floor for regulated data in the United States, and it comes from the HIPAA Security Rule rather than from any ITAD standard. The rule requires documentation of a required action, activity, or assessment to be retained \"for 6 years from the date of its creation or the date when it last was in effect, whichever is later\" [11]. Since final disposition of electronic protected health information is a required documented activity under the same subpart, the destruction record inherits that clock [10][11].\n\nDo not assume the provider is holding a copy on your behalf. NAID AAA certification requires a certified provider to retain serial number logs, opt-out agreements, and equipment calibration records \"for a specified length of time, as documented in the Applicant's written policies, or in accordance with client agreements or contractual stipulations\" [3]. The certification sets no universal period, so the retention term is whatever the provider wrote down or what you negotiated. Get that number into the contract and keep your own copies in a system you control, because a provider that is acquired or shuts down takes its records archive with it.\n\nSurveillance footage runs on a much shorter clock. NAID AAA specifications require at least 90 consecutive days of CCTV recordings to be retained in an organized, retrievable manner [3], so a question raised six months after a pickup usually cannot be answered from video. That is an argument for running the reconciliation while the footage still exists.","introHtml":"<p>Six years is the practical floor for regulated data in the United States, and it comes from the HIPAA Security Rule rather than from any ITAD standard. The rule requires documentation of a required action, activity, or assessment to be retained &quot;for 6 years from the date of its creation or the date when it last was in effect, whichever is later&quot; <a href=\"https://www.ecfr.gov/current/title-45/section-164.316\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>. Since final disposition of electronic protected health information is a required documented activity under the same subpart, the destruction record inherits that clock <a href=\"https://www.ecfr.gov/current/title-45/section-164.310\" class=\"citation-ref\" data-citation-index=\"10\" target=\"_blank\" rel=\"noreferrer\">[10]</a><a href=\"https://www.ecfr.gov/current/title-45/section-164.316\" class=\"citation-ref\" data-citation-index=\"11\" target=\"_blank\" rel=\"noreferrer\">[11]</a>.</p>\n<p>Do not assume the provider is holding a copy on your behalf. NAID AAA certification requires a certified provider to retain serial number logs, opt-out agreements, and equipment calibration records &quot;for a specified length of time, as documented in the Applicant&#39;s written policies, or in accordance with client agreements or contractual stipulations&quot; <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>. The certification sets no universal period, so the retention term is whatever the provider wrote down or what you negotiated. Get that number into the contract and keep your own copies in a system you control, because a provider that is acquired or shuts down takes its records archive with it.</p>\n<p>Surveillance footage runs on a much shorter clock. NAID AAA specifications require at least 90 consecutive days of CCTV recordings to be retained in an organized, retrievable manner <a href=\"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf\" class=\"citation-ref\" data-citation-index=\"3\" target=\"_blank\" rel=\"noreferrer\">[3]</a>, so a question raised six months after a pickup usually cannot be answered from video. That is an argument for running the reconciliation while the footage still exists.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":80},{"id":"ddc0090c-9816-46bd-b32b-173f7ce99431","sectionKey":"what_itad_documentation_is_not","sectionType":"markdown_section","heading":"What ITAD documentation does not do","introMarkdown":"### It does not transfer your liability\n\ni-SIGMA, which administers NAID AAA certification, is explicit that customers misread the certificate of destruction on this point, calling the belief that it transfers liability to the service provider \"a dangerous misconception\" and noting that \"the more significant reason the CoD is not capable of transferring liability is because regulations do not allow for it\" [5]. By that account, regulatory responsibility moves only through due diligence and contract language, and even then only partly [5].\n\n### A record of sanitization is not a test of sanitization\n\nSERI states the distinction plainly for R2v3: the Appendix B(13) verification requirement \"is different than verifying that a record of data sanitization is available for the media,\" because it relies on actually attempting to recover data using commercial recovery software [7]. A certificate confirms that a process ran and who ran it, while sampling-based recovery testing is what produces evidence about the outcome.\n\n### A certification logo is not a scope statement\n\nNAID AAA endorsements separately cover mobile on-site operations, facility-based operations, and individual media types such as hard drives, and the program runs scheduled and unannounced audits against those specific endorsements [4]. Ask which endorsements cover the service on your quote rather than reading the badge as blanket coverage.\n\n### Citing NIST SP 800-88 Rev. 1 no longer means what it used to\n\nNIST withdrew Revision 1 on September 26, 2025 and superseded it with Revision 2 [2]. Templates and vendor collateral still reference Rev. 1 widely, which is not automatically a problem, but a certificate citing the withdrawn revision is a fair prompt to ask when the provider last reviewed its forms [1][2].","introHtml":"<h3>It does not transfer your liability</h3>\n<p>i-SIGMA, which administers NAID AAA certification, is explicit that customers misread the certificate of destruction on this point, calling the belief that it transfers liability to the service provider &quot;a dangerous misconception&quot; and noting that &quot;the more significant reason the CoD is not capable of transferring liability is because regulations do not allow for it&quot; <a href=\"https://isigmaonline.org/customer-misconception-the-certificate-of-destruction-removes-regulatory-liability-selling-information-disposition-by-the-book-vol-7/\" class=\"citation-ref\" data-citation-index=\"5\" target=\"_blank\" rel=\"noreferrer\">[5]</a>. By that account, regulatory responsibility moves only through due diligence and contract language, and even then only partly <a href=\"https://isigmaonline.org/customer-misconception-the-certificate-of-destruction-removes-regulatory-liability-selling-information-disposition-by-the-book-vol-7/\" class=\"citation-ref\" data-citation-index=\"5\" target=\"_blank\" rel=\"noreferrer\">[5]</a>.</p>\n<h3>A record of sanitization is not a test of sanitization</h3>\n<p>SERI states the distinction plainly for R2v3: the Appendix B(13) verification requirement &quot;is different than verifying that a record of data sanitization is available for the media,&quot; because it relies on actually attempting to recover data using commercial recovery software <a href=\"https://sustainableelectronics.org/knowledge-base/discussion-on-logical-data-sanitization-in-r2v3/\" class=\"citation-ref\" data-citation-index=\"7\" target=\"_blank\" rel=\"noreferrer\">[7]</a>. A certificate confirms that a process ran and who ran it, while sampling-based recovery testing is what produces evidence about the outcome.</p>\n<h3>A certification logo is not a scope statement</h3>\n<p>NAID AAA endorsements separately cover mobile on-site operations, facility-based operations, and individual media types such as hard drives, and the program runs scheduled and unannounced audits against those specific endorsements <a href=\"https://isigmaonline.org/certifications/naid-aaa-certification/\" class=\"citation-ref\" data-citation-index=\"4\" target=\"_blank\" rel=\"noreferrer\">[4]</a>. Ask which endorsements cover the service on your quote rather than reading the badge as blanket coverage.</p>\n<h3>Citing NIST SP 800-88 Rev. 1 no longer means what it used to</h3>\n<p>NIST withdrew Revision 1 on September 26, 2025 and superseded it with Revision 2 <a href=\"https://csrc.nist.gov/pubs/sp/800/88/r1/final\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a>. Templates and vendor collateral still reference Rev. 1 widely, which is not automatically a problem, but a certificate citing the withdrawn revision is a fair prompt to ask when the provider last reviewed its forms <a href=\"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf\" class=\"citation-ref\" data-citation-index=\"1\" target=\"_blank\" rel=\"noreferrer\">[1]</a><a href=\"https://csrc.nist.gov/pubs/sp/800/88/r1/final\" class=\"citation-ref\" data-citation-index=\"2\" target=\"_blank\" rel=\"noreferrer\">[2]</a>.</p>\n","outroMarkdown":null,"outroHtml":null,"contentJson":{},"configJson":{},"noteMarkdown":null,"noteHtml":null,"sortOrder":90}],"citations":[{"title":"NIST SP 800-88 Revision 2, Guidelines for Media Sanitization","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf","excerpt":"Following sanitization, a certificate of sanitization (see Appendix C) should be completed for each ISM that has been sanitized, per the organization's policies.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Certificate of sanitization field list (Sec. 4.6 and Appendix C); per-item certificate requirement; verification vs. validation; lifecycle record-keeping and reconciliation rationale; Appendix D change log on multi-pass overwrite and DoD 5220.22-M","domain":"nvlpubs.nist.gov","publisherName":"National Institute of Standards and Technology"},{"title":"SP 800-88 Rev. 1, Guidelines for Media Sanitization (withdrawn)","url":"https://csrc.nist.gov/pubs/sp/800/88/r1/final","excerpt":"Withdrawn on September 26, 2025. Superseded by SP 800-88 Rev. 2.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Revision 1 withdrawal date of September 26, 2025 and supersession by Revision 2","domain":"csrc.nist.gov","publisherName":"NIST Computer Security Resource Center"},{"title":"i-SIGMA Certification Specifications Reference Manual (0925M)","url":"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf","excerpt":"The log of recorded serial numbers is returned to the Data Controller upon the completion of the service, unless the Data Controller has opted out of this requirement.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Serial number recordation and return of the log to the data controller; opt-out agreement wording; written description of the destruction process in advance; custody-transfer receipts showing type and quantity; subcontractor name disclosure; failed-drive documentation and transfer of custody back to","domain":"isigmaonline.org","publisherName":"i-SIGMA"},{"title":"NAID AAA Certification | Secure Data Destruction","url":"https://isigmaonline.org/certifications/naid-aaa-certification/","excerpt":"Endorsements further define services such as mobile (on-site), facility-based operations, and specific media types like paper and hard drives.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Endorsement structure covering mobile on-site vs. facility-based operations and specific media types; scheduled and unannounced audits","domain":"isigmaonline.org","publisherName":"i-SIGMA"},{"title":"Customer Misconception: The Certificate of Destruction Removes Regulatory Liability","url":"https://isigmaonline.org/customer-misconception-the-certificate-of-destruction-removes-regulatory-liability-selling-information-disposition-by-the-book-vol-7/","excerpt":"the more significant reason the CoD is not capable of transferring liability is because regulations do not allow for it","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"A certificate of destruction does not transfer regulatory liability from the data controller to the service provider","domain":"isigmaonline.org","publisherName":"i-SIGMA (Bob Johnson)"},{"title":"Summary of R2v3 Requirements","url":"https://sustainableelectronics.org/wp-content/uploads/2021/05/Summary-of-R2v3-Requirements.pdf","excerpt":"Downstream tracking and verification can stop at the first R2v3 Certified DSV since that vendor has already been audited and verified through the certification process.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Appendix A downstream tracking and documentation to final disposition, and the allowance to stop tracking at the first R2v3-certified downstream vendor when the chain is registered with SERI; Appendix B device tracking and sanitization records; Core 7 data security","domain":"sustainableelectronics.org","publisherName":"SERI (Sustainable Electronics Recycling International)"},{"title":"Discussion on Logical Data Sanitization in R2v3","url":"https://sustainableelectronics.org/knowledge-base/discussion-on-logical-data-sanitization-in-r2v3/","excerpt":"Appendix B(13) is different than verifying that a record of data sanitization is available for the media. This requirement relies on the technique of actually trying to recover data from the device.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Spreadsheet-based sanitization records are error-prone and subject to alteration; per-device accountability over batch signoff; Appendix B(13) verification is a recovery attempt rather than a records check","domain":"sustainableelectronics.org","publisherName":"SERI R2 Guidance and Knowledge Base"},{"title":"Morgan Stanley Smith Barney to Pay $35 Million for Extensive Failures to Safeguard Personal Information of Millions of Customers","url":"https://www.sec.gov/newsroom/press-releases/2022-168","excerpt":"A records reconciliation exercise undertaken by the firm during this decommissioning process revealed that 42 servers, all potentially containing unencrypted customer PII and consumer report information, were missing.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"The $35 million penalty; the records reconciliation exercise that found 42 missing servers; use of a moving company with no data destruction expertise and devices resold on an internet auction site","domain":"sec.gov","publisherName":"U.S. Securities and Exchange Commission"},{"title":"OCC Assesses $60 Million Civil Money Penalty Against Morgan Stanley","url":"https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-134.html","excerpt":"failed to maintain appropriate inventory of customer data stored on the decommissioned hardware devices","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"October 8, 2020 action; $60 million civil money penalty; failure to maintain appropriate inventory of customer data on decommissioned hardware and inadequate vendor due diligence and monitoring","domain":"occ.gov","publisherName":"Office of the Comptroller of the Currency"},{"title":"45 CFR 164.310, Physical safeguards (device and media controls)","url":"https://www.ecfr.gov/current/title-45/section-164.310","excerpt":"Accountability (Addressable). Maintain a record of the movements of hardware and electronic media and any person responsible therefore.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Accountability specification requiring a record of the movements of hardware and electronic media and the responsible person; disposal and media re-use requirements","domain":"ecfr.gov","publisherName":"Electronic Code of Federal Regulations"},{"title":"45 CFR 164.316, Policies and procedures and documentation requirements","url":"https://www.ecfr.gov/current/title-45/section-164.316","excerpt":"Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.","quoteText":null,"sourceRole":"PRIMARY","verifiedAt":"2026-08-11T00:00:00","supportsText":"Six-year documentation retention period for required documented actions, activities, and assessments","domain":"ecfr.gov","publisherName":"Electronic Code of Federal Regulations"},{"title":"Must Have Elements of a Data Destruction Certificate","url":"https://blancco.com/resources/blog-must-have-elements-of-a-data-destruction-certificate/","excerpt":"Date and duration of erasure with start/end time... Method used (IEEE 2883, NIST 800-88, etc.) and level of erasure (Clear/Purge)... Status of erasure (pass/fail)","quoteText":null,"sourceRole":"INDEPENDENT","verifiedAt":"2026-08-11T00:00:00","supportsText":"Vendor-side certificate element list including software and version, erasure start and end time, method and level, pass or fail status, serial numbers, digital signature, and report identifier","domain":"blancco.com","publisherName":"Blancco"},{"title":"End-of-Lifecycle IT Asset Disposition: What Most Companies Get Wrong (and Pay for Later)","url":"https://www.greentec.com/blog/enterpriseit-asset-disposition","excerpt":"You receive certificates of destruction for every data bearing device serial number, along with carbon impact reports and exportable ESG data to satisfy regulators and auditors.","quoteText":null,"sourceRole":"SUPPORTING","verifiedAt":"2026-08-11T00:00:00","supportsText":"One Ontario provider's stated documentation deliverables: per-serial certificates of destruction, serialized device logging, carbon impact reports, and exportable ESG data. Provider-published material about its own offering; general documentation requirements in this answer rest on [1], [3], [6], an","domain":"greentec.com","publisherName":"Greentec"}],"revisions":[],"relatedAnswers":[{"id":"2b59274c-3317-43fc-9e27-904d77a8f9db","slug":"is-onsite-hard-drive-destruction-worth-the-premium-over-offsite","question":"Is onsite hard-drive destruction worth the premium over offsite?","publishedAt":"2026-08-28T14:15:05.515","confidenceScore":80,"confidenceLabel":"Medium","industry":{"id":"827514c6-e279-422b-b56a-f1cba07d8bd6","slug":"cybersecurity","label":"Cybersecurity","description":"SIEM, endpoint protection, and identity security"},"topic":{"slug":"itad-data-destruction","label":"ITAD & Data Destruction","description":"IT asset disposition, secure data destruction, and end-of-life electronics: certifications, chain of custody, documentation, and compliance.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"The onsite premium buys a shorter chain of custody, not a more thorough shred. Offsite physical destruction runs about $4 to $20 per drive; onsite is quoted 20% to 100% higher plus a visit minimum near $90 to $300. Most of that premium is fixed, so small jobs pay dearly per drive and large jobs barely notice it. Decide on data classification, witness requirements, asset mix, and volume, in that order.","url":"/q/is-onsite-hard-drive-destruction-worth-the-premium-over-offsite"},{"id":"55cc3b8a-834c-47e9-a84a-06e0a15da4d3","slug":"does-a-mid-market-company-need-an-rpra-registered-provider","question":"Does a mid-market company need an RPRA-registered provider?","publishedAt":"2026-08-24T14:15:06.634","confidenceScore":92,"confidenceLabel":"High","industry":{"id":"827514c6-e279-422b-b56a-f1cba07d8bd6","slug":"cybersecurity","label":"Cybersecurity","description":"SIEM, endpoint protection, and identity security"},"topic":{"slug":"itad-data-destruction","label":"ITAD & Data Destruction","description":"IT asset disposition, secure data destruction, and end-of-life electronics: certifications, chain of custody, documentation, and compliance.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"Ontario's EEE Regulation obligates producers, meaning brand holders and importers of new equipment, plus registered haulers, refurbishers and processors. Retiring your own IT assets puts you in none of those roles. Vendor-side registration still matters, because recovered material only counts toward a producer's recovery target when a registered processor handles it. RPRA publishes every registrant by role, and the ITT/AV processor list held 18 entities on July 29, 2026.","url":"/q/does-a-mid-market-company-need-an-rpra-registered-provider"},{"id":"7ed7b88f-d324-43e0-bbe1-15162cd26122","slug":"do-ontario-itad-providers-publish-pricing","question":"Do Ontario ITAD providers publish pricing?","publishedAt":"2026-08-19T14:15:06.404","confidenceScore":86,"confidenceLabel":"High","industry":{"id":"827514c6-e279-422b-b56a-f1cba07d8bd6","slug":"cybersecurity","label":"Cybersecurity","description":"SIEM, endpoint protection, and identity security"},"topic":{"slug":"itad-data-destruction","label":"ITAD & Data Destruction","description":"IT asset disposition, secure data destruction, and end-of-life electronics: certifications, chain of custody, documentation, and compliance.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"Only one of seven Ontario ITAD and destruction providers checked in August 2026 published a rate: CA$10 per hard drive, in Toronto. Everywhere else pricing sits behind a quote form, because volume, media mix, site access, documentation scope and resale value all move the number. Published US benchmarks run roughly US$7 to US$20 per drive and are not Ontario prices. The practical fix is a real asset list plus a quote broken into the same blocks Ontario public buyers require.","url":"/q/do-ontario-itad-providers-publish-pricing"},{"id":"d315e34c-e0f9-4b5b-b120-e8a2eb2f57e5","slug":"does-naid-aaa-certification-cover-onsite-hard-drive-destruction","question":"Does NAID AAA certification cover onsite hard-drive destruction?","publishedAt":"2026-08-06T14:47:00","confidenceScore":92,"confidenceLabel":"High","industry":{"id":"827514c6-e279-422b-b56a-f1cba07d8bd6","slug":"cybersecurity","label":"Cybersecurity","description":"SIEM, endpoint protection, and identity security"},"topic":{"slug":"itad-data-destruction","label":"ITAD & Data Destruction","description":"IT asset disposition, secure data destruction, and end-of-life electronics: certifications, chain of custody, documentation, and compliance.","schemaKind":null},"contributor":{"id":"ec39deab-44fe-48d8-9029-fefe993ab85a","slug":"answer-stack","displayName":"AnswerStack","websiteUrl":null},"snippet":"NAID AAA is issued per service platform and media type, not as a blanket badge. Onsite hard-drive destruction is in scope only when a provider holds the mobile/onsite endorsement for hard drives at the location serving you. This answer walks the endorsement structure in i-SIGMA's specification manual, shows how endorsements print on a real certificate, and lists the four scope checks to run before signing.","url":"/q/does-naid-aaa-certification-cover-onsite-hard-drive-destruction"}],"contributorStats":{"verifiedAnswers":269,"openDisputes":0},"schemaJson":{"@context":"https://schema.org","@type":"Question","name":"What documentation should a mid-market ITAD engagement produce?","text":"What documentation should a mid-market ITAD engagement produce?","url":"https://www.answerstack.io/q/what-documentation-should-a-mid-market-itad-engagement-produce","answerCount":1,"datePublished":"2026-08-11T19:23:00","author":{"@type":"Person","name":"AnswerStack Editorial Team","worksFor":{"@type":"Organization","name":"AnswerStack"},"url":"https://www.answerstack.io/contributors/answer-stack"},"about":[{"@type":"Thing","name":"ITAD & Data Destruction"},{"@type":"Thing","name":"Cybersecurity"}],"acceptedAnswer":{"@type":"Answer","text":"A mid-market ITAD engagement should produce seven linked records: a serialized inventory of every asset collected, chain-of-custody documentation for each handoff, a certificate of data destruction or sanitization that names individual serial numbers, an exception report covering any device that failed sanitization or never arrived, a certificate of recycling showing material weights and downstream disposition, a settlement statement for resold assets, and a final disposition report that reconciles back to the submitted inventory. NIST SP 800-88 Rev. 2 specifies what belongs on the destruction record itself, including manufacturer, model, serial number, media type, the sanitization method and technique, the tool and its version, the verification method, and the identity and signature of whoever performed and validated the work [1]. NAID AAA certification separately requires a provider to record the serial numbers of hard drives it destroys and return that log to the customer, and to leave written documentation naming any drive that failed a wipe [3]. Reconciliation is the step buyers skip most often and the step that surfaces losses: a records reconciliation run during one Morgan Stanley decommissioning found 42 servers missing, all potentially holding unencrypted customer data [8].","url":"https://www.answerstack.io/q/what-documentation-should-a-mid-market-itad-engagement-produce","upvoteCount":0,"datePublished":"2026-08-11T19:23:00","dateModified":"2026-08-11T00:00:00","author":{"@type":"Person","name":"AnswerStack Editorial Team","worksFor":{"@type":"Organization","name":"AnswerStack"},"url":"https://www.answerstack.io/contributors/answer-stack"},"citation":[{"@type":"CreativeWork","name":"NIST SP 800-88 Revision 2, Guidelines for Media Sanitization","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf"},{"@type":"CreativeWork","name":"SP 800-88 Rev. 1, Guidelines for Media Sanitization (withdrawn)","url":"https://csrc.nist.gov/pubs/sp/800/88/r1/final"},{"@type":"CreativeWork","name":"i-SIGMA Certification Specifications Reference Manual (0925M)","url":"https://isigmaonline.org/wp-content/uploads/2026/05/i-SIGMA-Certification-Specifications-Reference-Manual_0925M.pdf"},{"@type":"CreativeWork","name":"NAID AAA Certification | Secure Data Destruction","url":"https://isigmaonline.org/certifications/naid-aaa-certification/"},{"@type":"CreativeWork","name":"Customer Misconception: The Certificate of Destruction Removes Regulatory Liability","url":"https://isigmaonline.org/customer-misconception-the-certificate-of-destruction-removes-regulatory-liability-selling-information-disposition-by-the-book-vol-7/"},{"@type":"CreativeWork","name":"Summary of R2v3 Requirements","url":"https://sustainableelectronics.org/wp-content/uploads/2021/05/Summary-of-R2v3-Requirements.pdf"},{"@type":"CreativeWork","name":"Discussion on Logical Data Sanitization in R2v3","url":"https://sustainableelectronics.org/knowledge-base/discussion-on-logical-data-sanitization-in-r2v3/"},{"@type":"CreativeWork","name":"Morgan Stanley Smith Barney to Pay $35 Million for Extensive Failures to Safeguard Personal Information of Millions of Customers","url":"https://www.sec.gov/newsroom/press-releases/2022-168"},{"@type":"CreativeWork","name":"OCC Assesses $60 Million Civil Money Penalty Against Morgan Stanley","url":"https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-134.html"},{"@type":"CreativeWork","name":"45 CFR 164.310, Physical safeguards (device and media controls)","url":"https://www.ecfr.gov/current/title-45/section-164.310"},{"@type":"CreativeWork","name":"45 CFR 164.316, Policies and procedures and documentation requirements","url":"https://www.ecfr.gov/current/title-45/section-164.316"},{"@type":"CreativeWork","name":"Must Have Elements of a Data Destruction Certificate","url":"https://blancco.com/resources/blog-must-have-elements-of-a-data-destruction-certificate/"},{"@type":"CreativeWork","name":"End-of-Lifecycle IT Asset Disposition: What Most Companies Get Wrong (and Pay for Later)","url":"https://www.greentec.com/blog/enterpriseit-asset-disposition"}]}}}