Skip to content
Answer Stack
Open menu

Is onsite hard-drive destruction worth the premium over offsite?

✓ Verified Last reviewed by AnswerStack Next review due Nov 17, 2026

Every claim is sourced below

Onsite hard-drive destruction earns its premium when a data classification, a customer contract, or an internal policy requires that drives never leave your building intact, and it usually does not earn it for routine refreshes of standard office hardware. Published US benchmarks put physical destruction at roughly $4 to $20 per drive offsite and $10 to $40 per drive onsite, with one pricing comparison putting the onsite premium at 50% to 100% plus a per-visit minimum of about $90 to $300, and another putting it at 20% to 30% [8][9]. What the money buys is custody rather than a better shred: NAID AAA's mobile service platform requires a certified provider to destroy media on your premises unless you sign a written agreement saying otherwise, which closes the transport window entirely [3]. Offsite destruction under the same certification is not unsupervised, since the program sets locked-cab and locked-box vehicle rules, fleet route tracking, and seven-year criminal record screening for anyone who handles media [3]. Because most of the onsite premium is a fixed mobilization cost, volume decides the economics: at 25 drives it can nearly double the bill, and at several hundred it rounds to noise [9][10].

What does the onsite premium actually buy?

Onsite and offsite destruction usually end in the same place: a shredded drive and a certificate carrying your serial numbers. The premium buys a different custody model. With onsite service, a technician brings industrial destruction equipment to your dock or server room and reduces the drives before anything leaves your control. With offsite service, the drives go into locked containers, ride to a plant in a locked and fully enclosed vehicle box, and are destroyed there [3]. Both routes can carry NAID AAA certification, and both produce a certificate of destruction.

i-SIGMA, which administers NAID AAA, treats the two as separate certified service platforms rather than one service delivered two ways. Its published program description distinguishes mobile operations, which "occur at the client's site using on-site equipment," from facility-based operations, which are "performed at a secure, stationary location" [2]. Media types are scoped separately too, with a distinct endorsement for hard-drive physical destruction and another for solid-state devices [3]. A vendor that says it is NAID AAA certified has told you little about whether it is certified for the thing you are buying.

The rule that makes onsite mean something

Specification 4.23 of i-SIGMA's certification manual applies only to the mobile and onsite service platform, and it states that the "Applicant must perform information destruction services on the Data Controller's premises." The audit method requires the provider's own policy manual to say that "mobile destruction services must be performed at the Data Controller's site unless there is a written Data Controller agreement stating otherwise" [3]. A certified mobile provider therefore cannot load your drives, drive away, and destroy them at the plant while still billing it as onsite service, unless you have signed something permitting exactly that.

What onsite does not mean

Onsite service is not a tighter destruction standard. i-SIGMA's hard-drive endorsement requires that drives be "damaged to the point where the platters will not engage," with no separate particle-size figure attached, and that requirement holds whether the shredder sits in a truck at your dock or on a plant floor [3]. Onsite is also not a substitute for verification. NIST's current guidance describes verifying a destructive method as inspecting "the remnants of a destruction technique" and identifying "the equipment used with it," which is an observation-and-records exercise in both models rather than a per-drive test [1].

How much more does onsite cost?

Published US benchmarks put physical destruction of a hard drive at roughly $4 to $20 per unit offsite and $10 to $40 per unit onsite. One industry pricing comparison states that onsite services add a 50% to 100% premium for security and convenience, with minimum charges of about $90 to $300 per visit [8]. A second published guide puts the gap much lower, "often 20-30% higher than off-site alternatives" [9]. Both figures circulate widely, and the spread between them is the honest answer: the premium is not a stable percentage, because it is mostly a fixed cost expressed as one.

Volume is what moves it. Small onsite jobs of 25 drives or fewer can run "as high as $40 per drive" [9]. Below 50 drives, per-unit costs commonly sit in the $15 to $20 band, while above 100 drives they fall to $7 to $10, and one comparison quotes as low as $4.25 per drive at 251 units or more [10][8]. Since a visit fee is charged once regardless of load, a $150 mobilization cost works out to $6 per drive on a 25-drive job and 30 cents per drive on 500.

The equipment is faster than the paperwork

Mobile throughput is high enough that shredding time rarely drives the bill. Shred-Tech's ST-5, sold as a portable unit and as an installation on shred trucks for onsite work, is rated at up to 750 hard drives per hour or up to 1,000 solid-state drives per hour, reducing a drive in about five seconds [11]. A 400-drive onsite job is therefore well under an hour of actual shredding, and most of the visit goes to staging and serial-number capture.

Canadian and US rates land in similar territory

Rates published outside the US benchmarks sit in the same band. Carbon Neutral Shredding, which serves Toronto and the surrounding region, publishes a flat $10 per hard drive on a page describing destruction performed in front of the customer, with a photograph of each drive and its serial number taken before destruction and a second afterward [12]. That page cites the Treasury Board of Canada's shredding standard rather than a third-party destruction certification, a reminder that a headline per-drive rate and an audited chain of custody are separate line items.

Five inputs settle most of these decisions, and only one is price. Work through them in order, because the first two can make the cost question moot.

Input Points toward onsite Points toward offsite
Data classification Unencrypted media, regulated or contractually restricted records, data you could not reconstruct [1] Standard office endpoints, drives encrypted at rest, non-sensitive assets [1]
Written policy or audit requirement A policy, customer contract, or auditor asks for destruction witnessed on your premises [3] No witness clause; the FTC's own example of a reasonable measure is a vetted destruction contract [5]
Volume Fewer than about 50 drives, or a one-time purge on a fixed deadline [9][10] Several hundred drives, rolling refresh cycles, scheduled pickups [10]
Asset mix and downstream intent Destruction only, drives already pulled from chassis Mixed streams where reuse, resale, or recycling also apply [14]
Site logistics Truck access, a usable dock, floor space to stage cartons [3] Restricted docks, high-rise or multi-tenant space, many small sites

The rows do not carry equal weight. A regulated data class or a contractual witness clause decides the question on its own, and cost decides only once the first two rows come back neutral.

When does data classification force onsite?

Onsite becomes the defensible default when the media is unencrypted, holds regulated or contractually restricted records, and could not be reconstructed if it went missing. NIST's framing helps here because it is about control rather than about shredders. SP 800-88 draws a line between media under organizational control and media that is not, and it counts work "being performed on an organization's site, under the organization's supervision" as still under the control of the organization [1]. Onsite destruction keeps the entire disposal event inside that boundary. Offsite destruction moves it outside, shifting the assurance from your own observation to a vendor's controls and records. NIST adds that legal or statutory requirements attached to certain sensitive data "can treat the loss of organizational control of ISM that have not been sanitized as a data breach" [1].

Regulation itself rarely mandates onsite. The FTC's Disposal Rule sets a standard of "taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal," and lists as one such measure "after due diligence, entering into and monitoring compliance with a contract with another party engaged in the business of record destruction" [5]. NIST stays neutral on the same question, listing "Whether sanitization techniques should be conducted by the organization or a third party" and "Whether sanitization is performed on-site or off-site" among the factors an organization should weigh, alongside the anticipated volume of media, whether the media will be processed in a controlled area, and the cost of sanitization [1]. Neither instrument asks for a witness.

Where onsite gets written into policy anyway

Internal policy and customer contracts do more work here than statute does. Defense subcontracts and some healthcare and financial agreements specify that data-bearing media may not leave a facility intact, and acquisition-related data purges often carry the same clause. Once that language exists, the cost comparison is over, and the useful question becomes whether your provider actually holds the mobile endorsement for the media type you are destroying, since NAID AAA scopes hard drives and solid-state devices as separate endorsements [3]. Ask for the endorsement list rather than the badge.

When is offsite the better fit?

Offsite fits high-volume, mixed-asset work better than onsite does. A plant runs larger equipment than anything that fits in a truck, and it can separate reusable assets from destruction candidates while processing a data center's worth of drives in one intake. Provider guidance describes the same split. Greentec, an Ontario ITAD and electronics recycling company, frames offsite destruction as "generally preferred for large-volume projects, data center decommissions, or mixed electronics streams where destruction, recycling, and reuse may all be required," and frames onsite as the choice where "policy or risk tolerance dictates that data-bearing media must never leave the site intact" [14].

Value recovery is the second reason volume pushes offsite. Drives that will be shredded have no resale value, but a decommissioning project that includes servers, switches, and laptops usually has recoverable assets in the pile. Splitting that into an onsite destruction visit plus a separate offsite logistics engagement adds a mobilization fee without changing the outcome for drives that were always going to be shredded.

Site constraints decide more jobs than buyers expect

Physical access stops more onsite plans than budget does. A shred truck needs a route in, a place to park, and floor space to stage cartons, and the destruction has to happen on your premises to satisfy the mobile specification rather than in a lot down the block [3]. Multi-tenant high-rises and hospital campuses with controlled loading docks tend to make onsite either impossible or expensive enough that the premium becomes the entire cost. Portfolios of small branch offices hit the same wall, since each site is its own visit. Scheduled offsite collection absorbs distributed footprints far more cheaply.

What does witnessing destruction actually prove?

Witnessing proves that the specific drives you handed over were destroyed at a specific time. It proves nothing about the drives you did not hand over, and that distinction matters more than it sounds, because inventory error is a far more common failure than destruction error. In the Morgan Stanley matter, no shredder underperformed. The firm hired "a moving and storage company with no experience in data destruction," that vendor sold the devices to a third party which auctioned them online with unencrypted data intact, and 42 servers were never accounted for [6]. A witness standing at the dock would not have caught any of that. A reconciled serial-number inventory would have.

NIST's current verification guidance points the same direction. For destructive methods it describes verification as inspecting "the remnants of a destruction technique" and identifying "the equipment used with it," and its validation step names sanitization "performed by unqualified personnel" or equipment that was "not approved and/or were improperly calibrated" among the reasons an outcome should be rejected [1]. Physical destruction therefore gets verified by observing the process and the machine and then reconciling records, not by testing each drive afterward. That argues for onsite service, and just as strongly for making an offsite plant name and document the equipment it used.

The paperwork carries the assurance in both models

i-SIGMA's hard-drive endorsement requires that serial numbers of all drives destroyed be recorded unless the customer signs an opt-out, that the log of recorded serial numbers be returned to the customer on completion of the service, and that the provider supply a written description of the destruction process before it happens [3]. None of those requirements change between the mobile and facility-based platforms. A buyer who reconciles the returned serial log against an asset inventory holds stronger evidence than a buyer who watched a truck run for an hour and never checked the list. Doing both beats doing either alone, and the reconciliation is the cheaper half.

Is offsite destruction actually riskier?

Offsite adds a transport window, and under NAID AAA that window is audited rather than left to trust. i-SIGMA's specification manual requires that "all vehicles used for transfer of Data-Controller Media will have lockable cabs and lockable, fully enclosed boxes," that those cabs and boxes "must be locked during transport and when unattended," and that providers define "clear and effective controls to manage fleet route location detail such as GPS tracking technologies or other reporting" [3]. Vehicles are inspected before going into service each day, containers may not be left unattended unless locked in a transportation vehicle or inside the secured facility, and auditors physically inspect trucks, covering every vehicle when a provider runs three or fewer and 75% when it runs four or more [3]. Staff who handle media must clear a seven-year criminal record search through an outsourced third-party screening service, a seven-year employment history verification, and pre-hire drug screening [3]. Certified companies "must pass scheduled and surprise audits" [4].

The measured incidence of disposal failures is also low. Of 710 healthcare data breaches reported to US regulators in 2025, exactly one was an improper-disposal incident, although it affected more than 35,000 people [7]. Disposal is a low-frequency, high-visibility failure mode.

The residual risk offsite is real but specific

What offsite exposes you to is the gap between the manifest and the plant. Drives stay intact and readable from the moment they leave your dock until they reach the shredder, and during that stretch you are relying on the provider's controls instead of your own. For standard office hardware, particularly drives encrypted at rest, that exposure is acceptable and priced accordingly. For unencrypted media holding regulated records, it is the precise exposure onsite service exists to remove.

The certification and regulatory claims in this answer come from primary documents: i-SIGMA's own certification specifications manual for the NAID AAA requirements, NIST SP 800-88 Revision 2 (September 2025) for the sanitization and verification language, and the text of 16 CFR 682.3 for the FTC's disposal standard. Revision 1 of the NIST guideline, still the version most vendor marketing cites, was withdrawn on September 26, 2025, and its representative-sampling verification and outsourcing appendices did not carry into Revision 2, so nothing here rests on them. The cost figures are weaker evidence by nature. No trade body publishes an audited price index for hard-drive destruction, so the ranges here come from pricing guides published by destruction vendors and marketplaces, cross-checked against one another. Those guides disagree, placing the onsite premium anywhere from 20% to 100%, and that disagreement is reported here rather than averaged away. Practitioners who run competitive ITAD bids, especially anyone holding current onsite and offsite quotes for comparable volumes, are invited to submit figures so these ranges can be tightened or corrected.

This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.

Trade-offs and what to watch

Onsite reduces one risk and introduces a smaller one

A truck at your dock means an outside technician moving through your space with your drives in cartons. i-SIGMA requires certified providers to hold a written policy preventing staff from using photographic or other electronic equipment, including handheld phones, in the presence of customer media [3]. Confirm that policy is in force during your visit, and escort the technician.

The premium is not linear, so price both options on the same inventory

Because the visit charge is fixed while per-drive rates fall with volume, the onsite premium on a 500-drive job can be smaller in absolute dollars than the premium on a 40-drive job [8][9][10]. Ask for onsite and offsite pricing against the identical asset list rather than accepting one number and a percentage.

Solid-state media is a separate conversation

Flash memory needs a finer particle size than magnetic platters, and one published pricing comparison notes that solid-state media requires shredding to a smaller particle size, which is part of why it prices higher [8]. NIST warns that a sanitization step can complete and still accomplish nothing, giving the example that "a sanitization operation that degausses an SSD can complete successfully, but no sensitive data is sanitized" [1]. i-SIGMA scopes solid-state destruction as its own endorsement, requiring that devices be "damaged to the point where they are unable to be used" [3]. Confirm your provider holds that endorsement, and note that customers "may specify a smaller particle size at their discretion, which should be codified contractually" [3].

Cost data in this market is thin, so treat percentages as directional

Most providers quote rather than publish. Shred-it's own comparison describes offsite as "often more cost-effective" and onsite as "may be higher due to on-site service delivery," with no figures attached [13]. Any single published premium percentage, including the ones cited here, should be read as a starting point for negotiation rather than a market rate.

Sources

NIST SP 800-88 Revision 2, Guidelines for Media Sanitization

National Institute of Standards and Technology

Primary source Verified Aug 17, 2026 Supports: Sec. 4.3.4 Control of Media and the organizational-control boundary, including loss of control of unsanitized media potentially constituting a data breach; Sec. 2.4 factors influencing sanitization decisions, which explicitly name onsite versus offsite performance, organization versus third party, c

“Maintenance being performed on an organization's site, under the organization's supervision, by a maintenance provider is also considered to be under the control of the organization.”

NAID AAA Certification | Secure Data Destruction

i-SIGMA

Primary source Verified Aug 17, 2026 Supports: Endorsements define mobile versus facility-based operations and media types; unannounced audits; CCTV retention and employee screening as certification requirements

“Mobile operations occur at the client's site using on-site equipment, while facility-based operations are performed at a secure, stationary location.”

i-SIGMA Certification Specifications Reference Manual (0925M)

i-SIGMA

Primary source Verified Aug 17, 2026 Supports: Spec 4.23 on-premises destruction requirement for the mobile/onsite platform; separate hard-drive and solid-state device destruction endorsements; platter non-engagement standard; serial-number recording and log return; vehicle locking, daily inspection, GPS/fleet route controls and truck inspection

“Applicant must perform information destruction services on the Data Controller's premises. ... mobile destruction services must be performed at the Data Controller's site unless there is a written Data Controller agreement stating otherwise.”

NAID AAA Certification FAQs

i-SIGMA

Primary source Verified Aug 17, 2026 Supports: Certified companies face both scheduled and surprise audits

“Certified companies must pass scheduled and surprise audits to demonstrate compliance with strict operational and security standards.”

16 CFR 682.3: Proper disposal of consumer information

Legal Information Institute, Cornell Law School

Primary source Verified Aug 17, 2026 Supports: The FTC Disposal Rule's reasonable-measures standard and its explicit allowance for contracting a vetted destruction firm after due diligence; no witness requirement

“Any person who maintains or otherwise possesses consumer information for a business purpose must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.”

Morgan Stanley fined $35M by SEC over improper data disposal

Cybersecurity Dive

Independent Verified Aug 17, 2026 Supports: The failure mode was vendor selection and inventory reconciliation, not destruction quality: an inexperienced vendor resold devices and 42 servers were never accounted for

“hired a moving and storage company with no experience in data destruction ... sold the devices to a third party, which auctioned them online with some unencrypted data intact”

2025 Healthcare Data Breach Report

The HIPAA Journal

Independent Verified Aug 17, 2026 Supports: Base rate of improper-disposal breaches: one incident among 710 reported healthcare breaches in 2025, affecting more than 35,000 individuals

“Improper disposal incidents are also something of a rarity. In 2025, there was only one such incident at a HIPAA-regulated entity, although it was a significant data breach, affecting more than 35,000 individuals.”

Digital Data Destruction Pricing: Certified Methods, Costs, and Comparisons

Data Destruction Inc.

Independent Verified Aug 17, 2026 Supports: Onsite premium of 50% to 100%; onsite shredding $10 to $40 per unit versus offsite $4 to $15; per-visit minimum charges of about $90 to $300; as low as $4.25 per drive at 251 or more units; smaller particle size required for solid-state media

“On-site services add 50-100% premium for security and convenience ... Minimum charges typically $90-$300 per visit”

How Much Does Hard Drive Destruction Service Cost?

Scan N More

Independent Verified Aug 17, 2026 Supports: Average $7 to $20 per drive; onsite premium often 20% to 30% above offsite; small onsite jobs of 25 drives or fewer as high as $40 per drive; 100 or more drives dropping to $5 to $15

“Small quantities of hard drives (25 or less) to be shred onsite can be very costly...as high as $40 per drive”

Hard Drive Shredding Cost: A Business Guide to Secure Disposal in the USA

Beyond Surplus

Independent Verified Aug 17, 2026 Supports: Volume tiers: fewer than 50 drives at $15 to $20 per unit, 100 or more drives falling to $7 to $10 per drive; fuel and transportation surcharges are standard for mobile service; solid-state drives cost slightly more

“Businesses shredding fewer than 50 drives typically face costs in the $15 to $20 range per unit.”

E-Waste Shredders for E-Waste Recycling

Shred-Tech

Supporting Verified Aug 17, 2026 Supports: Mobile destruction throughput: the ST-5 is rated at up to 750 hard drives per hour or up to 1,000 solid-state drives per hour, about five seconds per drive, and is installable on shred trucks for onsite work. Equipment-manufacturer specification; pairs with cost sources [8][9][10] for the economics

“up to 750 hard drives per hour, or up to 1,000 solid-state drives per hour”

Secure Hard Drive Destruction Toronto & GTA

Carbon Neutral Shredding

Supporting Verified Aug 17, 2026 Supports: A published Canadian per-drive rate: $10 per hard drive including emailed documentation, with before-and-after photographs of the drive and its serial number, on a page describing destruction performed in front of the customer. Vendor's own published rate card; corroborated as in-band by [8][9][10]

“$10/hard-drive including e-mailed documentation”

On-Site vs. Off-Site Shredding: What You Need to Know

Shred-it

Supporting Verified Aug 17, 2026 Supports: A major provider's own onsite versus offsite framing: witnessed destruction, secure transport to a locked monitored facility, and cost direction stated qualitatively rather than numerically. Vendor content; quantitative claims rest on [8][9][10]

“Often more cost-effective ... May be higher due to on-site service delivery”

How to Destroy Data on Hard Drives Securely (Step-by-Step)

Greentec

Supporting Verified Aug 17, 2026 Supports: One Ontario ITAD provider's stated decision drivers for onsite versus offsite destruction, used only for the qualitative when-and-why framing. This page contains no pricing or cost-premium information; all cost claims rest on [8][9][10]

“generally preferred for large-volume projects, data center decommissions, or mixed electronics streams where destruction, recycling, and reuse may all be required”

Revision history

2 revisions since publication
v1.1 Reviewed and re-verified.
v1.0 Published after editorial review.