Guides → Audit & paperwork
What a Certificate of Data Destruction should actually contain
A certificate reading "42 items securely destroyed" proves nothing. It cannot answer the only question an auditor will ask, which is whether this specific drive was destroyed. Here is what separates an evidence document from a compliment slip.
What the certificate is for
It is easy to treat the certificate as a receipt. It is not — it is the evidence you rely on in three situations, each of which asks a different question.
- An audit — ISO 27001, a customer security review, an NHS or public sector assurance check. The question is: show me your process and the evidence it ran.
- A data subject request or an ICO enquiry. The question is: this person's data was on your systems, what happened to it?
- An asset turning up where it should not be. A device appears on eBay or in a news story with your asset tag. The question is: what did you do with it, and when?
Only the third is rare. The first two are routine, and both are answered by serial numbers.
The fields that matter
1. Every device listed individually by serial number
This is the one that carries all the weight. A certificate with a quantity but no serial numbers cannot connect your asset register to the destruction event, so it cannot prove anything about a particular device. If the supplier says serial capture costs extra, understand what you are declining: the certificate's evidential value.
Alongside the serial you want make, model and capacity, so the record is still interpretable when the drive is long gone.
2. The method applied to each device
Not a blanket statement at the top of the page, but a value per line — degaussed, shredded, or sanitised with the standard used. This is what demonstrates the right method reached the right media. A certificate that says "all items degaussed" and includes SSDs in the list is self-evidently wrong, and you want to be able to see that before an auditor does. See degaussing vs shredding vs wiping for why.
3. The standard claimed
"Securely destroyed" is marketing. "NIST 800-88 Rev 2 Purge" is a claim that can be checked, and it tells a reviewer exactly what level was achieved. If the certificate names no standard, there is nothing to hold the supplier to.
4. Dates — both of them
The collection date and the destruction date, separately. The gap between them is your window of exposure, and an auditor will look at it. A certificate showing a single date conceals whether drives sat in a warehouse for six weeks first.
5. Who did it, and under what authority
The operator or authorised signatory, the company, and the registration numbers that make them accountable — Environment Agency waste carrier registration, ICO registration, and any relevant certification. This is what makes the document traceable to a regulated entity rather than a logo in a header.
6. Your own reference
Your company name, site address and any job or PO reference. Obvious, but it is what lets you file the certificate against the right cost centre and find it again in three years.
7. A unique certificate number
So it can be cited in an audit response and verified with the issuer.
The one-line test
Pick a serial number from your asset register at random. Can you find that exact string on a certificate, with a destruction method and a date beside it, in under two minutes? If yes, your paperwork works. If no, you have a filing system, not an evidence trail.
Red flags
- Quantities instead of serial numbers. The fundamental failure. Everything else is secondary.
- "Securely destroyed" with no named standard. Unfalsifiable and therefore unenforceable.
- One method applied to visibly mixed media. Particularly degaussing listed against SSDs.
- Issued before the work happened. Certificates handed over at the point of collection describe an intention, not an event.
- No carrier registration number. Suggests the waste side is being handled informally too.
- No waste transfer note alongside it. The certificate covers the data; the transfer note covers the equipment. You are legally required to hold the second for two years, and it is a separate document.
- Counts that do not match what left your building. Reconcile them. Discrepancies are much easier to resolve in the first week.
What to do when it arrives
- Reconcile the serial numbers against the list you recorded before collection, and query anything missing immediately.
- Check the methods line by line against the media types.
- Close the assets off in your asset register, referencing the certificate number.
- File it with the matching waste transfer note — keep them together, because an audit will want both.
- Store it somewhere durable and findable. A named folder beats an inbox.
Retention: keep the waste transfer note for a minimum of two years as the law requires. Destruction certificates are usually worth keeping considerably longer — they are the evidence that closes off a data protection obligation, and six years is a common policy.
The overlooked half: capture serials before anything leaves
You cannot reconcile a certificate against a list you never made. The most common gap is not a bad certificate but the absence of a baseline to check it against. Record serial numbers at the point equipment is retired, not at the point it is collected — by then items have a habit of being borrowed, swapped or quietly taken home.
How we do it
Every device is logged by serial number at the point of collection, and the certificate records make, model, serial, method and date per line, against the NIST 800-88 Rev 2 standard, with our waste carrier and ICO registrations on the document. The waste transfer note is issued alongside it.
Want to see the format first? We will send a sample certificate so you can check it against your own audit requirements before booking anything.
Request a sample