A Certificate of Destruction (COD) is a formal document that proves a specific piece of data-bearing equipment was sanitized or physically destroyed, using a documented method, on a specific date. It serves as your audit evidence that retired equipment was handled compliantly, not just as a generic receipt confirming a vendor “took care of it.”
What Information a Real COD Should Include
Not every document labeled “Certificate of Destruction” actually proves what it claims to. A complete, audit-ready COD should include:
- Serial numbers for every individual device processed — not a batch total or an aggregate device count
- The specific destruction method used, such as software-based overwrite (Clear), cryptographic erase (Purge), degaussing, or physical destruction (Destroy)
- The date of destruction, tied to each device or processing batch
- The technician or witness responsible for performing or verifying the destruction
- The standard referenced, such as NIST SP 800-88, confirming the method meets a recognized sanitization framework
- The processing location, confirming where destruction actually took place
If a certificate you receive is missing serial numbers or doesn’t specify a destruction method per device, it’s not giving you what you actually need for an audit. For the full breakdown of what current federal guidance requires, see our NIST 800-88 guide.
Why You Need One
A Certificate of Destruction isn’t paperwork for its own sake — it’s the evidence that protects your organization in three specific situations:
- Audits. Compliance auditors and regulators want proof that data-bearing equipment was destroyed according to a specific, defensible standard — not just a vendor’s word that it happened.
- Compliance documentation. Regulations like HIPAA, FISMA, and others require organizations to demonstrate proper disposition of data-bearing media. A COD is often the specific document that satisfies this requirement.
- Legal protection. If a data breach investigation ever traces back to retired equipment, a serialized COD is your evidence that the device was properly destroyed before it left your control, well before any alleged breach could have occurred.
Without a proper COD on file, your organization has no defensible proof that retired equipment didn’t leave your facility with recoverable data still on it.
Certificate of Destruction vs. Certificate of Recycling
These two documents get confused often, but they prove different things.
A Certificate of Destruction confirms that data on a specific device was sanitized or the device was physically destroyed to prevent data recovery. It’s about data security.
A Certificate of Recycling confirms that the physical materials from a device — plastics, metals, and other components — were processed through a certified recycling channel rather than sent to a landfill. It’s about environmental compliance, not data security.
An organization retiring data-bearing equipment typically needs both documents, since they cover two entirely separate compliance concerns. If a vendor only provides one, ask specifically which one you’re missing.
See a Real Certificate of Destruction
Reading about what a COD should include is one thing — seeing an actual, complete example makes it concrete. Download a sample Certificate of Destruction to see exactly what serialized, audit-ready documentation looks like from DES Technologies.
Frequently Asked Questions
Is a COD legally required?
Not universally, but many regulations — including HIPAA, FISMA, and various state data protection laws — require organizations to demonstrate proper disposition of data-bearing media. A Certificate of Destruction is typically the document that satisfies this requirement, even when the law doesn’t name the document by that exact title.
How long should I keep a COD on file?
Retention requirements vary by industry and regulation, but many organizations keep Certificates of Destruction for several years to align with their broader compliance documentation retention policies. Check your specific regulatory framework (HIPAA, FISMA, SOX, or others) for the retention period that applies to your organization, and when in doubt, retain records longer rather than risk gaps in your audit trail.
What’s the difference between a Certificate of Destruction and a Certificate of Recycling?
A Certificate of Destruction proves data was securely destroyed. A Certificate of Recycling proves the physical materials were processed responsibly. They address separate compliance requirements, and most organizations need both.
What should I do if my vendor’s COD is missing information?
Ask for a corrected version before you file it. A COD missing serial numbers, destruction method, or date doesn’t hold up as real audit evidence, regardless of how official it looks.
Ready to See What Complete Documentation Looks Like?
Download a Sample Certificate of Destruction to review exactly what serialized, standards-referenced documentation should include before your next audit.