Insights

Security

NIST 800-88, ADISA and data wiping for ITAD

Open laptop board during diagnostics before certified erasure

NIST 800-88 data wiping is the method language most European security teams already accept for ITAD. Pair it with a facility audit trail (often described as ADISA-style) and a log per serial, and you can answer GDPR Article 32 without a batch letter that names no device.

Jonas found the gap in March 2024. An insurer asked for proof on a ThinkPad that had held payroll exports. The recycler file said "IT equipment, Q3, wiped." It did not say that serial, that media type, or what happened when the wipe tool returned a fail. He had a PDF with a padlock icon. He did not have evidence.

You already retire machines in Intune or Jamf. That is not the same as destroying the bits on the drive. This article splits MDM retire, NIST sanitisation, failed-wipe destruction and the certificates buyers actually keep.

MDM retire is not data wiping

When an employee leaves, IT removes the laptop from the tenant. That is correct and necessary. The disk can still hold a previous image, a local cache, or a forgotten BitLocker recover key sitting in a text file on the desktop.

Factory reset on a phone is closer, and still not a named sanitisation method. It is also easy to skip when a drawer fills up in the last week of a refresh.

Treat three layers as separate:

If you only do the first layer, you have a clean directory and a dirty pallet. ITAD refurbishment fails at that point even if the resale story looks fine.

Refresh is where we bind wipe logs to serials. See the Refresh process if you need certificates, not icons.

What NIST SP 800-88 actually asks you to choose

NIST SP 800-88 Rev. 1 is a sanitisation guide, not a brand. It asks you to pick a category that matches residual risk:

Clear. Logical techniques that make data recovery infeasible with standard interfaces. Think overwriting user-addressable space. Fine for many internal reallocations. Weak if a buyer might chip-off a drive.

Purge. Physical or logical techniques that make recovery infeasible even with lab methods aimed at that media. Crypto-erase on a self-encrypting drive can sit here if you trust the implementation. Degaussing of magnetic media sits here. SSDs are messy; vendor secure-erase plus verification is the usual workshop path.

Destroy. Shred, pulverise, incinerate, melt. Use it when Purge fails, when the media is unknown, or when policy says the data class never leaves the building in working form.

Write the choice in the Recover brief, not on a sticky note at the bench. A payroll laptop and a kiosk tablet should not share a default because "we always run DBAN." DBAN does not speak NVMe. The tool has to match the bus.

Helene, who reports security controls for a public body, used to list "wiping: yes" in the annual control file. In 2025 she changed the line to "Purge via vendor secure-erase, verify, destroy on fail, log retained 7 years." The auditor still asked questions. They were shorter questions.

ADISA and facility proof, not a prettier PDF

NIST tells you what to do to media. It does not tell a buyer that your workshop actually does it on Tuesdays when the queue is long.

ADISA (the Asset Disposal and Information Security Alliance) is the name most EU professional buyers recognise for independently audited ITAD processes. You do not need the acronym in every paragraph. You do need an audit story: who tests the process, how failed jobs are handled, how media is stored before destruction.

A certificate with a hologram and no serial is marketing. A CSV with serial, method, tool version, timestamp, operator ID and pass/fail is operations. We keep the second and will attach the first if a buyer asks.

If a vendor leads with ISO logos and cannot show a failed-wipe row, keep shopping. Failed wipes are the honest part of the file.

Map wiping to GDPR Article 32 without legal theatre

GDPR Article 32 asks for appropriate technical and organisational measures, including protection against unauthorised processing and accidental loss. It does not say "NIST." It does not say "three-pass overwrite."

Your job is to pick a method that matches the data class, apply it, and show that you did. For employee laptops that saw mail and files, Purge plus verification is the usual bar. For devices that never left a kiosk image, Clear might be enough if legal agrees in writing.

Organisational measures matter as much as the algorithm:

Missing serials are a wiping problem. You cannot certify a device you never identified. That is why reverse logistics and the first scan sit in Recover, not in a security afterthought.

Failed wipes, unknown media, and the quiet bin

Every workshop has a pile that did not cooperate. The SSD that times out. The phone with a dead board that still has flash. The laptop whose firmware password survived the last admin.

Policy for that pile:

  1. Stop. Do not remarket.
  2. Record the fail against the serial.
  3. Destroy the media to the agreed method.
  4. Keep a destruction witness (weight, shredder job ID, photo of the bin seal if you use one).

Luca in Milan once found "Grade B, wiped" on a lot of 40 units. Two SSDs had empty wipe fields. The vendor had graded the lids. The buyer rejected the lot. The two empty fields cost more than the shredder would have.

Do not mix destroyed media with recycled plastics in the same line of the report if legal wants a media-only trail. Recycling of the chassis can still happen. The disk's story stays separate.

What a usable wipe certificate contains

Minimum fields we put on the file that leaves Refresh:

Optional but useful: hash of the log row, photo of the unit at scan, link to the grade after wipe.

Buyers of B2B lots will ask for the lot-level summary. Legal will ask for a serial. Build both from the same table.

If your current certificates name a quarter and not a serial, send us a sample (redacted). We will tell you what an auditor will still request. Contact.

SSDs, HDDs and the tools people still name from 2012

Most fleet laptops in 2024 and 2025 are NVMe. A three-pass overwrite story copied from an old HDD runbook does not apply, and it wastes hours. Overwrite still has a place on magnetic disks. On flash, you want a vendor secure-erase or a crypto-erase you can defend, then a verify that the namespace is gone.

Common traps:

If your workshop cannot name the tool per media family, you do not have a method. You have a ritual.

Helene asked a previous vendor for "the NIST setting." There is no setting. There is a category and a technique. We sent her a one-page matrix: HDD Clear/Purge, SATA SSD Purge, NVMe Purge, phone factory + account release + verify, unknown equals Destroy. She put it in the brief. The bench stopped improvising.

Verification is the part vendors skip on the quote

A progress bar is not evidence. Verification means you try to read the media after the method and you record that the read failed in the expected way, or that the namespace is empty, or that the crypto-erase status the drive reports matches the vendor note.

For Destroy, verification is a witness: weight in, weight out, shredder job, or a crushed-drive photo next to the serial sticker you peeled first. Peeling the sticker after the crush is how you certify the wrong brick.

Build time for verify into the 96-hour sort. Teams that skip it do it because the pallet is late, which is a Recover problem, not a reason to skip the only step an auditor can still test.

Jonas now samples 5 percent of "pass" rows and asks for the raw tool log, not the pretty PDF. We would rather fail that sample in the workshop than in an insurance email.

Practical sequence on the bench

A sane Refresh order for a mixed pallet:

  1. Scan and match to the Recover file.
  2. Identify media. Flag unknown, RAID, soldered, or crypto-unknown.
  3. Apply the method in the brief.
  4. Verify. Do not trust a progress bar.
  5. If fail, destroy and close the row.
  6. Only then cosmetic work and grading.

Wiping after a polish looks efficient. It is how you discover a fail when the device already has a Grade A photo. Then you shred a pretty laptop. Do the ugly step first.

Phones need their own station. Profiles, Find My, MDM locks and dead batteries each block erasure. A locked iCloud unit is not a wipe fail in the NIST sense; it is an identity fail. Keep it out of Remarket until the account owner releases it. That is an HR and IT conversation, not a shredder conversation, until you have waited out the policy window.

FAQ

Can we overwrite HDDs and crypto-erase SSDs in the same lot?

Yes, if the log says so per serial. Homogeneous lots are easier to sell. Mixed methods are fine for evidence.

Is degaussing enough for laptops?

Only for magnetic media you can actually degauss. Most modern laptops are SSD. Degaussing an SSD does not do what people think it does.

How long should we keep wipe logs?

Align with your data retention and insurance. Seven years is a common ask. The workshop should not be the only copy.

Do employees need to sign that their device was wiped?

Not usually. You need the technical log. A staff acknowledgement is for the handover of a refurbished unit, which is a different form.

Write the method before the truck moves

NIST 800-88 data wiping is a choice you can put in a sentence. ADISA-style audit is a claim about the building. GDPR Article 32 is why legal will ask. The serial is the join key.

Put the method in the Recover brief. Run it in Refresh. Carry it into Remarket so a buyer is not guessing. If you want a second pair of eyes on a current certificate pack, ask for an audit and send the template you use today.