Home / Insights

IT Asset Disposition (ITAD) for Data Centres: A Complete UK Guide

Engineer-led UK guide to data centre ITAD, covering discovery, secure decommissioning, sanitisation, chain of custody, asset recovery and recycling.

What data centre ITAD actually involves

Data centre IT asset disposition is the controlled retirement of infrastructure that has reached the end of its operational role. It is broader than recycling. A well-run programme coordinates technical decommissioning, data protection, asset identification, sanitisation, physical removal, secure custody, value recovery, reuse and final recycling.

In a live data centre, those activities are connected. Removing a server before an application dependency has been migrated can cause an outage. Removing a storage array without resolving data retention requirements can create a security or legal problem. Sending equipment for processing without reliable serial-level records can create an audit gap. ITAD therefore begins before equipment leaves the rack.

Start with business scope, ownership and the intended end state

Define which site, room, cage, racks and asset classes are in scope. Identify business owners, technical owners, security stakeholders and the person authorised to approve irreversible actions.

For each asset class, define the intended disposition: internal reuse, resale, vendor return, parts recovery, donation where policy permits, recycling, or physical destruction. The end state affects the required engineering, sanitisation and evidence.

Discovery must happen before removal

Build an inventory from live discovery and physical inspection rather than relying exclusively on a CMDB or spreadsheet. Record manufacturer, model, serial number, asset tag, rack/U position, hostname where appropriate, storage media, power/network connections and current role.

Reconcile discrepancies early. Data centre estates commonly contain equipment that was moved, upgraded, cannibalised or left in place without documentation being updated.

Map dependencies before touching production infrastructure

Identify application, virtualisation, network, storage, backup, monitoring, security and management dependencies. Confirm replacement services are operating before irreversible steps.

NCSC's current decommissioning guidance emphasises planning, coordination, replacement assets, secure interim storage, tracking, verification and post-decommission monitoring. These principles are especially important in dense data centre environments where one asset can support many services.

Servers and virtualisation hosts

Before retiring physical servers or VMware/other hypervisor hosts, migrate or shut down workloads through the approved change process. Check cluster membership, HA/DRS or equivalent services, shared datastores, backup jobs, monitoring, licences, management systems and out-of-band controllers.

Do not equate an apparently idle host with an unused host. Confirm workload, cluster and infrastructure state from the relevant management plane and from dependent services.

SAN, NAS and storage systems

Storage retirement needs special care because arrays can contain large volumes of replicated, deduplicated, cached or snapshot data. Map hosts, LUNs/volumes, file shares, replication, snapshots, backup integration, SAN zoning, multipathing and management dependencies.

Confirm data retention and migration requirements before deleting storage objects. For a detailed engineering sequence, use Compritech's server and storage decommissioning guide alongside the project plan.

Switches, routers and fabric infrastructure

Network devices should be withdrawn only after VLAN, trunk, LACP, spanning-tree, routing, HA, fibre and management dependencies have been validated. A device with little visible traffic can still provide a critical control-plane or failover role.

Use the network change process to withdraw services while rollback remains possible, then sanitise configuration and credentials according to the exact platform and policy.

Firewalls, VPN gateways and security appliances

Security appliances can retain rules, objects, certificates, private keys, VPN configuration, authentication relationships and network topology. Migrate security functions before retirement and revoke associated certificates or credentials as required.

NCSC network-device guidance specifically recommends revoking certificates associated with a device before disposal, changing or revoking other credentials as appropriate, following media sanitisation guidance where relevant, and using factory reset or device wiping as a general precaution.

Data classification should drive sanitisation decisions

The sanitisation method should reflect the sensitivity of the information, the storage technology, the assurance required and whether the asset will be reused.

NIST SP 800-88 Rev. 2, published in September 2025, focuses on establishing an enterprise media sanitisation programme and selecting appropriate controls based on information sensitivity. It also places emphasis on validation and on trust in vendor implementations for Clear and Purge techniques.

NIST SP 800-88 Rev. 2: Clear, Purge and Destroy

A useful ITAD programme should distinguish the sanitisation outcome required rather than treating every device the same. NIST's current guidance frames media sanitisation around methods including Clear, Purge and Destroy, with the appropriate approach selected through organisational policy and risk.

Revision 2 no longer acts as a catalogue of device-specific wiping recipes. Except for cryptographic erase guidance, it points organisations toward current relevant standards such as IEEE 2883, NSA specifications or an organisationally approved standard. This makes manufacturer capability, validation and documented policy particularly important.

NCSC guidance for UK organisations

NCSC defines sanitisation as treating data on storage media to reduce the likelihood of retrieval and reconstruction. It advises organisations to understand their data, identify assets containing electronic storage media, record the media lifecycle, establish reuse/disposal policy and understand sanitisation requirements.

NCSC also notes that many devices beyond obvious disks can contain electronic storage media, including routers, switches and peripherals. Data centre ITAD therefore should not limit its data-security scope to HDDs and SSDs alone.

Secure erasure and reuse

Where reuse or resale is permitted, successful sanitisation can preserve residual asset value and reduce unnecessary electronic waste. The process must be appropriate for the device and must be verified.

Record the asset identity, sanitisation method, result, operator/system reference and exception status. Failed or unsupported devices should move into an approved exception path rather than being silently treated as successfully erased.

When physical destruction is appropriate

Physical destruction may be selected when policy, data sensitivity, failed media, technical limitations or risk make reuse inappropriate. NCSC's current storage-media guidance describes circumstances where destruction may be required and, for the threat model addressed by that guidance, specifies destruction to particles of 6 mm or less and verification of resulting particle size.

That recommendation should not be generalised to every security classification or organisation. NCSC explicitly notes that separate guidance applies to HMG SECRET or above.

HDD, SSD and NVMe require technology-aware handling

HDDs, SSDs and NVMe devices do not behave identically. Flash storage introduces wear levelling, over-provisioning and controller-managed areas, while magnetic drives have different sanitisation characteristics.

Avoid assuming that a generic overwrite or degaussing process is suitable for every medium. Follow approved standards, manufacturer capabilities and the organisation's sanitisation policy. Compritech's dedicated HDD, SSD and NVMe destruction guide covers these differences in more depth.

Cryptographic erase

Cryptographic erase can be valuable for correctly implemented encrypted media when the relevant encryption keys can be sanitised with appropriate assurance. NIST Rev. 2 expands its cryptographic erase guidance and discusses key sanitisation and externally managed keys.

The important question is not merely whether encryption was enabled, but whether the cryptographic design, key location, key lifecycle and sanitisation operation support the required assurance.

Failed and inaccessible media

A drive that no longer boots is not automatically free of recoverable data. Faulty media should remain under controlled custody and follow an approved sanitisation or destruction exception process.

The same principle applies to failed RAID members, cache modules, flash cards, removable boot media and storage embedded in appliances.

Chain of custody starts at the rack

Chain of custody should begin when assets leave operational control, not when they arrive at a processing facility. Record who released the equipment, who received it, asset identifiers, time/date, location, container or consignment references and subsequent transfers.

NCSC's decommissioning guidance states that sensitive or valuable assets may require detailed chain-of-custody tracking when transferred between people or teams.

Serial-level reconciliation

Serial-level reconciliation links technical decommissioning to commercial and security outcomes. Compare the approved source inventory, physical collection manifest and final processing records.

Investigate missing, duplicate or unreadable serials before project closure. Exceptions should be visible rather than hidden by aggregate counts.

Secure staging and interim storage

Decommissioned equipment often spends time in a staging area before collection. Treat that stage as part of the security boundary. Restrict access, separate processed from unprocessed equipment and maintain traceability.

NCSC specifically advises that assets holding potentially sensitive data should not be stored in insecure environments while awaiting the next decommissioning stage.

Secure transport

Transport controls should reflect asset sensitivity and value. Use documented handover, appropriate packaging, controlled vehicle access, route/collection records where required, and clear responsibility for custody.

The security objective is continuity of accountability from rack removal through processing, not simply proof that a vehicle collected equipment.

Asset value recovery

Not every retired asset is waste. Servers, network equipment, memory, processors, enterprise SSDs, optics and other components may retain resale or reuse value.

Value recovery should happen only after data-security and contractual requirements are satisfied. Grade equipment consistently, document deductions and reconcile recovered value against the asset list so that commercial reporting remains auditable.

Reuse before recycling where appropriate

Extending the useful life of suitable equipment can preserve value and reduce demand for new hardware. Reuse should never bypass security, licensing, contractual or data-sanitisation requirements.

Assets unsuitable for reuse should enter an appropriate recycling route rather than being mixed into an undocumented downstream stream.

WEEE and environmental responsibilities

UK WEEE obligations depend on the parties' roles and circumstances. GOV.UK guidance explains that organisations placing electrical and electronic equipment on the UK market can have producer responsibilities, including registration and financing obligations in applicable cases.

For a customer ITAD project, do not reduce environmental compliance to a generic claim that 'WEEE means everything must be recycled'. Establish the applicable duty, waste classification, carrier/processor arrangements and evidence for the actual transaction.

Downstream due diligence

An ITAD provider should be able to explain what happens after collection: where equipment is processed, how reusable assets are handled, how data-bearing media exceptions are controlled and where residual waste goes.

For higher-risk projects, customer due diligence may include certifications, permits, downstream partners, insurance, security controls and sample evidence. The required depth should match the organisation's risk and procurement requirements.

Certificates of destruction and sanitisation evidence

A certificate is evidence, not a substitute for a controlled process. It should be traceable to the relevant assets or media and to the service actually performed.

NCSC's decommissioning guidance says organisations should confirm and retain evidence when external parties perform sensitive tasks such as destruction, and notes that this evidence typically comes in the form of certificates. Internally performed decommissioning should also be documented.

Project evidence pack

A mature data centre ITAD project can produce an evidence pack containing the approved scope, change references, source inventory, collection manifest, chain-of-custody records, sanitisation results, destruction evidence, exception register, asset recovery statement and final disposition/recycling records as applicable.

The pack should allow a reviewer to trace what happened to a specific asset without reconstructing the project from emails.

Exceptions and failed processing

Define exception categories before processing begins: missing asset, serial mismatch, inaccessible drive, sanitisation failure, unexpected storage media, damaged asset, ownership uncertainty or quarantine requirement.

Assign an owner and resolution status to each exception. Project completion should not convert unresolved exceptions into assumed success.

CMDB, asset register and IPAM updates

After physical and logical retirement, update authoritative records. Remove or mark retired assets in the CMDB and asset register, and update monitoring, DNS, IPAM, configuration management, support contracts and licensing systems as appropriate.

NCSC recommends updating asset inventories after decommissioning so that the organisation retains a dependable source of truth.

Post-decommission monitoring

Continue monitoring for unexpected effects after the change. Missing telemetry, failed backup jobs, routing changes or application errors can appear after the immediate implementation window.

NCSC explicitly recommends continued monitoring after decommissioning because unforeseen impacts may not be immediately apparent.

Data centre ITAD project sequence

A practical sequence is: approve scope; discover assets; reconcile inventory; map dependencies; classify data and disposition; migrate services; validate replacements; withdraw infrastructure under change control; sanitise or quarantine media; reconcile assets; establish chain of custody; remove and package equipment; transport securely; process reuse/resale/recycling; resolve exceptions; issue evidence; update authoritative records; and formally close the project.

Pre-decommission checklist

Confirm scope and owners; verify inventory; map applications, networks and storage; confirm backups/retention; validate replacement services; approve change and rollback; define sanitisation policy; identify high-risk media; establish chain-of-custody records; define exception handling; and agree final evidence requirements before irreversible work begins.

Post-processing checklist

Reconcile every required asset; confirm sanitisation/destruction status; resolve exceptions; reconcile recovered value; verify downstream disposition; update CMDB and asset registers; retain certificates/evidence; confirm monitoring is clean; and obtain project acceptance.

Common data centre ITAD mistakes

Common failures include treating ITAD as a collection-only exercise; relying on an outdated spreadsheet; destroying reusable assets without a risk decision; reselling equipment before sanitisation is verified; failing to track embedded or failed media; accepting aggregate certificates with no asset traceability; ignoring network/security appliance credentials; leaving decommissioned equipment unsecured in staging; and closing the project with unresolved serial discrepancies.

How Compritech approaches data centre ITAD

Compritech combines hands-on infrastructure engineering with IT asset disposition. The aim is to manage the transition from live infrastructure to secure final disposition without separating the engineering risk from the asset-security risk.

That approach can include discovery, network/server/storage decommissioning, rack removal, secure sanitisation, data destruction, serial-level reconciliation, chain of custody, asset recovery and responsible downstream recycling.

Final takeaway

Data centre ITAD is strongest when it is treated as an engineering, security, asset-management and evidence process from the start. The goal is not merely to empty racks. It is to prove that services were safely retired, data was appropriately protected, assets remained accountable, recoverable value was handled transparently and the final disposition can withstand audit.

Related Compritech engineering guides

Primary guidance used

Planning a data centre ITAD or decommissioning project?

Compritech provides engineer-led data centre decommissioning, network and server engineering, secure data sanitisation and destruction, asset reconciliation, recovery and ITAD services across the UK.

Discuss your projectData centre decommissioning servicesServer decommissioning servicesIT asset disposal servicesNetwork engineering services