Home / Insights

IT Asset Disposal for Government & Public Sector: Secure Data Destruction and Asset Accountability

UK public-sector ITAD guide covering OFFICIAL data, secure sanitisation, chain of custody, asset accountability, destruction evidence and supplier controls.

Why public-sector ITAD is an information-security and accountability process

Government departments, local authorities, agencies, public bodies and their delivery partners can hold citizen data, commercial information, operational records, security configuration and other sensitive material across a large and varied technology estate.

Secure IT asset disposition therefore involves more than collecting obsolete hardware. The organisation needs to know what is being retired, what information or credentials it may contain, whether services still depend on it, who is authorised to release it, how custody will be maintained and what evidence will demonstrate the final outcome.

Understand the Government Security Classifications Policy

HM Government uses three classification tiers: OFFICIAL, SECRET and TOP SECRET. The Government Security Classifications Policy applies protective behaviours and controls proportionate to the impact of compromise and the threat profile.

Most government information is handled at OFFICIAL, but that does not mean it can be disposed of casually. Classification, additional handling instructions, descriptors and local security policy should be understood before an asset or storage medium is released from operational control.

OFFICIAL-SENSITIVE is not a separate classification tier

Current Cabinet Office guidance states that OFFICIAL-SENSITIVE is not a separate classification tier. It is an additional marking used for OFFICIAL information requiring additional handling because compromise could cause moderate damage and the information is of interest to threat actors, activists, media or others.

An ITAD process should preserve any additional handling requirements that remain relevant during decommissioning, transport, sanitisation and final disposition.

SECRET and TOP SECRET require different controls

Do not apply public OFFICIAL sanitisation guidance to SECRET or TOP SECRET assets by assumption. NCSC's public storage-media guidance explicitly states that separate guidance should be followed for media that has stored HMG information classified SECRET or above, obtained through the organisation's normal NCSC point of contact.

Assets that have handled higher classifications should remain within the organisation's approved classified-material process. A general commercial ITAD workflow must not be represented as automatically sufficient.

Start with scope, ownership and authority

Define the organisation, site, room, racks, offices and asset classes in scope. Identify the asset owner, technical owner, security adviser or information-risk stakeholder, project manager and person authorised to approve irreversible actions.

Establish the intended disposition for each asset class: internal reuse, transfer, vendor return, external reuse where permitted, recycling or destruction. The required assurance and evidence depend on that destination.

Build an authoritative asset inventory

Record manufacturer, model, serial number, asset tag, hostname where appropriate, location, storage-media type, classification or handling context where authorised, operational role, intended disposition and exception status.

Compare physical discovery with the CMDB and asset register. Missing, duplicate and unexpected equipment should be investigated rather than silently removed from project totals.

Map dependencies before equipment becomes an ITAD asset

A server, storage array, switch or firewall should not be treated as ready for disposal merely because a project says it is obsolete. Confirm that applications, networks, backups, management systems and dependent services have been migrated or formally retired.

Infrastructure decommissioning and ITAD should be coordinated so that security controls do not create service outages and operational changes do not bypass asset accountability.

Electronic storage exists in more than disks

NCSC notes that practically every electronic item can contain electronic storage media. This includes computers, smartphones, routers, switches, IoT devices and many peripherals. NCSC also highlights examples of sensitive documents being recovered from decommissioned photocopiers and printers.

Discovery should therefore include embedded flash, removable cards, cache devices, management modules and other storage rather than focusing only on obvious HDDs and SSDs.

Endpoints and user devices

Laptops and desktops can retain citizen data, locally cached documents, browser data, authentication material, encryption keys and downloaded reports. Establish whether the device will be redeployed, transferred, resold where policy permits, recycled or destroyed before selecting the sanitisation outcome.

Removing the device from Active Directory, MDM or an asset register does not sanitise its local storage.

Servers and virtualisation hosts

Migrate workloads and validate replacement capacity before retiring physical servers or hypervisor hosts. Check cluster membership, shared datastores, backups, monitoring, licensing, management platforms and out-of-band controllers.

Identify local boot media, RAID members, flash modules and cache devices that require sanitisation or controlled destruction.

Storage arrays, SAN and NAS

Enterprise storage can contain data in active volumes, snapshots, replicas, cache, spare drives and failed members. Map hosts, LUNs, file shares, replication, zoning, multipathing and backup relationships before retirement.

Resolve retention requirements before deleting storage objects. Failed media should remain controlled until the approved sanitisation or destruction outcome has been completed.

Network and security appliances

Routers, switches, firewalls and VPN appliances may retain configuration, topology, credentials, certificates, private keys and security policy. They should first be safely withdrawn from production and then processed under the approved security procedure.

NCSC network-device lifecycle guidance recommends revoking certificates associated with a device before disposal, changing or revoking other credentials as appropriate and applying relevant media-sanitisation controls.

NIST SP 800-88 Rev. 2

NIST SP 800-88 Rev. 2 was published in September 2025 and supersedes Rev. 1. The current publication focuses on establishing an enterprise or agency media-sanitisation programme using appropriate techniques and controls based on information sensitivity.

Revision 2 strengthens sanitisation validation and trust in vendor implementations. Apart from cryptographic erase guidance, detailed technique and tool recipes have been replaced by recommendations to use current relevant standards such as IEEE 2883, NSA specifications or an organisationally approved standard.

Clear, Purge and Destroy decisions

The sanitisation policy should define the required outcome for each media class and disposition route. Clear, Purge and Destroy represent different approaches and assurance outcomes in the NIST framework.

Do not use these terms as generic labels without establishing what process was actually performed, whether it was supported for the media and how the result was validated.

NCSC sanitisation guidance for OFFICIAL data

NCSC's public storage-media guidance is designed around protections proportionate for OFFICIAL information. It advises organisations to understand their data, identify assets containing electronic storage media, record the media lifecycle and establish reuse and disposal policy.

It also states that media used for OFFICIAL data should not subsequently be reused for SECRET or above even after the public sanitisation processes have been followed.

Secure reuse where policy permits

Where policy and risk permit reuse, successful sanitisation can preserve useful equipment and residual value. Reuse should occur only after the required sanitisation has been completed and validated.

Record the asset identity, method, result and exception status. Unsupported or failed sanitisation should move the asset into a controlled exception route rather than being treated as successful.

Physical destruction

Physical destruction may be required where policy mandates it, media has failed, sanitisation cannot achieve the required assurance or the risk owner determines that reuse is inappropriate.

The destruction specification must match the applicable classification, threat model and organisational policy. Public OFFICIAL guidance should not be extrapolated into a destruction specification for SECRET or TOP SECRET material.

HDD, SSD and NVMe require media-aware handling

Magnetic disks and flash storage have different technical characteristics. SSD and NVMe controllers may use wear levelling, remapping and over-provisioning, while HDDs rely on magnetic storage.

Use supported device capabilities and approved standards rather than assuming that one overwrite or degaussing method applies universally.

Cryptographic erase

Cryptographic erase can be appropriate for correctly implemented encrypted media when the relevant cryptographic keys can be sanitised with sufficient assurance. NIST Rev. 2 expands its guidance on cryptographic erase, key sanitisation and externally managed keys.

Confirm where keys and copies reside and validate the outcome. Encryption being enabled is not, by itself, proof that disposal requirements have been met.

Failed and inaccessible media

A drive that fails to initialise or a device that no longer boots can still contain recoverable information. Failed media should remain within controlled custody and follow the approved exception route.

The same applies to failed RAID members, cache modules, flash cards and embedded storage removed from appliances.

Chain of custody

Chain of custody should begin when assets leave operational control, not when they arrive at a processor. Record asset identifiers, releasing and receiving parties, time/date, location and subsequent transfers.

For sensitive or valuable equipment, detailed handover records, containers and consignment references can provide stronger traceability.

Secure staging

Equipment awaiting collection remains part of the security boundary. Restrict access, separate processed from unprocessed assets and prevent uncontrolled storage in corridors, loading areas or other open locations.

NCSC decommissioning guidance advises that assets holding potentially sensitive data should not be stored insecurely while awaiting the next stage.

Transport and transfer

Transport arrangements should preserve accountability and meet the organisation's security requirements. Use documented handover, appropriate packaging, controlled custody and consignment records proportionate to the information and equipment.

For classified or specially marked material, follow the applicable government and local handling instructions rather than relying on a generic commercial collection process.

Supplier and contractor controls

The HMG Security Policy Framework states that partners in the wider public sector, suppliers and commercial partners handling HMG information are expected to protect it appropriately. Procurement guidance also requires appropriate protective controls in relevant government contracts.

ITAD due diligence can therefore include security capability, staff controls, certifications where required, subcontracting, downstream processors, environmental permissions, incident procedures and evidence quality.

Know where subcontracting occurs

A prime ITAD provider may use logistics companies, specialist destruction facilities, resale channels or downstream recyclers. Establish which activities are performed directly and which are subcontracted.

Contractual controls should define whether subcontracting is permitted, what security requirements flow down, how custody is recorded and how incidents or exceptions are escalated.

Certificates and destruction evidence

A certificate is useful only when it is linked to the service performed and the relevant assets or media. Serial-level evidence provides greater traceability than a generic statement covering an entire load.

NCSC decommissioning guidance recommends retaining evidence when external parties perform sensitive tasks and notes that certificates are a typical form of such evidence.

Serial-level reconciliation

Compare the authorised source inventory, physical collection manifest and final processing records. Investigate missing serials, duplicate records, unexpected assets and separated components.

Public-sector asset accountability should not be reduced to aggregate counts. Exceptions should remain visible until resolved and approved.

Audit-ready evidence pack

A project evidence pack can include authorised scope, source inventory, change references, collection manifests, chain-of-custody records, sanitisation results, destruction evidence, exception register, recovery/reuse records and final disposition evidence.

A reviewer should be able to select an individual in-scope asset and understand its authorised journey from service to final disposition.

Asset labels and ownership markings

Before external reuse or disposal, remove labels and markings where organisational policy requires it and where doing so does not undermine the evidence trail. NCSC specifically advises removing ownership labels or markings from certain non-data-bearing equipment before sale or disposal.

Do not remove identifiers prematurely if they are still required for reconciliation, custody or audit.

Reuse, recovery and public value

Where permitted, sanitised equipment may retain operational or resale value. Reuse can extend equipment life and reduce avoidable electronic waste.

Commercial recovery must remain subordinate to classification, security, contractual and asset-accountability requirements. No asset should enter resale or donation channels until formally released.

Environmental disposition

Equipment unsuitable for reuse should enter an appropriate recycling route. Maintain evidence proportionate to the project and applicable waste/environmental requirements.

Environmental compliance does not replace data sanitisation, and a recycling certificate alone does not prove that data-bearing media was securely processed.

Incident and exception handling

Define escalation for missing assets, broken custody, failed sanitisation, unexpected storage media, incorrect classification handling or uncertain destruction evidence.

Assign an owner, risk decision and resolution status. Where required, involve the organisation's security adviser, information assurance team or other authorised authority rather than resolving a security exception solely within the disposal supplier.

Update authoritative systems

After successful retirement, update the CMDB, asset register, monitoring, configuration management, IPAM/DNS, licences and support records as appropriate. Revoke credentials and certificates that no longer have a legitimate purpose.

NCSC recommends updating asset inventories after decommissioning and monitoring for unforeseen impacts.

A practical public-sector ITAD workflow

A controlled workflow is: authorise scope; identify classification and handling requirements; discover and reconcile assets; identify embedded storage; map technical dependencies; resolve retention requirements; define disposition; migrate services; validate replacements; decommission under change control; sanitise or quarantine media; establish custody; securely stage and transfer; process reuse, destruction or recycling; resolve exceptions; reconcile assets; issue evidence; update authoritative records; and obtain formal closure.

Pre-collection checklist

Confirm authorised scope, asset owner, technical owner, security stakeholder, classification/handling requirements, serial inventory, embedded storage, retention decisions, dependency migration, approved sanitisation standard, failed-media route, staging controls, custody method, transport requirements, supplier/subcontractor controls, evidence format and exception escalation.

Questions to ask a public-sector ITAD provider

Ask how assets are reconciled; how classification and handling instructions are incorporated into the project; which sanitisation standards are supported; how results are validated; how failed media is controlled; where assets are processed; which activities are subcontracted; how custody is maintained; what serial-level evidence is supplied; how incidents are escalated; and how final reuse or recycling is evidenced.

Common mistakes

Common mistakes include treating all government information as equivalent; confusing OFFICIAL-SENSITIVE with a separate classification; applying public OFFICIAL sanitisation guidance to SECRET or TOP SECRET; overlooking embedded storage; assuming failed drives contain no recoverable information; releasing assets before serial reconciliation; leaving equipment unsecured before collection; accepting generic certificates with no asset traceability; forgetting network-device credentials and certificates; and closing unresolved exceptions.

How Compritech approaches public-sector ITAD

Compritech combines infrastructure engineering with IT asset disposition. For appropriate projects, this allows technical decommissioning, sanitisation, asset reconciliation, chain of custody and final disposition to be managed as a connected workflow.

Services can include server and storage decommissioning, Cisco and Juniper infrastructure retirement, onsite engineering, secure sanitisation, physical destruction, serial-level reconciliation, asset recovery and responsible recycling. Requirements involving classified government information must follow the customer's applicable security policy and authorised guidance.

Final takeaway

Government and public-sector ITAD should be driven by information classification, asset accountability and evidence. OFFICIAL information still requires controlled handling, while SECRET and TOP SECRET require the specific enhanced controls and authorised guidance applicable to those classifications.

The strongest process begins before equipment leaves service and ends only when every in-scope asset has an authorised, reconciled and evidenced final disposition.

Related Compritech guides

Primary guidance used

Planning a public-sector IT asset disposal project?

Compritech provides engineer-led infrastructure decommissioning, ITAD, onsite support, secure data sanitisation and destruction, asset reconciliation and responsible final disposition across the UK, subject to the security requirements applicable to each engagement.

Discuss your projectIT asset disposal servicesSecure data destruction servicesOnsite data destruction