The batch list travels with the work
A table inside the first task holds every asset tag, serial and route. Sanitisation, certification and reconciliation all work against that table, with the vendor’s certificates attached alongside.
IT asset disposal (ITAD) is the point where a laptop, phone, server, storage array or switch leaves your control for good. This free ITAD checklist is for IT operations teams and the security or data protection staff who have to prove that no data left with the hardware. It takes a disposal batch through quarantine and chain of custody, sanitisation matched to each media type under NIST SP 800-88, verification, vendor checks and the final route: reuse, resale, lease return or recycling. It ends with a serial-by-serial match of certificates against what you sent, and an updated asset register.
Three processes touch a device at the end of its life, and they are easy to blur. Server decommissioning retires a service: dependencies, final backup, DNS, monitoring, firewall rules and the change record. What it leaves behind is a box of hardware, and that box is the input to this checklist. IT asset management runs underneath both as the record of what you own, who holds it and what it costs. Disposal is where that record ends, with a date, a route and a certificate reference.
They fail differently. A decommissioning mistake causes an outage; a disposal mistake causes a data breach. Under UK GDPR the security principle and Article 32 apply until the data is gone, and the ICO’s data protection audit framework looks for a log of devices awaiting destruction, management sign-off before disposal, and a named person who checks destruction certificates against what was sent.
Examples: dependency discovery, scream test, removing DNS records, monitoring and backup jobs.
Trigger: an approved change request.
Output: a closed change and a powered-off server.
Hands off: the hardware, to this checklist.
Examples: custody log, sanitisation, certificates, vendor checks, recycling.
Trigger: an approved disposal batch.
Output: a certificate per device and a closed register record.
Hands off: register updates, to IT asset management.
Seven phases take a batch from approval to a reconciled certificate. Sanitisation tasks appear only for the media types in the batch, and Phase 6 shows only the routes you selected.
Run one checklist per disposal batch, not per device. The batch list in the first task is the reference for every later check.
Each media task is shown only when the batch contains that media type. NIST SP 800-88 Rev. 2 no longer lists techniques per device, so follow IEEE 2883 or your own approved standard for the exact command.
The first three tasks appear only when the vendor is new or its annual review is due. Otherwise the checklist goes straight to handover.
Each task is shown only when at least one asset in the batch is on that route, based on the routes set in Phase 1.
Assign the first task to someone who did not handle the devices.
NIST SP 800-88 Rev. 2, published in September 2025, supersedes the 2014 Rev. 1 but keeps its three methods: Clear, Purge and Destroy. What changed is everything around them. The device-by-device technique tables are gone in favour of IEEE 2883 or an organisation-approved standard, multi-pass overwriting is described as unnecessary, degaussing is narrowed, and a validation decision now follows every sanitisation. Use the table as a starting point for your own standard.
| Media | Reuse, resale or lease return | Not reused | Watch for |
|---|---|---|---|
| Hard disk drives | Purge with the drive’s sanitise command; Clear by overwrite only for low-sensitivity internal reuse | Destroy | Degaussing needs a degausser matched to the drive and never counts as Destroy |
| SSDs and NVMe drives | Purge by block erase or cryptographic erase | Destroy | Overwriting misses spare and over-provisioned cells; degaussing does nothing to flash |
| Self-encrypting drives | Purge by cryptographic erase | Destroy | Only as strong as the drive’s encryption and key handling, which Rev. 2 sets conditions for |
| Phones, tablets, printers, network kit | Clear by factory reset through the device interface | Destroy | Release management and anti-theft locks first, and remove cards |
| Failed or obsolete drives | Not suitable | Destroy | Rev. 2 advises against shredding or pulverising for anything above the lowest data categories |
For the vendor, two certifications matter most. R2v3, run by SERI, covers the recycler and its downstream vendors; for data work, look for a facility certified to Appendix B, which SERI describes as enhanced data destruction with tracking to serial-number level. e-Stewards, run by the Basel Action Network, requires compliance with the Basel Convention on cross-border shipments of hazardous waste and uses NAID AAA certification for data security. Check either certificate in the issuing body’s directory and read its scope.
In the UK, the WEEE Regulations 2013 and the waste duty of care reach business users as well as producers: store waste equipment safely, use a registered carrier and complete a waste transfer note when it leaves your site. Across the EU, Article 13 of the WEEE Directive 2012/19/EU sets the same financing split: producers pay for business equipment placed on the market after 13 August 2005, and users pay for older equipment unless it is being replaced.
A table inside the first task holds every asset tag, serial and route. Sanitisation, certification and reconciliation all work against that table, with the vendor’s certificates attached alongside.
Yes/no fields in Phase 1 record which media types and routes the batch includes. Conditional logic hides the SSD steps for a batch of phones and the lease-return steps when nothing is leased.
Keep approved ITAD vendors in a data set with certification, scope and expiry dates. Choosing the vendor fills them into Phase 5, and the activity trail records who handled each batch.
Most laptops and phones reach this checklist through a leaver. CheckFlow’s IT offboarding software covers access removal and device recovery, so each device arrives in quarantine with a named previous user.
Servers and storage arrive from the Server Decommissioning Checklist, which retires the service, takes the final backup and releases the hardware. For an ISMS, this checklist is the evidence for ISO/IEC 27001:2022 Annex A 7.14, secure disposal or re-use of equipment.
ITAD is the controlled process for retiring physical IT equipment: laptops, phones, servers, storage and network devices. It covers securing the equipment, sanitising or destroying its data, documenting that with certificates, and then reusing, reselling, returning or recycling the hardware. It has to prove two things: no data left with the device, and the device was handled lawfully.
They are the three sanitisation methods in NIST SP 800-88. Clear uses the device’s normal interface, such as an overwrite or a factory reset, and protects against simple recovery. Purge uses techniques such as a drive’s sanitise command or cryptographic erase, so recovery is infeasible even in a laboratory, and the device can usually still be used. Destroy achieves the same outcome by physically destroying the media. NIST recommends Purge over Clear wherever it is possible, and notes that Destroy is often the simplest option when the media will not be reused.
No. Rev. 2 was published in September 2025 and supersedes Rev. 1 from 2014. The biggest practical change is that Rev. 2 no longer tells you which technique to use for each device type. It asks organisations to run a media sanitisation programme and to follow IEEE 2883, NSA specifications or their own approved standard for techniques.
Not necessarily. A working SSD can be purged with the drive’s own sanitise command, using block erase or cryptographic erase, and then reused or resold. Hard-disk habits do not work: overwriting leaves data in spare cells the host cannot address, and degaussing has no effect on flash. Destroy an SSD that has failed or will not complete a sanitise command.
One record per device, not a batch total. NIST’s sample certificate lists manufacturer, model, serial number, media type, sanitisation method and technique, tool and version, verification method, and the verifier’s name, title, date and signature. Ask your vendor for that shape, then match every serial to what you sent.
Both certify electronics recyclers and ITAD providers. R2v3 is run by SERI; its core requirements cover the facility and its downstream vendors, and optional appendices add specialisms such as data sanitisation (Appendix B), test and repair (Appendix C) and materials recovery (Appendix E). e-Stewards is run by the Basel Action Network, requires compliance with the Basel Convention on hazardous waste shipments and uses NAID AAA certification for data security. Either works if the certificate is current and its scope covers the work you are sending.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.