NIST 800-88 COMPLIANCE DOCUMENT
Certificates of destruction — validated per asset, per method
Enter IT assets by serial number with media type and sanitization method. Destructcert validates each entry against the NIST 800-88 matrix — a method that does not apply to that media is flagged, not accepted — and produces a numbered, audit-ready certificate with per-asset detail.
Asset data flows through NIST 800-88 validation and produces a numbered certificate with per-asset detail. The example above uses illustrative data.
01 / THE PRODUCT
A document that answers the auditor before they ask
An ITAD vendor's certificate of destruction is often a logo and a sentence. The standard asks for specifics: which sanitization category was used (Clear, Purge or Destroy), what technique, on what media type, who verified it, and when. An auditor asking "how do you know this drive was purged?" needs a document that answers each question — and Destructcert is designed to produce that document.
The tool lets you enter assets by serial number with make, media type and method, or paste a list. Destructcert validates each row against NIST 800-88 — a method that does not apply to that media type will be flagged, not accepted — compute summary counts, and produce a numbered certificate with per-asset detail.
- For compliance officers generating audit-ready records
- For ITAD operators documenting sanitization per asset
- For data center staff who need a standard-compliant document for their records
02 / HOW IT WORKS
Enter, validate, certify — on one page
Two intake modes give you control over how assets enter the system:
- Structured form — serial number, make/model, media type, sanitization method. One asset at a time with immediate validation feedback.
- Paste batch — comma- or tab-separated lines for bulk entry. Parse once, review flagged rows, remove what does not belong.
Every asset is checked against the NIST 800-88 matrix. A method that does not apply to that media type — for example, "Clear" on an SSD — is rejected with the standard citation. Invalid entries cannot enter the certificate.
When the asset list is ready, the tool generates a numbered certificate (CERT-001, CERT-002, … per session). Download as HTML or print to PDF from the browser.
03 / VALIDATION REFERENCE
NIST 800-88 Rev. 1 — which methods apply to which media
NIST Special Publication 800-88 Revision 1 defines three sanitization categories and specifies which are effective for each media type. Destructcert's validation implements this matrix exactly:
| Media | Clear | Purge | Destroy |
|---|---|---|---|
| HDD | ✓ | ✓ | ✓ |
| SSD | ✗ | ✓ | ✓ |
| Hybrid (SSHD) | ✗ | ✓ | ✓ |
| Tape | ✓ | ✓ | ✓ |
| Optical | ✗ | ✗ | ✓ |
| Flash / USB | ✗ | ✓ | ✓ |
Each method will be validated against this matrix at the time of entry. A combination that does not apply to the selected media type will be rejected with a clear error citing the standard. Only valid combinations will appear on the certificate.
04 / LIMITATIONS
What Destructcert will not do — stated plainly
The tool documents what the operator entered and does not itself verify that any drive was sanitized. The accuracy of each certificate depends entirely on the accuracy of the information provided.
These are design decisions, not missing features. A tool that validates against a standard and produces a document has no reason to store, send, or authenticate anything.
05 / BACKGROUND
Why NIST 800-88 matters for your certificate
NIST SP 800-88 Rev. 1 is the US government standard for media sanitization. It defines three categories — Clear (simple overwrite), Purge (specialised overwrite or degaussing for magnetic media, block-erase for flash), and Destroy (physical or chemical) — and specifies which methods are effective for each media type. An SSD cannot be "Cleared" by overwrite alone; a tape can be Purged by degaussing; an optical disc can only be Destroyed.
A certificate that does not name the method used, and cannot show that the method applied to the media in question, leaves a gap the auditor will fill with a follow-up request. Destructcert's per-asset validation closes that gap: every row on the certificate has been checked against the standard before generation.
06 / THE OUTPUT
What the certificate looks like
Every certificate is numbered sequentially within your session (CERT-001, CERT-002, ...). It carries the generation date, a standard citation, a per-asset table with serial number, make, media type and method, and a footer disclosing that Destructcert documents the operator's entries and does not verify the sanitization itself. An example of the output format is shown below.
This certificate documents the sanitization of the following assets, recorded per NIST SP 800-88 Rev. 1. Each asset is listed with its sanitization category and method as entered by the operator.
| # | Serial Number | Make / Model | Media Type | Method |
|---|---|---|---|---|
| 1 | SN-DL-3847 | Dell PowerEdge R740 | HDD | Purge |
| 2 | SN-HP-2911 | HP ProLiant DL380 | SSD | Destroy |
| 3 | SN-IB-5632 | IBM TS1150 | Tape | Clear |