NIST 800-88 Data Wipe Certificates for Company Laptops
What a data wipe certificate is, what it should contain, and how CISOs and Data Protection Officers in India can use it as audit evidence under the DPDP Act 2023.
Why a certificate matters
When a company laptop leaves your organisation — returned at the end of a rental, sold in a buyback or retired — the data on it has to be destroyed. In an audit, what counts is the record: a certificate that shows a specific device was sanitised by a specific method on a specific date. Without it, your position rests on trust alone.
What Techvity does: every returned or bought-back device is wiped to NIST SP 800-88 before it is reused or resold, and a per-device certificate is available on request.
NIST SP 800-88: the three levels
- Clear — logical techniques through the device's normal read/write interface. Suitable for media that stays inside the same organisation.
- Purge — techniques that make recovery infeasible even with laboratory methods, such as cryptographic erase, ATA Secure Erase, NVMe Sanitize and, for magnetic media, degaussing.
- Destroy — physical destruction so the media can no longer store data: shredding, disintegration, incineration or pulverisation.
The right level depends on the media type, how sensitive the data is, and whether the device will be reused, sold or scrapped. For laptops leaving your organisation, Purge is the usual choice, with Destroy for damaged drives or highly sensitive data.
What a good certificate contains
- Customer name and, for companies, GSTIN
- Device make, model and serial number
- Your asset tag, if you supplied one
- Storage type (hard disk, SATA SSD, NVMe SSD, eMMC)
- NIST SP 800-88 level (Clear, Purge or Destroy)
- Method or tool used
- Result of the wipe
- Date
- A unique certificate reference
How to use the certificate in your audit pack
- Data Protection Officer: file the certificate against the device's record as evidence that personal data on it was erased.
- CISO and IT team: close the device in your asset register using the serial number on the certificate.
- Internal or external auditor: sample certificates against the asset register and the vendor's invoices.
What the certificate does not do
A certificate is evidence of a sanitisation event on a specific device. It does not satisfy every obligation under the DPDP Act 2023 on its own: the Data Fiduciary still needs notice records, consent records where applicable, retention rules and a breach response plan. It does close an important gap — the moment data leaves your control.
Frequently asked questions
What is NIST SP 800-88 and why does Techvity use it?
NIST Special Publication 800-88 ('Guidelines for Media Sanitization') is published by the U.S. National Institute of Standards and Technology and is widely used as the reference for wiping storage before reuse or disposal. It defines three levels — Clear, Purge and Destroy — and the right method for each media type. Techvity wipes every returned or bought-back device to it because auditors recognise it.
Clear, Purge, Destroy: when is each used?
Clear overwrites the storage through the normal interface; it suits media that stays inside the same organisation. Purge uses media-specific commands such as cryptographic erase, ATA Secure Erase or NVMe Sanitize, which resist laboratory recovery; it is the usual choice for laptops leaving your organisation. Destroy physically destroys the media and is used when a drive is damaged or the data is highly sensitive.
What should a certificate of data destruction contain?
At minimum: the device make, model and serial number, the storage type, the NIST SP 800-88 level (Clear, Purge or Destroy), the method or tool used, the result, the date, and a unique certificate reference. Ask any vendor for a sample and check it against your audit requirements before you sign.
Are SSDs wiped differently from hard disks?
Yes. Because SSDs move data around internally, overwriting from the operating system cannot reach every block. NIST SP 800-88 points to cryptographic erase or the drive's own sanitize command for SSDs, and to physical destruction when those cannot be verified. Multi-pass overwrites add nothing on modern drives.
Does Techvity issue a certificate for every device?
On request, yes. Every returned or bought-back device is wiped to NIST SP 800-88 before reuse or resale; ask for per-device certificates when you place your order or return laptops, and ask for a sample during onboarding.
References
- NIST Special Publication 800-88 — "Guidelines for Media Sanitization." National Institute of Standards and Technology, U.S. Department of Commerce.
- Digital Personal Data Protection Act, 2023 — Government of India.
- E-Waste (Management) Rules, 2022 — Ministry of Environment, Forest and Climate Change.
