Resources · Compliance
Disposal requirements, by the regulation you are actually being asked about
Buyers arrive at this subject holding a regulation, not an industry. These pages take each one, quote what it says from the primary source, and separate your legal obligation from the evidence a disposal provider can give you.
The thing worth knowing first
No US regulator certifies a disposal vendor
It is worth establishing this before anything else, because it reframes every vendor claim you will read on this subject — ours included. There is no federal certification, approval or accreditation of IT asset disposition or data destruction providers. Not under HIPAA, not under GLBA, not under FERPA, and not under the FACTA Disposal Rule. PCI DSS is not federal law at all.
The consistent architecture is the opposite: the regulated organization holds a non-delegable duty and must exercise its own diligence over the vendors it uses. HHS says so explicitly. The FTC writes the duty into the rule. EPA encourages third-party certification and issues none.
Where federal regulation comes closest to touching vendor credentials at all is the FACTA Disposal Rule, which lists requiring that the disposal company be certified by a recognized trade association or similar third party as one example of reasonable diligence — alongside reviewing an independent audit, taking references, and evaluating the provider's own security policies. One method among several, discharging your duty. It confers nothing on the vendor.
Which is why these pages are built the way they are. A certification we hold is evidence you can weigh. It is not a status that transfers, and any provider telling you otherwise has told you something useful about the rest of their claims.
The regulations
Five requirements, each cited to its primary source
Every page follows the same five sections: what the rule says, what it does not say, what an auditor asks for, what our documentation provides, and what stays your obligation.
- 45 CFR 164.310(d)(2)
HIPAA
Two Required specifications — disposal and media re-use — plus the breach safe harbour that makes sanitization to NIST 800-88 commercially valuable rather than merely diligent.
- v4.0.1 · Req. 9.4.6 and 9.4.7
PCI DSS
Where requirement 9.8 went in the renumbering, what 9.4.6 says verbatim, and why a contractual standard behaves differently from a law.
- 16 CFR 314.4(c)(6)
GLBA Safeguards Rule
The two-year disposal provision, the three exceptions usually left out of it, and the service-provider oversight duty that stays yours.
- 34 CFR Part 99
FERPA
What FERPA actually says about destroying education records — which is not what district procurement usually assumes — and where the real obligation comes from.
- Trust Services Criterion CC6.5
SOC 2
An attestation rather than a certification, the criterion that actually covers asset disposal, and what a vendor's report proves about your position.
If your auditor is working from something not listed here, send us the request itself.
Ask us what we can evidenceThe shared technical basis
Where NIST 800-88 fits into all five
Four of these five regulations name no sanitization method at all, and the fifth is prescriptive only for paper. What fills that gap in practice is NIST SP 800-88, which HHS references directly in its breach guidance and which has become the common vocabulary — Clear, Purge and Destroy — that auditors across all five frameworks now expect to see used correctly.
One currency note, because it is the sort of detail a technical reviewer will catch: NIST published Revision 2 as final in September 2025, superseding Revision 1, which is now withdrawn. HHS guidance still links the Revision 1 document, so you will encounter both citations in the wild. The practical position is to work to the current revision and to cite NIST SP 800-88 without a revision number when describing what HHS points to.
FAQ
Questions about compliance and certification
Is any IT asset disposition vendor certified by a US federal regulator?
Then what is R2v3 worth?
Why does every page here have a section on what the rule does not say?
Do you have a page for our regulation?
Send us your auditor's request.
Tell us what has been asked for and we will tell you which of it we can evidence — and which of it is yours to produce.