Data destruction according to NIST SP 800-88
Erasure or destruction, with a certificate per device
Formatting does not remove data. Under the GDPR your organisation remains responsible until the data has been demonstrably destroyed, and from 2026 NIS2 also requires that proof. That is why we erase or destroy every storage medium according to NIST SP 800-88 and record this per serial number.
030 123 45 67
Two routes, one certificate per device
If the device can be reused, we erase it using software (Clear or Purge) with verification of all sectors. If that is not possible, or not preferred, we destroy it physically (Destroy) using a shredder or degausser according to DIN 66399. Both routes end in the same erasure log and certificate.
sectors verified after erasure
fragment size when shredding, DIN 66399 H5 (example)
certificate per device, within 2 working days (example)

Which method for which device
NIST SP 800-88 links the method to the medium. On the left the software-based route (device remains usable), on the right the physical route (device is destroyed). You choose per batch, we record per device what was applied.
- HDD (magnetic)Clear · Purge
Overwriting, followed by verification of all sectors
- SSD / NVMePurge
Cryptographic erasure or the device's own sanitize command
- Laptop / desktopClear · Purge
Device erased inside the equipment, equipment remains usable
- Smartphone / tabletPurge
Factory reset with encryption and verification
- USB / SD / flashClear
Overwriting where the controller allows it
- HDD (magnetic)Destroy
Degaussing and shredding
- SSD / NVMeDestroy
Shredding to ≤ 6 mm, degaussing does not work on flash
- Tape / LTODestroy
Degaussing and shredding
- Smartphone / tabletDestroy
Shredding including memory chip
- Device with failed verificationDestroy
Automatically routed to physical destruction
Data demonstrably gone, without hassle?
Send a list of devices or storage media. You will receive a proposal within one working day, including erasure at your location.
- Method per device according to NIST SP 800-88
- Certificate per serial number
- On-site possible
How data destruction works at RQNX IT
Every step is recorded in the erasure log and can be traced per serial number in your dossier.

1
Registration
Serial number, model and device recorded on arrival or at your site

2
Erasure or destruction
Method per device according to NIST SP 800-88, verified

3
Certificate
Erasure log and certificate per device: method, verification, date, signature

This is what we process, at our site or yours
From a handful of loose drives to a complete data centre. For sensitive environments we bring an erasure station or shredder to your site, with the same registration and the same certificate.
- Laptops, desktops, servers and storage (HDD, SSD, NVMe)
- Smartphones, tablets, USB sticks, SD cards, tapes
- Network equipment, printers and copiers with storage
- On-site: erasure or shredding at your premises
- Sealed transport with a transfer receipt
- Healthcare (NEN 7510) and government (BIO): tailored reporting
Questions about data destruction
What is the difference between Clear, Purge and Destroy?
Clear overwrites the data using software, Purge uses the device's own erasure function (including cryptographic erasure for SSDs), Destroy destroys the device physically. NIST SP 800-88 links the method to the medium and the risk.
Isn't formatting or a factory reset enough?
No. Formatting only removes the file references, the data can be recovered with forensic tools. For GDPR proof, a genuine erasure with verification or physical destruction is required.
Can an SSD be safely erased?
Yes, via Purge (cryptographic erasure or sanitize command) with verification. If verification fails, the SSD automatically goes into the physical route.
Does degaussing also work on SSDs?
No. Degaussing only works on magnetic media such as HDDs and tapes. Flash memory is shredded.
Can you erase or shred at our location?
Yes. For sensitive environments we bring an erasure station or shredder to you, with the same registration and the same certificate per device.
What is on the certificate?
Serial number, model, device, method (for example NIST SP 800-88 Purge), verification, date and signature. Without registration per serial number a certificate is not usable in an audit, which is why we register everything.
What does NIS2 mean for decommissioned equipment?
Organisations that fall under NIS2 must be able to demonstrate how they handle data on decommissioned devices. The dossier per assignment (registration, erasure log, certificates) is that proof.
How quickly do I receive the certificate?
After processing you receive the certificate per device and the summary report within a few working days (example value: 2 working days).
Does the equipment remain usable?
With software-based erasure, yes: that equipment goes on to repair or remarketing and generates residual value. Not with physical destruction.
What happens between collection and processing?
Everything stays under chain-of-custody: sealed transport, transfer receipt at collection, registration on arrival, a secured processing area.
Request a quote for data destruction, or request a free valuation first. We respond within one working day. Other services: Recycling, Repair, Remarketing.
Email us
Response within one working day
info@rqnx-it.com
Visiting address (example)
Mon to Fri, 8.00 to 17.30
Industrieweg 12, 3542 AD Utrecht (example address)
Call us
Prefer to talk directly?
030 123 45 67 (example number)
Request a quote or collection
Send a list of device types and quantities, or describe the situation.