IT Asset Disposal Services: What You Are Buying and What You Are Not

What a disposal vendor actually provides, why certification is the whole product, and the difference between wiping a device and disposing of one.

Rachel Kim Rachel Kim • • 25 min read

TL;DR

  • IT asset disposal is the regulated end of the device lifecycle: collecting retired hardware, destroying the data on it, and recycling or reselling what remains.
  • If you retire four laptops a year and can wipe them yourself, you do not need a disposal vendor. You need a documented wipe and a recycling drop-off.
  • What you are actually buying is evidence. The physical work is commodity; the certificate that ties a destruction to a serial number is the product.
  • Wiping a device and disposing of it are different services. Plenty of platforms do the first and none of them certify the second.
  • Resale value is real and it is not the reason to choose a vendor. A good certificate on a worthless device beats a good price on an undocumented one.
  • Ask for a sample certificate before you ask for a price. It tells you more about the vendor than the quote will.

The Certificate That Did Not Mention Any Devices

A company retired 180 machines after a hardware refresh. They engaged a disposal vendor, the pallets were collected, and eleven days later a certificate arrived. Everybody filed it and moved on.

Fourteen months later a security review asked a specific question: show me that the data on asset tag HL-0442 was destroyed. The certificate said that 180 units had been processed and data destroyed to a recognised standard on a given date. It did not list a single serial number. There was no way to connect it to HL-0442, or to any other individual device, and the asset register still showed 180 rows marked "sent for disposal" with no closure evidence against any of them.

Nothing had gone wrong physically. The devices really were destroyed, the vendor was reputable, and the work was done properly. What the company had bought was a disposal service, and what it needed was an evidence trail, and those are not the same purchase even though the same vendor sells both. The difference is one line in a statement of work asking for serialised reporting, and almost nobody asks for it.

So the useful question is not which vendor disposes of hardware. It is what arrives afterwards, and whether it answers the question somebody will eventually ask.

When You Don't Actually Need a Disposal Vendor

When the manual way is genuinely fine

Under about ten devices a year, all in one country, all wipeable by you. Encrypt, wipe, record the wipe with a date and a method against the asset, and take the hardware to a licensed electrical recycler. That is a complete and defensible process and it costs almost nothing. Buying a disposal contract for this volume adds procurement overhead and no evidence you could not generate yourself.

When friction starts appearing

The first signal is usually storage rather than compliance. Retired machines accumulate because no single batch is large enough to justify arranging anything, and the cupboard becomes the de facto disposal process. That is the point at which the cost of doing nothing starts exceeding the cost of a quarterly collection.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

When it becomes a liability

The point at which somebody asks for evidence you cannot produce, which is exactly the opening example. It is also the point at which devices in storage become the exposure: an unwiped machine in your own cupboard carries the same data risk as one in a skip, it just has a lower probability of being read.

The edge case that forces it

A refresh, a site closure or an acquisition that produces a large batch at once. Volume changes the calculation entirely, because a hundred devices is both worth something on resale and genuinely difficult to process in-house, and it is the one scenario where a vendor is clearly the right answer rather than a convenience.

Five Questions People Ask First

"What does ITAD actually mean?" IT asset disposition, which covers collection, data destruction, and then either refurbishment and resale or recycling. The term is used loosely and that looseness causes most of the confusion in this category, because a platform that collects devices and wipes them will reasonably describe itself as handling disposition while providing none of the certification that the word implies to an auditor.

"Is wiping the same as disposal?" No, and conflating them is the single most expensive mistake here. Wiping is a technical operation you can perform yourself on most modern hardware. Disposal is a chain of custody plus an evidenced destruction plus a documented downstream outcome. A device you wiped and then put in a cupboard has been wiped and not disposed of.

"Will we get paid for the hardware?" Sometimes, and you should treat any resale value as a rebate rather than a reason to choose. Three-year-old business laptops in working order with no activation locks do have a market. Mixed pallets of unknown age with locked devices and missing components generally do not, and a vendor quoting an attractive per-unit return before seeing the fleet is quoting a best case.

"How long should we keep the certificate?" As long as you would need to answer a question about the data that was on the device, which is a question for your own retention policy and, where it touches regulated data, for advice rather than a rule of thumb. What matters practically is that it is stored against the asset record rather than in a folder, because a certificate nobody can connect to a device is the opening example.

"Can our existing device platform do this?" It can almost certainly collect and wipe, and it almost certainly cannot certify. Check specifically whether the vendor holds a recognised disposition certification themselves or subcontracts to somebody who does, and ask who appears on the certificate. A platform that subcontracts is fine; a platform that is vague about it is not.

What You Are Actually Buying

Four things, in descending order of how much they should influence the decision.

Evidence. A serialised record tying each device to a destruction method and a date, issued by an entity you can name. This is the product. Everything else is logistics.

Chain of custody. A documented handover at each transfer, so there is no window in which devices existed and nobody was accountable. The weak point is almost always collection, where a driver takes a pallet and leaves a signature that names a count rather than a set of serials.

Downstream assurance. What happens after the vendor. Material that is resold, recycled or exported passes to another party, and your exposure does not stop at your vendor's gate. Ask how far down the chain they can evidence, because "we use an approved partner" is an answer about their contract rather than about your risk.

Value recovery. Real, worth having, and the thing most quotes lead with. It belongs fourth because optimising for it reliably produces a vendor selection you regret when somebody asks for evidence.

The Three Kinds of Vendor

Certified disposition specialists

Companies whose primary business is processing retired IT at scale, holding recognised certifications, with their own facilities.

Right when you have volume, when evidence matters, or when the material includes anything beyond standard laptops. They fail on small batches, where minimum charges make them uneconomic, and they are generally not interested in collecting three devices from an employee's flat.

Lifecycle platforms that also handle retirement

Device platforms that manage procurement, delivery and recovery, and that wipe devices and route end-of-life hardware onward.

Right when your actual problem is getting devices back from distributed people, which is a genuinely hard logistics problem that disposal specialists do not solve. They fail at the certification step, because wiping is not certifying, and the honest ones say so.

Local electrical recyclers

Licensed waste handlers who will take hardware and recycle it.

Right for small volumes of genuinely dead equipment that you have already wiped and recorded yourself. They fail on data: most will not perform or evidence destruction, so the data obligation is entirely yours to have closed beforehand.

Chain of Custody, and Where It Actually Breaks

Chain of custody sounds like a formality and it is the part most likely to have a hole in it. The hole is almost always at collection.

A driver arrives, loads a pallet, and signs a docket that says a number of units. From that moment until the devices are booked into a facility, your evidence consists of a count. If three machines went missing in transit, nothing in that document would reveal it, and nothing afterwards could prove which three.

The fix is to make the handover serialised rather than numeric. Produce a list of serials for the batch, have the collecting party sign against the list rather than a total, and keep your copy. It adds about twenty minutes per collection and it is the difference between a chain and a gap.

Three other points worth checking. Who holds the devices between collection and processing, because material frequently sits at a depot for days and that custody belongs to somebody. Whether the facility reconciles on receipt, meaning they count and serialise what arrived and tell you if it differs from what you sent, which good vendors do unprompted and will confirm if asked. And what happens to a discrepancy, because the answer reveals whether anybody is actually checking.

The internal half matters too and is usually weaker than the vendor half. Devices move from a user, to a desk, to a storeroom, to a pallet, often over weeks, with no record of any transfer. By the time the vendor's chain begins, your own has already had four unrecorded handovers. Recording who received a device and when, at the moment it arrives back, closes most of that and costs one field.

Preparing a Batch, Which Affects Evidence and Value Equally

The work you do before collection determines both what the certificate can say and what the hardware is worth. It is an afternoon for a batch of a hundred and it is routinely skipped.

Preparation step Effect on evidence Effect on value
Capture every serial into a list Makes serialised certification possible at all Lets you challenge a per-unit quote line by line
Remove activation and management locks None directly Large. A locked device is frequently scrap to a refurbisher
Wipe on arrival, record date and method Closes the obligation before the device leaves you Neutral, and it removes the urgency from the vendor choice
Note missing components and damage Prevents disputes about what you sent Sets realistic expectations rather than a revised quote later
Separate by device type and age None Mixed pallets are quoted at the weakest item
Pull the battery health or cycle count None Batteries are the most common reason a machine is downgraded

The activation lock row is the one that costs real money. A device still enrolled to an organisation or tied to an account cannot be reset by a refurbisher, which moves it from resale to recycling and removes essentially all of its value. Releasing devices from management before they leave is a five-minute job per batch in most consoles and nobody remembers to do it.

The wipe row is the one that changes your negotiating position. If the data obligation is already closed, disposal becomes a logistics decision you can take your time over. If it is open, you are under pressure, and pressure is a poor basis for choosing a vendor on evidence quality.

Closing the Register Properly

The disposal is not finished when the van leaves. It is finished when the asset record says so, with something behind it.

Each row needs three closures, not one. The physical outcome, meaning what happened to the hardware. The data outcome, meaning the wipe or destruction with a date and method. And the financial outcome, meaning whether it was written off or produced a receipt. Most registers have a single status field that collapses all three into "disposed", which is why the opening example could not answer a question about one machine.

Store the certificate reference against the row, not just in a folder. A document identifier and a link is enough. The test is whether somebody starting from a serial number can reach the evidence in two clicks, because that is the shape every future question takes.

Reconcile what you sent against what the certificate lists. This is the step that catches the real problems, and it takes ten minutes. If you sent 180 and the certificate covers 176, you want to know now rather than in fourteen months, while the vendor still has the intake records and the people who handled the batch are still there to ask.

And keep the batch list. Your own pre-collection serial list, the signed handover, and the certificate together form a complete chain. Any one of them alone is partial, and the first is the one companies throw away because it feels like working paper. Keep it with the other two and the set answers almost any question somebody can ask about a given machine.

How to Choose: Five Questions Before You Talk to Any Vendor

Ask for a sample certificate first. Before volumes, before pricing. If it does not carry serial numbers, a method and an issuing entity, you have learned the most important thing about that vendor in the first five minutes.

Who holds the certification, and is it them? Subcontracting is normal and fine. Ambiguity about who actually processes the material is the warning sign, because your evidence chain ends wherever their clarity does.

What happens to devices they cannot resell? The answer tells you whether they have a real downstream process or are a broker. Ask for the next party by name.

How do they handle collection from individuals? If your retired devices are with people rather than on a pallet, this is the question that decides whether a specialist is usable at all, and for many of them the answer is that they are not.

What is the minimum? Minimum charges, minimum volumes and minimum collection sizes are where small companies discover this category is not built for them. Establish it before investing time in a comparison.

The Options

A note on pricing. Disposal is quoted on volume, material mix, collection geography and the resale value of what you are sending, which genuinely cannot be published as a list price, so expect quotes rather than figures. What can be compared before any quote is the evidence each one produces.

A certified disposition specialist

Best for: any batch above roughly fifty devices, and any situation where somebody will later ask for evidence.

Why companies choose them: this is the only category that produces serialised certification from an entity holding a recognised standard, with their own processing facility and a documented downstream chain. For the opening example, this is the fix.

Where they struggle: minimum charges make small batches uneconomic, and almost none of them will collect individual devices from employees' homes. They are built around pallets, not people.

Blancco

Best for: teams that want to perform certified erasure themselves and produce their own tamper-evident reports.

Why companies choose it: it addresses the evidence problem directly at the point of erasure rather than afterwards, which suits companies who keep hardware in-house or resell independently.

Where it struggles: it publishes no price and is quote-based, confirmed on its own site 9 October 2026. It is erasure software rather than a disposal service, so collection, recycling and the physical downstream remain yours to arrange.

Lifecycle platforms with retirement built in

Workwize, Deel IT, Firstbase, GroWrk and allwhere all recover devices from distributed staff and route end-of-life hardware onward. None publishes a price. Their strength is the collection problem that specialists will not touch; their limit is that the certification, where it exists, comes from a partner further down the chain, so ask who issues the certificate.

RemoAsset

Disclosure: RemoAsset is owned by the same people who publish HROpsLab. It appears here because it competes in this category and is assessed against the same criteria as everything else on this page, with its limitations stated in the same detail.

Best for: the collection half of the problem, meaning getting retired devices back from people in places you have no office, and wiping them on arrival.

Why companies choose it: retirement is triggered by the same platform that handled procurement and delivery, so the device has a known serial and a known location before anybody tries to collect it, and devices can be wiped and held in region rather than shipped to a central point first.

Where it struggles, and it is the relevant limit on this page: it is not a certified IT asset disposition vendor. It wipes devices; it does not issue disposition certification, and bulk end-of-life processing with certification is a different purchase from a different kind of supplier. It also publishes no price and requires a demo. For the question this article is about, it belongs alongside a certified specialist rather than instead of one.

A local licensed recycler

Best for: small volumes of dead hardware you have already wiped and documented.

Where it struggles: generally will not evidence data destruction, so this route only works if your own wipe record is solid.

The Comparison

Option Collects from individuals Wipes Issues serialised certification Publishes a price
Certified disposition specialist Rarely Yes Yes, this is the product No, quoted on volume and mix
Blancco No Yes, certified erasure Erasure reports, not disposition No, quote-based
Lifecycle platforms Yes Yes Via a partner, ask who No
RemoAsset Yes Yes No, not a certified ITAD No, demo required
Local licensed recycler No Usually not No Varies, often per weight

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
Handful of devices a year, one country Under 10 Wipe yourself, licensed recycler Nothing structural Document the wipe properly. No vendor needed
Retired devices piling up in a cupboard Any Quarterly collection No batch is big enough to act on Set a calendar trigger rather than a volume one
Refresh or site closure, large batch 50 plus Certified disposition specialist Volume and evidence together A specialist, with serialised reporting in the statement of work
Devices are with people, not on a pallet Any Lifecycle platform for collection Specialists will not collect from homes Platform to collect and wipe, specialist to certify
Somebody has asked for evidence you lack Any Fix the certificate, then the process Certificates not tied to serials Ask your vendor to reissue serialised, then change the SOW
Regulated or sensitive data on the devices Any Certified erasure plus certified disposal Assurance depth, not logistics Certified erasure at source, and take advice on retention
Want maximum resale value 50 plus Specialist with refurbishment Optimising on price loses the evidence Treat resale as a rebate. Choose on the certificate

The Four Destruction Methods, and When Each Applies

Certificates name a method per device, which is only useful if you know what the names mean and which ones are appropriate for what you sent.

Overwrite. Writing patterns across the whole drive so the previous contents cannot be recovered. Appropriate for conventional hard drives, slow on large capacities, and the method most people picture when they think of wiping. Its weakness on modern solid-state drives is that wear levelling means the controller may not expose every physical cell to the overwrite, so blocks can survive.

Cryptographic erase. Destroying the encryption key so the encrypted contents become unreadable, which on a self-encrypting drive takes seconds regardless of capacity. This is the right method for most modern laptops and it depends entirely on the device having been encrypted in the first place, which is the argument for enforcing encryption at deployment rather than at disposal.

Degaussing. Applying a magnetic field strong enough to destroy the data and usually the drive. Applies to magnetic media only and does nothing whatever to a solid-state drive, which is a genuine and recurring error: a degaussed SSD is an intact SSD.

Physical destruction. Shredding or disintegrating the drive. The most assured and the most final, with the obvious cost that there is no resale value afterwards. Appropriate where the data warrants it or where a drive has failed in a way that prevents any software method from running.

Two practical consequences. A failed drive that will not power on cannot be overwritten or cryptographically erased, so it must be physically destroyed, and a batch will always contain a few of these. And a certificate listing a single method for every device in a mixed batch is describing a process that did not happen, which is worth querying.

Where the data is regulated or particularly sensitive, which method is sufficient is a question for advice rather than for a table, because the answer depends on the obligations that apply to you and on the circumstances. What this section gives you is enough to read a certificate critically and ask the right question.

What the Certificate Should Contain

Six fields. If a sample is missing any of them, ask why before you ask anything else.

Serial numbers, individually listed. Not a count. This is the field whose absence created the opening example, and it is the one most often missing.

The destruction method, per device. Overwrite, cryptographic erase, degauss or physical destruction. Different devices in the same batch will legitimately get different treatment, and the certificate should say which got what.

The standard applied, named rather than alluded to.

The date of destruction, not the date of collection. The gap between those two is the window in which devices existed outside your control and had not yet been destroyed, and it is worth knowing how long it typically is.

The issuing entity, with enough identification that somebody could verify it later. If the processor is a subcontractor, their name belongs here.

The outcome per device. Recycled, resold or destroyed. This is what connects your asset register closure to a real-world end state.

Store it against the asset record rather than in a shared drive folder. A certificate that cannot be found from a serial number is doing a fraction of its job.

One field that is not usually on a certificate and is worth asking for: the weight or unit count received at the facility, reconciled against what the collection docket said. It is the only independent check that the batch which arrived is the batch you sent, and vendors who do it routinely will supply it without fuss. Vendors who cannot are telling you something about their intake process.

And read the first certificate you receive properly, line by line, rather than filing it. Every subsequent one from that vendor will look the same, so the ten minutes spent on the first is the only opportunity to notice that serials are absent, that the method is identical across a mixed batch, or that the issuing entity is not who you contracted with. Nobody reads the fourteenth certificate, which is precisely why the first one deserves attention.

The Distributed Problem Specialists Do Not Solve

Everything above assumes the hardware can be got onto a pallet. For a company whose devices are in flats across six countries, that assumption is the entire difficulty, and it is worth being explicit because it determines whether a disposal vendor is usable at all.

Certified specialists are built around volume arriving at a facility. Their economics, their minimums and their collection models all assume a loading bay. Ask one to collect a single laptop from somebody's home in another country and the answer is usually no, and where it is yes the cost per device is high enough that the hardware is not worth moving.

So the realistic shape for a distributed fleet is two suppliers doing different jobs. Something that recovers devices from individuals, wipes them on arrival and consolidates them somewhere. Then, once there is a batch, a certified specialist who processes it and issues the certification. That is not a failure of either supplier; it is two genuinely different problems.

The consolidation point is the decision that matters and it is usually got wrong in one of two ways. Shipping everything to a head office in another country spends more on freight than the hardware is worth and creates a customs event for goods with no commercial value, which is its own administrative problem. Holding devices wherever they happen to land produces fourteen locations with three devices each and no batch anywhere.

The workable middle is to consolidate regionally, in your two or three busiest markets, and to run disposal per region rather than globally. It means more vendor relationships and it keeps the hardware in the market it was bought in, which avoids the freight and the border entirely.

There is a timing decision inside this that is worth making deliberately. Holding devices until a region accumulates a worthwhile batch maximises what a specialist will pay and minimises collection cost, and every month of holding costs residual value, because hardware depreciates whether it is in use or in a box. For most fleets the crossover is somewhere around two quarters: beyond that the depreciation outruns the batching benefit. Set a maximum holding period alongside the batch size, and dispose on whichever comes first, so a region that never quite fills a pallet does not accumulate three-year-old machines indefinitely.

One consequence worth planning for: regional consolidation means your certificates come from several entities in several countries, so the register needs to hold which vendor certified which device. A single global disposal contract is simpler to administer and usually more expensive to operate for this fleet shape.

What Getting This Wrong Costs

The direct cost is the disposal fee, and it is usually modest and occasionally negative once resale is counted. This is not where the money is.

The second cost is the one that arrives with a question. An unevidenced destruction is, from the point of view of anybody assessing you, indistinguishable from no destruction, and the work of reconstructing it fourteen months later is substantial and sometimes impossible. The vendor may no longer hold the records, the people involved may have left, and the register will say "sent for disposal" against 180 rows with nothing behind it.

The third cost is the cupboard. Devices that nobody disposes of because the process is unclear sit in storage carrying an open data obligation, depreciating, and occupying space. This is the most common actual outcome in companies that have not sorted this out, and it is worse than either a cheap disposal or an expensive one.

There is a fourth cost that only appears in a transaction, and it is the one that makes this worth doing properly rather than adequately. In any diligence exercise, a buyer's advisers will ask what hardware the company has held, what data was on it and how it was disposed of. A register with 180 rows marked disposed and no evidence behind any of them does not usually kill a deal, and it does reliably produce a workstream, a set of warranties somebody has to give, and occasionally a retention. The cost is not the disposal fee. It is senior time during the worst possible month, spent reconstructing something that would have been free to record at the time.

So the question worth asking before the next refresh is not who will take the hardware away. It is what will arrive afterwards, and whether it will answer a question about one specific machine.

When You're Ready to Move Beyond the Cupboard

Almost every company reaches this the same way. Devices come back, there is no obvious process, they go in a room, and the room gets fuller. Nobody decided this; it is what happens when a task has no owner and no deadline.

What changes it is usually not a policy but a trigger. The companies that handle this well have a calendar date rather than a volume threshold, because a volume threshold is never quite met and a date arrives whether or not anybody is ready. Quarterly works for most, and the batch is whatever has accumulated.

The sequence is short. Wipe on arrival rather than on disposal, so the data obligation closes at the moment of custody and the cupboard stops being a liability. Set the quarterly date. Ask two vendors for a sample certificate before asking either for a price, and choose on the six fields above. Put serialised reporting in the statement of work. Then store each certificate against the asset record and close the row. None of that requires a large contract, and it converts a room full of exposure into a documented process.


Frequently Asked Questions

What are IT asset disposal services?

They cover the regulated end of the device lifecycle: collecting retired hardware, destroying the data on it to a recognised standard, and then recycling or refurbishing and reselling what remains. The term IT asset disposition, or ITAD, is used for the same thing and is used loosely across the industry, which causes most of the confusion here. The practical distinction worth holding is that collection and wiping are widely offered while serialised certification is not, and only the second answers the question an auditor will ask.

Is wiping a device the same as disposing of it?

No, and treating them as the same is the most expensive mistake in this category. Wiping is a technical operation that you can perform yourself on most modern hardware and that many device platforms will perform for you. Disposal is a chain of custody, an evidenced destruction and a documented downstream outcome, so a device you wiped and then left in a cupboard has been wiped and not disposed of, and it still carries an open obligation.

What should a certificate of destruction contain?

Six things: individually listed serial numbers rather than a count, the destruction method applied to each device, the named standard, the date of destruction rather than collection, the issuing entity including any subcontractor who did the processing, and the outcome per device. Ask for a sample before discussing price, because a certificate that lists a quantity and a date but no serials cannot be connected to any particular machine later, which is exactly when somebody will ask.

Will we be paid for retired hardware?

Sometimes, and it should be treated as a rebate rather than as the basis for choosing a vendor. Working business laptops around three years old with no activation locks have a genuine resale market, while mixed pallets of unknown age with locked devices and missing components usually do not. Be sceptical of an attractive per-unit figure quoted before anybody has seen the fleet, since that is a best case rather than an estimate.

Can our device management platform handle disposal?

It can almost certainly collect devices and wipe them, which is genuinely the harder logistics problem when your hardware is with people rather than on a pallet, and it almost certainly cannot issue disposition certification. Ask directly whether the vendor holds a recognised certification themselves or routes material to a partner who does, and ask whose name appears on the certificate you receive. Subcontracting is completely normal; vagueness about it is the warning sign.

How small is too small for a disposal vendor?

Below roughly ten devices a year in a single country, a vendor usually adds procurement overhead without adding evidence you could not produce yourself. At that scale, encrypt and wipe the device, record the wipe with a date and method against the asset, and take the hardware to a licensed electrical recycler. The thing that actually changes the calculation is not volume but whether the data on those devices is the kind where somebody will want independent evidence.

What should we do with devices already sitting in storage?

Wipe them now rather than at disposal, because an unwiped machine in your own cupboard carries the same data exposure as one anywhere else and simply has a lower chance of being read. Record each wipe against the asset with a date and method, which closes the obligation immediately and means the eventual disposal is a logistics exercise rather than a compliance one. Then set a calendar date for collection rather than waiting for the pile to reach a size that justifies action, since that size is never quite reached.

HROpsLab takes no vendor money and publishes no paid placements, which is why the owner's own product appears below a certified specialist on this page rather than above one.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →