Certificate of destruction: what it is and why you need one

The erase itself is only half the job. The other half is the paper trail that proves it happened — and a certificate of destruction is its headline document.

t tScrub Team Last updated 22 Sep 2026 7 min read

A certificate of destruction (sometimes called a certificate of data destruction or erasure certificate) is a formal record that a specific set of media was sanitised on a specific date, by a specific method. It's what you hand an auditor, a client, or a regulator when they ask: "how do you know that data is really gone?"

In this series:

Chain of custody

Behind every good certificate is a chain of custody — the unbroken record of where each drive was and what happened to it. A chain of custody starts at identification (serial number, model, source) and ends at final disposition (erased, resold, or destroyed), with each step timestamped.

tScrub's reports are built around a Chain of Custody ID (COCID): one identifier ties together every drive in a job, the system serials they came from, the methods used, and the final status of each drive.

What a certificate should include

FieldWhy it matters
Certificate IDUnique reference you can file and later look up
Chain of Custody IDLinks the certificate back to the job
Device list (Annex A)Serial numbers, models, and methods per drive
Certification date / rangeWhen the erasure took place
Method & outcomeWhich wipe ran and its NIST 800-88 result
Report manifestFile names and SHA-256 hashes of the source reports
SignatureCryptographic proof the report hasn't been tampered with
Verification code / QRLets a third party confirm the certificate is genuine

How tScrub certificates work

The flow is simple: run tScrub to produce a report (CSV + manifest + signature), then upload it on your dashboard's Reports page and generate a certificate from the Certificates page. tScrub verifies the report, renders a printable PDF certificate — with a device annex and, where the report includes it, a pre/post-wipe SMART capture — and stores the issuance record.

The verification QR code

Every tScrub certificate carries a QR code that encodes a verification link. Scanning it opens /verify?cert=…, which confirms the certificate's issuance record and document hash against the database. That turns a static PDF into something a third party can independently check — no phone call to you required.

Free vs paid: self-signed vs vendor-signed

Not all signatures are equal, and tScrub is explicit about which kind a certificate has:

For regulated disposal, vendor-signed certificates are the standard; self-signed is fine for internal reuse tracking.

Making certificates audit-ready

FAQ

Is a certificate of destruction a legal requirement?

Not in itself, but data-protection law (GDPR, HIPAA) requires you to be able to demonstrate appropriate disposal. A certificate is the most practical way to do that.

Can I generate a certificate without a tScrub report?

tScrub certificates are generated from a tScrub report (CSV + manifest), because the certificate is only as trustworthy as the record it certifies.

Keep reading

Turn any tScrub report into a certificate

Upload, verify, and download a printable, QR-coded Certificate of Destruction in seconds.

Get tScrub