Home / Guides / What Is a Certificate of Destruction?

Field note / document shredding

What Is a Certificate of Destruction?

A certificate of destruction is a document a secure destruction company issues after shredding or destroying your materials, confirming what was destroyed, when, how, and by whom. It's your proof of compliant disposal if you're ever audited, sued, or asked to demonstrate due diligence over discarded records. A reputable provider includes one with every job, on-site or drop-off, at no extra charge.

What the document should actually contain

A certificate of destruction is only useful if it's specific enough to hold up as evidence. At minimum, look for:

Date and location of destruction. Not just the date of pickup — the date the material was actually destroyed, and whether that happened on-site at your location or later at a plant.

Method of destruction. Shredding, pulverizing, or another approved method, along with the particle size or standard applied, especially for hard drives or other media where "wiped" and "physically destroyed" are meaningfully different claims.

Description and quantity of material. Number of boxes, consoles, bins, or units of media destroyed — a generic "confidential documents" line with no quantity is weaker evidence than an itemized count.

Company identity and signature. The destruction company's name, and ideally a signature or authorized statement from the operator or witness, not just a printed template.

Client and job reference. Your company name and a reference to the specific service date or work order, so the certificate can be tied back to a specific transaction if questioned later.

Why this document matters beyond a formality

Certificates of destruction exist because disposal obligations don't disappear once the shredder does its job — the business that generated the records is generally the one accountable for showing disposal was handled properly. The FTC's Disposal Rule, part of FACTA and the FTC's broader data-security guidance, directs businesses to take reasonable measures when discarding information derived from consumer reports. Organizations handling health records or financial data carry additional obligations under HIPAA or GLBA. None of this is legal advice, and specific requirements vary by industry and jurisdiction — but in a dispute or audit, a dated, specific certificate is far more persuasive than a memory of "we shredded that."

Keep certificates the same way you'd keep any compliance record: filed by date, retrievable, and retained for as long as your internal policy or applicable regulation requires — often several years beyond the destruction date itself.

Red flags in a weak or missing certificate

No certificate offered unless you ask. Providers who treat documentation as an upsell rather than a standard part of service are worth questioning.

Vague or undated templates. A boilerplate PDF with no date, no quantity, and no reference to your specific job isn't meaningfully different from no certificate at all.

No connection to a witnessed or verifiable process. For on-site shredding, you should be able to watch destruction happen or view it through the truck's camera; for drop-off or plant-based service, ask how chain of custody is maintained between your drop-off and the certificate's destruction date. See drop-off versus on-site shredding for how the two approaches differ on this point.

Certification claims that don't check out. A company might reference NAID AAA on its certificate letterhead without current certification. You can verify any provider's actual status yourself — see below.

Certificate of destruction vs. NAID AAA certification

These sound similar but answer different questions. NAID AAA certification is an audited credential covering a company's ongoing security practices — background-checked staff, secured facilities, controlled chain of custody. A certificate of destruction is a record of one specific job. A NAID AAA certified provider should reliably produce solid certificates as part of its audited process, but you should still read each certificate rather than assume the company's certification alone covers you.

Frequently asked questions

Is a certificate of destruction legally required? Generally there's no single federal law mandating this exact document by name, but "reasonable measures" language in rules like FACTA's Disposal Rule effectively makes documented, verifiable disposal the safer practice, and many industry-specific rules (HIPAA, GLBA) or client contracts require it explicitly.

Should I get a certificate for recurring shredding service, or just one-time purges? Both. For recurring business shredding service, ask whether you receive a certificate for each pickup or a periodic summary — either can work, but you should know which one you're getting and keep the record.

What if I lose a certificate? Ask the provider if they retain records and can reissue documentation; reputable companies keep destruction logs for a defined retention period.

How to choose and verify a provider

Before hiring, confirm in writing that a certificate of destruction is included with every job, and ask to see a sample so you know what detail level to expect. Cross-check the provider's certification claims in i-SIGMA's public NAID AAA directory rather than taking a logo on their site at face value — the directory reflects independently audited, source-backed public records, and it doesn't itself certify or endorse anyone, so treat it as a place to verify, not a stamp of approval from us or any listing site. A provider that's transparent about both its certification status and its documentation practices is a reasonable signal you're dealing with a serious operation rather than a truck with a shredder in the back.

Primary references

These authoritative sources govern the safety and regulatory context used across this guide. State and local requirements may be more specific.

Find a certified document shredding provider near you

Browse verified providers by city →

Related guides