ITAR Compliant Data Destruction: What You Must Know

ITAR Compliant Data Destruction: What You Must Know

Key Takeaways for ITAR Data Destruction

  • Standard software wiping fails to meet ITAR requirements. Physical destruction to unrecoverable fragments is mandatory under 22 CFR Part 120.
  • Every technician and witness must be a screened U.S. person, with documented background checks and chain-of-custody logs that prevent deemed-export violations.
  • Certificates of Destruction must be serialized per device, reference NIST SP 800-88 Rev. 2 methods and include an attached ITAR conformance memo.
  • NAID AAA-certified, in-house shredding performed by vetted personnel under witnessed protocols satisfies State Department guidance and withstands audit scrutiny.
  • Full Circle Electronics delivers end-to-end ITAR-compliant destruction across the U.S., Mexico and Colombia. Build a defensible ITAR program with a single accountable provider.

ITAR Data Destruction Standards for 2026

22 CFR Part 120 governs the International Traffic in Arms Regulations. Under that framework, defense contractors handling export-controlled technical data must destroy ITAR-controlled media so that reconstruction is not possible. Physical shredding and degaussing plus shred align with State Department guidance for technical-data destruction.

A hard drive dissolving into particles against a dark background.
Improperly decommissioned devices are a leading breach vector. Certified data destruction to NIST 800-88 and DoD 5220.22-M standards renders information irretrievable — with a verifiable certificate for every asset.

The regulation also restricts who may perform destruction work. Under 22 CFR 120.15, U.S. persons include U.S. citizens, lawful permanent residents, refugees and asylees. Sharing ITAR-controlled technical data with any other individual, including visual access, constitutes a deemed export. That restriction covers every technician, witness and support staff member present during destruction.

Full Circle Electronics operates with background-checked U.S.-person technicians and NAID AAA-certified in-house shredding at its facilities. Every destruction event uses vetted personnel under witnessed chain-of-custody protocols, with real-time documentation available through a secure customer portal.

Workers in blue coveralls and respirators process electronics along an industrial line.
Certified processes and background-checked technicians handle sensitive and ITAR-controlled hardware in controlled, audit-ready workflows.

Discuss a compliant destruction program for ITAR-controlled assets.

Seven-Step ITAR Data Destruction Checklist

Meeting these regulatory requirements in practice requires a systematic approach. The following checklist maps to the core compliance controls required under 22 CFR, NIST SP 800-88 Rev. 2 and DoD 5220.22-M.

  1. Identify and flag all ITAR-controlled assets at intake, separate from non-controlled inventory.
  2. Confirm every technician and witness is a U.S. person as defined under 22 CFR 120.15, with documented screening on file.
  3. Verify the destruction vendor holds NAID AAA, R2v3 and e-Stewards certifications and performs destruction in-house rather than brokering to a third party.
  4. Select the appropriate NIST SP 800-88 Rev. 2 sanitization level for each media type: Clear, Purge or Destroy.
  5. Perform witnessed destruction within an ITAR-controlled perimeter, and document the named witness and operator on the chain-of-custody log.
  6. Issue a per-device Certificate of Destruction with an attached ITAR conformance memo citing 22 CFR Part 120.
  7. Store all records in a serialized, audit-ready portal accessible 24/7 for regulatory review.

Core ITAR Data Destruction Requirements

An ITAR Technology Control Plan must define controlled destruction and disposal protocols for ITAR-controlled materials as part of its physical security controls. That plan must address four operational requirements.

  1. U.S.-person screening. Every employee, contractor, consultant, temporary worker, intern or visitor who may access ITAR-controlled technical data must be screened to determine citizenship or immigration status at the point of hire or engagement, with results documented in personnel files.
  2. Technology Control Plan controls. TCPs require employee screening for citizenship status during hiring with documentation in personnel files, data segregation with need-to-know access protocols, comprehensive visitor logs with pre-approval screening and regular ITAR awareness training.
  3. Flagged assets on the chain-of-custody log. ITAR-controlled assets must be flagged separately on the chain-of-custody log to ensure they receive the appropriate destruction protocol. This flagging supports accurate documentation and triggers the need for ITAR-specific records.
  4. ITAR conformance memo attached to the certificate. A separate ITAR conformance memo citing 22 CFR Part 120 must be attached to the Certificate of Destruction for organizations handling export-controlled technical data. The memo provides auditors with explicit confirmation that the vendor recognized the asset’s controlled status and applied the correct regulatory standard.

NIST 800-88 Rev. 2 Methods by Media Type

NIST SP 800-88 Rev. 2 defines three sanitization levels. Each level applies differently depending on media type and data sensitivity.

Clear applies logical techniques, such as overwrite passes, to sanitize data in all user-addressable storage locations. It suits lower-sensitivity media that will be redeployed internally. It does not satisfy ITAR requirements for technical-data drives.

Purge applies physical or logical techniques that render data recovery infeasible using state-of-the-art laboratory methods. For HDDs, this includes secure erase commands or degaussing. For SSDs and NVMe drives, cryptographic erase combined with a verified overwrite is the recommended Purge method, because standard overwrite passes do not reliably reach all storage cells in flash-based media. Purge may be acceptable for some ITAR scenarios when combined with documented verification.

Destroy renders the media unusable and unrecoverable through physical disintegration, shredding, melting or incineration. For ITAR-controlled technical-data drives, including HDDs, SSDs and NVMe, physical shredding to unrecoverable fragments aligns with State Department guidance under 22 CFR Part 120 and with DoD 5220.22-M. Full Circle Electronics performs in-house shredding at its certified facilities and maintains an unbroken chain of custody from intake to destruction.

A hard drive amid a pile of shredded electronic components.
For end-of-life media, physical destruction is the final safeguard — shredding renders drives and components unrecoverable, closing the loop on data security.

Certificate of Destruction Requirements for Audit Readiness

A Certificate of Destruction that cannot withstand audit scrutiny becomes a liability instead of a compliance asset. Certificates issued before destruction occurs, or those lacking per-device serial numbers, inventories, or any cited method and standard, fail to provide verifiable proof during audits or breach investigations.

A defensible Certificate of Destruction for ITAR work must include all of the following elements:

  • Per-device serial number for every asset destroyed, not bulk quantities
  • Device type and manufacturer for each item
  • Exact destruction method and the standard followed, including NIST SP 800-88 Rev. 2 level
  • Date, time and location of destruction
  • Named witness signature and operator identification
  • Chain-of-custody reference number
  • Vendor certifications including NAID AAA, R2v3 and e-Stewards certification numbers
  • Attached ITAR conformance memo referencing 22 CFR Part 120

All required fields must be populated. Full Circle Electronics issues serialized Certificates of Destruction through its 24/7 customer portal, where compliance officers and auditors can access records on demand with CSV export capability.

A corridor of blue-lit server racks in a data center.
From a single login, every asset is tracked 24/7 through a secure online portal — full chain-of-custody from on-site pickup to final disposition.

Choosing On-Site, Off-Site or Hybrid ITAR Destruction

The choice between on-site and off-site destruction depends on risk tolerance, asset volume and chain-of-custody requirements. The right model reflects the classification level of the media and the organization’s Technology Control Plan.

On-site destruction eliminates the transport window for intact media. On-site destruction directly supports policies that require unsanitized media to remain inside the building, a common requirement in government, defense-adjacent work and security-conscious sectors. Witnessed destruction performed on-site produces a strong audit record. Witnessed destruction documentation achieves higher audit success rates than vendor-only certificates. On-site services carry a cost premium over off-site due to travel, setup and security requirements.

A technician with a tablet inspects server racks in a data center.
On-site, white-glove data center decommissioning — de-racking, de-stacking, and secure chain-of-custody — retires high-density hardware with minimal operational disruption.

Off-site destruction at a certified facility provides access to a full range of destruction methods and supports larger volumes. Off-site destruction relies on a documented chain of custody during transport rather than in-person witnessing at the client site. It requires more custody transfers than on-site work, which increases the window during which intact media is in transit. Vendors must hold R2v3, NAID AAA and transportation security credentials at minimum.

Hybrid models combine both approaches. Many organizations adopt a hybrid model, with on-site destruction for the most sensitive drives so they never leave the premises intact, combined with off-site collection of reusable equipment under chain of custody for wiping and value recovery.

Full Circle Electronics supports on-site, off-site and hybrid models. Its in-house shredding infrastructure, not brokered to third parties, maintains an unbroken chain of custody regardless of which model an organization selects. Facilities span the U.S., Mexico and Colombia, enabling consistent execution across multi-site programs.

Common ITAR Audit Red Flags and How to Avoid Them

Auditors reviewing ITAR data destruction records look for specific failure patterns. The following issues frequently trigger audit disputes or enforcement action.

  • Bulk certificates: A certificate listing “200 hard drives” without per-device serial numbers is not defensible. Every device requires its own serialized record.
  • Missing U.S.-person documentation: If the vendor cannot produce screening records confirming every technician is a U.S. person under 22 CFR 120.15, the destruction event is non-compliant regardless of the method used.
  • Unsigned chain-of-custody: An unsigned or undated chain-of-custody log creates an evidentiary gap that auditors treat as a break in custody.
  • Pre-issued certificates: Certificates issued before destruction occurs fail to provide verifiable proof during audits or breach investigations.
  • No ITAR conformance memo: A standard Certificate of Destruction without an attached ITAR conformance memo referencing 22 CFR Part 120 does not satisfy the documentation standard for ITAR-controlled assets.

How to Evaluate an ITAD Vendor for ITAR Work

Not every ITAD vendor is qualified to handle ITAR-controlled media. The following criteria map directly to the seven-step checklist and the requirements under 22 CFR.

  • NAID AAA certification confirming 100 percent background-checked personnel
  • R2v3 and e-Stewards certifications for responsible downstream processing
  • ISO 9001, ISO 14001 and ISO 45001 certifications for process and environmental controls
  • In-house shredding capability, not brokered, to maintain an unbroken chain of custody
  • Documented U.S.-person screening workflow with personnel files available for audit
  • Witnessed destruction with named witness and operator signatures on every Certificate of Destruction
  • ITAR conformance memo issued with every Certificate of Destruction for ITAR assets
  • 24/7 serialized portal access for real-time audit documentation
  • Multi-site capability across all locations where ITAR-controlled assets are retired

Full Circle Electronics holds NAID AAA, R2v3, e-Stewards, ISO 9001, ISO 14001 and ISO 45001 certifications. Its facilities operate across the U.S., Mexico and Colombia under a single accountable provider model, with in-house shredding and real-time portal documentation at every location.

Request a vendor qualification review or sample Certificate of Destruction.

Conclusion: Building a Defensible ITAR Destruction Program

ITAR-compliant data destruction in 2026 requires physical destruction to unrecoverable fragments, performed by vetted U.S. persons, under witnessed chain-of-custody, with per-device serialized Certificates of Destruction and an attached ITAR conformance memo citing 22 CFR Part 120. Software wiping alone does not meet this standard. Vendors that broker destruction to uncertified third parties or issue bulk certificates without per-device records also fall short.

Full Circle Electronics operates every required control: NAID AAA-certified in-house shredding, 100 percent U.S.-person background-checked technicians, witnessed destruction protocols, real-time serialized documentation and a 24/7 customer portal across the U.S., Mexico and Colombia.

Build a defensible ITAR destruction program with a single accountable provider.

Frequently Asked Questions

What makes data destruction “ITAR compliant”?

ITAR-compliant data destruction requires that ITAR-controlled media be destroyed to the point where reconstruction is not possible, as required under 22 CFR Part 120. Physical shredding is the standard method that satisfies this requirement for technical-data drives. Compliance also requires that every technician and witness be a U.S. person as defined under 22 CFR 120.15, that ITAR assets be flagged separately on the chain-of-custody log and that an ITAR conformance memo citing 22 CFR Part 120 be attached to the Certificate of Destruction. Software wiping alone does not meet this standard.

Does NIST SP 800-88 Rev. 2 apply to ITAR data destruction?

NIST SP 800-88 Rev. 2 defines the sanitization levels Clear, Purge and Destroy that apply to different media types. For ITAR-controlled technical-data drives, the Destroy level is the appropriate standard. This level requires physical shredding or incineration to unrecoverable fragments. For SSDs and NVMe drives, standard overwrite passes do not reliably reach all storage cells in flash-based media, which makes physical destruction the method that satisfies both NIST SP 800-88 Rev. 2 and State Department guidance under 22 CFR Part 120. Full Circle Electronics performs in-house physical shredding certified to these standards.

What should a Certificate of Destruction include for ITAR assets?

A Certificate of Destruction for ITAR-controlled assets must include the per-device serial number for every asset destroyed, the device type and manufacturer, the exact destruction method and NIST SP 800-88 Rev. 2 level applied, the date and time of destruction, the named witness signature and operator identification, a chain-of-custody reference number and the vendor’s current certification numbers. For ITAR assets, an attached ITAR conformance memo citing 22 CFR Part 120 is also required. Bulk certificates listing quantities rather than individual serial numbers are not defensible in an audit. Full Circle Electronics issues serialized Certificates of Destruction through its 24/7 customer portal, with all required fields populated.

When is on-site ITAR data destruction required versus off-site?

On-site destruction is the appropriate choice when an organization’s Technology Control Plan or risk posture requires that unsanitized ITAR-controlled media never leave the facility intact. It eliminates the transport window for intact media and allows the client to witness destruction in person, which produces a strong audit record. Off-site destruction at a certified facility is viable when a documented chain of custody during transport is established and the vendor holds required certifications, including NAID AAA, R2v3 and e-Stewards. Many defense contractors use a hybrid model, with on-site destruction for the most sensitive drives and off-site processing for lower-sensitivity assets under chain of custody. Full Circle Electronics supports both models with in-house shredding infrastructure and no third-party brokering.

How does Full Circle Electronics handle ITAR destruction across multiple locations?

Full Circle Electronics operates certified facilities across the U.S., Mexico and Colombia under a single accountable provider model. All technicians are background-checked U.S. persons, and all destruction is performed in-house rather than brokered to third parties. This structure maintains an unbroken chain of custody across every location in a multi-site program. Clients access serialized destruction records, Certificates of Destruction and chain-of-custody documentation through a secure 24/7 customer portal, which supports consistent audit-ready reporting regardless of which facility processed the assets.