The most important questions to ask a media disposal vendor cover what media they handle, how they maintain chain of custody, which destruction methods they use, how they verify destruction, and whether their contract obligates subcontractors to meet the same requirements. For ISO 27001 control 7.10, an MSSP should also confirm that the vendor can support the customer’s classification scheme from pickup through final disposal and provide evidence that each asset was destroyed or sanitized appropriately. The right depth of review depends on the sensitivity, volume, and portability of the media involved.
How should you assign vendor risk tiers for media disposal?
Start by tiering the disposal provider based on the customer data that may remain on the media, the vendor’s physical possession of that media, and the consequences of a lost or improperly processed asset. ISO 27001 practice 7.10 requires storage media to be managed across acquisition, use, transportation, and disposal according to classification and handling requirements.[1] A disposal vendor becomes part of that lifecycle when it transports, stores, sanitizes, shreds, resells, or recycles media.
| Tier | When to use it | Examples of media | Review owner and cadence |
|---|---|---|---|
| Tier 1: Critical | Vendor handles media containing regulated, confidential, production, credential, or customer data and transports it off-site. | Production database drives, backup tapes, encrypted laptops with recovery keys, failed cloud appliance disks. | MSSP analyst and customer security owner; annual reassessment plus review after material incidents. |
| Tier 2: High | Vendor handles internal or customer-related media, but exposure is limited by encryption, sanitization before pickup, or supervised destruction. | Encrypted employee laptops, retired network appliances, internal file-server drives. | MSSP analyst; annual questionnaire and artifact refresh. |
| Tier 3: Standard | Vendor processes low-sensitivity media or supplies bins, logistics, or recycling with no expected access to recoverable data. | Blank optical media, paper labels, already-destroyed drive fragments, packaging. | Customer operations owner; review every two years or at contract renewal. |
Do not automatically downgrade a vendor because drives are encrypted. Encryption materially reduces exposure, but lost devices can still create reporting obligations, key-management concerns, and contractual risk. For Tier 1 engagements, treat transport and temporary storage as high-risk activities even where the final destruction method is reliable.
For example, a 180-person SaaS company retiring failed SSDs from VMware hosts and backup appliances should classify its destruction vendor as Tier 1. The drives may contain customer account records, API tokens, database snapshots, and diagnostic logs. A 35-person software company disposing of BitLocker-encrypted employee laptops through a supervised local shredding event may reasonably use Tier 2 if recovery keys are held only in Microsoft Entra ID and devices are reconciled before shredding.
What are the tier-specific questions to ask a media disposal vendor?
Use the checklist below as an evidence-oriented review, not just a sales-call script. Record the vendor’s answer, the evidence received, exceptions, compensating controls, and approval decision in the customer’s vendor register.
| Due-diligence area | Tier 1 questions | Tier 2 questions | Tier 3 questions |
|---|---|---|---|
| Media scope and classification | Which media types do you accept, and how do you identify drives, tapes, mobile devices, and equipment containing confidential or regulated data? Can you process serialized assets individually? | Which device types are included, and which require separate handling? Do you reject damaged or unknown media? | Can you confirm that your service excludes media likely to contain recoverable confidential data? |
| Chain of custody | Who scans assets at pickup, transfer, storage, and destruction? Are custody records time-stamped and tied to serial number, asset tag, and destruction event? | Do you provide pickup manifests and a certificate tied to the customer shipment or event? | Can you provide a pickup receipt and final recycling confirmation? |
| Transport and storage | Are vehicles GPS-tracked, locked, and alarmed? Is media stored in access-controlled cages? What is the maximum storage period before destruction? | Are containers locked during transport and stored in a restricted facility before processing? | How is material protected from loss between pickup and recycling? |
| Destruction and sanitization | Which method is used for HDDs, SSDs, tapes, and mobile devices? Can you meet NIST SP 800-88 Rev. 1 purge or destroy expectations? What shred size is used? | Do you use physical shredding, degaussing, or verified wiping? How do you validate the selected method? | What method prevents reuse or recovery of material accepted for recycling? |
| Exceptions and incidents | What happens when an asset is missing, unreadable, mismatched, or discovered outside a sealed container? What is your notification period? | Will you notify us within one business day of a lost asset or custody discrepancy? | Who should receive notification if a pickup manifest cannot be reconciled? |
| Subcontractors | Do subcontractors transport, store, shred, recycle, or export material? Provide their locations, services, and controls. | Do you use downstream recyclers, and are they contractually bound to equivalent controls? | Can you identify the final recycler if one is used? |
A useful practical question for every tier is: “Can you show us a redacted certificate of destruction and the corresponding custody record?” If the vendor cannot connect a certificate to a specific pickup, asset list, or destruction batch, the certificate may be insufficient evidence for an ISO 27001 audit.
Which artifacts should the vendor provide?
Artifacts should match the risk tier rather than becoming an unmanageable document-collection exercise. For a Tier 1 vendor, request evidence before approval and refresh it annually. For Tier 2, accept a narrower set when the customer has strong compensating controls, such as encryption and a documented asset-return process.
- Certificate of destruction sample: It should identify the customer, date, location, destruction method, and preferably serial numbers or asset tags. A generic statement that “materials were destroyed” is weak evidence.
- Chain-of-custody procedure and sample manifest: Look for signatures or electronic scans at pickup, facility receipt, transfer, and destruction.
- SOC 2 Type II report: Request the current report, bridge letter where applicable, and management response to relevant exceptions. A SOC 2 report is helpful but does not replace media-specific evidence.
- Penetration-test attestation: For vendors operating customer portals, tracking systems, or APIs, request a recent independent penetration-test summary, remediation status, and scope. The test should cover the portal used to download certificates and manifests.
- Information security policies: Request policies for access control, incident response, personnel screening, secure transport, and media handling.
- Insurance and incident history: Obtain cyber and general liability evidence, plus written disclosure of material media-loss incidents or regulatory actions from the prior three years.
- Environmental and downstream documentation: Request R2v3 or e-Stewards certification when recycling is included, along with downstream vendor controls and geographic processing locations.
- Personnel controls: For Tier 1, confirm background screening, confidentiality agreements, role-based access, and training for employees who handle customer media.
For the SaaS company example, the MSSP analyst should also request a sample serial-number report compatible with the customer’s ServiceNow asset records. That lets the IT operations team reconcile a retired Dell PowerEdge drive from the decommission ticket, through pickup, to a destruction certificate without relying on manually maintained spreadsheets.
How should an annual reassessment workflow work?
Annual reassessment should prove that the vendor remains suitable, not merely confirm that a contract still exists. Build the process into the customer’s vendor-management calendar and trigger an out-of-cycle review when the vendor changes facilities, subcontractors, destruction methods, ownership, or incident-notification terms.
- 60 days before renewal: Export the prior year’s pickup manifests, certificates, incident tickets, and unresolved asset discrepancies.
- 45 days before renewal: Send the tier-appropriate questionnaire and request refreshed SOC 2, penetration-test attestation, insurance certificate, and relevant recycler certifications.
- 30 days before renewal: Reconcile a sample of at least 10 disposed assets, or 10% of annual volume when that is higher, from the customer asset register to vendor evidence.
- 15 days before renewal: Score gaps as acceptable, compensating control required, remediation required, or disqualifying. Document approval in the vendor register.
- At renewal: Confirm contract clauses remain current, particularly incident notification, subcontractor approval, evidence retention, and audit rights.
For SMB customers, keep the review usable. A simple vendor record in Jira Service Management, ServiceNow, or Microsoft Lists can track the tier, renewal date, artifacts, exceptions, owner, and approval decision. The analyst’s key output is an auditable decision: continue, continue with remediation, or replace.
What contractual flow-down clauses should be required?
The contract should turn vendor promises into enforceable requirements. For Tier 1 providers, the customer should require written approval before material subcontracting and ensure that each downstream party is bound to equivalent obligations.
- Handling standard: Require management of media according to the customer’s data classification and handling requirements, including ISO 27001 control 7.10 lifecycle expectations.
- Chain of custody: Require documented custody from collection through final destruction or sanitization, including asset identifiers where available.
- Approved methods: Specify accepted sanitization or destruction methods by media type, including shredding requirements for SSDs and degaussing or shredding requirements for magnetic tape.
- Evidence retention: Require manifests and certificates of destruction to be retained for at least seven years, or longer where customer, legal, or regulatory obligations require it.
- Incident notification: Require notification within 24 hours of confirmed or suspected loss, theft, custody break, unauthorized access, or destruction failure.
- Subprocessor flow-down: Require prior notice and equivalent written obligations for transporters, shredding facilities, recyclers, and downstream processors.
- Audit and assurance rights: Permit review of relevant policies, certifications, audit reports, and custody records, with on-site review rights for critical vendors where justified.
- Return or destruction of records: Require the vendor to securely destroy customer manifests and tracking data when retention ends, unless law requires continued retention.
When evaluating disposal providers, treat the vendor’s proof of custody and destruction as part of the customer’s control evidence, not as a procurement attachment.
Next step: Add these vendor-review questions and required artifacts to your MSSP’s Tier 1 and Tier 2 vendor assessment templates before the next customer disposal event.