Secure sanitisation and destruction standard (SS-036) was published in 2022 and was recently updated on June 26, 2025. It outlines the minimum technical security measures that are mandatory to implement to sanitise and/or destroy media or IT assets used within the organisation or used to process the organisation’s data. The standard SS-036 is designed to promote consistency across the DWP UK and contracted third party providers, pertaining to implementation and management of security controls. The purpose of the secure sanitisation and destruction standard is to prevent the organisation’s data stored on IT assets from getting compromised when the IT asset exits the organisation or usual work environment to get repurposed, repaired, destroyed, or disposed of. It also aims to minimise risks from common threats related to disclosure of media or IT assets outside the organisational environment.
Scope of SS 036
Secure sanitisation and destruction standard applies to all physical and virtual media and IT assets, including drives, mobile devices, storage systems, network infrastructure, and virtual machines (See Appendix B for the full list) that store or process DWP data, whether on-premises or with third-party providers. These applications and services handle the organisation’s data, including backup data.
SS 036 is proposed for technical engineers, security teams, and architects, domain and solution architects, project teams, operation teams, along with suppliers involved in the design, development, operation, and implementation of systems, services, and applications that store the organisation’s data.
When sanitising IT assets that store large volumes of organisational data, both the sensitivity and the quantity of data must be carefully evaluated before determining the appropriate sanitisation steps.
Minimum Technical Security Measures of SS-036
Section 11 of the Secure sanitisation and destruction standard elaborates on the mandatory technical security measures that should be implemented at the very least to ensure the desired outcomes. It is to be noted that since these are the minimum technical security measures, security measures should be exceeded and enhanced as and when considered appropriate to address the threats and risks.
Subsection 1.1 provides information on general sanitisation and destruction considerations applicable to all non-cloud environments, like on-premises, physical assets, and storage media.
- Reference 11.1.1 - To ensure whether it is appropriate to sanitise a device for reuse or destroy it, consider the following criteria: expected life, possibility of repair, signs of equipment failure/damage, signs of tampering, technological suitability, technological currency, device residual value.
- Reference 11.1.2 - Prior to reuse, all the storage media and IT assets must be sanitised onsite or at an assured offsite location.
- Reference 11.1.3 - Sanitisation must be performed as soon as devices no longer in use are identified. Until the devices or storage media have been appropriately sanitised, they must remain within a controlled environment approved by the organisation.
- Reference 11.1.4 - Whenever possible and applicable, sanitisation must be performed according to the National Cyber Security Center (NCSC) Assured Sanitisation Assurance Service (CAS-S).
- Reference 11.1.5 - The Risk Officer should formally sign the release of all the devices since remnant data may remain on the device, depending on the storage technology.
- Reference 11.1.6 - If reuse of storage media or devices is impossible, then either they must be destroyed offsite or they should be sanitised onsite before taking them to an offsite location for destruction.
- Reference 11.1.7 – For both onsite and offsite destruction, an NCSC CAS-S Scheme-approved third-party contractor must be used.
- Reference 11.1.8 – The Risk Owner must approve all the off-site destruction via risk acceptance, taking into account factors like data sensitivity, data aggregation, and association.
- Reference 11.1.9 – A record of the sanitisation or destruction must be maintained. The record must include date, time, media type (serial number, etc.), method, and verification results, in an asset inventory. BitRaser Drive Eraser automatically generates erasure reports and certificate of destruction which provide all details in line with SS036.
- Reference 11.1.10 – The storage media or device that cannot be sanitised must go through the approved destruction process mentioned in Section 11.3.
- Reference 11.1.11 - The records in the CMDB database must be updated to reflect the sanitisation or destruction status.
- Reference 11.1.12 - Records of sanitisation and destruction in addition to appropriate certificates, must be retained as per organisation policy.
- Reference 11.1.13 – Devices must be reset to default factory settings wherever applicable, before sanitisation or destruction.
- Reference 11.1.14 – To sanitise virtual machines, NIST SP 800-88 must be referred to, and Cryptographic Erase (CE) must be applied, wherever applicable.
- Reference 11.1.15 – When data at rest has been encrypted, then Cryptographic keys must be managed and protected according to SS-002 PKI and the Key Management Security Standard.
- Reference 11.1.16 - Regular training and awareness sessions must be conducted for the personnel whether internal staff or external suppliers, involved in the sanitisation and destruction activities.
Subsection 1.2 explains the minimum technical security measures when performing sanitisation of storage media and devices.
- Reference 11.2.1 - Identify media/device type and decide whether to sanitise or destroy.
- Reference 11.2.2 – Update or create record in asset inventory or database - CMDB.
- Reference 11.2.3 – Include if the sanitisation was performed by internal staff, the manufacturer, or a third-party ITAD provider.
- Reference 11.2.4 – Use Sanitisation software according to the classification of data.
- Reference 11.2.5 - After processing, storage media or devices must be returned to reuse cycle.
- Reference 11.2.6 - Verify sanitisation effectiveness; retain certificates per policy.
- Reference 11.2.7 - Below are listed the sanitisation methods that should be followed. For devices or media types not listed below, the organisation must seek advice from the DWP or Authority.
- Networking Devices & Office Equipment: Perform a factory reset to bring the router or switch back to its manufacturer’s default settings. Likewise for printer and fax.
Note: For more information on the sanitisation procedure, contact the manufacturer.
-
- Mobile Devices: Perform a factory reset to bring the mobile device, including iPhones, Google Android OS Devices, Windows Phones, PDAs, and tablets, back to their manufacturer’s default settings. Sanitise the mobile device using Erase All Content or a Full Reset, and wherever possible and feasible, utilize MDM capability. Take into consideration any expandable storage installed on the device.
Note: If removable media is present, then sanitisation techniques may be applied to the storage device.
-
- Magnetic Media: Overwrite data on the tape with an approved pattern using a system with similar features to that of the original system. The entire magnetic tape must be overwritten once with non-sensitive data.
To sanitise ATA HDDs and SCSI HDDs, refer to NIST SP 800-88 Guidelines for Media Sanitisation.
-
- Cloud Storage: Use Cryptographic Erase (CE) or another approved method to securely erase or render cloud data, including cryptographic keys and backups, inaccessible. If automated erasure fails, manual deletion must be performed. For deleted data on active devices, system owners must ensure cloud providers meet the organisation’s sanitisation requirements. At end-of-life, cloud devices/media must be securely decommissioned following an approved standard such as NIST SP 800-88
- Peripherally Attached Storage, Flash Memory-based Storage Devices : To sanitise externally attached HDDs, including USB and Firewire, refer to NIST SP 800-88 Guidelines for Media Sanitisation. Similarly follow NIST for flash memory based storage devices.
- Optical Media: There is no sanitisation method available for CD, DVD, and BD. They must be destroyed.
Note: This applies only to internal storage media/devices. Media/devices external to the organisation should be destroyed.
-
- USB Removable Storage Media and Memory Cards: Overwrite the media/device with at least two passes, once with one pattern, and then with its complement.
- Embedded Flash Memory on Boards and Devices: Perform a factory reset to restore the default factory settings, if supported; otherwise, destroy.
Note: Factory reset doesn’t ensure complete data erasure; data remnants may persist. If the device is supposed to be reused or resold, then acceptance must be received from the organisation’s Risk Owner.
-
- RAM, ROM, and Dynamic Random-Access Memory (DRAM): Turn off the device, disconnect it from the power source, and if it is backed by a battery, then remove the battery.
OR
Remove DRAM from the device. It must stay removed from the device for 24 hours.
-
- EAPROM and EEPROM: No sanitisation method as per the organisation’s standards is effective on these; hence, they should be destroyed.
- ‘Internet of Things’ (IoT) devices: Sanitisation or destruction must be performed prior to disposal. It should be assumed that the IoT device contains data. It should be ensured that devices are restored to default factory settings and data is irretrievable.
Subsection 1.3 explains the security measures that need to be considered when performing the destruction of storage media and devices.
- Reference 11.3.1 - The media/device type must be identified, and it should be decided if:
- Sanitisation should be performed on the media/device prior to destroying it
- Destruction of media/device should be carried out directly
- The media or device that cannot be effectively sanitised should be destroyed physically. It should be reduced to a particle size of 6mm or less, which should be verified post-destruction. The certificate of destruction must contain the details of the attained particle size.
- Reference 11.3.2 - Either a new record must be created or the record status of the destruction activity must be updated in the asset inventory or the CMDB.
- Reference 11.3.3 – The record must include whether the destruction was performed by internal staff, the manufacturer, or a third-party service provider like an ITAD.
- Reference 11.3.4 – An appropriate destruction method must be detected and utilized in accordance with the security classification of data.
- Reference 11.3.5 - Records of sanitisation destruction, in addition to appropriate certificates, must be retained according to the requirements of the organisation’s Information Management Policy.
- Reference 11.3.6 - The asset inventory or the CMDB must be updated to reflect the status of the media or device.
- Reference 11.3.7 - Below are listed the destruction methods that should be followed at the very least:
Note: Only the NCSC (CAS-S) Scheme must be engaged to destroy the organisation’s media or device. For devices or media not listed below, the organisation must seek advice.
-
- Networking Devices: Shred, disintegrate, incinerate, or pulverize the routers, switches, etc., by burning them in an incinerator.
- Mobile Devices: Shred, disintegrate, incinerate, or pulverize, etc., smartphones including iPhones, Google Android OS Devices, Windows Phones, PDAs, and tablets by burning them in an incinerator.
- Office Equipment: Shred, disintegrate, incinerate, or pulverize the printers, fax, and multi-function devices by burning them in an incinerator.
- Magnetic Media: Either shred the reel and cassette format magnetic tapes or incinerate them by burning them in a licensed incinerator. Shred, disintegrate, incinerate, or pulverize the ATA Hard Disk Drives (HDDs)1 and SCSI HDDs2 by burning them in an incinerator.
1 includes PATA, SATA, eSATA, etc.
2 includes Parallel SCSI, Serial Attached SCSI (SAS), Fibre Channel, USB Attached Storage (UAS), and SCSI Express
- Peripherally Attached Storage: Shred, disintegrate, incinerate, or pulverize the externally locally attached HDDs, including USB, Firewire, etc., by burning them in an incinerator.
- Optical Media: Destroy CDs, DVDs, and BDs in order of precedence:
- Use a commercial optical disk grinding device to remove data-bearing CD
- Use optical disk shredders or disintegrators to reduce optical disk media to particles with dimensions of 0.5 mm and a surface area of 0.25 mm² or smaller.
- Flash Memory-based Storage Devices (including IoT devices): Shred, disintegrate, incinerate, or pulverize the following by burning them in an incinerator.
Subsection 1.4 elaborates on the security requirements of media or devices prior to their sanitisation or destruction.
- Reference 11.4.1 - The storage media or device must be stored securely in accordance with the security classification of stored data, the organisation’s Security Classification Policy, and the Physical Security Policy.
- Reference 11.4.2 - If there is a requirement of transportation to an external location, records should be maintained in detail with storage media, manufacturer, serial number, etc.
- Reference 11.4.3 – The organisation must approve any third party hired.
- Reference 11.4.4 – When relocating storage media or devices, the organisation must be contacted for permission. This should also be documented.
- Reference 11.4.5 – Media or devices with residual data should not be stored for the long term. If required, a risk should be raised and approved by an appropriate Senior Risk Owner (SRO). The organisation must be informed by the suppliers in case this is required.
Subsection 1.5 describes the activities that the third IT Asset Disposal (ITAD) suppliers must ensure.
- Reference 11.5.1 – Prior to taking service, it must be ensured that the ITAD suppliers are Assured Service Providers under the NCSC CAS-S Scheme and approved by the organisation.
- Reference 11.5.2 – Organisations must be assured that ITADs can provide secure transportation for safe pickup and drop-off with an asset tracking mechanism. They must provide a certificate of sanitisation for every asset wiped or destroyed whether done onsite or offsite. Quality assurance or third-party accreditations such as ISO 27001 should also be checked.
Subsection 1.6 elucidates the responsibilities of third-party ITAD suppliers.
- Reference 11.6.1 – Third party ITADs must provide secure collection and transportation services according to the organisation’s Security Classification & Physical Security Policy.
- Reference 11.6.2 – Third party ITADs must store storage media and devices safely prior to sanitisation and destruction as per company policy.
- Reference 11.6.3 – A register of storage media processes must be maintained by third party ITADs.
- Reference 11.6.4 – Certification of sanitisation must be made available to the organisation by third party ITAD suppliers.
- Reference 11.6.5 – Accredited auditors must be used by third party suppliers to conduct audits of sanitisation and/or destruction.
- Reference 11.6.6 – The organisation must be assured by third party ITAD suppliers that the sanitisation and/or destruction equipment is regularly reviewed and maintained.
- Reference 11.6.7 – According to the Authority’s Security Vetting Policy, third party suppliers must ensure that the vetted personnel are utilized in terms of handling, transportation, and sanitisation or destruction.
Section 12 has Appendices A to H. For the relevance of the article, only the first three are discussed. Appendix A elaborates on security outcomes that are achieved due to the contribution of minimum-security standards. Appendix B lists the media devices in scope. Appendix C lists the criteria for sanitisation and destruction certificates.
The certificate of sanitisation should have:
- Device/media manufacturer/hardware model/type
- Serial number
- Source of media
- Type & Method of sanitisation – Clear, Purge, (SE, CE, Overwrite) and Destroy (Degauss)
- Sanitisation tool with version
- Method of verification
For sanitisation and validation:
- Name of the personnel who performed the activity
- Job role, Location
- Date and time of process completion
- Contact details
Signature field for personnel who performed the activity:
- Confirm if an electronic signature is used and ensure an appropriate electronic signature process is in place
- Confirm if a handwritten signature is required
If remote wiping is undertaken, take into account:
- Device location
- Location of erasure tool/software
- Location of erasure operator
Achieving Compliance with Secure Sanitisation & Destruction Standard
Organisations can comply with SS-036 by:
- Identifying the devices/IT assets that are no longer in use and sanitising them at the earliest; onsite, offsite, or with the support of an ITAD service provider
- Ensuring that data-bearing devices are sanitised before they are moved out of a controlled environment
- Sanitising storage media with methods effective for their media type and according to the applicable media sanitisation standards and guidelines
- Maintaining a secure chain of custody along with retaining sanitisation reports
- Training internal and external employees on sanitisation to equip them with the knowledge required to safeguard data before and during sanitisation
SS 036 also suggests a few methods to verify compliance with it, which include an independent external audit and control tests performed by security teams. The test results are shared with the risk and system owners of the organisation.