For medium and high-sensitivity backups, LTO cartridges need to be physically destroyed through incineration or melting, or cryptographically purged under verifiable, documented conditions. Ad-hoc shredding and simple degaussing rarely meet the bar on their own. Whatever method you choose, pair it with a chain-of-custody record and a serialized certificate of destruction, because an unreadable tape is not the same as a sanitized one.
TL;DR:
- Degaussing is considered a purge method and is unreliable for high-sensitivity tapes; physical destruction remains essential.
- Shredding and pulverizing often leave recoverable data, making them inadequate for medium or high-security requirements.
- Incineration, melting, and smelting offer the highest assurance but require vetted vendors and proper environmental handling.
- A thorough destruction process includes verifying tape eligibility, documenting custody, using specific methods, and obtaining serialized certificates.
- An effective workflow mandates detailed record-keeping, immediate reconciliation, and clear vendor specifications to ensure compliance and audit readiness.
Table of Contents
- How to match tape sensitivity to the right sanitization outcome
- Method-by-method evaluation of destruction techniques
- Building an audit-ready destruction workflow
- Choosing between on-site and off-site destruction, and what to put in your RFP
- What a defensible certificate of destruction needs to contain
- Practitioner perspective: where destruction jobs actually go wrong
- Why “secure enough” destruction isn’t the same as defensible destruction
- Audit-ready tape destruction when you need it done right
- FAQ
- Sources
How to match tape sensitivity to the right sanitization outcome
Before you pick a destruction method, you need to know which sanitization category your data requires. NIST SP 800-88 Revision 2 defines three outcomes: clear, purge, and destroy, each tied to how much residual risk is acceptable once the media leaves your control.
Clear removes data through standard read/write commands and suits low-risk, internally reused media. Purge uses techniques that resist laboratory-level recovery attempts, and under the current revision, degaussing legacy tape media falls into this purge category rather than destroy. Destroy is reserved for cases where the media itself is physically rendered unusable through methods like incineration or melting, and it applies to medium and high-security data where any residual risk is unacceptable.
Cryptographic erase is a separate path worth considering for tape specifically. It only works when encryption was active at the time of writing and your organization still controls the keys; destroying or revoking the key renders the data unreadable without needing to touch the physical cartridge. This shortcut fails quietly if encryption was added after some backups were already written in the clear, so verify key management history before relying on it.
Before authorizing any destruction, run through a short decision checklist:
- Confirm the cartridge is outside any retention schedule or legal hold.
- Classify the data by sensitivity tier, not just by backup age.
- Determine whether cryptographic erase preconditions (encryption plus key control) are actually met.
- Decide what evidence you will require: certificate only, witnessed destruction, or lab-validated sampling.
Skipping this step is the most common reason organizations end up destroying tapes still under hold, or applying a purge-level method to data that needed full destruction.
Method-by-method evaluation of destruction techniques
Each physical destruction method carries different assurance levels, and procurement documents should specify exactly which one you require rather than leaving it to a vendor’s default process.
Degaussing exposes a cartridge to a strong magnetic field to disrupt the data pattern on the tape. It can render older tape formats unreadable, but modern LTO media uses coercivity levels that make reliable degaussing harder to verify, and NIST SP 800-88 Revision 2 now treats degaussing as a purge technique rather than an approved destroy method. Use it as a precaution before shredding, not as a standalone destroy solution for sensitive data.
Shredding and pulverizing cut or crush cartridges into fragments. Specs vary by vendor, but the practical issue is data density: LTO cartridges pack enough data per square millimeter of tape that larger fragments can still contain recoverable sequences. The NIST SP 800-88r2 FAQ is direct about this, noting that shredding and pulverizing are generally inadequate for anything beyond the lowest sensitivity categories.

Incineration, melting, and smelting reduce the cartridge and tape to raw material, which is why standards treat these as the highest-assurance destroy options. The tradeoff is environmental handling: these processes require permitted facilities and documented disposal of residual materials, so they’re better suited to batch processing through a vetted vendor than to in-house equipment.
Manual and ad-hoc methods (cutting tape by hand, physically smashing cartridges) have a narrow, defensible use case: very small quantities, low sensitivity, and documented supervision. Beyond a handful of cartridges, the lack of consistent verification makes these methods hard to defend in an audit.
Two-step processes, typically degauss followed by shred, are often appropriate for medium-sensitivity data where you want belt-and-suspenders assurance without full incineration. The limitation is that even combined, these methods don’t reach the verifiability of destroy-grade incineration for high-sensitivity categories; they reduce risk, but they don’t eliminate the sampling uncertainty inherent to fragment-based destruction.
Pro Tip: Specify the destruction method by name and standard reference in your service agreement, not just “secure destruction,” so there’s no ambiguity about what assurance level you purchased.
Building an audit-ready destruction workflow
A defensible destruction job follows the same sequence every time, regardless of volume: inventory, approval, custody, destruction, and reconciliation.
- Pull a current inventory of the cartridges slated for destruction and check each against retention schedules and any active legal holds.
- Scan or log barcodes for every cartridge before it leaves its storage location.
- Record the custody handover: who released the media, who received it, and the exact timestamp.
- Use locked, tamper-evident containers for transport, whether the destruction happens on-site or off-site.
- Decide whether destruction will be witnessed in person, recorded on video, or both.
- Collect a serialized certificate of destruction immediately after the job, before the vendor leaves or the on-site unit is powered down.
- Reconcile the certificate’s media list against your original inventory the same day, while discrepancies are still easy to trace.
Catalogic’s guidance on tape disposal reinforces a point worth repeating: confirming retention status and keeping a scanned inventory matters as much as the destruction method itself, because most compliance failures trace back to process gaps, not equipment failures.
| Record field | Why it matters |
|---|---|
| Media serial/barcode ID | Confirms the specific cartridge destroyed matches your inventory |
| Destruction method and equipment | Ties the job to a specific NIST sanitization category |
| Operator name and employer | Establishes accountability and chain of custody |
| Date and time of destruction | Anchors the record for audit timelines |
| Certificate ID | Lets you cross-reference the job in future audits |
Choosing between on-site and off-site destruction, and what to put in your RFP
On-site destruction makes sense when you have a large volume of cartridges, strict chain-of-custody requirements, or data that cannot legally leave your premises before sanitization. Off-site destruction can be more cost-effective for smaller batches, provided the vendor’s transport and custody controls are documented and verifiable. Volume, sensitivity, and your internal tolerance for media leaving the building should drive this decision more than price alone.
Whichever model you choose, your RFP should force vendors to answer specific questions rather than make general claims:
- What exact method and equipment will be used, and does it match our required sanitization category?
- Can you provide a sample certificate of destruction with all required fields filled in?
- What insurance and environmental or hazardous-waste permits do you carry for the destruction method used?
- Will destruction be witnessed, video recorded, or both, and is that included in the base price?
- How do you handle chain-of-custody during transport, and can we review your transport security controls?
Treat a few responses as outright red flags: a vendor who can’t produce a sample certificate, one who markets itself as “NIST-certified” (NIST doesn’t certify vendors, it publishes guidelines), or one who is vague about what happens to residual material after incineration or shredding.
What a defensible certificate of destruction needs to contain
A certificate is only useful as audit evidence if it ties back to a specific, verifiable event rather than a generic statement that “destruction occurred.” At minimum, require these fields:
- Media identifiers (serial numbers or barcodes) for every cartridge destroyed.
- Method and equipment used, stated specifically enough to map to a NIST sanitization category.
- Operator name, destruction date and time, and a unique certificate ID for later reference.
Verification options scale with sensitivity. Witnessed destruction (in person or by video) works for most medium-sensitivity jobs. For high-sensitivity data, consider sample laboratory validation or vendor-supplied equipment test reports confirming the destruction equipment meets its stated specification. NIST’s SP 800-88r2 FAQ is explicit that unreadability alone does not equal sanitization, which is exactly why the certificate’s method field matters more than a vendor’s assurance that the tape “can’t be read anymore.”
Practitioner perspective: where destruction jobs actually go wrong
Most destruction failures aren’t technical, they’re procedural. Inventory gets lost between the backup system and the physical media room, so nobody can confirm which cartridges were actually destroyed versus simply missing. Certificates arrive vague, listing a quantity and a date but no serial numbers, which makes them useless if a regulator asks for proof a specific tape was sanitized.
Scheduling witnessed destruction around actual business need, rather than batching it quarterly regardless of volume, keeps custody gaps shorter. When discrepancies surface after the fact (a tape listed as destroyed that turns up in a backup catalog, for instance), reconcile immediately rather than waiting for the next audit cycle; the paper trail is easiest to rebuild while the people involved still remember the job.

Why “secure enough” destruction isn’t the same as defensible destruction
The conventional advice on this topic treats destruction as a single event: shred the tapes, get a piece of paper, file it away. That misses the point. A certificate without serialized media IDs is not meaningfully different from no certificate at all, and a vendor’s marketing claim of “NIST compliance” means nothing without a documented process behind it.
What’s underrated is the inventory step. Organizations spend far more energy evaluating shredder specs than they spend verifying that the cartridge list handed to a vendor actually matches what left the building. That mismatch is where audits get uncomfortable, not in the destruction method itself.
If you take one thing from this guide, prioritize matching your sanitization category to your actual data sensitivity before you shop for a method. A high-assurance destroy process on low-risk tapes wastes money; a purge-level process on high-sensitivity tapes creates risk you can’t see until someone asks for proof.
— Keith
Audit-ready tape destruction when you need it done right
We provide on-site data destruction services that include documented chain-of-custody, serialized certificates, and processes aligned with the sanitization category your data requires; learn more about removal steps for U.S. clinics.

Reach out when you’re dealing with a large batch of retired LTO cartridges, when your compliance team requires witnessed destruction, or when you need a vendor who can answer RFP questions about method, equipment, and certificate fields without hedging. We also handle broader IT asset recovery and e-waste recycling, so a single engagement can cover tape destruction alongside retired hardware.
- Onsite destruction is scheduled in accordance with your volume and witness requirements.
- We provide certificates of destruction with serialized media identifiers for each job, matching your media inventory.
- We offer service options covering tape, hard drives, and other retired IT assets that can be handled in one visit.
Start with our onsite data destruction page to request a quote and get a process that holds up when someone asks for proof.
FAQ
What is the best way to destroy old VHS tapes?
VHS tapes carry the same general risk profile as other magnetic media, so the same purge-versus-destroy logic applies based on what was recorded. For most personal or low-sensitivity VHS content, degaussing followed by physical destruction is sufficient, while higher-sensitivity recordings warrant full physical destruction through shredding or incineration.
Can LTO 6 drive read LTO 4 tapes?
LTO drives are generally backward compatible by two generations for reading and one generation for writing, so an LTO 6 drive can typically read LTO 4 tapes. This compatibility window matters when planning destruction, since older tapes may still be readable on newer hardware and should not be assumed obsolete by data alone.
How much does an LTO tape cost?
LTO cartridge pricing varies by generation, capacity, and vendor, and no single figure applies across the market. Check current pricing directly with a media supplier or backup hardware vendor for the generation you need.
Why are LTO tape drives so expensive?
LTO drives combine precision tape-transport mechanics, high-density read/write heads, and licensing costs tied to the LTO consortium’s technology, which keeps hardware prices well above consumer storage devices. The cost reflects the engineering needed to reliably read and write extremely high data densities across multiple backward-compatible generations.
Is degaussing enough to destroy an LTO tape securely?
Degaussing alone is no longer treated as an approved destroy method for LTO media under current federal guidance; it falls into the purge category instead. For medium- and high-sensitivity data, follow degaussing with physical destruction such as shredding or incineration to meet a destroy-level outcome.
Sources
- NIST Special Publication 800-88 Revision 2 (Guidelines for Media Sanitization)
- Old tape backup disposal: Secure destruction (Catalogic Software)