SOC 2 requires organizations to destroy data appropriately once its retention period ends, but it does not mandate one method. Acceptable approaches range from logical sanitization, including cryptographic erase, to physical destruction, depending on the media type, data sensitivity, and how well the outcome can be proven. Auditors are looking for a documented procedure, evidence tying each destruction event to a specific asset, and proof that any outsourced vendor was properly vetted.
TL;DR:
- Data destruction methods depend on media type and data confidentiality, with physical destruction used when sanitization cannot be guaranteed.
- Auditors require documented procedures, asset identifiers, destruction methods, and chain-of-custody evidence to verify irreversible data loss.
- Cloud environments, backups, and encryption keys must be included in program-level sanitization, not just physical media.
- Vendor controls should include certifications, recent audits, and evidence packages to ensure destruction meets SOC 2 standards.
- A repeatable, documented destruction workflow that inventories assets, classifies data, and captures evidence consistently is critical for audit compliance.
Table of Contents
- What SOC 2 expects from disposal controls
- Sanitization methods by media: clear, purge, cryptographic erase, and destruction
- Audit evidence: what to record for each destruction event
- Outsourcing and vendor controls for destruction
- A repeatable workflow from inventory to recordkeeping
- Why program-level sanitization beats checklist thinking
- How an on-site destruction service supports your SOC 2 evidence
- Sources
- FAQ
What SOC 2 expects from disposal controls
SOC 2 does not contain a standalone “data destruction” clause. Disposal obligations live inside the confidentiality and privacy trust services criteria, where control CC6.5 and related points ask whether an organization removes or securely disposes of confidential information and system components once they are no longer needed. The AICPA’s SOC framework is an attestation of controls mapped to these criteria, not a technical standard that names specific tools or wipe passes. That distinction matters for how you build a program.
Because SOC 2 is outcome-based, auditors care about whether the result, irreversible data loss, was achieved and documented, not which brand of software or shredder produced it. Three things typically drive the disposal decision:
- Your data retention policy, which sets when information should no longer exist.
- Any active legal hold, which can override a scheduled destruction date.
- The classification level assigned to the data, which determines how rigorous the sanitization method needs to be.
Sanitization methods by media: clear, purge, cryptographic erase, and destruction
NIST groups sanitization into a few practical categories, and matching the category to the media type is the core technical decision behind any SOC 2 disposal control. Clear methods overwrite data using standard read/write commands, and are typically sufficient for lower-sensitivity data on traditional hard drives. Purge methods, including block erase, ATA or SCSI sanitize commands, and cryptographic erase, provide stronger assurance against laboratory-level recovery attempts. Destroy methods, such as shredding, disintegration, or incineration, physically eliminate the media and are appropriate when no supported sanitize command exists or when confidentiality requirements are highest. Degaussing works for magnetic media only, and mobile devices are usually handled through a factory reset or remote wipe tied to mobile device management.
- Solid-state drives and flash media use wear-leveling, so a single-pass overwrite can miss data written to reallocated blocks.
- Cryptographic erase only works when the drive was fully encrypted from the start, key management was sound, and the key itself is verifiably destroyed.
- Destruction becomes the default when a device predates sanitize command support or when it held data at the highest confidentiality tier.
NIST’s updated guidance stresses that program-level sanitization now needs to cover logical environments, not just physical drives. SP 800-88 Rev. 2 makes explicit that cloud deletion, backups, replicas, and encryption key destruction all belong in the same sanitization program as physical media, since a shredded drive means little if an unencrypted backup of the same data survives elsewhere. Our guide to SSD-specific destruction covers the purge-versus-shred decision in more depth for flash media specifically.
Audit evidence: what to record for each destruction event
A SOC 2 Type II examination tests whether controls operated consistently over a period of time, so a single certificate of destruction rarely satisfies an auditor on its own. Guidance from Studentprivacy on data destruction best practices outlines the record fields that should accompany every event.
- Asset identifier and its assigned confidentiality classification.
- The approved procedure and the sanitization method actually used.
- Operator or vendor name, along with date and time of the event.
- Chain-of-custody documentation from removal through final disposition.
- Validation result confirming the method worked, plus any exceptions noted.
Each record should cross-reference the retention schedule that triggered disposal and confirm no legal hold applied to that asset. Validation itself usually comes from a sample of destroyed media checked against tool logs, vendor certificates, or in-house verification, and that validation evidence needs to be retained alongside the destruction record, not just the certificate.
Outsourcing and vendor controls for destruction
Most organizations do not destroy media in-house, and outsourcing does not remove the organization’s own responsibility for the outcome. The FTC’s Disposal Rule requires businesses handling consumer-report information to take reasonable measures to dispose of it, and its guidance recommends reviewing a contractor’s independent audits, certifications, and references before signing a contract.
- Confirm the vendor’s certifications and ask for evidence of recent independent audits, not just a marketing claim.
- Require contract language covering method, chain-of-custody, audit access, and how long evidence records are retained.
- Consider on-site or witnessed destruction for the highest-sensitivity assets rather than relying on a certificate alone.
A certificate with no asset identifier, no method detail, and no chain-of-custody attached is a red flag that should trigger a follow-up before the next batch ships out.
Pro Tip: Ask any destruction vendor for a sample evidence package before you sign, not after your first shipment.

A repeatable workflow from inventory to recordkeeping
Treating destruction as a recurring process, rather than a one-time cleanup, is what makes it survive an audit year after year.
- Inventory everything, including physical media and logical locations such as backups, snapshots, and cloud replicas, since a device audit alone misses the copies stored elsewhere.
- Classify by confidentiality and map each classification to the minimum sanitization strength it requires, whether that is clear, purge, or destroy.
- Select the method and schedule, checking for active legal holds and deciding whether the asset gets reused after sanitization or sent for physical destruction.
- Execute and capture evidence, using a standard template so the operator or vendor records the identifier, method, date, and chain-of-custody at the moment of destruction.
- Verify through sampling, escalate any exceptions immediately, and update the asset inventory and retention records so the next audit cycle starts clean.
Our step-by-step guide to certified hard drive destruction walks through steps three and four in more operational detail, and the broader overview of auditable disposal methods is useful for building the recordkeeping side of this workflow from scratch.
Why program-level sanitization beats checklist thinking
Treating data destruction as a recurring checkbox misses the point. A documented program, one that inventories logical copies, validates every batch, and tracks recoverable asset value alongside compliance, holds up under repeat audits in a way a one-time wipe never will. Witnessed, on-site destruction with a certificate tied to an asset ID removes most of the friction auditors raise about chain-of-custody gaps.
— Keith
How an on-site destruction service supports your SOC 2 evidence
Auditors respond well to destruction that happened where they can trace it, and that is the gap Onsite Data Destruction from Usedcartridge is built to close. Witnessed on-site destruction, operator logs, and certificates tied to each asset give a compliance team the chain-of-custody documentation SOC 2 examiners ask for, without waiting on a third-party facility to mail back paperwork.

Usedcartridge provides on-site destruction services and supports payment for recoverable IT assets. For a closer look at how the destruction and certification process fits into a broader disposal strategy, see Hard Drive Destruction or request a quote for your next asset disposition.
Sources
- SP 800-88 Rev. 2, Guidelines for Media Sanitization
- Disposal of Consumer Report Information and Records (FTC)
- Studentprivacy
- AICPA SOC reports flyer
FAQ
Is SOC 2 legally required?
SOC 2 is not a law. It is a voluntary attestation that many customers, partners, and contracts require as proof that a service organization’s controls, including data disposal, meet an accepted standard.
What is SOC 1 and SOC 2 and SOC 3?
SOC 1 covers controls relevant to a client’s financial reporting, while SOC 2 covers security, availability, processing integrity, confidentiality, and privacy controls under the AICPA’s trust services criteria. SOC 3 is a shorter, public-facing summary of a SOC 2 report meant for general distribution.
Does SOC 2 mean HIPAA compliant?
No. SOC 2 and HIPAA are separate frameworks with different scopes, and a SOC 2 report does not by itself demonstrate HIPAA compliance, though the confidentiality controls it evaluates often overlap with HIPAA’s safeguards.
What does SOC 2 stand for?
SOC 2 stands for System and Organization Controls 2, an attestation framework from the AICPA that evaluates a service organization’s controls against the trust services criteria, including confidentiality and privacy.
What counts as acceptable evidence of data destruction for an audit?
Auditors generally expect a record linking each destroyed asset to its identifier, classification, method used, operator or vendor, date, chain-of-custody, and validation result, not just a certificate. Missing fields, such as no asset identifier or no validation step, are common reasons evidence gets rejected during review.