When a government agency hires an outside company to destroy confidential records, hard drives, evidence, or other sensitive material, that material leaves the agency’s direct control before it is destroyed.
The RFP needs to account for that period. Who picks up the material? How is it secured in transit? Where is it destroyed? Does another company ever take custody? What records will the agency receive afterward?
Answering those questions before bids are submitted makes it easier to compare vendors on more than price and pickup schedules. For government agencies in New England and elsewhere, the evaluation should cover independent certification, chain of custody, destruction methods, reporting, subcontracting, capacity, and downstream handling.
1. Start With Independent Certification
Terms such as “secure,” “compliant,” and “confidential” do not tell a procurement officer much about how a vendor actually operates. Independent certification provides a standard that can be verified.
i-SIGMA’s NAID AAA Certification applies specifically to secure information destruction providers. Certified providers are subject to scheduled and unannounced audits covering areas such as employee screening, access controls, operational security, destruction equipment, and documented procedures.
For government procurement, NAID vendor selection gives buyers an independent qualification to include in the RFP rather than relying only on a bidder’s description of its security practices.
We have maintained NAID AAA Certification since 2008. Certification does not replace the agency’s own requirements. The bidder still needs to show that the proposed service meets the scope of work.
RFP question: Is the facility performing the proposed destruction currently NAID AAA Certified for the services and media types included in this contract?
2. Require a Documented Chain of Custody
Destruction may happen quickly. The material can spend much longer being collected, loaded, transported, received, and staged for destruction. Those steps need controls of their own.
A documented data destruction chain of custody should cover collection, transfer, transportation, receipt, destruction, and final verification. Depending on the contract, controls may include locked containers, authorized personnel, vehicle security, GPS tracking, facility access restrictions, signatures, container counts, and asset-level tracking.
A pickup receipt confirms that material was collected. It does not, by itself, document who controlled the material afterward or when destruction occurred.
RFP question: Describe the chain of custody from agency pickup through final destruction, including transportation security, custody transfers, facility controls, and the records created at each stage.
3. Define the Destruction Method by Material Type
Government destruction contracts often include more than paper.
Hard drives, SSDs, backup media, identification cards, confiscated products, obsolete equipment, and other materials may all contain information or identifying details that should not remain recoverable.
The RFP should identify these materials and require the bidder to state how each will be handled. The appropriate method should reflect the agency’s own media sanitization or destruction requirements, the type of material involved, and whether the device or media is intended for reuse or final disposition.
For electronic media, sanitizing a device for reuse is different from physically destroying media at final disposition. Our comparison of hard drive destruction methods explains the practical differences among wiping, degaussing, and shredding.
RFP question: What sanitization or destruction method will be used for each material type included in the contract, and where will that work take place?
4. Specify the Documentation Before Bids Are Submitted
If an agency needs serial numbers, quantities, service locations, or other detailed records, those requirements belong in the RFP.
A Certificate of Destruction documents completion of a destruction service. Depending on the agency and material involved, additional records may include destruction dates, quantities, container counts, service locations, serial numbers, barcodes, or witness information.
For hard drives and other inventoried assets, serial-number reporting can allow the agency to reconcile destroyed devices against its own asset records.
These requirements are difficult to add after the fact. Once a device has been destroyed, missing serial-number information cannot simply be recreated.
Authorization also needs to remain separate from proof of destruction. A Certificate of Destruction documents the completed service. It does not establish that the agency had authority to destroy the records or property. Retention schedules, legal holds, preservation requirements, and internal approvals need to be addressed before material is released.
RFP question: What documentation will be provided after destruction, and can reporting include serial numbers, barcodes, quantities, dates, locations, or other agency-required information?
5. Ask Who Will Actually Handle the Material
Subcontracting should be addressed directly in a data destruction RFP checklist.
If the bidder picking up confidential material sends it somewhere else for destruction, the agency has another custody transfer to account for. The RFP should establish whether that is permitted and, if it is, require the bidder to identify the subcontractor and explain the controls that apply.
Downstream recycling is different. A recycling operation receiving material after confidential information has been securely destroyed is not in the same position as a subcontractor receiving intact records or data-bearing devices.
The agency should know where destruction occurs and at what point the resulting material can leave the secure destruction process.
RFP question: Will any subcontractor or other provider take custody of intact confidential or data-bearing material before destruction? If so, identify the provider, its role, and the controls governing that transfer.
6. Match Vendor Capacity to the Contract
A routine records pickup and a multi-location agency cleanout are very different jobs.
The vendor evaluation criteria should reflect the work the agency actually expects the contractor to perform. Relevant factors may include service territory, transportation capacity, destruction equipment, secure staging capacity, scheduling, multi-location coordination, and witnessed destruction.
Mixed-material projects also need to be considered. A technology refresh, facility closure, or records cleanout could involve paper files, hard drives, badges, electronic media, and other sensitive materials at the same time.
A vendor that can handle those materials within one controlled process can reduce handoffs and make the resulting documentation easier to reconcile.
RFP question: Describe your capacity to support the expected volume, locations, material types, scheduling requirements, and any witnessed destruction requirements included in this contract.
7. Define What Happens After Destruction
Secure destruction and recycling are separate steps.
Until confidential information has been destroyed, the material remains within the secure destruction process. Once that information is no longer recoverable, eligible material can move into an appropriate recycling stream.
The RFP should make that transition clear. Agencies should know when secure custody ends, how recyclable material is handled after destruction, and whether downstream providers are involved.
We can coordinate eligible material with our recycling arm after secure destruction. Keeping those functions coordinated can reduce unnecessary handoffs while maintaining a clear separation between confidential material and commodities that are ready for downstream recycling.
RFP question: Describe what happens to material after secure destruction, including downstream recycling and any disposition documentation available to the agency.
Government Data Destruction RFP Checklist
Before awarding a contract, confirm:
- Is the destruction provider currently NAID AAA Certified for the required services?
- How is chain of custody documented from pickup through final destruction?
- How are vehicles, facilities, containers, and access to sensitive material secured?
- What sanitization or destruction method will be used for each type of material?
- Where will destruction occur?
- What Certificate of Destruction and other completion records will the agency receive?
- Can the vendor provide serial-number or barcode reporting when required?
- Will a subcontractor handle intact sensitive material before destruction?
- Can the vendor meet the agency’s volume, scheduling, geographic, and multi-site requirements?
- Is witnessed destruction available when required?
- What happens to recyclable material after destruction?
- Who is responsible for each custody transfer and downstream handoff?
These questions give agencies specific vendor evaluation criteria that can be compared across bids and carried into the final contract.
Make Vendor Selection Part of the Agency’s Security Process
Vendor selection comes after the agency has determined that the material is eligible for destruction. Records schedules, legal holds, preservation requirements, and required internal approvals still apply.
Our guide to government data destruction requirements covers those issues in more detail.
Once material is approved for destruction, the contractor becomes part of the agency’s information-security process. NAID vendor selection, chain-of-custody requirements, destruction specifications, reporting, subcontractor controls, and downstream handling should all be settled before work begins.
If your agency is preparing an RFP or reviewing an existing destruction contract, contact us with the scope of work, material types, locations, and documentation requirements. We can review the proposed destruction scope and explain how our collection, chain-of-custody, destruction, reporting, and downstream recycling processes align with the requirements in your scope.
