Destroy drives on-site before they leave your custody. NSA-listed Crunch 250. NIST 800-88 Destroy alignment. 150 drives per hour. Certificate of Destruction in hand the same day.
If your data destruction policy says drives must be destroyed before they ever leave your facility, on-site hard drive crushing is the cleanest path. Excess IT Hardware brings a NSA-listed Crunch 250 hard drive crusher to your site, deforms each drive past any mechanical recovery threshold, scans serials for inventory reconciliation, and issues a per-project Certificate of Destruction. The whole crew is HIPAA-trained and background-checked. Material is removed under chain of custody and routed through an R2 Certified downstream chain to our EPA-registered processing facility (EPA ID FLR000269027) for final environmental disposition.
A single hard drive can hold years of patient records, customer payment data, employee files, and access keys. The moment it leaves your loading dock under someone else’s care, your organization is trusting a chain of custody you cannot independently verify. For some data, that risk is acceptable. For regulated data, sensitive intellectual property, or anything subject to a Business Associate Agreement, it usually is not.
On-site hard drive crushing closes that gap. The drive is removed from its host system, placed in the crusher, deformed beyond any mechanical recovery threshold, and only then leaves the building. Your authorized witness sees every drive enter the machine. The destroyed media is sealed, manifested, and removed under chain of custody for environmentally sound material recovery.
This is the operational reality behind compliance. The HIPAA Security Rule, PCI DSS Requirement 9.8, GLBA Safeguards Rule, FACTA Disposal Rule, and Sarbanes-Oxley IT general controls all require either rendering data unrecoverable or maintaining a documented chain of custody with verified destruction. On-site crushing satisfies both at once. Read the structural overview in our ITAD compliance policy.
Not all hard drive crushers are equal. Excess IT Hardware operates the Crunch 250, an NSA-listed device certified to DIN 66399 security levels H-3 (for hard drives) and E-1 (for solid-state media). Those two acronyms matter for any compliance officer evaluating the method:
NSA listing. The U.S. National Security Agency maintains an Evaluated Products List for media destruction devices. NSA listing means the device has been independently tested and confirmed to render media unrecoverable to the standard required for federal CUI handling. When the destruction method matters in an audit, this is the credential auditors look for.
DIN 66399 H-3. European standard for hard drive destruction. H-3 is the level required for personal data, financial data, and confidential business information. The Crunch 250 deforms platters and bends the spindle past the H-3 particle threshold.
DIN 66399 E-1. Same standard, applied to electronic media (chips, SSDs, USB drives). E-1 is suitable for general business data on solid-state media. Note that highly sensitive SSD data is typically routed to hard drive shredding for E-2 or higher particle sizes; we will route your SSDs to the appropriate method during scoping.
Operational throughput on the Crunch 250 is up to 150 drives per hour. For a fleet refresh of 200 drives, you are looking at under 90 minutes of crushing time on the floor, plus serial scanning and documentation.
A strong service is more than the destruction itself. It is the complete project control around it. Every Excess IT Hardware on-site crushing engagement includes:
HIPAA-trained, background-checked technicians on site. Every technician arriving at your facility has completed HIPAA security training and a current background check. Where required, an executed Business Associate Agreement is in place before the project begins. (Note: a company itself cannot be HIPAA Certified. HIPAA compliance is a function of trained personnel, executed BAAs, and documented procedures.)
Optional serial number scanning. Every drive’s serial number can be scanned at intake and matched against your IT asset list. The destruction record ties each serial to its destruction timestamp, supporting lease return audits, ticket closeout, and inventory reconciliation. Especially useful for organizations with asset tracking requirements.
Per-project Certificate of Destruction. A single audit-ready document covering every drive processed in the engagement, including method (Crunch 250 to DIN 66399 H-3 or E-1), destruction date, serial range, and operator. For organizations needing the broader Certificate package covering recycling and downstream disposition, see our Certificate of Recycling and Data Security.
Chain-of-custody handling for the destroyed material. Crushed drive material does not stay on your floor. It is sealed, manifested, and removed under the same chain of custody used at intake. Final destination is our EPA-registered processing facility (EPA ID FLR000269027) where material is routed through an R2 Certified downstream chain consistent with our zero-landfill policy.
Online reporting access. Project records are accessible through the online reporting portal for retrieval during audits, vendor reviews, or incident investigations. Records are retained for the regulatory window applicable to your industry.
On-site crushing is the right method for most platter-based hard drives and for general business data on solid-state media. For some media types, a different method is more appropriate. The honest answer matters more than upselling, so here is the breakdown:
Platter-based HDDs (3.5 inch, 2.5 inch). Crushed to DIN 66399 H-3. Suitable for personal data, financial records, healthcare records, and confidential business information. This is the primary use case.
SSDs and NVMe drives (general business data). Crushed to DIN 66399 E-1. Suitable for routine business data, employee files, mid-sensitivity records.
SSDs and NVMe drives (highly sensitive data). Routed to hard drive shredding for E-2 or higher particle sizes. The smaller particle size of shredding addresses the data-density characteristics of NAND flash memory.
Magnetic tape (LTO, DLT). Routed to our tape shredding and degaussing service. Crushing is not designed for tape media.
Drives with remaining market value where reuse is preferred. Routed to data erasure using NIST 800-88 referenced overwrite methods with verification. Once sanitized, drives can re-enter service or be remarketed.
On-site erasure where physical destruction is not required. See on-site hard drive erasure for in-place sanitization that preserves the drive for redeployment.
NIST SP 800-88 Rev. 1 (Destroy category). NIST 800-88 defines three sanitization categories: Clear, Purge, and Destroy. On-site crushing maps to the Destroy category, which NIST defines as physical destruction such that the media cannot be reused or rebuilt. The Crunch 250 satisfies this definition for HDDs and SSDs at the DIN 66399 H-3 and E-1 thresholds respectively.
HIPAA Security Rule (45 CFR 164.310(d)(2)(i) and (ii)). Requires policies and procedures for the final disposition of ePHI and the hardware on which it is stored. Physical destruction with documented verification is one of the recognized methods. HIPAA-trained technicians and executed BAAs round out the operational compliance posture.
PCI DSS Requirement 9.8. Mandates rendering cardholder data unrecoverable when media is no longer needed. Crushing to DIN 66399 H-3 satisfies the unrecoverable threshold for platter-based media.
GLBA Safeguards Rule. Financial institutions must protect non-public personal information through asset retirement. Documented destruction is part of the Safeguards Rule program documentation.
FACTA Disposal Rule. Anyone handling consumer report information must take reasonable measures during disposal. Verified physical destruction is the operative reasonable measure.
Sarbanes-Oxley (SOX). Public companies retiring servers, workstations, and storage that touched financial systems need documented destruction tied to the IT general controls audit. Per-asset destruction records support that testing.
DoD 5220.22-M (historical reference). Where contracts or internal policies still cite the older DoD overwrite standard, software data erasure methods are available alongside crushing for projects that mix erasure with physical destruction.
Many organizations use more than one method across different asset categories. The decision usually comes down to four questions: data sensitivity, drive type, lifecycle goal, and policy mandate. Use this table as a starting point. We can confirm fit during project scoping.
Method | Best For | Drive Outcome | Standard Reference |
Crushing | On-site destruction before drives leave custody. Platter HDDs. General SSDs. | Drive deformed, unusable, unrecoverable | DIN 66399 H-3 / E-1, NIST 800-88 Destroy |
Shredding | Highly sensitive SSDs. Mixed media. Smaller particle requirements. | Drive reduced to small particles | DIN 66399 H-4 to H-7, NIST 800-88 Destroy |
Erasure | Drives with remaining market value. Reuse or remarketing path. | Drive sanitized, fully functional | NIST 800-88 Clear or Purge, DoD 5220.22-M |
Degaussing | Magnetic media (LTO tape, legacy magnetic drives). | Magnetic field disrupted, drive non-functional | NIST 800-88 Purge |
Excess IT Hardware supports projects beyond a single city or region. The hard drive crushing page highlights global reach, noting support whether you have a single hard drive in Topeka, Kansas or 1,000 drives in Kuala Lumpur.
In addition, Excess IT Hardware offers nationwide service and nationwide pick up across South Florida and outside South Florida, including outside South Florida repair service where applicable.
At the end of every project, location should never be a limitation.
Step 1: Site walkthrough and staging.
Our technicians arrive at the agreed time with the Crunch 250 and ancillary equipment. We confirm the staging area, witness arrangements, and any badge or escort requirements. If your team has pulled drives in advance, we move directly to scanning. If drives are still in chassis, we proceed with removal.
Step 2: Drive removal from host systems (if needed).
Drives are extracted from laptops, desktops, servers, copiers, multi-function printers, and any other host system in scope. Each drive is bagged and tagged with its source asset ID.
Step 3: Serial scan and intake (optional but recommended).
Each drive’s serial number is scanned and entered into the destruction record. This is the moment your IT asset list gets closed out, with a serial-to-destruction-record mapping you can hand to auditors.
Step 4: Crushing.
Drives are loaded into the Crunch 250 one or several at a time depending on form factor. Each drive is deformed to DIN 66399 H-3 (HDDs) or E-1 (SSDs). Throughput up to 150 drives per hour. Your authorized witness can observe every cycle if your policy requires.
Step 5: Material removal and documentation.
Crushed drives are sealed and manifested for transport. Certificate of Destruction is issued at project close, covering every serial processed. Records are uploaded to the online reporting portal for future retrieval.
Yes. The Crunch 250 deforms platters and the spindle past any commercial recovery threshold and is NSA-listed for that destruction outcome. The result satisfies DIN 66399 H-3 for platter-based hard drives and NIST SP 800-88 Rev. 1 Destroy category. For SSD or NVMe media holding highly sensitive data, organizations with strict policy can route those drives to hard drive shredding for smaller particle sizes (E-2 or higher).
Up to 150 drives per hour on the Crunch 250 for platter-based HDDs. A typical 200-drive office refresh runs under 90 minutes of crushing time, plus serial scanning and documentation. Larger projects (1,000-plus drives) are scoped with multi-day windows or additional units depending on site logistics.
Yes, optionally. Each drive’s serial number is scanned at intake and entered into the destruction record. The record ties every serial to its destruction timestamp, so your IT team can match destroyed drives to your asset list, close out tickets, document lease return compliance, and hand auditors a serial-to-destruction-record mapping.
Yes, to DIN 66399 E-1, suitable for routine business data on solid-state media. For highly sensitive SSD data, our standard recommendation is to route those drives to hard drive shredding for E-2 or higher particle sizes. We will confirm the right method for your specific data classification during project scoping.
We remove it under chain of custody by default. The crushed material is sealed, manifested, and transported to our EPA-registered processing facility (EPA ID FLR000269027) where it routes through an R2 Certified downstream chain consistent with our zero-landfill policy. If your internal policy requires you to retain the crushed material, we can document that handoff at project close instead.
HIPAA, PCI DSS, GLBA, SOX, FACTA, NIST SP 800-88, DIN 66399, and DFARS for federal contractors. The Certificate of Destruction cites the standards relevant to the engagement so the document maps directly to your audit framework.
Yes. Witnessed destruction is the default for healthcare and financial services projects. Your authorized witness sees every drive enter the Crunch 250 and signs the destruction record at project close. Some organizations also record video of the witnessed crushing for their internal records.
Crushing deforms each drive past mechanical recovery (DIN 66399 H-3 for HDDs, E-1 for SSDs). Shredding reduces drives to small particles (DIN H-4 through H-7 depending on shredder spec). Crushing is faster and produces less waste volume. Shredding produces smaller particles for higher-sensitivity data, especially SSDs. Many organizations crush HDDs and shred SSDs from the same project.
Project ID, client name, destruction date, destruction method (Crunch 250 to DIN 66399 H-3 or E-1, NIST 800-88 Destroy), serial range, drive count, operator name, and witness name where applicable. The certificate is a single audit-ready document covering every drive in the engagement.
Standard scheduling is 7 to 14 days for routine projects. Time-sensitive projects (office closure, lease return deadline, breach response) can be accelerated to within 48 to 72 hours where logistics permit. Reach out with your timeline and we will confirm.
Drive risk does not need to be a months-long project. On-site hard drive crushing eliminates the chain-of-custody question, satisfies your destruction policy, and produces the documentation your audit framework expects, all in a single visit.
Planned project: schedule a pickup online and a project specialist responds within one business day.
Time-sensitive: call (561) 600-8656 directly. Same-business-day response on accelerated projects.
Evaluating vendors: talk to a specialist for a scoping conversation. We will walk through your data classification, drive count, site logistics, and the destruction method that fits, then send a written quote.