Ask ten IT managers what ISO 27001 hard drive destruction means and most will describe a shred size. Six millimetres. Two millimetres. Whatever the last supplier quoted.
The standard specifies no millimetres. Not one number.
ISO 27001 does not provide a specification to buy against. It requires you to demonstrate that you decided how far destruction needed to go, that you can justify why, and that you hold the records to evidence it. Auditors examine the paper trail behind your storage devices at least as closely as the devices themselves.

What ISO 27001 Hard Drive Destruction Requires
The 2022 revision distributes the requirement across several Annex A controls.
Control 7.14, secure disposal or re-use of equipment. Equipment holding storage media must be verified before leaving service, so sensitive information and licensed software are removed, overwritten or destroyed. Asset tags identifying your organisation should also be removed.
Control 7.10, storage media. A documented approach to media across its lifecycle, disposal included, proportionate to the sensitivity of its contents.
Control 8.10, information deletion. Information is deleted when no longer required, in a manner that leaves it unrecoverable.
Control 5.9, inventory of assets. This causes more audit findings than the others combined. A drive on your asset register with no matching destruction record is an unarguable gap.
Controls 5.19 to 5.22, supplier relationships. Once you appoint a hard drive destruction service, their process becomes your risk. Your agreement must specify what they will do, and you must monitor whether they do it.
Read together: deletion alone is insufficient, physical destruction applies where reliable erasure cannot be achieved, and the method must match data sensitivity.
Shred Sizes: Where the DIN 66399 Levels Come From
Since ISO 27001 sets no dimension, the industry adopted one. Almost every quote for a hard drive shredding service is priced against DIN 66399, published internationally as ISO/IEC 21964.
That standard grades destruction from level 1 to 7 across media classes. Magnetic hard disks fall under H, solid state devices under E, paper under P, which is why the same framework governs security document destruction.
For magnetic disks, H-4 caps particle area at 2,000 mm² for sensitive commercial data. H-5 tightens this to 320 mm², covering most personal, financial and health records. H-6 reaches 10 mm² and H-7 5 mm² for classified material.
Solid state media runs a separate scale because NAND chips behave nothing like platters. E-3 allows 160 mm². E-4 cuts this to 30 mm², the common commercial baseline for SSDs. E-5 reaches 10 mm² where personal or financial data is involved.
Most UK contracts settle on H-5 for spinning disks and E-4 or E-5 for solid state. That is a default rather than a rule. Where clients approach Total Shred without a stated level, we work backwards from the classification of the data rather than quoting a level and letting price decide.
BS EN 15713:2023 is the European code of practice for physical destruction of confidential material, aligned to GDPR and ISO/IEC 27001, and it deliberately excludes erasure methods. NIST SP 800-88 Rev. 1 takes the alternative route, sorting sanitisation into Clear, Purge and Destroy.
ISO 27001 Hard Drive Destruction for HDDs and SSDs
A degausser floods a magnetic platter with a field strong enough to scramble recorded data. On a traditional hard drive this works. On an SSD it achieves nothing, because there is no magnetic domain to disturb.
Overwriting is not a clean answer for solid state either. Wear levelling moves data across chips, over-provisioned blocks sit outside the addressable space, and a controller can retire a bad block with your data inside it. A single-pass overwrite can leave readable fragments in cells the operating system never touches.
That leaves two credible options: cryptographic erasure on a drive encrypted from day one with verified key destruction, or physical destruction fine enough to break apart individual NAND chips rather than separate them from the board. A shredder rated H-5 is not automatically rated E-4. Ask explicitly.
Software erasure works on both drive types but depends on the drive responding, so faulty units cannot be verified at all. Degaussing covers magnetic drives and tape only, and leaves no visible sign that anything happened. Shredding handles every media type and produces the strongest evidence, at the cost of any resale value.
Chain of Custody Is Where Audits Fail
Your storage devices are most vulnerable between the server room and the shredder. That gap is what an auditor probes hardest, and it is the part of data destruction services most often bought on price alone.
A defensible chain of custody captures the serial number of every drive at collection rather than at destruction, so the record is independent of the supplier. Media travels in sealed, tamper-evident containers. Vehicles are tracked and drivers vetted. Every handover is signed. The certificate lists individual serials rather than a headline count.
That last point matters. A certificate stating “47 hard drives destroyed” tells an auditor nothing about whether drive 31 from your register was among them. A serialised certificate closes the loop between control 5.9 and control 7.14 in one document, which is why Total Shred issues certificates listing serial numbers. Our vehicles carry cameras covering the full shredding process, so evidence can be requested for a specific job.
On-site destruction removes transport risk entirely. Off-site processing at a secure facility is cheaper and usually achieves finer particle sizes, and remains defensible where custody controls are in place. Total Shred operates both.
The Evidence Pack Your Auditor Will Request
– A disposal policy stating which method applies to which data classification, and why
– The risk assessment justifying your chosen destruction level
– An asset register reconciling cleanly against destruction records
– Serialised certificates of destruction for every batch
– Collection notes and signed handover records
– Your supplier’s current certifications and your due diligence records
– The processor agreement under UK GDPR Article 28
– Waste carrier registration, transfer notes and WEEE compliance evidence
The last item catches people out. Secure disposal services and waste disposal are legally separate obligations, and satisfying one does not satisfy the other.
What UK GDPR adds
ISO 27001 certification is voluntary. UK GDPR is not, and the two overlap at end of life. Article 5(1)(f) requires appropriate security of personal data and Article 32 requires measures proportionate to the risk. Article 28 requires a written contract with any processor, and a company shredding your drives is processing personal data on your behalf.
The ADISA ICT Asset Recovery Standard 8.0 was approved by the ICO in July 2021 as a UK GDPR certification scheme under Article 42. Appointing a certified provider gives a controller documented evidence of the sufficient guarantees Article 28 requires.
Four failures that keep recurring
Drives disposed of before the asset register was updated. The register still lists them. Nothing else does.
A certificate with no serial numbers. It proves something was destroyed, and nothing about what.
SSDs run through an HDD process. Shredded to a size appropriate to platters and nowhere near fine enough for NAND.
Printers and copiers left out of scope. Almost all contain an internal drive, and almost nobody remembers at lease return.
Getting the specification right
Decide what your data is worth, choose a destruction level that matches, appoint a hard drive destruction service that can evidence its own controls, and keep records that reconcile against your asset register.
If you are reviewing a provider or specifying secure destruction services, ask for a sample certificate, ask which DIN 66399 level applies to your SSDs specifically, and ask whether you can witness a destruction run.
Total Shred handles hard drive destruction, IT asset disposal and security document destruction for UK businesses, with serialised certificates and a documented chain of custody on every collection, which is what gives compliance owners peace of mind at audit.
FAQ
Does ISO 27001 require hard drives to be physically destroyed?
No. It requires you to ensure information cannot be recovered from equipment leaving service. Verified erasure is acceptable where it can be reliably achieved and evidenced. Physical destruction becomes the answer when erasure cannot be verified, when drives are unresponsive, or when the sensitive information is too valuable to trust to software.
What shred size does ISO 27001 specify?
None. The sizes quoted in the market come from DIN 66399. H-5 caps particles at 320 mm² for magnetic disks and is the common commercial baseline, with E-4 at 30 mm² typically applied to solid state storage devices.
Is degaussing enough to meet ISO 27001?
For magnetic drives and tape, degaussing is an effective sanitisation method where documented and verified. It does not work on SSDs or any flash-based media, and leaves no visible sign, so most organisations shred afterwards.
Do I need a certificate of destruction for every drive?
You need destruction records that reconcile against your asset register. In practice that means certificates listing individual serial numbers, because only a serialised certificate lets an auditor trace a specific asset from register to destruction.
Should I choose on-site or off-site shredding?
On-site destruction removes transport risk and lets you witness the process. Off-site processing usually achieves finer particle sizes at lower cost and is defensible where chain of custody controls are documented. Total Shred provides both.
