CAS-320977: certificates accepted as proof, procedure never tested

Certificate of Destruction

FOI reference CAS-320977, published on The National Archives’ disclosure portal on March 3, 2026, runs to a modest exchange: a question submitted by an unnamed requester and a response issued by The National Archives, with no named official credited on either side. The full text is in the public domain, and the substance of what that record contains, and omits, is what this piece examines.

What the Requester Actually Asked

The request drew a precise distinction. First: do the certificates and disposal documentation from The National Archives’ supplier constitute a warranty that personal data on each specific device has been rendered irrecoverable, or do they confirm only that a certified erasure procedure was followed? Second: beyond reliance on accreditation frameworks and recognized standards, does The National Archives hold any device-specific, independently verified evidence that data on a particular piece of storage media was actually made unrecoverable in practice?

Process-confirmation documentation records that a procedure was run. Outcome evidence records that the procedure produced a verified result on a specific device. These are different categories of document, and the request was asking which one The National Archives held.

What The National Archives Said It Holds

The response confirmed that The National Archives receives documentation and certificates from its disposal supplier and treats these as its warranty and guarantee of destruction. The certificates are issued by Blancco, described in the response as NIST-approved data erasure software. Disposal operations are stated to comply with ADISA-8, the ICT Asset Recovery Standard published by ADISA, which the UK Information Commissioner’s Office approved as a UK GDPR certification scheme in July 2021. Service providers hold Cyber Essentials Plus certification and are stated to be compliant with ISO/IEC 27001. The response also states that drives are encrypted as an organizational standard, an assertion The National Archives does not support with reference to any specific encryption standard, key-management procedure, or independent validation, and that this encryption alone renders data unrecoverable from the point of initial storage. No additional independent verification beyond the Blancco certificates is commissioned for individual devices.

The Case for Taking the Certificates at Face Value

Blancco is widely deployed at enterprise scale, holds Common Criteria certification at EAL 3+, and its Drive Eraser product has been verified by ADISA’s research laboratory for compliance with NIST SP 800-88, the media sanitization guidelines document updated to Revision 1 in 2014. Each erasure run generates an audit-ready certificate containing serial numbers, timestamps, and results. ADISA-8 is accredited by the UK Accreditation Service. Cyber Essentials Plus requires an independent technical assessment by an accredited certification body. ISO/IEC 27001 covers governance, risk management, and supplier management in a structured framework.

When a disposal supplier operating under ADISA-8 with ISO/IEC 27001 compliance issues a Blancco certificate, that certificate sits within a regulated, auditable chain. The National Archives is not behaving unusually in treating it as adequate documentation. Most public and private sector organizations handle device disposal in precisely this way, and the credentials behind it are real.

Procedure and Outcome Are Not the Same Document

The requester’s central distinction, procedure-confirmation versus outcome evidence, does not appear anywhere in The National Archives’ response. The response confirms that certificates exist and that accreditation frameworks govern the process that produces them. It does not address what the Blancco certificates contain at the device level: whether each one records a tested, device-specific finding that irrecoverability was achieved, or whether each one records that the erasure software was executed on a given device. The National Archives presents the certificates as both warranty and guarantee without explaining why those two functions are satisfied by the same document.

The response describes Blancco as “NIST-approved software”, a characterization worth examining. Blancco’s own published materials state that it has been tested and approved by NIST and supports compliance with NIST SP 800-88. However, NIST SP 800-88 is a guidelines document; NIST does not operate a formal product-certification program for commercial data erasure software. The precise basis for the characterization in the response is not documented in the FOI exchange and is not reconciled against Blancco’s published certifications list.

What No Document in the Case Addresses

The published record leaves three specific questions unanswered.

The response does not state whether any Blancco certificate in The National Archives’ possession specifies irrecoverability as a tested, device-level result rather than a procedural output. The requester asked this directly. The response does not answer it.

The response references internally registered device information without describing what that registration contains: whether it includes device serial numbers cross-referenced to individual certificates, or whether records are held at batch or contract level only.

On the encryption point: The National Archives states that full-drive encryption applied from the point of initial storage renders data unrecoverable before any software erasure step is taken. The response does not identify the encryption standard used, describe how encryption keys are managed or destroyed at end of life, or reference any independent validation of that claim.

The published case closes with the request marked as resolved. The record does not resolve whether the certificates in The National Archives’ possession answer the question the requester posed, whether they document an outcome or a process. That distinction remains open.