Is your ITAD process audit-ready under DORA and NIS2

Is your ITAD process audit-ready under DORA and NIS2?

When an auditor asks what happened to a retired laptop, "it was destroyed" is not an answer. The answer is a record: which device, collected when, handled by whom, sanitised or destroyed by which method, and with what result. A batch certificate of destruction rarely provides that.

The regulatory basis for that question is now clear. DORA has applied to financial entities since 17 January 2025. Its technical standard on ICT risk management, Delegated Regulation (EU) 2024/1774, requires documented processes for securely deleting data and for securely disposing of storage devices that contain confidential information. NIS2 reaches the same point through asset management and supply-chain security. In Poland, it applies through the amended KSC Act, in force since 3 April 2026. In the Netherlands, it applies through the Cyberbeveiligingswet, in force since 15 August 2026.

End of life is where these requirements are easiest to miss. Assets leave your perimeter, usually through a third party, often with data still on them. Neither framework prescribes a certificate format, but both expect you to show that disposal was controlled. In practice, that means evidence for each device.

This article explains what the rules require, where ITAD processes typically fall short, and what to ask of your ITAD provider.

Who is in scope

If you are a financial entity, DORA governs your ICT risk, including end-of-life assets. If you are an essential or important entity in another sector, NIS2 and its national transposition apply.

DORA. Regulation (EU) 2022/2554 covers 20 types of financial entities (Article 2). They include credit institutions, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and others. The Polish Financial Supervision Authority (KNF) confirms that DORA has applied since 17 January 2025. Smaller entities under the simplified framework (Article 16) face the same disposal requirement in a shorter form (RTS 2024/1774, Article 35(e)-(f)).

NIS2. Directive (EU) 2022/2555 applies to essential and important entities in the sectors listed in its annexes. For financial entities, DORA is the sector-specific act and takes precedence (DORA Article 1(2) and recital 16).

What this means for ITAD providers. Many ITAD providers are not essential or important entities themselves, although some may be, for example under the waste management sector in NIS2 Annex II, depending on their main activity and size. They are suppliers to entities that are. The requirements reach them through contracts, due diligence and audits (NIS2 Article 21(2)(d) and 21(3)).

What DORA expects at end of life

Under DORA, end-of-life handling must be a documented and implemented procedure under a management-approved policy, not an ad hoc logistics task. The detail sits in Delegated Regulation (EU) 2024/1774, the RTS on ICT risk management. The table paraphrases the provisions most relevant to ITAD.

RTS 2024/1774 provision What it requires (paraphrased) What it means for ITAD
Art. 11(2)(h) A process to securely dispose of or decommission storage devices holding confidential information, on premises or stored externally The core ITAD requirement: a defined, repeatable disposal process
Art. 11(2)(g) A process to securely delete data the entity no longer needs, on premises or stored externally Sanitisation method chosen per media type and data classification
Art. 4(2)(b) Asset records with unique identifier, location, classification and owner for each ICT asset Every device sent for disposal reconciles to the register, down to serial number
Art. 8(2)(a)(i)-(ii) Requirements for secure deinstallation of ICT systems and handling of information assets Documented decommissioning steps before collection
Art. 18(2)(c) Measures to secure ICT assets inside and outside the premises, including unattended assets Secure storage before pickup and secure transport
Art. 19(b)(iii) Staff return all ICT assets when employment ends Leavers' devices enter the controlled disposal flow
Art. 7(1) Key management across the lifecycle, including destroying keys Cryptographic erase is only defensible if key destruction is recorded
Art. 11(2)(k), Art. 14(1)(c) Resilience requirements for third-party operated assets (only if the provider is classified as an ICT third-party service provider); confidentiality agreements with third parties Contract and NDA terms with the ITAD provider and its staff
Art. 12, Art. 22(d) Logging procedures; secure retention of evidence on ICT-related incidents Sanitisation logs, chain-of-custody records and retention periods
Art. 2(2)(b), (f) Policies show the management body's approval date and list the documentation to keep A disposal policy that is approved, dated and tied to a records list

For entities under the simplified framework, Article 34(a) (lifecycle monitoring) and Article 35(e)-(f) (secure deletion and disposal) carry the same expectations.

Is your ITAD provider an "ICT third-party service provider"?

This is an open question, and each financial entity should decide and document it. DORA defines ICT services as digital and data services provided through ICT systems on an ongoing basis, including hardware services (Article 3(21)). Collection, wiping and destruction do not fit that definition neatly.

If you classify the provider as an ICT third-party service provider, the register of information (Article 28) and the key contractual provisions (Article 30) apply. Article 30(2) sets the minimum contract content, including the locations where data is processed (point (b)), data protection provisions (point (c)), and access, recovery and return of data if the contract ends or the provider fails (point (d)). Where the service supports critical or important functions, Article 30(3)(e) adds rights of access, inspection and audit. Deletion of personal data at the end of the service is a separate GDPR requirement for processors (Article 28(3)(g)).

If you do not, Article 11(2)(h) still applies, together with asset records (Art. 4), physical security (Art. 18) and confidentiality arrangements with third parties (Art. 14(1)(c)).

What NIS2 and the Polish KSC Act expect

NIS2 does not mention ITAD by name, but several of its ten minimum measures reach it directly. Article 21(2) requires an all-hazards approach that protects network and information systems and their physical environment.

NIS2 provision Measure Relevance to ITAD
Art. 21(2)(i) Human resources security, access control and asset management Inventory stays accurate until the asset is sanitised or destroyed
Art. 21(2)(d) Supply chain security, including relationships with direct suppliers and service providers The ITAD provider is a direct service provider handling your data
Art. 21(3) Account for each supplier's specific vulnerabilities and the quality of its cybersecurity practices Due diligence on the provider's sites, staff, subcontractors and methods
Art. 21(2)(h) Policies on cryptography and, where appropriate, encryption Encryption at rest reduces exposure and enables cryptographic erase
Art. 21(2)(f) Procedures to assess whether measures are effective Sample-based verification of sanitisation results
Art. 21(2)(b), Art. 23 Incident handling and reporting A lost or stolen device with readable data may be a significant incident
Art. 21(4) Corrective measures without undue delay when non-compliance is found Gaps found in disposal must be fixed and tracked

Incident timelines. If an incident is significant, Article 23(4) requires an early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after the submission of the incident notification. Financial entities follow DORA instead: an initial notification within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours and a final report within one month. A device lost in transit is a realistic scenario to rehearse.

Management accountability. Article 20 requires management bodies to approve the cybersecurity risk-management measures and oversee their implementation. In Poland, the amended KSC Act places responsibility for cybersecurity obligations on the head of the entity, typically the management board.

Audit and enforcement in Poland. Essential (key) entities must complete a first cybersecurity audit by 3 April 2028, then at least every three years. Disposal records produced from now on are likely to be reviewed in that first audit. For entities that met the criteria on 3 April 2026, the core obligations apply from 3 April 2027. For most obligations, administrative fines can only be imposed after 3 April 2028. The head of the entity can be fined personally, up to 300% of their remuneration.

Personal data. Retired devices often hold personal data. GDPR obligations on security of processing and on processors apply alongside DORA and NIS2.

Where ITAD processes typically fail an audit

Most findings come from missing links in the evidence chain, not from a failed wipe. The patterns below are common in practice; they are observations, not survey data.

  • Batch-level certificates. "50 laptops destroyed" with no serial numbers cannot be reconciled to the asset register.
  • No three-way reconciliation. The asset register, the collection manifest and the certificate do not match, and nobody explains the difference.
  • Method not matched to media. Overwrite tools designed for hard drives are used on SSDs, where they may not reach all storage areas. No purge-or-destroy decision is recorded.
  • Hidden storage missed. Printers, multifunction devices, network equipment, phones, tablets and removable media hold data but are not tracked as data-bearing.
  • Custody gaps before pickup. Devices wait in unlocked rooms or open cages for weeks before collection.
  • Custody gaps in transit. No sealed or tamper-evident containers, no seal numbers on the manifest, no record of who handled what.
  • No verification. Nobody samples sanitised devices or checks that sanitisation tools are validated.
  • Remote and leaver devices outside the flow. Laptops of departing or remote staff are returned by courier or never returned at all.
  • Policy without governance. No approval date, no named owner, no link to the risk assessment.

What to ask your ITAD provider

  • Do you issue certificates per serial number, not per batch?
  • Do you use sealed containers and record seal numbers on the manifest?
  • Which sanitisation method do you use for each media type, and how do you verify results?
  • What happens when an erasure fails or a serial number is missing?
  • Where do devices end up: reuse, resale or recycling – and can you prove it?

The bottom line

An audit-ready ITAD process closes the loop: register, manifest, certificate and register again, with a serial number at every step. DORA's RTS 2024/1774 makes secure deletion and disposal a required procedure for financial entities. NIS2 and the Polish KSC Act reach the same point through asset management and supply-chain security.

Reconcile your last disposal batch against the asset register and check whether your certificates are per device.

This article is general information, not legal advice. Check your obligations with your legal and compliance teams and the competent authority.


How Device Europe supports audit-ready ITAD

Device Europe has roots dating back to 1996 and operates from sites in Bydgoszcz (Poland) and Haarlem (the Netherlands). We help organisations show auditors and supervisors what happened to each retired device.

Common gap How we close it
Batch-level certificates A certificate and report for each serial number
Custody gaps in transit Direct transport to our facility, sealed containers, sealed vehicles, GPS tracking and photos of intact seals on arrival
Method not matched to media Software erasure, degaussing of magnetic media, or shredding in line with ISO/IEC 21964
No verification R2v3 (Appendix B) requires independent verification of at least 5% of software-erased devices; we verify 10%
Failed erasures Drives that fail erasure are destroyed, and the result is recorded per serial number

Our management systems are certified to ISO/IEC 27001, ISO 9001, ISO 14001 and ISO 45001. We hold R2v3 certification (Polish branch in Bydgoszcz) and are a Certified B Corporation. Certificates, including their scope, are published on our Certificates page.

Need ITAD that supports your DORA and NIS2 compliance?

Device Europe provides secure data sanitisation and device destruction, records per serial number and a documented chain of custody, designed to support your DORA and NIS2 obligations. Send us a service interest form via Contact our ITAD team page or write to contact@deviceeurope.com, and we will reply with a proposal tailored to your volumes and locations.

Sources