Decommissioning and disposal
Revoke device identities, cloud claims, credentials and integrations during retirement. Handle stored data and backups through the approved disposal process.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.
On this page
Overview#
Removing hardware doesn't remove its identities, data, credentials, certificates, cloud claim, API access, licences, backups or references from other systems. Decommissioning is a coordinated trust and data transition.
Preconditions#
- Confirm replacement coverage and safe physical behaviour.
- Identify authoritative configuration, evidence, retention and legal hold needs.
- Export only required records through an auditable process.
- Map device/workload certificates, shared keys, tokens, accounts, mobile credentials, broker ACLs, firewall rules, DNS/DHCP, monitoring, backups, vendor cloud and support contracts.
- Obtain manufacturer guidance for reset, ownership release, storage removal and licensed/certified functions.
Removal sequence#
- Stop new assignments and integrations; announce the maintenance boundary.
- Preserve required evidence, configuration and support records.
- Revoke or remove accounts, certificates, tokens, shared keys and cloud ownership.
- Remove routes, firewall policy, discovery, DNS/DHCP, broker/API permissions and monitoring exceptions.
- Remove credentials and mappings from controller, VMS/PACS/PSIM, mobile and identity systems.
- Sanitize storage using media and sensitivity appropriate methods; physically destroy when required.
- Remove recovery copies and backups when retention permits.
- Update inventories, diagrams, licences, risk records and certificate/source registers.
- Complete a system owner review confirming that no orphaned access, event noise, physical gap, or unsafe dependency remains.
Transfer and resale#
Factory reset isn't proof that all storage, secure elements, cloud bindings, logs, edge recordings, certificates or recoverable data were removed. Record the exact sanitisation method and verification limitation. Transfer must include explicit release from vendor/cloud tenancy and destruction or revocation of prior trust.
Sources#
- NIST 800 88, NIST SP 800-88 Rev. 2: Guidelines for Media Sanitization, final September 2025, accessed 25 August 2026.
- NISTIR 8259A, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline, device lifecycle capabilities, accessed 25 August 2026.