Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    [email protected]

CUI Media Disposal Record template for NIST 800-171 requirement 3.8.3

A disposal log with the sixteen columns an assessor expects, an example row, drop-down lists for the sanitization method and media type, and an instructions tab. Fill it as media leaves service and attach it to your System Security Plan; it is the evidence behind NIST SP 800-171A objectives 3.8.3[a] and [b].

Version 1.0, reviewed 2026-09-19. Free under CC BY 4.0. Not legal or assessment advice.

Who it is for

Any contractor or supplier that must show CUI media was sanitized or destroyed before disposal or reuse. It is sized for a small organization keeping the record in a spreadsheet; larger ones can map the columns into an asset system.

What is inside

  • Columns: asset tag, media serial number, make, model or part number, media type, data category, media source, removal date, sanitization method (Clear, Purge, Destroy), equipment or vendor, destruction date, technician or witness, second witness, verification, certificate number, notes
  • An example row to overwrite
  • Drop-down lists for method and media type, and a summary that counts items recorded, destroyed, and certified
  • An instructions tab explaining each column, how to record devices found empty, and where the record belongs in the SSP

Why the columns are what they are

The asset tag ties the row to your inventory; the media serial number is the unit of accountability once the drive leaves the chassis. The data category (for example CUI // CTI, FCI, or None) drives the method. Method, equipment, verification, and certificate number are the fields NIST SP 800-88 Rev. 2 section 4.6 asks for, and the two witness columns satisfy the two-person practice the High policy requires. A device that turns out to hold no media gets a row too, marked “none found,” because a log that lists only drives cannot prove which computers were checked.

How to adapt it

  1. Fill the yellow header cells: organization, preparer, date.

  2. Overwrite the blue example row with your first real item.

  3. Add rows as media leaves service, not after the fact; the removal date should be the day it happened.

  4. When the certificate arrives, enter its number on every row it covers.

  5. Keep the file with the SSP and the certificates it references.

What it rests on

  • NIST SP 800-171 requirement 3.8.3 and 800-171A objectives 3.8.3[a] and [b]
    Sanitize or destroy CUI media before disposal and before release for reuse.
  • NIST SP 800-88 Rev. 2, section 4.6 and Appendix C
    The record fields.
  • NSA/CSS Policy Manual 6-22
    Administrative declassification details for storage media.

Primary sources are linked on the Standards page.

Questions

  • Do we need a row for every drive, or one per job?

    One per item. The assessment objectives are tested per device, and a certificate that references the log by line only works if the line exists.

  • What goes in the record for a device we could not open?

    Record the asset tag and media type as unknown, note why it could not be opened, and send it for destruction whole; the vendor's log will then carry the media serial found inside.

  • Can the vendor fill this in for us?

    The destruction vendor's media log covers what it destroyed; this record starts earlier, at removal, and includes devices that never went to the vendor. Keep both.

More answers on the FAQ.

Other templates

Download the Excel file

Need it tailored, or the destruction it describes?

Request a custom quote