Overview
ISO/IEC 21964-2:2018 specifies requirements for machines that destroy data carriers to ensure safe, verifiable data destruction. Part 2 of the ISO/IEC 21964 series focuses on physical equipment - shredders, disintegrators, degaussers and other destruction machines - and defines how equipment must perform and be tested to meet defined security levels for different media types.
Key topics and technical requirements
- Scope and objective: Applies to machines for destruction of data carriers and specifies performance and testing requirements to ensure secure destruction.
- Degree of destruction / security levels: Machines must meet minimum degree-of-destruction criteria. Security levels are expressed for different media categories and linked to maximum particle sizes or conditions after destruction.
- Media classification: Media types are defined by letter codes:
- P – original-size media (paper, film)
- F – miniaturized media (microfilm/microfiche)
- O – optical media (CD/DVD)
- T – magnetic media (floppy, tape, ID cards)
- H – hard drives (HDDs)
- E – electronic/solid-state media (USB, SSD, chip cards, mobile devices)
- Particle size limits and tolerances: Detailed limits for particle dimensions per security level (e.g., strip width, maximum particle size, allowance that 10% of material may exceed the specified size within defined maxima). Highest-level methods cover lower levels.
- Feed and collection apparatus: Machines must provide safe feeding mechanisms (manual or mechanical) that fully grip and feed media, plus collection/discharge arrangements (chutes, collectors, extractors).
- Verification and testing: Requirements cover ambient conditions, test materials, rated throughput testing, sampling and analysis of destroyed material, and procedures for evaluating degree of destruction.
- Documentation and certification: Security level must be demonstrated by test certificate, declaration of conformity or equivalent; certificates should accompany user documentation.
Applications and who uses it
ISO/IEC 21964-2 is used by:
- Manufacturers of shredders, disintegrators and specialized destruction equipment (design and conformity)
- Procurement teams and facilities managers specifying secure destruction equipment
- IT/security managers, data centers and records management teams aiming for compliant media disposal
- Secure destruction service providers validating equipment performance
- Compliance officers demonstrating adherence to data-protection requirements
Practical uses include selecting appropriate equipment for shredding paper, destroying optical discs, dismantling HDDs/SSDs, and defining testing procedures to prove secure destruction.
Related standards
- ISO/IEC 21964-1 - Principles and definitions (Part 1 of the series)
- DIN 66399-2 - German standard referenced in preparation (as the basis for this part)
- ISO 216 - referenced for paper sizes
Keywords: ISO/IEC 21964-2:2018, data destruction, destruction of data carriers, shredders, security levels, particle size, secure disposal, HDD destruction, SSD destruction, optical media disposal, testing and certification.