Skip to main content

Decommissioning assets

How to retire digital assets (such as data, software, or hardware) from operation.
anilyanik via Getty Images

This guidance describes why it’s important for organisations to decommission digital assets, and how to do so securely. It’s aimed at technical staff and risk owners. For advice dealing specifically with decommissioning hardware, please refer to our guidance on discontinuing obsolete products or network devices. 




Note that the NCSC has also published separate guidance on the secure removal of data or malware from smartphones, tablets, laptops and desktop PCs, which is aimed at users wishing to sell or dispose of their own personal devices.

Once the actual decommissioning of assets begins, you’ll need to ensure that: 

  • the coordination of decommissioning activities is in place, such as the introduction of replacement assets  
  • there are effective communications so that everyone who is impacted (including end users) is aware of what is happening
  • assets are stored securely whilst they are awaiting their next stage of decommissioning; assets holding potentially sensitive data should not be stored in insecure environments 
  • replacement assets are in place and working as expected before performing irreversible actions (such as the permanent destruction of configuration data)
  • third parties are appropriately certified and vetted if they are carrying out sensitive activities
  • appropriate tracking is in place for any assets that are transferred between individuals or teams; this may require a more stringent, detailed, chain-of-custody type of tracking for sensitive or valuable assets