ISO 21964 & DIN 66399
Secure Destruction Standards for Confidential Media
Understanding international standards for secure destruction of data-bearing media and end-of-life IT assets
In secure IT asset disposal, destruction is a controlled security measure
that must align with the type of media involved, the sensitivity of information contained, and the organisation's risk framework. ISO 21964 and DIN 66399 are internationally recognised standards for destruction that help organisations define requirements in a structured and auditable way. This page explains what they are, why they matter, and how Katana Digital applies these standards through certified destruction equipment and risk-based methods.
Understanding ISO 21964 & DIN 66399
ISO 21964
is the international standard for the secure destruction of data carriers. It represents the evolution and globalisation of the earlier German standard DIN 66399, which it has effectively replaced in most markets. Today, ISO 21964 is the recognised destruction standard across Europe and internationally. DIN 66399 is still referenced in some German-speaking contexts for historical or regulatory continuity, but ISO 21964 is the current standard that applies. This standard establishes a classification framework based on three key variables:
-
Media Type
The standard recognises different categories of data-bearing media—from hard drives and solid-state drives to magnetic tape, optical media and printed documents containing sensitive information.
-
Security Classes
ISO 21964 defines security classes (typically ranging from Class 1 to Class 6). Higher security classes require more rigorous destruction methods, allowing destruction approaches to be matched to the actual risk level of the information involved.
-
Cut Sizes & Physical Destruction
The standard specifies acceptable cut sizes (measured in millimetres) for different security classes. These are achieved through certified destruction equipment and documented through destruction certificates.
Risk-based destruction: Not all confidential data carries the same risk level, and not all destruction methods provide the same level of protection. ISO 21964 helps organisations make defensible, evidence-based choices.
Why ISO 21964 matters
-
Governance & Accountability
Recognised destruction standards provide a structured basis for defining and documenting secure destruction requirements.
-
Risk-Based Decision Making
Different data carries different risks. Destruction requirements can be adapted to the level of protection required.
-
Procurement Clarity
ISO 21964 and DIN 66399 provide a common reference for evaluating destruction providers, equipment capabilities and destruction outcomes.
-
Vendor Assessment
For security and compliance teams, certified destruction equipment and documented understanding of applicable requirements are important vendor assessment criteria.
-
Audit Readiness
Standards-based destruction processes provide documented evidence that can support internal audits and compliance reviews.
How Katana digital applies ISO 21964
Katana Digital applies ISO 21964 through a fleet of certified shredder trucks equipped to achieve multiple security classes through three distinct cut types.
Certified Equipment
All Katana Digital shredder trucks are ISO 21964 certified, meaning they are independently verified to achieve the cut sizes specified in the standard. This certification is maintained through regular equipment inspection.
On-Site Destruction Advantage
- Reduced transport risk: Confidential media never leaves your premises
- Witnessed execution: Operations observed by your team
- Immediate proof: Destruction certificates generated on-site
- Chain of custody control: Security maintained throughout
Three Distinct Cut Types
All Katana Digital shredder trucks are ISO 21964 certified, meaning they are independently verified to achieve the cut sizes specified in the standard. This certification is maintained through regular equipment inspection.
- Class 1-2 Destruction Larger cut sizes for lower-sensitivity materials. Faster processing, appropriate where data risk is lower.
- Class 3-4 Destruction Medium cut sizes for standard confidential information. Suitable for most corporate IT asset disposal scenarios.
- Class 5-6 Destruction Finest cut sizes for highest-sensitivity materials. Designed for government contracts and extreme data protection requirements.
Explore our ISO 21964 white paper
Practical guide for IT managers, security officers and compliance professionals seeking deeper understanding of ISO 21964 implementation, security class assessment and vendor evaluation.
Frequently asked questions
-
Not necessarily. ISO 21964 helps classify destruction needs based on data sensitivity and media type. The appropriate level depends on your data risk profile, internal policies and regulatory context.
-
We assess media type, data sensitivity and your internal policy, then match the security class to the risk. The decision is documented with the destruction certificate.
-
Both. The standard covers all data carriers, from printed documents to hard drives, solid-state drives, magnetic tape and optical media.
-
Our shredder trucks are ISO 21964 certified, so the standard applies at your premises. Destruction is witnessed and the certificate is issued on site.
Next steps
Understand ISO 21964 in the context of broader secure destruction governance:
Or reach out to our team: