If compliance is the goal, just use FIPS certified self-encrypting drives and trust them to wipe their encryption keys when instructed to do so. At that point, any failure is clearly the vendor's fault, not your own.
That 100% sounds like the right thing to do that can't be done due to budget constraints. The shredding company (who accepts the liability, I think) is just too cheap in comparison.
Comments
If compliance is the goal, just use FIPS certified self-encrypting drives and trust them to wipe their encryption keys when instructed to do so. At that point, any failure is clearly the vendor's fault, not your own.
That 100% sounds like the right thing to do that can't be done due to budget constraints. The shredding company (who accepts the liability, I think) is just too cheap in comparison.