Ann Arbor Government IT Procurement Guide | FISMA | STS
Presented by STS Electronic Recycling

Ann Arbor Government IT Procurement Guide

Your complete resource for FISMA-compliant IT asset procurement and end-of-life disposal for Ann Arbor and Washtenaw County government organizations: NIST 800-88, chain-of-custody documentation, and certified vendor evaluation included
Free Download • No Registration Required
Save this guide for offline FISMA compliance reference
Ann Arbor government IT procurement and NIST 800-88 certified data destruction for Washtenaw County agencies by STS
STS Electronic Recycling: R2v3 certified ITAD and NAID AAA data destruction serving Ann Arbor, Washtenaw County, and Michigan government organizations.

Why Do Ann Arbor Government Organizations Need Specialized IT Procurement Guidance?

STS Electronic Recycling provides R2v3 certified IT asset disposition and NAID AAA data sanitization for Ann Arbor government organizations, serving City of Ann Arbor departments, Washtenaw County agencies, VA Ann Arbor Health System, and the Gerald R. Ford Presidential Library. Public sector organizations average $2.99 million per data breach according to 2024 security industry data; NIST SP 800-88 Rev. 2 compliant disposal and serialized chain-of-custody records prevent that exposure.

Ann Arbor's government IT footprint is more complex than most mid-sized cities. The City of Ann Arbor operates across municipal departments from Larcom City Hall while Washtenaw County coordinates IT across county offices, courts, and public safety. The VA Ann Arbor Health System adds a significant federal technology infrastructure serving Michigan veterans. The Gerald R. Ford Presidential Library operates as a federal facility with its own IT compliance obligations under FISMA, OMB Circular A-123, and the State of Michigan's IT governance framework.

FISMA
Annual compliance reporting required for all federal and state-funded IT systems
NIST Rev. 2
Current mandatory standard for government media sanitization; Rev. 1 withdrawn September 2025

Government IT procurement in Ann Arbor operates at the intersection of federal, state, and municipal regulatory requirements. University of Michigan procurement practices, while predominantly academic, influence the broader Washtenaw County IT supply chain. The result is one of Michigan's most compliance-dense government technology environments, where Ann Arbor government electronics recycling requires certified destruction documentation that can withstand both federal inspector general review and State of Michigan audit scrutiny.

What Has Changed in Government IT Disposal Compliance

NIST SP 800-88 Rev. 1 was withdrawn September 2025. Ann Arbor government IT teams still citing Rev. 1 in disposal policies are working from a standard that no longer exists. Rev. 2 introduced changes to the Clear, Purge, and Destroy methodology categories and added flash storage requirements that affect most laptops and mobile devices procured since 2018. STS Electronic Recycling supports FISMA-compliant electronic asset disposition for Ann Arbor government organizations from our 600,000 sq ft facility.

The Procurement Gap Most Government IT Teams Miss

Treating end-of-life disposal as an afterthought to the procurement cycle. By the time a lease expires or a hardware refresh is approved, disposal vendors are selected under time pressure with inadequate documentation review. Government IT managers operating under OMB A-123 internal control requirements need a certified disposal program in place before procurement contracts are signed, so every asset entering the fleet has a documented exit path that satisfies FISMA reporting requirements.

What Do Ann Arbor Government IT Compliance Requirements Include?

Under FISMA and OMB Circular A-123 requirements, Ann Arbor public agencies must document IT asset disposal through the full equipment lifecycle. U.S. federal agencies reported 32,211 information security incidents in 2023, according to FISMA reporting data; disposal documentation gaps are among the most common findings in federal IT security audits across Michigan agencies.

FISMA and Federal IT Disposal Requirements

Under the Federal Information Security Management Act, covered federal agencies and contractors must protect information systems throughout their entire lifecycle, including end-of-life disposal under NIST Special Publication 800-88 Rev. 2. For Ann Arbor's federal facilities, including the VA Ann Arbor Health System and the Gerald R. Ford Presidential Library, this means a specific disposal framework:

  • NIST SP 800-88 Rev. 2 compliant data sanitization: The current federal standard for media sanitization. Rev. 1 was withdrawn September 26, 2025 and must no longer be cited in agency disposal policies.
  • FIPS 199 media categorization before method selection: Media classified as Low, Moderate, or High impact before method assignment. High-impact media requires physical destruction regardless of media type.
  • Serialized destruction certificates per device: Each certificate must document manufacturer, model, serial number, sanitization method, date, and technician identification. Batch receipts do not satisfy federal audit requirements.
  • Unbroken chain-of-custody documentation: Tracked from agency facility to final destruction with zero gaps for every asset in the disposition batch.

The Ann Arbor data destruction services provided by STS are designed to meet NIST SP 800-88 Rev. 2 documentation requirements for covered entities operating under FISMA reporting obligations across Washtenaw County.

State of Michigan IT Governance and Local Requirements

Michigan state agencies and local governments face IT disposal requirements parallel to federal FISMA standards. Washtenaw County departments and City of Ann Arbor IT staff must comply with Michigan DTMB IT security policies, which reference NIST SP 800-88 Rev. 2 as the baseline sanitization standard for all state-owned media.

Municipal Government

City of Ann Arbor departments and Washtenaw County offices require disposal documentation that survives state audit review and public records requests. Chain-of-custody records must be retained per Michigan Records Retention Schedule requirements, typically a minimum of three years.

Federal Facilities

VA Ann Arbor Health System and Gerald R. Ford Presidential Library operate under federal IT security policy: NIST SP 800-88 Rev. 2 sanitization with FIPS 199 classification and R2v3 certified downstream tracking.

FISMA Compliance Checklist: Required Documentation for Government ITAD Vendors

A FISMA-compliant documentation set must specify: NIST SP 800-88 Rev. 2 sanitization method per asset; FIPS 199 impact categorization; serialized certificate per device with serial number and technician ID; chain-of-custody through final processing; R2v3 downstream tracking; and destruction records per agency retention schedule.

How Should Government Organizations Evaluate IT Disposal Vendors for FISMA Compliance?

Public Sector IT Managers at Ann Arbor agencies face a consistent vendor evaluation challenge: most cannot demonstrate current NAID AAA certification, NIST SP 800-88 Rev. 2 documentation, and R2v3 downstream tracking simultaneously. Verifying all three before any asset transfer is how Washtenaw County procurement officers distinguish compliant partners from unverified claims.

Non-Negotiable Certifications for Government IT Disposal

Require current certifications with verifiable dates before any asset transfer. "We follow industry standards" is not a certification.

R2v3 Certification

Why it matters for government: R2v3 ensures downstream tracking of all materials through certified processors, protecting Ann Arbor government agencies from downstream liability and satisfying OMB A-123 internal control requirements. Verify current certification at sustainableelectronics.org before any contract is executed.

NAID AAA Certification

Why it matters for FISMA: NAID AAA certified data destruction demonstrates documented sanitization processes that federal inspectors and state auditors recognize as meeting good-faith compliance standards. Verify at naidonline.org and confirm scope covers both plant-based and mobile destruction.

Facility Capacity and Government-Specific Capabilities

Ask these questions before any procurement decision:

  • Facility square footage: Anything under 100,000 sq ft suggests limited capacity. STS serves Ann Arbor government organizations from our 600,000 sq ft R2v3 certified facility.
  • NIST SP 800-88 Rev. 2 documentation: Washtenaw County procurement officers typically disqualify vendors still citing Rev. 1, which was withdrawn in September 2025.
  • Mobile shredding capability: For witnessed on-site destruction at government facilities where chain-of-custody cannot leave the premises before confirmed destruction.
  • Degaussing equipment: NSA/CSS EPL-approved degaussers for magnetic media and backup tapes from government archival systems.

Government Procurement Documentation Requirements

Government IT disposal contracts require procurement documentation beyond standard commercial agreements: insurance certificates, downstream processor certifications, and disposal records formatted for agency asset management systems. Learn about Ann Arbor e-waste recycling services and the documentation standards STS maintains for government procurement engagements. Government agencies searching for electronics recycling near me in Ann Arbor find STS provides scheduled pickup throughout Washtenaw County, Ypsilanti, and the I-94 corridor.

The Insurance Verification Most Government Procurement Teams Skip

Request a Certificate of Insurance showing minimum $5M general liability and $2M cyber liability. If a vendor claims that level is unnecessary for government work, disqualify them immediately: this is a non-negotiable threshold for Michigan government IT contracts.

How Do Ann Arbor Government Organizations Build a FISMA-Compliant IT Disposal Program?

STS engagements with public sector IT typically include chain-of-custody reporting aligned with OMB Circular A-123 requirements, standard for Ann Arbor agencies from Larcom City Hall to Washtenaw County offices. Building a disposal program before a hardware refresh cycle prevents the documentation gaps that FISMA audits flag.

Phase 1: Policy Development (Weeks 1 to 2)

Written policies must exist before any disposal activity. Under FISMA Section 3554 and OMB Circular A-123, this is required documentation. Auditors check this first in any disposal-related review.

FIPS 199 asset classification with method assigned per category is a standard procurement provision. Document these elements:

  • Who approves equipment for disposal and at what asset value threshold
  • FIPS 199 impact categorization for different asset types in your agency's fleet
  • Required documentation: serialized destruction certificates, chain-of-custody records, downstream tracking
  • Retention periods for disposal records per agency schedule and applicable federal records requirements

Phase 2: Vendor Selection (Weeks 3 to 6)

Request proposals from at least three vendors. Government procurement best practices require competitive sourcing for IT disposal contracts above the micro-purchase threshold. RFP scope should specify: FIPS 199 asset categories, geographic buildings covered, NIST SP 800-88 Rev. 2 documentation requirement, serialized certificate format, and R2v3 plus NAID AAA verification. Government procurement officers expect per-device serialized documentation as a standard contract requirement. Run a controlled pilot with a single department batch before committing to a multi-year contract.

Phase 3: Implementation and Ongoing Review

Once a vendor is qualified, a Master Service Agreement should lock in pricing for 12 to 24 months, define SLA penalties, and include audit rights. Establish quarterly reviews and align annual disposal reviews with your FISMA assessment cycle.

The Multi-Building Coordination Challenge Most Government Programs Miss

Government facilities in Ann Arbor span Larcom City Hall, courthouse buildings, public safety facilities, and satellite offices across Washtenaw County. Each has different vendor access requirements. A qualified ITAD vendor maps building-specific logistics before the first pickup. STS coordinates secure multi-building government pickup across Ann Arbor from our 600,000 sq ft facility.

Which Data Destruction Methods Meet Government FISMA and NIST Requirements?

According to NIST SP 800-88 Rev. 2 guidelines, media sanitization for government IT assets requires FIPS 199 impact classification before method selection: Clear, Purge, or Destroy. Ann Arbor public sector organizations processing Moderate or High impact media at sites including VA Ann Arbor Health System require Purge or Destroy level documentation for every asset in the disposal batch.

NIST SP 800-88 Rev. 2: Clear, Purge, and Destroy

NIST SP 800-88 Rev. 2 defines three sanitization categories based on FIPS 199 confidentiality impact level. Learn more about government electronics recycling and ITAD requirements under federal procurement frameworks.

  • Clear: Logical sanitization using read/write commands. Appropriate for Low impact media only; insufficient for Moderate or High impact government systems.
  • Purge: Cryptographic erase or multi-pass overwrite protecting against laboratory-level recovery. Required minimum for Moderate impact media under FIPS 199, covering most government workstations and laptops.
  • Destroy: Physical destruction rendering media completely unusable. Required for High impact media and any media that cannot be reliably sanitized through overwrite methods, including failed or damaged drives.

Critical note for government IT managers: Purge-level wiping only works on functioning media. A laptop that crashed and will not boot cannot be wiped. It must be physically destroyed. Documenting a "wipe" on non-functional media creates a false certificate that creates audit liability. This is especially important for older equipment common in government fleet refreshes.

Software-Based Purge vs. DoD 5220.22-M

NIST SP 800-88 Rev. 2 Purge-level wiping uses multi-pass cryptographic overwrite with verification and is the current federal baseline standard. DoD 5220.22-M (three-pass overwrite) is still referenced in many contractor disposal policies. For new FISMA compliance cycles, NIST SP 800-88 Rev. 2 documentation is the preferred standard for federal facilities including VA Ann Arbor Health System.

NSA/CSS EPL Degaussing for Government Media

NSA/CSS Evaluated Products List approved degaussers eliminate data at the domain level, rendering drives completely inoperable. Government applications in Ann Arbor include:

  • Failed drives from government workstations that cannot be Purge-sanitized
  • Backup tapes from government archival and records management systems
  • Any magnetic media requiring NSA-approved sanitization per agency security policy

Important: Degaussing does not work on solid-state drives. Most government laptops procured since 2018 are SSD-based, making Ann Arbor mobile hard drive shredding the only NIST SP 800-88 Rev. 2 compliant Destroy-category method for these assets.

Physical Shredding for High-Impact Government Assets

Plant-Based Shredding

Drives transported under documented chain-of-custody to our 600,000 sq ft R2v3 certified processing facility and shredded with video verification. Serialized destruction certificates issued per device, formatted for government audit requirements.

Mobile Shredding

Truck-mounted shredder arrives at your Ann Arbor government facility. Witnessed destruction eliminates chain-of-custody transfer risk entirely. Required by some security programs for High-impact media. Certificates issued on-site.

What FISMA IT Disposal Mistakes Do Ann Arbor Government Organizations Make?

STS Electronic Recycling provides R2v3 certified IT asset disposition and NAID AAA data sanitization for Ann Arbor government organizations including City of Ann Arbor departments, Washtenaw County agencies, VA Ann Arbor Health System, and University of Michigan (approximately 30,000 employees). Services include NIST SP 800-88 Rev. 2 compliant sanitization, serialized certificates per device, and FISMA-formatted chain-of-custody records from our 600,000 sq ft facility.

These are the recurring compliance failures that generate audit findings for Ann Arbor government organizations:

Mistake 1: Citing a Withdrawn Standard

NIST SP 800-88 Rev. 1 was withdrawn September 26, 2025. Agencies still referencing Rev. 1 in disposal policies or vendor contracts are citing a non-existent standard. Update all policy references and certificate templates to NIST SP 800-88 Rev. 2 now.

Mistake 2: Accepting Batch Certificates Instead of Serialized Documentation

A certificate stating "150 computers destroyed on [date]" does not satisfy FISMA audit requirements. When an auditor asks you to prove a specific asset was sanitized, a batch certificate proves nothing. Proper Ann Arbor certificates of destruction require one per device: manufacturer, model, serial number, NIST SP 800-88 Rev. 2 sanitization method, date, and technician ID.

  • Verify R2v3 certification at sustainableelectronics.org before contract execution
  • Verify NAID AAA membership at naidonline.org, confirming scope covers your requirements
  • Require NIST SP 800-88 Rev. 2 documentation as a written contract provision

Mistake 3: No FIPS 199 Classification Before Method Assignment

Applying the same sanitization method to every asset without FIPS 199 classification either over-spends on low-impact equipment or under-protects high-impact government systems. A general office printer and a server holding law enforcement data are not the same asset class. Build a media classification matrix before your next disposal cycle to ensure each asset type receives the correct NIST SP 800-88 Rev. 2 category treatment.

Mistake 4: Treating Mobile Devices as a Lower Priority

Smartphones and tablets issued to government staff carry the same NIST SP 800-88 Rev. 2 disposal requirements as desktop workstations. City of Ann Arbor and Washtenaw County mobility programs generate significant volumes of these assets annually; missing them from disposal batches creates documentation gaps that FISMA auditors flag.

Mistake 5: No Vendor Contingency Plan

Government organizations cannot pause IT disposal while sourcing a replacement vendor. Mature programs maintain a primary certified vendor plus a qualified backup engaged at least once annually to keep procurement documentation current.

The Small-Lot Disposal Gap That Audit Findings Are Built From

Most vendors prioritize large government orders. Small-quantity disposals, a department with four laptops or a satellite office with one failed server, are where documentation gaps accumulate. Establish a quarterly protocol where departments stage assets centrally to prevent undocumented backlogs before the next FISMA assessment.

About This Guide

Questions about government IT disposal? Email This email address is being protected from spambots. You need JavaScript enabled to view it.. This compliance guide was developed by the STS Electronic Recycling team based on direct experience serving City of Ann Arbor departments, Washtenaw County agencies, VA Ann Arbor Health System, and government organizations throughout Michigan. STS holds R2v3 and NAID AAA certifications and supports government IT disposal programs under FISMA, NIST SP 800-88 Rev. 2, and OMB A-123 requirements. Content reviewed by Mark Domnenko, AI Strategy Consultant.

About STS Electronic Recycling

STS Electronic Recycling, Inc. is a R2v3 Certified IT Asset Disposal Service Provider and Recycler based in Jacksonville, Texas. We provides free computer, laptop and tablet recycling as well as computer liquidation and ITAD services to schools, businesses and government agencies across the United States, processing all equipment through our R2v3 Certified processing facility in Jacksonville, Texas, ensuring that no matter where your business is located, your equipment is processed sustainably, transparently and securely.

R2v3 Certified Electronics Recycler Profile

Search