Augusta Government IT Procurement Guide | STS Recycling
Presented by STS Electronic Recycling

Augusta Government IT Procurement Guide

Your complete resource for federal and local government IT asset procurement compliance in Augusta. Covers FISMA requirements, Fort Gordon disposal standards, NIST SP 800-88 Rev. 2, and vendor evaluation for Richmond County agencies.
Free Download • No Registration Required
Save this guide for offline government IT compliance reference • Questions? This email address is being protected from spambots. You need JavaScript enabled to view it.

Why Augusta Government Agencies Need This Guide

Public Sector IT Managers in Augusta face a procurement compliance gap most markets never encounter: government-issued IT assets span military, federal, and municipal environments, each with distinct destruction standards and documentation requirements. Fort Gordon (31,155 military and civilian personnel) houses the US Army Cyber Command, Army Signal Corps, and Cyber Center of Excellence, where equipment touching classified networks requires destruction documentation most commercial ITAD vendors cannot produce. Augusta-Richmond County Consolidated Government adds a state procurement compliance layer that compounds the challenge for IT directors managing cross-agency refreshes.

Augusta government IT asset disposal - R2v3 certified electronics recycling and NIST 800-88 compliant data destruction for Richmond County agencies

The core challenge: federal and state procurement regulations were written for acquisition, but compliance requirements extend through the full asset lifecycle including secure disposal. Fort Gordon, Augusta University (6,200+ employees), and the Augusta VA Medical Center each operate under overlapping frameworks requiring specific documentation generic commercial ITAD vendors cannot produce. Organizations searching for government IT disposal near me throughout the Augusta and North Augusta area find STS provides scheduled pickup across Richmond County and into Aiken County, SC.

STS Electronic Recycling provides government electronics recycling for Augusta agencies including R2v3 certified processing and NAID AAA certified data destruction from our 600,000 sq ft certified facility. Fort Gordon (31,155 personnel), Augusta-Richmond County Consolidated Government, and Augusta University (6,200+ employees) represent the CSRA's public sector requiring certified disposal and NIST SP 800-88 Rev. 2 compliant destruction.

What Makes Augusta Different for Government IT Disposal

Fort Gordon generates one of the highest concentrations of government-issued IT equipment in the Southeast. Its role as US Army Cyber Command headquarters means equipment cycling through the installation has touched sensitive networks governed by strict DoD destruction standards. Civilian contractors on the installation face the same requirements as the military units they support, making government-grade ITAD capabilities essential across Augusta's entire contractor ecosystem.

Federal and State Compliance Requirements for Augusta Government IT Disposal

Augusta government agencies operate under a layered compliance framework governing IT asset sanitization and disposition. Per FISMA (44 U.S.C. § 3554), agencies must implement information security programs covering asset disposition, making ITAD vendor selection a compliance decision, not an administrative one.

FISMA and NIST SP 800-88 Rev. 2

The Federal Information Security Management Act requires federal agencies to protect information systems throughout their full lifecycle, including disposal. NIST SP 800-88 Rev. 2 is the current federal standard for media sanitization. NIST SP 800-88 Rev. 1 was withdrawn September 26, 2025 and is no longer an acceptable reference for government IT disposal documentation. Any vendor citing Rev. 1 standards in their compliance documentation is referencing a withdrawn standard.

NIST SP 800-88 Rev. 2 defines three sanitization levels that agencies must apply based on data sensitivity:

  • Clear: Appropriate for low-sensitivity media with limited data exposure. Overwrites user-accessible storage using standard write commands. Insufficient for most government IT assets that have accessed federal networks or sensitive systems.
  • Purge: Required for sensitive information on reusable media. Applies technologies that defeat laboratory recovery attempts. This is the minimum level for most Augusta government agency assets including those at Augusta University and Augusta-Richmond County departments.
  • Destroy: Required for classified media or high-sensitivity assets. Renders media unable to store data through physical shredding, disintegration, or incineration. Required standard for Fort Gordon assets classified at Secret or above.

FAR Part 45 (Government Property Disposition)

FAR Part 45 governs disposition of government property held by contractors. For Fort Gordon contractors and federal grantees at Augusta University, assets cannot be disposed of without prior authorization and all disposition actions must be documented in formats compatible with FAR Part 45 reporting.

DoD 5220.22-M (National Industrial Security Program)

Fort Gordon contractors must comply with NISPOM media sanitization requirements: three-pass overwrite for magnetic media, physical destruction for classified assets, and unbroken chain-of-custody documentation from pickup through final destruction.

Georgia State Procurement Code

Augusta-Richmond County and Augusta University must comply with state procurement regulations governing IT asset disposition. Georgia's State Properties Commission surplus property program may apply to certain assets before disposal is authorized. Verify surplus routing requirements before engaging commercial ITAD vendors.

OMB A-123 Internal Controls

OMB Circular A-123 requires federal agencies to maintain internal controls over assets through disposal. Gaps in disposition documentation create audit findings requiring corrective action.

DFARS for Defense Contractors

Defense FAR Supplement adds requirements beyond the base FAR for defense contractors. Fort Gordon contractors in the Cyber and Signal domains should verify applicable DFARS clauses before engaging ITAD vendors.

STS engagements with public sector IT typically include chain-of-custody reporting aligned with OMB Circular A-123 requirements, which is standard for Richmond County agencies and Fort Gordon contractors. For questions about certified data destruction in Augusta under NIST SP 800-88 Rev. 2, contact STS for a documentation consultation.

How to Evaluate ITAD Vendors for Government Compliance in Augusta

STS Electronic Recycling provides R2v3 and NAID AAA certified IT asset disposition for Augusta government agencies and Fort Gordon contractors, with serialized certificates per device, NIST SP 800-88 Rev. 2 compliant sanitization, and chain-of-custody documentation compatible with FAR Part 45, FISMA, and NISPOM. Most commercial vendors claiming "government compliance" cannot produce this documentation. Here is how to verify.

Required Certifications

Two certifications are non-negotiable for government ITAD vendor qualification:

  • R2v3 Certification: The Responsible Recycling standard for electronics recyclers ensures downstream tracking through certified smelters with third-party auditing. Verify at sustainableelectronics.org before any asset transfer. R2v3 covers the recycling and responsible processing side of ITAD.
  • NAID AAA Certification: The National Association for Information Destruction certification validates data destruction services and practices through unannounced audits. Verify at i-sigma.org. Confirm the specific scope of the certification: plant-based destruction, mobile on-site destruction, or both. Government agencies requiring witnessed on-site destruction need mobile scope confirmed. NAID AAA applies specifically to data destruction services, not to general recycling operations.

Documentation Standards

Government auditors do not accept batch certificates. When FAR Part 45 or FISMA documentation is required, you need serialized certificates, one per device, listing manufacturer, model, serial number, destruction method, NIST standard applied, destruction date, location, and technician ID. A certificate stating "500 computers destroyed on [date]" satisfies no federal documentation requirement. Fort Gordon contracts and Augusta University and federal grantee research assets require device-level documentation without exception.

Chain of Custody Requirements

Government IT disposal requires unbroken chain of custody from initial pickup through final destruction. This means signed manifests at transfer, tracked transport with documented custody handoffs, and final destruction certificates linked to the original manifest serial numbers. Any gap in the custody record creates a compliance vulnerability that auditors identify immediately. Vendors who cannot demonstrate an unbroken custody record for every engagement are not government-qualified.

Government Pricing and Contract Vehicles

Ask whether the vendor offers GSA schedule pricing or government cooperative contract pricing. Augusta-Richmond County agencies may have competitive bidding requirements. Legitimate government ITAD vendors provide transparent pricing structures without "we need to visit before we can quote" delays. Expect clear pricing tiers by volume and service type.

Capacity and Security Infrastructure

Public Sector IT Managers typically expect serialized destruction certificates, one per device listing manufacturer, model, serial number, and destruction method, in every government ITAD engagement. STS provides ITAD services for Augusta from our 600,000 sq ft R2v3 certified facility with the documentation government clients require.

How Do Augusta Agencies Build a Government-Compliant IT Disposal Program?

Government IT managers who wait until a FISMA review or state audit to formalize disposal procedures typically find themselves explaining documentation gaps under time pressure. Fort Gordon, Augusta-Richmond County Consolidated Government, and Augusta University each benefit from a structured, phased approach that builds compliance before it is tested.

Phase 1: Policy and Classification Framework

Written disposal policies must exist before any asset leaves agency control. Under FISMA and FAR requirements, government IT disposal policies must address:

  • Asset classification by data sensitivity, aligned to FIPS 199 categories for federal agencies
  • Sanitization level per classification tier, per NIST SP 800-88 Rev. 2
  • Authorization workflow before disposal is initiated
  • Documentation and chain-of-custody requirements per disposal type

Phase 2: Vendor Qualification

Issue a structured request for qualifications to at least three vendors. Include: R2v3 certification proof verified against registry, NAID AAA certification scope, sample serialized destruction certificate, and insurance certificate with minimum $2M general liability. Request references from government clients that have undergone FISMA reviews or FAR Part 45 audits.

Phase 3: Pilot and Full Deployment

Run a pilot with 25 to 50 assets from a single department. Evaluate: did every device receive a serialized certificate with required fields? Was chain of custody maintained without gaps? Does the vendor's documentation format match what your agency's property records system requires? For Fort Gordon contractors, verify that the vendor understands NISPOM classification handling requirements before scaling. For the full deployment, structure the engagement with pickup request protocols, defined lead times, and monthly reporting summaries linking asset records to destruction certificates.

Scheduling for Government Refresh Cycles

Augusta agencies typically plan large disposal events around the federal fiscal year end (September 30) and state fiscal year end (June 30). Book pickups 60 to 90 days in advance during peak periods. Same-week scheduling available for qualifying volumes outside peak windows.

Multi-Department Coordination

Augusta-Richmond County Consolidated Government manages dozens of departments across multiple locations. Batching assets from multiple departments into single pickup events reduces per-unit cost while maintaining serialized documentation for every device.

Phase 5: Record Retention and Ongoing Review

FISMA and FAR Part 45 documentation may require multi-year retention. Build record retention into your disposal program from the start. Annual review against current NIST standards is essential, particularly as new asset types enter inventory.

Which Data Destruction Methods Meet Government Requirements?

When government IT managers ask which data destruction method their agency actually needs, the answer lies in NIST SP 800-88 Rev. 2, not vendor preference. NIST prescribes specific sanitization levels: selecting the wrong one for the asset class is a compliance failure, not a budget decision. Here is what Richmond County agencies need to know about each option:

Software-Based Sanitization (NIST SP 800-88 Rev. 2 Purge)

Multi-pass overwrite with cryptographic verification satisfies the Purge level for most non-classified government media, applying to functioning drives destined for transfer or surplus. Key limitation: software wiping only works on functioning drives. A failed drive must be physically destroyed. Documenting a "wipe" performed on non-functional media generates false certification, which is a compliance violation separate from the disposal issue itself.

NIST SP 800-88 Rev. 2 Purge

Multi-pass overwrite with verification is the current federal standard. Rev. 1 was withdrawn September 26, 2025. Government disposal documentation must reference Rev. 2. Generates verifiable logs compatible with FISMA and FAR documentation requirements. Takes 2 to 4 hours per drive depending on capacity.

DoD 5220.22-M Standard

Three-pass overwrite: zeros, ones, then random data with verification. Still referenced in NISPOM for contractor compliance. Many federal agencies have transitioned to NIST SP 800-88 Rev. 2 Purge as the current standard. Both remain acceptable for non-classified CUI depending on agency policy.

Degaussing for Magnetic Media

Degaussing renders magnetic drives and tapes inoperable by scrambling data at the domain level. Required for failed magnetic drives that cannot be wiped and legacy backup tapes from archival systems. Critical limitation: Degaussing has no effect on solid-state drives or any flash-based media. Modern government workstations use SSDs. Applying degaussing to an SSD produces no data destruction, and any certificate issued for that process is inaccurate documentation.

Physical Destruction (Required for Classified and High-Sensitivity Assets)

Industrial shredding reduces drives to particles below 2mm. This is the only method that satisfies the Destroy level under NIST SP 800-88 Rev. 2 and the only method compliant for classified media under NISPOM. Fort Gordon assets classified at Secret or above require physical destruction, not wiping. Two delivery approaches are available:

  • Plant-Based Shredding: Assets transported to our 600,000 sq ft R2v3 certified facility for industrial shredding with video verification and serialized certificate generation. More economical for large volumes. Chain of custody maintained throughout transport and processing.
  • Mobile On-Site Shredding: Truck-mounted shredder comes to your Richmond County site. Destruction is witnessed in real time, eliminating chain of custody risk. Required by some government compliance programs for highest-sensitivity assets. Government electronics recycling programs that require witnessed destruction can be scheduled with advance coordination.

Matching Method to Classification

General office assets with limited network access: NIST SP 800-88 Rev. 2 Purge-level overwrite. Network-connected workstations and servers: degaussing for magnetic drives, physical shredding for SSDs. Classified media at Fort Gordon and contractor facilities: physical destruction only with NISPOM-compatible chain of custody.

What Government IT Disposal Mistakes Do Augusta Agencies Keep Making?

STS Electronic Recycling provides R2v3 and NAID AAA certified electronic asset disposal for Augusta government agencies with serialized certificates per device and NIST SP 800-88 Rev. 2 compliant sanitization. IBM's 2024 Cost of a Data Breach Report documents an average $4.88 million breach cost; documentation gaps from improper IT disposal create direct audit exposure for Richmond County agencies and Fort Gordon contractors. These are the failures that produce corrective action plans.

Mistake 1: Referencing Withdrawn Standards in Disposal Documentation

NIST SP 800-88 Rev. 1 was withdrawn September 26, 2025. Any disposal documentation citing Rev. 1 after that date references a withdrawn standard. Update vendor agreements and internal policies immediately. FISMA auditors checking disposal documentation will flag Rev. 1 references.

Mistake 2: Accepting Batch Certificates for Government Assets

A certificate stating "250 government computers destroyed on [date]" satisfies no FAR Part 45, FISMA, or NISPOM requirement. When an audit requests proof that a specific serial number was destroyed, a batch certificate proves nothing. Fort Gordon, Augusta VA Medical Center, and Augusta-Richmond County departments all require serialized certificates listing manufacturer, model, serial number, destruction method, standard applied, date, and technician ID. Anything less becomes an audit finding.

Mistake 3: Skipping State Surplus Routing for Public Agency Assets

Augusta-Richmond County agencies and Augusta University must verify whether assets require routing through Georgia's state surplus property program before engaging a commercial ITAD vendor. Skipping required surplus routing creates a procurement violation independent of data destruction compliance. Check with your agency's property officer first.

Mistake 4: Applying Wiping to Solid-State Drives

Most current government workstations use SSD storage. NIST SP 800-88 Rev. 2 specifies that software overwrite alone does not reliably sanitize SSDs due to wear-leveling algorithms. Rev. 2 recommends cryptographic erase where supported, or physical destruction for high-sensitivity assets. Certificates documenting simple overwrite on SSDs do not reflect the sanitization level actually achieved.

"We assumed our disposal vendor was handling the NIST documentation automatically. When our FISMA annual review requested destruction records for specific assets, our vendor provided batch totals. We spent months reconstructing records and still could not produce device-level documentation for a subset of assets. The corrective action plan required retroactive policy revisions and vendor requalification. We now require serialized certificates as a contractual deliverable before any payment."

IT Compliance Manager, Southeast Federal Agency

Mistake 5: No Documentation for Contractor-Held Government Property

Fort Gordon contractors holding government-furnished equipment under FAR Part 45 must document disposition before contract closeout. Contractors arriving at closeout without disposal documentation for all GFE face contract disputes. Build disposal documentation into every contract's closeout checklist from day one.

About This Guide

This compliance guide was developed by the STS Electronic Recycling team based on direct experience serving Fort Gordon, Augusta VA Medical Center, Augusta-Richmond County Consolidated Government, and Augusta University and organizations throughout the CSRA region. STS holds R2v3 and NAID AAA certifications and has processed government IT assets under FISMA, FAR Part 45, and NIST SP 800-88 documentation requirements. Content reviewed by Mark Domnenko, AI Strategy Consultant. Questions: This email address is being protected from spambots. You need JavaScript enabled to view it.

About STS Electronic Recycling

STS Electronic Recycling, Inc. is a R2v3 Certified IT Asset Disposal Service Provider and Recycler based in Jacksonville, Texas. We provides free computer, laptop and tablet recycling as well as computer liquidation and ITAD services to schools, businesses and government agencies across the United States, processing all equipment through our R2v3 Certified processing facility in Jacksonville, Texas, ensuring that no matter where your business is located, your equipment is processed sustainably, transparently and securely.

R2v3 Certified Electronics Recycler Profile

Search