Auditing Surplus Network Gear for Bulk Resale: The Five Levels of Decommissioning Discipline
What happened to the last twenty access switches your team pulled out of a rack?
Most organizations cannot answer that at the serial level. They know roughly how many devices came out. Roughly where they went. Roughly when. Roughly is the problem. It turns a refresh that should have returned real money into a pallet of aging hardware in a storeroom. It also leaves a compliance gap that nobody notices until an auditor asks for the disposal record of one specific chassis.
The security side is not theoretical. In April 2023, ESET researchers bought a batch of used enterprise routers on the secondary market. More than half of the devices still carried their previous owner’s configuration data. That meant router-to-router authentication keys, application inventories, and enough detail to identify the former owner and map the network. Sixteen usable devices, over 56 percent still talking. Every one reached the secondary market by legitimate sale, from organizations that believed they had finished the job.
What follows is a maturity model, not another generic checklist. It covers auditing and preparing surplus network hardware before a bulk sale, in five levels of discipline. Work out which level you operate at now, then move up one. The biggest single gain sits in the jump from Level 1 to Level 2. Almost nobody is honestly at Level 5.
First, Some Definitions Worth Agreeing On
Teams use these words loosely. The looseness costs money in negotiation. Fix the vocabulary before you fix the process.
A serialized audit catalogs every asset by make, model, serial number, and configuration, captured before anything moves. It is the spine of a bulk sale. No other artifact both prices the lot and satisfies the buyer’s intake process.
Condition grading assigns each asset to a defined state. The inputs are a functional test, a cosmetic inspection, and a completeness check. Three grades cover nearly everything. Working: powers on, boots, passes a port and power supply test. Untested: no test performed, sold as is. For parts: known fault, value is in the components.
Completeness means the unit ships with the parts a buyer needs to resell or deploy it. On network gear that means rail kits, both power supplies, fan trays, uplink or expansion modules, stack cables, and any transceivers still seated in the cages.
Depreciation assessment judges a generation of hardware against the current secondary market. Not against purchase price. Not against book value. Those three numbers are rarely close.
A documentation pack travels with the lot. It holds the asset list, the condition grades, the sanitization record, and the chain of custody handoff. A buyer’s compliance team reads it.
Level 0: Nobody Wrote Anything Down
The gear came out of the rack during a migration window and went onto a pallet. The pallet went into a storeroom. There is no list. The person who did the decommission has since changed roles.
Level 0 has a specific symptom. Someone finally decides to sell, and the first two weeks go to walking a storeroom with a phone camera. Every buyer conversation stalls. Nobody can say what is actually there.
Level 0 also carries the worst version of the value decay problem. A commonly cited working figure in asset recovery: surplus hardware sheds something like 20 to 30 percent of its recoverable value across six to twelve months in storage. Treat that as a planning assumption, not a measurement. It varies enormously by category. The direction is right, and it is worse for networking than for drives. Vendors push switch generations toward end of sale and end of support on a published schedule. Once a platform crosses that line, the buyer pool thins out fast.
Level 1: A Spreadsheet of Model Numbers
Somebody counted. There is a tab that says forty-two Catalyst 9300s, eleven Juniper EX switches, a handful of FortiGates, and a box of optics.
This beats Level 0, and it is where I find most mid-sized IT teams. It is also the most expensive place to stop. A model-level count feels like an inventory. It fails at both jobs an inventory actually has.
It fails the pricing job. Network hardware prices by configuration, not by model. Two Catalyst 9300s sharing a model prefix can differ by port count, uplink module, power supply count, license tier, and whether the stacking module is present. A quote built on a model count gets revised downward the moment the buyer receives the pallet. Revisions after shipping are the least favorable negotiations available to you.
It fails the compliance job too. A count cannot be reconciled. Your CMDB says a device existed, and your disposal record says forty-two units went out the door. Nothing proves which forty-two. Chain of custody is a per-serial concept, or it is nothing.
Level 2: Serials, Condition Grades, and Completeness
This is the first level that deserves the word audit. Every asset gets a row. Every row carries make, model, serial, configuration detail, condition grade, and a completeness note.
For network hardware, the configuration detail a buyer cares about is narrower than people expect:
- Port count and port type. Twenty-four versus forty-eight. Copper versus fiber. PoE, PoE+, or UPoE. The PoE variants price differently, and buyers ask first.
- Uplink and expansion modules. Present, absent, and which SKU. An empty uplink slot is a discount.
- Power supplies. How many, what wattage, and whether they are AC or DC. Single supply units and DC units both narrow the buyer pool.
- Firmware or IOS version, and the license tier where the platform is licensed.
- Stack members and stack cables, kept together as a unit and not scattered across the pallet.
- Transceivers and optics, counted separately by form factor and coding. SFP, SFP+, QSFP, and whether they are vendor-coded. Coded optics have a smaller resale audience than generic ones. That is not a defect. It is a pricing fact.
Testing at this level does not need to be elaborate. Power the unit, confirm it boots to a working image, and check that fans and power supplies are healthy. Link-test a sample of ports, not all of them. Ten minutes per device separates working from untested. That grade difference is usually worth far more than ten minutes of technician time.
One ordering point gets missed: capture serials before you test anything. Testing is optional and can be delegated to the buyer under an untested grade. Serial capture cannot be delegated. Once the units leave your building without a serial list, the record is gone permanently.
Level 3: Sanitization Recorded Against Every Serial
Here network hardware stops behaving like the rest of the estate. Most audit processes handle this level badly.
The standard mental model of IT disposal is drive-centric. Wipe the disks, shred what cannot be wiped, keep the certificate. Switches, routers, and firewalls do not fit that model at all. They carry no user data in the conventional sense. They are still often the most sensitive assets on the pallet, because what they carry is the configuration: interface addressing, routing detail, VLAN structure, SNMP community strings, local account credentials, RADIUS and TACACS secrets, VPN pre-shared keys, certificates, and ACLs describing your internal trust boundaries. That material lives in NVRAM and in on-board flash. It is a distinct sanitization problem from a drive, and it needs a distinct procedure.
Two technical points to get right.
First, a factory reset is a starting point, not a finish line. On Cisco Catalyst fixed configuration switches, the VLAN database lives in vlan.dat in flash, outside the startup configuration. Cisco’s own knowledge base documents that VLAN information survives a write erase followed by a reload. The file has to be deleted explicitly. RSA key pairs need zeroizing separately. Any file the previous engineer copied to flash sits there until someone removes it. There is nearly always one.
Second, a degausser is the wrong instrument for this entire class of device. It sanitizes by scrambling a magnetic field. That is a real technique against platters and tape ribbon, and it means nothing to the NAND flash and NVRAM inside a switch supervisor or a firewall chassis. The same limit catches the solid-state drives riding along in the shipment. Their controllers hold back a pool of spare cells that no external field and no host-level overwrite will ever address. Applying a drive-shaped process to a network device is a common way to put an unsanitized asset into the resale channel.
The reference standard is worth reading, not just citing. NIST published Revision 2 of Special Publication 800-88, Guidelines for Media Sanitization as a final document in September 2025. It supersedes the 2014 revision that most disposal policies still quote. It keeps the three familiar categories: Clear, Purge, and Destroy. It is explicit that flash-based storage with spare cells and wear leveling cannot be reliably sanitized by simple overwriting. That is exactly the situation on embedded network hardware. CISA has separately warned that attackers actively collect network device configuration files and crack the older password hash types inside them. Treat Cisco device configuration hygiene as a disposal issue, not only a live-network issue.
Worth pinning to the runbook. On a Catalyst switch, write erase plus reload leaves the VLAN database in flash. It leaves any RSA key pairs in place. It leaves whatever files an engineer once copied onto the device. A reset clears the configuration you can see from the console. It does not clear the device.
So who is going to own the per-device zeroization procedure, the flash inventory, and the evidence trail underneath both? Few network teams want to. One answer is to sell into a buyer that already does it. Big Data Supply buys enterprise switches, routers, and firewalls, and logs custody at each handoff. The custody log is the part that matters to an audit. By the time a switch estate reaches the point of selling used networking equipment in volume, the movement record counts for as much as the payment. The audit you built at Level 2 is what makes the quote accurate.
The audit requirement does not move with the work. Every serial in your list carries a sanitization status, a method, a date, and a responsible party. If a device was sanitized in place before it shipped, record that. If it shipped for the buyer to sanitize under contract, record that too. Keep the certificate when it comes back.
Level 4: Valuation Judged Against the Live Secondary Market
At this level the audit stops being a list and starts being a pricing instrument.
The mistake to avoid is anchoring on internal numbers. Book value tells you what your finance system thinks the asset is worth. Purchase price tells you what you paid in a different market. Neither has any bearing on what a reseller can move the unit for next quarter.
What actually drives the number on network gear:
- Platform generation, set against the vendor’s end-of-sale and end-of-support dates. Demand holds while support is available. It falls off afterward. There is a partial rebound from operators who run gear well past support and need spares.
- Configuration, per the detail captured at Level 2. Higher port count, PoE capability, and dual power supplies all price up.
- Volume and homogeneity. Forty identical switches with matching configuration are worth more per unit than forty mixed units. The buyer can sell them as a block.
- Condition, grade and completeness. This is where the rail kits and the uplink modules pay for themselves.
- Current market conditions, which move. The secondary hardware market has been genuinely volatile over the last two years. Anyone quoting a fixed percentage of list without looking at this month’s demand is guessing.
For a bulk lot, get more than one quote and compare on identical information. The audit makes that possible. If every buyer prices from the same serialized list with the same condition grades, you are comparing offers, not interpretations.
Level 5: A Package a Buyer Can Underwrite
The final level is presentation. Once the audit exists, it is the cheapest of the five to implement.
A buyer-ready listing covers each asset or matched group. It gives the make and model, the full configuration, the serial or serial range, the condition grade with a plain note on any fault, the firmware version, and the completeness detail. Write the condition note honestly. A disclosed fault costs you a small discount. An undisclosed fault found at intake costs you the buyer’s trust, and usually a renegotiation of the entire lot.
Photographs do more work than sellers expect. For network hardware the useful set is specific:
- The front face, showing port banks and any port damage.
- The rear, showing power supply bays, fan trays, and which slots are populated.
- A close shot of the serial and model label.
- A shot of any uplink or expansion module in place.
- One photograph of the pallet or lot as staged. It tells a buyer how the lot will arrive and cuts surprise at intake.
Then the documentation pack: the serialized asset list, the condition grades, the sanitization records tied to serials, and a chain of custody handoff document signed by both parties at collection. Internal teams skip that last item. Auditors ask for it.
Where These Programs Usually Stall
Two failures show up repeatedly. Neither is technical.
The first is ownership. The infrastructure team doing the decommission performs the audit. The risk of an unsanitized configuration sits with security. The value recovery sits with finance or procurement. Three owners, one spreadsheet, and nobody accountable for the record being complete. Naming one owner for the disposal record, before the migration window opens, fixes more than any tooling change.
The second is timing. Audits get scheduled after the new equipment is live. By then the old gear is on a pallet, and the project team has moved on. The configuration knowledge has evaporated. Capture the serial, the configuration, and the sanitization status while the device is still racked and still owned by someone who knows what it does. Put that step in the migration runbook, not the cleanup phase. Then the disposal record gets written by the one engineer who can still explain what each device was doing. That is the only version a buyer or an auditor can rely on.
What to Fix First
At Level 0 or Level 1, do not try to reach Level 5 in one project. Add serial capture to the decommission runbook, then add a sanitization status column beside it. That is Level 2 and most of Level 3, achievable inside one refresh cycle.
The rest follows from there, because every later level reads from the same list. Pricing, listing, photography, and the compliance file are all views of the audit. Without it, what leaves the dock is a pallet with a hope attached to it.
