Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do DFIR firms preserve chain of custody?

Updated

A chain of custody is the chronological record of digital evidence: who collected it, hashes, every transfer, and the working copy examiners use. DFIR firms keep that record so another examiner can reconstruct handling. This page is not legal advice.

Operational guidance, last verified 7 September 2026 against NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), ISO/IEC 27037 (guidelines for identification, collection, acquisition and preservation of digital evidence — a standard of guidelines, not a law; the full text is paywalled), and RFC 3227 (Guidelines for Evidence Collection and Archiving — IETF BCP 55, a Best Current Practice, not a statute). Legal admissibility is a forum-specific rules-of-evidence question (for context: US Federal Rule of Evidence 901 on authentication); it is not the same as a NIST guide, an ISO standard of guidelines, or an IETF BCP. This page does not rank DFIR firms, does not name any, does not start a notification clock, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The preserve-evidence page on this site is the capture list. The what-is-dfir page on this site is the explainer. The never-delete-after-breach page on this site is the anti-list. The best-digital-forensics-firms page on this site is the criteria checklist (not a ranking). A dedicated information-to-give-a-dfir-firm guide is not on this site yet. Not legal advice.

What a chain of custody records

Audience: a CISO, counsel, incident commander, or engineering leader who needs to know what 'chain of custody' actually is before a DFIR firm starts moving images. The preserve-evidence page on this site is the capture list and the field list this record sits on. The what-is-dfir page on this site is the explainer (identify, preserve, analyze, report; forensic soundness; chain of custody). The never-delete-after-breach page on this site is the isolate-don't-destroy anti-list. The best-digital-forensics-firms page on this site is the criteria checklist (not a ranking). This page is the handling record: what a chain records, how transfers and hashes work, why examiners use a working copy, a fictional custody-log example, and what to demand of a provider. It does not rank DFIR firms, does not name any, and does not ship a downloadable form. The how-to-select-a-dfir-provider page on this site is the selection decision tree. A dedicated information-to-give-a-dfir-firm guide is not on this site yet.

NIST SP 800-86 describes chain of custody as tracking movement of evidence through collection, safeguarding, and analysis by documenting each person who handled it, the date and time of collection or transfer, and the purpose of the transfer. The chain is itself evidence. A Slack 'fyi' is not a chain. Last verified 7 September 2026. Not legal advice.

  • At collection: what it is; unique ID; source system / volume / account; UTC date and time; collector name and role; method and tool (name, version, command line); hashes of original and copy; where the original and the working copy now live; why it was taken.
  • At every transfer: from whom, to whom, UTC time, why, receiving storage, and a confirmation the hashes still match on receipt.
  • In storage: location, access list, write-protect or equivalent, access logs on the evidence store, and any deviation (live capture you could not write-block, a cloud API with no snapshot).
  • Limit handlers. Every extra copy is another transfer you must record. NIST SP 800-61r2 wants designated people, not a blast.
  • This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, and is not legal advice.

Four kinds of claim — do not mix them

A matching hash, a filled log, and a court ruling are not the same kind of claim. This page keeps them apart. Last verified 7 September 2026. Not legal advice.

Legal admissibility vs standards-body guidance vs best practice vs SRM recommendation (not a ranking, not legal advice)
Kind of claimWhat it isWhat this page does with it
Legal admissibilityWhether a particular copy is admitted in a particular forum. In US federal court, Federal Rule of Evidence 901 addresses authentication; a chain of custody is one way parties try to show an item is what they claim. Other forums have their own rules. Admissibility is a ruling on YOUR facts, not a property of a hash.Cited for context only. This page is not legal advice, not a determination that YOUR copy will be admitted, and not a substitute for counsel in YOUR forum.
Standards-body guidanceNIST SP 800-86 (guide to integrating forensic techniques into IR — guidance, not a statute). ISO/IEC 27037 (guidelines for identification, collection, acquisition and preservation of digital evidence — a standard of guidelines, not a law; the full text is paywalled). ISO/IEC 27041, 27042, and 27043 are related standards of guidelines on assurance of methods, analysis and interpretation, and incident investigation; they are named here, not reproduced.This page teaches the handling those documents describe. A guide or a standard of guidelines is not a statute and not a court ruling.
Best practiceRFC 3227 is IETF BCP 55 — Guidelines for Evidence Collection and Archiving. Teaching order of volatility; make a bit-level copy; do not analyse the evidence copy. SWGDE publishes consensus digital-evidence guidelines. Neither is a statute.Used as practitioner method. A Best Current Practice is not a legal duty. SWGDE is not a ranking of firms.
SRM recommendationWhat this page tells you to record and demand: a chronological log, hashes at acquisition and transfer, examination on a working copy, limited handlers, documented gaps. The product does not keep a chain of custody.Our operational recommendation, not a legal duty, not a product feature, and not a ranking. Record the chain where YOUR procedure says — paper, a counsel-held log, the DFIR firm's system.

Hashes and the working copy

A hash is a cryptographic digest of the bits. Record it for the original and for the copy at acquisition, and again at every transfer. A match is an integrity check: the bits you have now are the bits you hashed then. A match is not a ruling that a court will admit the copy. NIST SP 800-86 treats hashing as part of preserving integrity during collection — guidance, not a statute. Last verified 7 September 2026. Not legal advice.

  • Working copy, not the original. Acquire, hash, and examine a duplicate. NIST SP 800-86: collection should preserve the integrity of the data. RFC 3227: make a bit-level copy and do not analyse the evidence copy.
  • Name the algorithm YOUR procedure names (MD5, SHA-1, or SHA-256 are common in notes). Record tool, version, and command line so another examiner can repeat the digest.
  • Hash original and copy at acquisition. Confirm the hashes still match on every receipt. A mismatch is the record: stop, write what happened, and do not silently re-hash until it looks right.
  • Use write-blocking on media you can write-block. Live memory and some cloud APIs have no write-blocker. Document the gap: how, why, who, when (UTC).
  • Personnel should be trained for the method they are using. NIST SP 800-86: untrained collection is how originals get written.

The transfer log

Every time the evidence changes hands or storage, the chain gets a row. From whom, to whom, UTC time, purpose, receiving location, and the hash check on receipt. Wide distribution of the image is how the chain and privilege both fray. Counsel-directed collection is common practice so working papers can sit under attorney-client privilege and work-product; that is practice, not a ruling that privilege will attach. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Last verified 7 September 2026. Not legal advice.

Transfer-log fields (NIST SP 800-86-class handling record — not a form this product provides, not legal advice)
FieldWhat to writeLimit
From / toNamed person and role on each side. A team alias is not a person. A ticket queue is not a recipient.Every extra copy is another transfer. Limit handlers.
WhenUTC date and time of the hand-off, not 'this afternoon' and not a local clock you cannot place.Clock skew belongs in the notes. The incident-timeline page on this site is the UTC discipline.
WhyPurpose of the transfer: examination, storage, return, counsel review. NIST SP 800-86 asks for the purpose.A purpose is not a legal conclusion and not a notification filing.
WhereReceiving store: locker ID, evidence-vault path, write-protected volume, sealed bag. The working copy's store is a different row from the original's.A laptop Downloads folder is not an evidence store.
Hash on receiptRe-digest on arrival. Record match or mismatch. A match continues the chain; a mismatch is the event.A matching hash is an integrity check, not admissibility.

Worked custody-log example (fictional)

The table below is invented. Cedar & Pine Analytics Ltd, incident INC-FIC-2026-0914, workstation WS-4412, and the people and hashes are fictional. It is a teaching log, not a real case, not YOUR form, and not a downloadable template this product ships. Hashes are labelled fictional. Last verified 7 September 2026. Not legal advice.

Fictional custody log — Cedar & Pine Analytics Ltd, INC-FIC-2026-0914. Invented names, hosts, and hashes. Not a real case, not a form this product provides, not legal advice.
UTC time (fictional)ActionFrom → toSHA-256 (fictional)Notes
2026-09-14 18:42:11ZCollected memory image MEM-001 of workstation WS-4412A. Rivera (IR lead, Cedar & Pine) acquired on-hostc0ffee00deadbeef0123456789abcdef0123456789abcdef0123456789abcdefTool name, version, and command line recorded. Original sealed to locker L-3. Working copy not yet issued. Live memory: no write-blocker; gap recorded.
2026-09-14 19:10:04ZTransfer of original image for examinationA. Rivera → M. Okonkwo (DFIR examiner, retained firm)Same digest confirmed on receiptPurpose: forensic examination. Hash matched. This page does not name a real firm.
2026-09-14 19:22:40ZWorking copy issuedM. Okonkwo → analysis workstation FORENSIC-07 (write-protected store)Same digest on the working copyOriginal remains in locker L-3. Examination on the working copy only. RFC 3227: do not analyse the evidence copy.
2026-09-15 11:03:18ZWorking copy returned to evidence storeFORENSIC-07 → locker L-3 (working-copy shelf)Hash re-verified, matchAnalysis notes cite MEM-001 and this hash. Original never mounted. Fictional example ends here.

What to demand of a DFIR provider — verification checklist

These are handling questions, not a ranking and not a vendor list. Verify against YOUR engagement letter and YOUR procedure. The best-digital-forensics-firms page on this site is the criteria checklist (not a ranking). The how-to-select-a-dfir-provider page on this site is the selection decision tree. A dedicated information-to-give-a-dfir-firm guide is not on this site yet. Last verified 7 September 2026. Not legal advice.

  • A written chain of custody for every item: unique ID, UTC times, named handlers, purpose of each transfer, storage location.
  • Hashes of original and working copy at acquisition, and a hash check recorded on every receipt. Name the algorithm.
  • Examination on a working copy. Original stored write-protected. RFC 3227: do not analyse the evidence copy.
  • Tool name, version, and command line in the notes so another examiner can reconstruct the acquisition.
  • Documented gaps where write-blocking was impossible (live memory, some cloud APIs).
  • Limited handlers. Ask who else will receive a copy and why.
  • Counsel-directed engagement is common practice for privilege; it is not a ruling that privilege will attach. The contact-breach-counsel page on this site is that checklist.
  • This page does not rank DFIR firms, does not name any, and does not interpret YOUR panel or policy.

What you need to do now

If evidence is already moving, start the log on the next transfer — do not wait for a prettier form. If nothing has been collected yet, the preserve-evidence page on this site is the capture order. Isolate, do not wipe. Last verified 7 September 2026. Not legal advice.

  • Open a chain for each item you already have: unique ID, UTC time, who holds it, hashes if they exist, where it lives.
  • Stop informal copies. A shared drive dump is a transfer you did not record.
  • Work from a working copy. Hash original and copy. Do not analyse the evidence copy.
  • Call counsel before you spread the image. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • The never-delete-after-breach page on this site is the anti-list that keeps this chain from becoming a story about a wiped host.

Glossary

Terms as this page uses them. Where a source names the idea, the kind of source is in the third column so a guidance document is not mistaken for a statute. Last verified 7 September 2026.

Chain-of-custody glossary (definitions for this page — not legal advice, not a ranking)
TermMeaning on this pageKind of source
Chain of custodyThe chronological record of who handled the evidence, when, where, how, why, and where it was stored, including every transfer and the hashes.NIST SP 800-86 (guidance). The record is itself evidence. This page does not ship YOUR form.
HashA cryptographic digest of the original and the copy, recorded on the chain so a later reader can see whether the bits changed.NIST SP 800-86 integrity check (guidance). A match is not a ruling of admissibility.
Working copyThe duplicate you examine so the original stays unchanged. Hashes of original and copy should match at acquisition.NIST SP 800-86 collection / examination (guidance). RFC 3227: do not analyse the evidence copy.
Transfer logThe subset of the chain that records each hand-off: from, to, UTC time, purpose, receiving store, hash on receipt.NIST SP 800-86 (guidance): person, date and time, purpose of the transfer.
Write-blockingA hardware or software control that prevents writes to the original media during acquisition.NIST SP 800-86-class method (guidance). Not always available. Document the gap.
AdmissibilityWhether a particular copy is admitted in a particular forum. Not a property of a hash and not a NIST checkbox.Rules of evidence in THAT forum (for context: FRE 901 in US federal court). Not legal advice.

Where this shows up in ShipReady Metrics

This product does not keep a chain of custody. The signed-in app does not image hosts, keep a chain of custody, produce a forensic report, retain a DFIR firm, or file with a regulator. It does not rank forensic vendors and does not ship a downloadable custody form. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. Compliance surfaces also hold evidence artifacts (control-mapped collection and review for SOC 2 / ISO 27001-style programs — a timestamped evidence record for controls, not a host image and not a forensic chain of custody). The cyber risk register lives under Security. None of those surfaces preserves volatile memory, images a disk, or substitutes for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

NIST SP 800-86 (August 2006), Guide to Integrating Forensic Techniques into Incident Response, remains the current final guide this page cites for collection that preserves integrity, working copies, hashes, trained personnel, and chain of custody — documenting each person who handled the evidence, the date and time of collection or transfer, and the purpose of the transfer. Guidance, not a statute, last verified still final on 7 September 2026. ISO/IEC 27037 is a standard of guidelines for identification, collection, acquisition, and preservation of digital evidence; it is not reproduced here, is not a law, and the full text is paywalled. ISO/IEC 27041, 27042, and 27043 are related standards of guidelines (assurance of suitability and adequacy of methods; analysis and interpretation; incident investigation principles); they are named, not reproduced. RFC 3227 (February 2002), Guidelines for Evidence Collection and Archiving, is IETF BCP 55 — a Best Current Practice, not a statute; make a bit-level copy and do not analyse the evidence copy. SWGDE publishes consensus digital-evidence guidelines, not a statute and not a ranking of firms. Federal Rule of Evidence 901 is cited for context as a US federal authentication rule, not as a global statute and not as a determination that YOUR copy is admissible. NIST SP 800-61 Revision 2 remains the current final Computer Security Incident Handling Guide this cluster cites for designated handlers and for acquire, preserve, secure, and document — guidance, not a statute.

Frequently asked questions

What is a chain of custody?

The chronological record of digital evidence: who collected it, when (UTC), where, how, why, who it was transferred to, where it was stored, and the hashes of original and copy. NIST SP 800-86 tracks movement through collection, safeguarding, and analysis. The chain is itself evidence. A Slack ping is not a chain. This product does not keep one. Not legal advice.

What is a working copy, and why hash both?

The duplicate you examine so the original stays unchanged. Hash the original and the copy at acquisition; a match is an integrity check that the bits agree. RFC 3227: make a bit-level copy and do not analyse the evidence copy. A matching hash is not a ruling of admissibility. Not legal advice.

Does a matching hash mean the evidence is admissible?

No. A match is an integrity check under NIST SP 800-86-class handling, not a court ruling. Admissibility is a forum-specific rules-of-evidence question (for context: US Federal Rule of Evidence 901 on authentication). Other forums have their own rules. Counsel on YOUR facts owns that question. This page is not legal advice.

Does ShipReady Metrics keep a chain of custody?

No. This product does not keep a chain of custody, image hosts, produce a forensic report, retain a DFIR firm, or ship a downloadable custody form. It does have Compliance → CRA reporting (the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for CRA-in-scope findings), evidence artifacts on compliance surfaces (control-mapped collection — not a forensic chain), and a cyber risk register under Security. None of those is a forensic exam. Not legal advice.

Is this legal advice?

No. It is operational guidance distilled from NIST SP 800-86, ISO/IEC 27037 (named as a standard of guidelines; the full text is paywalled), and RFC 3227 (IETF BCP 55). Whether a copy is admissible, whether privilege attaches, whether a notification duty applies, and which firm to retain are questions for counsel on YOUR facts. This page does not rank DFIR firms and does not start a notification clock.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.