Chain of Custody for Digital Evidence: What the Expert Has to Testify To
- AUTHOR
- J-Michael Roberts
- PUBLISHED
- April 9, 2026
- READ TIME
- 12 min
- REVISED
- 2026-09-10
SENIOR DIRECTOR, HEAD OF NEW YORK OFFICE, LAW & FORENSICS
Chain of custody is the part of a forensic engagement most often described as paperwork and most often litigated as substance. It is a documentary record, not a technical control, and the expert is the person who has to stand behind it under oath. This is what that record has to contain, how the Federal Rules of Evidence actually treat it, where it fails in practice, and — the part reports usually skip — what a perfect custody record still does not prove.
What is chain of custody for digital evidence?
A chain of custody is the documented, continuous account of who held an item of evidence, when, where it was stored, and what was done to it, from the moment it was collected until it is offered in court. For digital evidence it covers two things at once: the physical object, if there is one, and the data extracted from it — because the data is copied, and every copy needs its own traceable history back to a source whose integrity can be demonstrated.
The reason it is the expert's problem rather than the paralegal's is that the expert is the one asked, on cross-examination, to say whether the exhibit is what it purports to be. That answer rests on records the expert either created, supervised, or inherited — and inheriting a custody record built by someone else is where the exposure lives.
What do the Federal Rules actually require?
Less than most people assume, and in a different shape. Rule 901(a) sets the bar for authentication generally: evidence sufficient to support a finding that the item is what the proponent claims. That is a conditional-relevance threshold, not a demand for certainty, and Rule 901(b) lists illustrative ways of meeting it — including 901(b)(9), evidence describing a process or system and showing that it produces an accurate result, which is the provision a forensic acquisition method is usually authenticated under.
Rules 902(13) and 902(14), added effective December 1, 2017, permit self-authentication by certification. Rule 902(13) covers records generated by an electronic process or system, certified by a qualified person; 902(14) covers data copied from an electronic device, storage medium or file, where the copy is authenticated by a process of digital identification — in practice, hash comparison — and again certified by a qualified person. Both require the same written notice and opportunity-to-inspect procedure that Rule 902(11) uses for business records.
What that architecture means for the expert is worth stating plainly, because it is regularly overstated in both directions. Rule 902(14) removes the need to call a live witness merely to say a copy is a true copy; it does not remove the need for a defensible acquisition, and a certification signed by a person who cannot describe the process is worth what any unsupported certificate is worth. Nor does authentication resolve hearsay, best-evidence, or Rule 702 reliability. It gets the exhibit in the door.
What belongs in the custody record?
A usable custody record is one a stranger could reconstruct the history from without asking anyone a question. The fields below are the ones whose absence actually gets noticed.
| FIELD | WHY IT IS ASKED ABOUT |
|---|---|
| Item identity | Make, model, serial number, capacity, and any asset tag — recorded on receipt, with photographs. A record identifying "the laptop" cannot be matched to a device two years later. |
| Condition and state on receipt | Powered on or off, damaged or intact, encrypted volume mounted or not. State on receipt determines what acquisition was possible and pre-empts the argument that something was lost in handling. |
| Acquisition method and tooling | Tool, version, write-blocking method, image format, and whether the acquisition was live or static. Versions matter: tool behaviour changes between releases and the report has to say which behaviour applied. |
| Acquisition and verification hashes | The algorithm, the value, and the time each was computed. A verification hash taken at acquisition and recomputed later is the evidence that nothing changed in between. |
| Custodian transfers | Every hand-off: from whom, to whom, when, by what means, and for what purpose — including shipment, with tracking, and including internal transfers between examiners. |
| Storage | Where the item and the images were held between transfers, and what restricted access to them. "In the lab" is not an answer; a specific secured location with controlled access is. |
| Working copies | Which copies were made, from which source, when, and which one each analysis was run against — so a finding can be traced back to a specific verified image rather than to "the data". |
What does a hash actually prove about custody?
This is the single most over-claimed point in custody testimony. A cryptographic hash computed at acquisition and recomputed later demonstrates that the data has not changed between those two computations. That is a real and valuable thing, and it is the entire claim. It says nothing whatsoever about the period before the first hash was taken.
So if a custodian used the device for a week, or an IT administrator ran triage tooling on it, or someone opened files to see what was there, hashing afterwards freezes the altered state and proves the alteration was preserved faithfully. An expert who answers "the hashes match, so the evidence is unaltered" has answered a narrower question than the one asked, and the follow-up — unaltered since when? — is the one that does the damage.
A related caveat applies where no static image was possible. A live acquisition of a running server, or an export pulled from a cloud tenant through an API, cannot be verified by re-reading the source and getting the same value, because the source is not the same source any more. The honest record hashes the resulting image or export on receipt, states that the acquisition was live and why, and does not imply a source-to-image verification that did not occur.
What is the difference between a gap and a break in the chain?
The distinction decides whether counsel is arguing about admissibility or about weight, and it is the distinction most often collapsed in briefing. A gap is a missing entry: an undocumented interval where nothing shows the item was tampered with and nothing shows it was not. A break is an interval where the record affirmatively shows the evidence was accessible to alteration, or where the integrity check fails.
Courts generally treat imperfections in a chain of custody as going to weight rather than admissibility, on the reasoning that Rule 901 asks for evidence sufficient to support a finding rather than proof beyond doubt. That is a general tendency and not a rule an expert should recite as one — the outcome turns on the record, the jurisdiction, and how much the gap plausibly matters. What is reliably true is that the argument runs better for the side whose expert identified the gap in the report than for the side whose expert was shown it at deposition.
The practical consequence is a reporting habit rather than a handling one. Where the expert took custody after someone else, the report should say when the expert's own record begins, what it inherited, and what is documented about the period before. That sentence costs nothing when the chain is clean and is the difference between a disclosed limitation and a concealed one when it is not.
Where does chain of custody actually fail?
Almost never through malice, and almost never at the expert's bench. It fails in the interval between the event and the engagement, while everyone involved is still treating the matter as an IT problem.
- Self-collection by the custodian — the person whose conduct is in question is asked to gather their own documents, which puts the collection and the collector in the same dispute
- Triage before preservation — an administrator runs anti-malware, rotates credentials, reimages the machine or restores from backup, each of which is competent IT practice and each of which destroys artifacts
- Screenshots offered in place of an extraction, which capture a rendering rather than the underlying record and carry none of the metadata that would authenticate it
- A device left connected to a network, where remote-wipe commands, synchronised deletions and disappearing-message timers continue to execute on evidence nobody has isolated
- Original media used as a working copy, so every analytical step writes to the thing that was supposed to be preserved
- A cloud account deprovisioned on the ordinary HR schedule, taking the mailbox, the drive and in some configurations the audit records with it
Two of those are worth separating from the rest because they are frequently defended as reasonable. Reimaging is normal remediation and is often required to get a business running again — but it is also the single act most likely to erase the record of how an intrusion began, which is why preservation ordering matters more than remediation speed in any matter likely to be litigated. And synchronised deletion is not deletion by anyone at the keyboard: an account that removes a file on one device removes it on the others, which means an unisolated device can lose evidence with nobody having touched it.
How does custody work when there was never a physical object?
Most evidence in current matters is collected from a tenant or a service rather than seized from a desk, and the custody concept has to be translated rather than abandoned. There is no seizure, no shipping, and no storage locker. What replaces them is the collection record: the account and role used to run the collection, the exact query or API call, the parameters including the date range and time zone, the tool and version, the time the export completed, any provider-supplied integrity value, and the hash computed on receipt.
Two properties of that record differ from a physical chain and both should be stated rather than glossed. First, the collection is not repeatable in the ordinary case: run the same query in six months and retention will have removed part of the answer, so the export is a snapshot whose reproducibility has an expiry date. Second, the collecting account's own privileges are part of the record, because an export scoped by permissions is an export whose completeness depends on them. An expert who cannot say what the collection account could and could not see cannot say what the absence of a record means.
What does a clean chain of custody not establish?
It establishes provenance and integrity of the data. It is silent on everything the data is being offered to prove, and conflating the two is a common enough error to be worth listing.
- It does not make the contents accurate. A faithfully preserved log is a faithful copy of whatever the system wrote, including whatever the system wrote wrongly.
- It does not attribute an act to a person. Custody covers the evidence, not the conduct recorded in it; an account name in a preserved log is still an account name.
- It does not establish completeness. A verified image of one device says nothing about the devices that were never collected, and a verified export says nothing about what fell outside its date range or the collector's permissions.
- It does not satisfy Rule 702. Authenticating the data is separate from qualifying the methodology applied to it, and an opinion can be excluded on evidence whose custody nobody disputes.
- It does not cure spoliation. Preserving what remains after material was destroyed documents the survivors; it does not recover the destroyed material or establish what it contained.
Custody testimony in a matter with mobile devices
Phones sit inside the same custody framework and add two complications to it. The first is isolation: a handset that remains on a network can receive a remote wipe, complete a synchronised deletion, or run out an ephemeral-message timer while it sits in an evidence bag, so isolation is a preservation step rather than a precaution. The second is that the extraction available depends on the device, its operating-system build and its lock state, so the custody record has to say which method was used and what it could not reach — an extraction that did not recover a category of data is not evidence that the category was empty.
The extraction techniques themselves, and their behaviour across current iOS and Android builds, are a specialist subject covered on the firm's dedicated mobile forensics site. The point that belongs here is the custody one: the expert who testifies about a phone extraction is testifying about a record they may not have created, and the questions are the same as for any other inherited chain — when does my own documentation begin, and what is documented about the period before it.
Does a broken chain of custody make digital evidence inadmissible?
Not automatically. Rule 901(a) asks for evidence sufficient to support a finding that the item is what it is claimed to be, and courts commonly treat imperfections in the chain as bearing on weight rather than admissibility. How far that carries depends on the record and the jurisdiction: a documentary gap with no indication of alteration is treated differently from an integrity check that fails.
How long does a chain of custody have to be maintained?
Until the evidence is no longer needed for the proceeding, including any appeal, and the record itself should outlive the engagement. The practical reason is the four-year testimony history a retained expert discloses under Rule 26(a)(2)(B)(v): an expert may be asked about handling in a matter that closed years earlier.
Can a screenshot ever substitute for a forensic extraction?
It can evidence what a screen displayed, which is occasionally the fact in issue. It cannot substitute for an extraction, because it captures a rendering rather than the stored record and carries none of the underlying metadata — the database row, its timestamps, its identifiers — that would let anyone verify it or place it in a timeline.
Who signs the Rule 902(14) certification?
A qualified person, meaning someone who could testify to the process of digital identification used to authenticate the copy — in practice the examiner who performed or supervised the acquisition and the hash comparison. The certifying party must also give the adverse party written notice and make the record and certification available for inspection, so the certificate is a substitute for live foundation testimony rather than a substitute for the foundation.
Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals. If you have a matter where digital evidence is in play, start a scoping conversation or reach us directly below.
ENGAGE AN EXPERT→Or write to info@lawandforensics.com or call 855-529-2466.
Attorney advertising / expert services. General information, not legal advice. Case examples are anonymized except where publicly identified.