Unannounced
NAID AAA requires surprise audits of the actual destruction process — not just paperwork reviews.
Vendor Procurement Guide
NAID AAA, ISO 27001, and ISO 9001 answer different vendor-risk questions. This guide explains their scopes, the project evidence to request, and how to evaluate an ITAD provider without treating one credential as a substitute for another.
Reviewed by the SecureErase compliance team · Updated August 19, 2026
Unannounced
NAID AAA requires surprise audits of the actual destruction process — not just paperwork reviews.
ITAD-Specific
The only major certification standard scoped exclusively to data destruction and IT asset disposal.
HIPAA · FACTA · GLBA
These rules create safeguarding or disposal duties, but they do not name NAID AAA as a required certification.
ISO ≠ NAID
ISO 27001, 9001, and others are legitimate — but none verify how a vendor destroys your data.
$5M
SecureErase’s stated insurance limit. Request a current certificate and confirm the applicable coverage with your risk team.
The Common Mistake
When organizations put together vendor checklists, they often treat any ISO certification as a sign of strong data security practices. That’s understandable — ISO is a rigorous global standards system. But for IT asset disposal specifically, ISO certifications answer the wrong questions.
NAID AAA · i-SIGMA
Issued by i-SIGMA (formerly NAID), this certification applies exclusively to ITAD and data destruction service providers. It audits the actual process — not just the policies.
ISO 27001 · ISO 9001
ISO certifications are legitimate and valuable for evaluating a vendor’s overall organizational practices. They’re just not scoped to data destruction — and the audits look very different.
Side-by-Side
This practical comparison summarizes the different scopes described by i-SIGMA and ISO. Confirm a vendor’s current certificates, covered services, and facility before relying on any credential.
NAID AAA · i-SIGMA
Independent auditors show up without warning to watch the actual destruction process. No advance preparation and no policy review substituting for reality.
ISO 27001 · Information Security
Audits are scheduled and focus on policies, risk processes, and controls—not the physical act of destroying your hard drives.
ISO 9001 · Quality Management
Verifies consistent service delivery and customer satisfaction, with no destruction-specific audit scope.
| What it covers | NAID AAA (i-SIGMA) | ISO 27001 | ISO 9001 |
|---|---|---|---|
| Who it applies to | Data destruction and ITAD service providers only — industry-specific and purpose-built. | Any organization handling sensitive information, in any industry. | Any organization in any industry, of any size. |
| Primary focus | Secure destruction of data-bearing media — hard drives, paper, and devices — with chain of custody. | Protecting confidential information from loss, theft, or unauthorized access — broadly. | Consistent delivery of quality products and services; customer satisfaction. |
| Audit style | Announced and unannounced audits conducted under the i-SIGMA certification program. | Announced audits by an accredited certification body: Stage 1 document review and Stage 2 on-site. | Announced audits by an accredited certification body: Stage 1 and Stage 2. |
| Audit frequency | Annual renewal plus random unannounced audits throughout the year. | Annual surveillance audits; full recertification every 3 years. | Annual surveillance audits; full recertification every 3 years. |
| Employee screening | Criminal background checks required for all employees with access to data-bearing media. | Access controls and screening, but no destruction-specific requirements for handlers. | Employee training records required; no background-check mandate for media handlers. |
| Chain of custody | Documented, verified chain of custody from your loading dock through final disposition. | Incident management and access controls; chain of custody for physical media is not specified. | Supplier controls exist; no specific chain of custody for data-bearing media. |
| Data sanitization standard | Destruction procedures and controls are reviewed within the vendor’s certified service scope; ask separately how NIST SP 800-88 is applied. | Physical media destruction methods are referenced in Annex A controls, but are not independently verified as destruction operations. | No data sanitization or media-specific destruction requirements. |
| Certificate of destruction | Required — issued per work order with serial-level detail and retained for 7 years. | Not a requirement of the ISO 27001 standard. | Not a requirement of the ISO 9001 standard. |
| Regulatory alignment | Can support vendor due diligence and operational assurance; applicable laws and contracts determine each organization’s obligations. | Useful for HIPAA, GDPR, CCPA, and FISMA, but not referenced in FACTA or the GLBA Safeguards Rule by name. | General product and service regulatory requirements; no specific data-law alignment. |
| Federal contracting value | May satisfy a solicitation’s destruction-vendor criteria when the procurement document requests it; verify the actual contract language. | Broadly recognized for operational discipline and often preferred in RFPs, but not destruction-specific. | Broadly recognized for quality; not specific to data handling or destruction. |
| Legal defensibility | Provides third-party evidence about the certified operation; it does not by itself establish legal compliance for a customer or project. | Useful evidence of general security posture, but not destruction-specific due diligence under the FTC Disposal Rule. | Demonstrates operational quality, not data-disposal liability controls. |
Procurement Checklist
Paste these into your RFP or vendor qualification form. Any reputable ITAD company should be able to produce all seven without hesitation.
01
Ask for the actual certificate — it should show the issuing body (i-SIGMA), the current certification period, and the facility address. Verify it hasn’t lapsed.
Required — not optional
02
Ask whether all employees with access to your equipment undergo criminal background screening before hire. NAID AAA requires this — but it’s worth confirming explicitly.
NAID AAA requirement
03
Request a sample certificate to confirm it includes work order details, serial-level device data, destruction method, and date certified. This is your legal record — it matters.
Your compliance document
04
Confirm they operate to NIST SP 800-88 (Purge or Clear level, depending on your data classification). Ask how they handle drives that fail the wipe verification — physical destruction is the correct answer.
NIST 800-88 alignment
05
Ask how each asset is tracked from pickup to final disposition. You should be able to match a serial number on your incoming manifest to its destruction record in the closeout report.
Audit trail
06
For anything that can’t be resold, ask whether their downstream recyclers are R2 certified (Responsible Recycling). This closes the chain of custody all the way through.
End-of-chain verification
07
Request a current certificate showing coverage types, limits, insurer, and policy period. Ask your broker or counsel whether additional-insured status or other endorsements are appropriate for the engagement.
Risk review
Critical Question Most Vendors Never Think to Ask
Certification and insurance answer different questions. Review both the vendor’s operational controls and the current policy documents that may respond to a covered event.
SecureErase, LLC · Vendor Protection
Request a current certificate of insurance during procurement and have the appropriate risk professional review the insurer, policy period, limits, coverage types, exclusions, and relationship to the proposed work. A stated limit is not a promise that every event will be covered.
$5M
SecureErase Stated Insurance Limit
Request the current certificate and have your risk team confirm the coverage that applies to the proposed engagement.
NAID AAA Certified · NWBOC Woman-Owned · NIST SP 800-88 Rev. 2-Aligned Methods
SecureErase, LLC
Stated insurance limit. A current certificate is available during vendor due diligence so the details can be reviewed.
Every vendor
Compare current limits, coverage types, policy periods, exclusions, and the work addressed by the policy.
Your RFP
Request a current certificate and any endorsements your broker or counsel determines are appropriate.
Warning Signs
These aren’t disqualifiers on their own — but they’re questions worth pressing on before you commit.
ISO is not a substitute. Without a current NAID AAA certificate, the vendor’s destruction process has not been audited by the standard built for it.
A certificate of destruction isn’t an add-on — it’s what proves the work was done. If a vendor doesn’t produce one automatically per work order, you have no documented record for HIPAA, FACTA, or audit purposes.
If your contact can’t show you a sample manifest, a sample closeout report, or walk you through how a serial number is tracked from intake through destruction, that’s a process gap — not just a documentation gap.
The people loading your equipment into a van and handling it at the facility have access to your data before anything is wiped. If a vendor can’t confirm they background-screen those employees, that’s a real exposure.
A reliable wipe process also handles failures. If a drive can’t be software-wiped to NIST standards, it should be physically shredded — not returned, resold, or quietly set aside. Ask what the failure protocol is.
Regulatory Context
The FTC Disposal Rule and Safeguards Rule describe duties such as reasonable disposal measures and service-provider oversight; they do not name a required certification. NAID AAA can contribute third-party evidence about a destruction provider’s certified operation. ISO 27001 can contribute evidence about an information security management system. Neither credential replaces a review of the actual service scope, contract, custody controls, sanitization methods, or project records.
This is general information, not legal advice. If your compliance team is working from specific regulatory language or internal policy, we are glad to review the exact wording with you.
Requires reasonable measures to dispose of consumer data. NAID AAA maps directly to the vendor due-diligence expectation.
Financial institutions must select and oversee service providers that maintain appropriate safeguards.
Covered entities and Business Associates must protect the confidentiality of PHI through disposal.
The federal standard for media sanitization and verification.
Due Diligence
These questions will reveal more about a vendor’s actual practices than any marketing page will — including the two that most procurement teams never think to ask.
A certified vendor will produce this immediately. It should show i-SIGMA as the issuing body, a current date range, and the specific facility. Lapsed or missing means not certified.
NAID AAA includes random, unannounced audits. A certified vendor will know this answer. “We haven’t had one” or a blank look is a flag — check the certificate’s currency.
The correct answer: it’s flagged and physically shredded, never resold or returned. This is table stakes for NAID AAA compliance and basic data-security practice.
A solid ITAD vendor should be able to walk you through its intake manifest, processing system, and closeout report — showing how a serial number moves through every step.
NIST SP 800-88 is the answer. Ask whether they operate to Purge level or Clear level and how they select the method per device type.
This covers the people on the pickup truck and on the processing floor — not just the account manager. NAID AAA requires this; ask for the policy in writing.
It should list the work order, customer details, per-device serial numbers, destruction method used, date completed, and issuing party. A one-page summary without device detail is not sufficient for most compliance needs.
Any equipment that can’t be sanitized and resold goes to a recycler. R2 certification helps ensure those partners meet environmental and data-security standards too.
Ask for the current certificate, dollar limits, coverage types, policy period, and any endorsements your risk team requires. SecureErase states a $5 million limit; the current evidence should be reviewed for the proposed engagement.
Either an accredited third party audits the destruction process, or it doesn’t. NAID AAA means unannounced independent auditors verified the actual destruction. Self-reported compliance does not provide the same assurance. Ask for the auditor’s name and most recent audit date.
Work With a NAID AAA Certified ITAD Provider
Woman-owned, NWBOC certified, and audited unannounced by i-SIGMA — we can show you our certificate, our sample Certificate of Destruction, and walk you through exactly how your equipment is tracked from pickup to final disposition.
Procurement Evidence
SecureErase can provide current evidence during due diligence. Your team should review each document against the proposed facility, service scope, contract, and internal requirements.
Request the current certificate and confirm its service and facility scope.
Review the asset-level fields and the record produced after processing.
See the supported device methods, fallback path, and verification process.
Follow the documented path from receipt through inventory, processing, and certification.
Request a current certificate for review by your broker, counsel, or risk team.
Confirm reporting, exception handling, and closeout expectations in the quote.
Documentation