Vendor Procurement Guide

NAID AAA vs. ISO for ITAD vendor due diligence.

NAID AAA, ISO 27001, and ISO 9001 answer different vendor-risk questions. This guide explains their scopes, the project evidence to request, and how to evaluate an ITAD provider without treating one credential as a substitute for another.

Reviewed by the SecureErase compliance team · Updated August 19, 2026

Unannounced

NAID AAA requires surprise audits of the actual destruction process — not just paperwork reviews.

ITAD-Specific

The only major certification standard scoped exclusively to data destruction and IT asset disposal.

HIPAA · FACTA · GLBA

These rules create safeguarding or disposal duties, but they do not name NAID AAA as a required certification.

ISO ≠ NAID

ISO 27001, 9001, and others are legitimate — but none verify how a vendor destroys your data.

$5M

SecureErase’s stated insurance limit. Request a current certificate and confirm the applicable coverage with your risk team.

The Common Mistake

ISO certifications are real — they just don’t cover what you think they do.

When organizations put together vendor checklists, they often treat any ISO certification as a sign of strong data security practices. That’s understandable — ISO is a rigorous global standards system. But for IT asset disposal specifically, ISO certifications answer the wrong questions.

NAID AAA · i-SIGMA

Built for data destruction

Issued by i-SIGMA (formerly NAID), this certification applies exclusively to ITAD and data destruction service providers. It audits the actual process — not just the policies.

  • Announced and unannounced audits under the certification program
  • Employee screening requirements for covered roles
  • Operational security and chain-of-custody controls
  • Destruction procedures within the certified scope
  • Written policies, records, and incident controls
  • Service and facility scope shown on the certificate
  • Ongoing certification and audit requirements

ISO 27001 · ISO 9001

Built for general operations

ISO certifications are legitimate and valuable for evaluating a vendor’s overall organizational practices. They’re just not scoped to data destruction — and the audits look very different.

  • Scheduled, announced audits — documentation and process review
  • Applies to any industry and organization size
  • No destruction-specific sanitization requirements
  • No chain of custody for data-bearing media
  • No provisions for certificate of destruction
  • No NIST 800-88 or equivalent media-specific requirements
  • Full recertification every 3 years

Side-by-Side

How NAID AAA compares to the ISO standards you may already be tracking.

This practical comparison summarizes the different scopes described by i-SIGMA and ISO. Confirm a vendor’s current certificates, covered services, and facility before relying on any credential.

NAID AAA · i-SIGMA

Unannounced Audits

Independent auditors show up without warning to watch the actual destruction process. No advance preparation and no policy review substituting for reality.

ISO 27001 · Information Security

Announced Audits

Audits are scheduled and focus on policies, risk processes, and controls—not the physical act of destroying your hard drives.

ISO 9001 · Quality Management

Announced Audits

Verifies consistent service delivery and customer satisfaction, with no destruction-specific audit scope.

What it covers NAID AAA (i-SIGMA) ISO 27001 ISO 9001
Who it applies to Data destruction and ITAD service providers only — industry-specific and purpose-built. Any organization handling sensitive information, in any industry. Any organization in any industry, of any size.
Primary focus Secure destruction of data-bearing media — hard drives, paper, and devices — with chain of custody. Protecting confidential information from loss, theft, or unauthorized access — broadly. Consistent delivery of quality products and services; customer satisfaction.
Audit style Announced and unannounced audits conducted under the i-SIGMA certification program. Announced audits by an accredited certification body: Stage 1 document review and Stage 2 on-site. Announced audits by an accredited certification body: Stage 1 and Stage 2.
Audit frequency Annual renewal plus random unannounced audits throughout the year. Annual surveillance audits; full recertification every 3 years. Annual surveillance audits; full recertification every 3 years.
Employee screening Criminal background checks required for all employees with access to data-bearing media. Access controls and screening, but no destruction-specific requirements for handlers. Employee training records required; no background-check mandate for media handlers.
Chain of custody Documented, verified chain of custody from your loading dock through final disposition. Incident management and access controls; chain of custody for physical media is not specified. Supplier controls exist; no specific chain of custody for data-bearing media.
Data sanitization standard Destruction procedures and controls are reviewed within the vendor’s certified service scope; ask separately how NIST SP 800-88 is applied. Physical media destruction methods are referenced in Annex A controls, but are not independently verified as destruction operations. No data sanitization or media-specific destruction requirements.
Certificate of destruction Required — issued per work order with serial-level detail and retained for 7 years. Not a requirement of the ISO 27001 standard. Not a requirement of the ISO 9001 standard.
Regulatory alignment Can support vendor due diligence and operational assurance; applicable laws and contracts determine each organization’s obligations. Useful for HIPAA, GDPR, CCPA, and FISMA, but not referenced in FACTA or the GLBA Safeguards Rule by name. General product and service regulatory requirements; no specific data-law alignment.
Federal contracting value May satisfy a solicitation’s destruction-vendor criteria when the procurement document requests it; verify the actual contract language. Broadly recognized for operational discipline and often preferred in RFPs, but not destruction-specific. Broadly recognized for quality; not specific to data handling or destruction.
Legal defensibility Provides third-party evidence about the certified operation; it does not by itself establish legal compliance for a customer or project. Useful evidence of general security posture, but not destruction-specific due diligence under the FTC Disposal Rule. Demonstrates operational quality, not data-disposal liability controls.

Procurement Checklist

Seven things to require from any ITAD vendor before you sign.

Paste these into your RFP or vendor qualification form. Any reputable ITAD company should be able to produce all seven without hesitation.

01

Current NAID AAA Certificate

Ask for the actual certificate — it should show the issuing body (i-SIGMA), the current certification period, and the facility address. Verify it hasn’t lapsed.

Required — not optional

02

Employee Background Check Policy

Ask whether all employees with access to your equipment undergo criminal background screening before hire. NAID AAA requires this — but it’s worth confirming explicitly.

NAID AAA requirement

03

Sample Certificate of Destruction

Request a sample certificate to confirm it includes work order details, serial-level device data, destruction method, and date certified. This is your legal record — it matters.

Your compliance document

04

Data Sanitization Standard

Confirm they operate to NIST SP 800-88 (Purge or Clear level, depending on your data classification). Ask how they handle drives that fail the wipe verification — physical destruction is the correct answer.

NIST 800-88 alignment

05

Chain of Custody Documentation

Ask how each asset is tracked from pickup to final disposition. You should be able to match a serial number on your incoming manifest to its destruction record in the closeout report.

Audit trail

06

Downstream Recycler Certifications

For anything that can’t be resold, ask whether their downstream recyclers are R2 certified (Responsible Recycling). This closes the chain of custody all the way through.

End-of-chain verification

07

Current Certificate of Insurance

Request a current certificate showing coverage types, limits, insurer, and policy period. Ask your broker or counsel whether additional-insured status or other endorsements are appropriate for the engagement.

Risk review

Critical Question Most Vendors Never Think to Ask

What happens if something goes wrong — and who’s paying for it?

Certification and insurance answer different questions. Review both the vendor’s operational controls and the current policy documents that may respond to a covered event.

SecureErase, LLC · Vendor Protection

SecureErase states a $5 million insurance limit.

Request a current certificate of insurance during procurement and have the appropriate risk professional review the insurer, policy period, limits, coverage types, exclusions, and relationship to the proposed work. A stated limit is not a promise that every event will be covered.

$5M

SecureErase Stated Insurance Limit

Request the current certificate and have your risk team confirm the coverage that applies to the proposed engagement.

NAID AAA Certified · NWBOC Woman-Owned · NIST SP 800-88 Rev. 2-Aligned Methods

SecureErase, LLC

$5,000,000

Stated insurance limit. A current certificate is available during vendor due diligence so the details can be reviewed.

Every vendor

Verify scope

Compare current limits, coverage types, policy periods, exclusions, and the work addressed by the policy.

Your RFP

Evidence + review

Request a current certificate and any endorsements your broker or counsel determines are appropriate.

Warning Signs

Red flags when evaluating an ITAD vendor.

These aren’t disqualifiers on their own — but they’re questions worth pressing on before you commit.

“We’re ISO certified” — but can’t produce a NAID AAA certificate

ISO is not a substitute. Without a current NAID AAA certificate, the vendor’s destruction process has not been audited by the standard built for it.

No certificate of destruction offered as a standard deliverable

A certificate of destruction isn’t an add-on — it’s what proves the work was done. If a vendor doesn’t produce one automatically per work order, you have no documented record for HIPAA, FACTA, or audit purposes.

Vague or verbal chain-of-custody assurances

If your contact can’t show you a sample manifest, a sample closeout report, or walk you through how a serial number is tracked from intake through destruction, that’s a process gap — not just a documentation gap.

No answer on employee background checks

The people loading your equipment into a van and handling it at the facility have access to your data before anything is wiped. If a vendor can’t confirm they background-screen those employees, that’s a real exposure.

No disclosure of what happens to failed drives

A reliable wipe process also handles failures. If a drive can’t be software-wiped to NIST standards, it should be physically shredded — not returned, resold, or quietly set aside. Ask what the failure protocol is.

Regulatory Context

How certification fits into regulatory due diligence.

The FTC Disposal Rule and Safeguards Rule describe duties such as reasonable disposal measures and service-provider oversight; they do not name a required certification. NAID AAA can contribute third-party evidence about a destruction provider’s certified operation. ISO 27001 can contribute evidence about an information security management system. Neither credential replaces a review of the actual service scope, contract, custody controls, sanitization methods, or project records.

This is general information, not legal advice. If your compliance team is working from specific regulatory language or internal policy, we are glad to review the exact wording with you.

FTC Disposal Rule (FACTA)

Requires reasonable measures to dispose of consumer data. NAID AAA maps directly to the vendor due-diligence expectation.

GLBA Safeguards Rule

Financial institutions must select and oversee service providers that maintain appropriate safeguards.

HIPAA Security Rule

Covered entities and Business Associates must protect the confidentiality of PHI through disposal.

NIST SP 800-88

The federal standard for media sanitization and verification.

Due Diligence

10 questions to ask every ITAD vendor you evaluate.

These questions will reveal more about a vendor’s actual practices than any marketing page will — including the two that most procurement teams never think to ask.

Q: Can you show me your current NAID AAA certificate?

A certified vendor will produce this immediately. It should show i-SIGMA as the issuing body, a current date range, and the specific facility. Lapsed or missing means not certified.

Q: When was your last unannounced audit?

NAID AAA includes random, unannounced audits. A certified vendor will know this answer. “We haven’t had one” or a blank look is a flag — check the certificate’s currency.

Q: What happens to a drive that fails the wipe verification?

The correct answer: it’s flagged and physically shredded, never resold or returned. This is table stakes for NAID AAA compliance and basic data-security practice.

Q: How do I track a specific device from pickup to destruction?

A solid ITAD vendor should be able to walk you through its intake manifest, processing system, and closeout report — showing how a serial number moves through every step.

Q: What sanitization standard do you operate to?

NIST SP 800-88 is the answer. Ask whether they operate to Purge level or Clear level and how they select the method per device type.

Q: Do all employees who handle our equipment pass background checks?

This covers the people on the pickup truck and on the processing floor — not just the account manager. NAID AAA requires this; ask for the policy in writing.

Q: What’s in the Certificate of Destruction you provide?

It should list the work order, customer details, per-device serial numbers, destruction method used, date completed, and issuing party. A one-page summary without device detail is not sufficient for most compliance needs.

Q: Who are your downstream recyclers, and are they R2 certified?

Any equipment that can’t be sanitized and resold goes to a recycler. R2 certification helps ensure those partners meet environmental and data-security standards too.

Q: What insurance do you carry, and what’s the limit?

Ask for the current certificate, dollar limits, coverage types, policy period, and any endorsements your risk team requires. SecureErase states a $5 million limit; the current evidence should be reviewed for the proposed engagement.

Q: Do you self-certify your compliance — or is it independently audited?

Either an accredited third party audits the destruction process, or it doesn’t. NAID AAA means unannounced independent auditors verified the actual destruction. Self-reported compliance does not provide the same assurance. Ask for the auditor’s name and most recent audit date.

Work With a NAID AAA Certified ITAD Provider

SecureErase, LLC holds current NAID AAA certification.

Woman-owned, NWBOC certified, and audited unannounced by i-SIGMA — we can show you our certificate, our sample Certificate of Destruction, and walk you through exactly how your equipment is tracked from pickup to final disposition.

Phone
208-362-7703
Email
info@secureerase.com
Location
8540 W Elisa St, Boise, ID 83709
Certifications
NAID AAA · NWBOC Woman-Owned