CERTIFICATION · INDUSTRY UPDATE

NAID AAA Is Moving Past the Shred Floor. Cybersecurity Requirements Arrive October 1.

i-SIGMA — the association behind NAID AAA and PRISM Privacy+ certification — has notified certified service providers that enhanced cybersecurity requirements take effect October 1, 2026: documented cyber policies with per-employee attestations, access control that now explicitly covers servers and network equipment, and an annual third-party security review with named controls. Here's what's changing section by section, why the audit is following the data, and what it means whether you hold the certification or hire someone who does.

By Charles Nygard Published 8 min read

STRAIGHT ANSWER

Effective October 1, 2026, i-SIGMA is adding cybersecurity requirements to its NAID AAA and PRISM Privacy+ certification standards: a documented cybersecurity policy with per-employee attestations (new Section 1.29), access control extended to servers, storage devices, and network equipment (Section 2.1), an annual third-party security risk analysis covering MFA, endpoint detection, and patch management (Section 3.2), and new workstation and identity access management requirements for erasure and degaussing endorsement holders.

What i-SIGMA announced

In a July 2026 notice to certified service providers, i-SIGMA announced that it is enhancing the cybersecurity requirements within its NAID AAA and PRISM Privacy+ Certification standards, effective October 1, 2026. The changes apply to three groups: holders of i-SIGMA's NAID AAA Certification, holders of i-SIGMA's PRISM Privacy+ Certification, and holders of the NAID AAA Erasure & Degaussing endorsements. Providers have been asked to review the changes and plan to be fully compliant by the effective date.

The update lands in five places in the certification specifications: one entirely new requirement that applies across both certifications, one enhanced requirement that applies across both, one enhanced requirement whose reach extends to erasure and degaussing operations, and two new requirements at the endorsement level. None of them changes how paper gets shredded or how a drive gets destroyed. All of them change what a certified provider has to prove about the environment around that work.

That's a meaningful shift for a certification family that built its reputation on the physical side of information destruction — vetted personnel, secured facilities, verified particle sizes, unannounced audits. The new requirements take the same audit-and-verify posture and point it at the provider's own data environment: its policies, its people's security awareness, its network, and the systems that sit between intake and destruction.

The five changes, section by section

i-SIGMA certification specification changes — effective October 1, 2026
SectionChangeApplies to
1.29 Cybersecurity Policy / TrainingNew requirementNAID AAA · PRISM Privacy+
2.1 Access ControlEnhanced requirementNAID AAA · PRISM Privacy+
3.2 Third-Party Network Security VerificationEnhanced requirement — newly extended to erasure & degaussing operationsPRISM Privacy+ · Erasure & Degaussing
7.4 Workstation Access ControlNew requirementErasure & Degaussing endorsements
7.5 Identity Access ManagementNew requirementErasure & Degaussing endorsements

Section 1.29 — Cybersecurity Policy / Training (new)

The new requirement asks certified providers to maintain documented cybersecurity policies or procedures covering, at minimum, acceptable use of services and products, password management, and incident response. It then goes a step further than most policy requirements: every Access Individual — the certification's term for personnel with access to client information — must provide documented confirmation stating their understanding of and agreement with the organization's cybersecurity protocols.

The audit methodology makes the intent concrete. The auditor doesn't just inspect the policy binder; they pull an appropriate random sample of employee files and verify the attestations are actually in them. A policy nobody signed is a finding. This mirrors how the certification has always treated destruction training — the record of the individual's acknowledgment is the evidence, not the existence of the document.

Section 2.1 — Access Control (enhanced)

Access control has always been core to the certification: physical, logical, and administrative controls preventing unauthorized access to client information in the destruction environment, storage areas, and staging areas. The enhancement adds an explicit second sentence: providers must also implement measures to prevent unauthorized physical access to servers, storage devices, and network equipment.

In other words, the locked door now has to extend past the shred floor to the server closet. At audit, inspectors verify entrances to secured areas prevent unauthorized access when media is unattended, and that the provider's documented policies and training materials cover access control and the interdiction of unauthorized individuals.

Section 3.2 — Third-Party Network Security Verification (enhanced)

PRISM Privacy+ operations were already subject to third-party network security verification. The enhanced requirement names the controls the annual comprehensive Security Risk Analysis must evidence: enforcement of least-privilege principles, multi-factor authentication, antivirus software, a firewall, endpoint detection tools across all devices, and patch management. Per i-SIGMA's announcement, this requirement also newly reaches erasure and degaussing operations.

The verification isn't a self-assessment. The audit methodology requires documented evidence that the provider's networks achieved an acceptable security review by a competent third-party security expert. That's the same independence logic that makes NAID AAA itself valuable — the provider doesn't get to grade its own homework.

Sections 7.4 and 7.5 — Workstation Access Control and Identity Access Management (new, endorsement level)

For providers holding the NAID AAA Erasure & Degaussing endorsements, two new requirements land at the endorsement level. Workstation access control requires policies, procedures, and physical infrastructure that restrict access to servers and local workstations to trained and approved Access Individuals — auditors inspect the physical, logical, and administrative controls, not just the paperwork. Identity access management requires the provider's policies and procedures to describe its IAM and control methodology for all Access Individuals.

This is the part of the update most directly aimed at sanitization work. A drive-wiping workstation is a computer with privileged access to client media; the update treats it that way.

Why the audit is following the data

i-SIGMA's own framing of the change is telling: risk has moved well beyond the shred floor and into the data environment itself. A destruction provider's exposure is no longer limited to whether a bin is locked and a particle is small enough — it includes whether the provider's own network, workstations, and people could become the path to the client data it's trusted to destroy.

The second driver is expectation. Organizations buying destruction services increasingly ask for evidence of security controls, not just service claims — the same shift that pushed security questionnaires and SOC-style attestations into every other vendor category. A certification program that wants to keep doing the vetting work for its clients has to align its requirements with the exposure those clients actually care about.

No single control carries the program on its own. Administrative, physical, and technical safeguards work together — and under the updated standards, each layer is independently validated at audit rather than taken on the provider's word.

That layered logic is the through-line of all five changes. Section 1.29 is the administrative layer — policy plus a signed human acknowledgment. Sections 2.1 and 7.4 are the physical layer, extended to the systems that hold or touch data. Sections 3.2 and 7.5 are the technical layer, verified by an outside expert. It's a compact version of the same defense-in-depth structure that frameworks like NIST 800-171 spell out across 110 controls.

What this means if you buy destruction services

If your organization hires a NAID AAA or PRISM Privacy+ certified provider, nothing in this update creates an obligation for you. What it does is raise the floor under a credential you're probably already relying on — and it's worth understanding what the credential will attest to after October 1.

Before this update, a current NAID AAA certificate told you the provider's destruction process, personnel screening, facility security, and chain of custody had been independently audited, on both scheduled and unannounced visits. After it, the same certificate also tells you the provider maintains documented cybersecurity policies its employees have individually signed, controls physical access to its servers and network equipment, and — for the relevant certifications and endorsements — passes an annual network security review by an independent security expert covering MFA, endpoint detection, patching, and least privilege.

That's due-diligence work the certification is now doing for you. It's also a useful differentiator during the transition: between now and October 1, providers will be at different stages of readiness, and how a vendor answers questions about the new requirements tells you something about how seriously it takes the certification behind its marketing. For our part, CyberCrunch has held NAID AAA certification continuously since 2012, and we're closing our own gap analysis against the updated specifications well ahead of the effective date.

Six questions to ask your vendor before October

If you're refreshing vendor due diligence this quarter — or evaluating a new destruction or ITAD partner — the update gives you a ready-made line of questioning:

  • Is your NAID AAA (or PRISM Privacy+) certification current, and which locations and endorsements does it cover? Verify the answer against i-SIGMA's public directory rather than a logo on a website.
  • Are you tracking the October 1, 2026 specification changes, and where does your gap analysis stand? A certified provider that can't answer this hasn't read its own mail.
  • Do your employees sign cybersecurity protocol attestations? After the effective date, auditors will sample employee files for exactly this — an answer of "our policy covers everyone" is the old standard, not the new one.
  • How is physical access to your servers, storage, and network equipment restricted? The secure area can no longer stop at the destruction floor.
  • Has your network passed a third-party security review, and does it evidence MFA, endpoint detection across all devices, patch management, and least privilege? Where applicable, ask for the date of the most recent analysis.
  • For drive erasure or degaussing work: how are sanitization workstations access-controlled, and what does your identity access management look like for the people who operate them?

None of these questions requires you to audit anything yourself — that's the certification's job. They establish whether your vendor is ahead of its own compliance deadline or behind it.

If you're a certified provider: the preparation window

For providers, the announcement is a two-month runway with a clear structure. i-SIGMA's own guidance to members maps cleanly onto a workable plan:

  1. Scope it. Determine which of your certifications and endorsements are affected — the changes reach NAID AAA, PRISM Privacy+, and the Erasure & Degaussing endorsements differently.
  2. Gap-assess each requirement. Compare Sections 1.29, 2.1, 3.2, 7.4, and 7.5 against current practice. The most common gaps are likely to be the per-employee attestations (a policy usually exists; individual signed acknowledgments usually don't) and the named-control third-party security analysis.
  3. Involve the team early. The attestation requirement makes every Access Individual part of the compliance surface — this is a training conversation, not just a document update.
  4. Update client-facing materials. The strengthened standard is a selling point; collateral that still describes the old scope undersells the credential.
  5. Ask i-SIGMA. Ambiguities about applicability or audit evidence are cheaper to resolve with the certifying body before the effective date than during an audit after it.

i-SIGMA update FAQ

Who do the new i-SIGMA requirements apply to?

Holders of i-SIGMA's NAID AAA Certification, i-SIGMA's PRISM Privacy+ Certification, and the NAID AAA Erasure and Degaussing endorsements. The changes take effect October 1, 2026, and i-SIGMA has asked certified service providers to plan to be fully compliant by that date. If you're a client of a certified provider rather than a provider yourself, nothing is required of you directly — but your vendor's certification baseline rises.

I'm a client of a certified provider, not a provider. Do I have to do anything?

No — the requirements bind the certified provider, not its clients. But the update is worth acting on anyway: after October 1, 2026, a current NAID AAA or PRISM Privacy+ certificate attests to more than destruction process. It's a good moment to refresh your vendor due diligence, confirm your vendor's certification is current, and ask how the new cybersecurity requirements show up in their audit evidence.

What does the new cybersecurity policy requirement (Section 1.29) actually require?

Documented evidence of cybersecurity policies or procedures — including acceptable use, password management, and incident response — plus documented confirmation from each Access Individual stating their understanding of and agreement with the organization's cybersecurity protocols. At audit, the auditor inspects the documentation and examines a random sample of employee files to verify the attestations exist.

Does this change how the physical destruction itself is performed?

No. The particle sizes, destruction methods, chain-of-custody rules, and witnessed-destruction provisions of the certification are not what this update touches. The change adds administrative and technical safeguards around the data environment — policies, training attestations, network security verification, and access control that now explicitly covers servers, storage devices, and network equipment.

How does this compare to R2v3 or e-Stewards?

The certifications still occupy different lanes — R2v3 and e-Stewards are electronics-recycling and reuse standards, while NAID AAA and PRISM Privacy+ certify information destruction and protection operations. What this update changes is NAID AAA's posture: it now independently audits cybersecurity safeguards around the destruction environment, not just the destruction process itself. For the full comparison, see our R2v3 vs. e-Stewards vs. NAID AAA brief.

THE BAR JUST MOVED

Vet your destruction vendor against the new standard

Our vendor due-diligence questionnaire covers certifications, chain of custody, insurance, and downstream accountability — the evidence layer the updated i-SIGMA standards now formalize. Use it as the paper trail behind the six questions above.

This article describes the i-SIGMA certification program update as of July 29, 2026, based on i-SIGMA's July 2026 communication to certified service providers and the accompanying Certification Specifications Reference Manual. Requirements may be clarified or amended before or after the October 1, 2026 effective date; certified providers should confirm applicability and audit expectations directly with i-SIGMA. This is general information, not legal or compliance advice — consult your counsel and your certifying body for guidance on your specific obligations.