Certification anatomy · ISO 9001 · ISO 14001 · ISO/IEC 27001 · ISO 45001 · RIOS

The ISO Management-System Standards Field Guide: 9001, 14001, 27001 & 45001 on an ITAD Vendor’s Wall

Alongside the destruction and recycling certifications, many ITAD and recycling vendors display ISO logos — sometimes one, sometimes four. They are frequently read as a single credential (“ISO certified”) when they are four different standards certifying four different management systems, none of which is a data-destruction standard. This guide explains what a management-system standard actually is, what ISO 9001, 14001, 27001, and 45001 each cover, how certification works (and why ISO itself certifies no one), how to verify a certificate and read its scope, where the recycling industry’s own RIOS standard fits, and which ISO/IEC 27001 controls genuinely speak to the disposition of storage media and equipment. It is written for buyers evaluating a vendor’s wall — and it should be read alongside the ITAD Certification Field Guide, which covers NAID AAA, R2v3, RIOS, and the state permit, the credentials that speak to destruction and downstream directly.

Reading time: ~15 min Published: September 1, 2026 Author: Brian Boynton Applies to: ISO 9001:2015; ISO 14001:2015; ISO/IEC 27001:2022; ISO 45001:2018

STRAIGHT ANSWER

What do ISO certifications mean on an ITAD vendor’s site?

Each certifies a different management system, not data destruction itself: ISO 9001 quality, ISO 14001 environmental, ISO/IEC 27001 information security, ISO 45001 occupational health and safety. Certification comes from an accredited certification body, not ISO, typically on a three-year cycle with surveillance audits, and covers only the scope on the certificate. Verify the scope, then pair it with the credentials that audit the destruction work itself.

TL;DR

A management-system standard certifies that an organization runs a documented, audited system for managing something — it does not certify the outcome of any particular job. ISO 9001:2015 is quality (consistent, controlled processes). ISO 14001:2015 is environmental (identifying and controlling environmental impacts). ISO/IEC 27001:2022 is information security (a risk-based ISMS, with 93 Annex A controls in four themes, several of which address storage media, equipment disposal, and information deletion). ISO 45001:2018 is occupational health and safety. All four share a common structure and a Plan-Do-Check-Act logic. ISO does not certify anyone; accredited certification bodies do, on a typical three-year cycle with surveillance audits, and a certificate is only as broad as the scope printed on it. RIOS is the recycling industry’s integrated quality-environmental-health-and-safety alternative. For a buyer, the ISO logos answer “is this operation systematically managed?” — and leave “is the destruction secure and the downstream responsible?” to NAID AAA and R2v3.

Section 01

What a management-system standard is — and isn’t

The four ISO standards on a vendor’s wall share a common design, and understanding it explains both what they prove and what they cannot.

A management-system standard specifies requirements for the system an organization uses to manage an area of performance — quality, environment, information security, safety — rather than requirements for the performance itself. The organization defines its context and scope, sets policy and objectives, identifies risks and opportunities, plans and implements controls, monitors and measures, audits itself, reviews at management level, and corrects and improves. That Plan-Do-Check-Act cycle is common to all of them, and since the 2010s ISO has written its management-system standards to a harmonized high-level structure with shared clause numbering (context, leadership, planning, support, operation, performance evaluation, improvement), which is why an organization can run several of them as one integrated system.

What certification to such a standard proves is that an accredited auditor found the system in place and operating — documented procedures, competent people, records, internal audits, management review, corrective action. What it does not prove is any specific outcome on any specific job: an ISO 9001 certificate does not mean a particular pallet was processed correctly, and an ISO/IEC 27001 certificate does not mean a particular drive was sanitized. It means the organization has a system that is supposed to make those outcomes consistent, and that the system was audited.

That is genuinely valuable — consistency is what a buyer wants across a multi-year, multi-site relationship — and it is also why management-system certifications are complements to, not substitutes for, the standards that audit the work itself.

Bottom line

A management-system certificate says the organization has an audited system for managing an area. It does not certify the result of any individual job. Read it as a consistency credential, not a performance guarantee.

Section 02

The four standards, one at a time

Same architecture, four different subjects. The subject determines what the certificate is evidence of.

StandardCurrent editionManagesWhat it is evidence of at an ITAD vendorWhat it is silent on
ISO 90012015Quality management systemDocumented, controlled processes; customer-requirement capture; nonconformity handling; consistent output across jobs and sitesWhether the destruction technique is adequate; where materials go
ISO 140012015Environmental management systemIdentification and control of environmental aspects and impacts; legal-compliance obligations tracked; environmental objectives and monitoringDownstream vendor accountability at the R2v3 level; data security entirely
ISO/IEC 270012022Information security management system (ISMS)Risk-based information security governance across the organization, with Annex A controls including storage media, equipment disposal, and information deletion; the most directly relevant of the fourPer-device destruction verification; unannounced audits of the destruction floor; media-specific technique
ISO 450012018 (replaced OHSAS 18001)Occupational health and safety management systemHazard identification and control for workers — relevant on a floor with shredders, forklifts, and lithium batteriesAnything about data or materials

ISO 9001:2015 is the most widely held management-system certificate in the world and the most generic: it applies to any organization that produces a product or service. At an ITAD vendor it is evidence that intake, processing, reporting, and customer-requirement handling run through defined, monitored processes with corrective action when they fail — the machinery behind consistent certificates and reconciled inventories.

ISO 14001:2015 asks the organization to identify its environmental aspects, determine its compliance obligations, set objectives, and control and monitor its impacts. For a recycler that is a meaningful discipline — emissions, waste streams, hazardous materials handling — but it is not a downstream-accountability standard: it does not require the vendor-by-vendor qualification of the recycling chain that R2v3’s Appendix A does.

ISO/IEC 27001:2022 (Edition 3, October 2022) is the one buyers of data destruction should read most carefully, and it gets its own section below. It certifies an ISMS — a risk-assessed, policy-driven information security program — whose Annex A control set was reorganized in 2022 into 93 controls across four themes (organizational, people, physical, technological).

ISO 45001:2018 replaced the older OHSAS 18001 as the international occupational health and safety management standard. On a destruction and recycling floor — industrial shredders, material handling, battery streams with thermal-runaway risk — it is evidence that worker safety is systematically managed, which matters to a buyer both ethically and because safety incidents interrupt custody.

Section 03

How certification actually works

“ISO certified” is a common phrase and a technically wrong one. Knowing why tells you how to verify a claim.

The International Organization for Standardization writes standards; it does not certify organizations. ISO’s own materials describe certification as one way an organization may choose to demonstrate conformity, performed by external bodies. Those bodies — certification bodies (sometimes called registrars) — audit the organization against the standard and issue the certificate. Certification bodies are themselves accredited by national accreditation bodies (in the United States, for example, the ANSI National Accreditation Board) that assess their competence and impartiality, typically against ISO/IEC 17021. A certificate issued by an accredited body under an accreditation mark is the credible form; an unaccredited certificate is a private opinion.

Certification typically runs on a three-year cycle: an initial two-stage audit (documentation review, then on-site assessment of implementation), followed by surveillance audits — commonly annual — and a full recertification audit before the three-year expiry. Nonconformities found at any stage must be corrected on a schedule or the certificate can be suspended or withdrawn.

Every certificate states a scope: which activities, at which sites, the management system covers. This is the field buyers most often skip and most need to read. An ISO/IEC 27001 certificate scoped to “the corporate IT department” says nothing about the destruction floor; an ISO 9001 certificate scoped to one facility says nothing about a second. The scope statement, the accreditation mark, the issuing body, the certificate number, and the expiry date are the five things to check — and certification bodies and accreditation bodies maintain registries where a certificate’s status can be confirmed.

Verification checklist

Issuing certification body named? Accreditation mark present, and the body listed by the accreditation body? Certificate number and expiry current? Scope statement covering the activities and sites you are buying? If any answer is no, the logo is a claim, not a credential.

Section 04

ISO/IEC 27001:2022 and the controls that touch disposition

Of the four standards, only 27001 speaks to information on storage media. Its 2022 control set does so in three places worth knowing by number.

ISO/IEC 27001 requires an organization to establish an ISMS: define scope, assess information security risks, select controls to treat them (documented in a Statement of Applicability against the Annex A reference set), implement, monitor, audit, and improve. The 2022 edition’s Annex A holds 93 controls organized into organizational, people, physical, and technological themes; the detailed implementation guidance sits in the companion ISO/IEC 27002:2022.

Three Annex A controls bear directly on retired hardware. Control 7.10, Storage media, requires that storage media be managed through their life cycle of acquisition, use, transportation, and disposal in accordance with the organization’s classification scheme and handling requirements. Control 7.14, Secure disposal or re-use of equipment, requires that items of equipment containing storage media be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use. Control 8.10, Information deletion, requires that information stored in information systems, devices, or any other storage media be deleted when no longer required.

Two observations for buyers. First, these controls are stated as objectives, like the regulations discussed elsewhere on this hub; the ISMS decides how, and a well-run one cites NIST SP 800-88 Rev. 2 and IEEE 2883 for the technique — a certificate does not by itself tell you which technique was chosen. Second, and more useful: a vendor holding a 27001 certificate whose scope covers its disposition operations has, by definition, had these controls assessed as part of its ISMS. That is the question to ask — not “are you 27001 certified?” but “does your 27001 scope include the destruction operation, and how are 7.10, 7.14, and 8.10 implemented?”

Bottom line

ISO/IEC 27001:2022 Annex A controls 7.10 (storage media), 7.14 (secure disposal or re-use of equipment), and 8.10 (information deletion) are the ones that speak to disposition. Ask whether the certificate’s scope covers the destruction operation and how those three are implemented.

Section 05

RIOS: the recycling industry’s integrated management-system certification

Many recyclers hold RIOS instead of — or alongside — ISO 9001, 14001, and 45001. This section is the RIOS reference for buyers: what it is, what it certifies, where R2v3 accepts it, and how to verify it.

The Recycling Industry Operating Standard (RIOS) is an integrated quality, environmental, health and safety (QEH&S) management-system standard written specifically for recycling operations across all commodities — scrap metal, paper, plastics, and electronics alike. It grew out of the scrap and recycling industry’s trade association (ISRI, now the Recycled Materials Association, ReMA) and is administered today by the Global Recycling Standards Organization (GRSO), with ReMA as a partner organization. Its design intent was to give a recycler one audited management system covering the ground that ISO 9001, ISO 14001, and ISO 45001 cover in three separate frameworks, and to build it around a recycling floor rather than a generic organization.

What it certifies. Like the ISO standards it parallels, RIOS is a Plan-Do-Check-Act management system with a risk-based approach: the facility identifies its quality, environmental, and health-and-safety risks and impacts; implements documented procedures and controls; measures whether they work; and corrects and improves on a defined cadence, with management review and internal audit built in. Certification adds an independent third-party audit of that system against the published standard on a recurring cycle. The practical output for a buyer is that procedures, training, incident response, and environmental controls exist as an audited system rather than as institutional memory — the same assurance an ISO 9001 + 14001 + 45001 stack provides, in one certificate.

Where R2v3 accepts it. RIOS matters to ITAD buyers chiefly because of its role underneath R2v3. R2v3 Core Requirement 3 requires an R2 facility’s environmental, health and safety management system to be independently certified, and SERI’s own published materials describe the two paths as ISO 14001 together with ISO 45001, or RIOS. For facilities that test and repair equipment under R2v3 Appendix C, a certified quality management system is also required — ISO 9001 or RIOS. A single RIOS certificate can therefore satisfy both of R2v3’s management-system prerequisites, which is why it is so common on electronics recyclers’ walls and why its absence on an R2v3 facility means the ISO certificates should be there instead. The R2v3 Certification Field Guide covers that dependency from the R2 side.

QuestionRIOSISO route
Quality management systemIncludedISO 9001
Environmental management systemIncludedISO 14001
Occupational health & safetyIncludedISO 45001
Information security managementNot coveredISO/IEC 27001
Data destruction securityNot covered (see NAID AAA)Not covered (see NAID AAA)
Downstream accountabilityNot covered (see R2v3)Not covered (see R2v3)
Accepted by R2v3 for Core 3 EH&S systemYesISO 14001 + ISO 45001
Accepted by R2v3 for Appendix C QMSYesISO 9001

What it does not certify. RIOS is a management-system certification. It does not certify that data on any device was destroyed, does not audit personnel screening or destruction methods (that is NAID AAA’s domain), and does not verify where materials go after they leave the facility (that is R2v3 Appendix A). A vendor presenting RIOS as a data-security credential is presenting it for something it was never designed to show.

How to verify it. RIOS certification is issued by third-party certification bodies, and GRSO maintains a public Find a RIOS Recycler directory of certified companies. Verify the vendor there, then ask for the certificate itself and confirm the certified location and the certificate’s expiry and issuing body — the same three checks that apply to any management-system certificate. If the vendor is also R2v3 certified, the RIOS certificate is the document that satisfies R2v3’s management-system prerequisites, and its currency matters to the R2 certificate as well.

Bottom line

RIOS = ISO 9001 + 14001 + 45001 in one recycling-specific certificate, accepted by R2v3 for both of its management-system prerequisites. Strong evidence the operation is systematically run; no evidence about data destruction or downstream. Verify in GRSO’s directory, then read the certificate.

For how RIOS sits alongside NAID AAA, R2v3, and a state permit as a stack, see the ITAD Certification Field Guide.

Section 06

Reading the whole wall: what each credential answers

Put the ISO logos back next to the destruction and recycling certifications and the wall becomes a set of answers to different questions.

QuestionCredential that answers it
Is the destruction operation itself secure — people, facility, methods, unannounced audits?NAID AAA (i-SIGMA)
Are devices, data, and materials handled responsibly through a vetted downstream chain?R2v3 (SERI) — Appendix A downstream, Appendix B data sanitization
Is the operation run through an audited quality / environmental / safety system?RIOS, or ISO 9001 + ISO 14001 + ISO 45001
Is information security governed organization-wide through a risk-based ISMS, including media and equipment disposal controls?ISO/IEC 27001 — if the scope covers the disposition operation
Is the facility legally authorized to process electronics?State permit — in Pennsylvania, the PA DEP general permit
Which sanitization technique was used on this device, and was it verified?No certificate answers this — the per-device Certificate of Sanitization (NIST SP 800-88 Rev. 2, Section 4.6) does

The last row is the one to remember. No logo on the wall — ISO or otherwise — tells you what happened to a specific drive. Management-system certificates tell you the organization is built to do it consistently; destruction and recycling certifications tell you the work is audited; the serialized certificate tells you it was done. A buyer who reads the wall as a stack, and then asks for the sample certificate, has read it correctly.

Section 07

Using this as a buyer

The ISO standards reward a specific kind of question — about scope, verification, and what the certificate is being asked to prove.

  • Never accept “ISO certified.” Ask which standards, which edition, issued by which accredited certification body, with what expiry.
  • Read the scope statement. The activities and sites listed are the only ones the certificate covers. Disposition operations at the facility you will use should appear in it.
  • Verify in the registry. Certification bodies and accreditation bodies publish certificate status; a certificate number that cannot be found is a finding.
  • Treat 9001/14001/45001 (or RIOS) as the consistency layer. Valuable evidence that the operation is systematically managed; not evidence about any particular job’s outcome.
  • Treat 27001 as the governance layer — and ask about 7.10, 7.14, and 8.10. If the scope covers disposition, those controls were assessed; ask how they are implemented and which technique standard the ISMS cites.
  • Pair with the work-auditing credentials. NAID AAA for destruction security, R2v3 for downstream. ISO management systems do not substitute for either.
  • Then ask for the sample certificate. Per device, method, technique, tool, verification, named people. That document, not any logo, is what tells you what happened to your drive.

CyberCrunch holds NAID AAA (continuously since 2012), R2v3, RIOS, and the PA DEP general permit — the destruction-security, downstream, integrated management-system, and legal-authorization layers described above — and documents every device to NIST SP 800-88 Rev. 2. Where a buyer’s own framework calls for ISO-family evidence, the credentials packet maps the held credentials to the requirements they satisfy. The vendor due-diligence guide and scorecard walk the verification steps for every credential on the wall.

Bottom line

Which standard, which body, which scope, verified where — then pair the management-system logos with the credentials that audit the work, and ask for the per-device certificate. That is how to read an ISO logo on an ITAD vendor’s site.

Section 08

Frequently asked questions

Is ISO 9001 or ISO 27001 a data destruction certification?

No. Both are management-system standards. ISO 9001 certifies a quality management system, evidence that processes are documented, controlled, and corrected when they fail. ISO/IEC 27001 certifies an information security management system, a risk-based program whose Annex A controls include storage media handling, secure disposal or re-use of equipment, and information deletion. Neither certifies the outcome of any specific destruction job or prescribes a sanitization technique. The credentials that audit destruction work directly are NAID AAA for destruction security and R2v3 for data sanitization and downstream accountability, and the per-device certificate under NIST SP 800-88 Rev. 2 is what records what was done.

Does ISO certify companies?

No. The International Organization for Standardization develops and publishes standards; it does not perform certification. Organizations are certified by independent certification bodies, which audit against the standard and issue certificates, and those bodies are accredited by national accreditation bodies that assess their competence and impartiality. A credible certificate names an accredited certification body, carries an accreditation mark, states a scope and an expiry, and can be confirmed in the body's registry. The phrase 'ISO certified' is shorthand, not an accurate description.

What is the difference between RIOS and the ISO standards?

RIOS, the Recycling Industry Operating Standard, is an integrated quality, environmental, health and safety management-system standard written specifically for recycling operations and administered through the Global Recycling Standards Organization. It covers in one framework the ground that ISO 9001 (quality), ISO 14001 (environmental), and ISO 45001 (occupational health and safety) cover in three. For a buyer they are largely interchangeable as evidence of an audited management-system layer; neither RIOS nor the ISO trio addresses information security governance, which is ISO/IEC 27001's domain, or destruction-floor security and downstream accountability, which are NAID AAA's and R2v3's.

Which ISO 27001 controls apply to retiring IT equipment?

In the 2022 edition's Annex A: control 7.10, Storage media, which requires managing media through acquisition, use, transportation, and disposal according to the organization's classification scheme; control 7.14, Secure disposal or re-use of equipment, which requires verifying that sensitive data and licensed software have been removed or securely overwritten before equipment is disposed of or re-used; and control 8.10, Information deletion, which requires deleting information when it is no longer required. The controls state objectives; a well-run ISMS cites NIST SP 800-88 Rev. 2 and IEEE 2883 for how they are met.

How do I verify a vendor's ISO certificate?

Ask for the certificate itself and check five things: the issuing certification body, whether that body is accredited (an accreditation mark and a listing with a national accreditation body such as ANAB in the United States), the certificate number, the expiry date within the typical three-year cycle, and the scope statement, which lists the activities and sites the management system covers. Confirm the certificate's status in the certification body's or accreditation body's public registry. A certificate whose scope does not include the disposition operations and facility you will use does not cover them.

THE WHOLE WALL, IN ONE FILE

Read our credentials the way this guide recommends

CyberCrunch holds NAID AAA (continuously since 2012), R2v3, RIOS, and the PA DEP general permit — and documents every device to NIST SP 800-88 Rev. 2. The credentials packet reproduces each certificate with its scope and maps them to the frameworks your auditors cite, so you can verify rather than trust a logo.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects, as of September 2026, publicly available information about ISO 9001:2015, ISO 14001:2015, ISO/IEC 27001:2022 and ISO/IEC 27002:2022, ISO 45001:2018, the ISO/IEC 17021 accreditation framework, and the RIOS program. ISO standards are copyrighted documents available from ISO and national member bodies; this guide describes their structure and purpose and paraphrases control objectives without reproducing normative text. Certification practices, cycle lengths, and registry procedures vary by certification body and accreditation body. It is not legal, compliance, or procurement advice and does not certify any organization’s conformance. CyberCrunch holds the credentials it names in the text — NAID AAA, R2v3, RIOS, and the PA DEP general permit — and makes no representation of holding ISO certifications not stated; credential statements reflect certificates at the time of publication.