Certification anatomy · NAID AAA · i-SIGMA · How to read the certificate

The NAID AAA Certification Field Guide: How to Read, Verify, and Use a Vendor’s Certificate

“NAID AAA Certified” appears on thousands of vendor websites, and most buyers treat it as a binary: the logo is there or it isn’t. The certificate behind the logo is not binary. It is issued to a specific operation, for specific media types, by specific methods, at a facility or on a truck or both — and it is audited on a schedule and without one. This guide is written for the person who has been handed a certificate and has to decide what it proves. It explains what i-SIGMA actually verifies, how the endorsement list defines the scope, how to check a claim in the public directory, why membership and certification are different things, and what to ask before the first truck arrives. For how NAID AAA sits alongside R2v3, RIOS, and a state permit, start with the ITAD Certification Field Guide; for the security-side requirements arriving October 1, 2026, see the companion brief.

Reading time: ~16 min Published: September 1, 2026 Author: Brian Boynton Applies to: i-SIGMA Certification Specifications Reference Manual (current edition)

STRAIGHT ANSWER

What does NAID AAA certification actually prove?

NAID AAA Certification proves that an information-destruction operation was audited by i-SIGMA against a published specification: screened personnel, secured facilities and vehicles, documented custody, and destruction methods verified per media type. Its scope is defined by the endorsements on the certificate, not the logo. Verify a claim in i-SIGMA’s directory and match the endorsements to the media you are retiring.

TL;DR

NAID AAA is i-SIGMA’s security certification for information-destruction operations, audited against the Certification Specifications Reference Manual on a schedule and by random unannounced audit. The certificate’s scope is its endorsements — paper, micro media, hard drives (physical destruction, overwriting, degaussing), solid-state devices (physical destruction, overwriting), optical and tape media, product destruction — each designated facility-based, mobile, or both. Membership in i-SIGMA is not certification. Verify a claim in the i-SIGMA directory, read the endorsements against the media you actually retire, and ask for the serial-number log the specification requires the vendor to return.

Section 01

What NAID AAA certifies — and what it does not

The certification is narrower and more specific than its reputation, and the specificity is what makes it useful.

NAID AAA Certification is administered by i-SIGMA, the International Secure Information Governance & Management Association — the trade association for the secure destruction and records-management industry, of which NAID (the National Association for Information Destruction) is the destruction division. The program audits information destruction operations against a published, numbered specification, the i-SIGMA Certification Specifications Reference Manual, and issues certification to operations that conform.

What it certifies is the security of the destruction operation: who is allowed near client media and how they were screened; how facilities and vehicles are secured and monitored; how custody is documented from pickup to destruction; how each media type is destroyed and to what specification; what the client receives as proof; and, from October 1, 2026, how the operation secures its own network and systems. Each requirement is published with the audit methodology an auditor will use to verify it — what will be inspected, sampled, or examined — so the standard functions as a checklist rather than a framework.

What it does not certify is equally important for a buyer. NAID AAA does not certify environmental handling or downstream materials management — that is R2v3’s territory. It does not certify a quality or environmental management system — that is RIOS or the ISO management-system standards. It does not, by itself, tell you that a company is legally permitted to process electronics at a given site — that is a matter of state permitting. And it does not certify every service a certified company sells: the specification requires the provider to tell the client, in writing, when a service is not covered by a certification that could apply to it.

Bottom line

NAID AAA answers one question: is the destruction operation itself secure, by people, facility, method, and documentation? It is a strong answer to that question and no answer at all to the others. Read it alongside R2v3 and a state permit, not instead of them.

Section 02

How the specification is built: sections, levels, and audit methodology

Understanding the manual’s architecture explains why two certificates with the same logo can mean different things.

The current Reference Manual is organized in numbered sections that apply to different kinds of operations. Section 1 holds the universal requirements every i-SIGMA-certified operation meets — NAID AAA and its records-management sibling, PRISM Privacy+. Section 2 applies to facility-based operations: the building, its access points, its cameras. Section 3 is PRISM Privacy+ only. Section 4 carries the NAID AAA media-destruction specifics, endorsement by endorsement. Sections 5 and 6 add requirements for the Australian government (PSPF) endorsements that U.S. buyers will rarely encounter.

Each numbered specification carries a Level designation (1 through 3) that signals audit depth, and each is followed by its audit methodology — the published description of what the auditor does to verify it. For the screening requirements, for example, the methodology states the sampling rule: where an operation has seven or fewer Access Individuals the auditor checks every file; above seven, a random sample of 25 percent with a floor of seven and a ceiling of fifteen. A provider knows in advance exactly how it will be tested, and a buyer can read the same page.

The consequence for reading a certificate: the universal and facility sections are the same for everyone, but Section 4 is modular. A provider is certified for the endorsements it applied for and passed — and only those. That is the subject of the next section.

Manual sectionApplies toWhat it governs
Section 1All i-SIGMA certificationsAccess Individual screening, training, ID badges, confidentiality, receipts, transfer of custody, unannounced-audit policy, compliance officer, cybersecurity policy (from Oct 2026)
Section 2Facility-based operationsBuilding access control, CCTV coverage and 90-day retention, operational security logs, staging and storage
Section 3PRISM Privacy+ onlyRecords-management and imaging services (not information destruction)
Section 4NAID AAA endorsementsPer-media destruction specifications, documentation, equipment, insurance
Sections 5–6Australian PSPF endorsementsGovernment-classified destruction in Australia
Section 03

Endorsements: the line on the certificate that defines its scope

A NAID AAA certificate is the sum of its endorsements. Everything a buyer needs to check starts here.

NAID AAA does not certify “data destruction” in the abstract. It certifies an operation for specific endorsements — per-media, per-method modules, each with its own specifications in Section 4 and its own audit methodology. The current manual lists endorsements for paper and printed media; micro media (microfiche and microfilm); hard drives — physical destruction; hard drives — overwriting; hard drives — degaussing; solid-state devices — physical destruction; solid-state devices — overwriting (that is, sanitization); optical and magnetic tape media; and product destruction, alongside the Australian PSPF endorsements.

Each endorsement is further designated facility-based, mobile (on-site, typically in a truck), or both. A provider may hold facility-based hard-drive physical destruction and no mobile endorsement at all — in which case “we can shred on-site” describes a service outside its certification. The manual is explicit about this scenario: if a service is not certified but a certification exists that could apply to it, the client must be notified in writing, and where a bid or RFQ requires or favors NAID AAA, the provider must disclose in writing when the requested service is not certified at the time of the bid.

For an ITAD buyer, three endorsements do most of the work: hard drive physical destruction, solid-state device physical destruction, and — if the program includes drive reuse or remarketing — the overwriting (sanitization) endorsements for hard drives and solid-state devices. A vendor destroying tape backups needs the optical and magnetic tape endorsement; one degaussing drives needs the degaussing endorsement, under which the manual requires degausser selection and operator training tied to the media the equipment can actually neutralize.

The one-sentence check

Put the endorsement list next to the media inventory for the project. Every media type you are retiring, and every method the statement of work names, should appear on the certificate — with the right facility-based or mobile designation for where the work will happen.

Bottom line

Same logo, different work. Two NAID AAA providers can be certified for entirely different media and methods. The endorsement line, not the logo, is the certificate.

Section 04

People: the Access Individual requirements

The specification’s central concept is the person with access to client media, and most of Section 1 is about that person.

The manual defines an Access Individual as anyone with access to client (“Data Controller”) media, and it attaches conditions to becoming one. Before access is granted, the individual must sign a confidentiality agreement and, for employees, be legally eligible to work. Initial screening requires verification of employment history (employer name and location, dates), a criminal records search that in the United States must pull directly from county and state repositories and include federal districts, and initial drug screening, which the manual requires to be outsourced to a third-party screening service. Where law permits, the manual’s restrictive-hiring rule bars employment in access roles for anyone with a felony conviction in the last seven years for crimes involving theft, fraud, burglary, or larceny.

Screening is not one-time. Ongoing criminal record searches are required for all Access Individuals every three years. Ongoing substance-abuse screening is satisfied either by random annual testing of 50 percent of Access Individuals or by management training in an i-SIGMA-approved substance-abuse recognition program. Drivers’ licenses and records are reviewed at least quarterly or monitored through a government notification service. Every Access Individual completes annual training — i-SIGMA’s own program or an approved equivalent — and wears an employer-issued photo badge on duty.

The manual also names exemptions a buyer should understand. Officers, owners, and others not engaged in day-to-day operations are exempt from employment verification, drug screening, and eligibility checks — though headquarters-level owners and stakeholders who are Access Individuals must still undergo criminal background searches. Independent contractors and subcontractors and their employees are exempt from these screening requirements, which is exactly why the transfer-of-custody rules discussed below exist: the specification handles subcontractors by disclosure and by requiring them to meet certification criteria, not by screening them under the provider’s program.

Bottom line

Ask a vendor how many Access Individuals it has and how the ongoing three-year criminal re-screen and annual training are tracked. A certified operation answers from its records; the auditor sampled the same files.

Section 05

Facility, custody, and the paper you should receive

The requirements a buyer can see from outside: the cameras, the receipt, the serial-number log, and what happens when a subcontractor touches the media.

Facility security (Section 2). A facility-based operation must have a closed-circuit camera system monitoring all access points into the secure areas where media is received, staged, processed, and destroyed, with enough clarity to identify people and their activities and enough lighting after hours to keep that clarity. Recordings must be retained for 90 consecutive days in an organized, retrievable manner; the operation must log a weekly inspection of the system including at least five minutes of playback; and i-SIGMA must be notified within 48 hours if a CCTV problem results in lost footage. The auditor’s method is published: inspect the recording to verify 90 days are captured and review four random two-minute samples, including one from the ninetieth day back.

Receipts and certificates (Sections 1.15, 4.3–4.7). When custody transfers from the client to the provider, the client must receive a receipt indicating the type and quantity of materials and an acknowledgement of services rendered; an electronic receipt is acceptable with a verifiable audit trail. For hard drives, the log of recorded serial numbers is returned to the client on completion unless the client has opted out; for solid-state devices, the same where possible. For the overwriting endorsement, the client receives a receipt or certificate of destruction reflecting unique identifiers — and the documentation must identify any drives that failed the wiping process, by identifier, regardless of any opt-out. For degaussing, a confirmation receipt or certificate reflecting serial numbers.

Transfer of custody (Section 1.20). If custody of media includes a subcontractor, the client must be notified in writing of the subcontractor’s name and the service it provides; the subcontractor’s employees must acknowledge in writing that the media is confidential; and every company accepting custody of media must meet the certification criteria — or the client must be told in writing that the service is not certified. In practice, this means an unexplained second truck or an unnamed “processing partner” is a specification issue, not just a preference.

Insurance and compliance officer. The manual sets a minimum general-liability limit for NAID AAA operations (Section 4.24, currently stated as a $2,000,000 aggregate or umbrella policy, verified by the auditor against a certificate of insurance or broker letter dated within a month of the audit) and requires a designated i-SIGMA Certification Compliance Officer with authority to mandate compliance, reported to i-SIGMA within 30 days of any change.

What to ask for, in the specification’s own words

The materials receipt at pickup. The serial-number log at completion. Written disclosure of any subcontractor in the custody chain. The failed-device list on any sanitization job. A certified provider produces each of these because the manual requires them — not as a favor.

Section 06

How the audits work: scheduled, unannounced, and evidence-first

The audit model is the reason the certificate carries weight, and it is the part most vendor marketing describes least accurately.

NAID AAA operations are audited on a schedule against the full specification, and they accept, as a condition of the program, random unannounced audits. The specification requires the operation to be structurally ready for a surprise visit: a written unannounced audit policy naming at least one person or position with physical access to the information an auditor may ask to review, so that the visit cannot be defeated by the absence of the one person with the keys. If the designated contact is unavailable, the manual contemplates i-SIGMA’s Member Resolution Council requesting the information afterward — the visit is not simply forfeited.

Audits are evidence-first. Because every specification publishes its methodology, the auditor does not accept the policy manual’s description of a control in place of observing it: entrances are inspected, employee files are sampled against the stated formula, CCTV recordings are pulled at the stated intervals, insurance documents are examined for currency and limit. The published methodology cuts both ways — the provider cannot be surprised by how it is tested, and it cannot argue afterward that the test was unfair.

A buyer should read two things into this. First, tenure matters: an operation certified for many years has passed a long series of scheduled and unannounced audits, not one. Second, the certificate is a snapshot with teeth: i-SIGMA’s Certification Committee oversees the program, and an operation found out of conformance can be required to correct or lose its status — which is why the directory, not a PDF from last year, is the place to verify.

Bottom line

Scheduled audits confirm the operation meets the specification. Unannounced audits confirm it meets the specification on a random Tuesday. Only the second is a statement about how the operation actually runs.

Section 07

How to verify a claim: membership is not certification

The most common misunderstanding about NAID AAA is a one-word confusion, and it is easy to resolve in five minutes.

i-SIGMA membership is not NAID AAA Certification. i-SIGMA is a trade association; a company can join it, display a member logo, and attend its events without ever being audited. NAID AAA Certification is a separate program with a separate mark, an application, an audit, and an ongoing obligation. Vendor websites sometimes blur the two — “NAID member,” “NAID affiliated,” or simply a NAID logo without the word “Certified” — and a buyer should treat any wording short of “NAID AAA Certified” as an unverified claim.

The verification path is public. i-SIGMA maintains an online directory of members that can be filtered to NAID AAA Certified operations. Look up the company by name; confirm that the location that will handle your media is the one listed as certified (certification attaches to operations and locations, and a multi-site company may not hold it everywhere); and then ask for the certificate itself, which names the endorsements. Compare the endorsement list to your media inventory and to the statement of work. If the vendor will subcontract any part of the custody chain, ask for the written subcontractor disclosure the specification requires and verify the subcontractor the same way.

  • Step 1 — Directory. Find the company in i-SIGMA’s directory filtered to NAID AAA Certified. No listing, no certification — regardless of the logo.
  • Step 2 — Location. Confirm the certified location is the one that will receive or visit your assets. A certificate at headquarters does not cover an uncertified regional site.
  • Step 3 — Endorsements. Request the certificate and read the endorsement list against your media types and methods, including the facility-based vs. mobile designation for the work you are buying.
  • Step 4 — Currency. Certification is ongoing and can lapse; confirm current status in the directory rather than relying on a dated PDF.
  • Step 5 — Subcontractors. Ask, in writing, whether any other party will take custody of the media, and verify that party’s certification independently.

For the other half of a vendor file — verifying an R2v3 certificate in SERI’s directory and reading its appendix list — see the R2v3 Certification Field Guide. The Vendor Due Diligence Guide turns both into a scorecard.

Bottom line

Directory, location, endorsements, currency, subcontractors. Five checks, all from public or on-request documents. A vendor that cannot produce them has told you something.

Section 08

What changes on October 1, 2026

The specification is extending from the shred floor to the network, and the additions arrive with the same audit methodology as everything else.

Effective October 1, 2026, i-SIGMA is adding cybersecurity requirements to the NAID AAA and PRISM Privacy+ specifications. In outline: a documented cybersecurity policy covering acceptable use, password management, and incident response, with a signed attestation from every Access Individual, verified at audit by sampling employee files; access control extended explicitly to servers, storage devices, and network equipment, not only the destruction and staging areas; a named set of controls that the annual third-party security risk analysis must evidence — least privilege, multi-factor authentication, antivirus, firewall, endpoint detection, patch management — now reaching erasure and degaussing operations; and endorsement-level requirements for workstation access control and identity and access management for holders of the erasure and degaussing endorsements.

For a buyer, the practical effect is that a NAID AAA certificate for sanitization (overwriting) work will, after this date, also speak to the security of the systems the sanitization software runs on and the logs it produces — a gap that previously had to be closed with your own questionnaire. The section-by-section breakdown and the buying-side implications are in the companion brief.

Freshness note

This guide describes the current Reference Manual and i-SIGMA’s announced October 2026 changes as published at the time of writing. i-SIGMA revises the manual periodically; verify the current edition and section numbering at isigmaonline.org before citing a clause in a contract or policy.

Section 09

Using NAID AAA as a buyer: the questions that matter

You do not need to read the manual to use it. You need to know what a certified vendor should be able to show you without hesitation.

  • “Which endorsements do you hold, and are they facility-based, mobile, or both?” The answer should match your media inventory and where the work will happen. It should come as a certificate, not a sentence.
  • “Is the location that will handle our assets the certified one?” Certification attaches to operations and locations. Confirm in the directory.
  • “Will anyone else take custody of the media?” If yes, the specification requires written disclosure of who and for what, and that party must meet certification criteria or you must be told it does not.
  • “What will we receive at pickup and at completion?” A materials receipt at custody transfer; a serial-number log (or certificate reflecting identifiers) at completion; a failed-device list on any sanitization work.
  • “How is your screening kept current?” Three-year criminal re-screens, annual training, ongoing substance-abuse program, quarterly driver review. A certified operation answers from records.
  • “What technical standard governs your sanitization and destruction methods?” NAID AAA verifies that the operation performs the endorsed method securely and documents it; the technical benchmark for what counts as sanitized comes from NIST SP 800-88 Rev. 2 and IEEE 2883, and for classified-grade destruction from NSA/CSS. A complete answer names both layers.

CyberCrunch has held NAID AAA Certification continuously since 2012 — with endorsements for mobile and facility-based physical destruction of hard drives and solid-state devices, plus hard drive and solid-state overwriting — and produces the certificate, endorsement list, and directory listing on request — the same documents this guide tells you to ask any vendor for. The Vendor Due Diligence Scorecard scores those answers; the NIST SP 800-88 Rev. 2 guide covers the technical layer the certification sits on top of.

Bottom line

Endorsements, location, custody, paper, screening currency, technical standard. Six questions. A NAID AAA Certified operation has already answered every one of them to an auditor.

Section 10

Frequently asked questions

What is NAID AAA Certification?

NAID AAA Certification is a security certification for information-destruction operations administered by i-SIGMA, the International Secure Information Governance & Management Association. An operation is audited against i-SIGMA's published Certification Specifications Reference Manual, which covers personnel screening, facility and vehicle security, custody documentation, per-media destruction methods, client receipts and serial-number logs, insurance, and, from October 1, 2026, cybersecurity controls. Certification is verified by scheduled audits and random unannounced audits, and its scope is defined by the endorsements the operation holds.

Is being a NAID or i-SIGMA member the same as being NAID AAA Certified?

No. i-SIGMA is a trade association, and membership is open to companies that have never been audited. NAID AAA Certification is a separate program with its own application, audit, and ongoing conformance obligations, and only certified operations may use the NAID AAA Certified mark. A vendor describing itself as a NAID member or NAID affiliated has not claimed certification. Verify certification, not membership, in i-SIGMA's directory filtered to NAID AAA Certified operations.

How do I verify a vendor's NAID AAA certification?

Search i-SIGMA's online directory, filtered to NAID AAA Certified, for the company and confirm that the specific location that will handle your media is the one listed. Then ask for the certificate itself and read the endorsement list, which names the media types and methods the operation is certified for and whether each is facility-based, mobile, or both. Check that every media type and method in your statement of work appears, and confirm current status in the directory rather than relying on a dated PDF.

What are NAID AAA endorsements?

Endorsements are the per-media, per-method modules that define a NAID AAA certificate's scope. The current manual lists paper and printed media, micro media, hard drive physical destruction, hard drive overwriting, hard drive degaussing, solid-state device physical destruction, solid-state device overwriting, optical and magnetic tape media, and product destruction, plus Australian government endorsements. Each is designated facility-based, mobile, or both. A provider is certified only for the endorsements it holds, so two NAID AAA providers can be certified for different work.

Does NAID AAA require unannounced audits?

Yes. Random unannounced audits are a stated part of the certification program, and the specification requires every certified operation to maintain a written unannounced-audit policy naming at least one person or position with physical access to the records an auditor may ask to review. Scheduled audits verify the full specification on a cycle; unannounced audits verify that the operation runs the same way when no visit is expected.

What documentation should a NAID AAA certified vendor give me?

At custody transfer, a receipt indicating the type and quantity of materials and acknowledging the services. On completion of hard drive work, the log of recorded serial numbers unless you opted out; for solid-state devices, the same where possible. For overwriting (sanitization) work, a receipt or certificate of destruction reflecting unique identifiers, plus documentation identifying any drives that failed the wiping process. For degaussing, a confirmation reflecting serial numbers. If any subcontractor takes custody, written disclosure of the subcontractor's name and service.

AUDITED, NOT ASSERTED

Certified since 2012 — and happy to show the paper

CyberCrunch has held NAID AAA Certification continuously since 2012, alongside R2v3, RIOS, and a PA DEP permit. Ask for the certificate, the endorsement list, and the directory listing — the same three things this guide tells you to ask any vendor for — and we will send them with the credentials packet.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects the i-SIGMA Certification Specifications Reference Manual (current published edition) and i-SIGMA’s public program materials as of September 2026, described at the level of structure and requirements rather than reproduced. NAID AAA, i-SIGMA, and PRISM Privacy+ are marks of their owner. This guide is not legal or compliance advice, does not certify any vendor’s conformance, and should not substitute for verifying a certificate directly with i-SIGMA. Specifications change; confirm the current edition and section numbering before relying on a specific clause. CyberCrunch credential statements reflect certificates held at the time of publication.