Certification anatomy · R2v3 · SERI · How to read the certificate

The R2v3 Certification Field Guide: Reading the Scope, the Appendices, and the Directory

An R2v3 certificate is one of the most information-dense documents in IT asset disposition, and one of the least read. It names a facility, not a company. It carries a scope statement that says exactly which activities were audited and, by omission, which were not. It lists appendix letters that determine whether the facility was ever examined for data sanitization at all. And it has a status — active, suspended, expired — that a PDF cannot show you but SERI’s public directory can. This guide is for the buyer who has been handed one and needs to know what it proves. For how R2v3 sits alongside NAID AAA, RIOS, and a state permit, start with the ITAD Certification Field Guide; for the destruction-security certification that pairs with it, see the NAID AAA Certification Field Guide.

Reading time: ~17 min Published: September 1, 2026 Author: Brian Boynton Applies to: R2v3 Standard; R2 Code of Practices; SERI directory

STRAIGHT ANSWER

What does an R2v3 certificate actually tell you?

An R2v3 certificate tells you that a specific facility, at a specific address, was audited by a SERI-authorized certification body against the ten Core Requirements plus the Process Requirement appendices listed on it. Only a facility whose certificate lists Appendix B was audited for data sanitization. Read the scope statement and appendix letters, then confirm the certificate is active in SERI’s directory.

TL;DR

R2v3 is the current version of SERI’s Responsible Recycling standard, and its certificate is per facility, not per company. It has three parts a buyer must read: the scope statement (which activities at that address were audited), the appendix letters (A downstream chain, B data sanitization, C test & repair, D specialty reuse, E materials recovery, F brokering, G solar modules), and the status in SERI’s public directory (active, suspended, revoked, expired). Appendix B is the letter that matters for ITAD: it requires a documented Data Sanitization Plan, security controls, records, and independent verification by sampling of logically sanitized media. R2v3 also requires a separately certified EH&S management system underneath it — ISO 14001 and 45001, or RIOS.

Section 01

What R2v3 is — and what the certificate belongs to

R2 is a facility standard. Almost every misreading of an R2 certificate starts by forgetting that.

R2 — Responsible Recycling — is a voluntary standard for the reuse and recycling of used electronics, owned and administered by SERI (Sustainable Electronics Recycling International), a nonprofit. R2v3 is the current version. The standard governs how a facility handles used electronics from receipt to final disposition: the sorting and categorization of equipment, the tracking of material through the facility, the control of data-bearing devices, the management of hazardous “focus materials” such as batteries and mercury devices, and — centrally — the qualification of the downstream vendors that receive what the facility ships out.

The first fact to hold onto is that R2 certification attaches to a facility, not a company. SERI’s license process is explicit: one license application per facility address, a new application when a facility moves or a new campus location is added, and use of the “R2v3 Certified” mark only where a valid certificate has been issued for that facility. A company with six sites may hold certificates at three. A vendor’s website saying “R2v3 Certified” is therefore a claim about at least one location, and the buyer’s first question is whether the location that will receive their assets is one of them.

The second fact is that R2v3 sits on top of other certifications rather than replacing them. Core Requirement 3 requires the facility’s environmental, health and safety management system to be independently certified — SERI’s own materials describe the two paths as ISO 14001 plus ISO 45001, or the recycling industry’s integrated RIOS standard. Facilities that test and repair equipment for reuse under Appendix C must additionally hold a certified quality management system, ISO 9001 or RIOS. An R2v3 certificate therefore implies a small stack of other certificates beneath it, each of which can also be verified.

Bottom line

R2v3 certifies a facility’s handling of used electronics, from intake to a vetted downstream. The certificate is issued to an address. Everything a buyer checks starts with confirming that the address on the certificate is the one their assets will go to.

Section 02

The ten Core Requirements every R2 facility meets

The core is universal. It is also where the data-security floor for every R2 facility lives, whether or not the certificate carries Appendix B.

Every R2v3 facility, whatever its business, is audited against ten Core Requirements: Scope (all R2-related processes the facility directly manages must be inside the audited scope); the Hierarchy of Responsible Management Strategies (reuse preferred over materials recovery, recovery over disposal); the certified EH&S Management System; Legal and Other Requirements (a documented compliance plan, including import and export law); Tracking Throughput (records that follow equipment and material through the facility); Sorting, Categorization and Processing (every item classified and routed by documented criteria, using SERI’s R2 Equipment Categorization document); Data Security; Focus Materials; Facility Requirements (physical security, storage, closure planning, insurance); and Transport.

Two of these deserve a buyer’s attention beyond the list. Core Requirement 1, Scope, is the rule that prevents a facility from carving out an activity to keep it away from the auditor: the scope must include all certifiable activities at the facility and only processes the facility itself directly manages — not downstream vendors (they are verified separately under Appendix A), not planned operations that cannot be demonstrated at audit, and not discontinued processes. The certification body, not the facility, determines the final scope wording based on what it could verify.

Core Requirement 7, Data Security, is the data floor every R2 facility must meet regardless of appendices: data-bearing devices must be identified, secured, and controlled through the process, and data must be destroyed or sanitized before equipment moves to reuse or materials recovery. What Core 7 does not do is certify a facility to perform logical sanitization — wiping drives for reuse — as a service. That is Appendix B. A facility with Core 7 alone handles data by physical destruction or by sending data-bearing devices to a downstream vendor qualified for sanitization; a buyer whose program involves wiped-and-remarketed assets needs the letter B.

Core RequirementWhat the auditor confirmsWhy a buyer cares
1 · ScopeAll R2-related activities at the address are inside the certificateNothing you are buying was quietly left out of the audit
3 · EH&S Management SystemCertified to ISO 14001 + 45001 or RIOSA second, independently audited system exists underneath
5 · Tracking ThroughputRecords follow equipment and material through the facilityYour serial numbers can be reconciled at each step
7 · Data SecurityData-bearing devices controlled; data destroyed or sanitized before reuse/recoveryThe floor every R2 facility meets; logical sanitization as a service needs Appendix B
8 · Focus MaterialsBatteries, mercury devices, CRT glass and similar routed through a vetted chainYour fleet’s hazardous components are handled lawfully
Section 03

The appendices: reading the letters on the certificate

The Core is the same for everyone. The Process Requirement appendices are where two R2v3 certificates diverge — and where an ITAD buyer’s attention belongs.

R2v3 attaches Process Requirements as lettered appendices, each covering an activity a facility may or may not perform. A facility is audited only for the appendices in its scope, and each appendix specifies the terms that must appear on the certificate when it applies. The letters: A — Downstream Recycling Chain: the qualification and ongoing verification of the vendors that receive the facility’s controlled streams, all the way to final disposition. B — Data Sanitization: logical and physical sanitization of data-bearing devices with enhanced security controls and traceability — the letter ITAD buyers look for. C — Test and Repair: testing, repair, and refurbishment of equipment for reuse, with a certified quality management system and product-safety verification. D — Specialty Electronics Reuse: commercial-grade specialty equipment (telecom, medical, scientific) handled in coordination with suppliers and customers. E — Materials Recovery: dismantling and mechanical processing into commodities. F — Brokering: arranging the movement of equipment without physically handling it, with responsibility for where it lands. G — Photovoltaic Modules: reuse and recycling of decommissioned solar panels, added to the standard in 2024.

The reading rule is simple: the appendix list is the service list. A certificate scoped to A, B, and C describes a facility audited for downstream vendor management, data sanitization, and refurbishment for reuse — the classic ITAD profile, and the scope CyberCrunch holds. A certificate scoped to A and E describes a materials-recovery operation whose certificate says nothing about data sanitization. A certificate carrying F describes a company that may never touch your equipment but is accountable for where it sends it. None of these is better in the abstract; each is a different set of audited promises, and the buyer’s job is to match the letters to the work.

The most common mismatch

An R2v3 logo on a vendor’s proposal for a laptop-refresh with drive sanitization and remarketing — and a certificate, when finally produced, scoped to Appendix E. The facility was audited as a recycler. It was never audited for sanitizing or refurbishing anything.

Bottom line

Letters, not logos. A, B, and C are the ITAD letters. B is the one that says the facility was audited for data sanitization. Ask for the certificate and read the line.

Section 04

Appendix B: what “audited for data sanitization” means

Appendix B is R2v3’s own set of data-sanitization requirements. Knowing what it does and does not require is what lets a buyer ask the right next question.

Appendix B requires a facility to operate under a documented Data Sanitization Plan. SERI’s guidance describes the plan as covering five areas across thirteen elements: identifying the types of data storage devices and data the facility manages; defining the security and sanitization requirements that apply, including legal, supplier, and customer obligations; establishing the sanitization processes and procedures; establishing the security controls around them; and developing the training and validation processes that keep the controls effective. The plan is a living document, updated at least annually.

The requirement most worth understanding is verification. Appendix B requires documented quality controls to confirm that every device was processed as planned, and specifically requires that a minimum of five percent of logically sanitized data storage media be routinely sampled and verified — by a competent and independent party, meaning someone other than the person who performed the sanitization, using data-recovery software to demonstrate that data is not recoverable by commercial means. A sanitization tool’s own success message does not count as verification. After a sustained record of success the sampling rate may be reduced, to as low as one percent; if residual data is ever found, the effectiveness of the entire process is in question, previously processed devices must be reassessed, a root-cause nonconformity process must run, and the higher sampling rate returns until corrective action is verified. Records of sanitization activity are required under Core Requirement 7 so that a device’s processing can be shown after the fact.

What Appendix B does not do is name the technical standard for what counts as sanitized. SERI’s guidance notes that R2v3 does not rely on external data-security standards for its requirements; the facility’s plan must define the methods appropriate to each media type and the requirements it is meeting. That is not a weakness — it keeps the standard from going stale when NIST or IEEE revise — but it means a buyer must ask the follow-up: which technical standard does the plan name? The defensible answer in 2026 is NIST SP 800-88 Rev. 2 for the program and IEEE 2883 for the techniques; a plan that names them, and a NAID AAA certificate covering the operation’s security, together answer the question Appendix B alone leaves open.

Bottom line

Appendix B = a documented plan, security controls, records, and independent sampling verification of at least five percent of wiped media. It certifies that sanitization is managed and checked. Ask separately which technical standard the plan names.

Section 05

Appendix A: the downstream chain, and why “we know where it goes” is a documented claim

The original reason R2 exists is the question of where retired electronics actually end up. Appendix A is how the standard makes the answer auditable.

Almost no facility processes electronics to their final form. Circuit boards go to a refiner, batteries to a battery processor, plastics to a compounder, whole units to a reuse channel, and each of those parties may ship onward again. Appendix A requires a facility that manages such a chain to qualify each downstream vendor before shipping — verifying its legal standing, its own R2 or equivalent status where applicable, its handling of focus materials, and its final disposition — and to monitor the chain on an ongoing basis, tracking controlled streams to the point where they cease to be a concern. The downstream vendors themselves are not inside the facility’s certificate scope (Core Requirement 1 excludes them); they are inside its due-diligence obligation.

For a buyer, Appendix A is the answer to two questions that used to be unanswerable: where did the material from our fleet go, and can the vendor prove it. A facility scoped to Appendix A can produce its downstream vendor list, its qualification records, and its throughput tracking. It is also the reason a buyer should be cautious about a vendor that describes its downstream as proprietary or declines to discuss it — under Appendix A, the chain is documented by requirement.

Export note

Core Requirement 4 obliges an R2 facility to comply with import and export law, and Appendix A carries that through the downstream. Appendix A is the mechanism; the laws are in the Multi-State ITAD Compliance Field Guide and the answers-hub entry on exporting electronics.

Section 06

How certification actually works: license, two-stage audit, annual surveillance

Knowing the process explains what a certificate’s date means and why the directory, not the PDF, is the source of truth.

The roles are split. SERI owns the standard, licenses facilities to pursue certification, and authorizes the certification bodies; it does not audit. Certification bodies — independent, SERI-authorized auditing organizations operating under SERI’s R2 Code of Practices and accredited by a recognized accreditation body (in the United States, ANAB) — conduct the audits and issue the certificates. SERI then collects the certificates from every authorized certification body into a single public directory.

Before an audit can begin, the facility completes a SERI license application for that address. SERI’s eligibility rules bar applicants that in the preceding 24 months engaged in deceptive marketing, illegal acts, or fraud related to the activities in scope, or in conduct that would impair the R2 mark. The initial certification audit is two-stage: Stage 1 reviews the documented processes and procedures; Stage 2, typically 30 to 60 days later, assesses the facility and its records on site. Nonconformances must be corrected before a certificate is issued. Thereafter the facility passes annual surveillance audits and renews its license each year; certification is a standing state, not an event.

The buying-side implication is that a certificate PDF is a snapshot. It shows that a facility was certified on a date, for a scope. It does not show that the facility passed its most recent surveillance, that the certificate has not been suspended, or that the scope has not been narrowed. SERI’s directory does — which is why the verification path in the next section runs through the directory first and the PDF second.

Bottom line

SERI licenses and lists; authorized certification bodies audit and issue; the facility passes an annual surveillance audit to keep the certificate. The directory reflects the current state. The PDF reflects a date.

Section 07

How to verify an R2v3 certificate in SERI’s directory

Five minutes on SERI’s website answers most of the questions this guide has raised.

SERI publishes a searchable directory of R2 Certified Facilities, built from the certificates it collects from all authorized certification bodies. It can be searched by facility name, by location and radius, and through an advanced search that filters by certificate status (active, suspended, revoked, expired), by process requirements (the appendices), by business workflow type, by R2 version, and by whether the facility accepts drop-offs. SERI invites reports of omissions or errors and publishes a guide to interpreting search results.

  • Step 1 — Find the facility, not the company. Search by the name and confirm the listed address is the location that will receive your assets. A different address is a different certificate, or no certificate.
  • Step 2 — Read the status. Only active is certified. Suspended, revoked, and expired are the states a vendor’s website will not mention.
  • Step 3 — Read the process requirements. The directory shows which appendices are in scope. For sanitization services you need B; for refurbishment and remarketing, C; for any facility that ships material onward, A.
  • Step 4 — Request the certificate and scope statement. Compare the scope wording and appendix list to the statement of work. The certification body wrote the scope based on what it could verify — if a service you are buying is not in it, it was not audited.
  • Step 5 — Verify the layer underneath. Ask for the EH&S management-system certificate (ISO 14001 and 45001, or RIOS) and, for Appendix C facilities, the QMS certificate (ISO 9001 or RIOS). These are separately verifiable with their certification bodies.
  • Step 6 — Check the destruction-security half. R2v3 Appendix B governs the management of sanitization; the security of a destruction operation — screened people, cameras, custody, unannounced audits — is what NAID AAA certifies. For data-bearing assets, look for both.

The Vendor Due Diligence Guide walks these steps with the other credentials, and the Vendor Due Diligence Scorecard scores the result.

Bottom line

Facility, status, appendices, scope statement, the certified system underneath, and the destruction-security certificate beside it. Six checks; the first three take five minutes in SERI’s directory.

Section 08

Using R2v3 as a buyer: the questions that matter

You do not need to read the standard. You need to know what a facility that has been audited to it should be able to show you.

  • “Which facility will process our assets, and is that the address on the certificate?” The only acceptable answer is the address in SERI’s directory, active.
  • “Which appendices are in your scope?” For ITAD with sanitization and remarketing, A, B, and C. Read the scope statement; do not accept a summary.
  • “What technical standard does your Data Sanitization Plan name, and how do you verify?” NIST SP 800-88 Rev. 2 and IEEE 2883 for the standard; independent sampling verification of at least five percent of wiped media with data-recovery tooling for the check. Ask to see a verification record.
  • “Who are your downstream vendors, and how were they qualified?” Under Appendix A this is documented by requirement. Reluctance is information.
  • “What is your EH&S management system certified to, and by whom?” ISO 14001 and 45001, or RIOS, with a certificate you can verify.
  • “What happens to a data-bearing device that fails sanitization?” The plan should say: physical destruction, with the failure recorded per serial and reported to you.

CyberCrunch’s R2v3 certification is scoped to Appendices A, B, and C, with RIOS as the management system beneath it and NAID AAA covering the destruction operation — and the certificate, scope statement, and directory listing are provided on request, as this guide tells you to ask of any vendor. The Data Destruction Field Manual covers what happens to a device once the letters check out.

Bottom line

Address, appendices, standard and verification, downstream, the system underneath, and the failed-device path. Six questions. An R2v3 facility with Appendix B has already documented every one of them for its auditor.

Section 09

Frequently asked questions

What is R2v3 certification?

R2v3 is the current version of the Responsible Recycling (R2) Standard, a voluntary standard for facilities that reuse and recycle used electronics, owned and administered by SERI (Sustainable Electronics Recycling International). A facility is audited by a SERI-authorized certification body against ten Core Requirements that apply to every R2 facility plus lettered Process Requirement appendices that apply to the activities it performs, such as Appendix A for the downstream recycling chain, Appendix B for data sanitization, and Appendix C for test and repair. Certification is issued per facility address and maintained through annual surveillance audits.

Is R2v3 certification for the company or the facility?

The facility. SERI requires a separate license application for each facility address, and the R2v3 Certified mark may be used only where a valid certificate has been issued for that location; a company that moves or adds a site must apply for that site. A vendor with several locations may hold certificates at some and not others, so a buyer should confirm in SERI's directory that the specific address that will receive their assets is listed as active, rather than relying on a company-level claim.

What do the appendix letters on an R2v3 certificate mean?

They are the Process Requirements the facility was audited for, in addition to the ten Core Requirements. A is the Downstream Recycling Chain, B is Data Sanitization, C is Test and Repair, D is Specialty Electronics Reuse, E is Materials Recovery, F is Brokering, and G is Photovoltaic Modules. A facility is audited only for the letters in its scope, so a certificate listing A, B, and C describes a facility audited for downstream vendor management, data sanitization, and refurbishment for reuse, while a certificate listing only E describes a materials-recovery operation that was not audited for sanitizing anything.

Does R2v3 certify data destruction?

Partly, and only with Appendix B. Core Requirement 7 requires every R2 facility to control data-bearing devices and to destroy or sanitize data before equipment moves to reuse or materials recovery. Appendix B, which a facility adds if it performs logical sanitization, requires a documented Data Sanitization Plan, security controls, records, and independent verification by sampling at least five percent of logically sanitized media with data-recovery tools. R2v3 does not itself name a technical sanitization standard, so buyers should ask which standard the plan follows, and should look to NAID AAA for the security of the destruction operation.

How do I verify an R2v3 certificate?

Search SERI's public directory of R2 Certified Facilities by facility name or location. Confirm that the listed address is the one that will process your assets, that the certificate status is active rather than suspended, revoked, or expired, and that the process requirements shown include the appendices your program needs, typically A, B, and C for IT asset disposition with sanitization and remarketing. Then request the certificate and scope statement from the vendor and compare the scope wording to your statement of work, since the certification body wrote the scope based only on what it could verify.

What other certifications does R2v3 require underneath it?

R2v3 Core Requirement 3 requires the facility's environmental, health and safety management system to be independently certified. SERI describes the two paths as ISO 14001 together with ISO 45001, or the recycling industry's integrated RIOS standard. A facility that tests and repairs equipment under Appendix C must also hold a certified quality management system, either ISO 9001 or RIOS. Each of these certificates is issued by its own certification body and can be verified separately, which is why a complete vendor file includes them alongside the R2v3 certificate.

A, B, AND C

Scoped for ITAD, and documented for your file

CyberCrunch’s R2v3 certification is scoped to Appendices A, B, and C — downstream chain, data sanitization, and test & repair — over a RIOS-certified management system, alongside NAID AAA and a PA DEP permit. Ask for the certificate, the scope statement, and the directory listing, and we will send them with the credentials packet.

NAID AAA · SINCE 2012 R2v3 · APPENDICES A/B/C RIOS PA DEP · WMGR081

This guide is informational only and reflects SERI’s public program materials for the R2v3 Standard — including its published descriptions of the Core and Process Requirements, the certification process, the R2 Code of Practices, and the directory of R2 Certified Facilities — as of September 2026. The R2v3 Standard is a licensed document available from SERI; this guide describes its structure and requirements at a summary level and does not reproduce normative text. R2 and R2v3 are marks of their owner. This guide is not legal or compliance advice and does not certify any vendor’s conformance; verify any certificate directly in SERI’s directory and confirm current requirements with SERI before relying on a specific clause. CyberCrunch credential statements reflect certificates held at the time of publication.