Two checks cover it: read the certificate, then confirm the listing with i-SIGMA. The scope prints on the certificate itself, under a line reading "The certificate holder is NAID AAA Certified for the following services and media types" followed by the platform and media endorsements [4].
Provider-side guidance says the same thing. Greentec, an IT asset disposition and electronics recycling company in Cambridge, Ontario, published a post arguing that the certification is service-specific and that buyers should press on scope, framing the question as "You're NAID certified for example, but what are your NAID certified for?" and advising that when a company claims it, "ask for a copy of it and read what they're really certified for" [12]. i-SIGMA's own conference exhibitor page lists Greentec's certifications as including "i-SIGMA's NAID AAA, R2v3, ISO 9001, ISO 14001, and ISO 45001" [13], and that listing shows no endorsement detail, which is exactly why the certificate and the directory are the artifacts that matter.
Where the directory lives
i-SIGMA's FAQ points buyers to its locator: "You can use the i-SIGMA Service Provider Locator on the website to find certified secure destruction or information management companies in your area" [3]. The locator page offers filtered directories, including one for NAID AAA Certified providers, with the searchable listings held inside i-SIGMA's member portal [5]. The portal directory renders through JavaScript rather than serving a static page, so open it in a browser rather than expecting a link an automated tool can read.
Membership is not certification
A company can belong to i-SIGMA without holding any certification. i-SIGMA's FAQ states that companies must be active members to apply and that "Membership and certification are separate programs with their own requirements and fees" [3]. Quantum Lifecycle Partners, an Ontario IT asset disposition provider, describes the same split from the vendor side, noting that membership involves no audit while "prospective NAID AAA certified companies must submit an application and undergo an audit" [10]. i-SIGMA describes certification as designed to "Provide independent, third-party validation that your operations meet strict regulatory and security requirements" [6].
The clause that does the work for you
Specification 1.19 hands the buyer a written obligation to point at. Where a bid or RFQ requires or favors NAID AAA certification, the certified applicant must notify the issuing data controller in writing when "the service or portion of the service being requested in the bid or RFQ is not certified at the time of the bid," and must disclose whether a subcontractor is involved and whether that subcontractor holds the required certification [2]. Writing "NAID AAA certified for mobile/onsite hard drive destruction at the servicing location" into the requirement therefore shifts a written disclosure obligation onto the bidder.
If a claim still looks wrong, i-SIGMA's Code of Ethics requires members to "Avoid statements or representations that are false, misleading, incomplete, or likely to mislead," and routes ethics complaints to its Member Resolution Council [7].