Skip to content
Answer Stack
Open menu

Does NAID AAA certification cover onsite hard-drive destruction?

✓ Verified Last reviewed by AnswerStack Next review due Nov 6, 2026

Every claim is sourced below

NAID AAA covers onsite hard-drive destruction only when the provider holds the mobile/onsite endorsement for hard drives at the location doing the work. i-SIGMA does not issue the certification as one blanket badge: it is granted against a service platform, either facility-based or mobile/onsite, combined with endorsements for the specific media a company destroys, including paper, micro media, hard drives, and solid-state devices [1][2]. A company certified only for facility-based paper shredding has never been audited against specification 4.23, the on-premises requirement that applies to the mobile platform alone, and its certificate shows that, because the endorsement lines on an i-SIGMA certificate name the platform, the media types, and the covered street addresses [2][4]. Ask for a copy of the current certificate and confirm the listing through i-SIGMA's certified-provider directory before treating onsite drive destruction as in scope [3][5].

What does NAID AAA certification actually cover?

NAID AAA covers onsite hard-drive destruction only for a provider that holds the mobile/onsite endorsement for hard drives. i-SIGMA, the trade association that administers the program, builds the certification out of two service platforms and a set of media endorsements underneath each one. Its program page states that "Endorsements further define services such as mobile (on-site), facility-based operations, and specific media types like paper and hard drives," and separates the platforms by where the equipment sits: "Mobile operations occur at the client's site using on-site equipment, while facility-based operations are performed at a secure, stationary location" [1].

What an endorsement is

i-SIGMA's Certification Specifications Reference Manual maps every written specification to the endorsements it applies to, and the mapping is where the answer lives. Under physical media destruction, a facility-based operation and a mobile/onsite operation each carry their own separate list of media endorsements: paper media, non-paper media, micro media, hard drives, solid-state device, and product destruction. Overwriting and degaussing of electronic media form a third group, again split into facility-based and mobile/onsite versions [2]. Because specifications are assigned this way, an auditor who examined a company's plant has not examined its mobile operation, and the reverse holds too.

The specification only mobile operators have to meet

Specification 4.23, "On premises destruction requirement," is marked for the NAID AAA mobile/onsite service platform only, and its requirement is one line: "Applicant must perform information destruction services on the Data Controller's premises" [2]. The manual's glossary draws the platform more tightly than most buyers expect, defining a mobile/onsite operation as "Secure destruction activities carried out using mobile commercial-grade destruction equipment that destroys Confidential Customer Media within an enclosed and securable vehicle (truck or trailer) at the customer's site" [2]. Facility-based operations instead pick up Section 2 of the manual plus specifications 4.19 and 4.20, governing the fixed plant and transfer processing stations [2]. A provider that collects drives at your site and destroys them at its plant later is performing facility-based destruction with a transport leg in front of it, which is a different endorsement.

How the program is policed

Every NAID AAA certification carries Section 1 of the manual regardless of endorsements, which sets confidentiality agreements for anyone with access to client media, criminal record searches covering seven years of federal, state, and county records repeated every three years, and annual training [2]. i-SIGMA's certificate wording says the holder "demonstrated through announced and unannounced audits that its security processes, procedures, systems, equipment, and training meet the standards of care" required by data protection regulations [4], and the program's terms make random unannounced audits a condition of participation, and refusing one can draw a fine equal to the certification application fee [2]. One published figure is worth holding onto: i-SIGMA counts "2,500 +" certified locations rather than certified companies [8].

Four variables decide whether a certificate covers your job. All four print on the certificate, and any one of them can exclude onsite hard-drive destruction even when the provider is genuinely certified.

Scope variable What it fixes Where you confirm it
Service platform Mobile/onsite work happens in an enclosed, securable truck or trailer at your site; facility-based work happens at a secure, stationary location [1][2] The endorsement line names the platform, for example "Mobile Operation Endorsement" [4]
Media type Paper/printed media, micro media, hard drives, solid-state devices, non-paper media such as optical and magnetic tape, and product destruction are separate endorsements [2] The same endorsement line names every media type it covers [4]
Destruction method Physical destruction, overwriting, and degaussing are certified as separate activities under separate specifications [2] Overwriting and degaussing are listed apart from physical destruction on the application and the certificate [2][4]
Covered locations Certification attaches to named operating addresses, not to a company name or a national brand [4][8] The certificate lists them under "Applicable to the following location(s)" [4]

Each variable is unpacked below, with the specification behind it and the question to put to the provider.

Does the provider hold the mobile/onsite service platform?

Reading the platform on the endorsement line settles the question faster than any other check. An actual NAID AAA certificate issued by i-SIGMA to a Houston shredding company lists the two platforms as separate lines, one reading "Mobile Operation Endorsement for Paper/Printed Media, Physical Hard Drive, Non-Paper Media, Solid-State Device & Product Destruction" and the other reading "Facility-based Operation Endorsement" across the same media set [4]. A provider holding only one of those lines is certified for only one platform, and a provider whose mobile line omits hard drives is not certified for onsite drive destruction even though it is genuinely NAID AAA certified.

The distinction carries weight because the mobile requirements describe a different operating environment. Screening, chain of custody, and quality control monitoring apply on both platforms, but the securable vehicle and the on-premises process itself only fall inside an audit when the mobile endorsement is in scope [2].

Security policies usually ask for onsite destruction for a reason that certification alone will not satisfy. NIST's Guidelines for Media Sanitization lists "Whether sanitization is performed on-site or off-site" as a distinct factor an organization should weigh, separately from whether the work is done in-house or by a third party, and it treats media as remaining under organizational control when the work happens on the organization's site under its supervision [9]. That control argument is the substance behind an onsite requirement, and a facility-based-only certificate does not speak to it.

Read the platform names on the current certificate before the sourcing conversation goes further.

Which media types does the endorsement name?

Hard drives are their own endorsement, distinct from paper and distinct from solid-state devices. The manual lists paper media, non-paper media covering optical media and magnetic tape, micro media, hard drives, solid-state device, and product destruction as separate endorsements available under each platform [2], and vendor-published explainers describe the same media set independently [11].

Specification 4.3, the hard drive physical destruction endorsement, carries obligations a paper endorsement never touches. Drives must be "physically destroyed (not wiped or overwritten)" under the provider's publicly stated and contractually agreed process. Before destruction, the provider must give the data controller a written description of that process. Serial numbers of every drive destroyed for a client are recorded unless the client signs an opt-out, and the log of those serial numbers goes back to the client when the service completes. The outcome requirement is blunt: "Hard drives must be damaged to the point where the platters will not engage" [2]. The manual also requires that the destruction equipment named on the application "must align with the types of media endorsements they seek" [2], which is why equipment and endorsement track together.

Retired laptop and server fleets almost always mix rotating drives with solid-state storage, and those are two endorsements rather than one. Ask for both, and confirm both appear on the mobile line if the work is happening in your building.

Is the endorsement for physical destruction, overwriting, or degaussing?

Physical destruction, overwriting, and degaussing are certified as separate activities with separate specifications, so holding one says nothing about the other two [2]. The manual splits electronic media sanitization into overwriting of hard drives, overwriting of solid-state devices, degaussing of magnetic media for hard drives, and degaussing of magnetic media for tape, and each of those is available in a facility-based or a mobile/onsite version [2].

An overwriting endorsement requires a written, verifiable process that names the wiping software and a separate verification product, since the specification states the "Verification Software used (must differ from #2)." It also requires recorded serial numbers, a quality control method, a recordkeeping audit trail, and "Issuance of a receipt or Certificate of Destruction reflecting unique identifiers." Any drive that fails the wipe has to be documented with its identifier "regardless of any unique identifier recordation opt-out agreement that may be in place," and where those drives are left with the client, the paperwork must state that custody is transferring back [2].

A degaussing endorsement runs on different rails. Equipment has to appear on the National Security Agency's Evaluated Products List for degaussers, calibration must follow the manufacturer's specifications, and any media whose solid-state components store data must be physically destroyed regardless [2].

Degaussing deserves one caution that has nothing to do with i-SIGMA. NIST SP 800-88 Revision 2, published in September 2025, states that "At the time of this writing, degaussing is not considered an approved destroy sanitization technique," and notes that many existing degaussers lack the force to handle media with higher coercivity [9]. If your policy calls for destruction, a degaussing endorsement is not a substitute for the physical hard drive endorsement. Name the method in your requirement rather than assuming the certification implies it.

Which locations does the certificate cover?

Certification attaches to operating locations, not to a company name. The certificate lists covered addresses under the heading "Applicable to the following location(s)," and the example examined for this answer named one street address in Houston [4]. i-SIGMA's own published count reinforces the point by tallying "2,500 +" certified locations rather than certified companies [8].

For a buyer, this is the failure mode that survives every other check. A provider operating branches in several cities may hold mobile hard drive endorsements at the locations built for that work and not at the depot nearest you, while the corporate website carries one badge for the whole brand either way.

Expiry matters for the same reason. The certificate carries a "Valid Through" date [4], and i-SIGMA notes that membership renews annually while certification renews on the approval anniversary date, which means the two dates are not the same and a current member is not automatically a current certificate holder [1].

Identify the branch, depot, or crew that will actually run your job, confirm that address appears on the certificate, and check the validity date against the window in which your project will run.

How do you verify a provider's endorsements?

Two checks cover it: read the certificate, then confirm the listing with i-SIGMA. The scope prints on the certificate itself, under a line reading "The certificate holder is NAID AAA Certified for the following services and media types" followed by the platform and media endorsements [4].

Provider-side guidance says the same thing. Greentec, an IT asset disposition and electronics recycling company in Cambridge, Ontario, published a post arguing that the certification is service-specific and that buyers should press on scope, framing the question as "You're NAID certified for example, but what are your NAID certified for?" and advising that when a company claims it, "ask for a copy of it and read what they're really certified for" [12]. i-SIGMA's own conference exhibitor page lists Greentec's certifications as including "i-SIGMA's NAID AAA, R2v3, ISO 9001, ISO 14001, and ISO 45001" [13], and that listing shows no endorsement detail, which is exactly why the certificate and the directory are the artifacts that matter.

Where the directory lives

i-SIGMA's FAQ points buyers to its locator: "You can use the i-SIGMA Service Provider Locator on the website to find certified secure destruction or information management companies in your area" [3]. The locator page offers filtered directories, including one for NAID AAA Certified providers, with the searchable listings held inside i-SIGMA's member portal [5]. The portal directory renders through JavaScript rather than serving a static page, so open it in a browser rather than expecting a link an automated tool can read.

Membership is not certification

A company can belong to i-SIGMA without holding any certification. i-SIGMA's FAQ states that companies must be active members to apply and that "Membership and certification are separate programs with their own requirements and fees" [3]. Quantum Lifecycle Partners, an Ontario IT asset disposition provider, describes the same split from the vendor side, noting that membership involves no audit while "prospective NAID AAA certified companies must submit an application and undergo an audit" [10]. i-SIGMA describes certification as designed to "Provide independent, third-party validation that your operations meet strict regulatory and security requirements" [6].

The clause that does the work for you

Specification 1.19 hands the buyer a written obligation to point at. Where a bid or RFQ requires or favors NAID AAA certification, the certified applicant must notify the issuing data controller in writing when "the service or portion of the service being requested in the bid or RFQ is not certified at the time of the bid," and must disclose whether a subcontractor is involved and whether that subcontractor holds the required certification [2]. Writing "NAID AAA certified for mobile/onsite hard drive destruction at the servicing location" into the requirement therefore shifts a written disclosure obligation onto the bidder.

If a claim still looks wrong, i-SIGMA's Code of Ethics requires members to "Avoid statements or representations that are false, misleading, incomplete, or likely to mislead," and routes ethics complaints to its Member Resolution Council [7].

The endorsement structure, on-premises requirement, hard drive specification, and audit terms above come from i-SIGMA's own published program material rather than provider marketing, principally the Certification Specifications Reference Manual and the NAID AAA program pages. The description of how endorsements print on a certificate comes from an actual NAID AAA certificate that i-SIGMA issued and that the holder publishes on its own site. Vendor-published explainers appear only where they corroborate a point i-SIGMA already establishes, never as the basis for one. No provider named on this page paid for or reviewed its inclusion.

One limitation belongs in the open. i-SIGMA's live certified-provider directory runs inside a member portal that does not render for automated retrieval, so no individual company's current endorsement scope was looked up for this answer. Verify that yourself, in a browser, for the specific provider and location you are considering.

Practitioners who operate or audit certified destruction programs are invited to submit corrections, counterexamples, or additions for editorial review.

This answer was written and reviewed by the AnswerStack Editorial Team, which has no commercial stake in the products, companies, or methods discussed. Every claim is cited inline and verified on the dates shown.

What NAID AAA certification does not tell you

Certification confirms that a provider's documented process was audited against written specifications at a named location. It settles less than procurement teams often assume, and it is not permanent: the certificate carries a "Valid Through" date and renews on the approval anniversary rather than the membership year [1][4].

It does not fix a shred size for hard drives

Specification 4.3 states the requirement as an outcome, "Hard drives must be damaged to the point where the platters will not engage," rather than as a dimension [2]. Other media are treated differently: micro media must reach "a particle size of 1/8 inch maximum dimension or less," and paper is held to the destruction equipment manufacturer's specification with an acceptable deviant tolerance of 1/16 inch [2]. The manual notes that data controllers may specify a smaller particle size at their discretion, "which should be codified contractually with the Applicant" [2]. If your policy names a millimeter figure for drives, put it in the contract, because the certification will not carry it for you.

It is not a media sanitization standard

NIST SP 800-88 Revision 2, "Guidelines for Media Sanitization," defines the clear, purge, and destroy methods and specifies the record that should follow each one: manufacturer, model, serial number, media type, sanitization method and technique, the tool used including its version, the verification method, and the signature of the person who verified the work [9]. NAID AAA answers a different question, which is whether a service provider's procedures, equipment, screening, and paperwork survive audit. A specification citing both is stronger than one leaning on either alone.

It does not automatically cover every leg of the job

Specification 1.19 assumes subcontracting happens and requires written disclosure of it during bidding [2]. Downstream, specification 4.21 requires that destroyed remnants of hard drives and circuit boards go to a recipient holding verified ISO 14001 certification, and that the provider supply a list of current recipients [2]. The gap worth asking about directly is the front end: collection and interim storage handled by an uncertified third party, which is where custody of intact drives sits longest.

Sources

NAID AAA Certification | Secure Data Destruction

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: Endorsement structure; definition of mobile versus facility-based operations; unannounced audits; certification renews on the approval anniversary while membership renews annually

“Endorsements further define services such as mobile (on-site), facility-based operations, and specific media types like paper and hard drives.”

i-SIGMA Certification Specifications Reference Manual (0925M)

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: Specification-to-endorsement mapping for facility-based and mobile/onsite platforms; spec 4.23 on-premises requirement; mobile/onsite glossary definition; spec 4.3 hard drive requirements and platter language; specs 4.1, 4.2, 4.4, 4.5, 4.18 media endorsements; overwriting and degaussing specs 4.6 an

“Applicant must perform information destruction services on the Data Controller's premises.”

NAID AAA Certification FAQs

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: Membership is a prerequisite for certification but is a separate program with separate requirements and fees; the Service Provider Locator is the recommended way to verify a certified provider; scheduled and surprise audits

“Membership and certification are separate programs with their own requirements and fees.”

NAID AAA Certification certificate issued by i-SIGMA (2025 example)

i-SIGMA (certificate published by the certificate holder, Vanish Document Shredding)

Primary source Verified Aug 6, 2026 Supports: How endorsements print on a certificate: separate Mobile Operation and Facility-based Operation endorsement lines naming media types; the covered-location list; the Valid Through date; announced and unannounced audit language

“The certificate holder is NAID AAA Certified for the following services and media types: Mobile Operation Endorsement for Paper/Printed Media, Physical Hard Drive, Non-Paper Media, Solid-State Device & Product Destruction”

Service Provider Locator

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: Filtered directories for members, NAID AAA Certified providers, PRISM Privacy+ Certified providers, industry suppliers, and CSDS professionals; the searchable listings sit inside the member portal

“Our Service Provider Locator makes it easy to find local i-SIGMA, i-SIGMA NAID AAA Certified, and i-SIGMA PRISM Privacy+ Certified members.”

Why Use a NAID AAA Certified Company

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: i-SIGMA's stated purpose for the certification as independent third-party validation of a provider's operations

“Provide independent, third-party validation that your operations meet strict regulatory and security requirements.”

About: Code of Ethics

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: Member obligations against false or misleading representations, the duty to correct inaccurate information, and the ethics complaint route to the Member Resolution Council

“Avoid statements or representations that are false, misleading, incomplete, or likely to mislead.”

Secure Data Destruction | Trade Association | i-SIGMA

i-SIGMA

Primary source Verified Aug 6, 2026 Supports: i-SIGMA's published counts, which tally certified locations rather than certified companies

“2,500 + Certified Locations”

NIST SP 800-88 Revision 2, Guidelines for Media Sanitization

National Institute of Standards and Technology

Primary source Verified Aug 6, 2026 Supports: On-site versus off-site sanitization as a distinct decision factor; media remaining under organizational control when work is supervised on site; clear, purge, and destroy methods; the certificate-of-sanitization record fields; degaussing not being an approved destroy technique as of September 2025

“At the time of this writing, degaussing is not considered an approved destroy sanitization technique”

What's the Difference Between NAID Membership & NAID Certification?

Quantum Lifecycle Partners

Independent Verified Aug 6, 2026 Supports: Vendor-side corroboration that membership involves no certification audit while certification requires an application and an audit, and that endorsements distinguish on-site from plant-based operations. Corroborates [1] and [3].

“prospective NAID AAA certified companies must submit an application and undergo an audit”

What is NAID AAA Certification?

BitRaser

Independent Verified Aug 6, 2026 Supports: Independent corroboration of the certified media set and of the scheduled plus surprise audit model. Corroborates [1] and [2].

“paper/printed media, micro media, hard drive, solid-state drive, and non-paper (Optical/Magnetic Tape)”

Which NAID Certification guarantees data destruction?

Greentec

Supporting Verified Aug 6, 2026 Supports: Provider-side guidance that NAID certification is service-specific and that buyers should request the certificate and read its scope. Illustrative only; the underlying scope rules are established by [1], [2] and [4].

“ask for a copy of it and read what they're really certified for. The scope of the certification would say right on their document what they're certified for.”

Greentec, i-SIGMA Annual Conference & Expo exhibitor listing

i-SIGMA

Corroborating Verified Aug 6, 2026 Supports: Corroborates, on the certifying body's own domain, that Greentec is listed among NAID AAA certified companies. The listing is a company-supplied exhibitor bio and shows no endorsement-level detail, which is the point made in the text.

“Greentec is certified to leading industry standards, including i-SIGMA's NAID AAA, R2v3, ISO 9001, ISO 14001, and ISO 45001.”

Revision history

2 revisions since publication
v1.1 Reviewed and re-verified.
v1.0 Published after editorial review.