The PC-Doctor Blog

R2v3, ADISA, and NAID AAA: What Each Certification Requires of Your Erasure Process

R2v3, ADISA, and NAID AAA: What Each Certification Requires of Your Erasure Process

Last technical review: September 29, 2026 by PC-Doctor Engineering

R2v3, ADISA, and NAID AAA all require documented data sanitization, and they all ask for different things. R2v3 sets a recoverability threshold and requires independent verification sampling.[1] ADISA audits the technical efficacy of the erase, on site, with forensic tools.[2][3] NAID AAA audits the people, the access controls, and the chain of custody around the erase, and leaves the technique to the operator’s policy.[4]

Most operations learn those differences during an audit. The better time is before one.

Three Certifications, Three Questions

Each program was built to answer a different question, and the erasure requirements follow from that.

  R2v3 ADISA ICT Asset Recovery 8.0 NAID AAA
Run by SERI (Sustainable Electronics Recycling International) ADISA Certification Ltd; UK ICO-approved GDPR certification scheme i-SIGMA
Governs The electronics reuse and recycling lifecycle ICT asset recovery and data sanitisation Information destruction services
The question it asks Is the material handled responsibly, and is the data gone? Does the sanitisation actually work? Can the people and the process be trusted?
Sanitization level required Data not recoverable by commercially available recovery software Aligned to NIST 800-88r2 or IEEE 2883 (see below) Not prescribed; the method used must be recorded
Verification Independent sampling of at least 5% of logically sanitized media Auditor forensic testing on processed media, on site Independent internal quality control
Who asks for it Enterprise ITAD buyers, recyclers’ downstream partners UK and EU enterprise and public-sector clients Clients in regulated industries; often a contractual requirement

The table is the summary. The rest of this article is what each row means for a technician running drives.

R2v3: A Threshold, and Proof You Checked

R2v3 does not use the words Clear or Purge. It sets a threshold instead: logically sanitized media must not yield data to commercially available recovery software. Factory resets and manual deletion do not meet it. Overwriting with sanitization software does, for magnetic drives, and firmware-level erasure does for solid-state drives.

The requirement that trips operations up is not the threshold. It is the check. Appendix B, clause 13, requires that at least 5% of logically sanitized media be routinely sampled by a competent and independent party to demonstrate that the data is not recoverable.[1] The sampling has to use recovery tools, not the erase tool’s own log. The point is to prove the process works, not to reread the process’s own report.

That is a real cost at volume. Five percent of a thousand drives a week is fifty drives a week under a recovery tool, by someone who did not run the erase. Operations that treat verification sampling as an audit-week activity rather than a routine one are the ones that fail this clause.

ADISA: The Erase Has to Survive a Forensic Examiner

ADISA’s standard is the most technically specific of the three, and the newest. Version 4.0 of the ICT Asset Recovery Standard 8.0 was released in March 2026, and its definition of logical sanitisation names the standards directly: firmware commands “aligned to published guidelines (NIST 800-88r2) or standards (IEEE 2883).”[2]

Certification is a two-day site audit, and the auditors bring forensic tools.[3] They select processed media and attempt to recover data from it. A certificate of erasure is required evidence, but it is not the test; the test is whether the drive gives anything up.

ADISA also handles erasure failure explicitly. Under the standard’s technical module, if an erasure tool attempts a Purge and the drive cannot complete it, the tool must fall back to a Clear. If the Clear also fails, the result must be recorded as an erasure failure — not silently retried, not reclassified, not omitted from the record.[2] This is the same sequence a well-built tool follows on its own: attempt the most stringent method, analyze the result, classify honestly. The standard makes that sequence a requirement rather than a design choice.

Two levels of ADISA certification exist and are often confused. Company certification covers the operation. Product Claims Testing certifies the erasure software itself, by testing it against specific media. An operation can be certified while using an uncertified tool, and a tool can be certified while the operation using it is not.

NAID AAA: The Method Is Yours to Choose, and to Record

NAID AAA is the program that most surprises technicians, because it does not care which erase command was used.

It audits operational security: employee screening and training, access control to the processing area, chain of custody from intake to final disposition, and independent internal quality control.[4] The sanitization method is not a strict criterion. What the standard requires is that the method used be recorded, and that custody of the media be maintained and documented at every step.

That makes NAID AAA the certification least concerned with what happened inside the drive and most concerned with what happened around it. A perfect Purge with a gap in the custody log fails NAID AAA. A Clear with an unbroken custody record can pass it.

Where NIST and R2v3 Disagree, and Why Both Are Right

NIST SP 800-88 Revision 2, Section 4.5.1, says that for non-destructive sanitization, verification means checking the tool’s completion status and the health of the media, and that “unless explicitly required by organizational policy, elaborate sampling” of the drive’s contents “is not necessary.”[5]

R2v3 Appendix B(13) requires exactly that sampling.[1]

These are not in conflict. They describe different things. NIST is describing what it takes to establish that a technique worked on a drive. R2v3 is describing what it takes to establish, to an auditor, that an operation’s process works across a population of drives. The first is a statement about sanitization. The second is a statement about evidence.

An operation subject to both follows R2v3, because it is the stricter requirement and because NIST’s clause explicitly defers to organizational policy — and an R2v3 certification is that policy.

The One Thing All Three Agree On

Every one of these programs wants the drive erased before anything else is done to the system.

The reasoning is chain of custody. A device that arrives with data and sits through triage, diagnostics, and grading still has data on it through every one of those steps, and every step is a point where custody can be questioned. Erase first, and every subsequent step happens to a sanitized device.

That is why PC-Doctor Factory Bootable now runs Drive Erase first, then diagnostics, in its default automation. Diagnostics tell you whether the drive is worth keeping. Certification bodies would rather you found that out after the data was gone.

What the Certificate Has to Carry

All three programs consume the certificate of erasure as evidence. None of them accepts it as the only evidence. What a certificate must contain to satisfy an auditor is covered in What a Certificate of Erasure Must Contain to Survive an Audit; the short version is that the certificate proves what the tool did to one drive, and the certification proves the operation does it every time.

If your erasure tool records the standard, the level reached, the technique, the tool version, the verification, and the operator, you have what all three audits will ask for from the tool. The sampling, the custody log, and the trained staff are yours to supply. See how Factory Drive Erase generates the per-drive record that R2v3, ADISA, and NAID AAA audits expect.

Frequently Asked Questions

Does R2v3 require a NIST 800-88 Purge?

No. R2v3 requires that logically sanitized data be unrecoverable by commercially available recovery software, and that at least 5% of sanitized media be independently sampled to prove it. A Purge satisfies the threshold. So does an overwrite Clear on a magnetic drive.

Does NAID AAA require a specific data erasure method?

No. NAID AAA audits employee screening, access control, chain of custody, and quality control. The erasure method is left to the operator’s policy, but it must be recorded, and custody must be documented throughout.

What is the difference between ADISA company certification and ADISA Product Claims Testing?

Company certification audits the operation, on site, including forensic testing of processed media. Product Claims Testing certifies a specific erasure tool by testing it against specific media. One does not imply the other.

Does NIST 800-88 require verification sampling?

Not by default. Revision 2 says elaborate sampling is unnecessary unless organizational policy requires it. R2v3 does require it, and an operation certified to R2v3 has adopted that requirement as policy.

Why do certification bodies want drives erased before diagnostics?

Chain of custody. Every step a device goes through with data still on it is a step where custody can be questioned. Erasing first means diagnostics, grading, and repair all happen to a sanitized device.

References

  1. SERI. “Verifying the Effectiveness of the Data Sanitization Process,” R2v3 Knowledge Base, quoting Appendix B(13). ↩
  2. ADISA. ICT Asset Recovery Standard 8.0, Part 1 v4.0, March 12, 2026. Published via the UK Information Commissioner’s Office. ↩
  3. UK Information Commissioner’s Office. ADISA ICT Asset Recovery Certification 8.0, certification scheme register. ↩
  4. i-SIGMA. “How Does NAID AAA Certification Intersect With NIST 800-88? (Part 1).” ↩
  5. National Institute of Standards and Technology. Guidelines for Media Sanitization, SP 800-88 Revision 2, §4.5.1. September 2025. ↩

Authors

Colin Corr

Colin Corr

Senior Information Technology Manager