The NAID AAA Certification® Program for secure information destruction operations has been around since 2000 (six years after the association’s founding). Here are answers to some of the most Frequently Asked Questions (FAQs) related to the program.
NAID AAA Certified companies are eligible to compete for the business of thousands of private secure destruction contracts and RFPs, and hundreds of government offices where NAID AAA Certification is required. More importantly, however, NAID AAA Certified service providers have the advantage of being pre-qualified as meeting the requirements of all data protection regulations. When the client understands they are legally required to verify service provider regulatory compliance, they naturally show preference to the service provider who has already verified it.
Yes. Any business broker or potential buyer will tell you that the value of your company is more when you can show that it is well-managed under standardized procedures, that it is compliant with regulations, and that it holds contracts that based on its credentials.
NAID AAA Certification applies to all types of secure destruction operations and is divided into two separate programs: one that applies to physical destruction operations and another that applies to electronic media overwriting operations. Within each program, there are “endorsements” that further define the specific nature of the certification. These endorsements indicate whether a firm is certified for on-site (mobile) or off-site (facility-based) services, the types of media it is certified to destroy (paper, hard drives, micromedia). There is even an endorsement for meeting Australian Protective Security Policy Framework which is recognized by government offices there.
Yes. NAID AAA Certification is a voluntary benefit of i-SIGMA Membership. Discover benefits of being an i-SIGMA Member. Those interested in joining should please contact the Membership Department for more information.
No. i-SIGMA Membership and NAID AAA Certification are two separate programs, with two separate fees, both of which need to be paid annually. In order to be NAID AAA Certified, you must be an i-SIGMA Member in good standing. Therefore, all membership dues must be maintained in order to be NAID AAA Certified. Membership dues follow a calendar year renewal. Certification renewal fees are paid on the anniversary of your initial approval.
The Member Resolution Council is the governing board of NAID AAA Certification. They are responsible for approving/denying certification and can assess points or fines to the members for discrepancies found during their audits.
Please submit an ethical complaint with proof of the offense to [email protected]. The complaint will be reviewed by the Complaint Resolution Council. Learn more about the association’s Code of Ethics and Complaint Resolution Council Guidelines for how to make a formal complaint.
Once you are an Active Member of i-SIGMA you can apply for NAID AAA Certification. Please submit the appropriate certification application along with the applicable fees to [email protected]. Once the application is completed, it will be assigned to a i-SIGMA auditor. The auditor will contact you to schedule the audit. They will report their findings back to i-SIGMA. If approved, you will receive an email notification along with NAID AAA Certification assets, be listed in the i-SIGMA Directory as certified, and receive a certificate showing your status.
Once i-SIGMA receives a completed application, NAID AAA Certification typically takes 4-8 weeks (slightly longer for electronic media erasure certification). Often, applications are not submitted complete.
Mobile Operations is completed via industrial destruction equipment in a mobile vehicle at the customer’s site to allow the customer the opportunity to witness the destruction taking place, if they chose to do so. Facility-based Operations is completed via stationary equipment in a secured building.
A Collection Facility and a TPS are both temporary secured locations, where the confidential material is stored prior to being destroyed via a Facility-based Operation. A Collection Facility must abide by the same requirements as a Facility-based Operation, with the exception of the destruction equipment and CCTV system. With a Collection Facility, the confidential material is not processed and therefore the bins are secured at all times and never opened. The confidential material must be transferred to the Facility-based Operation within 3 business days for destruction. A TPS must abide by the same requirements as a Facility-based Operation, with the exception of the destruction equipment. With a TPS, the confidential material is able to be processed and therefore a TPS must be audited. The confidential material must be transferred to the Facility-based Operation within 15 business days for destruction.
Yes. As long as the customer has the opportunity or option to witness the destruction, then the mobile destruction operation is still considered NAID AAA Certified.
As long as the customer stays to witness the destruction being performed, then it could be considered NAID AAA Certified. However, if the customer leaves and is unable to witness the destruction, the service is not considered NAID AAA Certified and the customer must be notified in writing of such.
Yes. To do so, please submit the form, Provisional Exception Request for the use of Mobile Destruction Equipment in a Facility-based Operation. The exception request will be forwarded to the Certification Committee for approval. If approved, you will be required to undergo an audit for this operation.
Yes. All criteria must be adhered to in order to be NAID AAA Certified. Therefore, prior to submitting your certification
application, we ask that you have 90 days of CCTV recordings in place. Failure to have 90 days of recordings may results in a denial of certification from the Certification Committee.
Yes. However we ask that there is enough lighting during non-business hours to recognize the face of the person in the Facility, and we ask that you have 90 days of CCTV recordings in place. Failure to have 90 days of recordings may results in a denial of certification from the Certification Review Board.
Yes. To do so, you must have a letter on file stating that the temp agency is aware that the material is confidential, they accept fiduciary responsibility of the material, and that their employees have had background checks which consist of the same requirements as NAID AAA Certification.
If you are involved in the day-to-day operations, then you must undergo all the employee screening requirements. However, if you are not involved in the day-to-day operations, then you are exempt from the I-9 form, drug screening and employment verification.
The certification fees range from $1,248 USD to $5,802 USD and are dependent upon the type of operations performed (Mobile, Facility-based, Overwriting, Degaussing, etc.). The certification fees are due annually on the month the member’s certification expires. Fees are all inclusive, already including processing fees, any auditor fees, auditor travel expense, etc.
All criteria needed for NAID AAA Certification can be found in the i-SIGMA Certification Specifications Manual.
i-SIGMA offers programs for companies with multi-location operations. In order to qualify for the program, an applicant must have at least three (3) destruction locations and must be committed to achieving 100% compliance with the NAID AAA Certification specifications at all information destruction-related locations and agreeing that all such facilities will be subject to the scrutiny of audits. Contact the Certification Department for specifics regarding the multi-location program that best meets your company’s needs. [email protected] | +1 602-788-6243
Yes, the association offers a number of resources to assist you in becoming certified.
The i-SIGMA Certification Department sends official notices of any certification program updates to the main certification contact for your company. Additionally, you can access all certification program updates here.
[email protected] | +1 602-788-6243