Certification · Last verified

NAID AAA Certification

NAID AAA Certification is i-SIGMA's voluntary program for member companies providing secure information destruction. Membership comes first. The owner audits certified companies on an ongoing, unannounced basis, with oversight by its Certification Committee. Applications are filed separately for physical media destruction and for electronic media erasure, and each is a distinct scope.

Class
Certification
Owner
i-SIGMA — International Secure Information Governance & Management Association
Last verified

What it is

The owner's own class sentence reads: "i-SIGMA's NAID AAA Certification® is a voluntary program for member companies providing secure information destruction".

Membership is a precondition. The owner's application page limits applications to i-SIGMA member service providers in secure data destruction or information management, so this is not a program any company can apply to directly.

The owner sets out three steps: "Meet all required specifications as outlined in the i-SIGMA Certification Specifications Reference Manual"; "Submit a completed i-SIGMA Certification application (select the appropriate application below) and send to" the address given; and "Successfully complete an initial scheduled audit verifying all aspects of compliance".

The requirements themselves live in a separate document the owner names on that page, the i-SIGMA Certification Specifications Reference Manual.

It is not one flat "data destruction certificate". The owner lists separate application types, including NAID AAA for Physical Media Destruction and NAID AAA for Electronic Media Erasure, alongside PRISM Privacy+ Certification, a combined PRISM Privacy+ and NAID AAA (Physical Media) application, and an Australian PSPF Endorsement Addendum.

The owner ties renewal to an approval anniversary date and describes a typical 4–8 week timeline from application to approval. A stated validity period in years and a recertification interval were not found on the owner's pages read for this record.

The owner runs a public search interface, the Service Provider Locator, described on its page as: "Looking for a service provider in your area? Our Service Provider Locator makes it easy to find local i-SIGMA, i-SIGMA NAID AAA Certified, and i-SIGMA PRISM Privacy+ Certified members." A separate member portal directory address exists for NAID AAA certified companies, but it loaded empty when tested on 4 September 2026, so its fields and access conditions were not verified.

Who owns it

i-SIGMA — the International Secure Information Governance & Management Association — owns and runs the program from 3030 N. Central Ave., Suite 706, Phoenix, AZ 85012, USA.

The association's canonical domain is isigmaonline.org, with a member portal at members.isigmaonline.org.

The owner uses a different word for its individual program on the same page: "Certified Secure Destruction Specialist® (CSDS®) Accreditation Program". NAID AAA is the company-level certification program.

Who assesses it

The first assessment is a scheduled audit, described by the owner as "an initial scheduled audit verifying all aspects of compliance".

Afterwards the owner states: "Ongoing, unannounced audits ensure continuous compliance, while oversight by the Certification Committee reinforces accountability and upholds the integrity of the program."

The pages read for this record carry no quotable statement about how auditor independence or auditor competence is established.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"NAID AAA Certification." Certifidex, FutureTechnologies. Last verified 4 September 2026. https://certifidex.com/frameworks/naid-aaa

All frameworks & audits →