Resources
Ten questions that separate ITAD providers
Written to be useful even if you do not choose us. Every question below has a falsifiable answer — which is the only kind worth asking when every provider's website says the same things.
Why this exists
Capability claims are cheap. Evidence requests are not.
Read four ITAD websites and you will find the same vocabulary on all of them: secure, certified, compliant, chain of custody, sustainable. The words are free. What differs is whether the controls behind them are mechanisms or intentions, and you cannot tell from the marketing.
So ask questions where a weak answer is visibly weak.
We have put our own answers into the pages on this site rather than reserving them for a sales call. If a provider will not answer these in writing before you contract, that is itself a finding.
The framework
Ask these, in writing
Certification scope — not the badge
“Which of your facilities hold which certifications, and what activities does each certificate's scope actually cover?”
A certificate names a scope. R2v3, for example, is issued with appendices covering specific activities — downstream recycling chain, data sanitization, test and repair — and a provider certified for logical sanitization is not thereby certified for physical destruction. Ask for the certificate, then read the scope line. Providers rarely lie about certification; they routinely let buyers assume a scope broader than the one they hold.
Where processing physically happens
“Where will our equipment be processed, and is any part of the work subcontracted?”
A provider who brokers your assets to a third party cannot show you the room they were processed in, and the party you assessed is not the party holding your data. Ask for the address. Ask whether you can visit it.
Evidence granularity
“Is a sanitization certificate issued per device or per batch?”
Per-batch certification looks like evidence until an auditor asks about one serial number. A per-device certificate should name the device serial, the method applied, the operator, the workstation, a timestamp, the result and a validation reference. Ask to see a sample.
Right to audit
“Can we or our third-party auditors inspect the facility and review records, and on what notice?”
Providers who have built for auditability say yes with a timeframe. Providers who have not become abstract. This question is unusually good at separating the two.
Verification versus validation
“Do you verify that the sanitization operation completed, or validate that the data was effectively sanitized?”
NIST SP 800-88 Revision 2 separates these deliberately. Verification asks whether the operation ran; validation asks whether it worked for that medium. A technique can execute perfectly and still be wrong for the storage type — an interface-level overwrite on flash being the classic case. A provider who only verifies is answering a narrower question than the standard poses.
What happens on failure
“What happens to a device that fails sanitization, and can it re-enter the flow?”
This exposes whether controls are mechanisms or intentions. Ask specifically whether a device lacking a passing result can still be shipped or invoiced. If the honest answer is that a supervisor could push it through, the control is advisory.
Downstream accountability
“Who processes residual material, do you audit them, and can we see the manifest trail?”
Liability for improper downstream handling does not disappear when the truck leaves. Certification schemes require downstream vendor management for exactly this reason, so ask how it is exercised rather than whether it exists.
Value recovery transparency
“How is residual value calculated, and how is it evidenced back to us?”
The weakest area in the industry. Very few providers publish anything about this. A credible answer ties proceeds back to individual assets — configuration at intake, grade at test, realised price at sale — rather than presenting a lump sum you cannot audit.
Insurance and liability transfer
“What insurance is carried and at what limits, and at exactly what point does liability transfer?”
Establish this in writing before equipment moves. The window between collection and intake is the least-governed part of most engagements and the one buyers most often forget to ask about.
Compliance framing
“Does engaging you make us compliant with HIPAA, GLBA or PCI-DSS?”
The correct answer is no. Those obligations rest with your organization and cannot be transferred to a vendor — NIST 800-88 itself assigns sanitization responsibility to roles inside the owning organization. A provider marketing itself as offering "HIPAA-compliant ITAD" has either misunderstood where the duty sits or is comfortable letting you misunderstand it. Either is informative.
FAQ
Questions about choosing a provider
What certifications should an ITAD provider hold?
Is more certification always better?
How do I compare providers who all say the same things?
What are the clearest warning signs?
Should price be a factor?
How should we structure an ITAD RFP?
This framework is provided for general information and is not legal, compliance or procurement advice. Certification requirements, regulatory obligations and contractual terms vary by organization and jurisdiction.
Put these questions to us.
Send your vendor questionnaire or your RFP. We would rather answer the hard ones during scoping than discover a blocker after contracting.