Compliance · 6 min read
R2v3 and NAID AAA vs. NIST 800-88: What They Actually Cover for Data Erasure Software
If you are evaluating data erasure tools for an ITAD or MSP operation, you have probably seen R2v3 and NAID AAA mentioned in the same sentence as NIST 800-88, sometimes on a vendor's own site. They get lumped together because they all show up in compliance checklists, but they certify different things, and knowing the difference will save you from asking a software vendor for a certification it was never built to hold.
NIST 800-88
A sanitization standard. Defines Clear, Purge and Destroy. No certifying body audits products against it.
NAID AAA
An audit of a physical destruction facility, issued by i-SIGMA. Site visits, staff screening, chain of custody.
R2v3
A recycler certification, managed by SERI. Covers material tracking and downstream vendor handling.
NIST 800-88 is a sanitization standard, not a certifying body
NIST Special Publication 800-88 defines how to make data unrecoverable: Clear (software overwrite), Purge (firmware-level commands like ATA Secure Erase or NVMe Sanitize that reach blocks a simple overwrite cannot), and Destroy (physical destruction). NIST does not audit or certify products against it. What a software vendor can do is implement the methods correctly, verify the result, and document it. That is a code and process question, and you can check it yourself: ask which specific commands the tool issues for SSDs versus HDDs, and whether it performs a verification read-back before it signs anything.
NAID AAA certifies a destruction facility, not a piece of software
NAID AAA Certification, issued by i-SIGMA, is an audit of a physical operation: unannounced site visits, background-checked staff, chain-of-custody controls, and specific standards for how a facility physically destroys media. In 2026, i-SIGMA extended those requirements to cover the digital side of certified facilities too, requiring things like multi-factor authentication and centralized access controls on the systems that hold a facility's audit trail. All of that describes a business that runs a shredding or degaussing operation. A piece of software you install on your own machines or boot from your own ISO is not a facility, and asking it to be NAID AAA certified is asking the wrong question.
R2v3 certifies a recycler, not an erasure tool
R2v3, managed by SERI, is the standard that governs responsible electronics recycling: how a recycler tracks material, manages downstream vendors, and handles data-bearing devices that pass through its facility. Like NAID AAA, it is a certification you would look for when you are choosing who physically recycles or resells retired hardware. If your MSP or ITAD business also does the recycling, R2v3 is worth pursuing for your own operation. If you are just buying software to generate a compliant erasure certificate before hardware leaves your hands, R2v3 is not a box that software needs to check.
Two different questions, two different answers
It helps to separate the two questions a compliance-minded buyer is actually asking. Is the data actually gone, and can I prove it? is a software and process question, answered by NIST 800-88 and by whether the tool verifies and signs what it did. Was the physical hardware handled and disposed of responsibly, by people who were background-checked and audited? is a facility question, answered by NAID AAA or R2v3. A vendor selling you erasure software is only ever answering the first question. If a vendor's marketing implies it holds a facility certification for a product that runs on your own machines, that is worth a direct question back to them.
What to actually ask a vendor
The useful question is not "are you NAID AAA or R2v3 certified." It is: which NIST 800-88 methods does the software implement for which drive types, does it verify the wipe before it certifies it, and can a third party check the certificate without trusting the vendor's word for it.
WipeCert's agent implements 7 selectable erasure methods across HDD, SSD, NVMe and eMMC (ATA Secure Erase, ATA Sanitize, NVMe Sanitize, NVMe Format Crypto Erase, Cryptographic Erase, TCG Opal PSID Revert, and multi-pass overwrite for NIST Clear or DoD 5220.22-M), and every wipe produces a certificate signed with Ed25519 over a canonical (RFC 8785) payload that anyone can verify at a public URL, no login required.
We do not hold NAID AAA or R2v3 certification, and we are not going to claim we do. Those apply to the business that physically destroys or recycles the hardware. If that is part of your operation, that is a certification for your facility to pursue, not something a software vendor can hold on your behalf.
The honest version of "compliant"
The reason this distinction matters is not pedantry. An auditor or an ISO 27001 assessor reviewing your ITAD process will ask what standard the erasure followed and who can verify it after the fact, not which unrelated facility certifications your software vendor lists on a badge. Getting that answer right, and being able to hand over a signed, independently verifiable certificate for every device, is what actually holds up.
See the certificate before you commit
Starter is $79/month for 75 wipes, with NIST 800-88 PDF certificates and QR verification included. Start free with 2 wipes, no card required.
Start free trial