By W. Miller, TetraCore
Who needs R2v3 certification
R2v3 is not a legal requirement in the United States. It is a market requirement — and in IT asset disposition it has become close to a baseline one. Four groups typically pursue it:
- ITAD providers whose enterprise, government, and healthcare customers write R2 into contracts and RFPs as a condition of receiving data-bearing equipment.
- Electronics recyclers and refurbishers that sell reuse product and need an audited claim about how equipment was tested and data was handled.
- Brokers that buy and sell used equipment without taking physical possession, covered under their own appendix.
- Downstream vendors of certified facilities. A certified facility must qualify and re-verify every vendor it ships to; being certified yourself makes you an easier vendor to keep.
The core requirements, at a high level
R2v3 is a set of core requirements every certified facility meets, plus process appendices that apply only to facilities performing that activity; the certificate names which appendices are in scope. What follows is an orientation, not the text — the standard itself is the authority, and your certification body's interpretation is the one that counts on audit day.
A documented management system
Written policies and procedures covering the scope of operations, legal and regulatory compliance, and environmental, health and safety controls — with the EH&S side itself certified to a recognized management-system standard. This is the part that looks like any ISO-style certification: defined responsibilities, training records, internal audits, and corrective action.
Tracking and chain of custody
Every unit and every lot of material must be traceable from receipt to final disposition — reuse, downstream recycling, or destruction — with records of each handoff along the way. For data-bearing devices this means serial-level tracking: which device arrived, from whom, where it went inside the facility, what happened to its data, and who received it when it left. This requirement is the backbone the others hang on, because sanitization evidence and downstream records are only meaningful if they attach to an identifiable unit.
Data sanitization (Appendix B)
Facilities that handle data-bearing media must operate a documented sanitization program: secure handling of media before it is sanitized, defined methods for logical (software-based) and physical sanitization, competent and trained operators, a verification and quality-control process that is independent of the operator who did the work, and records per device or per lot showing the method, the result, and who performed it. Failed sanitization has to be handled by a defined path — usually physical destruction — and the record has to show it.
Downstream due diligence (Appendix A)
A certified facility is responsible for what happens to material after it leaves: qualifying each downstream vendor before shipping, verifying that vendors handle material — especially focus materials — responsibly, keeping records of every outbound shipment tied to the vendor that received it, and re-verifying vendors periodically. Nearly every certified US facility holds this appendix.
Focus materials
R2 designates certain components as focus materials because of their environmental or health risk — batteries, mercury-containing devices, CRT glass, and circuit boards are the familiar examples. The facility needs a documented plan for identifying these materials, handling and storing them safely, and routing them only to downstream vendors qualified to process them.
Test and repair for reuse (Appendix C)
Facilities that sell equipment for reuse must test functionality, document the result, and label or describe the product accurately. Four in five US R2v3 facilities hold this appendix — the classic ITAD profile is a facility certified to both sanitize data and process hardware for resale.
The certification process, step by step
- Obtain the standard and gap-assess. Buy the current R2v3 standard and guidance from SERI, decide which appendices your operation actually needs, and compare each requirement against what the facility does today.
- Build the system. Write the procedures, implement tracking, document the sanitization program and its verification, qualify downstream vendors, train staff — then run it long enough to generate real records. Auditors audit evidence, not intentions.
- Choose an accredited certification body. Only bodies accredited under the R2 program can issue certificates. Two registrars audit 88% of certified US facilities (see below), so audit expectations are fairly standardized.
- Stage 1 audit. A documentation and readiness review: does the management system exist on paper, and is the facility ready for a full audit?
- Stage 2 audit. The on-site audit — records, the floor, interviews with operators, and evidence sampled across the certification scope.
- Close findings and receive the certificate. Nonconformities are corrected and the correction verified; the certificate is issued and the facility appears in SERI's public directory.
- Maintain it. Surveillance audits recur every year, full recertification every three years, and the R2 program also provides for unannounced audits — so the only durable strategy is a process that is continuously audit-ready.
What it costs and how long it takes
Cost. Audit fees are set by each certification body and vary with facility size, the appendices in scope, the number of sites, and whether the EH&S certification is bundled. We do not publish a figure because there is not one to publish honestly. The larger, less visible cost is internal: building and documenting the system, training, tracking and sanitization tooling, consultant support if used — and the recurring evidence-assembly work before every surveillance audit.
Timeline. Months, not weeks. The audits take days; the elapsed time is dominated by building the system and operating it long enough to have a body of records — sanitization events, sampling verification, vendor files, shipment records — for the Stage 2 auditor to examine.
The certification landscape by the numbers (2026)
We publish an original analysis of the public SERI R2 directory — The State of R2v3 Certification 2026 — snapshotted August 2026 and free to cite with attribution. The headline figures:
Two of those numbers matter most for a facility planning its own certification. The concentration of certification bodies means the audit experience is well established — what auditors ask to see is not a mystery. And the standard is in a growth phase, with 114 US certificates reaching their expiration date within the next twelve months and a large cohort of newly certified facilities building their evidence processes right now.
R2v3 chain of custody in practice
Strip the requirements down and the operational question is simple: for any unit that has passed through the facility, can you produce its complete story on demand? When it arrived and from whom. Every stage it moved through and who moved it. Its sanitization record — method, result, operator — and the erasure tool's certificate behind it. Whether it landed in a verification sample and who verified it. Which downstream vendor received it, and whether that vendor's certification was current on the ship date. A spreadsheet can record all of that; what it cannot do is enforce it, or prove a cell was not edited later.
How ItemStage supports R2v3 record-keeping
ItemStage's ITAD compliance mode runs the processing floor as a serialized, stage-gated workflow so the custody record is produced by doing the work:
| R2v3 area | What ItemStage provides |
|---|---|
| Tracking throughout | Serialized intake with barcode labels printed on-site; an append-only stage history per unit with server timestamps and the team member who made each transition; media lots for loose drives. |
| Data sanitization (Appendix B) | Append-only sanitization event records (one per attempt, pass or fail); a database-enforced gate that stops a unit leaving the sanitization stage without a passing record; automated random sampling of at least 5% of logically sanitized media each month for independent verification, with the verifier required to differ from the operator; CSV import of erasure-tool certificates matched by serial, with unmatched serials reported. |
| Downstream due diligence (Appendix A) | A vendor register with certification status and approved media scope; outbound shipments blocked to inactive or expired-certification vendors; shipment records tying specific units to the vendor that received them. |
| Test and repair (Appendix C) | Configurable test and repair stages with required checklist answers and photo-evidence gates per stage. |
| Producing the evidence | Per-item or per-job chain-of-custody PDF, CSV export of item records and process answers, and a time-stamped image archive. |
ItemStage does not perform data erasure and is not affiliated with SERI; using it does not itself constitute R2v3 conformance. It is the system of record and enforcement around your erasure tooling and physical processes. For the customer-facing side of sanitization evidence, see our guide to what a data destruction certificate must contain.
Frequently asked questions
What is R2v3 certification?
R2v3 is version 3 of the Responsible Recycling (R2) Standard, published by SERI (Sustainable Electronics Recycling International), for facilities that reuse, refurbish, recycle, or broker used electronics. Certification is issued per facility by independent certification bodies accredited under the R2 program after an audit of the facility's management system, data-sanitization and tracking controls, and downstream vendors. The certificate lists the core standard plus the process appendices the facility is certified to perform.
What are the R2v3 requirements?
At a high level: a documented management system with environmental, health and safety and legal-compliance controls; tracking of every unit or lot from receipt to final disposition (chain of custody); a data-sanitization program with documented procedures, verification, and per-device or per-lot records (Appendix B); due diligence on every downstream vendor that receives material (Appendix A); a plan for focus materials such as batteries, mercury-containing devices, and CRT glass; and, for facilities that resell equipment, documented test-and-repair processes (Appendix C). The standard itself is the authority — buy it from SERI and work from the text with your certification body.
How much does R2v3 certification cost?
Audit fees are set by each accredited certification body and vary with facility size, the appendices in scope, the number of sites, and whether an environmental, health and safety management-system certification is bundled. We do not publish a figure because there is no single one. Budget separately for the internal cost: building and documenting the system, training, tracking and sanitization tooling, and any consultant time.
How long does R2v3 certification take?
Typically months rather than weeks. The audit itself is a small part of the elapsed time; the gating item is usually running the documented system long enough to generate the records an auditor needs to see — sanitization events, sampling verification, vendor files, and shipment records — before the on-site audit is scheduled.
What does R2v3 chain of custody require?
That a facility can account for every data-bearing unit and every lot of material from the moment it is received to its final disposition — reuse, downstream recycling, or destruction — with records of each handoff, the sanitization outcome, and the vendor that received it. The practical test: pick any device shipped last quarter and assemble its complete history. If that takes minutes, the chain of custody is working; if it takes an afternoon of cross-referencing, it is not.