NAID AAA Security Risk Assessment for i-SIGMA Certification Renewal
The independent annual comprehensive Security Risk Analysis your auditor will ask for under Specification 3.2, delivered as an auditor-ready report before your renewal audit date.
Two weeks. $3,500 per location. Conducted remotely, so nothing stops.

Why This Landed On Your Desk This Year
i-SIGMA published a new edition of the Certification Specifications Reference Manual, version 1026O, described on its own renewal page as the Specs Manual with Cyber Hygiene. It takes effect 1 October 2026 and it changes what your auditor asks for.
Your renewal application asks for a document that did not exist last year
i-SIGMA rewrote Specification 3.2 in the 1026O Cyber Hygiene edition of the Certification Specifications Reference Manual. From 1 October 2026 it reads "Applicant is required to obtain an annual comprehensive Security Risk Analysis" and lists six controls you must evidence. If you renewed last year against the 0925M manual, this is new.
Spec 3.2 is a Level 3 specification, the most severe tier i-SIGMA uses
Under the Terms and Conditions, a first instance of a specific Level 3 specification found non-compliant draws a $1,000 fine, with escalation on repeat findings. This is not a documentation nicety. It sits alongside your quality control monitoring of the destruction process itself.
Your IT provider cannot sign it off credibly
The specification requires the review to be performed by a competent third-party security expert. Self-assessment does not satisfy it, and an MSP assessing the network it built and manages is marking its own homework. The auditor is looking for documented evidence of a passed independent review.


What Specification 3.2 Actually Requires
The audit methodology that follows it tells your auditor exactly what to look for: documented evidence that your network or networks have successfully achieved an acceptable security review by a competent third-party security expert.
Read that carefully, because two words in it decide whether your evidence passes. Successfully means the report has to evidence a pass, not merely prove that an assessment happened. Third-party means it cannot be you, and realistically should not be the provider who built the network being assessed.

Does It Actually Apply To You?
This is the question most write-ups get wrong, so here is the precise answer. In the 1026O applicability table, the entries for overwriting and degaussing of electronic media were amended to add Spec 3.2, alongside 7.4 and 7.5. Specs 4.6 and 4.7 carry an explicit note saying the same. Physical destruction endorsements were not changed.
Hard drive and SSD overwriting
NAID AAA operations holding an overwriting endorsement, facility-based or mobile. Spec 3.2 now applies to you.
Magnetic media degaussing
NAID AAA operations holding a degaussing endorsement. Spec 4.7 now carries an explicit note that conformance with 3.2, 7.4 and 7.5 is also required.
PRISM Privacy+ operations
Section 3 has always applied to PRISM Privacy+ certified operations. If you hold both certifications, you are in scope through this route regardless of erasure platform.
Paper and physical destruction only
If you hold only physical destruction endorsements and no electronic media erasure platform, Spec 3.2 is not triggered. New Spec 1.29 on cybersecurity policy and training does still apply to you.


The Independence Problem
i-SIGMA supplies its members with a great deal: policy templates, confidentiality agreements, breach notification forms, a standard business associate agreement. What it structurally cannot supply is the one thing Specification 3.2 demands, because an association cannot be the independent third party that verifies its own members.
The obvious fallback is your existing IT provider, and on a plain reading of the wording they may qualify. The difficulty is evidential rather than technical. If your auditor asks who performed the review and the answer is the company that designed, installed and manages the network, you are relying on a self-assessment wearing a third-party label. Most operators would rather not discover the auditor's view of that on audit day.
We have no role in your infrastructure, nothing to sell you afterwards, and no reason to grade generously.
Compared With The Alternatives
| Atlant Security | MSP or generic assessor | |
|---|---|---|
| Independence | No involvement in building or running your network, so the third-party requirement is genuinely met | Your MSP assessing infrastructure it designed, installed and maintains |
| Specification mapping | Report structured clause by clause against i-SIGMA Spec 3.2, 7.4 and 7.5 | A generic HIPAA or cyber risk report the auditor has to interpret |
| Industry knowledge | Built specifically for NAID AAA and PRISM Privacy+ operators and their audit cycle | No knowledge of i-SIGMA, the manual version, or what a Level 3 finding costs |
| Deliverable | Documented evidence of a passed review, which is the exact audit methodology wording | A scan report or a findings list that does not evidence a pass |
| Pricing | Published and fixed, per location, agreed before we start | Hourly, scoped after the fact, or bundled into an IT retainer |
| Who performs it | A former Microsoft Security Consulting team member, CISSP, personally | A technician running a template |
How It Runs: 5 Steps, 2 Weeks
Scope your certified locations and platforms
We confirm which of your locations and endorsements actually trigger Spec 3.2, because each location is certified, audited and renewed separately. You get a written scope and a fixed price before anything starts.
Remote technical review
Identity and access configuration, MFA coverage, privilege model, firewall ruleset, endpoint and EDR coverage, and patch process. Conducted remotely against your administrative network, with no disruption to routes or destruction operations.
Evidence collection mapped to the specification
Every one of the six required control areas is evidenced individually, in the order the specification lists them, so your auditor can tick them off without interpretation.
Auditor-ready report
A written Security Risk Analysis evidencing a passed review, which is what the audit methodology actually asks for. Not a scan output, not a raw vulnerability list.
Gap remediation, if needed
If something fails, you get a prioritised fix list with the specification clause it maps to, and time to close it before your audit date rather than a finding on the day.


Pricing
Nobody in this niche publishes prices, so we will. You already carry an annual i-SIGMA certification fee, and this sits alongside it as a predictable line item rather than an open-ended IT project. Priced per certified location, because i-SIGMA certifies, audits and renews each location separately.
Annual Security Risk Analysis
Exactly what Specification 3.2 asks for, structured so your auditor can tick it off.
- Remote technical review of your network
- All six required control areas evidenced individually
- Auditor-ready report evidencing a passed review
- Clause-by-clause mapping to Spec 3.2
- Prioritised gap list if anything falls short
- Re-issued each renewal cycle
You review the report before you pay.
Certification Readiness
For operators who would rather fix the whole cyber hygiene section once, properly.
- Everything in the Annual Security Risk Analysis
- Spec 1.29 cybersecurity policy and training pack
- Access Individual acknowledgement documentation
- Spec 7.4 and 7.5 access control and IAM write-up
- Written incident response plan
- Audit-day support if the auditor has questions
You review the report before you pay.
Multi-location operators get volume pricing per site, agreed in writing before we begin. If your renewal audit is imminent, say so on the call and we will tell you honestly whether the timeline works.
Get It Done Before The Auditor Asks
One call to confirm which of your locations and endorsements are actually in scope, a fixed price the same day, and an auditor-ready report two weeks later. No site visit, no disruption to routes.
Book Your Free Renewal CallSchedule Your Free Renewal Call
NAID AAA Security Risk Assessment FAQ
Does the annual Security Risk Analysis apply to every NAID AAA certified company?
What exactly does the specification say?
Can our IT company or MSP do this instead?
What happens if we cannot produce it at audit?
How much does it cost?
How long does it take?
Do you need to visit our facility?
What else changed in the 1026O manual?
We hold both NAID AAA and PRISM Privacy+. Does anything differ?
Is this the same as the HIPAA risk analysis?
Built For This Industry, Not Adapted To It
There are more than 950 i-SIGMA NAID AAA certified locations operating on five continents, each certified, audited and renewed separately. They physically destroy data for a living, and almost none of them carry an internal information security function, because there is no reason they should.
That is precisely the gap Specification 3.2 opens up. It asks a shredding, records management or ITAD operator to produce a network security assessment signed by someone competent and independent, on an annual cycle, with a Level 3 penalty attached.
Every engagement is delivered personally by a former Microsoft Security Consulting team member with 200+ security assessments across 14 countries since 2013. Never juniors, never a template with your logo on it.
