i-SIGMA Specification 3.2 / Effective 1 October 2026

NAID AAA Security Risk Assessment for i-SIGMA Certification Renewal

The independent annual comprehensive Security Risk Analysis your auditor will ask for under Specification 3.2, delivered as an auditor-ready report before your renewal audit date.

Two weeks. $3,500 per location. Conducted remotely, so nothing stops.

Genuinely independentMapped to the specificationYou review before you pay
NAID AAA Security Risk Analysis for i-SIGMA Specification 3.2 certification renewal by Atlant Security

Why This Landed On Your Desk This Year

i-SIGMA published a new edition of the Certification Specifications Reference Manual, version 1026O, described on its own renewal page as the Specs Manual with Cyber Hygiene. It takes effect 1 October 2026 and it changes what your auditor asks for.

Your renewal application asks for a document that did not exist last year

i-SIGMA rewrote Specification 3.2 in the 1026O Cyber Hygiene edition of the Certification Specifications Reference Manual. From 1 October 2026 it reads "Applicant is required to obtain an annual comprehensive Security Risk Analysis" and lists six controls you must evidence. If you renewed last year against the 0925M manual, this is new.

Spec 3.2 is a Level 3 specification, the most severe tier i-SIGMA uses

Under the Terms and Conditions, a first instance of a specific Level 3 specification found non-compliant draws a $1,000 fine, with escalation on repeat findings. This is not a documentation nicety. It sits alongside your quality control monitoring of the destruction process itself.

Your IT provider cannot sign it off credibly

The specification requires the review to be performed by a competent third-party security expert. Self-assessment does not satisfy it, and an MSP assessing the network it built and manages is marking its own homework. The auditor is looking for documented evidence of a passed independent review.

The annual comprehensive Security Risk Analysis becomes mandatory on 1 October 2026 under i-SIGMA manual 1026O
i-SIGMA Specification 3.2 is a Level 3 specification carrying a 1000 dollar fine for a first non-compliance

What Specification 3.2 Actually Requires

Manual 1026O, Spec 3.2, Level 3
Third-Party Network Security Verification. Applicant is required to obtain an annual comprehensive Security Risk Analysis. The analysis should include evidence of the following: enforcement of least-privilege principles, multi-factor authentication, antivirus software, firewall, endpoint detection tools across all devices, patch management.

The audit methodology that follows it tells your auditor exactly what to look for: documented evidence that your network or networks have successfully achieved an acceptable security review by a competent third-party security expert.

Read that carefully, because two words in it decide whether your evidence passes. Successfully means the report has to evidence a pass, not merely prove that an assessment happened. Third-party means it cannot be you, and realistically should not be the provider who built the network being assessed.

The six controls i-SIGMA Specification 3.2 requires evidence of: least privilege, MFA, antivirus, firewall, endpoint detection, patch management
Least privilege
Enforcement of least-privilege principles across accounts and systems
Multi-factor authentication
MFA on the accounts that matter, evidenced rather than asserted
Antivirus
Deployed, current, and actually reporting across the estate
Firewall
Boundary protection with a reviewed, documented ruleset
Endpoint detection
EDR tooling across all devices, including the ones nobody remembered
Patch management
A process that works on trucks and laptops, not just servers

Does It Actually Apply To You?

This is the question most write-ups get wrong, so here is the precise answer. In the 1026O applicability table, the entries for overwriting and degaussing of electronic media were amended to add Spec 3.2, alongside 7.4 and 7.5. Specs 4.6 and 4.7 carry an explicit note saying the same. Physical destruction endorsements were not changed.

In scope for Spec 3.2

Hard drive and SSD overwriting

NAID AAA operations holding an overwriting endorsement, facility-based or mobile. Spec 3.2 now applies to you.

In scope for Spec 3.2

Magnetic media degaussing

NAID AAA operations holding a degaussing endorsement. Spec 4.7 now carries an explicit note that conformance with 3.2, 7.4 and 7.5 is also required.

In scope for Spec 3.2

PRISM Privacy+ operations

Section 3 has always applied to PRISM Privacy+ certified operations. If you hold both certifications, you are in scope through this route regardless of erasure platform.

Not triggered by 3.2

Paper and physical destruction only

If you hold only physical destruction endorsements and no electronic media erasure platform, Spec 3.2 is not triggered. New Spec 1.29 on cybersecurity policy and training does still apply to you.

Which NAID AAA and PRISM Privacy+ operations the annual Security Risk Analysis requirement binds
Why an MSP cannot credibly sign off the i-SIGMA Spec 3.2 third-party network security verification

The Independence Problem

i-SIGMA supplies its members with a great deal: policy templates, confidentiality agreements, breach notification forms, a standard business associate agreement. What it structurally cannot supply is the one thing Specification 3.2 demands, because an association cannot be the independent third party that verifies its own members.

The obvious fallback is your existing IT provider, and on a plain reading of the wording they may qualify. The difficulty is evidential rather than technical. If your auditor asks who performed the review and the answer is the company that designed, installed and manages the network, you are relying on a self-assessment wearing a third-party label. Most operators would rather not discover the auditor's view of that on audit day.

We have no role in your infrastructure, nothing to sell you afterwards, and no reason to grade generously.

Compared With The Alternatives

Atlant SecurityMSP or generic assessor
IndependenceNo involvement in building or running your network, so the third-party requirement is genuinely metYour MSP assessing infrastructure it designed, installed and maintains
Specification mappingReport structured clause by clause against i-SIGMA Spec 3.2, 7.4 and 7.5A generic HIPAA or cyber risk report the auditor has to interpret
Industry knowledgeBuilt specifically for NAID AAA and PRISM Privacy+ operators and their audit cycleNo knowledge of i-SIGMA, the manual version, or what a Level 3 finding costs
DeliverableDocumented evidence of a passed review, which is the exact audit methodology wordingA scan report or a findings list that does not evidence a pass
PricingPublished and fixed, per location, agreed before we startHourly, scoped after the fact, or bundled into an IT retainer
Who performs itA former Microsoft Security Consulting team member, CISSP, personallyA technician running a template

How It Runs: 5 Steps, 2 Weeks

1

Scope your certified locations and platforms

We confirm which of your locations and endorsements actually trigger Spec 3.2, because each location is certified, audited and renewed separately. You get a written scope and a fixed price before anything starts.

2

Remote technical review

Identity and access configuration, MFA coverage, privilege model, firewall ruleset, endpoint and EDR coverage, and patch process. Conducted remotely against your administrative network, with no disruption to routes or destruction operations.

3

Evidence collection mapped to the specification

Every one of the six required control areas is evidenced individually, in the order the specification lists them, so your auditor can tick them off without interpretation.

4

Auditor-ready report

A written Security Risk Analysis evidencing a passed review, which is what the audit methodology actually asks for. Not a scan output, not a raw vulnerability list.

5

Gap remediation, if needed

If something fails, you get a prioritised fix list with the specification clause it maps to, and time to close it before your audit date rather than a finding on the day.

The five step NAID AAA Security Risk Analysis process from scoping to gap remediation
What you receive: auditor-ready Security Risk Analysis report mapped to i-SIGMA Spec 3.2 with gap remediation plan

Pricing

Nobody in this niche publishes prices, so we will. You already carry an annual i-SIGMA certification fee, and this sits alongside it as a predictable line item rather than an open-ended IT project. Priced per certified location, because i-SIGMA certifies, audits and renews each location separately.

Spec 3.2 deliverable

Annual Security Risk Analysis

Exactly what Specification 3.2 asks for, structured so your auditor can tick it off.

$3,500per location, per year
  • Remote technical review of your network
  • All six required control areas evidenced individually
  • Auditor-ready report evidencing a passed review
  • Clause-by-clause mapping to Spec 3.2
  • Prioritised gap list if anything falls short
  • Re-issued each renewal cycle
Book Free Renewal Call

You review the report before you pay.

Certification Readiness

For operators who would rather fix the whole cyber hygiene section once, properly.

$6,500first location
  • Everything in the Annual Security Risk Analysis
  • Spec 1.29 cybersecurity policy and training pack
  • Access Individual acknowledgement documentation
  • Spec 7.4 and 7.5 access control and IAM write-up
  • Written incident response plan
  • Audit-day support if the auditor has questions
Book Free Renewal Call

You review the report before you pay.

Multi-location operators get volume pricing per site, agreed in writing before we begin. If your renewal audit is imminent, say so on the call and we will tell you honestly whether the timeline works.

Get It Done Before The Auditor Asks

One call to confirm which of your locations and endorsements are actually in scope, a fixed price the same day, and an auditor-ready report two weeks later. No site visit, no disruption to routes.

Book Your Free Renewal Call

Schedule Your Free Renewal Call

NAID AAA Security Risk Assessment FAQ

Does the annual Security Risk Analysis apply to every NAID AAA certified company?
No, and this is the most misreported point in the industry. In the manual currently in force, version 0925M, Specification 3.2 sits in Section 3, which applies to PRISM Privacy+ certified operations. In the 1026O Cyber Hygiene edition effective 1 October 2026, the applicability table was amended so that 3.2 also reaches NAID AAA operations holding an electronic media erasure platform, meaning hard drive or SSD overwriting or magnetic media degaussing, whether facility-based or mobile. A company holding only physical destruction endorsements is not brought into 3.2 by that change. If your renewal correspondence is asking for the analysis, you almost certainly hold an erasure endorsement, a PRISM Privacy+ certification, or both.
What exactly does the specification say?
In the 1026O manual, Specification 3.2 Third-Party Network Security Verification is a Level 3 specification reading: "Applicant is required to obtain an annual comprehensive Security Risk Analysis." It then lists the evidence required: enforcement of least-privilege principles, multi-factor authentication, antivirus software, firewall, endpoint detection tools across all devices, and patch management. The audit methodology directs the auditor to verify documented evidence that the applicant network or networks have successfully achieved an acceptable security review by a competent third-party security expert.
Can our IT company or MSP do this instead?
The wording requires a competent third-party security expert. A managed services provider is a third party in the contractual sense, and the previous 0925M wording explicitly allowed "a competent third-party managed services provider or computer security expert." The practical problem is independence: an MSP assessing the network it built, configured and maintains is assessing its own work, which weakens the evidence considerably if an auditor probes it. It is also unlikely to structure the report against i-SIGMA specification numbers, which is what makes an audit go quickly.
What happens if we cannot produce it at audit?
Specification 3.2 is marked Level 3, the most severe non-conformity tier in the manual. Under the i-SIGMA Terms and Conditions, a first instance of a specific Level 3 specification found non-compliant carries a $1,000 fine, with escalation for repeat instances. Beyond the fine, certification is what gives you access to healthcare, financial and legal clients who require it contractually, so a lapse has commercial consequences well beyond the penalty.
How much does it cost?
The annual Security Risk Analysis is $3,500 per certified location, fixed. The Certification Readiness package, which adds the Spec 1.29 cybersecurity policy and training pack, Spec 7.4 and 7.5 access control documentation, an incident response plan and audit-day support, is $6,500 for the first location. Multi-location operators get volume pricing per site, because i-SIGMA certifies, audits and renews each location separately and so do we. You review the report before you pay.
How long does it take?
Two weeks from kickoff to auditor-ready report for a single location, assuming reasonable responsiveness on access and evidence. If your audit date is closer than that, tell us on the call and we will say honestly whether we can meet it rather than take the work and miss.
Do you need to visit our facility?
No. Specification 3.2 is about your online computer network, not your plant, vehicles or destruction equipment. Those are covered by entirely separate specifications and audited separately. The analysis is conducted remotely, which is why it can be delivered quickly and priced flat.
What else changed in the 1026O manual?
The other change that affects every certified operator is new Specification 1.29, a Level 1 requirement for documented cybersecurity policies and procedures covering acceptable use, password management and incident response, plus documented confirmation from each Access Individual that they understand and agree to them. Specification 2.1 on access control was also expanded to require measures preventing unauthorised physical access to servers, storage devices and network equipment. Unlike 3.2, these apply regardless of which endorsements you hold.
We hold both NAID AAA and PRISM Privacy+. Does anything differ?
Section 3 applies to PRISM Privacy+ operations in both manual versions, so if you hold Privacy+ you were already in scope for 3.2 before the October change. Holding both certifications does not mean two analyses: one properly scoped assessment covering your network can evidence the requirement for both, provided the report is structured to show it.
Is this the same as the HIPAA risk analysis?
Related but not identical, and the direction of the relationship is often reversed in write-ups. i-SIGMA markets that NAID AAA certification qualifies as the service provider risk assessment a covered entity or business associate must perform on its vendors. That is about your customers discharging their duty by hiring you. Specification 3.2 is the separate obligation running the other way, on your own network. If you are a business associate in your own right, one engagement can be scoped to serve both, and we will tell you when that makes sense.

Built For This Industry, Not Adapted To It

There are more than 950 i-SIGMA NAID AAA certified locations operating on five continents, each certified, audited and renewed separately. They physically destroy data for a living, and almost none of them carry an internal information security function, because there is no reason they should.

That is precisely the gap Specification 3.2 opens up. It asks a shredding, records management or ITAD operator to produce a network security assessment signed by someone competent and independent, on an annual cycle, with a Level 3 penalty attached.

Every engagement is delivered personally by a former Microsoft Security Consulting team member with 200+ security assessments across 14 countries since 2013. Never juniors, never a template with your logo on it.

More than 950 i-SIGMA NAID AAA certified locations operate worldwide, each certified and renewed separately

Related Services