i-SIGMA Specification 3.2 / Effective 1 October 2026

Hand Your i-SIGMA Auditor Exactly What Spec 3.2 Demands.

The independent annual comprehensive Security Risk Analysis your auditor will ask for under Specification 3.2, delivered as an auditor-ready report before your renewal audit date.

Two weeks. $3,500 per location. Conducted remotely, so nothing stops.

Genuinely independentMapped to the specificationYou review before you pay
NAID AAA Security Risk Analysis for i-SIGMA Specification 3.2 certification renewal by Atlant Security
Alexander Sverdlov, founder of Atlant Security
Alexander SverdlovFounder, Atlant SecurityCISSP, CEH, CHFI, Mandiant

Runs the NAID AAA risk assessment and prepares you for the Spec 3.2 change.

Connect on LinkedIn

Why This Landed On Your Desk This Year

i-SIGMA published a new edition of the Certification Specifications Reference Manual, version 1026O, described on its own renewal page as the Specs Manual with Cyber Hygiene. It takes effect 1 October 2026 and it changes what your auditor asks for.

Your renewal application asks for a document that did not exist last year

i-SIGMA rewrote Specification 3.2 in the 1026O Cyber Hygiene edition of the Certification Specifications Reference Manual. From 1 October 2026 it reads "Applicant is required to obtain an annual comprehensive Security Risk Analysis" and lists six controls you must evidence. If you renewed last year against the 0925M manual, this is new.

Spec 3.2 is a Level 3 specification, the most severe tier i-SIGMA uses

Under the Terms and Conditions, a first instance of a specific Level 3 specification found non-compliant draws a $1,000 fine, with escalation on repeat findings. This is not a documentation nicety. It sits alongside your quality control monitoring of the destruction process itself.

Your IT provider cannot sign it off credibly

The specification requires the review to be performed by a competent third-party security expert. Self-assessment does not satisfy it, and an MSP assessing the network it built and manages is marking its own homework. The auditor is looking for documented evidence of a passed independent review.

i-SIGMA Specification 3.2Version 1026OSpec rewrittenThe Cyber Hygiene editionof the manualNowPreparation windowAssessments booked aheadof renewal1 Oct 2026Requirement effectiveAnnual Security RiskAnalysis requiredEach renewalRepeat annuallyRe-issued per certifiedlocation
The requirement binds erasure-platform operations and all PRISM Privacy+ certified operations.
Level 3The most severe non-conformity tier, with a$1,000 first-instance fineUnder the i-SIGMA Terms and Conditions, with escalation for repeatinstances, on top of the commercial risk to a certification your regulatedclients require.
Specification 3.2 is a Level 3 specification, so it is not a finding you can carry.

What Specification 3.2 Actually Requires

Manual 1026O, Spec 3.2, Level 3
Third-Party Network Security Verification. Applicant is required to obtain an annual comprehensive Security Risk Analysis. The analysis should include evidence of the following: enforcement of least-privilege principles, multi-factor authentication, antivirus software, firewall, endpoint detection tools across all devices, patch management.

The audit methodology that follows it tells your auditor exactly what to look for: documented evidence that your network or networks have successfully achieved an acceptable security review by a competent third-party security expert.

Read that carefully, because two words in it decide whether your evidence passes. Successfully means the report has to evidence a pass, not merely prove that an assessment happened. Third-party means it cannot be you, and realistically should not be the provider who built the network being assessed.

The six control areas Spec 3.2 namesEach must be evidenced individually, not assertedLeast privilegeEnforced access rights, reviewed anddocumentedMulti-factor authenticationAcross the systems that matterAntivirusDeployed and current across all devicesFirewallConfigured, maintained, evidencedEndpoint detectionAcross all devices, not a subsetPatch managementA cadence you can show, not a promise
The audit methodology requires documented evidence of a successfully passed review by a competent third-party security expert.
Least privilege
Enforcement of least-privilege principles across accounts and systems
Multi-factor authentication
MFA on the accounts that matter, evidenced rather than asserted
Antivirus
Deployed, current, and actually reporting across the estate
Firewall
Boundary protection with a reviewed, documented ruleset
Endpoint detection
EDR tooling across all devices, including the ones nobody remembered
Patch management
A process that works on trucks and laptops, not just servers

Does It Actually Apply To You?

This is the question most write-ups get wrong, so here is the precise answer. In the 1026O applicability table, the entries for overwriting and degaussing of electronic media were amended to add Spec 3.2, alongside 7.4 and 7.5. Specs 4.6 and 4.7 carry an explicit note saying the same. Physical destruction endorsements were not changed.

In scope for Spec 3.2

Hard drive and SSD overwriting

NAID AAA operations holding an overwriting endorsement, facility-based or mobile. Spec 3.2 now applies to you.

In scope for Spec 3.2

Magnetic media degaussing

NAID AAA operations holding a degaussing endorsement. Spec 4.7 now carries an explicit note that conformance with 3.2, 7.4 and 7.5 is also required.

In scope for Spec 3.2

PRISM Privacy+ operations

Section 3 has always applied to PRISM Privacy+ certified operations. If you hold both certifications, you are in scope through this route regardless of erasure platform.

Not triggered by 3.2

Paper and physical destruction only

If you hold only physical destruction endorsements and no electronic media erasure platform, Spec 3.2 is not triggered. New Spec 1.29 on cybersecurity policy and training does still apply to you.

Who the requirement bindsOPERATION TYPESPEC 3.2 APPLIES?NAID AAA with an erasure platformYes: hard drive or SSD overwriting, or degaussing,facility-based or mobilePRISM Privacy+ certifiedYes, all such operationsPhysical destruction endorsements onlyNot brought into 3.2, but Spec 1.29 on policy and trainingapplies
Spec 1.29 on cybersecurity policy and training applies to everyone, regardless of endorsement.
Why your IT provider cannot sign itA competent third-party expertNo role in designing or running your networkNothing to sell you afterwardsA report structured clause by clause against 3.2Evidence of a review that was passed, not attemptedWhat an auditor will probeAn MSP assessing the network it managesAn internal self-assessmentA generic scan report with no clause mappingA vendor recommending its own products as the fix
An independent assessor with no role in your infrastructure removes the objection entirely.

The Independence Problem

i-SIGMA supplies its members with a great deal: policy templates, confidentiality agreements, breach notification forms, a standard business associate agreement. What it structurally cannot supply is the one thing Specification 3.2 demands, because an association cannot be the independent third party that verifies its own members.

The obvious fallback is your existing IT provider, and on a plain reading of the wording they may qualify. The difficulty is evidential rather than technical. If your auditor asks who performed the review and the answer is the company that designed, installed and manages the network, you are relying on a self-assessment wearing a third-party label. Most operators would rather not discover the auditor's view of that on audit day.

We have no role in your infrastructure, nothing to sell you afterwards, and no reason to grade generously.

Compared With The Alternatives

Atlant SecurityMSP or generic assessor
IndependenceNo involvement in building or running your network, so the third-party requirement is genuinely metYour MSP assessing infrastructure it designed, installed and maintains
Specification mappingReport structured clause by clause against i-SIGMA Spec 3.2, 7.4 and 7.5A generic HIPAA or cyber risk report the auditor has to interpret
Industry knowledgeBuilt specifically for NAID AAA and PRISM Privacy+ operators and their audit cycleNo knowledge of i-SIGMA, the manual version, or what a Level 3 finding costs
DeliverableDocumented evidence of a passed review, which is the exact audit methodology wordingA scan report or a findings list that does not evidence a pass
PricingPublished and fixed, per location, agreed before we startHourly, scoped after the fact, or bundled into an IT retainer
Who performs itA former Microsoft Security Consulting team member, CISSP, personallyA technician running a template

How It Runs: 5 Steps, 2 Weeks

1

Scope your certified locations and platforms

We confirm which of your locations and endorsements actually trigger Spec 3.2, because each location is certified, audited and renewed separately. You get a written scope and a fixed price before anything starts.

2

Remote technical review

Identity and access configuration, MFA coverage, privilege model, firewall ruleset, endpoint and EDR coverage, and patch process. Conducted remotely against your administrative network, with no disruption to routes or destruction operations.

3

Evidence collection mapped to the specification

Every one of the six required control areas is evidenced individually, in the order the specification lists them, so your auditor can tick them off without interpretation.

4

Auditor-ready report

A written Security Risk Analysis evidencing a passed review, which is what the audit methodology actually asks for. Not a scan output, not a raw vulnerability list.

5

Gap remediation, if needed

If something fails, you get a prioritised fix list with the specification clause it maps to, and time to close it before your audit date rather than a finding on the day.

How the assessment runs1ScopeCertified locations, erasureplatforms, systems in scope2Remote technicalreviewAll six control areasevidenced individually in yourenvironment3ReportClause-by-clause mapping toSpecification 3.2,auditor-ready4Gap closurePrioritised list whereanything falls short, retestedbefore renewal
Two weeks, delivered remotely, with no site visit required.
What the auditor receivesRisk analysis reportEvidencing a passed third-party reviewClause mappingEvery point of Specification 3.2 addressedSix control evidenceEach area shown separatelyGap listPrioritised, with owners and datesSpec 1.29 packPolicy and training, in the readiness optionAccess control write-upSpec 7.4 and 7.5, in the readiness option
Priced per certified location and re-issued each renewal year.

Pricing

Nobody in this niche publishes prices, so we will. You already carry an annual i-SIGMA certification fee, and this sits alongside it as a predictable line item rather than an open-ended IT project. Priced per certified location, because i-SIGMA certifies, audits and renews each location separately.

Spec 3.2 deliverable

Annual Security Risk Analysis

Exactly what Specification 3.2 asks for, structured so your auditor can tick it off.

From $3,500per location, per year
  • Remote technical review of your network
  • All six required control areas evidenced individually
  • Auditor-ready report evidencing a passed review
  • Clause-by-clause mapping to Spec 3.2
  • Prioritised gap list if anything falls short
  • Re-issued each renewal cycle
Get Your Renewal Plan

You review the report before you pay.

Certification Readiness

For operators who would rather fix the whole cyber hygiene section once, properly.

From $6,500first location
  • Everything in the Annual Security Risk Analysis
  • Spec 1.29 cybersecurity policy and training pack
  • Access Individual acknowledgement documentation
  • Spec 7.4 and 7.5 access control and IAM write-up
  • Written incident response plan
  • Audit-day support if the auditor has questions
Get Your Renewal Plan

You review the report before you pay.

Multi-location operators get volume pricing per site, agreed in writing before we begin. If your renewal audit is imminent, say so on the call and we will tell you honestly whether the timeline works.

Get It Done Before The Auditor Asks

One call to confirm which of your locations and endorsements are actually in scope, a fixed price the same day, and an auditor-ready report two weeks later. No site visit, no disruption to routes.

Get Your Renewal Plan

Get Your Renewal Plan

NAID AAA Security Risk Assessment FAQ

Does the annual Security Risk Analysis apply to every NAID AAA certified company?
No, and this is the most misreported point in the industry. In the manual currently in force, version 0925M, Specification 3.2 sits in Section 3, which applies to PRISM Privacy+ certified operations. In the 1026O Cyber Hygiene edition effective 1 October 2026, the applicability table was amended so that 3.2 also reaches NAID AAA operations holding an electronic media erasure platform, meaning hard drive or SSD overwriting or magnetic media degaussing, whether facility-based or mobile. A company holding only physical destruction endorsements is not brought into 3.2 by that change. If your renewal correspondence is asking for the analysis, you almost certainly hold an erasure endorsement, a PRISM Privacy+ certification, or both.
What exactly does the specification say?
In the 1026O manual, Specification 3.2 Third-Party Network Security Verification is a Level 3 specification reading: "Applicant is required to obtain an annual comprehensive Security Risk Analysis." It then lists the evidence required: enforcement of least-privilege principles, multi-factor authentication, antivirus software, firewall, endpoint detection tools across all devices, and patch management. The audit methodology directs the auditor to verify documented evidence that the applicant network or networks have successfully achieved an acceptable security review by a competent third-party security expert.
Can our IT company or MSP do this instead?
The wording requires a competent third-party security expert. A managed services provider is a third party in the contractual sense, and the previous 0925M wording explicitly allowed "a competent third-party managed services provider or computer security expert." The practical problem is independence: an MSP assessing the network it built, configured and maintains is assessing its own work, which weakens the evidence considerably if an auditor probes it. It is also unlikely to structure the report against i-SIGMA specification numbers, which is what makes an audit go quickly.
What happens if we cannot produce it at audit?
Specification 3.2 is marked Level 3, the most severe non-conformity tier in the manual. Under the i-SIGMA Terms and Conditions, a first instance of a specific Level 3 specification found non-compliant carries a $1,000 fine, with escalation for repeat instances. Beyond the fine, certification is what gives you access to healthcare, financial and legal clients who require it contractually, so a lapse has commercial consequences well beyond the penalty.
How much does it cost?
The annual Security Risk Analysis is $3,500 per certified location, fixed. The Certification Readiness package, which adds the Spec 1.29 cybersecurity policy and training pack, Spec 7.4 and 7.5 access control documentation, an incident response plan and audit-day support, is $6,500 for the first location. Multi-location operators get volume pricing per site, because i-SIGMA certifies, audits and renews each location separately and so do we. You review the report before you pay.
How long does it take?
Two weeks from kickoff to auditor-ready report for a single location, assuming reasonable responsiveness on access and evidence. If your audit date is closer than that, tell us on the call and we will say honestly whether we can meet it rather than take the work and miss.
Do you need to visit our facility?
No. Specification 3.2 is about your online computer network, not your plant, vehicles or destruction equipment. Those are covered by entirely separate specifications and audited separately. The analysis is conducted remotely, which is why it can be delivered quickly and priced flat.
What else changed in the 1026O manual?
The other change that affects every certified operator is new Specification 1.29, a Level 1 requirement for documented cybersecurity policies and procedures covering acceptable use, password management and incident response, plus documented confirmation from each Access Individual that they understand and agree to them. Specification 2.1 on access control was also expanded to require measures preventing unauthorised physical access to servers, storage devices and network equipment. Unlike 3.2, these apply regardless of which endorsements you hold.
We hold both NAID AAA and PRISM Privacy+. Does anything differ?
Section 3 applies to PRISM Privacy+ operations in both manual versions, so if you hold Privacy+ you were already in scope for 3.2 before the October change. Holding both certifications does not mean two analyses: one properly scoped assessment covering your network can evidence the requirement for both, provided the report is structured to show it.
Is this the same as the HIPAA risk analysis?
Related but not identical, and the direction of the relationship is often reversed in write-ups. i-SIGMA markets that NAID AAA certification qualifies as the service provider risk assessment a covered entity or business associate must perform on its vendors. That is about your customers discharging their duty by hiring you. Specification 3.2 is the separate obligation running the other way, on your own network. If you are a business associate in your own right, one engagement can be scoped to serve both, and we will tell you when that makes sense.

Built For This Industry, Not Adapted To It

There are more than 950 i-SIGMA NAID AAA certified locations operating on five continents, each certified, audited and renewed separately. They physically destroy data for a living, and almost none of them carry an internal information security function, because there is no reason they should.

That is precisely the gap Specification 3.2 opens up. It asks a shredding, records management or ITAD operator to produce a network security assessment signed by someone competent and independent, on an annual cycle, with a Level 3 penalty attached.

Every engagement is delivered personally by a former Microsoft Security Consulting team member with 200+ security assessments across 14 countries since 2013. Never juniors, never a template with your logo on it.

Where this sits in your certificationNAID AAA certificationThe certification your regulated clients requireCyber hygiene sectionSpec 1.29 policy and training, Spec 7.4 and 7.5 access controlSpecification 3.2The annual Security Risk Analysis by a third-party expertSelf-assessment does not satisfy Specification 3.2.
The Certification Readiness option fixes the whole cyber hygiene section once, properly.

Related Services