Understanding ADISA in the Data Destruction Industry

When evaluating data destruction providers, you’ll encounter various certifications and accreditations. One that carries particular weight in the IT asset disposal industry is ADISA, the Asset Disposal and Information Security Alliance. ADISA certification provides independent verification that a data destruction provider’s processes actually work, tested through forensic analysis rather than just paperwork review.

For Australian organisations choosing a data destruction or ITAD provider, understanding what ADISA certification means helps you distinguish between providers that genuinely deliver secure data destruction and those that simply claim to.

What Is ADISA?

ADISA is an independent, industry-led certification body that audits and tests IT asset disposal companies against rigorous information security standards. Founded in the UK, ADISA has become internationally recognised as one of the most credible certifications in the data destruction space.

What sets ADISA apart from many other certifications is its approach to testing. Rather than relying solely on policy review and process documentation (which tells you what a provider says they do), ADISA incorporates forensic testing of actual output. This means ADISA auditors take samples of media that have been through the provider’s destruction process and attempt to recover data from them. If data is recoverable, the certification isn’t granted.

This forensic verification element is critical. It bridges the gap between documented procedures and real-world performance, giving customers confidence that the destruction process actually works in practice.

ADISA Test Levels

ADISA certification is structured around different test levels that correspond to the type of media being processed:

Test Level 1 – Magnetic media (HDDs): Covers the destruction and sanitisation of traditional hard disk drives. Testing verifies that data has been rendered unrecoverable through the provider’s process, whether that’s software wiping, degaussing, shredding, or a combination.

Test Level 2 – Solid state media (SSDs, flash storage): Covers solid state drives and flash-based storage, which require different destruction approaches than magnetic media due to their architecture (wear levelling, over-provisioning, and other SSD-specific challenges that complicate data erasure).

Test Level 3 – Mobile devices: Covers smartphones, tablets, and other mobile devices, which present unique challenges due to embedded storage, encryption, and manufacturer-specific sanitisation processes.

ADISA test levels summary:

  • Level 1: Magnetic media (HDDs) – traditional hard drives
  • Level 2: Solid state media (SSDs, flash) – modern storage
  • Level 3: Mobile devices – phones, tablets
  • Each level verified through forensic analysis of processed media
  • Certification must be renewed through regular re-auditing

A provider may be certified at one, two, or all three levels depending on the types of media they process. When selecting a provider, check that their ADISA certification covers the specific media types you need destroyed.

The Audit Process

ADISA audits are comprehensive and cover both operational processes and actual output quality. The audit typically includes:

Operational assessment: Review of the provider’s facilities, security measures, staff training, chain of custody procedures, quality management, and documentation processes. This ensures the operational environment supports secure processing.

Process verification: Examination of how devices are received, tracked, processed, and reported. Auditors check that the documented process matches actual practice and that controls are consistently applied.

Forensic testing: The defining element of ADISA certification. Auditors take samples of processed media (wiped drives, shredded material, degaussed media) and subject them to forensic recovery attempts. If the provider’s process is effective, no data should be recoverable from the processed samples.

Reporting and documentation: Review of the certificates and reports the provider issues to customers, ensuring they contain sufficient detail to demonstrate what was done, to which assets, and when.

Certifications are not permanent. Providers must undergo regular re-auditing to maintain their ADISA certification, ensuring ongoing compliance rather than a one-time achievement.

Why ADISA Matters for Australian Businesses

For Australian organisations, ADISA certification addresses a fundamental trust problem in the data destruction market. Any provider can claim they destroy data securely. Fewer can prove it through independent, forensic-backed verification.

ADISA certification is particularly relevant when your organisation handles sensitive or regulated data (healthcare, financial services, legal, government), when you need to demonstrate compliance with standards like ISO 27001, the Privacy Act, or sector-specific regulations, when you’re conducting due diligence on potential ITAD providers, when your customers or clients require assurance about your data handling practices, and when you need to satisfy auditor requirements for third-party vendor assessment.

Having an ADISA-certified provider significantly strengthens your compliance position. If a regulatory body or auditor questions your data destruction practices, being able to point to an independently verified provider is far more compelling than relying on an uncertified provider’s self-assessment.

ADISA vs Other Certifications

ADISA is one of several certifications you might encounter. Understanding how it compares helps with provider selection:

ISO 27001: A broad information security management standard. It covers the entire ISMS, not just data destruction. A provider can be ISO 27001 certified without having ADISA certification, and vice versa. Ideally, a provider holds both: ISO 27001 for their overall security framework and ADISA for specific data destruction verification.

NIST 800-88: A US government standard that provides guidelines for media sanitisation. It’s a standard/guideline rather than a certification. Providers can claim to follow NIST 800-88, but there’s no independent body that certifies compliance with it specifically. ADISA’s forensic testing effectively verifies whether a provider’s process achieves the outcomes NIST 800-88 requires.

AS/NZS 5377: The Australian/New Zealand standard for end-of-life management of ICT equipment. Covers the broader process of e-waste handling, not just data destruction. Complementary to ADISA rather than competing with it.

ISO 14001: Environmental management certification. Relevant for the recycling aspects of ITAD but doesn’t address data destruction directly.

The strongest providers hold multiple certifications. ADISA addresses the specific question of “does the data destruction actually work?” while ISO 27001 addresses “is the overall security framework sound?” and AS/NZS 5377 addresses “is the e-waste handling process compliant?”

What to Ask an ADISA-Certified Provider

When engaging with a provider who claims ADISA certification, verify the details rather than taking the claim at face value:

Which test levels are they certified for? A provider certified only for Level 1 (magnetic media) may not meet your needs if you primarily need SSD or mobile device destruction.

Is the certification current? ADISA certifications have expiry dates. Ask to see the current certificate and check the validity period.

Does the certification cover all their facilities? A provider with multiple locations may only have certification for some of them.

What does their certificate of destruction include? ADISA-certified providers should issue detailed certificates including serial numbers, destruction methods, dates, and verification results.

Can you visit the facility? Reputable ADISA-certified providers welcome customer visits and are confident in showing how they operate.

Provider verification checklist:

  • Request current ADISA certificate with validity dates
  • Confirm certification covers the test levels you need (1, 2, and/or 3)
  • Verify the certificate covers the specific facility that will process your equipment
  • Check ADISA’s directory to confirm the provider’s listed status
  • Ask about their internal quality assurance beyond the ADISA audit requirements

The Bottom Line

ADISA certification provides something that most other data destruction certifications don’t: forensic proof that the process works. In an industry where the consequences of failure can include regulatory penalties, reputational damage, and legal liability, that independent verification is valuable.

When selecting a data destruction provider, ADISA certification should be on your shortlist of evaluation criteria, particularly for organisations handling sensitive or regulated data. Combined with ISO 27001 for overall security management and AS/NZS 5377 for e-waste handling compliance, it provides a strong foundation for confident IT asset disposal.

For a broader view of how to select and evaluate ITAD providers, see our guide on how to choose an ITAD provider in Australia, and for the technical details of destruction methods, explore our comparison of hard drive destruction methods.

EWV helps Victorian businesses manage e-waste and IT asset disposal compliantly and sustainably — including collection, certified data destruction, and recycling. Contact us for a free quote.