- Home
- /
- R2 & RIOS
R2v3 & RIOS certification consulting
R2v3 certification, without the surprises
We've taken more than 50 electronics recyclers and ITADs through R2 certification. This page is the short version of what we've learned about where it goes wrong.
- 50+Clients certified
- 10Core requirements
- 6Process appendices
- 2015Doing this since
The short answer
What is R2v3 certification?
R2v3 is the current version of the R2 Standard for responsible electronics reuse and recycling, published by SERI and released as an ANSI-approved American National Standard in July 2020. Certification is granted by an accredited certification body after an audit against ten Core Requirements that apply to every facility, plus any of six process-specific appendices that match what your facility actually does.
The structural change in v3 is the split between Core and Process requirements. Everyone certifies to the ten Cores. You then add appendices only for the activities you perform — data sanitization, test and repair, materials recovery, brokering and so on. Your certificate lists which ones you hold, which is why scope definition is the first thing we get right and the thing most first-time applicants get wrong.
R2v3 is not an environmental management standard in the ISO 14001 sense. It's a controls-and-evidence standard for the physical and data flows through your facility: where equipment came from, what happened to it, where it went, and whether you can prove it at any point in that chain.
Who needs R2v3?
If used electronics pass through your control, or through your contracts without physically arriving. R2 probably applies to you.
- Electronics recyclers
Facilities dismantling, shredding or recovering materials from end-of-life equipment.
- ITAD providers
IT asset disposition handling corporate retirements, with data-bearing devices in scope.
- Refurbishers & resellers
Anyone testing, repairing and returning devices to service — Appendix C territory.
- Brokers
Organizations directing equipment from supplier to downstream vendor without ever receiving it. Appendix F applies even with no facility.
Reference
The 10 Core Requirements
These apply to every R2-certified facility regardless of what you do. We keep this table accurate against SERI's published summary. A surprising number of consultancy sites get the numbering wrong.
| Core | Requirement |
|---|---|
| Core 1 | ScopeIdentifies which processes and materials are covered, and provides transparency about what was actually audited. |
| Core 2 | Hierarchy of Responsible Management StrategiesReuse first — devices, parts and components — then maximise materials recovery when reuse is no longer viable. |
| Core 3 | EH&S Management SystemRequires certification to an environmental, health and safety management system, plus industry-specific hazard controls. |
| Core 4 | Legal and Other RequirementsA plan for identifying, monitoring and demonstrating legal compliance, including proof of import/export legality and fair treatment of workers. |
| Core 5 | Tracking ThroughputRecords for inbound, in-process and outbound streams. Negative-value streams cannot be stored longer than one year. |
| Core 6 | Sorting, Categorization and ProcessingUses the REC (R2 Equipment Categorization) to assign processing status and route items down the correct path. |
| Core 7 | Data SecurityData-bearing devices secured from arrival, then sanitised by physical destruction or by the enhanced methods in Appendix B. |
| Core 8 | Focus MaterialsA documented FM Management Plan, downstream vendor verification, and a flowchart of the downstream recycling chain. |
| Core 9 | Facility RequirementsSafe and legally compliant processing and storage, site risk evaluation, adequate insurance, and a facility closure plan. |
| Core 10 | TransportSafe, secure and legal transport, with appropriate packaging for reusable items, Focus Materials and data-bearing devices. |
Focus Materials include circuit boards, batteries, CRT glass, mercury-containing devices and PCBs. Source: SERI's published Summary of R2v3 Requirements.
Reference
The 6 Process Requirements
Appendices apply only if you perform that activity, but if you perform it, it must be audited and named on your certificate. You cannot quietly leave an activity out of scope.
| Appendix | Applies to |
|---|---|
| A | Downstream Recycling ChainAny facility transferring R2 Controlled Streams to a downstream vendor. Tracking can stop at the first R2v3-certified vendor, but only if you register your chain with SERI. |
| B | Data SanitizationRequired for any facility performing logical data sanitization (data wiping) to enable reuse. Enhanced processes, security controls and device-level records. |
| C | Test and RepairTesting or repairing devices. Requires a certified quality management system — RIOS or ISO 9001 — underneath it. Items must be processed within one year of receipt. |
| D | Specialty Electronics ReuseMedical, telecom, laboratory and other non-consumer equipment. Must also hold Appendix C. |
| E | Materials RecoveryBreaking down electronics and refining recovered streams. Additional risk controls and pollution liability insurance. |
| F | BrokeringControlling delivery from supplier to downstream vendor without receiving the material. Also requires a certified QMS, and full downstream verification. |
Two appendices need ISO 9001 or RIOS underneath them
If you perform test and repair (Appendix C) or brokering (Appendix F), R2v3 requires a certified quality management system as the foundation. That means either RIOS or ISO 9001 before or alongside your R2 work.
Plenty of recyclers discover this late and lose months. If you're planning either appendix, the QMS decision belongs in your first conversation, not your third.
Where first-time applicants actually fail
Across 50+ certifications, the same four areas produce the majority of findings. None of them are exotic. They're all evidence problems. The work was done, but it can't be proved.
-
Appendix A · Core 8
Downstream vendor due diligence
Vendors used but never formally verified, chains that stop short of final disposition, or a flowchart that doesn't match the vendors actually receiving material.
Before your audit, confirm Every downstream vendor identified in the flowchart, verification records current for each, and documented tracking through to final disposition. -
Core 8
Focus Material tracking
An FM Management Plan that omits a stream the facility genuinely handles, or plans that describe intended handling rather than what happens on the floor.
Before your audit, confirm Every FM stream in scope is named in the plan, handling and storage match the written method, and the downstream route for each is documented. -
Core 7 · Appendix B
Data destruction documentation
Sanitization performed reliably but recorded inconsistently — missing device-level records, or logical wiping carried out without Appendix B certification.
Before your audit, confirm Device-level sanitization records, chain of custody from receipt, and Appendix B coverage if you perform logical sanitization at all. -
Core 3
EH&S control gaps
Treating Core 3 as an OSHA compliance question rather than a management system, so hazard assessments and emergency planning exist but aren't maintained as a system.
Before your audit, confirm Certified EH&S management system, hazard identification covering actual operations, and tested, documented emergency response.
Three of these are automatic major nonconformities
This is the part worth internalising. The R2 Code of Practices requires certification bodies to record certain deficiencies as major nonconformities. The auditor has no discretion. Among them:
- Failure to identify a Focus Material stream in the FM Management Plan
- Failure to identify a Downstream Vendor in the downstream recycling chain flowchart
- Due diligence not performed effectively for shipments of Controlled Streams
- Failure to maintain a valid SERI Licensing Agreement
Two requirement areas — Focus Materials and downstream vendors — account for three of the four. That's where we spend the most time before an audit, and it's why our gap analysis starts there rather than at Core 1.
How we work
From no system to certified
The same four stages every time. What changes is how much of stage three you need. Some clients have most of it already and just can't evidence it.
Scope and readiness call
Which appendices apply, whether you need a QMS underneath, and what your realistic audit date looks like.
Gap analysis
Requirement by requirement against your actual operation, weighted toward Focus Materials and downstream chain.
Build and document
FM Management Plan, downstream flowchart and verification, data security records, EH&S system, training.
Internal audit and audit prep
A full internal audit cycle with findings closed before your CB arrives — open internal findings become the auditor's findings.
Go deeper
R2 & RIOS resources
-
R2v3
The standard in detail — requirements, appendices and what certification involves.
Read more → -
RIOS
Quality, environmental and safety in one recycling-specific system. And when to choose it over ISO 9001.
Read more → -
R2 Center
Our reference library: requirement explainers, appendix walkthroughs, audit prep.
Browse → -
Certification bodies
Who can actually certify you, how they differ, and how to choose between them.
Compare → -
e-Stewards
The other electronics recycling standard, and how it differs from R2 on scope, prerequisites and export.
Compare → -
R2v3 readiness quiz
Ten questions, three minutes, an honest score against the areas that fail audits.
Start →
What recyclers say
-
Very knowledgable, helpful and confidence inspiring. Got us completely set up and through several audits and fully R2 certified.
Adam KubatGoogle review -
Tony has helped our new ITAD navigate the treacherous waters of R2v3 certification. Thanks Tony!
Paul SchweglerGoogle review
Common questions
R2v3 questions we get asked
How long does R2v3 certification take?
Most electronics recyclers and ITADs certify in four to six months. The realistic range is six to twelve when the facility is large, multi-site, or starting with no management system at all. Scope drives it more than size — adding Appendix B and Appendix C with a complex downstream chain takes considerably longer than a straightforward materials recovery operation. You get a dated plan after the gap analysis rather than an estimate up front.
What's the difference between R2v3 and ISO 14001?
ISO 14001 is a general environmental management standard for any organization. R2v3 is specific to electronics reuse and recycling and adds requirements ISO 14001 doesn't cover — data security, Focus Material handling, downstream vendor due diligence, and equipment categorization. R2v3's Core 3 does require a certified EH&S management system, so the two connect, but neither replaces the other.
Do we need ISO 9001 or RIOS as well?
Only if you perform test and repair (Appendix C) or brokering (Appendix F) — both require a certified quality management system underneath. If you only recycle and recover materials, you don't need one. Worth settling early, because adding a QMS certification mid-project adds months.
Can you be our certification body too?
No. A consultant who builds your system cannot audit it for certification — that separation is fundamental to the scheme. We work with you, an accredited certification body audits you, and we stay independent of all of them so we've no reason to push you toward any particular one.
What happens if we fail the audit?
You don't usually "fail" outright — you receive nonconformities and a window to close them, with the certification body assigning follow-up time to verify your corrective actions. Majors are the serious ones. That's the argument for a full internal audit cycle first: findings you close yourself cost you time, findings the auditor writes cost you time and audit fees.
Do you work with recyclers outside Michigan?
Yes, across the United States. Most of the documentation and system work runs remotely; we come on-site for internal audits, training, and walking the floor before a certification audit.
Part of the work
We help you pick the registrar
Your audit will only be as good as your auditor. Two registrars quoting the same scope can produce very different experiences — one sends someone who knows your sector and finds real problems, the other sends someone learning your business on your time.
So choosing one isn't administrative. We go through it with you: which bodies are accredited for your standards and scope, who has auditors with relevant sector experience, what the three-year cost actually looks like, and what their lead times mean for your deadline.
We have no preferred registrar. We recommend whoever fits your scope, your sites and your timeline, and we give you the questions to ask so you can check the reasoning yourself.
- Accreditation, checked
Accreditation is scope-specific. A body accredited for ISO 9001 is not automatically accredited for 45001 or 27001.
- The auditor, not just the firm
Ask about the specific auditor's sector experience. The brochure tells you about the company; you're getting a person.
- The whole cycle costed
Stage 1, Stage 2, two surveillance audits and recertification — plus travel, and a follow-up audit if you pick up majors.
- Lead times against your deadline
Auditor availability, not your readiness, frequently sets your certification date.
Certify you. A body accredited to ISO/IEC 17021-1 must protect its impartiality, which means it cannot consult for an organization it audits. Anyone offering both is worth a hard question.
Next step
Find out what your audit would find
Thirty minutes, free. Tell us your scope and target date and we'll tell you honestly what stands between you and a certificate.