TL;DR
- An ITAD vendor takes your retired IT equipment, destroys or erases the data, resells or recycles the hardware, and gives you records proving each step.
- If you retire fewer than 20 devices a year from one office, you don’t need a vendor contract. A certified recycler and good internal records are enough.
- A good vendor does four jobs well: data security, chain of custody, responsible recycling and fair commercial terms.
- Vendors fall into enterprise ITADs, regional recyclers with data destruction, and remote retrieval platforms that partner with ITADs.
- Judge them on the answers to twelve specific questions, not on their certification logos.
- Done right, you sign once, get serial-level reports every month, and never have to rebuild disposal records before an audit.
You’ve narrowed it to three ITAD vendors. All three have the same certification badges on their websites. All three say “secure,” “compliant” and “sustainable” in the first paragraph. All three sales reps say yes to everything on the call. Six months after you sign, you find out yours scans serial numbers when devices reach its plant, not at pickup, so the four laptops lost in transit don’t appear anywhere.
This is how most ITAD vendor decisions go. Buyers compare websites instead of processes, because nobody told them which questions separate a strong vendor from a weak one. Contracts get signed on price per device, and the revenue share on resale, the minimums and the certificate turnaround time go unread. The gaps show up later, usually during an audit.
The real issue isn’t finding an ITAD vendor. It’s asking the questions that expose how they actually work before you sign. That’s what an ITAD vendor evaluation is supposed to do.
When You Don’t Actually Need an ITAD Vendor
When volume is tiny. Under 20 devices a year, all in one office, no regulated data. Erase in-house, keep a log, use a certified recycler.
When friction shows up. Retirements hit two or three a month, some laptops still have resale value, and IT is spending a day a month on disposal admin.
When it becomes a liability. Auditors and enterprise customers ask for per-device evidence, and your in-house records have gaps. At that point a vendor with serial-level reporting pays for itself.
The edge case: a remote team across countries. Most traditional ITAD vendors are built for pickups from offices and data centers. If your laptops live in homes in eight countries, you need a retrieval partner in front of any ITAD vendor, or a vendor that genuinely does both.
What Teams Actually Need from an ITAD Vendor
“Will I have evidence for every single device?”
Only if the contract requires serial-level certificates, delivered within a set number of days.
Auditors sample individual laptops, not batches.
“Can they reach where my devices actually are?”
Offices, data centers, homes, other countries. Ask for coverage in writing.
A vendor that can’t collect from your employees’ homes leaves your hardest problem unsolved.
“Am I getting fair value for what they resell?”
Ask how resale revenue is shared and how you can check it.
On a refresh of newer laptops, the difference between two vendors’ resale terms can be bigger than their service fees.
“What happens if something goes wrong?”
You want clear liability terms, insurance and breach notification timelines.
Regulators hold you responsible even when the vendor made the mistake.
“Can I leave if it doesn’t work?”
Check term length, minimums and exit terms before you sign.
Long contracts with volume minimums are hard to escape if your headcount shrinks.
The Three Types of ITAD Vendors
1. Enterprise ITAD providers
What it is: Global companies handling laptops, servers and data center hardware at scale, with their own facilities in many countries.
When it’s right: Hundreds or thousands of devices a year, several regions, and a procurement team ready for a master services agreement.
When it fails: Small or remote-first companies. Minimums, slow onboarding and office-only pickups don’t fit.
2. Regional recyclers with data destruction
What it is: Certified recyclers serving one country or region, often with on-site shredding.
When it’s right: Most devices come back to one or two offices in the same country.
When it fails: Global or home-based fleets. You’d end up managing several vendors with different certificate formats.
3. Remote retrieval platforms with ITAD partners
What it is: Device lifecycle companies that collect laptops from homes, then wipe, store, redeploy or pass them to an ITAD partner.
When it’s right: Remote-first teams where getting devices back is the main problem.
When it fails: When nobody asks who issues the final certificate, what standard they follow, and whether serials appear on it.
How to Choose: The 12 Questions to Ask Any ITAD Vendor
Before you send these, know your own numbers: devices retired per year, where they sit, and what your auditors expect. Then ask every vendor the same twelve questions in writing, and compare the answers side by side.
Data security
1. Which standard do you follow for data sanitization, and do you verify every device? Look for NIST SP 800-88 Rev. 2 or IEEE 2883, with verification per device. A pitch built around a “7-pass DoD wipe” signals outdated practice.
2. Do I get a certificate for each serial number, and when do you capture serials? You want serials recorded at pickup, not on arrival at their plant. Otherwise anything lost in transit never shows up.
3. Which facility will handle my devices, and what certifications does that facility hold? Ask for the address, then check it in the public R2 and e-Stewards directories. NAID AAA covers data destruction, and ISO 27001 covers information security.
4. What happens to devices that fail erasure? They should be physically destroyed, with a separate destruction certificate listing each one.
Chain of custody and logistics
5. Can you collect from employees’ homes, and in which countries? Get the list in writing. “Global coverage” often means offices in a few cities.
6. Who transports the devices, and how is that tracked? Ask whether they use their own staff or subcontracted couriers, and whether shipments are sealed and tracked from pickup to plant.
7. Which subcontractors and downstream vendors touch my devices? Ask for the list and the right to approve changes. Downstream partners are where e-waste problems usually start.
Environmental
8. What share of devices do you reuse, and how do you report it? Ask for reuse versus recycling percentages and weights per batch, in a format your sustainability team can use.
9. How do you handle cross-border shipments under the 2025 Basel Convention rules? Since January 2025, most cross-border e-waste shipments need prior informed consent. A good answer is in-country processing.
Commercial
10. How is pricing structured, and how do you share resale value? Get per-device fees, logistics costs and the resale revenue share in writing, plus how and when you’re paid.
11. What are the minimums, term length and exit terms? Avoid long terms with volume minimums unless your headcount is stable.
12. What liability and insurance do you carry if data is exposed? Ask for coverage amounts, indemnity terms and breach notification timelines, then have your legal team read them.
Six ITAD Vendors Worth Knowing
For a full side-by-side comparison of ten providers, see our IT asset disposition vendor comparison.
Iron Mountain
Best for: Enterprises wanting one global contract for IT assets and records.
Why companies choose it: A trusted name with chain-of-custody processes built for regulated industries, and an asset lifecycle business expanded through acquisitions such as Wisetek.
Where it struggles: Built for volume, so small remote fleets may find the minimums and sales cycle out of proportion.
Sims Lifecycle Services
Best for: Large fleets and data centers with real resale value.
Why companies choose it: Strong resale and component recovery, which tends to mean better value on newer hardware.
Where it struggles: Its growth is focused on data center decommissioning, so small laptop fleets aren’t the priority.
TES
Best for: Multinationals that want consistent, in-country processing across regions.
Why companies choose it: A global footprint that makes local processing possible under the new cross-border rules.
Where it struggles: Onboarding can be heavy for smaller companies.
ERI
Best for: US companies that want recycling and data destruction from one national provider.
Why companies choose it: A network of US facilities with broad certification coverage.
Where it struggles: Limited help for employees outside the US.
Securis
Best for: US offices that want witnessed on-site destruction plus wider ITAD services.
Why companies choose it: Mobile shredding for failed drives, and off-site ITAD for the rest.
Where it struggles: It can’t collect from homes, so remote teams need to get laptops back first.
Human-I-T
Best for: US companies that want ITAD with a social impact angle.
Why companies choose it: A nonprofit that sanitizes donated devices at NAID AAA certified facilities and puts refurbished ones into low-income communities.
Where it struggles: US-only, and resale credits aren’t its model, since devices go to people in need.
The Decision Table: Which Vendor Type Fits
| Situation | Scale / Size | Setup | Primary Pain | Recommended Starting Point |
|---|---|---|---|---|
| Tiny volume, one office | Under 20 devices a year | Office | Not worth a contract | Certified local recycler plus internal records |
| US offices, regulated data | 100 - 1,000 people | Office or hybrid | Audit-grade evidence | ERI or Securis |
| Global enterprise | 1,000+ people | Many regions | One contract and one report format | Iron Mountain or TES |
| Data center or large refresh | Hundreds of devices or more | Racks and offices | Getting the most resale value | Sims Lifecycle Services |
| Remote-first, several countries | 50 - 500 people | Home-based | Getting devices back | Retrieval platform with a named ITAD partner |
| Mission-driven company | Any | US offices | Want devices reused in communities | Human-I-T |
Most teams land in two or three of these rows at once. Start with your biggest failure and layer from there.
The Cost of Choosing the Wrong ITAD Vendor
The painful part of a bad vendor choice is how long it takes to notice. Certificates arrive late or without serials, and nobody checks until the audit. Resale credits come in lower than quoted and there’s no way to verify them. Home pickups turn out to be “coming soon” in half your countries.
Then leaving costs money too. Term commitments and volume minimums, new certificate formats, a new portal and a gap in the records while you switch. Most teams stay with a weak vendor longer than they should because switching feels worse.
So before you sign, ask one question. Is your biggest need evidence, reach or value? Weight the twelve answers toward that one, and you’ll pick a vendor you won’t want to leave.
When You’re Ready to Move Beyond One-Off Pickups
You’ve outgrown one-off pickups when retirements happen every month, when you have devices in more than one country, or when finding the certificate for a single laptop takes more than a minute.
At that stage, a contract with clear SLAs for certificates, serial-level reporting and agreed resale terms turns disposal into a routine instead of a scramble.
If that’s where you are, it’s worth looking at dedicated tools in this space. Start with our ITAD vendor comparison and guide to IT asset disposition.
Frequently Asked Questions
What is an ITAD vendor?
An ITAD vendor is a company that handles retired IT equipment for you. It collects devices, erases or destroys the data, resells or recycles the hardware, and gives you records for each step.
How do I choose an ITAD vendor?
Ask every shortlisted vendor the same written questions about data security, chain of custody, recycling and commercial terms, then compare the answers. Check their facility certifications in public directories rather than trusting website badges.
What certifications should an ITAD vendor have?
NAID AAA for data destruction, R2v3 or e-Stewards for recycling, and ideally ISO 27001 for information security. Make sure the certifications cover the facility that will actually process your devices.
How much do ITAD vendors charge?
Most charge per-device fees for logistics and data sanitization, then credit you a share of any resale value. Newer business laptops can come out close to break-even or better, while old or broken equipment costs money to process.
What’s the difference between an ITAD vendor and an e-waste recycler?
An e-waste recycler mainly breaks equipment down into materials. An ITAD vendor also handles data sanitization, resale and reporting, and usually works with certified recyclers for the final step.
Should we use one ITAD vendor or several?
One vendor is simpler if it genuinely covers all your locations. Remote teams across countries often need a retrieval partner plus in-country recyclers, as long as every certificate uses the same serial-level format.
What should an ITAD contract include?
Serial-level certificates within a set number of days, named facilities and certifications, subcontractor approval rights, resale revenue terms, liability and insurance, breach notification timelines, and clear exit terms.
Ask the twelve questions, compare the answers, then sign.