R2 Certification Preparation¶
Last Updated: February 2026 Target Audience: Management, Operations Manager, IT Manager
This guide provides a comprehensive roadmap for achieving R2 certification at Scott Recycling. R2 (Responsible Recycling) is the electronics recycling industry's premier standard and demonstrates our commitment to responsible, safe, and environmentally sound practices.
Overview¶
R2 certification is issued by accredited third-party certification bodies and is based on the R2 Standard (currently R2:2013, with R2v3 released in 2020). It covers every aspect of an electronics recycling operation -- from environmental management and worker safety to data destruction and downstream accountability.
Why R2 Matters¶
Customer Trust¶
Many businesses, government agencies, healthcare organizations, and school districts require or strongly prefer R2-certified recyclers. Certification tells customers their materials are handled responsibly and their data is securely destroyed.
Legal Compliance¶
R2 requires compliance with all applicable environmental, health, safety, and data security laws. The certification process identifies gaps before they become violations.
Market Access¶
Large corporate contracts, government RFPs, and institutional partnerships frequently list R2 certification as a prerequisite. Without it, Scott Recycling is excluded from a significant portion of the market.
Competitive Advantage¶
In our 10-state service area, R2 certification differentiates us from uncertified competitors. It is a signal that we operate at the highest industry standard.
R2:2013 Core Requirements¶
The R2 Standard is built on eight core requirement areas. Each area requires documented policies, implemented procedures, and verifiable records.
1. Environmental Health & Safety Management System (EHSMS)¶
Foundation of R2
The EHSMS is the backbone of R2 compliance. Every other requirement ties back to this management system.
What is required:
- A documented EHSMS that covers all recycling operations
- Defined roles and responsibilities for EHS management
- A process for identifying and evaluating EHS risks
- Objectives and targets for continuous improvement
- Internal auditing procedures
- Management review process (at least annually)
- Corrective and preventive action procedures
- Employee training program with documented records
- Document control system for all EHS policies and procedures
What this means for Scott Recycling:
- We need a written EHSMS manual covering our Sunbright processing facility and all field operations
- Every employee's training must be documented and tracked
- We must conduct internal audits at least annually
- Management must formally review EHS performance at defined intervals
2. Downstream Due Diligence¶
What is required:
- Documented process for evaluating and qualifying downstream vendors (anyone we sell or send materials to)
- On-site audits or equivalent verification of downstream processors
- Written agreements with downstream vendors specifying environmental and legal requirements
- Tracking of all materials from receipt through final disposition
- Knowledge of where materials ultimately end up (not just the first buyer)
- Procedures for handling non-conforming downstream vendors
What this means for Scott Recycling:
- Every buyer, processor, and smelter we send materials to must be vetted and documented
- We need formal vendor qualification files with audit records
- Material flow must be tracked -- we must know the complete chain from our facility to final recycling/disposal
- Annual reviews of downstream vendor compliance
Focus Area
Downstream due diligence is one of the most scrutinized areas in R2 audits. Incomplete vendor files or inability to trace material flows are common audit findings.
3. Data Security / Data Destruction¶
What is required:
- Documented data destruction policy and procedures
- Physical security controls for data-bearing devices throughout the process
- Chain of custody documentation from receipt to destruction
- Destruction methods that meet recognized standards (e.g., NIST 800-88)
- Serial number tracking for data-bearing devices
- Certificates of destruction for customers
- Employee training on data security procedures
- Regular audits of data destruction processes
What this means for Scott Recycling:
- Our existing data destruction procedures (see Data Destruction Procedures) must be fully documented
- Every hard drive, SSD, phone, and tablet must be tracked by serial number from receipt to destruction
- Destruction records must be retained and auditable
- The processing facility must have physical security controls (locked areas, access controls)
4. Environmental Management¶
What is required:
- Identification and management of all environmental aspects (emissions, waste, spills)
- Compliance with all applicable environmental regulations
- Proper handling, storage, and disposal of hazardous materials
- Spill prevention and response procedures
- Waste minimization efforts
- Environmental monitoring where required
What this means for Scott Recycling:
- Our environmental procedures (see Environmental Compliance) must be documented and followed
- CRT processing, battery handling, and toner management need specific written procedures
- Spill kits must be in place and staff trained on their use
- All hazardous waste manifests must be maintained
5. Health & Safety Practices¶
What is required:
- Compliance with all applicable occupational health and safety regulations (OSHA)
- PPE program with hazard assessments
- Emergency action plan
- Fire prevention plan
- Lockout/tagout program for all applicable equipment
- Injury and illness recordkeeping
- Regular safety training with documented records
What this means for Scott Recycling:
- Our safety program (see Workplace Safety) must cover all required OSHA elements
- PPE requirements must be based on documented hazard assessments
- Lockout/tagout procedures must exist for balers, shredders, and any other applicable equipment
- All safety training must be formally documented with dates, topics, and attendee signatures
6. Legal Compliance¶
What is required:
- Identification of all applicable legal requirements (federal, state, local)
- Process for staying current with changing regulations
- Compliance with all identified legal requirements
- Documentation demonstrating compliance
What this means for Scott Recycling:
- We operate in 10 states -- we need to identify and track regulations in each state where we collect materials
- Tennessee regulations for our processing facility are the primary focus
- We need a legal register listing all applicable regulations and our compliance status
- Regulatory changes must be monitored and addressed
7. Insurance Requirements¶
What is required:
- Adequate insurance coverage for the scope of operations
- Types typically required:
- General liability
- Environmental/pollution liability
- Workers' compensation
- Commercial auto
- Professional liability (errors and omissions)
- Property insurance
- Umbrella/excess liability
What this means for Scott Recycling:
- Our current insurance policies must cover all R2-required areas
- Environmental/pollution liability insurance is particularly important and may need to be added or increased
- Insurance certificates must be available for the auditor
8. Closure Plan¶
What is required:
- A written plan describing how the facility would be closed in an environmentally responsible manner
- Identification of all materials that would need to be properly managed during closure
- Financial assurance or plan for funding closure activities
- Regular review and update of the closure plan
What this means for Scott Recycling:
- We need a written closure plan for the Sunbright facility
- The plan must address disposition of all inventory, hazardous materials, and equipment
- Financial provisions for closure must be identified
Certification Process¶
The path from decision to certification typically follows these steps:
Step 1: Choose a Certification Body (Month 1)¶
Select an accredited R2 certification body. Options include:
- NSF International
- Perry Johnson Registrars (PJR)
- SCS Global Services
- SGS
- TUV Rheinland
Selection Criteria
Consider proximity (to reduce travel costs for audits), industry experience, responsiveness, and audit scheduling flexibility.
Step 2: Gap Analysis (Months 1-2)¶
Conduct a thorough gap analysis comparing current operations against R2 requirements.
- Can be done internally or by hiring an R2 consultant
- Identifies what we already have in place vs. what needs to be created or improved
- Produces a prioritized action plan
Step 3: Implement Changes (Months 2-8)¶
Address all gaps identified in the analysis:
- Write required policies and procedures
- Implement new processes (chain of custody, downstream due diligence, etc.)
- Conduct required training and document it
- Set up document control systems
- Establish internal audit procedures
- Qualify downstream vendors
Step 4: Document Everything (Months 6-9)¶
Compile all required documentation:
- EHSMS manual
- All policies, procedures, and work instructions
- Training records
- Downstream vendor files
- Data destruction records
- Equipment maintenance logs
- Safety inspection records
- Insurance certificates
- Closure plan
Step 5: Internal Audit (Month 9)¶
Conduct a full internal audit against the R2 standard:
- Use the R2 checklist to verify every requirement
- Document findings
- Implement corrective actions for any non-conformities
Step 6: Certification Audit (Months 10-11)¶
The certification body conducts the formal audit:
- Stage 1 (Document Review): Auditor reviews documentation to verify the EHSMS is designed correctly
- Stage 2 (On-Site Audit): Auditor visits the facility to verify implementation
Step 7: Certification (Month 11-12)¶
If the audit is successful (or after any non-conformities are corrected):
- Certification body issues the R2 certificate
- Scott Recycling is listed in the SERI R2 directory
- Certificate is valid for 3 years
Gap Analysis Checklist¶
Use this checklist to assess Scott Recycling's current readiness. Mark each item as "In Place," "Partial," or "Missing."
EHSMS¶
| Requirement | Status | Notes |
|---|---|---|
| Written EHS policy | TO BE ASSESSED | |
| Defined EHS roles and responsibilities | TO BE ASSESSED | |
| Risk identification process | TO BE ASSESSED | |
| EHS objectives and targets | TO BE ASSESSED | |
| Internal audit procedure | TO BE ASSESSED | |
| Management review process | TO BE ASSESSED | |
| Corrective action procedure | TO BE ASSESSED | |
| Document control system | TO BE ASSESSED | |
| Employee training program (documented) | TO BE ASSESSED |
Downstream Due Diligence¶
| Requirement | Status | Notes |
|---|---|---|
| Downstream vendor list | TO BE ASSESSED | |
| Vendor qualification procedure | TO BE ASSESSED | |
| Vendor audit records | TO BE ASSESSED | |
| Written vendor agreements | TO BE ASSESSED | |
| Material flow tracking | TO BE ASSESSED | |
| Annual vendor reviews | TO BE ASSESSED |
Data Security¶
| Requirement | Status | Notes |
|---|---|---|
| Written data destruction policy | TO BE ASSESSED | |
| Chain of custody documentation | TO BE ASSESSED | |
| Serial number tracking system | TO BE ASSESSED | |
| Physical security controls | TO BE ASSESSED | |
| Certificates of destruction process | TO BE ASSESSED | |
| Data security training records | TO BE ASSESSED | |
| Destruction method documentation | TO BE ASSESSED |
Environmental¶
| Requirement | Status | Notes |
|---|---|---|
| Environmental aspects register | TO BE ASSESSED | |
| Hazardous material handling procedures | TO BE ASSESSED | |
| Spill prevention/response plan | TO BE ASSESSED | |
| Waste manifests and tracking | TO BE ASSESSED | |
| Environmental permits (current) | TO BE ASSESSED |
Health & Safety¶
| Requirement | Status | Notes |
|---|---|---|
| Written safety program | TO BE ASSESSED | |
| PPE hazard assessment | TO BE ASSESSED | |
| Emergency action plan | TO BE ASSESSED | |
| Fire prevention plan | TO BE ASSESSED | |
| Lockout/tagout program | TO BE ASSESSED | |
| OSHA 300 log (current) | TO BE ASSESSED | |
| Safety training records | TO BE ASSESSED |
Legal¶
| Requirement | Status | Notes |
|---|---|---|
| Legal requirements register | TO BE ASSESSED | |
| Regulatory monitoring process | TO BE ASSESSED | |
| Compliance documentation | TO BE ASSESSED |
Insurance¶
| Requirement | Status | Notes |
|---|---|---|
| General liability | TO BE ASSESSED | |
| Environmental/pollution liability | TO BE ASSESSED | |
| Workers' compensation | TO BE ASSESSED | |
| Commercial auto | TO BE ASSESSED | |
| Property insurance | TO BE ASSESSED |
Closure Plan¶
| Requirement | Status | Notes |
|---|---|---|
| Written closure plan | TO BE ASSESSED | |
| Inventory disposition plan | TO BE ASSESSED | |
| Financial assurance | TO BE ASSESSED |
Document Requirements¶
R2 auditors will want to review the following documents. This list serves as the master document checklist for certification preparation.
Policies (Written, approved by management)¶
- Environmental Health & Safety Policy
- Data Destruction / Data Security Policy
- Downstream Due Diligence Policy
- Environmental Management Policy
- Quality Policy
- Closure Plan
Procedures (Step-by-step instructions)¶
- Risk Assessment Procedure
- Internal Audit Procedure
- Corrective and Preventive Action Procedure
- Document Control Procedure
- Management Review Procedure
- Data Destruction Procedure (by media type)
- Chain of Custody Procedure
- Downstream Vendor Qualification Procedure
- Hazardous Material Handling Procedures (CRT, batteries, toner, etc.)
- Spill Response Procedure
- Emergency Evacuation Procedure
- Lockout/Tagout Procedure
- PPE Selection and Use Procedure
- Incident Investigation Procedure
- Employee Training Procedure
Records (Evidence of implementation)¶
- Training records (dates, topics, attendees, signatures)
- Internal audit reports
- Management review minutes
- Corrective action reports
- Data destruction logs with serial numbers
- Certificates of destruction issued
- Downstream vendor qualification files
- Downstream vendor audit reports
- Material flow records
- Hazardous waste manifests
- Equipment maintenance logs
- Safety inspection reports
- Incident/accident reports
- OSHA 300 logs
- Insurance certificates
- Permits and licenses
Timeline to Certification¶
| Phase | Duration | Activities |
|---|---|---|
| Decision & Planning | Month 1 | Select certification body, hire consultant (optional), kick off project |
| Gap Analysis | Months 1-2 | Assess current state against R2 requirements |
| Implementation | Months 2-8 | Write policies/procedures, implement processes, train staff, qualify vendors |
| Documentation | Months 6-9 | Compile all required documentation (overlaps with implementation) |
| Internal Audit | Month 9 | Full internal audit, corrective actions |
| Pre-Audit (optional) | Month 10 | Some certification bodies offer a pre-assessment |
| Certification Audit | Months 10-11 | Stage 1 (document review) + Stage 2 (on-site) |
| Corrective Actions | If needed | Address any audit non-conformities (typically 30-90 days) |
| Certification Issued | Month 11-12 | Certificate issued, listed in SERI directory |
Realistic Expectations
Most first-time R2 certifications take 9-12 months. Companies with strong existing safety and environmental programs may move faster. Budget 12 months to be safe.
Cost Estimates¶
These are approximate costs for a facility of Scott Recycling's size. Actual costs will vary.
| Cost Category | Estimated Range | Notes |
|---|---|---|
| R2 Consultant (optional but recommended) | $10,000 - $25,000 | Gap analysis, documentation assistance, implementation support |
| Certification Body Fees | $8,000 - $15,000 | Application, Stage 1, Stage 2 audit fees |
| Annual Surveillance Audits | $4,000 - $8,000/year | Required annually between certification audits |
| Re-certification Audit (every 3 years) | $6,000 - $12,000 | Full re-audit at end of 3-year cycle |
| Implementation Costs | $5,000 - $20,000 | PPE, signage, equipment, document management system, security upgrades |
| Insurance Upgrades | Varies | Environmental/pollution liability may need to be added or increased |
| Staff Time | Significant | Estimate 200-400 hours of management/staff time over the project |
| Total First-Year Estimate | $25,000 - $60,000 | Includes consultant, certification, and implementation |
Ongoing Compliance¶
Once certified, R2 requires continuous compliance:
Annual Surveillance Audits¶
- The certification body conducts an on-site surveillance audit each year between certification audits
- Auditor reviews a subset of R2 requirements and verifies ongoing compliance
- Non-conformities must be corrected within the specified timeframe
Re-certification (Every 3 Years)¶
- Full re-audit of all R2 requirements
- Must be completed before the current certificate expires
- Plan re-certification 3-4 months before expiration
Continuous Improvement¶
- The EHSMS must demonstrate continuous improvement over time
- Set measurable objectives and track progress
- Conduct internal audits at least annually
- Hold management review meetings to assess EHS performance
Record Retention¶
- Maintain all records for at least 3 years (one full certification cycle)
- Data destruction records should be retained for the period specified in customer contracts (often 7 years)
- Training records should be retained for the duration of employment plus 3 years
Maintaining Certification
Certification can be suspended or revoked if surveillance audits reveal significant non-conformities that are not corrected. Treat R2 compliance as an ongoing operational requirement, not a one-time project.
Next Steps¶
- Management Decision: Confirm commitment to R2 certification and allocate budget
- Assign Project Lead: Designate someone (Operations Manager recommended) to own the certification project
- Complete Gap Analysis: Use the checklist above to assess current state
- Select Certification Body: Research and select an accredited certification body
- Develop Implementation Plan: Create a detailed project plan with milestones and deadlines
- Begin Implementation: Start with the EHSMS framework, then address each R2 requirement area
Questions? Contact your supervisor or refer to the Getting Started guide.