Skip to content

R2 Certification Preparation

Last Updated: February 2026 Target Audience: Management, Operations Manager, IT Manager

This guide provides a comprehensive roadmap for achieving R2 certification at Scott Recycling. R2 (Responsible Recycling) is the electronics recycling industry's premier standard and demonstrates our commitment to responsible, safe, and environmentally sound practices.


Overview

R2 certification is issued by accredited third-party certification bodies and is based on the R2 Standard (currently R2:2013, with R2v3 released in 2020). It covers every aspect of an electronics recycling operation -- from environmental management and worker safety to data destruction and downstream accountability.


Why R2 Matters

Customer Trust

Many businesses, government agencies, healthcare organizations, and school districts require or strongly prefer R2-certified recyclers. Certification tells customers their materials are handled responsibly and their data is securely destroyed.

R2 requires compliance with all applicable environmental, health, safety, and data security laws. The certification process identifies gaps before they become violations.

Market Access

Large corporate contracts, government RFPs, and institutional partnerships frequently list R2 certification as a prerequisite. Without it, Scott Recycling is excluded from a significant portion of the market.

Competitive Advantage

In our 10-state service area, R2 certification differentiates us from uncertified competitors. It is a signal that we operate at the highest industry standard.


R2:2013 Core Requirements

The R2 Standard is built on eight core requirement areas. Each area requires documented policies, implemented procedures, and verifiable records.

1. Environmental Health & Safety Management System (EHSMS)

Foundation of R2

The EHSMS is the backbone of R2 compliance. Every other requirement ties back to this management system.

What is required:

  • A documented EHSMS that covers all recycling operations
  • Defined roles and responsibilities for EHS management
  • A process for identifying and evaluating EHS risks
  • Objectives and targets for continuous improvement
  • Internal auditing procedures
  • Management review process (at least annually)
  • Corrective and preventive action procedures
  • Employee training program with documented records
  • Document control system for all EHS policies and procedures

What this means for Scott Recycling:

  • We need a written EHSMS manual covering our Sunbright processing facility and all field operations
  • Every employee's training must be documented and tracked
  • We must conduct internal audits at least annually
  • Management must formally review EHS performance at defined intervals

2. Downstream Due Diligence

What is required:

  • Documented process for evaluating and qualifying downstream vendors (anyone we sell or send materials to)
  • On-site audits or equivalent verification of downstream processors
  • Written agreements with downstream vendors specifying environmental and legal requirements
  • Tracking of all materials from receipt through final disposition
  • Knowledge of where materials ultimately end up (not just the first buyer)
  • Procedures for handling non-conforming downstream vendors

What this means for Scott Recycling:

  • Every buyer, processor, and smelter we send materials to must be vetted and documented
  • We need formal vendor qualification files with audit records
  • Material flow must be tracked -- we must know the complete chain from our facility to final recycling/disposal
  • Annual reviews of downstream vendor compliance

Focus Area

Downstream due diligence is one of the most scrutinized areas in R2 audits. Incomplete vendor files or inability to trace material flows are common audit findings.


3. Data Security / Data Destruction

What is required:

  • Documented data destruction policy and procedures
  • Physical security controls for data-bearing devices throughout the process
  • Chain of custody documentation from receipt to destruction
  • Destruction methods that meet recognized standards (e.g., NIST 800-88)
  • Serial number tracking for data-bearing devices
  • Certificates of destruction for customers
  • Employee training on data security procedures
  • Regular audits of data destruction processes

What this means for Scott Recycling:

  • Our existing data destruction procedures (see Data Destruction Procedures) must be fully documented
  • Every hard drive, SSD, phone, and tablet must be tracked by serial number from receipt to destruction
  • Destruction records must be retained and auditable
  • The processing facility must have physical security controls (locked areas, access controls)

4. Environmental Management

What is required:

  • Identification and management of all environmental aspects (emissions, waste, spills)
  • Compliance with all applicable environmental regulations
  • Proper handling, storage, and disposal of hazardous materials
  • Spill prevention and response procedures
  • Waste minimization efforts
  • Environmental monitoring where required

What this means for Scott Recycling:

  • Our environmental procedures (see Environmental Compliance) must be documented and followed
  • CRT processing, battery handling, and toner management need specific written procedures
  • Spill kits must be in place and staff trained on their use
  • All hazardous waste manifests must be maintained

5. Health & Safety Practices

What is required:

  • Compliance with all applicable occupational health and safety regulations (OSHA)
  • PPE program with hazard assessments
  • Emergency action plan
  • Fire prevention plan
  • Lockout/tagout program for all applicable equipment
  • Injury and illness recordkeeping
  • Regular safety training with documented records

What this means for Scott Recycling:

  • Our safety program (see Workplace Safety) must cover all required OSHA elements
  • PPE requirements must be based on documented hazard assessments
  • Lockout/tagout procedures must exist for balers, shredders, and any other applicable equipment
  • All safety training must be formally documented with dates, topics, and attendee signatures

What is required:

  • Identification of all applicable legal requirements (federal, state, local)
  • Process for staying current with changing regulations
  • Compliance with all identified legal requirements
  • Documentation demonstrating compliance

What this means for Scott Recycling:

  • We operate in 10 states -- we need to identify and track regulations in each state where we collect materials
  • Tennessee regulations for our processing facility are the primary focus
  • We need a legal register listing all applicable regulations and our compliance status
  • Regulatory changes must be monitored and addressed

7. Insurance Requirements

What is required:

  • Adequate insurance coverage for the scope of operations
  • Types typically required:
    • General liability
    • Environmental/pollution liability
    • Workers' compensation
    • Commercial auto
    • Professional liability (errors and omissions)
    • Property insurance
    • Umbrella/excess liability

What this means for Scott Recycling:

  • Our current insurance policies must cover all R2-required areas
  • Environmental/pollution liability insurance is particularly important and may need to be added or increased
  • Insurance certificates must be available for the auditor

8. Closure Plan

What is required:

  • A written plan describing how the facility would be closed in an environmentally responsible manner
  • Identification of all materials that would need to be properly managed during closure
  • Financial assurance or plan for funding closure activities
  • Regular review and update of the closure plan

What this means for Scott Recycling:

  • We need a written closure plan for the Sunbright facility
  • The plan must address disposition of all inventory, hazardous materials, and equipment
  • Financial provisions for closure must be identified

Certification Process

The path from decision to certification typically follows these steps:

Step 1: Choose a Certification Body (Month 1)

Select an accredited R2 certification body. Options include:

  • NSF International
  • Perry Johnson Registrars (PJR)
  • SCS Global Services
  • SGS
  • TUV Rheinland

Selection Criteria

Consider proximity (to reduce travel costs for audits), industry experience, responsiveness, and audit scheduling flexibility.

Step 2: Gap Analysis (Months 1-2)

Conduct a thorough gap analysis comparing current operations against R2 requirements.

  • Can be done internally or by hiring an R2 consultant
  • Identifies what we already have in place vs. what needs to be created or improved
  • Produces a prioritized action plan

Step 3: Implement Changes (Months 2-8)

Address all gaps identified in the analysis:

  • Write required policies and procedures
  • Implement new processes (chain of custody, downstream due diligence, etc.)
  • Conduct required training and document it
  • Set up document control systems
  • Establish internal audit procedures
  • Qualify downstream vendors

Step 4: Document Everything (Months 6-9)

Compile all required documentation:

  • EHSMS manual
  • All policies, procedures, and work instructions
  • Training records
  • Downstream vendor files
  • Data destruction records
  • Equipment maintenance logs
  • Safety inspection records
  • Insurance certificates
  • Closure plan

Step 5: Internal Audit (Month 9)

Conduct a full internal audit against the R2 standard:

  • Use the R2 checklist to verify every requirement
  • Document findings
  • Implement corrective actions for any non-conformities

Step 6: Certification Audit (Months 10-11)

The certification body conducts the formal audit:

  • Stage 1 (Document Review): Auditor reviews documentation to verify the EHSMS is designed correctly
  • Stage 2 (On-Site Audit): Auditor visits the facility to verify implementation

Step 7: Certification (Month 11-12)

If the audit is successful (or after any non-conformities are corrected):

  • Certification body issues the R2 certificate
  • Scott Recycling is listed in the SERI R2 directory
  • Certificate is valid for 3 years

Gap Analysis Checklist

Use this checklist to assess Scott Recycling's current readiness. Mark each item as "In Place," "Partial," or "Missing."

EHSMS

Requirement Status Notes
Written EHS policy TO BE ASSESSED
Defined EHS roles and responsibilities TO BE ASSESSED
Risk identification process TO BE ASSESSED
EHS objectives and targets TO BE ASSESSED
Internal audit procedure TO BE ASSESSED
Management review process TO BE ASSESSED
Corrective action procedure TO BE ASSESSED
Document control system TO BE ASSESSED
Employee training program (documented) TO BE ASSESSED

Downstream Due Diligence

Requirement Status Notes
Downstream vendor list TO BE ASSESSED
Vendor qualification procedure TO BE ASSESSED
Vendor audit records TO BE ASSESSED
Written vendor agreements TO BE ASSESSED
Material flow tracking TO BE ASSESSED
Annual vendor reviews TO BE ASSESSED

Data Security

Requirement Status Notes
Written data destruction policy TO BE ASSESSED
Chain of custody documentation TO BE ASSESSED
Serial number tracking system TO BE ASSESSED
Physical security controls TO BE ASSESSED
Certificates of destruction process TO BE ASSESSED
Data security training records TO BE ASSESSED
Destruction method documentation TO BE ASSESSED

Environmental

Requirement Status Notes
Environmental aspects register TO BE ASSESSED
Hazardous material handling procedures TO BE ASSESSED
Spill prevention/response plan TO BE ASSESSED
Waste manifests and tracking TO BE ASSESSED
Environmental permits (current) TO BE ASSESSED

Health & Safety

Requirement Status Notes
Written safety program TO BE ASSESSED
PPE hazard assessment TO BE ASSESSED
Emergency action plan TO BE ASSESSED
Fire prevention plan TO BE ASSESSED
Lockout/tagout program TO BE ASSESSED
OSHA 300 log (current) TO BE ASSESSED
Safety training records TO BE ASSESSED
Requirement Status Notes
Legal requirements register TO BE ASSESSED
Regulatory monitoring process TO BE ASSESSED
Compliance documentation TO BE ASSESSED

Insurance

Requirement Status Notes
General liability TO BE ASSESSED
Environmental/pollution liability TO BE ASSESSED
Workers' compensation TO BE ASSESSED
Commercial auto TO BE ASSESSED
Property insurance TO BE ASSESSED

Closure Plan

Requirement Status Notes
Written closure plan TO BE ASSESSED
Inventory disposition plan TO BE ASSESSED
Financial assurance TO BE ASSESSED

Document Requirements

R2 auditors will want to review the following documents. This list serves as the master document checklist for certification preparation.

Policies (Written, approved by management)

  • Environmental Health & Safety Policy
  • Data Destruction / Data Security Policy
  • Downstream Due Diligence Policy
  • Environmental Management Policy
  • Quality Policy
  • Closure Plan

Procedures (Step-by-step instructions)

  • Risk Assessment Procedure
  • Internal Audit Procedure
  • Corrective and Preventive Action Procedure
  • Document Control Procedure
  • Management Review Procedure
  • Data Destruction Procedure (by media type)
  • Chain of Custody Procedure
  • Downstream Vendor Qualification Procedure
  • Hazardous Material Handling Procedures (CRT, batteries, toner, etc.)
  • Spill Response Procedure
  • Emergency Evacuation Procedure
  • Lockout/Tagout Procedure
  • PPE Selection and Use Procedure
  • Incident Investigation Procedure
  • Employee Training Procedure

Records (Evidence of implementation)

  • Training records (dates, topics, attendees, signatures)
  • Internal audit reports
  • Management review minutes
  • Corrective action reports
  • Data destruction logs with serial numbers
  • Certificates of destruction issued
  • Downstream vendor qualification files
  • Downstream vendor audit reports
  • Material flow records
  • Hazardous waste manifests
  • Equipment maintenance logs
  • Safety inspection reports
  • Incident/accident reports
  • OSHA 300 logs
  • Insurance certificates
  • Permits and licenses

Timeline to Certification

Phase Duration Activities
Decision & Planning Month 1 Select certification body, hire consultant (optional), kick off project
Gap Analysis Months 1-2 Assess current state against R2 requirements
Implementation Months 2-8 Write policies/procedures, implement processes, train staff, qualify vendors
Documentation Months 6-9 Compile all required documentation (overlaps with implementation)
Internal Audit Month 9 Full internal audit, corrective actions
Pre-Audit (optional) Month 10 Some certification bodies offer a pre-assessment
Certification Audit Months 10-11 Stage 1 (document review) + Stage 2 (on-site)
Corrective Actions If needed Address any audit non-conformities (typically 30-90 days)
Certification Issued Month 11-12 Certificate issued, listed in SERI directory

Realistic Expectations

Most first-time R2 certifications take 9-12 months. Companies with strong existing safety and environmental programs may move faster. Budget 12 months to be safe.


Cost Estimates

These are approximate costs for a facility of Scott Recycling's size. Actual costs will vary.

Cost Category Estimated Range Notes
R2 Consultant (optional but recommended) $10,000 - $25,000 Gap analysis, documentation assistance, implementation support
Certification Body Fees $8,000 - $15,000 Application, Stage 1, Stage 2 audit fees
Annual Surveillance Audits $4,000 - $8,000/year Required annually between certification audits
Re-certification Audit (every 3 years) $6,000 - $12,000 Full re-audit at end of 3-year cycle
Implementation Costs $5,000 - $20,000 PPE, signage, equipment, document management system, security upgrades
Insurance Upgrades Varies Environmental/pollution liability may need to be added or increased
Staff Time Significant Estimate 200-400 hours of management/staff time over the project
Total First-Year Estimate $25,000 - $60,000 Includes consultant, certification, and implementation

Ongoing Compliance

Once certified, R2 requires continuous compliance:

Annual Surveillance Audits

  • The certification body conducts an on-site surveillance audit each year between certification audits
  • Auditor reviews a subset of R2 requirements and verifies ongoing compliance
  • Non-conformities must be corrected within the specified timeframe

Re-certification (Every 3 Years)

  • Full re-audit of all R2 requirements
  • Must be completed before the current certificate expires
  • Plan re-certification 3-4 months before expiration

Continuous Improvement

  • The EHSMS must demonstrate continuous improvement over time
  • Set measurable objectives and track progress
  • Conduct internal audits at least annually
  • Hold management review meetings to assess EHS performance

Record Retention

  • Maintain all records for at least 3 years (one full certification cycle)
  • Data destruction records should be retained for the period specified in customer contracts (often 7 years)
  • Training records should be retained for the duration of employment plus 3 years

Maintaining Certification

Certification can be suspended or revoked if surveillance audits reveal significant non-conformities that are not corrected. Treat R2 compliance as an ongoing operational requirement, not a one-time project.


Next Steps

  1. Management Decision: Confirm commitment to R2 certification and allocate budget
  2. Assign Project Lead: Designate someone (Operations Manager recommended) to own the certification project
  3. Complete Gap Analysis: Use the checklist above to assess current state
  4. Select Certification Body: Research and select an accredited certification body
  5. Develop Implementation Plan: Create a detailed project plan with milestones and deadlines
  6. Begin Implementation: Start with the EHSMS framework, then address each R2 requirement area

Questions? Contact your supervisor or refer to the Getting Started guide.