Resources · ITAD RFP Template
The ITAD RFP Template Every IT Manager Needs in 2026
43 questions covering data security, certifications, chain of custody, value recovery, compliance documentation, and logistics — built from real ITAD projects across Phoenix's healthcare, financial services, and enterprise sectors.
Why Most Businesses Choose the Wrong ITAD Vendor
Most businesses select an ITAD vendor based on price alone — and pay for it later. A vendor who cannot produce a NIST 800-88 compliant Certificate of Destruction, who lacks R2v3 certification, or who cannot demonstrate an unbroken chain of custody is a data breach liability, not a recycling solution. The average cost of a data breach in 2024 was $4.88 million (IBM Cost of a Data Breach Report 2024). The cost of a proper ITAD RFP process: zero.
An ITAD RFP (Request for Proposal) is the structured document you send to ITAD vendors before signing a contract. It forces every vendor to answer the same questions in the same format — making it easy to compare capabilities, certifications, and pricing side by side. Without an RFP, you're evaluating vendors based on their sales pitch, not their actual capabilities.
EWaste Phoenix has answered hundreds of ITAD RFPs from Phoenix-area healthcare systems, financial institutions, law firms, and enterprises. We built this template from the questions that actually matter — the ones that separate certified, compliant ITAD providers from unqualified recyclers.
The Complete ITAD RFP Template (43 Questions)
Copy and paste this template into your procurement system. Customize the bracketed fields for your organization.
Section A — Company Overview & Credentials
- 1.What is your company's legal name, headquarters address, and years in operation?
- 2.Are you NIST 800-88 compliant? Please provide your current certificate number and expiration date.
- 3.Are you R2v3 certified? Please provide your current certificate number and expiration date.
- 4.Do you hold any additional certifications (ISO 14001, ISO 27001, NAID AAA, e-Stewards)? Please list all.
- 5.Have you had any data breach incidents, regulatory violations, or certification suspensions in the past 5 years? If yes, describe.
- 6.Provide 3 references from clients in [your industry] who have used your ITAD services in the past 24 months.
Section B — Data Security & Destruction
- 7.Describe your data destruction process for HDDs, SSDs, NVMe drives, and mobile devices.
- 8.Do you offer on-site data destruction? If yes, describe the equipment used and the minimum volume required.
- 9.What is your process for verifying and documenting data destruction (serial number tracking, technician sign-off, etc.)?
- 10.What Certificate of Destruction do you provide? Include a sample COD in your response.
- 11.How do you handle self-encrypting drives (SEDs) and cryptographic erasure verification?
- 12.What is your process for drives that fail data destruction verification?
- 13.Do you offer witnessed destruction? If yes, describe the process and any additional cost.
- 14.How do you handle data destruction for mobile devices, tablets, and smartphones?
Section C — Chain of Custody & Logistics
- 15.Describe your chain-of-custody process from pickup to final disposition.
- 16.Do you use GPS-tracked vehicles for IT asset transport? Provide details.
- 17.How do you handle asset intake, serialized logging, and manifest reconciliation?
- 18.What is your process for unmanifested items discovered during pickup?
- 19.Do you offer bonded drivers and locked transport containers?
- 20.What is your typical pickup lead time for [volume] assets in [city]?
- 21.Describe your facility security (monitoring, access controls, surveillance, etc.).
Section D — Compliance Documentation
- 22.What compliance frameworks do your services support (HIPAA, GLBA, SOX, FERPA, CMMC, PCI-DSS, FISMA)?
- 23.Do you sign Business Associate Agreements (BAAs) for HIPAA-covered clients?
- 24.What documentation package do you provide at project completion?
- 25.How long do you retain destruction records and chain-of-custody documentation?
- 26.Can your documentation be formatted for specific audit requirements (OCR, NCUA, PCAOB, etc.)?
- 27.Have your processes been audited by a third-party compliance firm? Provide the most recent audit summary.
Section E — Value Recovery & Asset Remarketing
- 28.Do you offer IT asset remarketing and buyback programs?
- 29.How do you determine the fair market value of retired IT equipment?
- 30.What is your revenue-sharing model for remarketed equipment?
- 31.How do you handle equipment that has no resale value?
- 32.Do you provide an itemized value recovery report by asset type?
- 33.What is your average value recovery per device for [server type / laptop model]?
Section F — Environmental Compliance
- 34.Do you have a zero-landfill guarantee? If yes, how is it enforced and documented?
- 35.Do you export e-waste to developing countries? What is your no-export policy?
- 36.How do you handle hazardous materials (CRT monitors, batteries, mercury-containing devices)?
- 37.Can you provide an environmental impact report (pounds recycled, CO2 avoided, materials recovered)?
- 38.Do you support ESG/Scope 3 emissions reporting for IT equipment disposal?
Section G — Pricing & Service Levels
- 39.Provide a detailed pricing schedule for: data destruction (per device), pickup (by volume/distance), on-site destruction, and project management.
- 40.Are there minimum volume requirements for free pickup?
- 41.What is your pricing for emergency or expedited service?
- 42.Do you offer annual contract pricing for ongoing ITAD programs?
- 43.What is included in your standard project documentation package, and what is billed separately?
How EWaste Phoenix Answers Every Question
| Category | EWaste Phoenix Answer | Proof |
|---|---|---|
| Certifications | NIST 800-88 compliant + R2v3 Certified | /certifications |
| Data Destruction | NIST 800-88 Purge + Physical Shredding to ≤2mm | /resources/certificate-of-destruction-sample |
| Chain of Custody | GPS-tracked, serialized, bonded drivers | /case-studies |
| Compliance | HIPAA BAA, GLBA, SOX, FERPA, CMMC, PCI-DSS | /faq |
| Value Recovery | Itemized buyback report, avg 40-70% recovery | /services/itad |
| Zero Landfill | 100% guarantee, documented | /impact |
Frequently Asked Questions
What is an ITAD RFP?
An ITAD RFP (Request for Proposal) is a formal document sent to IT Asset Disposition vendors before signing a contract. It asks each vendor to answer standardized questions about their certifications, data destruction methods, chain of custody, compliance documentation, and pricing — allowing your organization to compare vendors objectively. A proper ITAD RFP protects your organization from selecting an unqualified vendor who could create data breach liability.
What certifications should I require in an ITAD RFP?
The two non-negotiable certifications to require in any ITAD RFP are: (1) NIST 800-88 compliance — the gold standard for data destruction; and (2) R2v3 certification — the leading standard for responsible electronics recycling. Additional certifications to consider: ISO 14001, ISO 27001, and NAID AAA.
How do I evaluate ITAD vendors using an RFP?
Evaluate ITAD vendor RFP responses on four criteria: (1) Certifications — verify certificates are current; (2) Data security — require a sample Certificate of Destruction; (3) Compliance documentation — confirm audit-ready reports for your regulatory framework; (4) References — contact at least 2 references from your industry. Price should be the last factor, not the first.
Ready to Evaluate EWaste Phoenix?
Send us your RFP or schedule a demo. We'll return a complete vendor response within 3 business days.