R2 certification is an audited answer to one question: where did my old equipment go?
R2 is the most widely used standard for companies that refurbish, resell and recycle used electronics. It covers everything that happens to a device from the moment a certified facility takes control of it until it is either working again with its data gone, or broken down into materials ready to be used in manufacturing. Here is what the standard actually requires, in plain terms.
Every device that stores data is secured on arrival and sanitized, either by destroying the storage or by a verified wipe.
Working devices and parts have to be considered for a second life before anything is sent for recycling.
Every outbound shipment is tracked through the vendors who handle it next, all the way to final disposition.
First R2 practices published, following a US EPA initiative
Core requirements every certified facility has to meet
Process appendices for specialised work like data wiping and repair
Full recertification cycle, with surveillance audits in between
A standard written by one group and checked by another
That separation is what gives the certificate its value. Nobody grades their own homework.
Who writes it
R2 stands for Responsible Recycling. The standard is owned by SERI, Sustainable Electronics Recycling International, a non-profit standards body accredited by ANSI. R2 started as a US Environmental Protection Agency initiative that brought recyclers, manufacturers, regulators and environmental groups to the same table. The first version was published in 2008 and revised in 2013.
The current version, R2v3, was released in July 2020 and is the version every certification is now audited against. A 2024 amendment, R2v3.1, extended it to cover solar panels.
Who checks it
SERI does not audit anyone. Independent certification bodies do, and they come on site. An auditor reviews records, interviews staff and watches live operations to confirm the requirements are being followed in practice, not just written down.
A certificate is not permanent. Facilities go through a full recertification audit every three years with surveillance audits in the years between. Problems found during an audit are recorded as minor or major nonconformities and have to be corrected and verified.
What it certifies
R2 certifies a facility, not a product. It tells you how a company handles equipment, protects data and chooses its downstream partners. It audits the process behind our testing and grading, but the condition grade on each listing and the warranty behind it are ours.
Reuse first, then recover, and only in that order
Core requirement 2 sets the order a facility has to follow for everything it takes in.
Many people picture an electronics recycler as a shredder with a loading dock. Under R2 the shredder is the last option, not the first. A certified facility has to evaluate every device, and then every part inside it, for reuse before it is allowed to break anything down.
This is the rule that turns a pile of retired fleet laptops into refurbished stock. It is also why our 2025 impact report shows most of what we shipped going back into service rather than into materials recovery.
The order every R2 facility works through, from most preferred to least
If a laptop, tablet or handheld works, or can be repaired to work, it goes back into service with its data removed. This keeps every gram of material and all the energy spent making it in use.
When the device as a whole cannot be saved, its good components still can. Screens, batteries, keyboards and boards get harvested to repair other units.
Only what is left goes to materials recovery, where metals, plastics and glass are separated so they can return to manufacturing. Recovery has to be maximised, not just attempted.
Each step down keeps less of the original value. The bars narrow for that reason. A facility can only move an item down the list once the step above it has genuinely been ruled out.
Based on the Hierarchy of Responsible Management Strategies in R2v3 Core Requirement 2. Bar widths show the order of preference, not measured quantities.
The ten core requirements
These apply to every R2 facility, whatever kind of work it does.
A recycler, a refurbisher and an ITAD provider all meet the same ten core requirements. They are the baseline: how the facility tracks what it handles, protects data, manages hazardous materials, stays within the law and looks after its people.
The numbering below comes from the standard itself, so you can match it against any R2 certificate or audit report you are shown.
The certificate must state exactly which processes and material types were audited at which location. A facility cannot leave any of its R2 work out of the audit.
Every device and part is evaluated for reuse before anything is recycled. The order is shown in the diagram above.
The facility must hold a certified environmental, health and safety management system that addresses the specific hazards of electronics work.
Our ISO 14001:2015 and ISO 45001:2018 certifications are how we meet this.
A documented plan to identify and prove compliance with every law that applies, including proof that imports and exports are legal. It also covers fair and ethical treatment of workers.
Records of everything coming in, how it changes during processing and everything going out. Material that costs money to process cannot sit in storage for more than a year.
Every item gets a status under R2's own categorization system, which records its condition, how well it works and what has to happen to it next.
Every data-bearing device is secured from the moment it arrives, then sanitized by physical destruction or by the stricter wiping process in Appendix B.
Circuit boards, batteries, mercury, CRT glass and PCBs need a written management plan and verified handling by every downstream vendor.
Safe and legal storage and processing, insurance matched to the site's risks, and a closure plan in case the facility stops operating unexpectedly.
Packaging that protects reusable equipment, data-bearing devices secured and tracked in transit, and proper shipping documentation for every load.
Appendices cover the specialised work
They apply only to the work a facility actually does, and each one is audited on its own.
On top of the core, R2v3 has seven process appendices, lettered A to G. A facility has to certify to every appendix that matches work it performs. If it wipes even one drive so the drive can be reused, for example, it must be certified to Appendix B.
Certified appendices are printed on the facility's R2 certificate. When you compare R2 providers, compare the appendices, not just the logo. Two certified companies can be audited for very different work.
Checking every vendor that receives controlled material and tracking it to final disposition. Tracking can stop at the first R2v3 certified vendor only if the facility has registered its downstream chain with SERI.
On our certificateWiping drives so they can be reused, with tighter security controls, specific tracking and a sanitization record for every device. Required for any facility that wipes data rather than destroying the storage.
On our certificateA certified quality management system such as ISO 9001, a documented reuse plan, test records, R2 grading terms for condition and function, trained technicians, and processing within a year of receipt.
On our certificateA structured verification process for industrial, medical and telecom equipment that cannot be fully tested outside its working environment. Facilities certified to D must also hold C.
Not on our certificateDismantling, shredding and refining electronics for their materials. Adds risk assessments, monitoring and pollution insurance because this work carries the highest environmental and safety risk.
Not on our certificateArranging shipments straight from a supplier to a downstream vendor without the equipment ever passing through the broker's own facility, with the full downstream chain verified.
Not on our certificateAdded in the 2024 R2v3.1 amendment for solar panels and related components such as solar cells.
Not on our certificateOur certificate covers 3 of the 7 appendices. The ones we do not hold are work we do not perform. Under R2, a facility cannot be certified for an activity it has not demonstrated to an auditor.
How a device moves through an R2 facility
From intake to final disposition, every step leaves a record an auditor can check.
The requirements above can read like a checklist. In practice they form one continuous path. This is the route a used rugged laptop takes from the day it arrives at our facility, with the part of the standard that governs each step.
Tracking is the thread that runs through all of it. At no point is a device just sitting in a room unaccounted for.
One device, from arrival to its next life
-
Received and secured Core 5, Core 7
The device is logged into tracking and held in a secure area from the moment it arrives. Anything that stores data is treated as sensitive from day one.
-
Sorted and categorized Core 2, Core 6
It gets an R2 status for condition and function, and a decision on which path it follows next. Reuse is always evaluated first.
-
Data sanitized Core 7, Appendix B
The drive is wiped and the wipe is verified, with a record kept for that device. Storage that cannot be wiped is physically destroyed.
-
Tested and repaired Appendix C
Technicians test its functions, repair or replace what has failed and record the results. The unit is then graded using R2's condition terms.
After testing, every device ends up on one of two paths.
A working, sanitized unit with a documented grade is packed to survive shipping and sold to its next owner. This is where most of what we handle ends up.
Units that cannot be saved go to verified downstream vendors, with batteries and circuit boards handled under the focus materials plan. Tracking continues until the materials are ready to re-enter manufacturing.
Simplified to show the order of work. Parts harvested in step 4 follow the same reuse first rule as whole devices.
Shredding or otherwise destroying the storage so the data cannot be read. Effective, but the drive becomes scrap.
Overwriting or erasing the data with verified methods, so the drive can be used again.
Two ways to make data unrecoverable. One of them keeps the drive.
R2 allows both, but it sets a higher bar for wiping than for destroying. A facility that wipes drives for reuse has to meet the extra security, tracking and record keeping in Appendix B. R2v3 sets these sanitization requirements itself and audits the outcome, rather than simply pointing to an outside data standard.
Wiping is the method we use. In 2025 we sanitized and verified 6,000 units and physically destroyed none. See the full 2025 impact report.
Common questions about R2
What procurement teams and buyers ask us most.
Does R2 certify the laptop I am buying?
No. R2 certifies the facility and the way it works, not individual products. It tells you the device was handled, sanitized and tested under an audited process. The condition grade and warranty on a specific unit come from the seller.
How can I check whether a company is really R2 certified?
SERI publishes a public directory of R2 certified facilities. Check that the company and the specific location appear, that the certificate is current, and that the appendices listed match the work you need done. A certificate for materials recovery alone, for example, does not cover wiping drives for reuse.
Is R2 the same as e-Stewards?
No. They are separate certifications created by different organizations, each with its own requirements. Both address responsible electronics recycling. Some facilities hold both.
Why do R2 facilities also hold ISO certifications?
Because R2 requires management systems underneath it. Core requirement 3 requires a certified environmental, health and safety management system, and Appendix C requires a certified quality management system. ISO 14001 and ISO 45001 are common ways to meet the first, and ISO 9001 the second.
Does R2 apply outside the United States?
Yes. R2 certifies facilities in many countries, including Canada. Core requirement 4 also requires every facility to comply with the laws where it operates, so a certified facility in Ontario has to meet Canadian and provincial rules as well as the standard.
What happens if a facility fails an audit?
The auditor records each gap as a minor or major nonconformity, and the facility has to correct it and show the fix works. A facility that does not close its nonconformities or keep up with its audit schedule loses its certified status.
What this means when you work with us
If you are buying, every refurbished Toughbook, Getac, Dell Rugged or Durabook we sell has come through the process on this page, with its data gone and its history on record.
If you are retiring equipment, our IT asset disposition service runs on the same certified process, so your devices are handled to the same standard from the day they leave your building.
Rugged Books Inc. holds R2v3, ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 certifications. View our R2 certificate. R2 and R2v3 are standards owned by SERI. This page explains them in plain language and does not replace the standard itself.