Certifications, Awards, Commitments and Partnerships
Certifications, Awards, Commitments and Partnerships
AWARDS/Recognition




Fortune Magazine’s Fortune 1000.




Iron Mountain received the SSON Shared Services Award in 2021.
Commitments








Industry Memberships/Partnerships
- i-SIGMA (International Secure Governance & Management Association) – we’re a founding member of this professional body for information management vendors (formerly PRISM (Professional Records & Information Services Management).
- Shared Assessments – Iron Mountain is a long time member of the Shared Assessments program and sits on the steering committee. Shared Assessments is dedicated to developing standardization and best practices in the field of third party risk management.
- CEBA – we are a member of the Rocky Mountain Institute’s Business Renewable Center and the Clean Energy Buyers Association (CEBA). Combined, our commitments to wind and solar power make the company one of the top 25 buyers of clean energy among the FORTUNE 1000 and a top 70 energy buyer in the Environmental Protection Agency Green Power Partnership.
Certifications/Audit Reports
- Service Organization Control (SOC) 3 Report, formerly SysTrust®, from the American Institute of Certified Public Accountants (AICPA) – an audit of our IT systems by an outside, independent auditor to ensure we have appropriate internal controls in place for our IT infrastructure environment. Our SOC certification is based on three Trust Services Principles: (1) Security, (2) Confidentiality, and (3) Availability. Each principle is supported by well-defined and detailed criteria that encompass an organization's infrastructure, software, people, procedures and data. Download the Service Organization Control (SOC) 3 Report here.
- Service Organization Control (SOC) Type 2 Report from the AICPA – Iron Mountain also maintains a non-public SOC 2 Report. If needed, please work with your account representative to obtain this report.
- NAID AAA certification from i-SIGMA
- Privacy+ certification from i-SIGMA.
- PCI-DSS Attestation of Compliance (AOC) based on the Payment Card Industry Data Security Standard – If needed, please work with your account representative to obtain this attestation.
- ISO/IEC 27001:2013 Certification, which establishes common Information Security Management Systems (ISMS) controls and procedures for Iron Mountain InSight® running in a secure cloud hosted environment.
- FedRAMP, Iron Mountain InSight has achieved FedRAMP Ready status, as approved by the Federal Risk and Authorization Management Program (FedRAMP).
Iron Mountain is licensed by the New Jersey Office of Consumer Affairs, license NJPM001200. The permanent place of business in NJ is 526 Route 46, Teterboro, NJ.
ALM certifications and standards
- ISO 9001: Receiving, sorting, demanufacturing, testing, resale, and data destruction of electronic equipment.
- ISO 45001: Universal scope: Receiving, sorting, demanufacturing, testing, resale, and data destruction of electronic equipment.
- ISO 14001: Receiving, sorting, demanufacturing, testing, resale, and data destruction of electronic equipment.
- ISO 27001: IT policy, process, device, and system controls that safeguard organizational information security.
- Responsible Recycling: IT policy, process, device, and system controls that safeguard organizational information security.
-
NIST 800-88: Once every asset to be decommissioned has been identified, Teraware goes to work. Teraware’s agent-based architecture scales to any size job; whether it’s one drive or 100,000, Teraware erases all drives concurrently, minimizing customer data exposure risk window. NIST 800-88 is descriptive with regard to media types, chain of custody, methods of destruction, and reporting. ITRenew follows NIST 800-88 and goes a step further, exceeding all industry standards and compliance.
-
ADISA Certified Data Sanitization: The Asset Disposal & Information Security Alliance (ADISA) offers accreditation to companies that maintain the highest standards in IT asset disposal and data sanitization. Only nine companies worldwide are expected to achieve ADISA data sanitization accreditation for both HDDs and SSDs in 2020.
- Passed ADISA Threat Matrix Level 2: the only software to have done so for multiple types of SSDs and HDDs (incl. SATA-HDD, SAS-HDD, SATA-SSD, SAS-SSD, FC-SSD, and NVMe-SSD)
- Only sanitization platform to pass ADISA accreditation using the latest drive technologies (NVMe) and capacities (10TB+)
- 17 Certificates for Forensic Data Erasure of SSDs and HDDs