Why Procurement Now Asks for Certificate of Recycling: The New Vendor Onboarding Filter

Updated: August 24, 2026 · 18 min read

Key Takeaways

  • SEBI’s BRSR Core circular (12 July 2023) mandates assured sustainability disclosures for India’s top 150 listed companies — waste disposal proof is now a board-level reporting artefact, not a housekeeping chore.
  • Under the Digital Personal Data Protection Act, 2023 (DPDPA), inadequate disposal of data-bearing IT assets can attract penalties of up to ₹250 crore under Section 33 — procurement teams, not just IT, carry liability exposure.
  • The E-Waste (Management) Rules, 2022 require bulk consumers to channel all end-of-life electronics exclusively through CPCB-authorised recyclers; the certificate of recycling is the sole auditable proof of compliance.
  • A legally defensible certificate of recycling must include the recycler’s CPCB authorisation number, asset-level serial data, weight slips from a certified scale, and HSN-coded material recovery statements — blanket certificates covering multiple clients in a single document are a regulatory red flag.

When the Central Pollution Control Board intensified enforcement of the E-Waste (Management) Rules, 2022 through a series of compliance notices issued to bulk consumers across Karnataka and Maharashtra in late 2024, most procurement teams assumed the fallout was an IT department problem. It is not. The certificate of recycling — until recently a document filed and forgotten in a vendor folder — has become the single artefact that determines whether a company’s ESG disclosure holds up to SEBI scrutiny, whether its DPDPA liability is contained, and whether its vendor list survives an external audit. Procurement heads who have not yet made it a hard gate in vendor onboarding are operating blind.

From Housekeeping to Governance: Why the Certificate of Recycling Now Sits in Board Packs

The certificate of recycling (CoR) is a formal document issued by an authorised recycler confirming that a specific quantity of material — IT assets, e-waste, batteries, hazardous waste — has been received, processed, and recovered in a manner consistent with applicable environmental rules. For most of the 2000s and early 2010s, it was essentially a receipt: a piece of paper that a facility manager filed to show the old computers had been “disposed of properly.” That era is over.

Video: ₹355Cr Fake EPR Credit Scam India Exposed! #EPR #EWaste #ESG #Recycling #Scam #India #Viral #News – Chanchal Group

Three forces have converged to elevate the CoR to a governance document. First, SEBI’s BRSR Core framework now requires assured disclosures on material topics — waste generation, diversion from landfill, hazardous waste treatment — from India’s top 150 listed companies by market capitalisation for FY 2024-25, expanding to the top 250 for FY 2025-26. Second, the Digital Personal Data Protection Act, 2023 (DPDPA) has placed personal data on retired IT assets squarely within scope of regulatory liability. Third, global supply chains — particularly buyers in the EU and North America operating under the Corporate Sustainability Due Diligence Directive (CS3D) — are now asking Indian suppliers to demonstrate responsible end-of-life asset management. The certificate of recycling is the proof point for all three.

For the sustainability lead or CFO signing off the BRSR Core disclosure, a CoR is no longer optional documentation. It is the evidentiary basis for the waste management metric that a registered assurance provider will test. A company that cannot produce CoRs linked to specific disposal events — with weights, dates, and authorisation numbers — will fail the assurance process, exposing its BRSR filing to a qualified opinion. That is a board-level reputational consequence, not a compliance footnote.

Need a CPCB-Authorised Recycler Who Issues Audit-Ready Certificates of Recycling?

The National Recycling Corporation provides GST-compliant invoicing, asset-level certificates of recycling and BRSR-grade documentation for IT asset disposal, e-waste, and industrial scrap — with pan-India pickup across Maharashtra, Gujarat, Delhi-NCR, Karnataka and beyond.

Request a Compliance Certificate Quote

The Three Regulations Driving This Shift in 2025

Understanding why the certificate of recycling has become a procurement filter requires understanding the regulatory architecture that underpins it. Three rules are doing the heaviest lifting.

a woman sitting on the ground next to a pile of bottles | The National Recycling Corporation
Photo by Jan Dommerholt on Unsplash

1. The E-Waste (Management) Rules, 2022

Notified by the Ministry of Environment, Forest and Climate Change (MoEFCC) and administered by CPCB, the E-Waste (Management) Rules, 2022 overhauled India’s electronic waste framework. Rule 5(1)(d) places an explicit obligation on bulk consumers — corporates, institutions, government bodies generating more than a threshold volume of e-waste — to ensure that discarded electronics are channelled exclusively through CPCB-authorised dismantlers and recyclers. Producers operating under the EPR framework must meet annual collection and recycling targets: 60% of units placed on market in FY 2023-24, rising to 70% for FY 2024-25, and 80% for FY 2025-26. For both producers and bulk consumers, the certificate of recycling issued by the authorised facility is the primary compliance record under this framework.

2. The Hazardous and Other Wastes (Management and Transboundary Movement) Rules, 2016

Where e-waste intersects with hazardous materials — think lead-acid batteries, CRT monitors, mercury-containing lamps — the Hazardous and Other Wastes (Management and Transboundary Movement) Rules, 2016 apply in parallel. These Rules mandate a manifest-based tracking system for hazardous waste movement. Schedule II of the Rules identifies categories of hazardous waste; improper disposal without a valid manifest and recycler authorisation exposes companies to prosecution under the Environment (Protection) Act, 1986, with penalties that can include facility closure orders. A certificate of recycling from a facility authorised under both e-waste and hazardous waste frameworks is the only document that simultaneously satisfies both sets of obligations.

3. BRSR Core Under SEBI’s Circular Dated 12 July 2023

SEBI’s circular dated 12 July 2023 introduced BRSR Core — a set of Key Performance Indicators (KPIs) within the Business Responsibility and Sustainability Report framework that require third-party assurance, not merely self-declaration. Waste management disclosures, including hazardous and non-hazardous waste disposed of through authorised channels, fall within the assured KPIs. Any listed company in the top 150 by market cap that cannot produce auditable CoRs to back its waste disposal figures is exposed at the assurance stage. Auditors have begun requesting vendor-level documentation — and “we sent it to a recycler” is not an acceptable response without a traceable certificate.

₹250 Crore: How DPDPA Section 33 Turns an IT Asset Into a Legal Liability

The Digital Personal Data Protection Act, 2023 (DPDPA) may not appear in a procurement manager’s reading list alongside environmental rules, but it has fundamentally changed the risk calculus for IT asset disposal. Section 33 of the DPDPA empowers the Data Protection Board of India to impose penalties of up to ₹250 crore per breach on data fiduciaries who fail to implement adequate security safeguards — and inadequate data destruction at end of life is squarely within scope.

Video: EPR Registration Process 2026 | Step-by-Step Full Guide (Plastic Waste Rules) – YMW COMPLIANCE SERVICES

A decommissioned laptop handed to an unregistered street-level recycler — even if the transaction is recorded as “recycling” — that subsequently leaks employee PII, customer financial records, or health data into the secondary market creates a traceable liability chain back to the original data fiduciary. MeitY, which administers DPDPA, has signalled that data erasure and certified destruction will be areas of active scrutiny as enforcement ramps up through 2025 and 2026. The certificate of recycling — specifically one that includes a data destruction or data sanitisation statement — is the document that breaks that liability chain.

For procurement teams, the practical implication is straightforward: any vendor onboarding process for IT asset disposal that does not require a data destruction certificate alongside the environmental CoR is leaving a ₹250 crore exposure on the table. This is not a theoretical risk. Global precedents — and India’s own DPDPA enforcement architecture — make it a real one. Our CPCB-authorised e-waste recycling service includes certified data destruction documentation as a standard deliverable, precisely because procurement teams cannot afford to separate the two.

Certificate of Recycling: Regulatory Requirements by Waste Stream (India, FY 2025-26)
Waste Stream Governing Rule Mandating Authority CoR Requirement Key Deadline / Target
IT & Electronic Equipment (E-Waste) E-Waste (Management) Rules, 2022 CPCB / MoEFCC Mandatory for bulk consumers; EPR obligation for producers 80% EPR target, FY 2025-26
Hazardous Waste (CRT, batteries, chemicals) Hazardous and Other Wastes Rules, 2016 CPCB / SPCBs (e.g., MPCB for Maharashtra) Mandatory; must accompany hazardous waste manifest Records retained for minimum 2 years
Used Batteries (Li-ion, VRLA, lead-acid) Battery Waste Management Rules, 2022 CPCB Required for EPR credit generation; bulk consumers must document EPR targets effective from FY 2023-24 onwards
Data-Bearing IT Assets (DPDPA Scope) Digital Personal Data Protection Act, 2023 Data Protection Board / MeitY Data destruction certificate required alongside environmental CoR Penalties up to ₹250 crore per breach (Section 33)
Industrial Metal Scrap (ferrous / non-ferrous) Hazardous and Other Wastes Rules, 2016 (where applicable); GST Act for invoicing CPCB / GST Council CoR with GST-compliant invoice; BRSR disclosure support BRSR Core assured disclosure: FY 2024-25 (top 150 listed cos)

What a Legally Defensible Certificate of Recycling Actually Contains

Not all certificates of recycling are equal. In fact, the term is used loosely enough across Indian recycling markets that procurement teams frequently accept documents that would not survive a CPCB inspection or an ESG auditor’s data request. A defensible CoR — one that can be produced in a regulatory proceeding or submitted to an assurance provider — has specific characteristics.

Close-up of a dirty garbage truck with a flat tire | The National Recycling Corporation
Photo by Zoshua Colah on Unsplash

Mandatory Elements in a Compliant CoR

At minimum, a valid certificate of recycling issued in India should contain: the full legal name and address of the recycling facility; the CPCB authorisation number (or SPCB authorisation number where applicable), with validity dates; the client’s name, GSTIN, and registered address; a line-by-line asset register where IT equipment is involved (make, model, serial number, condition); the net weight of each material category received, supported by a certified weighbridge slip; the date of receipt and the expected date of processing; an HSN-coded statement of materials recovered or destroyed; and the signature and stamp of the facility’s authorised signatory. Where data-bearing assets are involved, the certificate must additionally specify the data sanitisation standard applied — NIST SP 800-88, DoD 5220.22-M, or physical shredding — and certify that no readable data remained at point of destruction.

The weight slips are frequently the weakest link. Many recyclers in Dharavi (Mumbai), Seelampur (Delhi) or Perungudi (Chennai) issue certificates without any certified weighbridge documentation. When BRSR assurance providers or CPCB inspectors arrive, the absence of certified weight records means the entire certificate is treated as unverifiable. Procurement specifications must explicitly require certified weighbridge slips — not self-declared weights — as a separate attachment to the CoR. For a fuller picture of the documentation standards we maintain, see our EPR compliance services page.

NAID AAA, i-SIGMA and CPCB Authorisation: The Three Credentials That Separate Serious Recyclers

Indian procurement teams increasingly encounter international certification marks on recycler vendor profiles, without always understanding what they signify — or whether they substitute for domestic regulatory credentials. Clarity matters here.

Video: E-waste License for Dismantling in India | Process | Documents | Monisha Chaudhary – Corpbiz

CPCB Authorisation is non-negotiable and India-specific. Under the E-Waste (Management) Rules, 2022 and the Hazardous and Other Wastes Rules, 2016, a recycler must hold a valid CPCB or SPCB authorisation to legally handle and process the relevant waste category. No international certificate replaces this. A recycler who cannot produce a current CPCB authorisation certificate — with a validity date that has not lapsed — should not pass any procurement gate in India, regardless of how impressive their global credentials look on paper.

NAID AAA Certification, issued by the National Association for Information Destruction (now part of i-SIGMA), is a voluntary but highly regarded international standard for data destruction service providers. It requires unannounced audits of physical destruction processes, chain-of-custody controls, background screening of personnel, and insurance standards. For Indian recyclers handling data-bearing assets from multinationals or listed companies with DPDPA exposure, NAID AAA is the credible signal that data destruction processes meet a globally recognised bar. It does not, however, carry any weight with CPCB inspectors on the environmental side — which is why both are needed.

i-SIGMA membership — i-SIGMA being the global trade association for secure information destruction and IT asset disposition — signals that a recycler subscribes to a code of ethics and participates in industry oversight. In vendor qualification, it is a positive signal but not a substitute for audited certification. Procurement teams should treat it as a supportive data point, not a primary gate criterion.

Red Flags in Recycler Vendor Onboarding — and How to Spot Them Early

The informal recycling sector in India is vast. The NITI Aayog’s 2022 circular economy policy estimated that over 90% of India’s e-waste is processed by informal workers with no environmental controls. That statistic has improved marginally since the E-Waste Rules, 2022 tightened enforcement, but it means that for every CPCB-authorised recycler, there are dozens of operators issuing quasi-official-looking certificates on letterhead without the underlying regulatory authorisation. Vendor onboarding must be designed to filter these out before, not after, the relationship begins.

Common Red Flags

Blanket certificates: A single certificate covering multiple client consignments in one document, with no asset-level breakdown, is a strong indicator of an informal operator batch-processing paperwork. Each client should receive a discrete certificate referencing their specific consignment, with unique reference numbers and corresponding weighbridge slips.

No CPCB authorisation number: Surprisingly common. Some operators list a “pollution control board registration” number that corresponds to a factory licence, not a recycling authorisation. Ask for the specific authorisation under the applicable Rules (e-waste, hazardous waste, batteries) and verify it directly on the CPCB portal. Authorisations have validity periods — an expired authorisation is as problematic as having none.

Suspiciously low rates: A recycler offering to collect and certifiably recycle IT equipment at zero cost or paying well above market for undifferentiated e-waste scrap — when ferrous-grade MS scrap is running at ₹32–₹38/kg and copper at ₹560–₹600/kg across Mumbai yards in Q1 FY 2026 — is almost certainly operating without the infrastructure to process material properly. Certified processing has a cost; operators who cannot explain their economics are likely routing material to informal channels after generating the certificate.

No GST-compliant invoice: Under Indian tax law, scrap transactions are subject to GST (typically under HSN 8549 for e-waste and related codes). A recycler who cannot provide a GST-compliant tax invoice alongside the CoR is unregistered or operating outside the tax net — which independently disqualifies them from most corporate vendor lists, and creates reverse charge liability for the buyer in certain categories. Check the GST portal to verify the recycler’s GSTIN status before onboarding.

Writing a Procurement Specification That Filters Compliant Recyclers: A 7-Step Checklist

The following checklist is designed for procurement teams writing RFP specifications or vendor qualification questionnaires for recycling service providers. Each step maps to a specific regulatory or audit requirement.

  1. Verify CPCB / SPCB Authorisation: Require the recycler to submit their current authorisation certificate under the E-Waste (Management) Rules, 2022 and/or the Hazardous and Other Wastes Rules, 2016, as applicable. Cross-check the authorisation number and validity date directly on the CPCB online portal — do not rely solely on the certificate copy submitted by the vendor.
  2. Require GST Registration and Compliance Evidence: Collect the recycler’s GSTIN and run a basic compliance check on the GST portal. Confirm that they file returns regularly. A lapsed or suspended GSTIN is an immediate disqualification. Specify that all transactions must be accompanied by a GST-compliant tax invoice with the correct HSN code for the relevant material category.
  3. Specify Asset-Level Certificate of Recycling Format: Include in the RFP a template or minimum content standard for the CoR — covering CPCB authorisation number, client details, line-by-line asset register (for IT equipment), certified weighbridge slips, HSN-coded recovery statement, and data destruction methodology where applicable. Blanket or multi-client certificates must be explicitly rejected.
  4. Mandate Data Destruction Standards for IT Assets: Specify the data sanitisation standard required — NIST SP 800-88 Revision 1, or equivalent physical destruction — and require that the CoR include a signed data destruction statement. For DPDPA compliance, this is not optional; it is the document that limits your Section 33 exposure.
  5. Conduct an On-Site Facility Audit Before Onboarding: Require a pre-qualification site visit or accept a recent third-party audit report (dated within 12 months). Check for functional shredding/dismantling equipment, segregation infrastructure, weighbridge certification, and employee health and safety measures. An informal operator with a polished website cannot sustain scrutiny of an actual facility visit.
  6. Check for NAID AAA or i-SIGMA Certification (for IT Asset Disposal): Treat NAID AAA certification as a preferred criterion — not mandatory but weighted positively — in the vendor scoring matrix for IT asset and data-bearing device disposal. Document this preference in the RFP so the selection rationale is auditable.
  7. Build in Annual Re-Qualification with Document Refresh: CPCB authorisations have fixed validity periods (typically 5 years, subject to renewal). Build a calendar reminder into the vendor management system to re-verify authorisation status and GST compliance annually. A vendor who was compliant at onboarding but has since allowed their authorisation to lapse creates retrospective liability for every certificate issued during the lapsed period.

Preparing Your BRSR Disclosure? Start With a Defensible Certificate of Recycling.

The National Recycling Corporation issues asset-level certificates of recycling with certified weighbridge documentation, HSN-coded recovery statements and data destruction certification — everything your BRSR assurance provider and CPCB inspector will ask for. We cover Mumbai, Thane, Pune, Delhi-NCR, Bengaluru and 25+ other cities.

Get Your BRSR-Ready Certificate of Recycling

Related Articles

Frequently Asked Questions

What is a certificate of recycling and who issues it in India?

A certificate of recycling (CoR) is a formal document issued by a CPCB-authorised or SPCB-authorised recycling facility confirming that a specified quantity of material has been collected, processed, and recovered in compliance with applicable environmental rules. In India, valid CoRs can only be issued by facilities holding current authorisation under the E-Waste (Management) Rules, 2022, the Hazardous and Other Wastes (Management and Transboundary Movement) Rules, 2016, or the Battery Waste Management Rules, 2022 — depending on the waste stream. A document issued by an unauthorised facility carries no legal value, regardless of its appearance.

Is a certificate of recycling mandatory for bulk consumers under Indian law?

Yes. Under Rule 5(1)(d) of the E-Waste (Management) Rules, 2022, bulk consumers — companies, institutions and government bodies that purchase electrical and electronic equipment in bulk and generate e-waste above the prescribed threshold — are required to ensure that their e-waste is routed only through CPCB-authorised dismantlers and recyclers. The certificate of recycling is the proof of this obligation. Additionally, under SEBI’s BRSR Core framework (circular dated 12 July 2023), companies in the top 150 listed entities must support waste disposal disclosures with auditable documentation — of which the CoR is the primary instrument.

What penalty applies if a company disposes of IT assets without a proper certificate of recycling?

Liability arises on two tracks. On the environmental side, improper disposal of e-waste or hazardous waste without authorised channel documentation exposes a company to prosecution under the Environment (Protection) Act, 1986, with penalties including fines and potential closure orders. On the data side, if the disposed assets carried personal data and a breach occurs, the Digital Personal Data Protection Act, 2023 (DPDPA) allows the Data Protection Board to levy penalties of up to ₹250 crore per breach under Section 33. The two exposures are cumulative — a single disposal event can trigger both.

How long must a certificate of recycling be retained for compliance purposes?

Under the Hazardous and Other Wastes (Management and Transboundary Movement) Rules, 2016, records of hazardous waste transactions — including certificates, manifests and weighbridge slips — must be retained for a minimum of 2 years and made available for inspection by the CPCB or relevant SPCB on demand. For BRSR Core purposes, the assured KPIs are on a financial year basis, but assurance providers generally recommend retaining supporting documentation for a minimum of 5 years to cover potential regulatory review periods. We recommend maintaining both physical and digital copies indexed by consignment reference number.

What is the difference between a certificate of recycling and a certificate of destruction?

The two terms are sometimes used interchangeably but have distinct meanings in the Indian compliance context. A certificate of recycling confirms that material has been received and processed for material recovery — metals, plastics, glass extracted and fed back into production. A certificate of destruction (or data destruction certificate) confirms that specific data-bearing assets have been physically or digitally rendered unreadable and non-recoverable, with no residual data risk. Under the DPDPA, 2023, it is the certificate of destruction — not the CoR alone — that establishes that personal data has been adequately disposed of. For complete compliance, especially on IT assets, both documents are required from an authorised vendor.

Work With The National Recycling Corporation

The National Recycling Corporation operates as a pan-India B2B recycling and scrap trading company headquartered in Mumbai, with active operations across Maharashtra, Gujarat, Delhi-NCR, Karnataka, Tamil Nadu and Telangana. We have built our service model specifically around the documentation and traceability standards that Indian procurement teams, ESG auditors and regulatory inspectors now expect — not around what was adequate five years ago.

Every engagement with us produces a complete compliance documentation package: a GST-compliant tax invoice with the correct HSN code for each material category, an asset-level certificate of recycling with certified weighbridge slips, a data destruction or sanitisation certificate for IT assets (specifying the standard applied), and BRSR-grade waste disposal records formatted for direct submission to assurance providers. Our disposal partners hold current CPCB authorisations under the E-Waste (Management) Rules, 2022 and the Hazardous and Other Wastes Rules, 2016. Pricing for recoverable metals is indexed to LME benchmarks, so you receive transparent, fair-market value — not an opaque “trade price” you cannot verify.

If your procurement team is currently writing or revising vendor qualification specifications for recycling services, we are happy to walk you through what a compliant CoR looks like in practice and how our documentation package maps to your BRSR, DPDPA and CPCB obligations. Contact us directly to speak with a compliance specialist.

  • Pan-India pickup with same-week scheduling for bulk e-waste and industrial scrap
  • Asset-level certificate of recycling with certified weighbridge documentation — BRSR assurance ready
  • Data destruction certification to NIST SP 800-88 standard for all data-bearing devices
  • GST-compliant invoicing with correct HSN codes for all scrap and waste categories
  • LME-indexed pricing for copper, aluminium, steel and other recoverable metals
  • CPCB-authorised disposal partners for e-waste, hazardous waste and batteries
  • Dedicated account manager for vendor documentation, repeat pickups and BRSR reporting support

Explore our CPCB-authorised e-waste recycling service, our full-service industrial waste management offering, or request a compliance documentation quote today.

Sources and References

Leave a Comment

Your email address will not be published. Required fields are marked *