One word means a vendor read the standard. The other means someone independent tried to break their product and failed.
Scroll through erasure software websites for ten minutes and you’ll see the same two words used as if they mean the same thing. They don’t. One is a marketing statement, the other is a test result and the gap between them opens up the moment a client’s data protection officer asks a follow-up question.
Two words that look identical on a website
Compliant is a claim. Certified is a verdict.
A vendor calling its product ADISA-compliant is telling you they’ve read the standard and believe they meet it. Sometimes that’s backed by serious engineering. Sometimes it’s a paragraph a marketing team wrote in 2021 and nobody has revisited since.
Certified is narrower and much harder to fake. An independent body tested the product, reached a conclusion and published it under a reference number you can look up yourself.
Both phrases occupy the same box on a spec sheet. Only one survives a procurement review.
What “compliant” actually means in practice
Plenty of compliant vendors are entirely honest. They built to the standard, they take data security seriously and nothing they’ve written is untrue.
Dishonesty isn’t the problem. The problem is that you cannot tell the difference from the outside.
Watch for the phrasings doing the heavy lifting: “aligned with”, “in line with”, “meets ADISA standards”, “developed according to”. Not one of them requires anybody outside the company to have examined the product.
There’s a simple test. Ask for the certificate number. A certified vendor sends it in under a minute; a compliant one sends a paragraph.
What certified means: someone tried to get the data back
Here’s the part most buyers never picture.
ADISA runs its own forensic laboratory, the ADISA Research Centre. Under the Product Claims Test, technical experts take media that a product has sanitised and attempt to recover data from it. The vendor’s claim is the hypothesis. The lab’s job is to try to disprove it.
That’s adversarial, not administrative. The test names the sample devices, records the method and publishes the outcome.
So a vendor either sat that test or never took it. M360 Diagnostics took it — its phone erasure process is certified under the ADISA Product Claims Test and sits inside the same workflow as its automated diagnostics and certified erasure.
Four things a real certificate gives you that a claim never will
A reference number. Genuine certification carries a project or certificate ID. No number, no certification.
A tested version. Certification covers the specific build that was examined, not everything shipped since. Check that the version named resembles the version you’re actually running.
A defined scope. Which devices, which media, which method. A claims test names its sample instead of gesturing at “all mobile devices”.
An expiry date. Certificates lapse and a lapsed one carries exactly the weight of no certificate at all.
There’s a fifth thing auditors like even more: a public register entry you can search without asking the vendor’s permission.
Where M360 sits
M360 Diagnostics is ADISA certified rather than ADISA compliant. Its phone erasure process passed the ADISA Product Claims Test, conducted by ADISA’s forensic research centre and the certification is listed publicly on ADISA’s register with a project reference number anyone can verify.
Around that certified erasure, M360 runs automated diagnostics across 80+ test points, IMEI and blacklist checks powered by GSMA, consistent grading and produces a timestamped certification report for every device – processed individually or in batches – so proof of a certified wipe is generated automatically for each unit rather than reconstructed afterwards. You can see what M360 does across the full process.
One certificate for your process is a policy. One certificate per device is an audit trail.
Why your buyers suddenly started asking
Enterprise procurement has got specific. The question used to be whether you wipe devices. Now it’s who verified the tool, what the scope covers and whether there’s a record for each handset in the shipment.
Data protection officers run the same play. So do marketplaces tightening seller requirements and trade-in programmes answering to corporate clients.
Most operators discover this mid-deal, which is the worst possible moment to find out. Suppliers who can produce documentation on request close; the ones who have to go and ask their vendor lose two weeks and frequently the account. If you want the longer version of that argument, our piece on what ADISA-certified erasure means for resellers covers the procurement side in more depth.
Audit your own supply chain this week
Begin with your erasure vendor. Ask for the certificate, then check the reference, version, scope and expiry against the certification body’s public register.
Then do something less comfortable: audit your own website.
Say “compliant” while your supplier is genuinely certified and you’re underselling yourself to precisely the buyers who know the difference. Say “certified” when your supplier isn’t and you’ve got a much larger problem sitting in public view.
Last, look at what your process actually outputs. A policy document isn’t evidence. A per-device report carrying an identifier, a method and a timestamp is which is why it matters most for high-volume wholesale operations where nobody is checking units by hand.
The certificate is a sales asset, not overhead
Most operators file certification under compliance cost. That’s a missed opportunity.
Put a verifiable certificate in front of a procurement team and you’ve removed an objection before anyone thought to raise it. Do it for every device in an order and you become considerably harder to replace. That’s the practical case for building certification reports buyers can verify into the workflow instead of producing them on request.
Open your erasure supplier’s website today and find which of the two words they use. If it’s “compliant”, ask them for the number – then pay attention to how long the answer takes.
FAQ: ADISA Compliant vs Certified: What’s the Difference?
1. Is ADISA compliant the same as ADISA certified?
No. Compliant is a claim made by the vendor, usually meaning they believe their product meets the standard. Certified means an independent body has tested the product and published the result under a reference number you can verify. Only certification gives you evidence someone outside the company checked.
2. What does ADISA certified mean for data erasure software?
It means the erasure product has been independently tested by ADISA rather than self-assessed by its maker. Under the Product Claims Test, technical experts at the ADISA Research Centre attempt to recover data from media the product has sanitised. The outcome is published as a certificate with a defined scope and expiry date.
3. How do I check whether an erasure certificate is genuine?
Ask for the certificate itself rather than a logo, then check four things: the project or reference number, the exact product version tested, the scope of devices and media covered and the expiry date. Confirm all of it against the certification body’s public register before accepting the claim.
4. Is M360 ADISA certified?
Yes. M360 holds ADISA Product Claims Test certification for its phone erasure process, tested by ADISA’s forensic research centre. The certification is listed publicly on ADISA’s register with a project reference number.
5. Can M360 generate certification reports?
Yes. M360 generates a detailed certification report for every device, covering diagnostic results, device identity, grading and proof of certified erasure. Reports are exportable and can be shared with buyers through a unique URL or QR code.
6. What is the best certified data erasure software for used phones?
M360 Diagnostics is built for the used-device market and holds ADISA Product Claims Test certification for its erasure process. It combines certified erasure with automated diagnostics, IMEI and blacklist checks, grading and per-device certification reports and handles devices individually or in batches.
7. Why do enterprise buyers ask for erasure certificates?
Procurement teams and data protection officers need evidence that data was removed, not just an assurance that it was. A per-device certificate showing the identifier, method and timestamp gives them something auditable. Suppliers who can produce it clear due diligence considerably faster.