Key Takeaways for TAA-Compliant ITAD
- TAA compliance under FAR 52.225-5 is a country-of-origin requirement and relies on documented substantial transformation in the United States or a designated country.
- The August 14, 2026 GSA Class Deviation CD-2026-03 removes the AbilityOne and FPI TAA exception, so contractors must verify TAA compliance for all ITAD sources that used that exemption.
- Commingling TAA-eligible and non-TAA assets creates audit-trail gaps and False Claims Act exposure. Programs need physical and systemic segregation throughout disposition.
- Repair or refurbishment alone rarely changes country-of-origin status. Serial-level OEM attestations and segregation logs support audit-ready documentation.
- Premier Logitech delivers TAA-compliant IT asset disposition with CAGE Code 4WAJ9 and ISO 9001/14001, NIST, CMMC and SOC 2 alignment. Talk to a lifecycle expert to evaluate a current program.
How ITAD Vendors Demonstrate TAA Compliance
Contractors determine TAA compliance by applying the FAR definition of a designated-country end product to each asset. FAR 52.225-5 defines a designated-country end product as one wholly the growth, product or manufacture of a designated country, or one substantially transformed there into a new and different article of commerce with a distinct name, character or use.
The TAA-designated country list draws from four categories in FAR 25.003: WTO Government Procurement Agreement parties, free trade agreement partners, Caribbean Basin countries and Least Developed Countries. China, India, Russia, Vietnam, Malaysia, Thailand, the Philippines and Pakistan fall outside that list.
Two common misconceptions can push contractors toward noncompliant vendors. Many assume a U.S.-based ITAD vendor automatically meets TAA requirements, yet TAA status depends on country of origin, not headquarters location. Others assume data erasure establishes TAA compliance, yet TAA compliance and media sanitization operate as separate domains, so a vendor can erase every drive and still deliver noncompliant end products.
FAR 52.225-5 flows down through GSA MAS contracts via GSAR 552.225-71, which incorporates the TAA into the schedule contract. Every SKU on a MAS contractor catalog must meet TAA requirements regardless of order size because the schedule contract value exceeds the threshold. The prime contractor certifies end products to the government and passes TAA clauses to product subcontractors.
The August 14, 2026 GSA Class Deviation CD-2026-03 removes the former AbilityOne and FPI exception that allowed certain products originating in China on GSA contracts. The deviation applies to all GSA acquisitions, including the Federal Supply Schedule MAS and blanket purchase agreements. Contractors that source IT asset disposition through AbilityOne or FPI channels now confirm TAA country-of-origin compliance for those offerings.
Premier Logitech holds TAA compliance, CAGE Code 4WAJ9, ISO 9001/14001 certifications and alignment with NIST, CMMC and SOC 2 frameworks. Premier Logitech provides secure, compliant handling for government and enterprise customers across the full IT asset lifecycle.
Evaluate TAA-Compliant ITAD Vendor Options
Key Steps in a TAA-Compliant IT Asset Disposition Process
A TAA-compliant IT asset disposition process addresses country-of-origin documentation at every stage of the lifecycle. The process does not wait until final reporting.

- Asset Inventory and TAA Eligibility Screening. Serial-level records are created for every device entering the disposition workflow. Each asset receives a country-of-origin flag based on OEM attestations or manufacturer documentation. Non-TAA assets, with final assembly or substantial transformation in a non-designated country, are identified before disposition begins.
- Chain of Custody and Segregation Controls. TAA-eligible assets remain physically and systemically separated from non-TAA assets throughout disposition. Commingling creates compliance risk because it introduces ambiguity into the audit trail and can expose a prime contractor to False Claims Act liability for assets that lack clear certification.
- Data Sanitization. Sanitization follows NIST SP 800-88 Revision 1, Guidelines for Media Sanitization. The guideline specifies minimum sanitization levels for media so data cannot be recovered. Sanitization satisfies data-security obligations but does not change a device’s country of origin.
- Reporting and Documentation. Country-of-origin attestations, Certificates of Destruction, downstream recycler certificates and serial-level audit trails form the core reporting set. Holland & Knight advises that documentation should include certificates of origin, supplier contracts, technical product specifications, records of transformation or processing and detailed bills of materials.
- Downstream Disposition and Recycling. Downstream partners with R2v3, e-Stewards or NAID AAA certifications manage responsible recycling and data destruction. Contractors verify that downstream partners do not reintroduce non-TAA sources into the chain. A primary vendor’s R2v3 certification does not extend to subcontractor operations, a gap auditors frequently identify.
Premier Logitech’s TAA-compliant IT asset disposition programs cover asset recovery, secure data wipe, compliance reporting aligned with ISO, NIST and CMMC frameworks, responsible recycling and disposal and parts reclamation. Serial-level traceability is maintained at each step.

Build a TAA-Compliant Disposition Workflow
Documenting Country of Origin for Disposed IT Assets
Complex refurbishment scenarios often create the hardest country-of-origin questions. A common example involves a device manufactured in a non-designated country that later receives repair work in the United States.
Under CBP ruling NY R04297, aircraft engine parts that are disassembled and exported for repair do not undergo substantial transformation and therefore retain their original country of origin. This illustrates that repair operations alone generally do not change country-of-origin status. The substantial transformation test requires a new and different article of commerce with a distinct name, character or use.

Labeling, repackaging, enclosure installation, simple fastening, connecting finished modules and basic testing usually fail the test. A laptop repaired in the United States with a new battery, keyboard or display keeps the original country of origin unless the U.S. work creates a new and different commercial article.
The audit-ready documentation set for disposed IT assets includes the following elements.
- Serial-level asset records identifying each device by make, model and serial number
- Country-of-origin attestations from the OEM or original supplier naming the specific SKU and current manufacturing location
- Repair and refurbishment records documenting the scope of work and the location where it occurred
- Segregation logs confirming TAA-eligible assets remained separated from non-TAA assets throughout disposition
- Certificates of Destruction for data-bearing media aligned with NIST SP 800-88 Revision 1
- Downstream recycler certificates from R2v3, e-Stewards or NAID AAA certified partners
- Chain-of-custody documentation from intake through final disposition
Origin certifications now receive close scrutiny, both pre-award and post-award. Premier Logitech produces this documentation set as part of standard compliance reporting for government and enterprise programs.
Get Help With Country-of-Origin Documentation
How TAA Compliance Relates to NIST SP 800-88, R2v3, e-Stewards and NAID AAA
Many summaries and vendor pages blend TAA requirements with data-security and environmental certifications. These frameworks address different risks and rely on different authorities.
FAR 52.225-5 governs country of origin and substantial transformation. It determines whether an end product qualifies for delivery under a covered federal contract. It does not govern data erasure methods or recycling practices.
NIST SP 800-88 Revision 1 describes three types of media sanitization, Clear, Purge and Destroy, intended to prevent unintentional data release. Appendix A specifies minimum recommended techniques for each media type. The guideline does not address country of origin.
R2v3 (Responsible Recycling) covers the electronics recycling process from collection logistics through final material recovery and environmental compliance. Data security appears as one component within that broader scope and does not include country-of-origin rules.

e-Stewards focuses on environmental protection and worker safety for electronics disposition. The standard also addresses data security, ethical labor practices, legal compliance and downstream accountability, but not country of origin.
NAID AAA, administered by the National Association for Information Destruction, sets the benchmark for secure data-bearing device destruction. It requires witnessed destruction, serial number verification, photographic evidence and unannounced facility inspections. It does not address country of origin.
A vendor can hold these certifications and still fail TAA requirements if country-of-origin and substantial-transformation standards are not met. A vendor can also meet TAA standards yet fall short on data security or environmental practices without these certifications. Premier Logitech addresses both dimensions with TAA compliance plus ISO 9001/14001, NIST, CMMC and SOC 2 alignment.
GSA MAS TAA Requirements for ITAD Contractors
GSA incorporates the required TAA clause into the MAS solicitation and resulting contracts. This structure obligates MAS contractors to provide only U.S.-made or TAA-designated country end products and services. MAS contractors must certify country of origin for each product, and GSA Advantage displays that information.
Misrepresenting country of origin creates False Claims Act exposure. False Claims Act liability can impose up to treble damages plus mandatory penalties currently set at a minimum of $14,308 and a maximum of $28,619 per false claim or invoice submitted, per 28 C.F.R. § 85.5.
The GSA deviation discussed earlier applies to all GSA acquisitions, including MAS and blanket purchase agreements. For new solicitations and resulting contracts, GSA contracting officers use the deviated FAR text and review items offered by AbilityOne and FPI for TAA compliance. GSA plans to issue a MAS modification incorporating these changes in Refresh #33, and contractors must accept the mass modification within 90 days. Orders issued before the effective date of the mass modification continue under the original terms.
Contractors update compliance files to reflect removal of the AbilityOne and FPI TAA exception, audit any IT asset disposition sourcing that relied on that exception and verify that current ITAD vendors can produce country-of-origin attestations and serial-level audit trails acceptable to a contracting officer.
Premier Logitech LLC’s CAGE Code 4WAJ9 is verifiable in SAM.gov and identifies the company as a registered federal contractor. A CAGE code or UEI alone does not prove active registration or eligibility, so contractors still review full compliance documentation. Premier Logitech’s TAA compliance and government-facing documentation practices are available during vendor evaluation.
Align ITAD Programs With GSA MAS TAA Requirements
Vendor Evaluation Checklist for TAA-Compliant IT Asset Disposition
This checklist supports evaluation of whether an ITAD vendor satisfies TAA country-of-origin obligations under FAR 52.225-5. Teams apply it during RFP evaluation and contract negotiation.
- Documented country-of-origin attestations from OEMs or suppliers naming specific SKUs and current manufacturing locations
- Serial-level asset traceability from intake through final disposition
- Segregation controls that physically and systemically separate TAA-eligible assets from non-TAA assets
- NIST SP 800-88 Revision 1-aligned data sanitization with documented logs and validation records
- Certificates of Destruction for all data-bearing media
- Downstream recycler certificates from R2v3, e-Stewards or NAID AAA certified partners, with verification that downstream partners do not reintroduce non-TAA sources
- GSA MAS country-of-origin certification, verifiable in SAM.gov and GSA Advantage
- CAGE Code verifiable in SAM.gov
- Audit-ready compliance reporting that a contracting officer would accept, including chain-of-custody documentation and segregation logs
- Alignment with ISO 9001/14001, NIST, CMMC and SOC 2 frameworks for secure handling
Premier Logitech meets these criteria. Premier Logitech holds TAA compliance, CAGE Code 4WAJ9, authorized service center status for more than 20 OEM brands and compliance reporting aligned to ISO, NIST and CMMC frameworks. Premier Logitech operates as a single-source lifecycle partner for programs that require verifiable TAA-compliant IT asset disposition.
Assess Vendor TAA Compliance Documentation
Conclusion and Next Steps for TAA-Compliant ITAD
TAA compliance functions as a country-of-origin and substantial-transformation requirement under FAR 52.225-5. Many ITAD offerings focus on data security alone, which leaves federal contractors without the audit-ready documentation a contracting officer expects.
The most actionable takeaways from this guide are the audit-ready documentation checklist and the impact of the August 2026 GSA class deviation on AbilityOne and FPI sourcing. Serial-level records, OEM attestations, segregation logs, Certificates of Destruction and downstream recycler certificates create a defensible compliance file.
Premier Logitech operates as a TAA-compliant IT lifecycle services and reverse logistics partner for government and enterprise programs. With TAA compliance, CAGE Code 4WAJ9, ISO 9001/14001, NIST, CMMC and SOC 2 alignment and authorized service center status for more than 20 OEM brands, Premier Logitech supports complex compliance requirements.
Recommended next steps include reviewing current ITAD contracts for country-of-origin documentation gaps, auditing segregation controls for non-TAA assets, updating compliance files to reflect the 2026 GSA class deviation and scheduling a call with Premier Logitech to assess TAA-compliant IT asset disposition readiness.
Assess TAA-Compliant IT Asset Disposition Readiness