← Data centres
ISO 27001 and SOC 2 for Data Centres and Colocation
Data centre and colocation operators are assessed largely on the controls their customers cannot see and must rely upon. The report exists to be handed to customers’ auditors, which makes the complementary user entity controls section commercially important rather than boilerplate.
What ISO 27001 & SOC 2 requires of data centres
- Physical and environmental controls evidenced to a depth most ISMS scopes never reach — access, power, cooling, fire suppression.
- Clear articulation of complementary user entity controls so customer auditors know what remains their responsibility.
- Availability commitments evidenced by actual uptime and maintenance records against SLA.
- Access governance covering engineers, contractors and customer personnel entering halls.
- Sub-service treatment where connectivity or managed services are provided by others.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Physical access logs reconciled with authorised-personnel lists
- Environmental monitoring and maintenance records
- Uptime evidence against SLA commitments
- Visitor and contractor escort records
- Documented complementary user entity controls in the report
Where data centres usually come unstuck
- An ISMS scope that covers corporate IT but treats the halls as out of scope.
- Customer personnel access managed informally at the front desk.
- Complementary controls written so vaguely that customer auditors reject them.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
