Reference
Industry Standards & Certifications
Explore the comprehensive database of data center compliance standards, security certifications, and operational frameworks. Click any card to view full details.
Showing 1-12 of 91 standards
California Privacy Rights Act
CPRA
by California Privacy Protection Agency
Purpose
Expands consumer privacy rights and creates dedicated enforcement agency.
Requirements Overview
SSAE 18 (Statement on Standards for Attestation Engagements No. 18)
SSAE 18
by American Institute of Certified Public Accountants (AICPA)
Purpose
Provides framework for service organizations to report on controls relevant to user entities financial reporting.
Requirements Overview
Personal Data Protection Act
PDPA
by Personal Data Protection Commission Singapore
Purpose
Governs collection, use, disclosure and care of personal data in Singapore.
Requirements Overview
China Cybersecurity Law
CSL
by Cyberspace Administration of China
Purpose
Regulates cybersecurity and requires data localization for critical infrastructure sectors.
Requirements Overview
Family Educational Rights and Privacy Act
FERPA
by US Department of Education
Purpose
Gives parents and students rights regarding education records and limits disclosure without consent.
Requirements Overview
Criminal Justice Information Services Security Policy
CJIS
by FBI Criminal Justice Information Services
Purpose
Protects criminal justice information and ensures proper handling by authorized agencies.
Requirements Overview
General Data Protection Regulation
GDPR
by European Union
Purpose
Harmonizes data privacy laws across Europe and gives individuals control over their personal data.
Requirements Overview
Lei Geral de Proteção de Dados
LGPD
by Brazilian National Data Protection Authority
Purpose
Regulates processing of personal data in Brazil and protects fundamental rights of freedom and privacy.
Requirements Overview
ISO/IEC 20000-1: IT Service Management
ISO 20000
by International Organization for Standardization
Purpose
Demonstrates effective IT service management and service delivery processes.
Requirements Overview
Vietnam Cybersecurity Law
Law No. 24/2018/QH14
by Ministry of Public Security Vietnam
Purpose
Regulates cybersecurity and requires data localization for service providers operating in Vietnam.
Requirements Overview
SOC 1 Type II
SOC 1
by American Institute of CPAs
Purpose
Provides assurance about controls at a service organization relevant to user entities' internal control over financial reporting.
Requirements Overview
NIST SP 800-53: Security and Privacy Controls
NIST 800-53
by National Institute of Standards and Technology
Purpose
Provides controls to protect organizational operations, assets, individuals, and other organizations.
Requirements Overview
SOC 2 Type II
SOC 2
by American Institute of CPAs
Purpose
Provides assurance that service organizations securely manage data to protect organizational interests and privacy.
Requirements Overview
COBIT: Control Objectives for Information and Related Technologies
COBIT
by ISACA
Purpose
Helps enterprises govern and manage IT to achieve strategic objectives.
Requirements Overview
FedRAMP Low
FedRAMP
by General Services Administration
Purpose
Minimum security requirements for federal cloud services processing public or low-impact information.
Requirements Overview
Health Information Technology for Economic and Clinical Health Act
HITECH
by US Department of Health & Human Services
Purpose
Promotes adoption of health IT while strengthening privacy and security protections.
Requirements Overview
ISO 22301: Business Continuity Management
ISO 22301
by International Organization for Standardization
Purpose
Helps organizations prepare for, respond to, and recover from disruptive incidents.
Requirements Overview
ISO 9001: Quality Management
ISO 9001
by International Organization for Standardization
Purpose
Ensures organizations consistently provide products and services that meet customer and regulatory requirements.
Requirements Overview
ITIL: Information Technology Infrastructure Library
ITIL
by Axelos
Purpose
Provides comprehensive guidance for establishing, operating, and continuously improving IT service management.
Requirements Overview
NFPA 75: Standard for Protection of IT Equipment
NFPA 75
by National Fire Protection Association
Purpose
Minimizes fire hazards and ensures safe operation of IT equipment.
Requirements Overview
Health Insurance Portability and Accountability Act
HIPAA
by US Department of Health & Human Services
Purpose
Protects the privacy and security of healthcare information and establishes national standards.
Requirements Overview
SOC 3
SOC 3
by American Institute of CPAs
Purpose
Provides public assurance about security and availability controls without disclosing details.
Requirements Overview
Federal Information Security Management Act
FISMA
by National Institute of Standards and Technology
Purpose
Establishes framework for securing federal government information, operations, and assets against threats.
Requirements Overview
FedRAMP High
FedRAMP
by General Services Administration
Purpose
Maximum security requirements for systems processing sensitive federal data.
Requirements Overview
International Traffic in Arms Regulations
ITAR
by US Department of State
Purpose
Controls access to defense and military technologies to protect US national security.
Requirements Overview
Gramm-Leach-Bliley Act
GLBA
by Federal Trade Commission
Purpose
Requires financial institutions to explain information-sharing practices and safeguard sensitive data.
Requirements Overview
Sarbanes-Oxley Act
SOX
by US Securities and Exchange Commission
Purpose
Protects investors by improving accuracy and reliability of corporate disclosures.
Requirements Overview
Russian Data Localization Law
Federal Law No. 242-FZ
by Russian Federation
Purpose
Ensures Russian citizens' personal data is stored within Russian territory for government access and control.
Requirements Overview
National Security Framework
ENS
by Spanish National Cryptologic Center
Purpose
Establishes security policy for use of electronic means in Spanish public administration.
Requirements Overview
Act on the Protection of Personal Information
APPI
by Personal Information Protection Commission Japan
Purpose
Protects rights and interests of individuals while promoting effective use of personal information.
Requirements Overview
Personal Information Protection and Electronic Documents Act
PIPEDA
by Office of the Privacy Commissioner of Canada
Purpose
Sets ground rules for how private sector organizations collect, use and disclose personal information.
Requirements Overview
FedRAMP Moderate
FedRAMP
by General Services Administration
Purpose
Standard authorization level for most federal cloud services.
Requirements Overview
Indonesia Data Localization Regulation
GR 71/2019
by Ministry of Communication and Information Technology Indonesia
Purpose
Ensures data sovereignty and supports development of local data center industry.
Requirements Overview
California Consumer Privacy Act
CCPA
by California Attorney General
Purpose
Gives California consumers rights to know, delete, and opt-out of sale of their personal information.
Requirements Overview
Protection of Personal Information Act
POPIA
by Information Regulator South Africa
Purpose
Promotes protection of personal information processed by public and private bodies.
Requirements Overview
NFPA 70: National Electrical Code
NEC
by National Fire Protection Association
Purpose
Protects people and property from electrical hazards.
Requirements Overview
Payment Card Industry Data Security Standard
PCI DSS
by PCI Security Standards Council
Purpose
Reduces credit card fraud by establishing minimum security requirements for storing, processing, and transmitting cardholder data.
Requirements Overview
Carrier Neutral Certified
Carrier Neutral
by Various
Purpose
Ensures customers have choice in network providers and prevents vendor lock-in.
Requirements Overview
Cloud On-Ramp Certified
Cloud On-Ramp
by Various Cloud Providers
Purpose
Provides low-latency, high-bandwidth private connections to cloud platforms.
Requirements Overview
ISO 14001: Environmental Management
ISO 14001
by International Organization for Standardization
Purpose
Helps organizations improve environmental performance through more efficient resource use and waste reduction.
Requirements Overview
BREEAM Excellent
BREEAM
by Building Research Establishment
Purpose
Demonstrates exemplary performance significantly better than standard practice.
Requirements Overview
BREEAM Outstanding
BREEAM
by Building Research Establishment
Purpose
Recognizes world-leading sustainable building design and operation.
Requirements Overview
LEED Certified
LEED
by US Green Building Council
Purpose
Recognizes basic sustainable building practices.
Requirements Overview
LEED Gold
LEED
by US Green Building Council
Purpose
Recognizes best-in-class building strategies and practices for environmental performance.
Requirements Overview
ENERGY STAR Certified
ENERGY STAR
by US Environmental Protection Agency
Purpose
Identifies buildings that use significantly less energy than typical buildings.
Requirements Overview
BREEAM Pass
BREEAM
by Building Research Establishment
Purpose
Leading European sustainability assessment method for buildings, widely used in UK and Europe.
Requirements Overview
ASHRAE Standard 90.4: Energy Standard for Data Centers
ASHRAE 90.4
by American Society of Heating, Refrigerating and Air-Conditioning Engineers
Purpose
Provides minimum energy efficiency requirements for the design of new data centers and major renovations.
Requirements Overview
LEED Platinum
LEED
by US Green Building Council
Purpose
Recognizes world-class sustainable building design and operation.
Requirements Overview
EU Code of Conduct for Data Centre Energy Efficiency
EU CoC
by European Commission
Purpose
Encourages data center operators and owners to reduce energy consumption through best practices.
Requirements Overview
BREEAM Very Good
BREEAM
by Building Research Establishment
Purpose
Represents advanced good practice in sustainable building design.
Requirements Overview
LEED (Leadership in Energy and Environmental Design)
LEED
by U.S. Green Building Council (USGBC)
Purpose
Certifies buildings that meet high standards for environmental performance including energy efficiency, water conservation, and indoor environmental quality.
Requirements Overview
BREEAM Good
BREEAM
by Building Research Establishment
Purpose
Demonstrates above-average sustainability performance in building design and operation.
Requirements Overview
LEED Silver
LEED
by US Green Building Council
Purpose
Demonstrates strong commitment to sustainability above basic certification.
Requirements Overview
ASHRAE Standard 90.1: Energy Standard for Buildings
ASHRAE 90.1
by American Society of Heating, Refrigerating and Air-Conditioning Engineers
Purpose
Establishes minimum energy efficiency requirements for buildings except low-rise residential buildings.
Requirements Overview
ISO 50001: Energy Management
ISO 50001
by International Organization for Standardization
Purpose
Framework for developing energy management systems to improve energy efficiency and reduce costs.
Requirements Overview
ISO/IEC 27039: Intrusion Detection and Prevention
ISO 27039
by International Organization for Standardization
Purpose
Provides guidance on selection, deployment, and operations of IDPS.
Requirements Overview
Information Security Registered Assessors Program
IRAP
by Australian Cyber Security Centre
Purpose
Provides independent assessment of ICT systems against Australian Government security requirements.
Requirements Overview
CSA STAR Level 2: Third-Party Audit
CSA STAR
by Cloud Security Alliance
Purpose
Demonstrates rigorous third-party validation of cloud security practices.
Requirements Overview
ISO/IEC 27002: Information Security Controls
ISO 27002
by International Organization for Standardization
Purpose
Provides guidance on selecting, implementing, and managing information security controls.
Requirements Overview
Cloud Computing Compliance Controls Catalogue
C5
by German Federal Office for Information Security
Purpose
Creates transparency and comparability for cloud service security assessments in Germany.
Requirements Overview
CSA STAR Level 3: Continuous Monitoring
CSA STAR
by Cloud Security Alliance
Purpose
Provides ongoing assurance through automated security control monitoring.
Requirements Overview
ISO/IEC 27017: Cloud Security
ISO 27017
by International Organization for Standardization
Purpose
Extends ISO 27001 with cloud-specific security guidance for providers and customers.
Requirements Overview
Cyber Security Mark
CS Mark
by Cyber Security Agency of Singapore
Purpose
Helps consumers identify products with better cybersecurity provisions.
Requirements Overview
ISO/IEC 27701: Privacy Information Management
ISO 27701
by International Organization for Standardization
Purpose
Helps organizations demonstrate GDPR compliance and establish a privacy management framework.
Requirements Overview
Korea Information Security Management System
K-ISMS
by Korea Internet & Security Agency
Purpose
Demonstrates systematic information security management for Korean organizations and cloud providers.
Requirements Overview
NIST Cybersecurity Framework
NIST CSF
by National Institute of Standards and Technology
Purpose
Provides voluntary framework for managing and reducing cybersecurity risk.
Requirements Overview
CSA STAR Level 1: Self-Assessment
CSA STAR
by Cloud Security Alliance
Purpose
Provides baseline documentation of security controls for cloud service providers.
Requirements Overview
ISO/IEC 27001: Information Security Management
ISO 27001
by International Organization for Standardization
Purpose
Provides framework for managing sensitive company and customer information to keep it secure.
Requirements Overview
Cyber Essentials
Cyber Essentials
by National Cyber Security Centre UK
Purpose
Demonstrates commitment to cyber security and provides baseline protection against common attacks.
Requirements Overview
Multi-Tier Cloud Security Singapore
MTCS
by Infocomm Media Development Authority Singapore
Purpose
Provides standardized security assessment for cloud service providers in Singapore.
Requirements Overview
Cyber Essentials Plus
Cyber Essentials Plus
by National Cyber Security Centre UK
Purpose
Provides higher assurance through independent technical testing of security controls.
Requirements Overview
ISO/IEC 27018: PII Protection in Cloud
ISO 27018
by International Organization for Standardization
Purpose
Establishes controls and guidelines for protecting PII processed by cloud service providers.
Requirements Overview
Tier Standard: Operational Sustainability
TSOS
by Uptime Institute
Purpose
Ensures facilities maintain design tier performance through proper operations, maintenance, and management.
Requirements Overview
Tier II: Redundant Capacity Components
Tier II
by Uptime Institute
Purpose
Adds redundant components to reduce risk of disruption from equipment failure.
Requirements Overview
TIA-942 Rated-2
TIA-942
by Telecommunications Industry Association
Purpose
Ensures redundant components to improve availability over Rated-1.
Requirements Overview
TIA-942 Rated-4
TIA-942
by Telecommunications Industry Association
Purpose
Provides fault tolerance to withstand any single failure without impacting operations.
Requirements Overview
TIA-942 Rated-1
TIA-942
by Telecommunications Industry Association
Purpose
Provides minimum requirements for data center design and infrastructure topology.
Requirements Overview
Tier Standard: Management & Operations Stamp of Approval
M&O Stamp
by Uptime Institute
Purpose
Validates that facility operations match the rigor and discipline of the Tier design certification.
Requirements Overview
Uptime Institute Tier II - Design
Tier II Design
by Uptime Institute
Purpose
Certifies that facility design provides redundant capacity components for 99.741% availability.
Requirements Overview
Uptime Institute Tier I - Constructed Facility
Tier I Facility
by Uptime Institute
Purpose
Validates that the as-built facility achieves 99.671% availability per Tier I requirements.
Requirements Overview
Uptime Institute Tier III - Design
Tier III Design
by Uptime Institute
Purpose
Certifies that facility design allows maintenance without shutdown, providing 99.982% availability.
Requirements Overview
Uptime Institute Tier IV - Design
Tier IV Design
by Uptime Institute
Purpose
Certifies that facility design is fault-tolerant with no single point of failure, providing 99.995% availability.
Requirements Overview
Uptime Institute Tier I - Design
Tier I Design
by Uptime Institute
Purpose
Certifies that facility design meets minimum requirements for a basic data center with 99.671% availability.
Requirements Overview
Uptime Institute Tier IV - Constructed Facility
Tier IV Facility
by Uptime Institute
Purpose
Validates that the as-built facility achieves 99.995% availability with fully fault-tolerant infrastructure.
Requirements Overview
Uptime Institute Tier II - Constructed Facility
Tier II Facility
by Uptime Institute
Purpose
Validates that the as-built facility achieves 99.741% availability with N+1 redundancy.
Requirements Overview
Uptime Institute Tier III - Constructed Facility
Tier III Facility
by Uptime Institute
Purpose
Validates that the as-built facility achieves 99.982% availability with concurrently maintainable infrastructure.
Requirements Overview
TIA-942 Rated-3
TIA-942
by Telecommunications Industry Association
Purpose
Enables maintenance activities without service disruption through concurrent maintainability.
Requirements Overview
BICSI 002: Data Center Design
BICSI 002
by BICSI
Purpose
Provides best practices for planning, designing, and implementing data center infrastructure.
Requirements Overview
Tier III: Concurrently Maintainable
Tier III
by Uptime Institute
Purpose
Enables planned maintenance without impacting IT operations through redundant capacity and distribution paths.
Requirements Overview
Tier IV: Fault Tolerant
Tier IV
by Uptime Institute
Purpose
Provides fault tolerance to prevent any single failure from impacting IT load, including maintenance activities.
Requirements Overview
Tier I: Basic Capacity
Tier I
by Uptime Institute
Purpose
Provides basic infrastructure capacity for non-critical IT operations with planned downtime for maintenance.
Requirements Overview
No standards found. Try adjusting your search or filter criteria.