Reference

Industry Standards & Certifications

Explore the comprehensive database of data center compliance standards, security certifications, and operational frameworks. Click any card to view full details.

Showing 1-12 of 91 standards

California Privacy Rights Act

CPRA

Compliance & Certification
California, United States

by California Privacy Protection Agency

Expands consumer privacy rights and creates dedicated enforcement agency.

All CCPA rights plus: Right to correct inaccurate dataRight to limit use of sensitive dataStricter opt-out requirements+1 more

SSAE 18 (Statement on Standards for Attestation Engagements No. 18)

SSAE 18

Compliance & Certification
United States

by American Institute of Certified Public Accountants (AICPA)

Provides framework for service organizations to report on controls relevant to user entities financial reporting.

Requires independent auditor examination of controls at service organizations, typically resulting in SOC 1, SOC 2, or SOC 3 reports.

Personal Data Protection Act

PDPA

Compliance & Certification
Singapore

by Personal Data Protection Commission Singapore

Governs collection, use, disclosure and care of personal data in Singapore.

Consent obligationPurpose limitationNotification+6 more

China Cybersecurity Law

CSL

Compliance & Certification
China

by Cyberspace Administration of China

Regulates cybersecurity and requires data localization for critical infrastructure sectors.

Critical information infrastructure must store data in ChinaSecurity assessment for cross-border transfersNetwork operator security obligations+2 more

Family Educational Rights and Privacy Act

FERPA

Compliance & Certification
United States

by US Department of Education

Gives parents and students rights regarding education records and limits disclosure without consent.

Student consent for disclosureParent/student access rightsRecord accuracy+3 more

Criminal Justice Information Services Security Policy

CJIS

Compliance & Certification
United States

by FBI Criminal Justice Information Services

Protects criminal justice information and ensures proper handling by authorized agencies.

13 security areas: Information exchange agreementsSecurity awareness trainingIncident response+9 more

General Data Protection Regulation

GDPR

Compliance & Certification
Europe

by European Union

Harmonizes data privacy laws across Europe and gives individuals control over their personal data.

Lawful processingConsentData subject rights+3 more

Lei Geral de Proteção de Dados

LGPD

Compliance & Certification
Brazil

by Brazilian National Data Protection Authority

Regulates processing of personal data in Brazil and protects fundamental rights of freedom and privacy.

Consent requirementsData subject rightsData protection officer+3 more

ISO/IEC 20000-1: IT Service Management

ISO 20000

Compliance & Certification
Global

by International Organization for Standardization

Demonstrates effective IT service management and service delivery processes.

Service management systemService deliveryRelationship processes+2 more

Vietnam Cybersecurity Law

Law No. 24/2018/QH14

Compliance & Certification
Vietnam

by Ministry of Public Security Vietnam

Regulates cybersecurity and requires data localization for service providers operating in Vietnam.

Personal data must be stored in VietnamDomestic service providers must maintain local serversForeign providers must establish local presence for certain services+1 more

SOC 1 Type II

SOC 1

Compliance & Certification
United States

by American Institute of CPAs

Provides assurance about controls at a service organization relevant to user entities' internal control over financial reporting.

Controls affecting financial reportingAudited over 6-12 monthsICFR (Internal Control over Financial Reporting)

NIST SP 800-53: Security and Privacy Controls

NIST 800-53

Compliance & Certification
United States

by National Institute of Standards and Technology

Provides controls to protect organizational operations, assets, individuals, and other organizations.

20 control familiesRisk management frameworkLow/Moderate/High baselines+1 more

SOC 2 Type II

SOC 2

Compliance & Certification
United States

by American Institute of CPAs

Provides assurance that service organizations securely manage data to protect organizational interests and privacy.

5 Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, PrivacyAudited over 6-12 months

COBIT: Control Objectives for Information and Related Technologies

COBIT

Compliance & Certification
Global

by ISACA

Helps enterprises govern and manage IT to achieve strategic objectives.

Governance frameworkManagement objectivesProcess capabilities+2 more

FedRAMP Low

FedRAMP

Compliance & Certification
United States

by General Services Administration

Minimum security requirements for federal cloud services processing public or low-impact information.

125 security controls from NIST 800-53Annual assessmentsLow impact data

Health Information Technology for Economic and Clinical Health Act

HITECH

Compliance & Certification
United States

by US Department of Health & Human Services

Promotes adoption of health IT while strengthening privacy and security protections.

Breach notification requirementsEnhanced penaltiesBusiness associate liability+2 more

ISO 22301: Business Continuity Management

ISO 22301

Compliance & Certification
Global

by International Organization for Standardization

Helps organizations prepare for, respond to, and recover from disruptive incidents.

Business continuity policyRisk assessmentBusiness impact analysis+3 more

ISO 9001: Quality Management

ISO 9001

Compliance & Certification
Global

by International Organization for Standardization

Ensures organizations consistently provide products and services that meet customer and regulatory requirements.

Customer focusLeadershipPeople engagement+4 more

ITIL: Information Technology Infrastructure Library

ITIL

Compliance & Certification
Global

by Axelos

Provides comprehensive guidance for establishing, operating, and continuously improving IT service management.

Service strategyService designService transition+2 more

NFPA 75: Standard for Protection of IT Equipment

NFPA 75

Compliance & Certification
Global

by National Fire Protection Association

Minimizes fire hazards and ensures safe operation of IT equipment.

Fire detection and suppressionEnvironmental controlsElectrical systems+1 more

Health Insurance Portability and Accountability Act

HIPAA

Compliance & Certification
United States

by US Department of Health & Human Services

Protects the privacy and security of healthcare information and establishes national standards.

Privacy Rule (PHI protection)Security Rule (administrative, physical, technical safeguards)Breach Notification Rule

SOC 3

SOC 3

Compliance & Certification
United States

by American Institute of CPAs

Provides public assurance about security and availability controls without disclosing details.

Trust Service CriteriaAuditor opinion onlyNo detailed testing+1 more

Federal Information Security Management Act

FISMA

Compliance & Certification
United States

by National Institute of Standards and Technology

Establishes framework for securing federal government information, operations, and assets against threats.

Risk-based approachContinuous monitoringNIST standards compliance+2 more

FedRAMP High

FedRAMP

Compliance & Certification
United States

by General Services Administration

Maximum security requirements for systems processing sensitive federal data.

421 security controls from NIST 800-53Continuous monitoringQuarterly assessments+1 more

International Traffic in Arms Regulations

ITAR

Compliance & Certification
United States

by US Department of State

Controls access to defense and military technologies to protect US national security.

US Person access onlyPhysical and logical access controlsData cannot leave US without license+3 more

Gramm-Leach-Bliley Act

GLBA

Compliance & Certification
United States

by Federal Trade Commission

Requires financial institutions to explain information-sharing practices and safeguard sensitive data.

Financial Privacy RuleSafeguards RulePretexting provisions+3 more

Sarbanes-Oxley Act

SOX

Compliance & Certification
United States

by US Securities and Exchange Commission

Protects investors by improving accuracy and reliability of corporate disclosures.

Section 302: CEO/CFO certificationSection 404: Internal controls assessmentSection 802: Record retention+4 more

Russian Data Localization Law

Federal Law No. 242-FZ

Compliance & Certification
Russia

by Russian Federation

Ensures Russian citizens' personal data is stored within Russian territory for government access and control.

Personal data must be recorded, systematized, accumulated, stored, clarified, and extracted using databases located in RussiaCross-border transfer restrictionsMandatory local storage

National Security Framework

ENS

Compliance & Certification
Spain

by Spanish National Cryptologic Center

Establishes security policy for use of electronic means in Spanish public administration.

Security framework based on: OrganizationOperational frameworkProtection measures+3 more

Act on the Protection of Personal Information

APPI

Compliance & Certification
Japan

by Personal Information Protection Commission Japan

Protects rights and interests of individuals while promoting effective use of personal information.

Purpose specificationProper acquisitionAccurate maintenance+4 more

Personal Information Protection and Electronic Documents Act

PIPEDA

Compliance & Certification
Canada

by Office of the Privacy Commissioner of Canada

Sets ground rules for how private sector organizations collect, use and disclose personal information.

10 Fair Information Principles: AccountabilityIdentifying purposesConsent+7 more

FedRAMP Moderate

FedRAMP

Compliance & Certification
United States

by General Services Administration

Standard authorization level for most federal cloud services.

325 security controls from NIST 800-53Continuous monitoringAnnual assessments

Indonesia Data Localization Regulation

GR 71/2019

Compliance & Certification
Indonesia

by Ministry of Communication and Information Technology Indonesia

Ensures data sovereignty and supports development of local data center industry.

Data centers must be located in IndonesiaDisaster recovery sites must be in IndonesiaApplies to public service providers and critical sectors+1 more

California Consumer Privacy Act

CCPA

Compliance & Certification
California, United States

by California Attorney General

Gives California consumers rights to know, delete, and opt-out of sale of their personal information.

Right to know data collectedRight to deleteRight to opt-out of sale+2 more

Protection of Personal Information Act

POPIA

Compliance & Certification
South Africa

by Information Regulator South Africa

Promotes protection of personal information processed by public and private bodies.

8 Conditions: AccountabilityProcessing limitationPurpose specification+5 more

NFPA 70: National Electrical Code

NEC

Compliance & Certification
Global

by National Fire Protection Association

Protects people and property from electrical hazards.

Wiring and protectionEquipmentSpecial occupancies+2 more

Payment Card Industry Data Security Standard

PCI DSS

Compliance & Certification
Global

by PCI Security Standards Council

Reduces credit card fraud by establishing minimum security requirements for storing, processing, and transmitting cardholder data.

12 requirements: FirewallsStrong passwordsProtect cardholder data+9 more

Carrier Neutral Certified

Carrier Neutral

Connectivity & Networking

by Various

Ensures customers have choice in network providers and prevents vendor lock-in.

Multiple carrier accessNo exclusive agreementsMeet-me room+1 more

Cloud On-Ramp Certified

Cloud On-Ramp

Connectivity & Networking

by Various Cloud Providers

Provides low-latency, high-bandwidth private connections to cloud platforms.

AWS Direct ConnectAzure ExpressRouteGoogle Cloud Interconnect+1 more

ISO 14001: Environmental Management

ISO 14001

Environmental & Sustainability
Global

by International Organization for Standardization

Helps organizations improve environmental performance through more efficient resource use and waste reduction.

Environmental policyPlanningImplementation+3 more

BREEAM Excellent

BREEAM

Environmental & Sustainability
United Kingdom

by Building Research Establishment

Demonstrates exemplary performance significantly better than standard practice.

70-84% scoreExemplary environmental practices and innovation

BREEAM Outstanding

BREEAM

Environmental & Sustainability
United Kingdom

by Building Research Establishment

Recognizes world-leading sustainable building design and operation.

85%+ scoreBest-in-class environmental performance and innovation across all categories

LEED Certified

LEED

Environmental & Sustainability
United States

by US Green Building Council

Recognizes basic sustainable building practices.

40-49 points across LEED categoriesBasic sustainability measures

LEED Gold

LEED

Environmental & Sustainability
United States

by US Green Building Council

Recognizes best-in-class building strategies and practices for environmental performance.

60-79 points across: Sustainable sitesWater efficiencyEnergy & atmosphere+4 more

ENERGY STAR Certified

ENERGY STAR

Environmental & Sustainability
United States

by US Environmental Protection Agency

Identifies buildings that use significantly less energy than typical buildings.

Must score 75 or higher on EPA 1-100 scaleTop 25% energy performance nationallyVerified by licensed professional

BREEAM Pass

BREEAM

Environmental & Sustainability
United Kingdom

by Building Research Establishment

Leading European sustainability assessment method for buildings, widely used in UK and Europe.

30-44% score across: ManagementHealth & wellbeingEnergy+7 more

ASHRAE Standard 90.4: Energy Standard for Data Centers

ASHRAE 90.4

Environmental & Sustainability
Global

by American Society of Heating, Refrigerating and Air-Conditioning Engineers

Provides minimum energy efficiency requirements for the design of new data centers and major renovations.

IT equipmentPower deliveryCooling systems+3 more

LEED Platinum

LEED

Environmental & Sustainability
United States

by US Green Building Council

Recognizes world-class sustainable building design and operation.

80+ points across all LEED categoriesExceptional performance in energy efficiency, water conservation, and environmental impact

EU Code of Conduct for Data Centre Energy Efficiency

EU CoC

Environmental & Sustainability
Europe

by European Commission

Encourages data center operators and owners to reduce energy consumption through best practices.

PUE targetsBest practicesEnergy management+2 more

BREEAM Very Good

BREEAM

Environmental & Sustainability
United Kingdom

by Building Research Establishment

Represents advanced good practice in sustainable building design.

55-69% scoreAdvanced environmental design and management practices

LEED (Leadership in Energy and Environmental Design)

LEED

Environmental & Sustainability
United States

by U.S. Green Building Council (USGBC)

Certifies buildings that meet high standards for environmental performance including energy efficiency, water conservation, and indoor environmental quality.

Energy efficiency metricsRenewable energy integrationWater conservation strategies+5 more

BREEAM Good

BREEAM

Environmental & Sustainability
United Kingdom

by Building Research Establishment

Demonstrates above-average sustainability performance in building design and operation.

45-54% score across all BREEAM categoriesGood practice environmental design

LEED Silver

LEED

Environmental & Sustainability
United States

by US Green Building Council

Demonstrates strong commitment to sustainability above basic certification.

50-59 points across LEED categoriesEnhanced sustainable practices

ASHRAE Standard 90.1: Energy Standard for Buildings

ASHRAE 90.1

Environmental & Sustainability
Global

by American Society of Heating, Refrigerating and Air-Conditioning Engineers

Establishes minimum energy efficiency requirements for buildings except low-rise residential buildings.

Building envelopeHVACService water heating+3 more

ISO 50001: Energy Management

ISO 50001

Environmental & Sustainability
Global

by International Organization for Standardization

Framework for developing energy management systems to improve energy efficiency and reduce costs.

Energy policyPlanningImplementation+4 more

ISO/IEC 27039: Intrusion Detection and Prevention

ISO 27039

Security & Access Control
Global

by International Organization for Standardization

Provides guidance on selection, deployment, and operations of IDPS.

IDPS selectionDeploymentConfiguration+2 more

Information Security Registered Assessors Program

IRAP

Security & Access Control
Australia

by Australian Cyber Security Centre

Provides independent assessment of ICT systems against Australian Government security requirements.

Security assessment by IRAP assessorCompliance with ISM (Information Security Manual)Risk management+2 more

CSA STAR Level 2: Third-Party Audit

CSA STAR

Security & Access Control
Global

by Cloud Security Alliance

Demonstrates rigorous third-party validation of cloud security practices.

Third-party auditISO 27001 or SOC 2 basedCCM assessment+1 more

ISO/IEC 27002: Information Security Controls

ISO 27002

Security & Access Control
Global

by International Organization for Standardization

Provides guidance on selecting, implementing, and managing information security controls.

114 security controls across 14 categoriesBest practice guidanceControl implementation

Cloud Computing Compliance Controls Catalogue

C5

Security & Access Control
Germany

by German Federal Office for Information Security

Creates transparency and comparability for cloud service security assessments in Germany.

114 security requirements across 17 domainsOrganization of information securityCompliance+10 more

CSA STAR Level 3: Continuous Monitoring

CSA STAR

Security & Access Control
Global

by Cloud Security Alliance

Provides ongoing assurance through automated security control monitoring.

Continuous monitoringReal-time security postureAutomated validation+1 more

ISO/IEC 27017: Cloud Security

ISO 27017

Security & Access Control
Global

by International Organization for Standardization

Extends ISO 27001 with cloud-specific security guidance for providers and customers.

Cloud-specific security controlsShared responsibility modelVirtual machine hardening+1 more

Cyber Security Mark

CS Mark

Security & Access Control
Singapore

by Cyber Security Agency of Singapore

Helps consumers identify products with better cybersecurity provisions.

4 security levelsDevice securityData protection+2 more

ISO/IEC 27701: Privacy Information Management

ISO 27701

Security & Access Control
Global

by International Organization for Standardization

Helps organizations demonstrate GDPR compliance and establish a privacy management framework.

Privacy controlsData subject rightsPrivacy by design+2 more

Korea Information Security Management System

K-ISMS

Security & Access Control
South Korea

by Korea Internet & Security Agency

Demonstrates systematic information security management for Korean organizations and cloud providers.

5 domains, 16 controls, 104 items: Management processProtection measuresPhysical security+2 more

NIST Cybersecurity Framework

NIST CSF

Security & Access Control
United States

by National Institute of Standards and Technology

Provides voluntary framework for managing and reducing cybersecurity risk.

5 Functions: Identify, Protect, Detect, Respond, RecoverRisk-based approachIndustry agnostic

CSA STAR Level 1: Self-Assessment

CSA STAR

Security & Access Control
Global

by Cloud Security Alliance

Provides baseline documentation of security controls for cloud service providers.

Self-assessmentCCM questionnairePublicly listed+1 more

ISO/IEC 27001: Information Security Management

ISO 27001

Security & Access Control
Global

by International Organization for Standardization

Provides framework for managing sensitive company and customer information to keep it secure.

Risk assessment and treatmentSecurity policyAccess control+4 more

Cyber Essentials

Cyber Essentials

Security & Access Control
United Kingdom

by National Cyber Security Centre UK

Demonstrates commitment to cyber security and provides baseline protection against common attacks.

5 technical controls: FirewallsSecure configurationUser access control+2 more

Multi-Tier Cloud Security Singapore

MTCS

Security & Access Control
Singapore

by Infocomm Media Development Authority Singapore

Provides standardized security assessment for cloud service providers in Singapore.

3 security levels based on data sensitivityRisk assessmentSecurity controls+1 more

Cyber Essentials Plus

Cyber Essentials Plus

Security & Access Control
United Kingdom

by National Cyber Security Centre UK

Provides higher assurance through independent technical testing of security controls.

All Cyber Essentials requirements plus: Hands-on technical verificationVulnerability scanningConfiguration testing+1 more

ISO/IEC 27018: PII Protection in Cloud

ISO 27018

Security & Access Control
Global

by International Organization for Standardization

Establishes controls and guidelines for protecting PII processed by cloud service providers.

PII protection controlsConsent managementTransparency of PII processing+1 more

Tier Standard: Operational Sustainability

TSOS

Uptime & Reliability
Global

by Uptime Institute

Ensures facilities maintain design tier performance through proper operations, maintenance, and management.

Operational proceduresStaff trainingChange management+3 more

Tier II: Redundant Capacity Components

Tier II

Uptime & Reliability
Global

by Uptime Institute

Adds redundant components to reduce risk of disruption from equipment failure.

Single power and cooling distribution pathRedundant components (N+1)Partial immunity to disruption+1 more

TIA-942 Rated-2

TIA-942

Uptime & Reliability
Global

by Telecommunications Industry Association

Ensures redundant components to improve availability over Rated-1.

Single distribution pathRedundant components (N+1)Improved reliability

TIA-942 Rated-4

TIA-942

Uptime & Reliability
Global

by Telecommunications Industry Association

Provides fault tolerance to withstand any single failure without impacting operations.

Multiple active paths2N redundancyFault tolerant+1 more

TIA-942 Rated-1

TIA-942

Uptime & Reliability
Global

by Telecommunications Industry Association

Provides minimum requirements for data center design and infrastructure topology.

Single path distributionNo redundancyBasic infrastructure requirements

Tier Standard: Management & Operations Stamp of Approval

M&O Stamp

Uptime & Reliability
Global

by Uptime Institute

Validates that facility operations match the rigor and discipline of the Tier design certification.

Staffing and organizationMaintenanceTraining+5 more

Uptime Institute Tier II - Design

Tier II Design

Uptime & Reliability
Global

by Uptime Institute

Certifies that facility design provides redundant capacity components for 99.741% availability.

Redundant power infrastructure (N+1)Single distribution path topologyCooling system component redundancy+5 more

Uptime Institute Tier I - Constructed Facility

Tier I Facility

Uptime & Reliability
Global

by Uptime Institute

Validates that the as-built facility achieves 99.671% availability per Tier I requirements.

Redundant power distributionSingle path cooling infrastructureNon-critical system topology+4 more

Uptime Institute Tier III - Design

Tier III Design

Uptime & Reliability
Global

by Uptime Institute

Certifies that facility design allows maintenance without shutdown, providing 99.982% availability.

Concurrent maintenance pathsSingle active distribution pathN+1 redundancy components+5 more

Uptime Institute Tier IV - Design

Tier IV Design

Uptime & Reliability
Global

by Uptime Institute

Certifies that facility design is fault-tolerant with no single point of failure, providing 99.995% availability.

Multiple independent power distribution pathsN+1 cooling redundancyConcurrent maintainability+5 more

Uptime Institute Tier I - Design

Tier I Design

Uptime & Reliability
Global

by Uptime Institute

Certifies that facility design meets minimum requirements for a basic data center with 99.671% availability.

Single power distribution pathSingle cooling distribution pathNo redundant infrastructure components+5 more

Uptime Institute Tier IV - Constructed Facility

Tier IV Facility

Uptime & Reliability
Global

by Uptime Institute

Validates that the as-built facility achieves 99.995% availability with fully fault-tolerant infrastructure.

Redundant power distributionFault-tolerant electrical infrastructureIndependent cooling systems+5 more

Uptime Institute Tier II - Constructed Facility

Tier II Facility

Uptime & Reliability
Global

by Uptime Institute

Validates that the as-built facility achieves 99.741% availability with N+1 redundancy.

Redundant power infrastructureConcurrent maintainability of componentsElectrical system N+1 design+5 more

Uptime Institute Tier III - Constructed Facility

Tier III Facility

Uptime & Reliability
Global

by Uptime Institute

Validates that the as-built facility achieves 99.982% availability with concurrently maintainable infrastructure.

Concurrent maintenance capabilityN+1 redundant infrastructureFault tolerance without service interruption+5 more

TIA-942 Rated-3

TIA-942

Uptime & Reliability
Global

by Telecommunications Industry Association

Enables maintenance activities without service disruption through concurrent maintainability.

Multiple distribution pathsN+1 redundancyConcurrently maintainable

BICSI 002: Data Center Design

BICSI 002

Uptime & Reliability
Global

by BICSI

Provides best practices for planning, designing, and implementing data center infrastructure.

Site selectionArchitecturePower+5 more

Tier III: Concurrently Maintainable

Tier III

Uptime & Reliability
Global

by Uptime Institute

Enables planned maintenance without impacting IT operations through redundant capacity and distribution paths.

Multiple power and cooling paths (one active)Concurrently maintainableN+1 redundancy+1 more

Tier IV: Fault Tolerant

Tier IV

Uptime & Reliability
Global

by Uptime Institute

Provides fault tolerance to prevent any single failure from impacting IT load, including maintenance activities.

Multiple active power and cooling paths2N+1 redundancyFault tolerant+2 more

Tier I: Basic Capacity

Tier I

Uptime & Reliability
Global

by Uptime Institute

Provides basic infrastructure capacity for non-critical IT operations with planned downtime for maintenance.

Single path for power and coolingNon-redundant componentsSusceptible to disruptions from planned and unplanned events+1 more