ciso.diy
Data Center Assessment Kit preview
Vendor Risk data centerdata centrecolocationdata residency

Data Center Assessment Kit

Where your data physically lives — at rest, in transit and in backup — and what sits next to it. One data centre and colocation assessment across colo, cloud regions, hosted private, edge and air-gapped estates, merging EN 50600, SOC 2 and ISO 27001 with the residency regimes and the 2026 tenancy risks.

What this actually gives you

  • Residency breaks in the backup — an EU-only contract satisfied at rest and broken by the US DR copy. The register tracks at rest, in transit and in backup separately, and the engine resolves each placement on its own.
  • Data centre operators are NIS2 essential entities; UK Ofcom regulates from 1 MW; EU EED reporting starts at 500 kW with a mandatory sustainability label in 2026; 27-plus US states are legislating.
  • AI and GPU halls run 50–120 kW per rack with liquid cooling and step loads, and crypto-mining neighbours are a tenancy risk — two 2026 risk classes no Tier III certificate covers.
  • BMC/IPMI on a shared VLAN is persistent below-OS access, and GPU firmware is the newest supply-chain surface in the building.
  • It reads a SOC 2 for what it does not say. An operator report has a scope, and the boundary of that scope is where your risk starts.

Residency breaks in the backup. An EU-only contract satisfied at rest and quietly broken by the US disaster-recovery copy is the single most common finding this kit produces, and almost no register catches it — because almost every register tracks one location per dataset. File 02 tracks at rest, in transit and in backup separately, and the decision engine in file 05 resolves each placement on its own.

Data centre operators are now regulated in their own right. NIS2 classes them as essential entities. In the UK, Ofcom regulates from 1 MW (10 MW for enterprise facilities) under the Cyber Security and Resilience Act. The EU's Energy Efficiency Directive requires annual reporting from 500 kW, with a mandatory sustainability rating arriving in 2026 — and national divergence beneath it: Germany from 300 kW with heat-reuse quotas, France from 100 kW. In the US, 27-plus states are legislating on cost allocation, water, disclosure and noise. Your facility profile now determines which of these attach, which is why file 01 flags them automatically from load and location.

Two 2026 risk classes no Tier III certificate covers. AI and GPU halls run 50 to 120 kW per rack with liquid cooling and step loads that behave nothing like the design assumptions of the facility around them. And crypto-mining neighbours are a tenancy risk in their own right. File 04 asks twelve AI questions — density, transients, liquid cooling, accelerator isolation, GPU and BMC firmware, export screening, fabric, battery storage, curtailment — and seven about crypto tenancy.

BMC and IPMI on a shared VLAN is persistent below-OS access, and GPU firmware is the newest supply-chain surface in the building. File 06 registers hardware class by class: vendor, OEM or ODM origin, firmware components, signing, BMC isolation, vendor remote access, screening, end of life, and whether an SBOM or CBOM exists.

What you get

01 Facility & Tenancy Profile (XLSX) — every facility and region with its model, load, availability class, PUE, cooling, density, AI hall, crypto or unknown tenants, tenancy type and assurance on file, with automatic regulatory flags for the EED, German and French thresholds, Ofcom, NIS2 and US federal and state regimes.

02 Data-Geography Register (XLSX) — dataset by at-rest, in-transit and backup/DR location, with sub-processors, transfer mechanism and residency requirement, returning a first-pass RED / AMBER / GREEN.

03 Merged Control Assessment (XLSX) — 29 controls mapped across EN 50600, Uptime, the SOC 2 trust services criteria, ISO 27001, NIS2 and the CAF, and the EED, weighted and scored, with an operator questionnaire tab so the facility answers in your format.

04 AI & Crypto Tenancy Overlay (XLSX) — the questions a standard due-diligence pack does not contain, because the estates they were written for did not have GPU halls in them.

05 Residency & Transfer Decision Engine (XLSX) — dataset, target and state in; adequacy, mechanism, contract clause, sector localisation and key location out, resolving to PERMITTED / CHECK / NOT PERMITTED with the fix. Covers the EU, UK, US, China, India and others.

06 Hardware & Firmware Supply-Chain Register (XLSX) — per hardware class, ending in HIGH, MEDIUM or LOW.

07 Findings Report + Board One-Pager (DOCX + PPTX) — the scorecard, the findings, the decisions, eight contract asks to put to operators, a ninety-day plan and two board slides.

08 Practitioner Guide (PDF) — why 2026, the estate, data geography, the merged control set, AI and crypto tenancy, the residency engine, hardware and firmware, what assurance scopes actually cover, the regulatory map, how to run it, ninety days, failure patterns and an FAQ.

dc01.json — regulatory thresholds, control ids, overlay ids and engine rules.

It reads a SOC 2 for what it does not say. An operator's report has a scope, and the boundary of that scope is where your risk starts. The merged control set exists so that a facility with a clean SOC 2, a Tier III certificate and an ISO 27001 scope statement can still be assessed on the 29 things that actually matter to a tenant.

This is the buyer's side, for infrastructure and platform leads, CISOs, DPOs and procurement at any organisation with colocation, cloud or owned facilities — and for operators preparing tenant evidence in advance. If you are a UK operator, your own duties are in the UK Cyber Security & Resilience Act Kit. The same assessment pattern applied to your managed service provider is the MSP & MSSP Assessment Kit, and the whole vendor programme around both is the Vendor Risk Operations Kit.

Pairs with the Post-Quantum Migration Kit for the key-location questions the residency engine raises, I've Been Breached if a facility incident becomes yours, the HIPAA Security Rule 2027 Readiness Kit where PHI sits in colocation, the CMMC 2.0 Readiness Accelerator if the facility holds CUI and has to appear in an SSP boundary, and the EU AI Act Compliance Clock if the GPU hall is running systems the Act reaches.

Every regulatory threshold in the files is marked for verification — the EED's 500 kW, Germany's 300 kW, Ofcom's 1 and 10 MW, the US executive order's 100 MW, Texas's 75 MW — as are the EU rating scheme's final text, the Data Act fee phase-out, Data Privacy Framework status and the PIPL and DPDP specifics. A practitioner's toolset, not legal advice.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-04
Pages 8