News & Events

The Data Centre Security Spec Sheet Just Changed — Is Your Stack Ready?

Unlock the full potential of Wavestore v6.50 -view our launch presentation today and explore the latest innovations in video management.

VIEW PRESENTATION

By Sebastian Marghella, Marketing Manager · Published 20 August 2026 · Last updated 20 August 2026

In short

  • Physical security is now the most-cited threat in the sector (61%) but still takes around 2% of the build budget — and that gap is closing through the specification, not the budget line.
  • Data centre physical security requirements are shifting from named products to performance-based outcomes proven under witness testing.
  • UK and EU regulation is driving it: data centres are being brought into scope as essential services, and NIS2 makes physical security a board-level liability.
  • Interoperability is now a disqualification criterion. A feature-complete product that cannot participate in the wider system gets excluded regardless of how good it is.

Physical security is now the most-cited threat in the data centre sector. It still gets about 2% of the build budget.

Those two numbers come from different reports published a few months apart. AFCOM's State of the Data Center 2026 found 61% of operators naming physical security among their top threats — more than any other risk. It was enough to displace ransomware from the top spot for the first time in nearly a decade. The Security Industry Association's data centre report, published the previous November, found physical security taking between 1% and 5% of total build budgets. Its worked example put it at 2.3%, against 42% for cooling and 19.3% for building fit-out.

That gap is closing. But it isn't closing because anyone suddenly wants to spend more on the same products. It's closing through the specification. Consultants are rewriting the data centre physical security requirements a compliant system has to meet, and those standards get applied portfolio-wide for years at a time.

Which makes this an integrator's problem before it's a manufacturer's problem. If the spec being written this quarter describes something your stack can't do, you don't lose one bid. You lose a client's entire estate until the next standards review.

What are data centre physical security requirements?

Data centre physical security requirements are the controls an operator must demonstrate to protect the facility itself: layered perimeter and zone access, continuously verified identity at every chokepoint, video and access events linked into a single auditable record, and monitoring evidence sufficient to satisfy SOC 2, ISO/IEC 27001 and — increasingly — national regulators.

What has changed is not the list. It is the standard of proof. Requirements that were once satisfied by installing the right equipment are now satisfied only by demonstrating the right behaviour, under test, in front of the client.

Why the spec moved: the regulatory floor came up

The specification didn't change because consultants developed new preferences. It changed because the compliance regime underneath it changed. Three shifts did most of the work.

Data centres are becoming regulated infrastructure in the UK. The Cyber Security and Resilience Bill was introduced to Parliament in November 2025 and is progressing through the Commons, with Royal Assent expected later in 2026. It brings data centres into scope as essential services by amending the NIS Regulations 2018. The thresholds are specific: colocation facilities with a rated IT load above 1MW, and enterprise data centres at 10MW or more. DSIT leads on policy and designation. Ofcom becomes the operational regulator, handling notifications, incident reports, monitoring and enforcement, with powers to require remedial action and impose financial penalties. Designated operators face a 24-hour initial and 72-hour detailed incident reporting duty, and must notify Ofcom within three months of designation.

NIS2 made physical security a board-level exposure in the EU. The directive requires an all-hazards approach: operators must protect the physical environment of their systems, not just the digital one. Article 34 sets administrative fines for essential entities at "a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover", whichever is higher. Management bodies can be held personally liable for gross negligence in oversight. That is a materially different conversation from the one the security line item used to get.

The standards themselves added continuous monitoring. When ISO/IEC 27001 was revised in 2022, clause 7 of Annex A gained exactly one new control out of fourteen: 7.4, Physical Security Monitoring. It requires continuous monitoring of premises to detect and deter unauthorised access. On the European side, EN 50600 supplies the layered model consultants now design against — the "onion shell principle", where protection rises class by class from the perimeter to the rack.

The four protection classes are commonly summarised as follows. Treat this as an orientation rather than a specification: EN 50600-2-5 is the normative text, and it distinguishes protection classes from protection zones more carefully than any summary does.

EN 50600 protection classes, as commonly summarised. EN 50600-2-5 is the normative text and distinguishes protection classes from protection zones more carefully than any summary does.
Protection class Typically applied to Access model
Class 1 Building entrance, perimeter fencing Restricted public access
Class 2 Offices, support areas Regulated and accompanied
Class 3 Technical areas Restricted, often accompanied
Class 4 Server rooms, IT racks Strictly regulated

If you have wondered why tender documents suddenly read like audit checklists, this is why. The client is being audited — and increasingly, so is the client's board.

What changed in data centre physical security requirements

Three shifts, all visible in current tender documents.

From device lists to performance-based specs

Operators are moving away from naming manufacturers and models. Instead they specify measurable outcomes and verify them with witness testing: you demonstrate the system doing the thing, in front of the client, before acceptance.

The stated reason is to prevent costly substitutions and ensure a design actually deploys at scale. The practical effect on integrators is larger than it first appears. Being on an approved product list stops being sufficient. You have to prove the outcome under observation.

Witness testing tends to expose the same three things: latency between subsystems, failover behaviour, and whether an "integration" survives a WAN interruption. If your unification story depends on two products exchanging messages through middleware, that's where it shows.

From integrated to identity-aware

Facial biometrics has moved from a technology under debate to a baseline line item. The conversation with clients has shifted too. Where privacy objections once dominated, the questions now are about user experience and integration speed.

The market data points the same way. Global revenue for biometric physical access control is forecast at around $6.1 billion in 2026, rising to over $9.8 billion by 2028. User numbers grow from roughly 567 million to more than 913 million across the same period, with data centres named as a leading sector for adoption. Contactless modalities are preferred for throughput reasons: face, iris and palm vein rather than fingerprint.

Two requirements travel with this that integrators routinely miss.

The first is liveness detection. Systems must distinguish a live person from a photograph or 3D mask, and ISO/IEC 30107 conformance for presentation attack detection is now treated as table stakes rather than a differentiator.

The second is OSDP, which specifies encrypted, supervised communication between readers and controllers. A reader on an unencrypted legacy protocol fails the spec no matter how good the matching algorithm is.

Specifications also increasingly call for single devices combining identity verification, visual documentation and intercom in one unit at the door, rather than three separate devices doing three jobs. That changes the door hardware schedule you're pricing against.

From logs to a forensic chain of activity

Access records are no longer just a compliance artefact. They're the evidence base for tenant investigations, and increasingly a commercial differentiator that operators sell on.

The requirement is specific. Identity data, access events and video have to link into a single reviewable chain, so that when something happens the security team can establish who was where, when, verified how, and what the footage shows — without reconstructing it from three systems after the fact.

The frameworks are explicit about this. SOC 2's CC6.4 criterion requires that an entity "restricts physical access to facilities and protected information assets (for example, data center facilities, backup media storage, and other sensitive locations) to authorized personnel", with points of focus covering authorisation, timely removal of access and periodic review. NIST SP 800-53's PE-3 enforces physical access authorisations at entry and exit points.

Visitor management has been pulled into the same evidentiary standard: ID scanning and photo capture, watchlist screening, nationality verification where ITAR or EAR apply, a real-time on-site roster for evacuation accountability, and log retention typically running to a year or more with periodic review.

Why good stacks still fail the spec

Most failed data centre submissions aren't from weak products. They're from products that couldn't participate, or from specs that were never written for a data centre in the first place.

The SIA report is blunt about the consequence: interoperability is non-negotiable, and products incapable of participating in a broader ecosystem will be excluded regardless of feature richness. That's a disqualification criterion with nothing to do with how good the product is.

Three failure modes recur.

Design fragmentation. Perimeter elements — fencing, bollards, vehicle mitigation — sit under construction divisions. Access control, video and visitor management sit with the security department. Nobody owns the join, and the systems arrive on site disconnected. This is an organisational failure that shows up as a technical one.

Specification recycling. Specs copied from retail, warehousing or an older data centre project produce predictable results: cameras mounted at 18 feet specified for facial recognition, licence plate readers positioned at optically impossible angles, access readers that can't interoperate across tenants on a multitenant site. These aren't hypothetical. They're the examples the industry keeps citing because they keep happening.

Vertical transplant. Architects, engineers and integrators are entering the data centre sector from other verticals without understanding uptime obligations, tenant requirements, or the compliance regime the operator is audited against. The approaches that worked elsewhere don't survive contact with a live buildout.

As the SIA report puts it: if your strategy starts with what you sell rather than how data centres are built and run, you're already behind.

The requalification checklist: 10 questions to ask of your stack

Run your current stack through these before the next bid — and run them honestly, because witness testing will.

  1. Native participation, not middleware. Can access control, video and alarms act on one another without a translation layer between them? Tests whether your unification is an architecture or a project.
  2. Layered zoning that maps to the standard. Can you enforce distinct authorisation rules per zone, from perimeter through to rack, in the way EN 50600's protection classes describe? Tests whether your design survives review against the framework the consultant is actually using.
  3. Chain of activity. Can you produce identity, access event and corroborating video as one record, in one export, for one incident? Tests whether the client survives a tenant audit.
  4. Biometrics with liveness, on a supervised protocol. Is facial verification native rather than a bolt-on with its own database — and does it carry ISO/IEC 30107 presentation attack detection and OSDP reader-to-controller encryption? Tests whether the biometric line item is specifiable or merely present.
  5. Edge decision logic. Does access authorisation continue to behave correctly with the WAN down? Tests whether you're proposing a cloud-dependent platform inside a facility that sells uptime.
  6. Witness-test readiness. Can you demonstrate end-to-end event-to-action latency under observation, on the client's site, on their hardware? Tests whether the unification you've claimed is real.
  7. Licensing at data centre scale. Does cost scale with the number of cameras and readers, or with the number of operators and sites? Tests whether your design gets value-engineered out at bid review.
  8. Supply chain and hardening. NDAA compliance, operating system attack surface, encryption standard, and the certification set procurement will ask for. Tests whether the security review kills your submission before the technical one starts.
  9. Incident reporting support. Can the system produce what a regulator's timeline demands — a defensible account within 24 hours and detail within 72? Tests whether your client can meet a duty they may not have had last year.
  10. Multi-region repeatability. Could a different regional integrator execute the same standard and reach the same result? Tests whether you can be adopted portfolio-wide, or only site by site.

If you can't answer six of these cleanly, the problem isn't your bid writing.

For a longer treatment of criterion 1, see our guide to evaluating a unified security platform.

Where Wavestore fits

To be direct about our position: WaveFusion was built as a single platform where video, access control and data automation are native participants on a shared event bus — not separate products connected after the fact. That architecture answers checklist items 1, 5 and 7 structurally rather than through integration work. Events are shared rather than translated, decision logic runs at the edge independently of the WAN, and licensing is per camera and per reader with no operator seat costs. Where an estate is already on Mercury panels, there is a controller-only migration path — worth checking against your own site conditions rather than taking on trust.

We'd rather you used the checklist than took our word for it. It's written to be run against any platform, including ours, and it's the same list we'd expect a consultant to be working from.

Frequently asked questions

What do data centre consultants require in a physical security specification?

Increasingly, performance-based outcomes verified by witness testing rather than named products. Alongside that: demonstrable interoperability across access control, video, intrusion and visitor management, layered zoning consistent with EN 50600, and a forensic audit trail linking identity to access events to video.

Are UK data centres now regulated as critical infrastructure?

They are heading that way. The Cyber Security and Resilience Bill, expected to receive Royal Assent later in 2026, brings colocation facilities above 1MW and enterprise data centres at 10MW or above into scope as essential services, with Ofcom as operational regulator and mandatory incident reporting on a 24-hour and 72-hour timeline.

Is facial recognition now standard in data centre access control?

It has moved from a debated option to a common baseline requirement, but with conditions attached. Specifications increasingly expect ISO/IEC 30107 presentation attack detection and OSDP-encrypted reader communication, not simply a biometric reader at the door.

What does SOC 2 require for physical access monitoring?

Criterion CC6.4 requires that physical access to facilities and protected information assets — data center facilities are named explicitly — is restricted to authorised personnel, with authorisation, timely removal and periodic review of that access.

How do multitenant data centres handle access control across tenants?

Through separated credential authority. Readers operate across the site, but each tenant's authorisation domain stays independent, with audit trails that can be produced per tenant without exposing others.

The spec is being written now

The standards consultants set this year will govern several refresh cycles, and in the UK and EU they're being written against a regulatory floor that is still rising. That's the reason to requalify against current data centre physical security requirements before the next bid rather than after it.

And if you're seeing something land in data centre specs that isn't on this list, we'd like to hear about it.

Sources

  • AFCOM, State of the Data Center 2026afcom.com
  • Security Industry Association, Data Center Security Reportsecurityindustry.org
  • SecurityInfoWatch, Identity, forensics and operational fluency: the data center integrator's playbooksecurityinfowatch.com
  • European Union, Directive (EU) 2022/2555 (NIS2)eur-lex.europa.eu
  • UK Parliament, Cyber Security and Resilience (Network and Information Systems) Billbills.parliament.uk
  • House of Commons Library, Research briefing CBP-10442commonslibrary.parliament.uk
  • Gowling WLG, Regulating data centres: the Cyber Security and Resilience Billgowlingwlg.com
  • AICPA & CIMA, 2017 Trust Services Criteriaaicpa-cima.com
  • ISO, ISO/IEC 27001:2022iso.org
  • ISO, ISO/IEC 30107-3:2023iso.org
  • NIST, SP 800-53 Rev. 5csrc.nist.gov
  • Security Industry Association, Open Supervised Device Protocol (OSDP)securityindustry.org
  • CENELEC, EN 50600-2-5 (protection classes and zones) — no free public text; available via CENELEC and national standards bodies
A group of five diverse business professionals smiling and engaging in a lively meeting around a table with laptops.

View Wavestore v6.50 presentation

Solutions for a world we can't yet see. Discover v6.50 features helping people and businesses.