Unlock the full potential of Wavestore v6.50 -view our launch presentation today and explore the latest innovations in video management.
By Sebastian Marghella, Marketing Manager · Published 20 August 2026 · Last updated 20 August 2026
In short
Physical security is now the most-cited threat in the data centre sector. It still gets about 2% of the build budget.
Those two numbers come from different reports published a few months apart. AFCOM's State of the Data Center 2026 found 61% of operators naming physical security among their top threats — more than any other risk. It was enough to displace ransomware from the top spot for the first time in nearly a decade. The Security Industry Association's data centre report, published the previous November, found physical security taking between 1% and 5% of total build budgets. Its worked example put it at 2.3%, against 42% for cooling and 19.3% for building fit-out.
That gap is closing. But it isn't closing because anyone suddenly wants to spend more on the same products. It's closing through the specification. Consultants are rewriting the data centre physical security requirements a compliant system has to meet, and those standards get applied portfolio-wide for years at a time.
Which makes this an integrator's problem before it's a manufacturer's problem. If the spec being written this quarter describes something your stack can't do, you don't lose one bid. You lose a client's entire estate until the next standards review.
Data centre physical security requirements are the controls an operator must demonstrate to protect the facility itself: layered perimeter and zone access, continuously verified identity at every chokepoint, video and access events linked into a single auditable record, and monitoring evidence sufficient to satisfy SOC 2, ISO/IEC 27001 and — increasingly — national regulators.
What has changed is not the list. It is the standard of proof. Requirements that were once satisfied by installing the right equipment are now satisfied only by demonstrating the right behaviour, under test, in front of the client.
The specification didn't change because consultants developed new preferences. It changed because the compliance regime underneath it changed. Three shifts did most of the work.
Data centres are becoming regulated infrastructure in the UK. The Cyber Security and Resilience Bill was introduced to Parliament in November 2025 and is progressing through the Commons, with Royal Assent expected later in 2026. It brings data centres into scope as essential services by amending the NIS Regulations 2018. The thresholds are specific: colocation facilities with a rated IT load above 1MW, and enterprise data centres at 10MW or more. DSIT leads on policy and designation. Ofcom becomes the operational regulator, handling notifications, incident reports, monitoring and enforcement, with powers to require remedial action and impose financial penalties. Designated operators face a 24-hour initial and 72-hour detailed incident reporting duty, and must notify Ofcom within three months of designation.
NIS2 made physical security a board-level exposure in the EU. The directive requires an all-hazards approach: operators must protect the physical environment of their systems, not just the digital one. Article 34 sets administrative fines for essential entities at "a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover", whichever is higher. Management bodies can be held personally liable for gross negligence in oversight. That is a materially different conversation from the one the security line item used to get.
The standards themselves added continuous monitoring. When ISO/IEC 27001 was revised in 2022, clause 7 of Annex A gained exactly one new control out of fourteen: 7.4, Physical Security Monitoring. It requires continuous monitoring of premises to detect and deter unauthorised access. On the European side, EN 50600 supplies the layered model consultants now design against — the "onion shell principle", where protection rises class by class from the perimeter to the rack.
The four protection classes are commonly summarised as follows. Treat this as an orientation rather than a specification: EN 50600-2-5 is the normative text, and it distinguishes protection classes from protection zones more carefully than any summary does.
If you have wondered why tender documents suddenly read like audit checklists, this is why. The client is being audited — and increasingly, so is the client's board.
Three shifts, all visible in current tender documents.
Operators are moving away from naming manufacturers and models. Instead they specify measurable outcomes and verify them with witness testing: you demonstrate the system doing the thing, in front of the client, before acceptance.
The stated reason is to prevent costly substitutions and ensure a design actually deploys at scale. The practical effect on integrators is larger than it first appears. Being on an approved product list stops being sufficient. You have to prove the outcome under observation.
Witness testing tends to expose the same three things: latency between subsystems, failover behaviour, and whether an "integration" survives a WAN interruption. If your unification story depends on two products exchanging messages through middleware, that's where it shows.
Facial biometrics has moved from a technology under debate to a baseline line item. The conversation with clients has shifted too. Where privacy objections once dominated, the questions now are about user experience and integration speed.
The market data points the same way. Global revenue for biometric physical access control is forecast at around $6.1 billion in 2026, rising to over $9.8 billion by 2028. User numbers grow from roughly 567 million to more than 913 million across the same period, with data centres named as a leading sector for adoption. Contactless modalities are preferred for throughput reasons: face, iris and palm vein rather than fingerprint.
Two requirements travel with this that integrators routinely miss.
The first is liveness detection. Systems must distinguish a live person from a photograph or 3D mask, and ISO/IEC 30107 conformance for presentation attack detection is now treated as table stakes rather than a differentiator.
The second is OSDP, which specifies encrypted, supervised communication between readers and controllers. A reader on an unencrypted legacy protocol fails the spec no matter how good the matching algorithm is.
Specifications also increasingly call for single devices combining identity verification, visual documentation and intercom in one unit at the door, rather than three separate devices doing three jobs. That changes the door hardware schedule you're pricing against.
Access records are no longer just a compliance artefact. They're the evidence base for tenant investigations, and increasingly a commercial differentiator that operators sell on.
The requirement is specific. Identity data, access events and video have to link into a single reviewable chain, so that when something happens the security team can establish who was where, when, verified how, and what the footage shows — without reconstructing it from three systems after the fact.
The frameworks are explicit about this. SOC 2's CC6.4 criterion requires that an entity "restricts physical access to facilities and protected information assets (for example, data center facilities, backup media storage, and other sensitive locations) to authorized personnel", with points of focus covering authorisation, timely removal of access and periodic review. NIST SP 800-53's PE-3 enforces physical access authorisations at entry and exit points.
Visitor management has been pulled into the same evidentiary standard: ID scanning and photo capture, watchlist screening, nationality verification where ITAR or EAR apply, a real-time on-site roster for evacuation accountability, and log retention typically running to a year or more with periodic review.
Most failed data centre submissions aren't from weak products. They're from products that couldn't participate, or from specs that were never written for a data centre in the first place.
The SIA report is blunt about the consequence: interoperability is non-negotiable, and products incapable of participating in a broader ecosystem will be excluded regardless of feature richness. That's a disqualification criterion with nothing to do with how good the product is.
Three failure modes recur.
Design fragmentation. Perimeter elements — fencing, bollards, vehicle mitigation — sit under construction divisions. Access control, video and visitor management sit with the security department. Nobody owns the join, and the systems arrive on site disconnected. This is an organisational failure that shows up as a technical one.
Specification recycling. Specs copied from retail, warehousing or an older data centre project produce predictable results: cameras mounted at 18 feet specified for facial recognition, licence plate readers positioned at optically impossible angles, access readers that can't interoperate across tenants on a multitenant site. These aren't hypothetical. They're the examples the industry keeps citing because they keep happening.
Vertical transplant. Architects, engineers and integrators are entering the data centre sector from other verticals without understanding uptime obligations, tenant requirements, or the compliance regime the operator is audited against. The approaches that worked elsewhere don't survive contact with a live buildout.
As the SIA report puts it: if your strategy starts with what you sell rather than how data centres are built and run, you're already behind.
Run your current stack through these before the next bid — and run them honestly, because witness testing will.
If you can't answer six of these cleanly, the problem isn't your bid writing.
For a longer treatment of criterion 1, see our guide to evaluating a unified security platform.
To be direct about our position: WaveFusion was built as a single platform where video, access control and data automation are native participants on a shared event bus — not separate products connected after the fact. That architecture answers checklist items 1, 5 and 7 structurally rather than through integration work. Events are shared rather than translated, decision logic runs at the edge independently of the WAN, and licensing is per camera and per reader with no operator seat costs. Where an estate is already on Mercury panels, there is a controller-only migration path — worth checking against your own site conditions rather than taking on trust.
We'd rather you used the checklist than took our word for it. It's written to be run against any platform, including ours, and it's the same list we'd expect a consultant to be working from.
What do data centre consultants require in a physical security specification?
Increasingly, performance-based outcomes verified by witness testing rather than named products. Alongside that: demonstrable interoperability across access control, video, intrusion and visitor management, layered zoning consistent with EN 50600, and a forensic audit trail linking identity to access events to video.
Are UK data centres now regulated as critical infrastructure?
They are heading that way. The Cyber Security and Resilience Bill, expected to receive Royal Assent later in 2026, brings colocation facilities above 1MW and enterprise data centres at 10MW or above into scope as essential services, with Ofcom as operational regulator and mandatory incident reporting on a 24-hour and 72-hour timeline.
Is facial recognition now standard in data centre access control?
It has moved from a debated option to a common baseline requirement, but with conditions attached. Specifications increasingly expect ISO/IEC 30107 presentation attack detection and OSDP-encrypted reader communication, not simply a biometric reader at the door.
What does SOC 2 require for physical access monitoring?
Criterion CC6.4 requires that physical access to facilities and protected information assets — data center facilities are named explicitly — is restricted to authorised personnel, with authorisation, timely removal and periodic review of that access.
How do multitenant data centres handle access control across tenants?
Through separated credential authority. Readers operate across the site, but each tenant's authorisation domain stays independent, with audit trails that can be produced per tenant without exposing others.
The standards consultants set this year will govern several refresh cycles, and in the UK and EU they're being written against a regulatory floor that is still rising. That's the reason to requalify against current data centre physical security requirements before the next bid rather than after it.
And if you're seeing something land in data centre specs that isn't on this list, we'd like to hear about it.

Solutions for a world we can't yet see. Discover v6.50 features helping people and businesses.
