Data Centers
What federal tenants actually ask data centers for
The requirements arrive as a questionnaire referencing control families, and they are mostly about your building — not your network. Here is what is behind them.
They ask for evidence that your physical controls operate — not a description of them. The questionnaire will reference control families, most often the physical and environmental protection set, and the reviewer's job is to find the gap between what your policy says and what your site does.
Almost none of it requires accredited space. Most of it requires being able to prove who was in which room, when, escorted by whom, and what left the building.
Why this landed on your desk
Compute for federal, defense, and defense-adjacent workloads increasingly sits in commercial facilities. That is a commercial opportunity and a security obligation arriving together. The tenant carries requirements from its own contracts — FedRAMP-adjacent expectations, DFARS clauses, program-specific security requirements — and a portion of those flow directly to the facility, because the tenant cannot satisfy them without you.
The operators who win this business are not the ones with the most impressive security narrative. They are the ones who can produce artefacts quickly when asked. Diligence rewards the prepared, not the persuasive.
What they actually ask about
Access authorisation and review
Not "do you have badge readers." Rather: who authorised each person's access to the tenant space, on what basis, when was the list last reviewed, and what evidence exists of that review. Access lists that grow and never shrink are the most common finding in the sector.
Visitor and maintenance escort
How visitors are identified, logged, escorted, and closed out. Critically: how remote-hands work and third-party maintenance are supervised inside a tenant's footprint, and whether there is a record. This is where policy and practice most often diverge.
Media handling and destruction
What happens to a drive from the moment it is decommissioned to the moment it is destroyed, including the chain of custody in between and the certificate at the end. Tenants with CUI obligations care about this disproportionately, and rightly.
Physical separation
Cage, cabinet, or suite construction; whether separation is genuine or nominal; whether shared infrastructure — cable trays, plenums, adjacent cages — creates paths the tenant did not agree to.
Monitoring and retention
Camera coverage geometry at the points that matter, not just camera counts. Retention periods. Who reviews footage, on what trigger, and whether anyone has ever tested that the coverage actually shows what it needs to show.
Construction and change history
Increasingly, and this catches operators out: what work has been done in or adjacent to the tenant space, by whom, and under what supervision. A facility that cannot account for its construction history has a gap that cannot be closed retroactively.
Three failure patterns
The building management system is on the flat network
Environmental controls, access control, and cameras sharing network paths with production, or reachable from a vendor's remote support tunnel with credentials nobody rotated. This is the convergence gap: the physical security systems are themselves an attack surface, and a competent reviewer will ask about it.
The guard force does something other than what the policy says
Post orders written years ago, revised by practice rather than by document. A reviewer finds this in ten minutes of interview. It is not usually a competence problem — it is a governance problem, and it is fixable before anyone asks.
Nobody watched the build
Trades, vendors, and drawings moved through the facility during construction and expansion with no security witness and no record. For most commercial workloads this is tolerable. For a tenant with program requirements, it is a question you cannot answer, and the answer "we don't know" carries weight.
What we would do, in order
- Map the actual requirement before answering anything. Which controls genuinely flow to the facility, and which is the tenant satisfying itself? Operators routinely over-commit on controls that were never theirs.
- Assemble the evidence pack — access authorisation records, review logs, escort records, media destruction certificates, camera coverage documentation, post orders. If it takes you a week to gather, it will take a reviewer a week to lose confidence.
- Walk the site as a reviewer would, including the interviews. Find your own gaps first, and present them with a plan rather than having them found.
- Close the convergence gap between building systems and production networks, because it is the finding most likely to escalate beyond the facility team.
- Fix policy-to-practice drift in post orders and escort procedure. Cheap, fast, and disproportionately reassuring.
- Institute construction security for future work, so the next expansion does not create the same unanswerable question.
What not to do
Do not answer a security questionnaire aspirationally. Answers become contractual representations. An operator that claims a control it does not operate has converted a gap into a liability, and the discovery usually happens at the worst moment — during an incident, or during an audit the tenant brings.
And do not build accredited space on speculation. Most federal and defense workloads in commercial facilities do not need it. Where a program genuinely requires it, the requirement arrives with specifics attached, and building to a guess beforehand is an expensive way to be wrong.
Questions
From operators
What is the first thing a federal-adjacent tenant asks for?
Do we need a SCIF to serve defense tenants?
What most often stalls a tenant security review?
How early should we involve a security advisor?
Next Step
Find your gaps before a tenant does.
A scoped assessment produces the evidence pack and the gap list — before the questionnaire arrives, ideally.
Prefer to talk? 866.960.7475 · info@orbitalfederal.com