Orbital FederalFederal

Data Centers

What federal tenants actually ask data centers for

The requirements arrive as a questionnaire referencing control families, and they are mostly about your building — not your network. Here is what is behind them.

The short answer

They ask for evidence that your physical controls operate — not a description of them. The questionnaire will reference control families, most often the physical and environmental protection set, and the reviewer's job is to find the gap between what your policy says and what your site does.

Almost none of it requires accredited space. Most of it requires being able to prove who was in which room, when, escorted by whom, and what left the building.

Why this landed on your desk

Compute for federal, defense, and defense-adjacent workloads increasingly sits in commercial facilities. That is a commercial opportunity and a security obligation arriving together. The tenant carries requirements from its own contracts — FedRAMP-adjacent expectations, DFARS clauses, program-specific security requirements — and a portion of those flow directly to the facility, because the tenant cannot satisfy them without you.

The operators who win this business are not the ones with the most impressive security narrative. They are the ones who can produce artefacts quickly when asked. Diligence rewards the prepared, not the persuasive.

What they actually ask about

Access authorisation and review

Not "do you have badge readers." Rather: who authorised each person's access to the tenant space, on what basis, when was the list last reviewed, and what evidence exists of that review. Access lists that grow and never shrink are the most common finding in the sector.

Visitor and maintenance escort

How visitors are identified, logged, escorted, and closed out. Critically: how remote-hands work and third-party maintenance are supervised inside a tenant's footprint, and whether there is a record. This is where policy and practice most often diverge.

Media handling and destruction

What happens to a drive from the moment it is decommissioned to the moment it is destroyed, including the chain of custody in between and the certificate at the end. Tenants with CUI obligations care about this disproportionately, and rightly.

Physical separation

Cage, cabinet, or suite construction; whether separation is genuine or nominal; whether shared infrastructure — cable trays, plenums, adjacent cages — creates paths the tenant did not agree to.

Monitoring and retention

Camera coverage geometry at the points that matter, not just camera counts. Retention periods. Who reviews footage, on what trigger, and whether anyone has ever tested that the coverage actually shows what it needs to show.

Construction and change history

Increasingly, and this catches operators out: what work has been done in or adjacent to the tenant space, by whom, and under what supervision. A facility that cannot account for its construction history has a gap that cannot be closed retroactively.

Three failure patterns

The building management system is on the flat network

Environmental controls, access control, and cameras sharing network paths with production, or reachable from a vendor's remote support tunnel with credentials nobody rotated. This is the convergence gap: the physical security systems are themselves an attack surface, and a competent reviewer will ask about it.

The guard force does something other than what the policy says

Post orders written years ago, revised by practice rather than by document. A reviewer finds this in ten minutes of interview. It is not usually a competence problem — it is a governance problem, and it is fixable before anyone asks.

Nobody watched the build

Trades, vendors, and drawings moved through the facility during construction and expansion with no security witness and no record. For most commercial workloads this is tolerable. For a tenant with program requirements, it is a question you cannot answer, and the answer "we don't know" carries weight.

What we would do, in order

  1. Map the actual requirement before answering anything. Which controls genuinely flow to the facility, and which is the tenant satisfying itself? Operators routinely over-commit on controls that were never theirs.
  2. Assemble the evidence pack — access authorisation records, review logs, escort records, media destruction certificates, camera coverage documentation, post orders. If it takes you a week to gather, it will take a reviewer a week to lose confidence.
  3. Walk the site as a reviewer would, including the interviews. Find your own gaps first, and present them with a plan rather than having them found.
  4. Close the convergence gap between building systems and production networks, because it is the finding most likely to escalate beyond the facility team.
  5. Fix policy-to-practice drift in post orders and escort procedure. Cheap, fast, and disproportionately reassuring.
  6. Institute construction security for future work, so the next expansion does not create the same unanswerable question.

What not to do

Do not answer a security questionnaire aspirationally. Answers become contractual representations. An operator that claims a control it does not operate has converted a gap into a liability, and the discovery usually happens at the worst moment — during an incident, or during an audit the tenant brings.

And do not build accredited space on speculation. Most federal and defense workloads in commercial facilities do not need it. Where a program genuinely requires it, the requirement arrives with specifics attached, and building to a guess beforehand is an expensive way to be wrong.

Scope note Requirements vary substantially by tenant, program, and contract vehicle. This describes patterns we see rather than a checklist that applies to your facility, and it is not a substitute for reading the actual flow-downs in the agreement in front of you.

Questions

From operators

What is the first thing a federal-adjacent tenant asks for?
Evidence, not assertion. Specifically, evidence against the physical and environmental protection control family — who has access to the space, how that access is authorised and reviewed, how visitors and maintenance are escorted, how media is handled and destroyed, and how all of that is recorded. Most operators can describe their controls fluently and cannot produce the artefacts that demonstrate them operating over time. The artefacts are the deliverable.
Do we need a SCIF to serve defense tenants?
Usually not. Most defense and federal-adjacent workloads in commercial data centers do not require accredited space. What they require is demonstrable physical control of the tenant environment — cages or cabinets with auditable access, separation from other tenants, and a documented chain of custody for hardware and media. Accredited space is a narrower requirement that arrives with specific programs, and building it speculatively is an expensive way to guess.
What most often stalls a tenant security review?
Three things, in our experience. Construction and maintenance access nobody can account for historically. Building management, environmental, and access-control systems sharing network paths with production. And a gap between the written policy and what the guard force or remote-hands team actually does, which a competent reviewer finds by interview rather than by reading.
How early should we involve a security advisor?
Before the tenant's questionnaire arrives, if you can — and certainly before you answer it. Answers are commitments. An operator who asserts a control it does not have has created a contractual exposure that is worse than admitting the gap and presenting a plan. If a build is in design, earlier still: the physical controls tenants ask about are far cheaper to design in than to retrofit.

Next Step

Find your gaps before a tenant does.

A scoped assessment produces the evidence pack and the gap list — before the questionnaire arrives, ideally.

Prefer to talk? 866.960.7475 · info@orbitalfederal.com