Research only

Data centers and colocation

Explore the policy documents and regulatory sources relevant to this industry. Assessment checks for this profile are in development.

Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.

Documents to review

  • Physical security planResearch document type
  • Incident response planResearch document type
  • Business continuity planResearch document type
  • Change management policyResearch document type
  • Vendor access policyResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Where does the organization operate, and which regulator, license, permit or contract governs the activity?
  • Which business activities, data types and organization roles does the document describe?
  • Do the relevant thresholds or exceptions change which requirements apply?

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Research only

NIS2 and national transpositions

Directive (EU) 2022/2555 · Commission Implementing Regulation (EU) 2024/2690

Potentially relevant to covered cloud, data-centre, DNS/CDN, managed service and managed security providers with an EU nexus. Confirm service definitions, size rules and exceptions, main establishment, and the applicable national implementing law. Commission Implementing Regulation (EU) 2024/2690 specifies risk-management measures and significant-incident criteria for listed digital providers; it does not replace national applicability review.

Jurisdictions: EU-EEA

Research applicability questions
  • Do you operate or provide the relevant service in an EU or EEA member state?
  • Do you meet the employee or financial thresholds used by this authority?
  • Does your principal activity fall within a sector covered by this authority?
  • Do you provide one of the services identified by this authority?
  • Are you established, represented, or offering the service in the relevant jurisdiction?
Research only

Digital Operational Resilience Act

Regulation (EU) 2022/2554

Distinguish regulated financial entities from their ICT suppliers. A cloud, MSP or security provider may face customer-contract duties; direct EU oversight follows designation as a critical ICT third-party provider. Check the service, EU financial customer, contract and critical-provider designation rather than treating every ICT supplier as a financial entity.

Jurisdictions: EU-EEA

Research applicability questions
  • Are you one of the financial-entity types named by the rule?
  • Do you supply ICT services to EU financial entities, and which services support their critical or important functions?
  • Which DORA security, incident, audit, exit and subcontracting obligations appear in your financial-customer contracts?
  • Do you operate or provide the relevant service in an EU or EEA member state?
  • Have the European Supervisory Authorities designated your organization as a critical ICT third-party provider?
Research only

NIST Cybersecurity Framework 2.0

NIST CSWP 29

Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Jurisdictions: GLOBAL

Research applicability questions
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?
Content rights required

ISO/IEC 27001:2022

ISO/IEC 27001:2022 · ISO/IEC 27001:2022/Amd 1:2024

ISO/IEC 27001:2022 is an information-security management-system standard, with Amendment 1:2024 also listed by ISO. Certification or alignment may be requested by customers; this is not automatically a legal duty. Assessment content remains mapping-only until reuse rights and specialist review are resolved; AuditReady cannot issue certification.

Jurisdictions: GLOBAL

Research applicability questions
  • Has a customer or your organization requested this standard or assurance engagement, and for which system boundary?
  • Which services, sites, assets and processes are inside the requested certification boundary?
Content rights required

SOC 2 Trust Services Criteria

Trust Services Criteria

SOC 2 is an AICPA assurance reporting service for service organizations, not a general law or an ISO-style certification. Scope depends on the system, trust-services categories and engagement. Customer requirements can drive the engagement. Content-rights review and CPA expertise are required; AuditReady cannot issue a SOC report.

Jurisdictions: GLOBAL

Research applicability questions
  • Has a customer or your organization requested this standard or assurance engagement, and for which system boundary?
  • Which trust-services categories and reporting period are in the planned SOC 2 engagement?
Content rights required

PCI DSS v4.0.1

PCI DSS v4.0.1

PCI DSS v4.0.1 is a payment-account security standard. Check whether the organization stores, processes or transmits account data, or can affect the cardholder-data environment, and confirm its merchant/service-provider role. Customer and payment-brand arrangements determine validation obligations. Content permission and qualified review remain required; AuditReady readiness is not PCI validation.

Jurisdictions: GLOBAL

Research applicability questions
  • Do you store, process or transmit payment-account data, or provide services that can affect a cardholder-data environment?
  • What payment-brand/acquirer validation requirements apply to your merchant volume and channels?
  • Do you store, process or transmit cardholder data, or provide services that can affect payment-data security?
  • Which systems and services are within or can affect the cardholder-data environment?
Research only

OSHA emergency action plans

29 CFR 1910.38

An emergency action plan is required when another OSHA standard triggers 29 CFR 1910.38. Confirm the triggering standard and state-plan coverage. A plan must generally be written and available to employees; employers with ten or fewer employees may communicate it orally. Do not infer a written-plan violation solely from the industry label.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Which OSHA standard requires an emergency action plan for this workplace?
  • How many employees does the employer have, and does the ten-or-fewer oral-plan exception apply?
  • Does an OSHA-approved state plan apply, and does it impose different workplace requirements?
  • What work activities, hazards and other OSHA standards trigger this workplace emergency-plan duty?
Research only

EU General Data Protection Regulation

Regulation (EU) 2016/679

Check EU establishment, offering goods/services to or monitoring people in the EU, and the controller/processor role. A cloud, MSP or security provider may be a processor with contract and security duties. EU data-subject location alone does not establish every territorial-scope condition; verify Articles 3 and 28 and relevant national rules.

Jurisdictions: EU-EEA

Research applicability questions
  • Does processing occur in the context of an EU establishment’s activities?
  • Does the organization offer goods/services to people in the EU or monitor their behavior there?
  • Do you determine the purposes and means of processing personal data, or process it on a customer’s documented instructions?
  • Where are the relevant people located for the processing activity, and which Article 3 scope condition is met?
Research only

HIPAA Security, Privacy, and Breach Notification Rules

45 CFR Parts 160 and 164

Applies to covered entities and business associates handling protected health information. Cloud providers that maintain electronic PHI can be business associates even when data is encrypted and they have no decryption key. Check the actual data/service role and business-associate agreement. A healthcare customer alone does not establish scope. Proposed Security Rule changes must be tracked separately from the currently effective rule.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Are you a HIPAA covered entity, or do you create, receive, maintain or transmit PHI for a covered entity or another business associate?
  • Which protected health information does the service handle, and under whose business-associate agreement?
  • Does your service handle electronic PHI, including encrypted information for which you do not hold the decryption key?
  • What size, complexity, capabilities and risk factors affect implementation of your HIPAA safeguards?
  • For each addressable implementation specification, have you evaluated reasonableness and documented any alternative?
Research only

FedRAMP federal cloud service scope

44 USC 3607–3616 · OMB Memorandum M-24-15 · FedRAMP Consolidated Rules for 2026 — Scope

Potentially relevant to cloud offerings handling federal information for US agencies. The agency determines whether its use case is in scope; not every government user, internet service, MSP or physical data centre needs FedRAMP. Check the offering boundary and exceptions. This research family does not authorize AuditReady to process CUI or issue a FedRAMP certification.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Will a US federal agency use this cloud service for an agency function?
  • Will the offering create, collect, process, store or maintain federal information on behalf of the agency?
  • Is this an operated IaaS, PaaS or SaaS cloud offering, rather than only consulting or physical colocation?
  • Does the agency use a shared cloud offering with a provider/agency responsibility boundary?
  • Has the agency assessed any applicable FedRAMP scope exception?