
Short answer: SOC 2 for data centers is a CPA's attestation report on a facility operator's controls, often scoped to security and availability, covering physical access, environmental protection, power and monitoring. Customers that host in that facility typically carve the provider out of their own SOC 2, then review its report and own the complementary controls it assigns to them.
Related guides:
- HIPAA compliant data center: what to check before you sign
- Complementary user entity controls explained
- SOC 2 bridge letters
Key takeaways
- A SOC 2 is an attestation report, not a certification. A CPA firm examines the operator's description of its system and its controls, and gives an opinion.
- Operators should scope the services customers actually buy, such as colocation space, cages, remote hands or managed hosting, at the facilities customers actually use. Security plus availability is a natural starting scope for a data center, because those are the controls customers rely on most.
- Customers that rely on a colo or hosting provider usually treat it as a subservice organization under the carve-out method, so the provider's controls are excluded from their own report.
- Carving out a provider does not remove the risk. You still review its report, map its complementary user entity controls (CUECs) to your own controls, and track the complementary subservice organization controls your auditor expects it to run.
- A report that does not list your facility, or ended many months ago, gives you much less to rely on.
What does SOC 2 mean for a data center?
It means an independent examination of the controls an operator runs over the facilities and services it provides to customers. The AICPA describes SOC 2 as reporting on controls at a service organization relevant to security, availability, processing integrity, confidentiality or privacy. Its SOC 2 guide frames the engagement as an assertion-based examination under the AICPA attestation standards, performed by a CPA. That is why "SOC 2 certified" is loose language. There is no certificate, only a report with an opinion, a system description and, for a Type 2, the tests the auditor ran.
Data centers are often asked for more than one SOC report, so it helps to know which one answers which question:
| Report | What it covers | Who it is for |
|---|---|---|
| SOC 1 | Controls likely relevant to user entities' internal control over financial reporting | Customers and their financial statement auditors |
| SOC 2 | Controls relevant to one or more of the five trust services categories | Customers, prospects and their security teams, usually under NDA |
| SOC 3 | The same categories with less detail, as a general use report that can be freely distributed | Anyone, often posted publicly |
A SOC 3 is useful as a marketing signal, but it does not contain the control descriptions, tests and exceptions a customer's auditor needs. For a fuller comparison, see our guide to SOC 1 vs SOC 2 vs SOC 3.
Which Trust Services Criteria should a data center include?
Start with security, add availability, and add others only when customer commitments call for them. The criteria are the AICPA's 2017 Trust Services Criteria (with revised points of focus, 2022), grouped into five categories. The security criteria are known as the common criteria, and they are aligned to the COSO framework's components and principles.
How each category tends to fit a data center or hosting operator:
| Category | Fit for colocation | Fit for managed hosting | Why |
|---|---|---|---|
| Security | Core | Core | Physical and logical access, monitoring, incident response, vendor management |
| Availability | Strong | Strong | Uptime is what customers buy: power, cooling, capacity, backup and recovery |
| Confidentiality | Sometimes | Often | Relevant when you handle customer data or media, such as backups or disposal |
| Processing integrity | Rare | Sometimes | Usually only when you process transactions or data on the customer's behalf |
| Privacy | Rare | Sometimes | Applies when you collect or handle personal information directly |
Scoping decisions that matter as much as the categories:
- Services in scope. List each service by the name customers see on their contract. A report that covers "colocation" but not "managed backup" leaves backup customers with nothing to rely on.
- Facilities in scope. Name every site. Customers will check that their cage is in a facility the auditor examined.
- Your own subservice organizations. If a third party runs security guarding, fire suppression maintenance or a backup site, decide whether to carve it out or include it, and say so in the description.
- Report type. Customers and their auditors generally prefer a Type 2, which covers whether controls operated over a period.
Which data center controls should the report cover?
The report should describe and test the controls that protect the facility, the power and environment, and the people who touch customer equipment. This table maps common control areas to what a customer should look for in the operator's report.
| Control area | What the operator typically runs | What a customer should look for in the report |
|---|---|---|
| Perimeter and building access | Fencing, guarded entry, visitor registration, badge issuance | Visitor logging and escort tested, and badge requests approved before access |
| Data hall and cage access | Badge plus biometric or PIN, locked cages and racks | Access lists reviewed on a set schedule, and terminated access removed promptly |
| Video surveillance | Cameras at entrances and data halls, footage retention | Coverage of the halls you use and a stated retention period |
| Power | Utility feeds, UPS, generators, fuel contracts | Maintenance and load testing of UPS and generators within the period |
| Cooling and environment | HVAC, temperature and humidity monitoring, leak detection | Alerting thresholds, monitoring evidence and response tickets |
| Fire detection and suppression | Detection, suppression systems, inspections | Inspection records for the period and the facilities in scope |
| Remote hands and shipping | Ticketed requests, authorization checks, chain of custody | Requests verified against your authorized contact list |
| Media handling and disposal | Destruction of failed drives or media, certificates | Only if the operator handles your media; check how destruction is evidenced |
| Incident and change management | Facility incident response, change approvals, customer notifications | How and when customers are notified of incidents and planned maintenance |
| Vendor management | Oversight of guards, maintenance contractors, carriers | Which of those vendors are carved out, and what the operator does to monitor them |
Read the exceptions next to each row. An exception in access reviews for the facility you use matters more than a clean result at a site you do not.
Carve-out or inclusive: how do you treat your colo in your own SOC 2?
SaaS and HealthTech companies typically use the carve-out method for their data center or hosting provider. A provider you rely on to deliver your service is a subservice organization in your SOC 2, and your system description has to say how it is handled, under the AICPA's SOC 2 description criteria. The two methods work like this (the PCAOB's interpretation of AS 2601, written for financial statement audits, gives the same definitions):
- Carve-out method: the subservice organization's relevant control objectives and controls are excluded from the description.
- Inclusive method: the subservice organization's relevant controls are included in the description and in the scope of the engagement.
The inclusive method is less common for colocation, because it brings the provider's controls into your auditor's testing, which needs the provider's cooperation. A carve-out is simpler, but it is not a free pass. Your system description still names the provider, the services it performs and the controls you expect it to have.
Who owns the complementary controls?
Two kinds of complementary controls connect your report to your provider's: some are the provider's job, and some are yours.
- Complementary subservice organization controls (CSOCs) are controls your own description assumes your carved-out provider runs, such as restricting physical access to the halls holding your servers. They appear in your report. Your job is to monitor that the provider actually runs them, usually by reviewing its SOC 2.
- Complementary user entity controls (CUECs) are controls the provider's report assumes its customers run. For a colo, typical CUECs include keeping your authorized access list current, removing departed staff from it, approving remote hands requests and securing your own equipment and data. They appear in the provider's report, and you own them. US government audit guidance treats this as a control in its own right: GAO's FISCAM expects complementary user-entity controls related to external parties to be identified, implemented and operating effectively.
A simple way to keep this straight:
| Question | CSOCs | CUECs |
|---|---|---|
| Whose report lists them? | Yours | Your provider's |
| Who runs them? | Your provider | You |
| How do you evidence them? | Annual review of the provider's report | Your own controls, tested by your auditor |
The CUEC guide linked at the top of this post covers mapping CUECs to your control set in more detail.
How do you review a provider's SOC 2 report?
Check scope, period, opinion, exceptions and CUECs, then record what you found. ISACA advises that enterprises fully review subservice organization SOC 2 reports rather than file them away. A workable review looks like this:
- Confirm the services and facilities. Your colo or hosting service and the exact site you use should both appear in the system description.
- Check the categories. If you promise customers availability, look for availability in the provider's scope, not just security.
- Check the period. Note when the period ended and when the next report is due. If there is a gap between the period end and today, ask for a bridge letter, a statement from the provider's management about changes since the period ended. It is not audited, so treat it as supporting evidence only.
- Read the opinion. An unqualified opinion is what you expect. A qualified opinion needs a conversation and a documented risk decision.
- Read the exceptions and management responses. Focus on access, environmental monitoring and incident notification at your facility.
- Find the provider's own carve-outs. If guarding or a backup site is carved out of its report, decide whether that matters to you.
- Map every CUEC to one of your controls. Unmapped CUECs are gaps in your own program.
- Record the review. Keep the report, your notes and any follow-up as vendor management evidence for your auditor.
For HealthTech teams storing ePHI in a colo, a SOC 2 review sits alongside a business associate agreement, not instead of it. Our HIPAA compliant data center guide, linked above, covers that side, and PCI compliant hosting covers card data environments.
How SecureSlate helps
SecureSlate helps data center operators and the SaaS and HealthTech teams that host with them organize their SOC 2 work. SecureSlate does not issue SOC 2 reports; only an independent CPA firm can. For operators, custom controls let you add data center specific physical and environmental controls, and audit management keeps evidence ready for your CPA firm, while the trust center helps you share security documentation with prospects. For customers, vendor risk management tracks each colo or hosting provider, its SOC 2 report, review dates and CUEC mapping, and risk management records decisions about exceptions. Multi-framework control mapping reuses the same controls across SOC 2, ISO 27001 and HIPAA, and security questionnaire automation answers customer questions about your hosting.
Start your free SecureSlate trial
FAQ
Is there such a thing as a SOC 2 certified data center?
Not formally. SOC 2 is an attestation report issued by a CPA firm, not a certification. The accurate claim is that a data center has a SOC 2 report, ideally a Type 2, covering named services and facilities.
Does my colo provider's SOC 2 cover physical security in my own SOC 2?
Not automatically. Under the carve-out method its controls are excluded from your report. You list the physical controls you expect it to run, review its report to confirm them, and run the CUECs it assigns to you.
Should a data center include availability in its SOC 2?
We suggest it does. Customers buy uptime, power and cooling, and availability lets the report address those controls directly. Add confidentiality, processing integrity or privacy only when your services and customer commitments call for them.
Is a SOC 3 enough to approve a hosting provider?
Usually not. A SOC 3 is a general use report with less detail, so it lacks the control descriptions, test results and CUECs you need. Ask for the SOC 2 under NDA.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds