What each standard actually requires of a data centre.
Written as reference material rather than as articles: a definitional answer first, then what auditors ask for, then how it lands market by market. Reviewed by Louisa Cilenti, dated, and sourced.

17 frameworks on one evidence base.
ISO management systems and the statutory regimes are assessed against the same documents. Evidence mapped once is reused, which is why adding a standard starts from what you already hold rather than from nothing.
ISO standards
- ISO 9001 · Quality management systems
- ISO 14001 · Environmental management systems
- ISO 14064-1 · Greenhouse gas inventories
- ISO 22301 · Business continuity management
- ISO 27001 · Information security management
- ISO 42001 · AI management systems
- ISO 45001 · Occupational health and safety
- ISO 50001 · Energy management systems
EU and UK law
- EED · Energy Efficiency Directive, including the Delegated Regulation (EU) 2024/1364 reporting duty
- NIS2 · EU Network and Information Security Directive
- DORA · EU Digital Operational Resilience Act
- UK NIS — CAF · NIS Regulations 2018, assessed against NCSC Cyber Assessment Framework v4.0, with Cyber Security and Resilience Bill duties
- EU Taxonomy · Sustainable activity screening and disclosure
- EU environmental permitting · EIA, IED and MCPD consent conditions
Industry codes and frameworks
- EU Code of Conduct for Data Centre Energy Efficiency · Participant and best-practice register
- SOC 2 · AICPA Trust Services Criteria
- PCI DSS · Payment card data security
Linked entries have a written reference page. The rest are carried in the product and have no public page yet.
Read what a standard requires before you buy anything.
ISO 14001 is the international standard for environmental management systems. For a data centre it governs how you identify environmental aspects and impacts, set objectives against them, control operations that affect them, and demonstrate continual improvement — across energy, water, refrigerants, waste and the supply chain.
Read the reference →ISO 50001 is the international standard for energy management systems. For a data centre it governs how energy performance is measured, what the baseline is, which indicators are tracked, and how improvement is demonstrated — which maps almost directly onto the data an EU operator now has to report anyway.
Read the reference →ISO 14064-1 specifies how an organisation quantifies and reports its greenhouse gas inventory. For a data centre it sets the rules for the organisational boundary, the treatment of indirect emissions, and — critically for colocation — how emissions attributable to tenants are identified and disclosed.
Read the reference →ISO 27001 is the international standard for information security management systems. For a data centre operator it governs how information security risk is assessed and treated across physical security, access control, operations, supplier relationships and incident response — and it is the certificate most frequently demanded in customer due diligence.
Read the reference →ISO 9001 is the international standard for quality management systems. For a data centre it governs how processes are defined and controlled, how nonconformity is handled, and how customer requirements are captured and met — which in practice means maintenance regimes, change control and service delivery.
Read the reference →