Security and Compliance · 2 min read · Aug 11, 2026

Third-Party Security and Compliance in Data Centers: Managing Vendors, Contractors and Service Providers

A practical guide to third-party security for data centers, covering due diligence, contracts, remote and physical access, privileged support, evidence, monitoring, offboarding and supplier risk reviews.

Data centers depend on external organizations for generators, UPS systems, cooling, fire systems, access control, software, networks, cleaning, security, construction and specialist maintenance. Third-party access is therefore necessary, but unmanaged supplier access can create persistent security and compliance exposure.

Perform due diligence before access

Supplier evaluation should consider the sensitivity of the service, required access, dependency on remote connectivity, subcontractors, data handled, support model and ability to meet security obligations. The depth of review should be proportional to risk.

Put security requirements in the agreement

Contracts or service agreements should define applicable security responsibilities, confidentiality, access restrictions, incident notification, use of subcontractors, evidence requirements, retention, return of assets and offboarding obligations where relevant.

Separate company approval from individual access

Approving a vendor does not mean every vendor employee should have unrestricted access. Individual technicians should be identified, authorized for the required period and given only the physical and logical permissions needed for the approved task.

Control remote support

Remote vendor access to BMS, UPS management, security systems or other infrastructure should be explicitly authorized, authenticated and logged. Persistent always-on accounts should be avoided where a controlled on-demand method is practical.

Manage privileged activity

When a supplier needs administrative rights, the organization should know when the session starts, who performs it, what system is affected and when privileges are removed. Change management should apply to configuration changes made by external personnel.

Monitor supplier performance

Supplier assurance should not end at contract signature. Review security incidents, access anomalies, missed maintenance, repeated defects, audit findings, unsupported software and failure to meet agreed evidence requirements.

Control subcontractors

Critical vendors may rely on subcontractors. The organization should understand whether contractual security requirements flow down to them and whether subcontractor personnel are subject to equivalent authorization and access controls.

Offboarding

  • Disable physical and logical credentials.
  • Recover badges, keys and tokens.
  • Remove remote-access accounts.
  • Return or destroy controlled information as required.
  • Transfer configuration files and documentation.
  • Review any shared secrets or passwords that require rotation.
  • Confirm no temporary access remains active.

Key takeaway

Third-party risk should be controlled throughout the supplier lifecycle: selection, contracting, onboarding, access, service delivery, monitoring and offboarding. The data center remains accountable for the security of critical operations even when specialist work is performed by another company.

References and Further Reading

  • ISO/IEC 27001:2022 and Amendment 1:2024.
  • ISO/IEC 27002:2022.
  • ISO/IEC 22237-6:2024.

Send this article

Please sign in to send this article to someone else.
Sign in

Reader comments

No approved comments yet.

Leave a comment

Sending: Sending your comment...

Stay Updated

Subscribe for data center articles, publications, and application updates.