Signing a colocation contract is easy to rush and expensive to reverse. This checklist is designed as a reusable due-diligence tool for comparing data centres before you commit: what to ask about resilience, power, cooling, access, network options, remote hands, security, compliance, pricing, and contract language. Use it when you are building a shortlist, touring facilities, reviewing a master service agreement, or re-evaluating an existing site before renewal.
Overview
A good data centre evaluation is less about glossy tour language and more about operational detail. Most colocation providers can describe uptime goals, security controls, and support options in broad terms. The real differences appear when you ask how those promises are delivered, documented, and priced.
This matters whether you are deploying one cabinet for a small production stack or planning a multi-site footprint for resilience and edge hosting. A facility may look suitable on paper yet still be a poor fit because remote hands are slow, cross connects are expensive, after-hours access is restrictive, or available power densities do not match your hardware roadmap.
Use the checklist below to compare providers in a way that is practical rather than theoretical. You are not trying to identify the “best” data centre in the abstract. You are trying to decide whether a specific facility is a good operational and commercial fit for your workloads.
As you work through it, keep three ideas in view:
- Match the facility to the workload. A latency-sensitive service, regulated workload, backup target, and internal business application do not have the same requirements.
- Separate marketing claims from verifiable detail. Ask for definitions, limits, escalation paths, maintenance policies, and sample reporting.
- Audit the contract as closely as the building. Many expensive surprises come from billing terms, support scope, access rules, and renewal clauses rather than from the raised floor itself.
If you are still deciding whether colocation is the right operating model, it helps to compare it against other options before you go deeper. See Colocation vs Dedicated Server vs Cloud: Which Hosting Model Fits Your Workload? and VPS vs Bare Metal: Performance, Cost, and Control Tradeoffs.
Core questions to ask every provider
- What level of power redundancy is provided to my space, and what assumptions should I make about my own A/B power design?
- How is cooling delivered, monitored, and constrained at the rack or cage level?
- What are the standard and emergency access procedures for my staff and contractors?
- What network carriers are available on-site, and what does it cost and take to order cross connects?
- What exactly is included in remote hands, and what is billed separately?
- How are incidents communicated, escalated, and reviewed with customers?
- Which certifications or audit reports are available, and under what NDA or review process?
- What are the contract term, renewal mechanics, exit conditions, and price adjustment rules?
Checklist by scenario
The right audit questions change depending on how you plan to use the facility. Start with the scenario closest to your project, then layer on the general checklist.
Scenario 1: First colocation deployment for a small team
If this is your first move from dedicated server hosting or cloud infrastructure into colo, operational simplicity matters as much as facility quality.
- Onboarding: Ask who owns move-in coordination, delivery handling, rack allocation, labeling expectations, and installation prerequisites.
- Remote hands: Confirm response windows, available hours, minimum billing increments, and whether basic tasks such as cable checks, power cycles, and media swaps are covered.
- Access control: Check how quickly new users can be authorized and whether emergency access for unplanned incidents is realistic.
- Cross-connect process: Understand order lead times, monthly charges, setup fees, and demarcation details.
- Power planning: Verify available amperage, per-cabinet density limits, socket types, and whether burst usage creates billing issues.
- Documentation: Ask for sample runbooks, incident communications, maintenance notices, and customer portal views.
For smaller teams, the practical question is often whether the provider can compensate for limited in-house presence. If not, a managed dedicated platform may be simpler. Compare operational tradeoffs in Managed vs Unmanaged Dedicated Servers: Total Cost and Risk Comparison.
Scenario 2: Latency-sensitive or edge hosting deployment
For edge hosting and low-latency applications, geography alone is not enough. You need to evaluate both physical location and network path quality.
- Metro fit: Ask why this site is suitable for your user distribution, not just whether it is in the right city.
- Carrier diversity: Verify actual on-site network choice, not just a long provider list used in sales material.
- Meet-me room and interconnection: Understand where handoffs occur and how quickly additional links can be provisioned.
- Backhaul strategy: If this is an edge node, ask how traffic returns to core regions and whether the facility supports that design cleanly.
- Operational access: A low-latency site is less useful if routine changes are difficult or support is slow.
To pressure-test location choices, review How to Deploy a Server Close to Your Users: A Practical Region Selection Workflow and Best Server Location for SEO and Core Web Vitals. For network choice, pair this article with Carrier-Neutral Data Centre Checklist: How to Verify Network Choice Before You Sign.
Scenario 3: Compliance-sensitive workloads
If your environment has data residency, auditability, or sector-specific control requirements, the colo audit has to cover both the facility and your own control boundaries.
- Data residency: Confirm where systems and backups will physically reside, including any optional services that may be delivered from other jurisdictions.
- Customer responsibilities: Clarify which controls the provider manages and which remain yours.
- Visitor and access logs: Ask how access is recorded, retained, and made available for audit support.
- Media handling: Review policies for disk swaps, failed drive custody, and destruction workflows.
- Evidence: Request available audit reports, certificates, or control summaries in a form your compliance process can actually use.
For a focused review of jurisdiction and control questions, see How to Choose a Data Centre for GDPR and Data Residency Requirements.
Scenario 4: High-density, growth-oriented, or mixed hardware estates
If you expect rapid scaling or mixed generations of hardware, ask about constraints that only emerge after move-in.
- Density roadmap: Can the provider support higher-density cabinets later, or would you need to relocate within the facility?
- Cage expansion: If you grow, can contiguous space be reserved or offered, and on what timeline?
- Cooling design: Ask what best practices are expected for airflow management, blanking panels, containment, and cabinet layout.
- Receiving and staging: Check whether there is practical space and process for larger refresh cycles.
- Supply chain support: If you depend on replacement parts, ask how deliveries are accepted and how long they can be held.
Scenario 5: Multi-site resilience or disaster recovery
If you are comparing datacentres as part of a primary and secondary site strategy, do not audit each site in isolation.
- Failure domain separation: Confirm the sites are not exposed to the same local risks, providers, or single points in practice.
- Network design: Understand how replication, failover, and management traffic will move between locations.
- Operational symmetry: Ask whether access, support scope, and standard operating conditions are similar enough to make failover realistic.
- Testing support: Check whether planned failover exercises can be scheduled without procedural friction.
Before migration or dual-running, it is also worth benchmarking likely performance and support quality. See How to Benchmark a Hosting Provider Before You Migrate.
What to double-check
This is the section most teams should revisit before legal review and signature. These are the areas where assumptions often survive too long.
Facility resilience
- Redundancy language: If the provider refers to a Tier 3 data centre or Tier 4 data centre, ask what that means in practical service terms for your specific deployment rather than relying on shorthand.
- Maintenance windows: Ask how planned works are communicated and how customer risk is reduced during maintenance.
- Generator and UPS dependency: Clarify what parts of the path are shared, what is customer-responsible, and how testing is handled.
Power and cooling fit
- Confirm committed power, billing method, overage treatment, and any distinction between reserved and used capacity.
- Check whether dual-corded equipment and A/B feeds are expected for SLA alignment.
- Ask what happens if your cabinet design creates local hot spots even when total draw is within contract.
Network and interconnection
- Do not stop at “carrier neutral data centre” as a label. Ask which providers are live, how they enter the facility, and how quickly you can provision and modify links.
- Review recurring and non-recurring charges for cross connects, including future adds and changes.
- Ask how outages involving third-party carriers are triaged and communicated.
Support operations
- Request the remote hands task catalog, not just a summary.
- Confirm response-time targets by severity and by time of day.
- Ask who is available during major incidents and whether escalation reaches on-site engineers or only a service desk.
Physical security and access
- Ask how visitors, contractors, and couriers are handled.
- Check whether after-hours access requires advance notice.
- Review escort policies, loading bay processes, equipment intake rules, and cage key or badge management.
Commercial terms
- Read all installation, power, remote hands, and cross-connect pricing schedules together.
- Check renewal clauses, notice periods, annual uplifts, and what triggers repricing.
- Confirm decommissioning, move-out, disposal, and final billing procedures.
If you want a more structured look at recurring charges and hidden line items, read Data Centre Pricing Explained: Colocation, Power, Cross Connects, and Hidden Fees.
Common mistakes
The most expensive colocation decisions are often not dramatic errors. They are ordinary assumptions that go untested.
- Choosing on facility prestige alone. A respected name does not guarantee the right fit for your workloads, processes, or budget.
- Overweighting headline uptime language. Uptime claims matter, but operations, access, support scope, and interconnection costs may affect your day-to-day outcome more.
- Ignoring network economics. A site with excellent location can become costly or restrictive if cross connects and carrier choice do not support your design.
- Underestimating remote-hands dependency. Small teams often assume they can operate remotely until the first urgent hardware issue exposes support gaps.
- Not mapping customer responsibility. Colocation gives control, but also shifts more operational responsibility onto your team.
- Signing before growth is discussed. Even if your first footprint is modest, ask about adjacent space, higher-density options, and contract flexibility.
- Treating compliance as a late-stage review. If data residency hosting or audit evidence matters, bring those questions into shortlist creation, not just procurement.
- Comparing providers with different assumptions. Normalize what is included: rack size, power commit, support hours, installation, security scope, and cross-connect charges.
A useful discipline is to build a comparison sheet with a column for “evidence seen.” If a claim is not backed by a document, portal screenshot, contract clause, sample report, or direct answer from operations staff, treat it as unverified.
When to revisit
A data centre audit checklist should not be a one-time procurement document. Revisit it whenever the workload, risk profile, or provider relationship changes.
- Before renewal: Re-check pricing schedules, support scope, access rules, and planned capacity needs.
- Before hardware refresh: Validate power density, cooling suitability, receiving processes, and staging support for new equipment.
- Before adding a second site: Re-run network, interconnection, and operational symmetry questions.
- When compliance requirements change: Review data residency, audit evidence, media handling, and access logging.
- When your team structure changes: A leaner on-call team may need stronger remote hands or more permissive access workflows.
- Before seasonal planning cycles: Capacity, contract timing, and deployment sequencing are easier to manage before budget and change windows tighten.
- When workflows or tools change: New deployment patterns, backup targets, or hybrid cloud links can change what the right facility looks like.
To make this practical, turn the checklist into a repeatable scorecard:
- List your non-negotiables: geography, compliance boundary, power model, access needs, and carrier requirements.
- Assign weighted criteria: resilience, network choice, support operations, commercial clarity, and expansion fit.
- Capture evidence for each answer: contract text, sample ticket response, photos, diagrams, and facility tour notes.
- Flag unknowns separately from negatives. Unknowns are often more dangerous than clear shortcomings.
- Review the scorecard again just before signature, because commercial terms and operational assumptions often drift during negotiation.
The goal is not to eliminate all uncertainty. It is to avoid preventable surprises and choose a colocation provider with a clear understanding of tradeoffs. In a market full of broad claims, a disciplined audit process is one of the few reliable advantages a buyer can create.
If your shortlist still includes alternatives outside colocation, compare them alongside your audit results using Best Dedicated Server Hosting for High-Traffic Websites: What to Compare. A careful comparison across dedicated server hosting, cloud, and data centre hosting will usually produce a better decision than optimizing one model in isolation.