Skip to content

EN 50600‑2‑5VDE 0801‑600‑2‑5

Security systems

EN 50600‑2‑5 covers the physical security of a data center: who may enter which space, how intrusion is detected and prevented, and how fires and other events inside and outside the spaces are dealt with. It assigns a to each space for each threat and combines building, technology, and processes into a security concept.

Current edition 2021‑09

What it is about

Part 2‑5 applies the classification for physical security from EN 50600‑1 to the spaces of a data center. It addresses five threats: unauthorized access, intrusion, fires within the spaces, other events within the spaces such as water, gas, dust, or vibration, and events from outside.

The starting point is a risk assessment, from which the Protection Classes for each space and the security level of the technical measures follow. The standard is aimed at building, system, and installation planners as well as those responsible for security installations; structural requirements are in Part 2‑1 (EN 50600‑2‑5:2021, Introduction, Clauses 1, 5.1 and 5.2).

Core requirements in our own words

  1. There is no data center “of one Protection Class”.

    Each space is classified individually for each of the five threats, regardless of the size and purpose of the data center. This applies horizontally and vertically, including risers, elevator shafts, and stairwells. Clause 5.3.

  2. The risk assessment decides, not the standard.

    The responsible organization evaluates the value of the assets, the probability of an attack, and the potential damage, and derives the countermeasures from this. The residual risk is accepted, further reduced, or transferred, for example through insurance. Clause 5.2.

  3. Access follows the “onion skin” model.

    Four Protection Classes against unauthorized access range from the public area to the area reserved for persons with a proven need. All parts of a boundary must offer the same resistance, and pathways must not allow passage between classes. Clause 6.1.2.

  4. Security levels are technical measures, not Protection Classes.

    For access control and intrusion detection, the standard specifies four levels each, from manual control with a log to enforced automated control. Which level applies at which Protection Class boundary is defined in the security concept. Clauses 6.1.4 and 7.2.

  5. Fire protection increases with the class.

    From Class 2, a fire detection and alarm system is mandatory; from Class 3, fire suppression equipment is added; in Class 4, depending on the risk assessment, a fixed fire suppression system with early detection. National regulations apply additionally in all classes, and an alarm should not automatically interrupt operation. Clauses 8.1.1, 8.1.3 and 8.2.

  6. Environmental events have their own classes.

    For internal events such as leakage, gas, dust, or vibration, there are four classes, from “no requirement” to detection and mitigation; Class 4 must be surrounded by Class 3 in all directions. For external events, there are three classes. Clauses 9.1, 9.2, 10.1 and 10.2.

From our seminars: two misconceptions

“Our data center has Protection Class 4.”

The standard states explicitly that a data center of a specific Protection Class does not exist; the outdoor area can be Class 1, the computer room Class 3 or 4. Anyone who designates the computer room as Class 4 must meet the higher requirements at every door and wall.

From seminar practice: a Class 3 computer room with a fire suppression system conforms to the standard if the security concept supports it (Clauses 5.3, 8.2).

“Security level 3 belongs to Protection Class 3.”

The levels describe technical measures and can be assigned freely. A Class 3 space can be secured at level 1, a Class 2 space with a personnel interlock at level 4. What matters is that the assignment is defined in the security concept and consistent across all spaces (Clauses 6.1.4, 7.2).

Where Part 2‑5 applies in a project

  • Planning

    The documented risk assessment determines the Protection Classes for each space and the security levels for each boundary; the result is the security concept.

  • Tendering

    The specification states the security level for each Protection Class boundary and, for each space, the Protection Class against fire and the detection of internal events, instead of prescribing products.

  • Operation and audit

    The organizational processes for visitors, deliveries, and emergencies are actually practiced; people, processes, physical controls, and technology together form the security system. The audit demonstrates that the classes are maintained at every door and every pathway (Clauses 6.3, 11.1).

This protects you from a security concept that fails the audit because of a cable tray connecting two zones. It also saves you level 4 technology in spaces for which the risk assessment results in level 2.

Status and revision

Current edition

DIN EN 50600‑2‑5:2021‑09, German edition of EN 50600‑2‑5:2021; supersedes the 2016 edition and adds intrusion protection as a separate clause.

International

ISO/IEC 22237‑6:2024.

Revision

According to our information as of September 2026, no ongoing revision. Committee CLC/TC 215, national committee DKE/GK 719.

Last reviewed

EN 50600‑2‑5

Frequently asked questions

The physical security of data centers against unauthorized access, intrusion, internal fires, and environmental events inside and outside the spaces, based on the classification from EN 50600‑1 (Clause 1).

Four per threat, except for external environmental events, where there are three. Each space is classified individually for each threat (Clauses 5.3, 6.1.2, 8.1.1, 9.1, 10.1).

No. The standard makes clear that the concept of a data center of a specific Protection Class does not exist; the class applies per space and per threat (Clause 5.3).

The Protection Class describes the space and its need for protection, the security level the technical measure at its boundary, for example single-factor or two-factor access control. The assignment is free and is defined in the security concept (Clauses 6.1.4, 7.2).

Fire detection from Class 2, fire suppression equipment from Class 3, a fixed fire suppression system in Class 4 if the risk assessment requires it. National fire protection regulations apply additionally in all classes (Clauses 8.1.1, 8.2).

  • DIN EN 50600‑2‑5:2021‑09 (German edition of EN 50600‑2‑5:2021), European foreword, Introduction, Clauses 1, 5.1 to 5.3, 6.1.2, 6.1.4, 6.3, 7.2, 8.1.1, 8.1.3, 8.2, 9.1, 9.2, 10.1, 10.2, 11.1
  • ISO/IEC 22237‑6:2024
  • DCE academy seminar practice: Data Center Design & Implementation (session November 2025), Data Center Passport (session January 2026), Data Center – General Principles (session April 2026)

Glossary terms

  • Protection Class (1 to 4)
  • Security level (1 to 4)
  • Onion skin model
  • Risk assessment and residual risk
  • Security concept
  • Fire detection and alarm system
  • Fire suppression system
  • Room-in-room construction
  • Access control system

Contact

Questions about applying EN 50600?

Thomas Wawra answers your questions about applying EN 50600 in your project, and which seminar suits it, by phone or email.

Newsletter

Expert articles and standards updates by email

Expert articles from the newsroom, news from standardization, and the next seminar dates.

You will receive a confirmation email and can unsubscribe at any time. Privacy information