What it is about
Part 2‑5 applies the classification for physical security from EN 50600‑1 to the spaces of a data center. It addresses five threats: unauthorized access, intrusion, fires within the spaces, other events within the spaces such as water, gas, dust, or vibration, and events from outside.
The starting point is a risk assessment, from which the Protection Classes for each space and the security level of the technical measures follow. The standard is aimed at building, system, and installation planners as well as those responsible for security installations; structural requirements are in Part 2‑1 (EN 50600‑2‑5:2021, Introduction, Clauses 1, 5.1 and 5.2).
Core requirements in our own words
There is no data center “of one Protection Class”.
Each space is classified individually for each of the five threats, regardless of the size and purpose of the data center. This applies horizontally and vertically, including risers, elevator shafts, and stairwells. Clause 5.3.
The risk assessment decides, not the standard.
The responsible organization evaluates the value of the assets, the probability of an attack, and the potential damage, and derives the countermeasures from this. The residual risk is accepted, further reduced, or transferred, for example through insurance. Clause 5.2.
Access follows the “onion skin” model.
Four Protection Classes against unauthorized access range from the public area to the area reserved for persons with a proven need. All parts of a boundary must offer the same resistance, and pathways must not allow passage between classes. Clause 6.1.2.
Security levels are technical measures, not Protection Classes.
For access control and intrusion detection, the standard specifies four levels each, from manual control with a log to enforced automated control. Which level applies at which Protection Class boundary is defined in the security concept. Clauses 6.1.4 and 7.2.
Fire protection increases with the class.
From Class 2, a fire detection and alarm system is mandatory; from Class 3, fire suppression equipment is added; in Class 4, depending on the risk assessment, a fixed fire suppression system with early detection. National regulations apply additionally in all classes, and an alarm should not automatically interrupt operation. Clauses 8.1.1, 8.1.3 and 8.2.
Environmental events have their own classes.
For internal events such as leakage, gas, dust, or vibration, there are four classes, from “no requirement” to detection and mitigation; Class 4 must be surrounded by Class 3 in all directions. For external events, there are three classes. Clauses 9.1, 9.2, 10.1 and 10.2.
From our seminars: two misconceptions
“Our data center has Protection Class 4.”
The standard states explicitly that a data center of a specific Protection Class does not exist; the outdoor area can be Class 1, the computer room Class 3 or 4. Anyone who designates the computer room as Class 4 must meet the higher requirements at every door and wall.
From seminar practice: a Class 3 computer room with a fire suppression system conforms to the standard if the security concept supports it (Clauses 5.3, 8.2).
“Security level 3 belongs to Protection Class 3.”
The levels describe technical measures and can be assigned freely. A Class 3 space can be secured at level 1, a Class 2 space with a personnel interlock at level 4. What matters is that the assignment is defined in the security concept and consistent across all spaces (Clauses 6.1.4, 7.2).
Where Part 2‑5 applies in a project
Planning
The documented risk assessment determines the Protection Classes for each space and the security levels for each boundary; the result is the security concept.
Tendering
The specification states the security level for each Protection Class boundary and, for each space, the Protection Class against fire and the detection of internal events, instead of prescribing products.
Operation and audit
The organizational processes for visitors, deliveries, and emergencies are actually practiced; people, processes, physical controls, and technology together form the security system. The audit demonstrates that the classes are maintained at every door and every pathway (Clauses 6.3, 11.1).
This protects you from a security concept that fails the audit because of a cable tray connecting two zones. It also saves you level 4 technology in spaces for which the risk assessment results in level 2.
Status and revision
- Current edition
DIN EN 50600‑2‑5:2021‑09, German edition of EN 50600‑2‑5:2021; supersedes the 2016 edition and adds intrusion protection as a separate clause.
- International
ISO/IEC 22237‑6:2024.
- Revision
According to our information as of September 2026, no ongoing revision. Committee CLC/TC 215, national committee DKE/GK 719.
- Last reviewed
EN 50600‑2‑5
Frequently asked questions
The physical security of data centers against unauthorized access, intrusion, internal fires, and environmental events inside and outside the spaces, based on the classification from EN 50600‑1 (Clause 1).
Four per threat, except for external environmental events, where there are three. Each space is classified individually for each threat (Clauses 5.3, 6.1.2, 8.1.1, 9.1, 10.1).
No. The standard makes clear that the concept of a data center of a specific Protection Class does not exist; the class applies per space and per threat (Clause 5.3).
The Protection Class describes the space and its need for protection, the security level the technical measure at its boundary, for example single-factor or two-factor access control. The assignment is free and is defined in the security concept (Clauses 6.1.4, 7.2).
Fire detection from Class 2, fire suppression equipment from Class 3, a fixed fire suppression system in Class 4 if the risk assessment requires it. National fire protection regulations apply additionally in all classes (Clauses 8.1.1, 8.2).
Seminars
Related seminars
Training path 2/4
DC-21002Data Center Design & Implementation
according to EN 50600 and ISO/IEC 22237
5 days · In person · Live webinar
Risk assessment, Protection Classes per threat, security levels, and fire protection in connection with Part 2‑1, with exercises on the security concept; this saves you zones that do not fit together in the audit.
Next date: 23–27 Nov 2026, onlinePrice plus VAT: €6,990Training path 1/4
DC-21001Data Center – General Principles
3 days · In person · Live webinar · Video course
The introduction to zoning, Resistance Classes, and fire protection in the data center.
Next date: 19–21 Oct 2026, onlinePrice plus VAT: €4,195
All prices plus VAT; the price is the same in every format.
- DIN EN 50600‑2‑5:2021‑09 (German edition of EN 50600‑2‑5:2021), European foreword, Introduction, Clauses 1, 5.1 to 5.3, 6.1.2, 6.1.4, 6.3, 7.2, 8.1.1, 8.1.3, 8.2, 9.1, 9.2, 10.1, 10.2, 11.1
- ISO/IEC 22237‑6:2024
- DCE academy seminar practice: Data Center Design & Implementation (session November 2025), Data Center Passport (session January 2026), Data Center – General Principles (session April 2026)
Glossary terms
- Protection Class (1 to 4)
- Security level (1 to 4)
- Onion skin model
- Risk assessment and residual risk
- Security concept
- Fire detection and alarm system
- Fire suppression system
- Room-in-room construction
- Access control system
