How to procure and implement public data centers: cloud-first, ETP, Law 14.133, TIA-942-C, ISO 22237, redundancy, inspection, commissioning, and acceptance.
Check it out!
Procuring a public data center is not about buying racks, servers, UPS systems, chillers, or generator sets. It is about deciding how a public organization will ensure availability, security, continuity, and capacity for critical digital services over many years — and then transforming that decision into multidisciplinary requirements that can be tendered, inspected, tested, and accepted.
Within Brazil’s Federal Executive Branch entities that are part of SISP, this decision has an even earlier gate: Normative Instruction SGD/ME No. 94/2022 establishes that agencies and entities needing to create, expand, or renew data-center infrastructure must do so through cloud-computing services, unless infeasibility is demonstrated in the Preliminary Technical Study. Therefore, for these agencies, a new investment in physical infrastructure should not begin with the BOM; it begins with the technical and strategic justification for why a physical, hybrid, or modernization alternative is necessary.
When physical infrastructure is justified, the problem changes in nature. A data center combines architecture, electrical systems, uninterruptible power, generation, cooling, telecommunications, automation, physical security, fire detection and suppression, monitoring, management software, operations, and procedures. IN 94 itself distinguishes several of these elements — such as cabling, electrical infrastructure, cooling, and physical security — from the strict category of ICT resources, even when they are part of a data-center room. This separation shows why procurement requires coordination between Engineering and Information Technology.
The most dangerous mistake is to reduce mission-critical infrastructure to an equipment list. Two projects can use similar brands and have completely different resilience levels. Availability results from architecture, elimination of single points of failure, maintainability, failure behavior, operating procedures, and integrated system validation.
The first question is: does the agency really need a new physical data center?
In Brazil’s federal public sector covered by SISP, the decision to create, expand, or renew physical data-center infrastructure must first pass the Preliminary Technical Study gate. The right decision may be cloud, hybrid, modernization, or owned infrastructure — and it must be demonstrated before design begins.
Before discussing power, Tier, redundancy, or technical area, the Preliminary Technical Study must compare alternatives.
In the context of Brazil’s federal SISP, the cloud-first rule of IN SGD/ME No. 94/2022 requires justification when the chosen solution involves creating, expanding, or renewing data-center infrastructure outside the primary cloud strategy.
The analysis should not be superficial. “We need to keep the data inside the building” or “we have always had our own data center” are not, by themselves, engineering justifications.
The study should evaluate at least:
- workload criticality;
- latency requirements;
- data sovereignty and information classification;
- integration with local systems;
- dependence on external connectivity;
- required availability;
- disaster-recovery requirements;
- capacity of existing infrastructure;
- CAPEX and OPEX;
- asset life cycles;
- operational capabilities;
- cloud and hybrid-environment strategy;
- concentration risks;
- portability;
- implementation schedule;
- possibility of colocation or specialized-service contracting.
The Data Center Feasibility Study should turn these dimensions into comparable alternatives, rather than becoming a justification written after the solution has already been selected.
A public data center is a mission-critical system, not an isolated IT project
The infrastructure may support services involving taxation, healthcare, justice, public security, education, identity, administrative systems, institutional data, and essential applications.
Downtime can produce impacts beyond internal productivity loss:
- interruption of citizen services;
- unavailability of core government systems;
- loss of access to critical information;
- communication failures between units;
- integrity and continuity risks;
- reputational impact;
- need for manual operation;
- contractual and regulatory exposure.
For this reason, architecture must derive from business and availability requirements.
Starting with the question “which UPS should we buy?” reverses the logic. First, the project must define which failures the installation must withstand and what level of maintenance must be possible without interrupting the critical load.
Cloud-first does not eliminate Data Center Engineering
Prioritizing cloud does not mean physical facilities have disappeared.
Agencies may maintain existing owned environments, hybrid architectures, edge infrastructure, connectivity infrastructure, technical rooms, local systems, or needs that justify physical resources. In addition, cloud services depend on physical data centers operated by third parties.
The consequence is a shift in focus:
- fewer decisions based on “owning hardware by default”;
- more service-architecture analysis;
- greater importance of end-to-end availability;
- integration between local infrastructure and cloud;
- migration and continuity planning;
- governance of external dependencies.
For existing owned facilities, modernization may be more complex than building a new environment because operations cannot stop.
The article Data Center Modernization Without Interrupting Operations addresses this brownfield condition.
The ETP for a public data center must compare risk, not only price
The lowest initial CAPEX may produce the highest operational risk.
An alternatives analysis should consider life-cycle cost and the consequences of downtime.
| Alternative | CAPEX | OPEX | Control | Scalability | External dependence | Operational complexity |
| owned data center | high | high | high | moderate | lower for local infrastructure | high |
| existing-facility modernization | variable | variable | high | limited by the site | moderate | very high during transition |
| colocation | lower CAPEX | recurring | shared | high | high | moderate |
| cloud | low physical CAPEX | recurring consumption | logical/contractual | high | high | different from building operation |
| hybrid | distributed | mixed | shared | high | multiple | high integration |
The table does not determine a solution. It shows that the comparison must go beyond acquisition price.
The ETP must also document growth assumptions. Designing for current load and discovering two years later that there is no available electrical, thermal, or physical capacity is a planning failure.
How to define availability requirements before design
Availability must be translated into expected behavior.
Useful questions include:
- must the critical load remain online during preventive maintenance?
- can a UPS failure interrupt the service?
- does the loss of one chiller bring down all cooling?
- is there an alternative electrical path to the rack?
- does the IT equipment have dual power supplies?
- does maintenance of the main switchboard require shutdown?
- can an automation failure cause an outage?
- is there enough autonomy for transfer and generator operation?
- which systems must survive a localized fire event?
- how will return to normal condition be tested?
These questions produce architectural requirements.
The terminology N, N+1, 2N, or A/B distribution is useful, but it does not replace system analysis. The article Data Center Electrical Architecture: N, N+1, 2N, and A/B Distribution shows why local redundancy does not guarantee end-to-end resilience.
TIA-942-C and ISO/IEC 22237: how to use standards without turning procurement into a badge exercise
ANSI/TIA-942-C, published in May 2024, covers infrastructure requirements for data centers and computer rooms, including telecommunications, power, cooling, architecture, fire protection, security, and other dimensions.
The ISO/IEC 22237 series structures requirements and recommendations for data-center facilities and infrastructure. Parts published in 2024 address, among other topics, building construction and security systems.
These references help establish common language and technical criteria, but the bidding documents must clearly state which requirements apply to the object.
Simply writing “the data center shall comply with TIA-942” may be insufficient. It is necessary to define:
- scope of compliance;
- target classification;
- disciplines included;
- mandatory requirements;
- verification criteria;
- responsibility for documentation;
- whether independent certification is required;
- treatment of existing installations that cannot fully meet the standard.
A standard should guide verifiable requirements. It should not replace design.
Procurement must separate performance requirements from manufacturer solutions
A public specification should avoid depending on a brand without legal and technical justification.
In mission-critical environments, the solution is to specify performance and interfaces with sufficient depth.
For UPS systems, for example, relevant factors may include:
- power rating and margin;
- topology;
- efficiency;
- redundancy;
- autonomy;
- bypass;
- protection coordination;
- maintenance;
- monitoring interfaces;
- failure behavior;
- generator compatibility;
- environmental requirements.
For cooling:
- thermal load;
- density;
- design conditions;
- redundancy;
- control;
- air or liquid distribution;
- containment;
- monitoring;
- failure response;
- concurrent maintenance.
The same logic applies to generators, switchboards, PDUs, cabling, security, fire protection, and automation.
The BOM should be a consequence of the architecture
Listing equipment before the architecture is finalized creates artificial dependencies.
The correct sequence is:
- business requirements;
- availability requirements;
- capacity and growth;
- conceptual architecture;
- redundancy criteria;
- basic/detailed design;
- performance specifications;
- quantities;
- reference or procurement BOM.
The BOM helps quantify the solution. It should not define the solution by itself.
In public procurement, this distinction reduces the risk of purchasing individually correct components that, once integrated, fail to deliver the required performance.
Disciplines that must be coordinated in a public data center
Architecture and construction
These include compartmentation, access, fire resistance, structural loads, flooring, technical areas, routes, electrical rooms, batteries, storage, docks, and maintenance circulation.
Electrical power
This includes utility supply, medium and low voltage, transformers, switchboards, ATS, STS where applicable, UPS systems, PDUs, A/B distribution, grounding, surge protection, selectivity, power quality, and metering.
Emergency generation
The system should consider starting, transfer, paralleling where applicable, autonomy, fuel, refueling, ventilation, exhaust, maintenance, and behavior with nonlinear loads.
Cooling
IT thermal load is not the only variable. Density, expansion, airflow, containment, redundancy, outdoor conditions, chilled water or direct expansion, pumps, controls, and failures must also be evaluated.
Telecommunications
Topology, pathways, rooms, racks, fiber, copper, cross-connects, and physical redundancy must be coordinated with power and layout.
Physical security
Perimeter, zones, access control, authentication, CFTV, intrusion detection, and procedures should reflect criticality and the operating model.
The content on Physical Security in Data Centers explores this architecture in greater depth.
Fire protection
Early detection, conventional detection, suppression, compartmentation, interfaces with HVAC and power, and emergency procedures must be integrated.
Supervision and automation
BMS, EPMS, and DCIM have different roles. Integration must prevent critical alarms from being lost among hundreds of unprioritized events.
The article DCIM, BMS, and EPMS in Data Centers details the differences.
The greatest risk lies at the interfaces between disciplines
A UPS may be correctly sized and still fail at system level because transfer with the generator was not validated. A redundant chiller may not improve availability if pumps or power remain a single point of failure. Two telecommunications paths may enter the building through the same physical route.
For this reason, inspection cannot be organized only through independent electrical, HVAC, and IT checklists.
It must verify interfaces.
Examples:
- generator x UPS;
- UPS x A/B distribution;
- HVAC x automation;
- fire protection x shutdowns;
- security x emergency routes;
- BMS x EPMS;
- power supply x dual-cord equipment;
- cabling x compartmentation;
- operating model x maintenance.
The value of Owner’s Engineering appears strongly at these boundaries.
How to structure the Terms of Reference for a data center
The document must translate the architecture into verifiable obligations.
A structure may include:
- context and objective;
- service requirements and criticality;
- scope and supply boundaries;
- capacity assumptions;
- availability requirements;
- applicable standards;
- discipline-specific requirements;
- integration requirements;
- design documentation;
- submittals;
- quality and inspection;
- FAT and factory tests;
- installation;
- pre-commissioning;
- functional commissioning;
- integrated tests;
- training;
- As-Built documentation;
- operating procedures;
- acceptance criteria.
The mistake is to devote dozens of pages to equipment datasheets and only a few lines to integration, testing, and acceptance.
Contracting model and risk allocation
Data centers can be procured through different strategies, and each changes the distribution of responsibility.
In a traditional procurement with a detailed owner-provided design, the Public Administration retains greater responsibility for the definition. In integrated or semi-integrated contracting, the risk matrix, performance requirements, and limits of contractor freedom become even more important.
Critical issues include:
- responsibility for final sizing;
- existing-condition risks;
- interfaces with operations;
- coordination;
- approval of equivalents;
- energy performance;
- warranties;
- testing;
- certifications;
- availability during transition;
- consequences of commissioning failure.
The contracting model cannot correct a poorly defined requirement. The more freedom the contractor receives, the clearer the expected outcomes must be.
How to deal with the boundary between ICT procurement and Engineering
IN SGD/ME No. 94/2022 is particularly useful in showing that a data center can combine objects of different legal and technical natures.
Its Annex I excludes from the ICT-resource category, among other items, civil engineering services, physical access control, structured cabling, electrical infrastructure, hydraulic/cooling infrastructure, and fire suppression, even when they are part of a data-center room.
This requires attention to procurement strategy.
The agency must decide whether it will use:
- an integrated multidisciplinary procurement;
- coordinated lots;
- separate contracts;
- construction with specialized supplies;
- ICT procurement separated from building infrastructure.
Any model can work. Risk arises when boundaries are not defined.
An interface without an owner usually becomes a delay or dispute.
Existing data center: due diligence before specifying modernization
Brownfield modernization should begin with diagnosis.
The team needs to survey:
- actual single-line diagrams;
- installed capacities;
- loads;
- condition of UPS systems and batteries;
- autonomy;
- generators;
- power quality;
- cooling;
- airflow;
- rack capacity;
- cabling routes;
- security;
- fire protection;
- automation;
- alarms;
- maintenance;
- failure history;
- existing documentation.
The Data Center and Server Room Diagnosis and Modernization service establishes a technical baseline before interventions are decided.
Without a survey, the bidding documents transfer unknowns into price or future change orders.
Capacity should be designed as a vector, not a single number
Saying that the data center will have “500 kW” is insufficient.
Capacity involves:
- total power;
- power per rack;
- space;
- cooling;
- network;
- ports;
- autonomy;
- generation capacity;
- available paths;
- expansion reserve;
- operational capacity.
The real bottleneck is the smallest of these limits.
A site may have available substation capacity but lack sufficient cooling, space, or distribution.
Capacity Management in Data Centers must continue throughout the asset’s life after handover.
Efficiency cannot compromise resilience
PUE, WUE, and other indicators are important, but they must be interpreted together with the load profile and architecture.
A public-sector design may pursue efficiency through:
- high-efficiency equipment;
- containment;
- controlled temperature increases;
- free cooling where applicable;
- setpoint optimization;
- better capacity utilization;
- reduced electrical losses;
- monitoring.
But savings should not create a single point of failure or eliminate required margin.
The assessment must integrate life-cycle cost, sustainability, and mission.
Commissioning must be specified before construction
Commissioning is not a final inspection added after the installation is complete.
Testing criteria must influence design, procurement, documentation, and interfaces.
A program may include:
- requirements review;
- design review;
- submittals;
- manufacturing inspections;
- FAT;
- installation checklists;
- individual tests;
- functional tests;
- load tests;
- failure scenarios;
- integrated systems testing;
- restoration;
- results documentation;
- open-item management.
The article Data Center Commissioning: Tests, Levels, and Acceptance Criteria presents the progressive testing logic.
IST: integrated testing is where architecture stops being a promise
A diagram can show perfect redundancy. IST verifies how the overall system behaves when real events are induced.
Scenarios may include:
- loss of normal power;
- UPS failure;
- failure of a redundant module;
- transfer to generator;
- loss of cooling equipment;
- loss of a pump;
- automation communication failure;
- fire-detection activation;
- loss of path A or B;
- return to normal condition.
The goal is not to “bring down the data center.” It is to demonstrate that anticipated failures are contained and that recovery procedures can actually be executed.
The content IST in Data Centers: Integrated Tests, Scenarios, and Acceptance Criteria explores this topic further.
Acceptance cannot depend on equipment simply being energized
“Powered on” does not mean “accepted.”
Technical acceptance should verify:
- installation;
- configuration;
- testing;
- redundancy;
- alarms;
- documentation;
- As Built;
- training;
- procedures;
- open-item list;
- warranties;
- spare parts;
- integration;
- performance under anticipated scenarios.
The Data Center Commissioning and Acceptance service structures this verification independently.
MOP, SOP, and EOP must exist before operation
Resilient facilities can still fail because of inadequate procedures.
MOPs describe planned maintenance operations; SOPs structure routine operations; EOPs guide emergency response.
The content MOP, SOP, and EOP in Data Centers shows why procedures are part of reliability.
Handover should deliver not only assets, but operational capability.
Physical security in a public data center requires zoning and traceability
Government facilities may concentrate sensitive information and services.
Security should combine:
- perimeter;
- zones;
- identity;
- access control;
- authentication;
- area segregation;
- CFTV;
- intrusion detection;
- visitor records;
- procedures;
- log retention;
- incident response.
ISO/IEC 22237-6:2024 addresses requirements and recommendations for data-center security systems regarding unauthorized access, intrusion, and internal and external events.
A public-sector requirement should avoid becoming a simple list of cameras and readers. It must define protection objectives, coverage, retention, integration, and operations.
How to inspect data-center implementation
Inspection must follow the complete chain, not only the civil-construction stage.
A matrix can use phases:
| Phase | Main evidence |
| design | calculations, diagrams, studies, coordination |
| procurement | submittals, equivalence, FAT, certificates |
| installation | inspections, checklists, photos, torque, identification |
| pre-commissioning | individual tests, calibration, continuity |
| commissioning | functional tests and interlocks |
| IST | integrated scenarios and simulated failures |
| handover | As Built, Data Book, procedures, training |
The inspector should have access to the evidence before measurement of the corresponding milestones.
Measurement should follow verifiable deliverables
Data centers contain expensive equipment. This creates a risk that the financial curve advances far ahead of operational readiness.
Measurement can be linked to milestones such as:
- approved design;
- manufacturing;
- FAT;
- delivery;
- installation;
- energization;
- functional testing;
- IST;
- acceptance.
Weights must be balanced to avoid front-loading.
Equipment delivered to site does not represent the same value as an installed, tested, and integrated system.
Owner’s Engineering: why the public sector needs an independent perspective
In mission-critical infrastructure, the integrator should not be the only source confirming that its own architecture serves the owner’s interests. An independent layer reviews design, interfaces, proposals, submittals, measurements, tests, and risks.
In a complex procurement, the contractor has a legitimate interest in fulfilling its contract and optimizing its solution. The Public Administration needs a technical layer representing its own requirements.
Owner’s Engineering can act in:
- requirements definition;
- ETP and Terms of Reference review;
- architecture review;
- proposal analysis;
- technical equivalence;
- design review;
- inspection;
- submittal analysis;
- inspections;
- measurement validation;
- interface control;
- risk management;
- commissioning;
- acceptance;
- handover.
The Owner’s Engineering for Data Centers service was structured specifically for this governance between requirements, design, implementation, and acceptance.
Independence in ICT assessment and inspection
IN SGD/ME No. 94/2022 contains a particularly relevant principle: when assessment, measurement, or inspection-support services for an ICT solution are contracted, the company providing the solution cannot be the same company that assesses, measures, or supports its inspection.
Even when part of the physical infrastructure falls under an Engineering framework, the principle of independence is valuable for mission-critical systems.
The integrator should not be the only source confirming that its own architecture meets the requirement.
Example: modernization of a public agency’s data center
Consider an agency with a 12-year-old data center, growing critical load, and a history of cooling alarms.
The initial demand might be “replace the UPS and air conditioning.” Due diligence reveals:
- UPS near its limit;
- batteries near end of life;
- generator with insufficient autonomy;
- electrical distribution with a single point of failure;
- nominal N+1 cooling only, because units share the same power supply;
- racks with uneven density;
- BMS not integrated with EPMS;
- convergent fiber routes;
- outdated As-Built documentation.
Buying only new UPS systems and CRAC units does not resolve the systemic risk.
The strategy becomes:
- validate physical need versus cloud/hybrid;
- define the availability requirement;
- create the target architecture;
- plan phases without interruption;
- design paths and redundancies;
- specify equipment by performance;
- procure with an interface matrix;
- execute with independent inspection;
- perform progressive commissioning;
- test integrated scenarios;
- deliver procedures and As Built.
The difference between equipment purchasing and Consulting Engineering lies precisely in this transformation of demand into a system.
Checklist before tendering a public data center
The Public Administration should be able to answer:
- did the ETP compare cloud, hybrid, and physical infrastructure where applicable?
- is the need for the data center technically justified?
- have availability requirements been defined?
- has current and future capacity been estimated?
- is the electrical architecture finalized?
- is cooling coordinated with density?
- do physical security and fire protection have defined criteria?
- do telecommunications have defined routes and redundancy?
- are monitoring systems integrated?
- are interfaces between ICT and Engineering defined?
- is the contracting model consistent with design maturity?
- does the risk matrix cover existing conditions and availability?
- are commissioning requirements included in the bidding documents?
- does IST have defined scenarios and criteria?
- is measurement linked to verifiable deliverables?
- are As Built and Data Book requirements specified?
- are training and procedures part of acceptance?
If several answers are negative, the bidding documents are probably attempting to procure equipment before procuring a mission-critical architecture.
When to use a Feasibility Study, Design, Owner’s Engineering, and Commissioning
These services solve different problems.
Feasibility Study
Defines the alternative: maintain, modernize, build, colocation, cloud, or hybrid.
Data Center Design
Transforms requirements into architecture, calculations, drawings, specifications, and procurement documents.
Owner’s Engineering
Technically represents the owner during procurement and implementation.
Commissioning
Verifies whether the installed system meets requirements and operates under normal and failure scenarios.
In higher-risk projects, the four form a logical sequence.
The technical gates that should precede tendering and acceptance
For critical infrastructure, procurement becomes safer when irreversible decisions are conditioned on technical gates. The objective is to prevent the project from advancing to acquisition, installation, or acceptance while assumptions remain open. Each gate should close a set of decisions and produce sufficient evidence to authorize the next phase.
| Gate | Decision | Minimum evidence |
| G0 — strategy | cloud, hybrid, colocation, modernization, or owned infrastructure | ETP, criticality, service requirements, alternatives analysis, and TCO |
| G1 — requirements | which availability, capacity, and resilience will be contracted | Owner’s Project Requirements, growth assumptions, criticality matrix, and continuity criteria |
| G2 — architecture | how power, cooling, telecommunications, fire protection, security, and automation integrate | diagrams, calculations, interface matrix, single-point-of-failure analysis, and concurrent maintenance |
| G3 — procurement | whether proposed equipment and systems meet specified performance | submittals, technical equivalence, data sheets, studies, FAT, and manufacturer documentation |
| G4 — readiness for energization | whether the installation can safely begin functional testing | checklists, inspections, calibration, torque, continuity, configuration, and controlled punch list |
| G5 — operational readiness | whether the system withstands operating and failure scenarios | functional tests, interlocks, alarms, load tests, and IST |
| G6 — acceptance | whether the owner can take over the asset | As Built, Data Book, MOP/SOP/EOP, training, warranties, residual open items, and performance evidence |
This sequence reduces the risk of accepting a technically incomplete system simply because physical installation has ended. In data centers, a significant part of the value appears precisely in what can only be demonstrated during simulated failure, planned maintenance, source transfer, and restoration.
Redundancy must be verified as a chain, not as a label
One of the most common traps is treating N+1 or 2N as an isolated equipment attribute. Real resilience depends on the complete chain from source to load. A system may have redundant UPS units and remain vulnerable because they share a single switchboard, bus, ATS, route, controller, pump supply, or distribution point.
Therefore, for every foreseeable failure, the architecture review must ask three questions: which component is lost, which path takes over the load, and which functions remain available during recovery. The answer must be demonstrable in diagrams and later proven through testing.
The same logic applies to cooling and telecommunications. Two machines do not provide effective redundancy if they depend on the same power source or hydraulic circuit. Two links do not provide diversity if they follow the same physical route. Supplier-declared redundancy must be converted into a single-point-of-failure analysis.
Acceptance must be tied to a performance matrix
Strong bidding documents do not end with a list of equipment and services. They explain how the Public Administration will recognize that the object has actually been delivered. For this purpose, each relevant requirement must have a verification method.
Documentary requirements can be verified by reviewing submittals and the Data Book. Physical requirements may require inspection. Capacity requirements require measurements. Redundancy requirements require component isolation and loss of paths. Integration requirements require interlock tests. Continuity requirements require integrated scenarios.
The performance matrix should originate in the design and be carried into the Terms of Reference, commissioning plan, and measurement reports. In this way, the criterion used to specify the system is the same one used to inspect and accept it. This reduces subjectivity, prevents premature acceptance, and strengthens the Public Administration’s technical position in the event of disputes.
Final considerations
Public data centers require a rare combination of Engineering, ICT, procurement, security, operations, and governance. Service criticality does not allow procurement to be reduced to catalog equipment.
Within Brazil’s federal SISP, planning itself begins with the cloud-first strategy and requires justification when a physical solution is selected. When such infrastructure is necessary, the Public Administration must define availability, capacity, architecture, interfaces, performance criteria, measurement, commissioning, and acceptance before tendering.
TIA-942-C and ISO/IEC 22237 help structure technical requirements, but they do not replace engineering of the object. Redundancy must be analyzed end to end, and system behavior must be demonstrated through integrated testing.
The procurement objective is not to receive a set of energized equipment. It is to receive infrastructure capable of sustaining the public services for which it was designed, with known risks, complete documentation, and demonstrated performance.
Data-center acceptance should be based on demonstrated performance. Individual, functional, and integrated tests must prove that the installation responds correctly to failures, transfers, and recovery conditions anticipated in the design.
Technical references
[1] BRASIL. Lei nº 14.133, de 1º de abril de 2021 — Lei de Licitações e Contratos Administrativos. 2021. Available at: https://www.planalto.gov.br/ccivil_03/_ato2019-2022/2021/lei/l14133.htm.
[2] SECRETARIA DE GOVERNO DIGITAL. Instrução Normativa SGD/ME nº 94, de 23 de dezembro de 2022 — processo de contratação de soluções de TIC. 2022. Available at: https://www.gov.br/governodigital/pt-br/contratacoes-de-tic/legislacao/processo-de-contratacao-de-solucoes-de-tic-regido-pela-lei-ndeg-14-133-de-2021.
[3] GOVERNO DIGITAL. Data Centers no Governo Federal. 2026. Available at: https://www.gov.br/governodigital/pt-br/infraestrutura-nacional-de-dados/ambiente-tecnologico/data-centers.
[4] TELECOMMUNICATIONS INDUSTRY ASSOCIATION. ANSI/TIA-942-C — Telecommunications Infrastructure Standard for Data Centers. 2024. Available at: https://tiaonline.org/standard/tia-942/.
[5] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO/IEC 22237-2:2024 — Data centre facilities and infrastructures — Building construction. 2024. Available at: https://www.iso.org/standard/82248.html.
[6] INTERNATIONAL ORGANIZATION FOR STANDARDIZATION. ISO/IEC 22237-6:2024 — Data centre facilities and infrastructures — Security systems. 2024. Available at: https://www.iso.org/standard/82250.html.
Frequently asked questions
For agencies and entities that are part of SISP, IN SGD/ME 94/2022 establishes that the creation, expansion, or renewal of data-center infrastructure must follow the cloud-computing service contracting strategy unless infeasibility is demonstrated in the Preliminary Technical Study.
It may involve both. IN 94/2022 excludes several physical elements from the ICT-resource category, such as civil engineering, structured cabling, electrical infrastructure, cooling, physical access control, and fire suppression, even when they are part of a data-center room. The strategy must clearly define the interfaces.
There is no general national requirement to certify every public data center to TIA-942-C. The standard may be adopted as a technical reference according to the object, and the bidding documents should define which requirements, classifications, and verifications will be required.
Criticality, availability requirements, capacity, electrical architecture, redundancy, autonomy, maintenance, and expected failure behavior should be defined. The equipment is a consequence of these requirements.
Because individually approved equipment can fail when integrated. Commissioning verifies functions, interlocks, alarms, redundancy, and failure scenarios, culminating in integrated system testing.
N+1 describes reserve capacity in a given subsystem. Resilience requires analysis of the complete path to determine whether single points of failure exist and whether there is adequate maintainability and behavior when components or utilities are lost.
It technically represents the owner in requirements definition, design review, procurement, proposal analysis, inspection, interface control, measurement validation, commissioning, acceptance, and handover.
Supplementary technical materials
Related solutions
- Data Centers: critical infrastructure, availability, power, and connectivity
- Data Center Infrastructure Management — DCIM
Related services
- Data Center Feasibility Study
- Data Center Design
- Owner’s Engineering for Data Centers
- Data Center Commissioning and Acceptance