What a single-tenant building you own actually changes
In shared space, the physical control families of every framework arrive as inherited controls.
You spend the audit reconciling a provider’s report against your own scope, defending
subservice-organization carve-outs, mapping a shared-responsibility matrix, and explaining an
access list you do not govern. When the landlord changes a procedure, your evidence changes with
it, and you find out afterwards.
Here, those controls are first-party. The access list is yours. The cameras and their retention
are yours. The visitor log, the environmental monitoring, the suppression test records, the
badge revocation process, the media destruction procedure and the change history are all
produced by systems you operate, in a building where you are the only tenant. Scope becomes a
property line instead of a negotiation, and the hardest evidence in the binder becomes the
easiest.
Trust servicesSOC 2 Type IIPhysical access, environmental safeguards and change management evidenced end to end from systems you run.
Trust servicesSOC 1 / SSAE 18For customers whose auditors reach into your controls over financial reporting.
ISMSISO/IEC 27001:2022The Annex A physical control theme falls inside your own management system rather than a provider’s.
Cloud servicesISO/IEC 27017 & 27018Cloud-specific controls and PII handling for anyone selling inference as a service.
AI governanceISO/IEC 42001The AI management system standard enterprise procurement has started writing into contracts.
ContinuityISO 22301Business continuity backed by generation, fuel and UPS you own and test on your own schedule.
HealthcareHIPAA & HITECHThe physical safeguards standard is satisfied under your sole control, so you can sign BAAs without a landlord in the chain.
HealthcareHITRUST CSFThe prescriptive certification hospital systems and payers actually ask for by name.
PaymentsPCI DSS v4.0Requirement 9 physical access inside a genuinely single-tenant cardholder data environment.
Defense supply chainCMMC 2.0 Level 2Controlled unclassified information with a physical boundary you draw and defend yourself.
Federal baselineNIST SP 800-171 & 800-53PE and MP control families implemented directly rather than inherited and argued.
Federal authorizationFedRAMP Moderate / High pathA defensible authorization boundary is far easier to draw around a facility you hold in fee simple.
State & localStateRAMP / TX-RAMPState government programs that lean on the same evidence base.
Law enforcementCJIS Security PolicyPersonnel screening, physical zones and escort rules enforced at a door you own.
Tax dataIRS Publication 1075Federal tax information handling, including restricted-area requirements.
Export controlITAR / EARU.S.-person-only physical access is enforceable when you control the badge system.
EducationFERPAStudent records for education technology and research workloads.
Public companySOX ITGCAccess, change and operations controls your listed customers will test annually.
PrivacyGDPR, CCPA / CPRAData residency you can point to on a survey map, with a named legal entity behind it.
AI riskNIST AI RMF 1.0 & EU AI Act readinessGovernance, traceability and human-oversight evidence for models you host yourself.
MediaMPA Content Security / TPNStudio-grade content handling — already the operating standard in this building.
Content protectionWidevine, PlayReady, FairPlayThe incumbent operator is Widevine CWIP-certified, so the facility is already run to key-handling discipline.
Design intentTIA-942 / concurrently maintainableRedundancy topology documented for gap assessment against the rating you want to target.
Sovereign AIU.S. data residencyFor non-U.S. companies that need an American footprint they own rather than rent.
Certification is awarded to an operator’s program, never to a building, and nothing above is
offered as a representation that any particular certification is currently held by the property.
What an owner-occupied single-tenant facility does is remove the dependency that makes each of these
programs slow and expensive: proving control over physical infrastructure that belongs to someone
else. Current certifications, audit history and the full controls inventory are disclosed under NDA.