One Boise Cabinet, Five Certifications: Stacking SOC 2, HIPAA, and PCI DSS Without Five Separate Audits

September 15, 2026 · 7 MIN READ

IDACORE Boise carries SOC 2 Type II, PCI DSS, NIST 800-53, SSAE-16, and HITRUST CSF certifications at the facility level, and is compliance-ready for HIPAA, financial, and government workloads. One cabinet inherits all of it. You don't audit the building five times — you audit your own controls stacked on top of infrastructure that's already proven.

Why Does Facility-Level Certification Matter More Than Vendor Promises?

Here's the thing most colocation shoppers miss: compliance isn't a feature you bolt on. It's a chain of custody, and every link matters. If your data center can't produce SOC 2 Type II evidence going back twelve months, your auditor is going to ask you why not — and "the sales rep said it was fine" doesn't hold up.

We went through the process at Boise the hard way. SOC 2 Type II isn't a point-in-time check; it's an auditor watching our controls operate over a sustained period — access logs, change management, incident response, the whole operational reality, not a slide deck. PCI DSS adds cardholder data environment segmentation requirements. NIST 800-53 is the control catalog federal systems lean on. HITRUST CSF harmonizes healthcare-specific requirements on top of that. SSAE-16 covers the attestation standard underneath SOC reporting itself.

Stack those five and you've covered the overlapping asks that come from healthcare compliance officers, PCI QSAs, and federal contracting officers — often in the same week, from different customers.

What Does This Actually Save You?

A mid-size healthcare SaaS company we work with needed HIPAA-eligible infrastructure with an audit trail their compliance officer could hand to an outside assessor without a six-month back-and-forth. Building that on generic cloud infrastructure meant configuring and documenting their own controls layer, then proving it independently — easily $50K-$80K in audit prep and ongoing evidence collection. At Boise, they colocated their own hardware, pointed their assessor at our SOC 2 Type II report and HITRUST CSF certification for the facility layer, and scoped their own audit down to what actually runs on their gear. Their first HIPAA assessment closed in six weeks instead of the five months they'd budgeted.

That's the real value of facility-level certification: it doesn't replace your compliance work, it shrinks the surface area you have to prove.

How Does This Compare to Building Compliance on Hyperscaler Infrastructure?

AWS, Azure, and GCP all publish their own compliance attestations, and they're real. But the shared responsibility model means you're still on the hook for a huge amount of configuration-level compliance — encryption key management, network segmentation, IAM policy, logging retention — and every layer you touch requires its own evidence trail. You're also paying hyperscaler compute and egress rates while you build it.

Factor IDACORE Boise Colocation Typical Hyperscaler
Facility certs SOC 2 Type II, PCI DSS, NIST 800-53, SSAE-16, HITRUST CSF Varies by region/service tier
Data residency Idaho only, contractually confirmed Multi-region by default unless configured
Monthly infra cost (example 5kW deployment) $1,500/month power 30-40% higher on comparable compute + egress
Contract term 12 months standard Often annual commit with complex tiering
Support model Direct access to engineers who know your rack Ticket queue, tiered support plans

The Idaho data residency piece matters more than people initially think. Under HIPAA and most state financial regulations, being able to say definitively "this data never leaves Idaho" removes an entire category of cross-border data transfer questions from your compliance narrative. We don't replicate customer workloads across regions unless you ask us to — your data stays where you put it.

What Do You Still Have to Handle Yourself?

Facility certification doesn't mean you get to skip your own compliance program. You're still responsible for:

  • Application-level access controls and encryption
  • Your own incident response plan (though our NOC will work directly with your team during an event)
  • BAAs with any downstream vendors touching PHI
  • Your own change management on anything running on your hardware

What we hand you is the physical and environmental control evidence — UPS redundancy (N+1), access logging, environmental monitoring, background-checked staff — and the operational attestations that back it up. Your auditor gets to treat the facility layer as a known quantity and focus their time on your actual application stack.

A Concrete Example: PCI DSS Scoping

Say you're running a payment processing backend that needs to stay in PCI scope. Your QSA needs evidence that the physical environment housing your cardholder data environment (CDE) meets Requirement 9 (physical access controls) and contributes to Requirement 10 (logging and monitoring). At Boise, that evidence already exists — cabinet-level access logging, badge-in/badge-out records, camera coverage, HVAC and power monitoring feeding into our own SOC 2 controls. You provide the network segmentation and application controls; we provide the physical layer proof. Your Report on Compliance (RoC) gets built faster because half of it isn't a blank page.

Why Boise Specifically?

Beyond the certifications, Boise gives you 12-month standard contract terms instead of the 36-month commitments most enterprise-grade facilities require elsewhere — useful when your compliance requirements or vendor list might shift. You get 7 on-net carriers (Zayo, Lumen/Level 3, Cogent, CenturyLink, Syringa, Cable One, Hurricane Electric) for redundant connectivity, sub-5ms latency to Treasure Valley businesses, and power billed transparently at $300/kW/month regardless of how much rack space you occupy. A 400W compliance-scoped server runs $120/month. No mystery line items.

Frequently Asked Questions

Does IDACORE Boise offer HIPAA-compliant colocation?
IDACORE Boise is compliance-ready for HIPAA workloads, holding HITRUST CSF certification alongside SOC 2 Type II, PCI DSS, NIST 800-53, and SSAE-16. The facility provides the physical and environmental control evidence a HIPAA compliance program requires; you retain responsibility for application-level controls and BAAs with your own vendors.

What certifications does IDACORE Boise actually hold?
IDACORE Boise holds SOC 2 Type II, PCI DSS, NIST 800-53, SSAE-16, and HITRUST CSF certifications at the facility level. These cover operational controls, cardholder data environment requirements, federal control catalogs, attestation standards, and healthcare-specific requirements respectively.

Can I use one Boise cabinet for both HIPAA and PCI DSS workloads?
Yes. Facility-level certifications apply regardless of what workload you're running. You'll still need to scope your own network segmentation and application controls per framework, but the physical and environmental evidence — access logs, monitoring, power/cooling redundancy — supports both simultaneously without separate facility audits.

How much does compliance-ready colocation cost at IDACORE Boise?
Colocation is billed at $300/kW/month based on actual power draw, not rack space. A 400W server costs $120/month. There's no separate "compliance tier" pricing — the certifications apply to the whole facility, so you pay standard colocation rates regardless of which framework you're auditing against.

Does data stay in Idaho for compliance purposes?
Yes. IDACORE Boise maintains Idaho data residency — workloads and data stay within the state and don't cross state lines unless you configure replication elsewhere. This simplifies data residency language in HIPAA, financial, and state-level compliance documentation considerably.

Compliance audits are expensive enough without re-proving your data center's physical controls every single time. If you're scoping a HIPAA, PCI DSS, or HITRUST workload and want a facility that's already done the certification legwork, talk to our team about IDACORE Boise colocation and we'll walk through exactly which reports your auditor will need.

Ready to Implement These Strategies?

Our team of experts can help you apply these regulatory compliance techniques to your infrastructure. Contact us for personalized guidance and support.

Get Expert Help