Due diligence before infra overhaul: sales sends 80-page "compliance" PDF — product screenshots, no certificate. CISO asks for SOC2 Type II: "confidential, enterprise NDA only." Project proceeds anyway. Six months later client audit shows datacenter used was not in certified scope.
Auditing a host is not repeating the vendor questionnaire unread. It is obtaining usable evidence: dated, scoped, mappable to your product and your region.
Readable evidence grid
| Document | Must state | Red flag |
|---|---|---|
| ISO 27001 | Number, date, service/site scope | Scope = admin only |
| SOC 2 | Type II, period, criteria | Total SMB refusal |
| DPA | Sub-processors, 72 h notice | Unsigned template |
| Pentest | Date, external scope | > 18 months |
| SLA | Maintenance exclusions | Symbolic credits |
Request same product you will buy: cloud subsidiary ISO may not cover legacy shared hosting.
Certification logo without certificate number is decor — not proof.
Three-meeting method
- Documentary — DPA, ISO scope, sub-processor list, backup/incident policy.
- Technical — region, encryption, admin logs, tested restore (see restore evidence).
- Contractual — SLA, liability cap, reversibility, breach notification.
Keep decision matrix: criterion, evidence received, gap, action.
The climax
Decide and move forward without blind spots
Shortlist two hosts, send same evidence grid, compare answers within 15 days. Directory + compare tool + Sub-processors.
Frequently asked questions
Evidence first?
Dated ISO/SOC2 + scope, DPA, incident, sub-processors, recent pentest.
On-site audit?
Rarely; questionnaire + docs + call enough if verifiable.
Verify ISO scope?
Annex services/sites; explicit exclusions.
Host refuses?
Signal on sensitive project; compare or harden contract.
Auditing a host means collecting evidence a foreign DPO could understand — not filling Excel to tick procurement.
