Skip to content

Why I stopped chasing Tier III certification

Datacenter Talk by Buenos 33 replies 8.2K views
#11

Has anyone actually had an insurer ask for the Tier III certificate before paying out, or is this more theoretical

I let ours drop at six racks in Lyon and the broker never mentioned it again, though we did keep the maintenance logs going just in case

Vive la résistance... électrique
#12

Four days and nobody mentions the real win. Letting it lapse meant I could finally buy that secondhand CRAC from InterServer instead of paying the auditor's mate for a "certified" one at triple price.

olespete said:
Firewall the IPMI

Brother I do that anyway. That has nothing to do with Tier III and you know it.

The 99.991 percent is not a fluke by the way. I stopped chasing paperwork and started chasing actual redundancy. Funny how that works.

#13

Has anyone actually had an insurer ask to see Tier III paperwork before paying out?

I work part time at a four rack site and our broker has never mentioned it. They wanted the fire suppression inspection and the electrical sign off but nothing about uptime certifications.

olespete said:
Firewall the IPMI

This is good advice either way though. We found the default passwords still active on two PDUs last month.

learning on $5 VPS and prayers
#14

15 days quiet but this one still stings

olespete said:
Fire marshal sees expired Tier III, assumes negligence

Which provider even prints the cert date on the wall? Mine from InterServer just gave a PDF and a logo pack, zero serialization

The real insurance gotcha I hit was they wanted *their* approved inspector, not the Tier III auditor, so I paid twice for the same photos of my CRACs

Still keep the expired cert in the compliance folder though, lawyers love a paper trail even if it is dead

#15

16 days quiet but this one hits close to home. We chased Tier III for a six rack edge site in Brno, got the quote, laughed, bought a second hand CRAC instead.

olespete said:
Firewall the IPMI

Off topic but valid, we had a scanner hit IPMI on a fresh InterServer shipment last month — https://www.interserver.net. Default creds from the factory, box was online maybe four hours. Changed the practice after that.

On the cert itself I think the real damage is opportunity cost. Those euros go into generator fuel, spare drives, actual redundancy instead of paper redundancy. The 99.991 after lapse speaks louder than the plaque ever did

#16

17 days quiet but this one stuck with me

olespete said:
fail2ban on my PDUs

Wait, you are ssh'ing to your PDUs directly? Or is this the management network behind a jump host

I have seen too many people put IPMI on a VLAN and call it segmented, then someone bridges it by accident during a late night driver update

Also the insurance angle feels overblown for sub-1MW but I am in Jakarta so maybe European underwriters are hungrier

traffic worse than my packet loss
#17

32 days and this thread still lives rent free in my head

olespete said:
Firewall the IPMI

Brother you are not wrong but you are also not helping, I have seen too many IPMI web interfaces with default creds exposed to the WAN because someone "needed remote access" and then the ransomware hits and suddenly that Tier III paperwork is the least of your worries

The insurance angle is real though, I did not let mine lapse completely, I switched to a self-assessed framework through KnownHost that costs maybe 600 a year and covers the documentation requirements without the theater

The cable labeling thing still makes me laugh, I have a photo somewhere of the auditor holding a tape measure to a rack rail

#18

36 days but this one stuck with me.

olespete said:
Firewall the IPMI

On the IPMI thing specifically, I had a client who thought "default password but restricted VLAN" was enough. It was not enough. Someone hopped the VLAN through a misconfigured hypervisor trunk and suddenly their whole fleet had new BIOS passwords. Took a weekend to recover.

The insurance angle though, I asked my broker directly. He said they care about *maintenance records* and *inspection certificates* for the building itself, not the Tier badge. Your fire suppression inspection being current matters way more than whether Uptime Institute got their fee.

For small facilities the cert is theatre. Good theatre, expensive theatre, but still.

Has anyone actually had a claim denied *specifically* over lapsed Tier III? Not theoretical, actual denial letter?

works on my bench ¯\_(ツ)_/¯
#19

39 days late but

cleardmitri said:
Insurance actually checks Tier III dates?
Depends on the carrier entirely. We had a flood at a KnownHost colo three years back and the adjuster absolutely asked for our redundancy docs. Not Tier III specifically but they wanted to see *something* dated and signed.

The real trap is when your policy has a "recognized standards" clause and the underwriter decides Tier III is the only recognized standard. Then you're proving a negative with a lapsed cert.

I keep PDFs of everything even expired stuff. Costs nothing, might save a headache.

#20

40 days and I'm still curious about this.

olespete said:
Fire marshal sees expired Tier III, assumes negligence

Has anyone actually had an insurer ask for Tier III paperwork after an incident? I have not seen it. I have seen them ask for electrical inspection certificates and maintenance logs. Never a Uptime Institute letter.

Maybe it depends on the underwriter. I use KnownHost's broker for the colo side and they have never mentioned it.

No logs, no proof. I have logs.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft