You share a building with dozens of other tenants. You don’t share your compliance obligations with any of them. That’s the uncomfortable structural reality of colocation ITAD tenant decommissioning — the facility operator (Equinix, Digital Realty, CyrusOne, and the rest) controls the perimeter, the power, and the vendor access list, but you own the hardware, you own the data on it, and you own the liability when something goes wrong. A failure in the vendor selection or the cage vacancy process doesn’t split along the lease line; it lands on the tenant.
This guide walks through the four decisions that define a defensible colocation IT asset disposition (ITAD) program: understanding the responsibility split, evaluating the operator’s approved vendor list, negotiating SLA terms that hold through lease exit, and handling cage vacancy in a way that doesn’t create cross-contamination risk for the next tenant — or a contract dispute for you. If you’re a tenant planning a hardware refresh, cage consolidation, or lease exit, these are the questions that separate a clean handoff from a six-figure problem.
Who Owns What in a Colocation ITAD Tenant Decommissioning Engagement?
The split is sharper than it looks on the lease agreement. Colocation operators own the physical infrastructure — the building, industrial cooling, multi-megawatt power distribution, biometric security perimeter, and the operational technology (OT) network running environmental sensors and smart-hands systems. Tenants own everything inside the cage: the servers, storage, switches, cabling, and — most importantly — the data residing on every drive.
This matters operationally because the regulatory frameworks that apply to your data — HIPAA if you’re a healthcare tenant, GLBA and SOX if you’re in financial services, PCI-DSS if you process payment data, CMMC if you contract with DoD — flow through to the disposition event. The colocation operator is not a party to those regulatory regimes. If a decommissioned drive containing electronic protected health information (ePHI) leaves your cage without verified sanitization, the HIPAA enforcement action names you, not Equinix.
Four responsibility boundaries worth drawing explicitly:
- Hardware ownership and data liability sit with the tenant, in all cases.
- Facility access control and vendor credentialing sit with the operator — which means your ITAD vendor needs operator approval to enter the cage, regardless of your contract with them.
- Cage vacancy condition and space remediation sit with the tenant contractually, but the operator sets the acceptance standard. An “empty cage” that still has anchor bolts, cable tray debris, or unremediated under-floor work won’t pass handback.
- Downstream environmental and chain-of-custody compliance sit with your ITAD vendor — but the certifications the operator requires (R2v3, e-Stewards, NAID AAA) are effectively your baseline too, since those are the only vendors who can access the cage.
The operational implication: tenant-led ITAD decisions run inside a framework the operator controls. Treating the engagement as if you had the same autonomy as an enterprise-owned data center is the fastest way to hit a scheduling conflict two weeks before lease exit.
Why Do Colocation Operators Impose Such Strict Vendor Qualification Frameworks?
Because tenant ITAD failures become operator reputation events.
Equinix, Digital Realty, and CyrusOne all run vetted vendor ecosystems for ITAD, environmental services, and smart-hands work. The reason is defensive — an unvetted vendor walking into a multi-tenant facility can compromise the operator’s physical security posture, their sustainability targets (Equinix’s “Future First” commitments, CyrusOne’s climate neutrality by 2030), and their chain-of-custody reputation with every other tenant in the building. One bad ITAD incident in a shared cage aisle affects the operator’s ability to sign the next Fortune 500 tenant.
What the qualification frameworks typically screen for:
- Active ITAD certifications — R2v3 or e-Stewards for downstream environmental compliance, NAID AAA for secure destruction operations, ISO 27001 for information security management, and SOC 2 Type II for operational controls.
- Insurance coverage at scale — cyber liability and errors-and-omissions policies sized to the potential exposure of a multi-tenant environment, often in the $10M-$50M range per occurrence.
- Background-checked personnel with active security clearances — technicians entering the cage must pass the operator’s credentialing process, which typically includes criminal background checks, drug screening, and facility-specific security training.
- Zero-landfill commitments and documented downstream recycler audits — operators running public sustainability commitments can’t tolerate a tenant vendor whose downstream materials end up in informal overseas recycling streams.
- Chain-of-custody technology — tamper-evident asset tagging, GPS-tracked logistics, and audit-ready documentation systems.
If your preferred ITAD vendor doesn’t carry the full stack, you have a decision to make before decommissioning begins, not during.
Should You Use the Operator’s Approved Vendor or Bring Your Own?
The honest answer: it depends on three things — your existing vendor relationships, the data sensitivity of the assets being retired, and how much negotiating leverage you have on timeline.
The case for the operator’s approved vendor. Faster facility access (they already have the credentials), simpler scheduling coordination with operator smart-hands teams, and no gap between the operator’s expectations and the vendor’s capabilities. If the operator has curated the list rigorously, the capability baseline is already qualified. This is often the right choice for straightforward hardware refreshes with standard data sensitivity.
The case for bringing your own vendor. Existing master services agreements with pricing already negotiated at volume, deeper integration with your CMDB and asset management tooling, ongoing relationships where the vendor understands your compliance framework, or specialized capabilities (high-density GPU handling, AI-era refurbishment, classified-tier destruction) that the operator’s general list may not fully cover. Tenants with global data center footprints typically want consistent ITAD execution across facilities, which usually means bringing a vendor of their own.
The hybrid model most sophisticated tenants end up running: maintain a preferred ITAD vendor for policy, pricing, and consistency, but require that vendor to complete whatever operator-specific qualification process the colocation provider runs. The vendor works in both worlds. You get negotiating leverage on price while the operator gets the certifications and insurance they require.
What to ask before committing either way:
- Can the operator’s approved vendor handle the data sensitivity class of your retired hardware? (A list built for standard CPU racks may not be sized for GPU clusters or classified workloads.)
- If you bring your own, how long does the operator’s vendor qualification process take? (At Equinix and Digital Realty, expect weeks, not days.)
- Who is the primary contact for scheduling — operator smart-hands or tenant project management? (Getting this wrong adds days to every workstream.)
- Does the operator charge access fees or require operator personnel to accompany third-party technicians? (These costs can materially shift the build-vs-buy math.)
Not sure whether your current ITAD vendor meets the qualification bar for major colocation operators? Take the free ITAD Readiness Assessment →
What Does Cage Vacancy Sanitization Actually Require?
More than an empty rack and a move-out ticket. Cage vacancy in a multi-tenant facility is where cross-contamination risk lives — and it’s where colocation operators and tenants both get burned.
The scenario that auditors care about: Tenant A vacates a cage. The cage gets turned over to Tenant B within 30 days. Tenant B deploys new hardware and begins operating. Six months later, a forensic review discovers residual tenant data artifacts on under-floor cabling Tenant A left behind, or on a disused KVM that was never accounted for in the decommissioning inventory. At that point you have a data exposure incident that touches Tenant A’s regulatory framework, Tenant B’s intake due diligence, and the operator’s multi-tenant security posture. Nobody wins.
Cage vacancy done right has four components:
- Complete asset inventory reconciliation. Every serial number originally brought into the cage leaves the cage — documented, sanitized, and routed. Reconciliation has to account for cage infrastructure that’s easy to overlook: KVM switches, environmental monitors, lights-out management modules, structured cabling, PDU tap boxes, and any tenant-owned cooling or networking auxiliaries. Elite ITAD programs achieve above 99% asset reconciliation; historical industry averages sit around 85%, which is the failure rate cage vacancy auditors are trying to close.
- Verified data sanitization per serial number. NIST SP 800-88 Revision 2, finalized September 26, 2025, defers technology-specific sanitization execution to IEEE 2883:2022. For modern NVMe and flash storage, that means Purge-level cryptographic erase via firmware commands, not multi-pass overwrite — with a per-serial-number Certificate of Erasure generated by automated platforms like Blancco Drive Eraser. Certificate documentation is the audit artifact that protects you when a successor tenant asks about cage history two years later.
- Physical remediation of the space itself. Anchor bolts removed, cable tray debris cleared, under-floor tiles reseated if they were pulled, overhead cable trays emptied. Operators have specific cage-handback condition standards; review them before you schedule the last day.
- Formal sign-off documentation. A joint walkthrough between tenant IT, the ITAD vendor, and operator facility management, with a signed acceptance document closing the handback. This document is the contractual seal on your decommissioning program — it’s what prevents a dispute six months later about what left the cage and what didn’t.
The underlying principle: the cage needs to be clean enough that the next tenant’s intake due diligence finds nothing attributable to you. That’s a higher bar than an empty rack.
How Do You Negotiate Colocation ITAD SLA Terms That Actually Protect You?
The SLA work happens two places — in your master services agreement with the ITAD vendor, and in the decommissioning addendum to your colocation lease with the operator. Both need to be tight before the first extraction ticket opens.
Five terms worth negotiating specifically for colocation ITAD tenant decommissioning:
- Timeline commitments that match your lease exit date. If your cage lease expires June 30 and holdover charges kick in July 1, your ITAD vendor’s “best-effort two-week turnaround” is not a contract term — it’s an exposure. Commit to specific handback milestones with liquidated damages if they slip.
- Right to audit downstream disposition. Your vendor’s downstream recyclers and remarketing partners are your chain-of-custody endpoints. The right to audit them on reasonable notice should be in the contract, not a handshake.
- Chain-of-custody documentation requirements and retention periods. Specify the format (serialized manifests, per-drive Certificates of Erasure, GPS-verified logistics logs), the retention period (seven years is a defensible baseline for most regulated data), and your right to retrieve these records on demand.
- Indemnification for data exposure attributable to sanitization failure. Vendor-side indemnification language is table-stakes; the question is whether it’s capped and how. Uncapped indemnification for sanitization failures is rare but worth pushing for; multi-million-dollar caps are the more common negotiation point.
- Operator coordination obligations. The vendor should be responsible for coordinating cage access, smart-hands hours, and operator sign-offs — not you. Your time is spent managing the workstream, not chasing Equinix’s scheduling team.
On the colocation lease side, pay particular attention to cage handback condition standards, any access fees or smart-hands charges associated with third-party vendor work, and the operator’s right to approve (or reject) your selected ITAD vendor. The lease should specify an approval SLA — operators that can take 30-60 days to qualify a new vendor will break your timeline if you leave it unspecified.
Want to benchmark your ITAD SLA terms against what mature colocation tenants actually negotiate? Take the free ITAD Readiness Assessment →
How Do You Avoid Cross-Contamination Between Successive Tenants?
The short answer: treat the cage handback as a security event, not a facilities event.
Cross-contamination in a colocation context happens in predictable ways. Residual data on overlooked equipment — KVM consoles, environmental monitors, management appliances — is the most common vector. Second is physical artifacts: labels, printouts, or documentation that identify the prior tenant left in floor tiles or cable channels. Third, and more subtle, is network artifact residue — IP allocations, VLAN assignments, or routing configurations in shared operator infrastructure that still reference the prior tenant’s topology. Operators catch most of the third category; tenants are on the hook for the first two.
Five practices that close the common gaps:
- Inventory audits that account for non-server assets. Every cage has equipment that wasn’t in the original commissioning inventory — monitors, keyboards, carts, spare parts, even documentation binders. All of it needs to leave, and data-bearing items need to go through the same sanitization workflow as primary servers.
- Under-floor and overhead inspection as part of handback. Cables, tie-wraps, and labels routinely get left behind when rack-level extraction runs in a hurry. A facilities walkthrough with the ITAD vendor present catches this before the operator rejects the handback.
- Photographic documentation of the cage at handback. Timestamped images of the empty cage, under-floor condition, and cable tray state give you a defensible record of the condition at handover. This is the evidence that protects you if an issue surfaces after the next tenant moves in.
- Formal data sanitization summary document. Not the certificate library — a one-page executive summary listing asset count, sanitization method per class, verification standard (IEEE 2883:2022 Purge, for example), and total drives processed. The operator doesn’t need to see every certificate, but they need a document they can reference if a successor tenant asks.
- Destruction of cage-specific documentation. Operator-provided access keys, biometric enrollments, network topology diagrams, any physical documentation of your deployment — all of it needs to be returned or destroyed per the lease terms. Leaving operational documentation in the cage is a security finding, not a housekeeping problem.
Where You Stand Matters
Colocation ITAD tenant decommissioning sits at an uncomfortable intersection: you own the liability, the operator controls the access, and the vendor executes the work inside constraints neither of you fully specified. The tenants running this well treat the engagement as three aligned but separate contracts — their lease obligations to the operator, their services agreement with the ITAD vendor, and their regulatory obligations to whatever compliance framework applies to their data. The tenants running it badly treat it as a logistics problem and discover at handback that logistics wasn’t the hard part.
If you’re planning a hardware refresh, cage consolidation, or colocation lease exit, the diagnostic questions are the same: Does your ITAD vendor meet your operator’s qualification framework? Are your SLA terms tight enough to hold through lease exit? Is your cage handback plan built for cross-contamination prevention, not just asset removal? If you can’t answer yes to all three with documentation in hand, the exposure is real.
Ready to assess your organization’s ITAD readiness? SureDispose’s free assessment evaluates your colocation ITAD program across vendor qualification, SLA coverage, cage vacancy procedures, and chain-of-custody documentation — then connects you with vetted providers qualified for multi-tenant facility environments. Take the Assessment →
SureDispose is an independent advisory platform. We connect organizations with vetted ITAD service providers but do not perform disposition services directly. Providers compensate us for qualified introductions.