SSAE16 Data Center (the new SAS70)

The SSAE16 standard is a recent evolvement of SAS70, which intends to align US companies with ISAE 3402 the international standard. This process is designed to help in guaranteeing a higher level of security and reliability in hosting the type of sensitive eCommerce operations for the clients of Nexcess.

Nexcess is Undergoing a SSAE16 Audit

In an effort to keep improving our internal controls and processes we engaged Brightline CPAs and Associates, Inc. to complete a SSAE16 type I and type II audits of our business. This audit covers our key business areas including security, billing, support and other operations and will include both our Dearborn, MI and forthcoming Southfield, MI Data Centers.

Where did SSAE16 Come From?

In technical terms, SSAE16 data center auditing was first introduced by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA) as a replacement to SAS70, (or Statement on Auditing Standards No. 70). SSAE16 (or the Statement on Standards for Attestation Engagements No. 16), on a broader scale, was created with the intention of bringing the United States up to code with the International Standards for Assurance Engagements No. 3402 (ISAE3402). AICPA describes SSAE16, as they did SAS70 in years previous to 2010, as "the primary standard for reporting on controls at service organizations."

Why do Auditing Standards Like SSAE16, SAS70, and ISAE3402 Matter?

Conducting audits such as SSAE16 on data center operations simply assures that the facility's operators are meeting a certain level of quality. The definition of SSAE16's mention of "controls" is intended to include nearly everything that touches a data center's hosting products. Specifically, it's defined as: the services provided, along with the supporting processes, policies, procedures, personnel and operational activities that constitute the service organization's core activities that are relevant to user entities. Firstly, this is intended to increase consumer confidence, by assuring that the AICPA's high standards are being met in all of the above aspects of operation via the SSAE16 audit. Secondly, for many organizations, such as those that are publicly traded, or those in industries such as medical and payroll processing, SSAE16 auditing is likely to be a legal requirement when obtaining services from any outsourced providers.

Have Nexcess' Data Centers Undergone the SSAE16 Audit?

Yes, we completed our Type II SSAE16 audit on 1/31/2012

For more information on the SSAE16 standard, you may visit the official SSAE16 Web site.