Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-10 |
| Control name | Emergency Shutoff |
| Framework | NIST SP 800-53 Revision 5 |
| Control family | Physical and Environmental Protection |
| Baselines | MODERATE HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk severity | Low |
What this control requires
PE-10 requires your organization to provide a reliable way to cut power to critical systems or individual components during an emergency. Most organizations treat emergency power shutoff as a facilities checkbox, but a missing or inaccessible kill switch during a fire, flood, or electrical fault turns a contained incident into a cascading failure that damages hardware, destroys data, and puts personnel at risk.
In practice, you need to accomplish three things. First, you must install emergency shutoff mechanisms that can de-energize the systems or components you define in your system security plan. Second, you must position those switches or devices in locations that authorized personnel can reach quickly under stress. Third, you must protect those shutoff controls from accidental or unauthorized activation, because an unintended power cut in a production data center can be just as damaging as the emergency you’re trying to prevent.
The requirement applies to any facility with concentrated system resources, including data centers, server rooms, mainframe environments, and areas housing computer-controlled machinery. If your organization operates physical and environmental protection controls across multiple sites, each site needs its own shutoff capability scoped to local infrastructure.
Why it matters
Auditors flag PE-10 gaps because an organization without documented, accessible emergency shutoff capability cannot demonstrate basic physical safety controls for its information systems. Failure to maintain this control introduces audit risk and may result in certification withdrawal, regulatory findings, or conditions on your authority to operate.
Beyond compliance, an absent or poorly maintained emergency power shutoff extends the damage window of any physical incident. Electrical fires, coolant leaks, and equipment malfunctions escalate faster when responders lack a clearly marked way to isolate power. The time lost searching for a shutoff switch or calling facilities management is time that heat, water, or electrical faults spend propagating through your racks.
For organizations operating under NIST SP 800-53 at the moderate or high baseline, PE-10 is not optional. An assessor who cannot locate your emergency shutoff switches, verify their placement documentation, or confirm safeguards against unauthorized activation will document a finding that ripples into your overall physical protection posture.
The following threat vectors make this control operationally relevant:
- Electrical faults without isolation capability. A short circuit or power surge in a rack cannot be contained when there is no emergency cutoff within reach of on-site personnel.
- Fire or smoke events in server rooms. First responders and facilities staff need immediate power shutoff to reduce ignition sources and prevent electrocution hazards during suppression.
- Unauthorized or accidental activation. Unprotected shutoff switches in high-traffic areas create risk of unplanned outages from accidental contact or intentional sabotage.
- Delayed incident response. When shutoff devices are poorly marked, located behind locked panels without documented access, or positioned far from the systems they control, response times increase and damage compounds.
How to implement
The most common failure mode for PE-10 is treating it as a one-time installation project rather than an ongoing operational control. Organizations install shutoff switches during facility buildout and then lose track of their locations, labeling, testing schedules, and access procedures as infrastructure evolves.
For your organization
Start by defining the scope of systems and components that require emergency shutoff capability. Your system security plan should list each facility, room, or zone where concentrated system resources operate, along with the specific equipment or circuits that each shutoff device controls.
Step 1: Install or verify shutoff mechanisms. Ensure every in-scope area has an emergency power off (EPO) button or switch that can de-energize the defined systems. EPO devices should cut power to IT loads and, where appropriate, to supporting infrastructure like cooling units that could pose secondary hazards.
Step 2: Position devices for rapid access. Place emergency shutoff controls near room exits, clearly visible and reachable without navigating obstacles. Document the exact location of each device in your physical and environmental protection procedures, including floor plans or photographs.
Step 3: Protect against unauthorized activation. Install physical safeguards such as protective covers, breakable seals, or keyed guards that prevent accidental or malicious activation. These safeguards must not delay authorized use during a genuine emergency.
Step 4: Document and train. Maintain a current inventory of all shutoff devices with their locations, the systems they control, and the personnel authorized to activate them. Train all relevant staff on shutoff locations and activation procedures at least annually.
Step 5: Test periodically. Schedule and document functional tests of emergency shutoff capability during planned maintenance windows. Record test dates, outcomes, and any corrective actions.
Common mistakes to avoid:
- Labeling shutoff switches with generic text that doesn’t identify what they de-energize
- Failing to update location documentation after facility renovations
- Installing protective covers that require tools or keys not available to on-site personnel during an emergency
- Skipping periodic functional tests because of downtime concerns
For your vendors
When your third-party service providers host your data or operate systems on your behalf, you need assurance that their facilities meet PE-10 requirements. Generic SOC 2 reports rarely provide the specificity you need for this control.
Security questionnaire questions to include:
- Do your data center facilities have emergency power shutoff capability for all areas housing customer systems?
- Where are emergency shutoff devices located relative to server room exits?
- What physical safeguards prevent unauthorized activation of emergency shutoff controls?
- How often do you test emergency shutoff functionality, and can you provide test records?
- Who is authorized to activate emergency shutoff, and how is that authorization documented?
Evidence to request:
- Data center floor plans showing EPO device locations
- Photographs of emergency shutoff devices with protective covers or guards
- Emergency shutoff testing records from the past 12 months
- Facilities management procedures for emergency power shutoff
- Training records confirming personnel know shutoff locations and procedures
Red flags during vendor assessment:
- The vendor cannot specify where emergency shutoff devices are located
- Testing records are absent or show intervals longer than 12 months
- Shutoff devices lack protective covers or labeling
- The vendor’s incident response plan does not reference emergency power shutoff procedures
Verification beyond self-attestation. Request a facility tour or virtual walkthrough that includes EPO device locations. Review the vendor’s most recent physical security assessment or data center audit report for PE-related findings. If the vendor uses colocation providers, confirm that the colocation facility’s controls extend to the vendor’s specific cages or suites.
Evidence examples
| Evidence type | Example artifact |
|---|---|
| Policy documentation | Physical and environmental protection policy defining emergency shutoff requirements, authorized personnel, and review cadence |
| Procedures | Emergency power shutoff procedures specifying activation steps, notification chains, and post-shutoff recovery actions |
| Device inventory | Inventory of emergency shutoff switches and devices with locations, system coverage, and installation dates |
| Facility diagrams | Floor plans or rack diagrams marking the exact placement of EPO buttons relative to room exits |
| Safeguard documentation | Records of protective covers, keyed guards, or breakable seals installed on shutoff devices to prevent unauthorized activation |
| Testing records | Scheduled test results documenting functional verification of emergency shutoff capability, including dates and outcomes |
| Training records | Annual training logs confirming authorized personnel completed emergency shutoff location and procedure training |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 7.11 Supporting utilities | Partial |
Related controls
- PE-15 — Water Damage Protection: addresses a complementary physical threat vector where emergency shutoff may be needed to prevent electrical hazards from water intrusion into areas with concentrated system resources.
Frequently asked questions
What is NIST SP 800-53 PE-10
PE-10 is the NIST SP 800-53 control that requires organizations to provide emergency power shutoff capability for defined systems, position shutoff devices where authorized personnel can reach them, and protect those devices from unauthorized activation. It applies to facilities with concentrations of system resources such as data centers, server rooms, and areas with computer-controlled machinery.
What happens if PE-10 is not implemented
Without PE-10, your organization cannot demonstrate that emergency shutoff switches or devices exist in documented locations to de-energize critical systems during a physical incident. Assessors will record a finding against your physical and environmental protection posture, which can delay or block authorization decisions at the moderate and high baselines. The operational consequence is extended damage during electrical faults, fires, or equipment malfunctions because responders lack an accessible way to isolate power.
How do you audit PE-10
Auditing PE-10 starts with verifying that emergency shutoff devices are installed in the locations documented in your procedures and that protective safeguards against unauthorized activation are in place. You should physically inspect EPO buttons or switches, confirm their labeling matches the systems they de-energize, and review testing records that demonstrate functional verification. Interviews with facilities and security staff confirm that authorized personnel know shutoff locations and activation procedures.
Where should emergency power off buttons be located in a data center
Emergency power off buttons should be placed near room exits where authorized personnel can reach them without navigating around racks, raised floor obstacles, or locked doors. The PE family of controls emphasizes that placement must balance rapid access during genuine emergencies with protection against accidental activation, which is why most data centers mount EPO buttons at exit points with flip-up protective covers.