Why these rooms run long
A wind farm, a pipeline stake or a toll road changes hands more slowly than a software company. Technical due diligence covers engineering reports, grid connection agreements, permits, environmental studies and years of operating data. Buyers are often consortia of funds and strategic investors, each with its own advisers, and project finance lenders run a parallel review. Where national security is involved, a government screening process adds months.
The result is a room that may stay open for six months or more, with thousands of large files and dozens of external users.
Large files change how the room is built. Drone surveys, geotechnical data and SCADA exports can run to gigabytes each. Agree file formats with the technical adviser before upload, convert what can be previewed in the browser, and keep raw data sets in a separate folder with download rights for the few people who need to run their own analysis.
Who sees what in a consortium deal
- Consortium lead. Usually the whole room for its lot, plus the right to manage its members’ access in some processes.
- Consortium members. Most folders, but sometimes not the lead’s commercial strategy or financing terms.
- Technical adviser. Engineering, operations and environmental folders, often with download rights for large data sets.
- Project finance lenders and their advisers. Financial model, key contracts, permits and the technical adviser’s report, after a set stage.
- Regulators or screening authorities. Rarely in the room itself, but the audit trail may support filings.
Who enters a consortium deal, and when
- 1Teaser and NDA
Consortium leads
- Teaser
- Process letter
- NDA for signature
- 2Round one
Consortium members and advisers
- Information memorandum
- Summary technical reports
- List of key permits
- 3Round two
Technical adviser and project lenders
- Engineering and operating data
- Financial model
- Grid and offtake contracts
- 4Before signing
Named users only
- Operational technology summaries
- Security assessments, often by supervised review
Round two is where file sizes and user numbers peak. Size the room, and its price, for that stage.
In the United States, CFIUS reviews certain foreign investments in critical infrastructure, and in the EU the NIS2 Directive sets cybersecurity duties for operators in energy and other essential sectors. Both make the handling of technical and grid data in the room a real compliance question.
The technical data pack
The technical folders are the heart of an energy room, and the ones buyers’ advisers spend longest in. Organize them by asset first, then by topic, so a technical adviser can review one site completely before moving to the next.
A technical data pack for one asset
15core items per asset
5folders
01Asset
- Engineering reports
- As-built drawings
- Maintenance history
02Grid and offtake
- Grid connection agreement
- Offtake or power purchase agreements
- Curtailment history
03Permits
- Environmental permits
- Planning consents
- Decommissioning obligations
04Operations
- Operating data
- Availability reports
- Incident log
05Land
- Leases and easements
- Land registry extracts
- Community agreements
Repeat the same five folders under every asset in a portfolio, and the technical adviser can compare sites like for like.
Decommissioning obligations are easy to overlook and expensive to discover late. Wind, solar and oil and gas assets often carry restoration duties secured by bonds or guarantees. Put the obligation, the security and any cost estimate side by side in the permits folder.
How the shortlist compares on security and features
Our Security pillar, scored out of 10, gives iDeals, Datasite and Intralinks 9.6, Ellty 9.4 and Drooms 9.2. On Deal features, Ellty, iDeals and Datasite score 9.5, Intralinks 9.4 and Drooms 8.8. The gaps are small. For an energy deal, the more useful differences are certification and deployment: four of the five hold ISO 27001, Ellty relies on SOC 2 Infrastructure, and Drooms is the only one offering an on-premises option.
Security and deal features on the energy shortlist
Procurement questions to settle early
- Does the seller’s or buyer’s policy require ISO 27001 by name, or will a SOC 2 report do?
- Is cloud hosting acceptable for grid and network data, or is an on-premises option needed?
- Which country hosts the data, and is that confirmed in writing?
- Is SSO required for the seller’s staff?
- Can large technical files be uploaded in bulk and previewed without download?
- How is the audit trail exported, and in what format?
These questions decide the shortlist more often than features do. Settle them with IT and procurement before inviting providers to pitch.
Regulators in the background
Foreign investment screening reaches beyond the United States and the EU. In the United Kingdom, the National Security and Investment Act requires mandatory notification of certain acquisitions in energy and other sensitive sectors. Similar regimes exist in many other countries. A screening authority may ask what the buyer saw and when; an exportable audit trail answers that without reconstructing it from emails.
Energy regulators and grid operators may also need to approve a change of control of a licensed entity. Their filings draw on the same documents as the room, so keeping a clean, final copy of each key license and approval in a clearly named folder saves time on both tracks.
Risks particular to energy rooms
Operational technology data. Network diagrams and control system details are useful to an attacker as well as a buyer. Release late, view only, to named users, or keep them out of the room.
Several consortia, one adviser. Technical advisers sometimes work for more than one bidder group in a market. Their access should sit inside one consortium’s group only, and their audit trail should show it.
Data hosting. Some sellers require grid or network data to stay in a particular country. Get the hosting location confirmed in writing before upload.
A common mistake
The most expensive error in these deals is sharing operational technology data too early. Detailed network diagrams, control system documentation and security assessments should be the last thing released, to named users only, view only. Many processes keep them out of the room altogether and offer supervised review instead.
What to budget
Long timelines and large files make storage and duration the main cost drivers. iDeals, Datasite, Drooms and Intralinks quote on request; ask how pricing scales with gigabytes and months, and what happens if a regulatory review extends the process. Ellty publishes a price from $149/mo with a 14-day free trial, which makes a six-month room simple to estimate. All figures are indicative, confirm with the provider. See VDR pricing for more, or compare two of the picks in iDeals vs Datasite.
The estimator below starts from an illustrative seven-month process with about 50 external users, 40,000 pages, Q&A and SSO. Large technical files make storage a separate line in many quotes, so ask about it alongside these ranges.
Estimate an energy or infrastructure room
Starts from a typical process in this industry. Move the sliders to match yours. Ranges are indicative market pricing in USD, not quotes; confirm with the provider.
Indicative total by billing model
Published plans that fit the must-haves
10 more providers in our directory price on request. See VDR pricing for how each model works.
FAQ
Do energy deals need an on-premises data room?
Rarely, but some operators of critical infrastructure prefer it for sensitive technical data. Most transactions use a cloud room and keep the most sensitive operational files out of it.
Is ISO 27001 required for an infrastructure data room?
It depends on the procurement policy of the seller or buyer. Many require it by name; others accept a SOC 2 report. Ask before shortlisting.
How long do energy and infrastructure data rooms stay open?
Often six months or more, and longer when government screening or permit transfers are involved. Budget for an extension rather than hoping to avoid one.
Can consortium members share one login?
They should not. Each member and each adviser needs named logins inside the consortium group, so the audit trail shows who saw what, which screening authorities and sellers may later ask about.
