Fire Risk in Modular Data Centers (MDCs) Case Study

Modular data centers deploy fast, scale predictably, and increasingly rely on lithium-ion battery systems for power continuity. But the same design choices that make them efficient also create a fire and explosion risk profile that conventional assessments routinely misjudge.

The stakes are no longer theoretical. On September 26, 2025, a lithium-ion battery caught fire in the uninterruptible power supply (UPS) system of South Korea's National Information Resources Service (NIRS) data center in Daejeon. The blaze started when lithium-ion batteries in the facility's UPS system caught fire, and it took 22 hours to fully extinguish. Authorities say it began during maintenance work when one cell exploded and initiated thermal runaway across a battery rack. The consequences reached far beyond the equipment room: the fire crashed 647 government digital services overnight, crippling emergency response, logistics, and public access, and roughly 858 terabytes of government data, representing eight years of work for 125,000 civil servants, was permanently lost.

That incident is a live illustration of the three challenges below, the very challenges a rigorous fire risk assessment is meant to surface before a facility is built. Having recently completed a detailed fire risk assessment of a lithium-ion-backed modular data center, we want to highlight where standard assessments go wrong, and what can actually be done about it.

The sealed enclosure and the danger of what sits nearby

The most consequential feature of a modern modular data center is that it's sealed. Closed-loop thermal management recirculates a fixed mass of air and admits no fresh air. That's excellent for cooling efficiency, but it transforms the fire physics. In a sealed box, a battery thermal runaway is no longer limited by ventilation airflow, it's limited by the finite oxygen trapped inside. More importantly, the vent gas that batteries release during runaway has nowhere to disperse. It accumulates. Once enough of it builds up, the internal atmosphere can reach a flammable concentration and a deflagration becomes credible. This is not a fringe concern: peer-reviewed testing confirms that the risk of thermal-runaway propagation is higher in a confined space than in an open environment [ScienceDirect].

The danger of accumulation is exactly what turned a battery fire into a catastrophe elsewhere. In the 2019 McMicken energy storage explosion in Arizona, the suppression system sealed the enclosure and prevented flaming - so instead of venting the flammable gas away, the system held it in. In the three minutes a door was left ajar, the gases reached the right mix and concentration to enter the explosive range, and an ignition source inside triggered a massive deflagration that seriously injured four firefighters. The lesson is blunt: in a sealed enclosure, the absence of flame is not the absence of hazard - it can mean more gas accumulating, not less.

Here's the part most stakeholders don't anticipate: the enclosure itself won't contain that event. A modular data center envelope is a lightweight panelized skin - thin aluminum over a foam core, fastened to a frame. It's weather protection, not a pressure vessel. When internal pressure rises, the panels relieve at a fraction of what a confined explosion would generate. That's not a defect; it's the intended behavior. The enclosure acts as a deflagration-venting structure.

  • But when it relieves, the hazard transfers outward. The governing risk stops being internal pressure and becomes the vented overpressure, flame, and panel debris directed toward whatever is nearby. In a typical yard, that means the adjacent unit- and, critically, the medium-voltage transformer often placed just a few feet away. This is why the distance between units and other combustible or critical equipment becomes the single most design-defining variable in the entire assessment. Well-designed venting is meant to release combustion products in a controlled direction and to avoid ejecting debris; our fragment-throw analysis is precisely the check that verifies whether a panelized envelope actually meets that objective, or whether tethering and barriers are needed. Separation is the cheapest safety measure available to an MDC project - and the most costly one to retrofit.

The unit test doesn't reproduce how the unit actually operates

Battery units are typically qualified using UL 9540A testing. It's valuable and necessary work - but it's essential to understand what the test does and doesn't represent, because a reassuring test result can create false confidence about installed conditions. Independent fire-engineering critiques note that unit-level testing that doesn't require large-scale fire conditions doesn't truly test the battery enclosure, and that the method has no pass/fail criteria - only compliance with a procedure. [Sandia National Laboratories]

There are three gaps that matter.

  • The test environment isn't usually sealed. UL 9540A testing is typically conducted where vent gas can disperse freely and never accumulate to a flammable concentration. A "no flaming, no propagation" result is real - but it was produced in exactly the conditions a sealed enclosure eliminates. The dispersion mechanism that protected the test simply doesn't exist in the installed unit.

  • Ambient temperature isn't representative. Lab testing runs at roughly room temperature. A real modular data center operates at an elevated internal baseline and may sit outdoors in hot climates, where external temperatures push conditions higher still. That elevated baseline shrinks the thermal headroom between normal operation and the temperature at which cells begin to vent: Increasing ambient temperature significantly accelerates thermal-runaway propagation, producing lower onset temperature and higher intensity.

  • Time and scale aren't captured. A single test observes a limited event over a limited window. But propagation is time-dependent - in a sealed, confined space, heat accumulates rather than dissipating, and adjacent modules can be driven toward their venting threshold gradually. The NIRS fire is the cautionary example: what began with a single cell propagated across an entire rack, and reporting indicates the event eventually involved all of the facility's battery modules and burned for nearly a day. A test that shows no propagation in its observation window, at its scale, on a single run, cannot be treated as proof that a much larger installation will behave the same way over a longer, hotter, confined event. Combine confinement, elevated temperature, and time, and every factor points the same direction: real-world conditions are more demanding than the test that qualified the unit.

The correct response isn't to distrust the test, it's to recognize its boundaries and assess the installed condition on its own terms.

What actually resolves these challenges

Identifying risks is only half the job. Here is what our work shows can genuinely be done about them.

  • Assess against the right regime and a worst-case bound. The starting point is modeling the enclosure as it truly operates - sealed, oxygen-limited, at its real baseline temperature - rather than borrowing assumptions from open, ventilated systems. From there, the robust approach is to assume the flammable atmosphere forms, assume it ignites, and demonstrate the enclosure response is still acceptable. This is the recognized philosophy behind deflagration venting, which accepts that ignition may occur and provides a safe outlet for the expanding gases and flames. If the design holds under that assumption, the ignition question doesn't have to be resolved perfectly for the facility to be safe.

  • Solve the exterior hazard through siting and separation. Because the enclosure is designed to vent rather than contain, the effective controls live outside it: adequate separation between units, deliberate placement of transformers and other critical or combustible equipment, and where separation alone isn't sufficient, engineered barriers to interrupt the fragment and flame path. Industry practice already allows prescriptive separation distances to be shortened using full-scale test data, performance-based methods, or engineered fire barriers. A quantified consequence-distance analysis turns these from guesswork into defensible design targets, ideally settled at the layout stage.

  • Close the test-to-reality gap with targeted analysis. Where a physical test can't represent sealed, elevated-temperature, time-extended conditions, engineering analysis can. Detailed thermal modeling of the module-to-module cross-section - resolving the conductive, radiative, and convective heat paths under the real cooling design- quantifies whether propagation is genuinely arrested or merely slowed, and how much time a response would have. This aligns with current best practice, which increasingly recommends computational fluid-dynamics plume modeling to visualize worst-case off-gas flow within enclosures.

  • Get the regulatory framing right at the outset. Depending on how the battery subsystem is listed and how its stored energy compares to code thresholds, a BESS in modular data center may fall outside the stationary energy storage standards teams reach for by default - and instead sit under IT-equipment listings. Establishing the correct framework early determines what must be proven and to whom, and avoids the costly discovery of a standards mismatch during review.

The takeaway

Modular data centers are neither miniature conventional facilities nor open-rack energy storage systems. Their sealed architecture, their lightweight venting envelopes, and their tightly packed layouts create a risk profile that demands purpose-built analysis. The NIRS fire showed how a single cell in a UPS system can cascade into a national-scale outage; the assessments that fail are the ones that transfer assumptions from the wrong reference case, while the ones that succeed model the real operating condition, carry the hazard outward to the assets that actually surround the unit, and turn those findings into concrete, early design decisions, protecting safety, timeline, and cost together.

If you're deploying, permitting, or insuring modular data center infrastructure, we'd welcome a conversation about how a rigorous, physics-based fire risk assessment can de-risk your project before it reaches the field.

Next
Next

BERDO 2.0 Compliance Case Study