NIS2
Who can open the server room is now a supervisory question.
In force since October 2024, transposed country by country. Supervision, audits and management liability are live.
Where each member state standsExtend your Identity Control Plane to Critical Infrastructure.
Hover to extend the control planeTap Key2XS to extend the control plane
Enforcing access through policy and approval flows
Linking physical keys to digital identities
Complete audit trails for every physical access event
Why now
Seven forces, one direction: physical access is becoming an identity governance problem. Regulators, auditors and your own IAM programme are all arriving at the same door.
Who can open the server room is now a supervisory question.
In force since October 2024, transposed country by country. Supervision, audits and management liability are live.
Where each member state stands ↓Key control is resilience evidence, and the clock is per entity.
In force since October 2024. Member states designated their critical entities by 17 July 2026; each one now has ten months to comply.
Where each member state stands ↓Their access has to end when the contract does.
More of the work on critical sites is done by people who are not employees, and CER puts the supply chain explicitly in scope.
One question across all of them: who holds access, right now?
Energy, water, transport and government run on thousands of dispersed, unmanned sites.
Offline cannot mean ungoverned.
Substations, cabinets, pumping stations: no network, no reader, no badge. A programmable key is the only control there is.
Evidence, not intent.
Supervisors no longer ask whether you keep people out. They ask whether you can prove who was where, and revoke access in minutes.
Physical access is the last domain outside it.
IAM has become the control plane for digital access: lifecycle, policy, certification, audit.
Six forces describe the problem. This one names the answer. Key2XS extends the identity control plane to physical access.
See how it works ↓Evidence
NIS2 and CER are law across the EU. Transposition and supervision differ by member state. See where each one is, from EUR-Lex, updated daily.
Measures notified None notified
From identity and policy to physical keys and audit evidence, in one controlled flow.
SailPoint ISC, Microsoft Entra ID, Okta, One Identity, OpenText NetIQ/ILM
Automated Physical Access Management
Keeps IAM updated with current key assignments and access status
Automatically determines who needs access to what based on their role
Complete audit trails and instant access revocation
Connects any identity system to any key system
Electronic access control systems
iLOQ, ASSA ABLOY (eCLIQ, PROTEC² CLIQ)
Key2XS is used in environments where physical access impacts public safety, service continuity or regulatory compliance. Typical organisations include:
Key2XS provides comprehensive access governance solutions for the Government Sector. Our platform ensures security, compliance, and operational efficiency.
Key2XS provides comprehensive access governance solutions for the Utility Sector. Our platform ensures security, compliance, and operational efficiency.
Key2XS provides comprehensive access governance solutions for the Water Management Sector. Our platform ensures security, compliance, and operational efficiency.
Key2XS provides comprehensive access governance solutions for the Transport Sector. Our platform ensures security, compliance, and operational efficiency.
Key2XS provides comprehensive access governance solutions for the Telecom Sector. Our platform ensures security, compliance, and operational efficiency.
Serving organisations where physical access directly impacts safety, continuity and compliance.
See how this works in practiceHow structured access governance directly translates into compliance, efficiency and risk reduction.
Why Key2XS was built
Traditional key systems and IAM solutions operated as isolated islands. Key2XS unites these worlds into one integrated platform.
Discover our solution →
Upcoming
Dynamic platform uniting cybersecurity professionals and innovative start-ups. We’ll be showcasing how the Key2XS platform connects ASSA ABLOY Opening Solutions CLIQ electronic key system with leading Identity & Access Management (IAM) platforms.
What will be included in your guided walkthrough;
Get a guided walkthrough of how identity, policy and physical access come together in one auditable system.
Everything you need to know before getting started: from integrations and security to compliance and deployment.
Key2XS is designed for critical organisations where physical access directly impacts safety, continuity and compliance. This includes government institutions, utilities, industrial facilities, transport organisations, and healthcare providers.
During a demo, we'll walk you through the Key2XS platform, show you how it integrates with your existing systems, and discuss your specific access management challenges. The demo typically takes 30-45 minutes.
No, Key2XS is designed to work alongside your existing access control and key management systems. We integrate with your current infrastructure rather than replacing it.
Key2XS integrates with major IAM systems, key management solutions, and access control platforms including ASSA ABLOY (eCLIQ, PROTEC² CLIQ, CLIQ Remote via CLIQ Web Manager), iLOQ, Microsoft Sailpoint, Okta, Open Text, One Identity, Entra ID, and various other identity providers.