Analyst recognition · KuppingerCole Analysts · September 2026
Key2XS named a KuppingerCole Rising Star 2026
KuppingerCole Analysts has recognised Physical Access Governance as a market segment of its own and placed Key2XS in the Rising Star zone. This page shows what the analyst wrote, in the analyst's words.
"Rising Star" is a designation of KuppingerCole Analysts AG. Report and badge supplied by KuppingerCole.
- Market segment
- Physical Access Governance
- Analyst
- Warwick AshfordSenior Analyst, KuppingerCole Analysts
- Published
- September 2026Rising Star report, 11 pages
- Position
- In the Rising Star zoneFig. 1, KuppingerCole Rising Star matrix
01 The KuppingerCole verdict
“Key2XS shows an early but real alignment with an emerging need, in a market that is not yet crowded.”
“The combination of a defined regulatory driver, a clear technical gap between identity governance and physical key systems, and a large future addressable base nonetheless points toward the potential to define a new market segment, not compete for share within an existing one.”
“Key2XS's primary innovation is its identity-native model, in which physical access rights inherit directly from the governance model already running inside enterprise identity systems.”
02 Position
Key2XS: In the Rising Star zone.
Where Key2XS sits on the Rising Star matrix: high innovation, with product-market fit still to be proven at scale.
- Founded 2024
- Headquarters The Hague, Netherlands
- Funding Seed
- Licensing Subscription
- Geographic focus Europe and the US
KuppingerCole ratings, out of five
- Innovation5 / 5
- Integrations4 / 5
- Market Fit3 / 5
- Brand Reach1 / 5
Scores from the report's At a Glance page. Brand Reach measures how widely a vendor is known today. This page is part of the answer.
03 Analyst's view
Why now, in the analyst's words
“Organizations need a single operational model connecting identity decisions to the physical keys and locks controlling access to critical national infrastructure (CNI).”
“Identity has already become the dominant attack surface for digital systems, and regulators are extending the same expectation of governed, auditable access to the physical estate that protects essential infrastructure.”
“Managing the two through separate, disconnected processes leaves gaps regulators are no longer willing to accept.”
“Physical Access Governance is likely to grow steadily in the next two to three years, tracking the pace at which the CER Directive and NIS2 are transposed into national law and enforced.”
04 Strengths
What KuppingerCole highlighted
Six strengths, listed in the report. The headings are ours. The text under each one is the analyst's.
Rights inherit from the identity. No second process.
“Physical access rights inherited directly from the governance model already running inside connected identity systems, avoiding a parallel, disconnected access process”
Any identity system, any lock vendor, in any combination.
“Support for multiple identity systems and multiple lock vendors simultaneously, in any combination, without tying customers to a single vendor pairing”
Offline, evidence and contractor access: designed in, not bolted on.
“Offline operation, audit evidence, and JIT contractor access treated as core design requirements from the outset, not added later”
AI Key Plan does the translation work.
“An AI Key Plan component that automates a large share of the manual work involved in translating identity roles into physical access rights”
Tested, and on the way to ISO 27001.
“Independent validation through ISO 27001 progress and completed penetration testing, offering buyers early proof of security maturity from a young vendor”
Contracts that run with the cylinder cycle.
“Long contract terms tied to the multi-year replacement cycle of physical lock cylinders supporting durable customer relationships once a deployment is won”
Strengths quoted verbatim from the report's Strengths and Challenges page. The report also lists four challenges; see "The work ahead" below.
Read in full
The work ahead
“A differentiated, identity-native core; scale, funding and category awareness are the work ahead.”
The report is candid about what a company founded in 2024 still has to prove, and we would rather you read it here than find it elsewhere. The analyst lists four challenges: a team of fewer than ten people against the delivery and support demands of large infrastructure tenders; adoption concentrated in a small number of early engagements, with wider validation depending on regulatory timelines and lock conversion rates outside our control; a new category between identity governance and lock management, where buyer awareness is still developing; and a single seed-stage investor, with international expansion and hiring tied to funding discussions that are still open.
None of that changes what the analyst says about the design. All of it is a fair question to bring to a first conversation. Bring it.
05 The category
What the analyst means by Physical Access Governance
That is the definition we have been working to since 2024, now in an analyst's words. The category page sets it out in full: why the discipline exists, what it consists of, where PIAM stops, and what to ask a vendor.
Integrations named in the report
- “Physical Access Governance extends identity governance to the offline, mechanical, and electronic key systems protecting critical field assets such as substations, pumping stations, and bridges.”
- “It connects to Identity Governance and Administration (IGA) and Physical Identity and Access Management (PIAM), carrying roles, approvals, and lifecycle decisions from digital identities to physical keys and locks.”
- “The discipline is emerging amid regulatory pressure from the EU Critical Entities Resilience (CER) Directive and the Network and Information Security 2 (NIS2) Directive, and the ongoing shift to electronic lock systems.”
KuppingerCole Analysts, Rising Star report, September 2026.
The Key2XS platform connects enterprise IAM systems to electronic key and lock infrastructure, translating identity decisions into physical access rights.
06 The report
Read the full Rising Star report
Eleven pages: the verdict, the positioning matrix, the solution highlight, strengths and challenges, and the analyst's view of the market. Published by KuppingerCole Analysts, September 2026.
Related KuppingerCole research
- Governing Third-Party Privileged Access: Moving Beyond VPN-Based Collaboration Whitepaper
- Cybersecurity for OT/ICS Buyer's Compass
- Analyst's View: Secure Remote Access for OT/ICS Advisory Note
- KRITIS: Understanding and Protecting Critical Infrastructure Whitepaper
- The Role of Identity Fabrics in Modern IAM Whitepaper
Talk to us about the findings
Every finding in the report is a fair question to bring to a first conversation. Tell us which one and we come back to you.
- The verdict, the scores and the challenges, read against your critical infrastructure
- Your identity systems and lock vendors in the conversation
- A 30-minute walkthrough of identity, policy and physical keys if you want one
WAAbout the analyst
“Warwick Ashford is a Senior Analyst who researches cybersecurity and identity-related topics, including emerging technologies and trends. He has been writing IT news and analysis as a journalist and editor since 2003, specialising in cybersecurity and privacy since 2012. Warwick has also worked as a freelance radio producer and broadcast journalist, writing and presenting news bulletins on national radio for the South African Broadcasting Corporation.”
KCAbout KuppingerCole Analysts
“KuppingerCole, founded in 2004, is a global, independent analyst organization headquartered in Europe. We specialize in providing vendor-neutral advice, expertise, thought leadership, and practical relevance in Cybersecurity, Digital Identity & IAM (Identity and Access Management), Cloud Risk and Security, and Artificial Intelligence, as well as for all technologies fostering Digital Transformation.”
Boilerplate as published by KuppingerCole Analysts AG.
© 2026 KuppingerCole Analysts AG. "Rising Star" is a designation of KuppingerCole Analysts AG. All product and company names are trademarks or registered trademarks of their respective holders. Their use does not imply any affiliation with or endorsement by them. Media enquiries: info@key2xs.com.
See what the analyst described, on your critical infrastructure
A 30-minute walkthrough of identity, policy and physical keys coming together in one auditable system. Bring the report's questions with you.