Analyst recognition · KuppingerCole Analysts · September 2026

Key2XS named a KuppingerCole Rising Star 2026

KuppingerCole Analysts has recognised Physical Access Governance as a market segment of its own and placed Key2XS in the Rising Star zone. This page shows what the analyst wrote, in the analyst's words.

"Rising Star" is a designation of KuppingerCole Analysts AG. Report and badge supplied by KuppingerCole.

KuppingerCole Rising Star 2026 badge for Key2XS
Market segment
Physical Access Governance
Analyst
Warwick AshfordSenior Analyst, KuppingerCole Analysts
Published
September 2026Rising Star report, 11 pages
Position
In the Rising Star zoneFig. 1, KuppingerCole Rising Star matrix

01 The KuppingerCole verdict

“Key2XS shows an early but real alignment with an emerging need, in a market that is not yet crowded.”

KuppingerCole Analysts, Rising Star report on Key2XS, At a Glance, September 2026

“The combination of a defined regulatory driver, a clear technical gap between identity governance and physical key systems, and a large future addressable base nonetheless points toward the potential to define a new market segment, not compete for share within an existing one.”

“Key2XS's primary innovation is its identity-native model, in which physical access rights inherit directly from the governance model already running inside enterprise identity systems.”

02 Position

Key2XS: In the Rising Star zone.

Where Key2XS sits on the Rising Star matrix: high innovation, with product-market fit still to be proven at scale.

The read“A differentiated, identity-native core; scale, funding and category awareness are the work ahead.”
  • Founded 2024
  • Headquarters The Hague, Netherlands
  • Funding Seed
  • Licensing Subscription
  • Geographic focus Europe and the US

KuppingerCole ratings, out of five

  • Innovation5 / 5
  • Integrations4 / 5
  • Market Fit3 / 5
  • Brand Reach1 / 5

Scores from the report's At a Glance page. Brand Reach measures how widely a vendor is known today. This page is part of the answer.

03 Analyst's view

Why now, in the analyst's words

“Organizations need a single operational model connecting identity decisions to the physical keys and locks controlling access to critical national infrastructure (CNI).”

Warwick Ashford, Senior Analyst, KuppingerCole Analysts
Regulators

“Identity has already become the dominant attack surface for digital systems, and regulators are extending the same expectation of governed, auditable access to the physical estate that protects essential infrastructure.”

The gap

“Managing the two through separate, disconnected processes leaves gaps regulators are no longer willing to accept.”

Outlook

“Physical Access Governance is likely to grow steadily in the next two to three years, tracking the pace at which the CER Directive and NIS2 are transposed into national law and enforced.”

04 Strengths

What KuppingerCole highlighted

Six strengths, listed in the report. The headings are ours. The text under each one is the analyst's.

01

Rights inherit from the identity. No second process.

“Physical access rights inherited directly from the governance model already running inside connected identity systems, avoiding a parallel, disconnected access process”

02

Any identity system, any lock vendor, in any combination.

“Support for multiple identity systems and multiple lock vendors simultaneously, in any combination, without tying customers to a single vendor pairing”

03

Offline, evidence and contractor access: designed in, not bolted on.

“Offline operation, audit evidence, and JIT contractor access treated as core design requirements from the outset, not added later”

04

AI Key Plan does the translation work.

“An AI Key Plan component that automates a large share of the manual work involved in translating identity roles into physical access rights”

05

Tested, and on the way to ISO 27001.

“Independent validation through ISO 27001 progress and completed penetration testing, offering buyers early proof of security maturity from a young vendor”

06

Contracts that run with the cylinder cycle.

“Long contract terms tied to the multi-year replacement cycle of physical lock cylinders supporting durable customer relationships once a deployment is won”

Strengths quoted verbatim from the report's Strengths and Challenges page. The report also lists four challenges; see "The work ahead" below.

Read in full

The work ahead

“A differentiated, identity-native core; scale, funding and category awareness are the work ahead.”

The report's own one-line read of its strengths and challenges page.

The report is candid about what a company founded in 2024 still has to prove, and we would rather you read it here than find it elsewhere. The analyst lists four challenges: a team of fewer than ten people against the delivery and support demands of large infrastructure tenders; adoption concentrated in a small number of early engagements, with wider validation depending on regulatory timelines and lock conversion rates outside our control; a new category between identity governance and lock management, where buyer awareness is still developing; and a single seed-stage investor, with international expansion and hiring tied to funding discussions that are still open.

None of that changes what the analyst says about the design. All of it is a fair question to bring to a first conversation. Bring it.

05 The category

What the analyst means by Physical Access Governance

That is the definition we have been working to since 2024, now in an analyst's words. The category page sets it out in full: why the discipline exists, what it consists of, where PIAM stops, and what to ask a vendor.

Integrations named in the report

ASSA ABLOYiLOQSailPointMicrosoft Entra IDOktaOne IdentityOpenText
  1. “Physical Access Governance extends identity governance to the offline, mechanical, and electronic key systems protecting critical field assets such as substations, pumping stations, and bridges.”
  2. “It connects to Identity Governance and Administration (IGA) and Physical Identity and Access Management (PIAM), carrying roles, approvals, and lifecycle decisions from digital identities to physical keys and locks.”
  3. “The discipline is emerging amid regulatory pressure from the EU Critical Entities Resilience (CER) Directive and the Network and Information Security 2 (NIS2) Directive, and the ongoing shift to electronic lock systems.”

KuppingerCole Analysts, Rising Star report, September 2026.

06 The report

Read the full Rising Star report

Eleven pages: the verdict, the positioning matrix, the solution highlight, strengths and challenges, and the analyst's view of the market. Published by KuppingerCole Analysts, September 2026.

The report is © 2026 KuppingerCole Analysts AG and is available from KuppingerCole by subscription. Quotations on this page are reproduced with attribution.

Related KuppingerCole research

Talk to us about the findings

Every finding in the report is a fair question to bring to a first conversation. Tell us which one and we come back to you.

  • The verdict, the scores and the challenges, read against your critical infrastructure
  • Your identity systems and lock vendors in the conversation
  • A 30-minute walkthrough of identity, policy and physical keys if you want one

About the analyst

“Warwick Ashford is a Senior Analyst who researches cybersecurity and identity-related topics, including emerging technologies and trends. He has been writing IT news and analysis as a journalist and editor since 2003, specialising in cybersecurity and privacy since 2012. Warwick has also worked as a freelance radio producer and broadcast journalist, writing and presenting news bulletins on national radio for the South African Broadcasting Corporation.”

About KuppingerCole Analysts

“KuppingerCole, founded in 2004, is a global, independent analyst organization headquartered in Europe. We specialize in providing vendor-neutral advice, expertise, thought leadership, and practical relevance in Cybersecurity, Digital Identity & IAM (Identity and Access Management), Cloud Risk and Security, and Artificial Intelligence, as well as for all technologies fostering Digital Transformation.”

Boilerplate as published by KuppingerCole Analysts AG.

See what the analyst described, on your critical infrastructure

A 30-minute walkthrough of identity, policy and physical keys coming together in one auditable system. Bring the report's questions with you.