← The Key2XS journal
ASSA Abloy Cliq

Closing the maturity gap in physical access: how Key2XS gets operators to CER compliance, fast, then right

Nov 17, 2025 · 6 min read · by the Key2XS team

Maturity Model

In short: European energy operators are unevenly prepared for CER: digitalization is advancing but key management often still runs on sign-out sheets. Key2XS gets operators to compliance fast with a standard integration, then right — extending governance depth without replacing locks or locking plans.

Closing the maturity gap in physical access: how Key2XS gets operators to CER compliance, fast, then right

 

Executive summary

European energy operators sit on uneven ground. Dutch DSOs are relatively advanced on digitalization, yet many still lag on key management. In Germany and elsewhere, manual sign-out sheets and ad-hoc approvals are still common. NIS2 and the CER Directive remove the wiggle room: board-level accountability, risk-based controls, provable governance, and auditable evidence across both IT and OT.

Key2XS is built to normalize that variance. It gives operators a single control plane to bind physical keys, cylinders, doors, people, roles, and time to the same identity fabric that governs IT, then it automates the maturity journey from “paper-based” to “policy-driven and auditable”.

 

The reality today

 

A pragmatic maturity model for physical access governance

 

Maturity Model for physical access governance

Level

Description

Level 0: Manual / Implicit Trust

Paper logs, keys exchanged hand-to-hand, no time-bound rights, and no central register.

Level 1: Central register & basic custody

Single inventory of keys/cylinders, named custodians, manual approvals captured in one place.

Level 2: Identity-bound access

Tie keys and cards to people in the IAM source of truth (Entra ID, Okta, SailPoint, One Identity). Time windows and role-based templates introduced.

Level 3: Workflow & evidence

Standardized approval flows (SoD, four-eyes), attestation cycles, automatic revocation on HR or vendor offboarding, exportable audit trails.

Level 4: Policy-as-code & automation

Risk-based policies, emergency override with just-in-time access, geo/time fencing, anomaly detection, API-level integrations to alarm/SCADA dispatch.

Level 5: Continuous compliance

Automated recertification, KPI/SLAs, incident-response playbooks linked to access controls, full CER control coverage with board-ready evidence.

Key2XS is engineered to move operators one rung at a time, without ripping and replacing lock systems or IAM.

 

How Key2XS closes gaps, capability map

1) Identity-anchored key and cylinder management

 

2) Approval workflows that scale from manual to automated

 

3) Contractor lifecycle control

 

4) Offline-tolerant operations with auditable evidence

 

5) Alarm, monitoring, and dispatch integration

 

6) Evidence, KPIs, and board-level reporting

 

Mapping to CER outcomes (operator language, not legalese)

 

A realistic adoption path (90/180/365)

Days 0–90: Stabilize

 

Days 91–180: Govern

 

Days 181–365: Automate & assure

 

What this means for different operator profiles

Mature DSOs (NL-style) with a weak spot in keys

Operators using manual/written approvals (common in parts of DE)

Contractor-heavy TSOs and service providers

 

Controls that move the needle (and are easy to defend in audits)

 

What you need from IT/OT to execute

 

Why this works for NIS2/CER

CER and NIS2 don’t mandate brands; they mandate outcomes: governed risk, controlled access, rapid response, and evidence. Key2XS operationalizes these outcomes for the physical domain, in language your auditors and your field teams both accept. You get quick wins in 90 days and a straight path to continuous compliance within a year, without derailing operations.

Written by the Key2XS team

Key2XS is founder-run. Questions about this piece land with the people who built the platform. Talk to us.

Govern the keys you already have

See identity, policy and physical keys in one 30-minute demo, scoped to your estate.