The EU Critical Entities Resilience Directive, CER, does not require organisations to replace mechanical locks with electronic ones. Yet it fundamentally changes what is expected from organisations responsible for critical infrastructure. Physical access is no longer simply about protecting a building or asset. It is becoming part of the governance and resilience of essential services.
For Key2XS, this creates a significant market opportunity. As an estimated 18 million CER-relevant physical access points across Europe gradually move from mechanical key management towards electronically governed access, organisations will need a governance layer that connects physical access to identity, policy, risk and the existing IAM and IGA infrastructure. This is precisely the layer Key2XS provides.
That change is likely to trigger one of the largest modernisation programmes ever seen in Europe’s physical security market. Once organisations must demonstrate who has access to critical assets, why that access exists and whether it can be revoked immediately, the limitations of traditional mechanical key management become increasingly apparent.
A Market Measured in Tens of Millions of Access Points
The scale of European critical infrastructure is often underestimated. When people think about critical infrastructure, they picture power stations, airports or large hospitals. In reality, Europe’s critical infrastructure is a vast network of geographically distributed assets. Electricity substations, transformer stations, telecom towers, railway stations, tunnels, bridges, pumping stations, data centres, hospitals, ports and government facilities are spread across every Member State. Each of these locations contains protected areas that require controlled access.
Based on the infrastructure covered by CER, Key2XS estimates that Europe contains approximately 18 million CER-relevant physical access points, with a realistic range between 15 and 22 million. This is not an official European statistic (there is no central EU database on locks) but a market model based on infrastructure density and the number of protected operational spaces that require controlled physical access.
The largest share is found in the energy sector, followed by transport, telecommunications, government infrastructure, water utilities, healthcare and digital infrastructure. Transport alone represents millions of access points because the sector extends far beyond railways. Roads, tunnels, airports, ports, inland terminals, traffic management centres and maintenance facilities all fall within the scope of critical infrastructure. A modern airport or railway station may contain hundreds or even thousands of restricted technical areas, while a tunnel includes control rooms, electrical installations, communications equipment and emergency facilities that all require different levels of authorisation.
The conclusion is straightforward. Europe is not preparing to modernise hundreds of thousands of locks. It is facing the governance of tens of millions of physical access decisions.
The Real Challenge Is Not the Lock
It would be easy to conclude that CER is creating a replacement market for electronic cylinders. That would miss the point entirely.
A high-quality mechanical lock can provide excellent physical protection. The weakness lies elsewhere. Once a mechanical key has been issued, the organisation has very limited control over the access right it represents. The key may still be in circulation years after the original assignment has ended. It may have been copied. An employee may have changed roles or left the organisation altogether. A contractor may still possess access to infrastructure long after the contract has expired. None of these situations is caused by the lock itself. They are governance problems.
CER shifts the discussion away from hardware and towards accountability. Organisations increasingly need to demonstrate not only that an asset is protected, but also that access is justified, approved, periodically reviewed and withdrawn when it is no longer required.
The Economics of Physical Access Are Changing
Historically, organisations compared the purchase price of a mechanical cylinder with that of an electronic one. The investment decision was largely made by facilities or maintenance departments.
CER changes that calculation. The real cost is no longer determined by the cylinder. It is determined by the effort required to maintain control over physical access. Lost keys, manual administration, contractor management, audit preparation, emergency rekeying and the inability to prove who should have access all become part of the business case.
At the scale of approximately 18 million potential access points, even gradual migration represents a substantial market. Assuming a blended hardware value of €250 to €500 per electronically governed access point, the hardware opportunity alone reaches approximately €4.5 to €9 billion. Once software platforms, electronic credentials, installation, lifecycle management, integration with Identity Governance systems and ongoing services are included, the overall market becomes significantly larger.
For Key2XS, however, the addressable opportunity is not primarily the hardware replacement market. The strategic opportunity sits above the lock. As organisations deploy different electronic locking technologies across thousands of assets, they need a common governance layer connecting those systems to corporate identities, policies and approval processes. The larger and more heterogeneous the electronic locking estate becomes, the stronger the requirement for such a layer.
This Transition Will Take Decades, Not Years
Replacing such a vast installed base cannot happen quickly. Critical infrastructure operators cannot simply close substations, tunnels, airports or hospitals while access systems are replaced. Every migration must be planned around operational continuity, procurement cycles, regulatory oversight and integration with existing security processes.
For that reason, the transition is unlikely to resemble a traditional product replacement cycle. It will evolve over fifteen to twenty years, beginning with the highest-risk assets and gradually expanding as infrastructure is modernised. During that period, organisations will continue to operate a mixture of mechanical locks, electronic cylinders, online access control systems and mobile credentials.
Managing that hybrid environment will become one of the largest operational challenges. Most organisations will not standardise on a single locking technology. Instead, they will need a governance layer capable of managing different locking systems, different suppliers and different generations of technology through one consistent identity model.
This hybrid transition is particularly relevant to Key2XS. Rather than requiring an organisation to replace its complete physical access infrastructure with a single technology, Key2XS can provide the governance layer across the evolving environment. Existing electronic locking systems can coexist with newly deployed systems while access decisions are increasingly controlled from the identity layer.
From Key Management to Identity Governance
The most important consequence of CER is therefore not technological but organisational.
Traditional key management records which employee possesses which key. Modern governance asks a different question altogether. It asks whether a particular identity should currently be allowed to access a particular asset, for a specific purpose, during a defined period and under approved conditions.
That shift mirrors the evolution that has already taken place in IT. Organisations no longer manage application passwords manually. They govern identities, roles and entitlements through Identity Governance and Administration platforms. Physical access is now beginning the same transformation.
When physical access becomes linked to digital identity, organisations can apply familiar governance principles such as least privilege, role-based access, just-in-time authorisation, automatic revocation and periodic access reviews. These concepts are already standard practice for logical access. CER is accelerating their adoption in the physical domain.
This is where Key2XS connects two historically separate environments. Instead of creating another standalone physical access management platform, Key2XS connects electronic locking systems to the organisation’s existing identity infrastructure. Physical access can therefore become part of the same governance processes already used for logical access.
Why Electronic Locks Alone Are Not Enough
Replacing mechanical cylinders with electronic ones does not automatically solve the governance problem. Electronic hardware without identity governance simply digitises the existing process.
The real transformation occurs when electronic access rights become part of the identity lifecycle. An employee joining the organisation receives only the physical permissions required for the role. A contractor receives temporary access linked to a specific work order. When employment or a contract ends, physical permissions disappear automatically alongside digital accounts.
At that point, physical and logical access are no longer separate disciplines. They become two expressions of the same identity.
This also explains why the CER opportunity for Key2XS potentially grows as electronic locking adoption accelerates. Key2XS does not compete for the cylinder. It governs the access decision behind it. The electronic lock makes the physical entitlement programmable. Key2XS connects that entitlement to identity and policy.
The Future of Critical Infrastructure Access
For centuries, physical security has been based on a simple principle. Whoever possesses the correct key may enter.
CER challenges that assumption. The relevant question is no longer whether a key fits a lock. The relevant question is whether the person standing in front of the door should have access at that particular moment, for that particular task and under those particular circumstances. That subtle difference fundamentally changes the role of physical security.
Europe is entering a period in which approximately 18 million critical infrastructure access points could gradually move from mechanical administration towards digitally governed access. The transition will take years, perhaps decades, but the direction is becoming increasingly clear.
For Key2XS, that creates a long-term opportunity that extends beyond the initial replacement cycle. Every new electronic access point becomes another physical entitlement that needs to be provisioned, reviewed, revoked, audited and governed throughout its lifecycle. The future is therefore not simply a transition from mechanical to electronic.
It is a transition from keys to identities, from possession to entitlement, and from physical security to governed access. And that is where Key2XS is positioned. Ultimately, every access decision to a critical infrastructure asset should become an Identity Decision.