---
title: Using Key2XS in the Transportation Sector under the CER Directive
description: How transport operators use Key2XS to govern access to trackside, depots, tunnels and terminals under the EU CER Directive.
image: https://key2xs.com/hubfs/205665854_m.png
---

[![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg) ![Key2XS](https://key2xs.com/hubfs/img/logo-blue-horizontal.svg)](https://key2xs.com/?hsLang=nl)

 Why Governance?

[Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=nl) [CER Directive](https://key2xs.com/cer-directive?hsLang=nl) [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=nl) [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=nl) Analyst recognition [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=nl)

 Industries

[Government](https://key2xs.com/sectors/government?hsLang=nl) [Utilities](https://key2xs.com/sectors/utilities?hsLang=nl) [Water management](https://key2xs.com/sectors/water-management?hsLang=nl) [Transport](https://key2xs.com/sectors/transport?hsLang=nl) [Telecom](https://key2xs.com/sectors/telecom?hsLang=nl)

 Platform

[Product](https://key2xs.com/products?hsLang=nl) [How it works](https://key2xs.com/?hsLang=nl#how-it-works) [Integrations](https://key2xs.com/integrations?hsLang=nl) [Book a demo](https://key2xs.com/contact?hsLang=nl)

 Partners

Technology partners [SailPoint](https://key2xs.com/sailpoint-partnership?hsLang=nl) [One Identity](https://key2xs.com/partners/one-identity?hsLang=nl) [Microsoft Entra ID](https://key2xs.com/partners/entra-id?hsLang=nl) [Okta](https://key2xs.com/partners/okta?hsLang=nl) [OpenText](https://key2xs.com/partners/opentext?hsLang=nl) [iLOQ](https://key2xs.com/partners/iloq?hsLang=nl) [ASSA ABLOY](https://key2xs.com/partners/assa-abloy?hsLang=nl) Resell & Implementation partners [Hanab](https://key2xs.com/partners/hanab?hsLang=nl)

 Resources

[Resource center](https://key2xs.com/resources?hsLang=nl) [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=nl) [Events](https://key2xs.com/events?hsLang=nl) Meet us at Navigate [Navigate Austin · Oct 5-8](https://key2xs.com/events/sailpoint-navigate-austin?hsLang=nl) [Navigate London · Nov 2-4](https://key2xs.com/events/sailpoint-navigate-london?hsLang=nl) [ROI calculator](https://key2xs.com/roi-calculator?hsLang=nl) [FAQ](https://key2xs.com/?hsLang=nl#faq)

[News](https://key2xs.com/news-archive?hsLang=nl) 

[Book a demo](https://key2xs.com/contact?hsLang=nl) 

[Book a demo](https://key2xs.com/contact?hsLang=nl)

[← The Key2XS journal](https://key2xs.com/news-archive?hsLang=nl)  
News

# Using Key2XS in the Transportation Sector under the CER Directive

Sep 22, 2025 · 5 min read · by the Key2XS team

![Using Key2XS in the Transportation Sector under the CER Directive](https://key2xs.com/hubfs/205665854_m.png)

**In short:** CER raises resilience requirements across rail, aviation, ports and road infrastructure. Key2XS lets transport operators govern trackside, depot and tunnel access from their IAM — with rapid revocation and evidence ready for supervisors.

# **Using Key2XS in the Transportation Sector under the CER Directive**

Europe’s **Critical Entities Resilience (CER) Directive** raises the bar for the resilience of transport infrastructure, rail, aviation, maritime/ports, road, bridges and tunnels, depots, intermodal terminals, and supporting energy/ICT sites. Operators must harden both **physical** and **digital** controls, prove supply-chain oversight, and demonstrate fast incident response.

**Key2XS** bridges Identity & Access Management (IAM) with electronic key systems (e.g., [ASSA ABLOY CLIQ](http://www.assaabloy.com), [iLOQ](http://www.iloq.com)), turning physical keys and cylinders into **policy-driven, auditable, and revocable** entitlements. The result: fewer standing privileges, cleaner audits, and measurably better resilience all aligned with [CER](https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng) (and complementary to [NIS2](https://key2xs.com/nis2-directive?hsLang=nl)).

 

## **What CER expects from transport operators (in plain terms)**

- **Risk-based resilience:** Identify critical assets and dependencies; reduce single points of failure across sites, doors, cabinets, and OT enclosures.
- **Controls that actually work:** Appropriate and proportionate physical protections, access governance, incident handling, business continuity, and supply-chain controls.
- **Evidence & reporting:** Prove who had access, when, and why; show timely incident notification and corrective measures as required by national transposition.
- **Third-party oversight:** Ensure contractors and vendors follow equivalent controls especially for time-bound, role-based physical access.

 

## **Where transport environments struggle today**

- **Standing keys and shared badges** that are hard to revoke across regions, depots, and contractors.
- **Siloed systems:** IAM governs apps; key systems govern doors and cabinets creating blind spots in audits.
- **Manual processes:** Paper authorizations and key safes slow emergency response and complicate investigations.
- **OT exposure:** Cabinets for SCADA, signaling, PIDS/CCTV, telecoms, and power distribution still rely on mechanical or locally programmed locks.
- **Fragmented vendors:** Multiple key systems per geography or business unit.

 

## **How Key2XS helps (capabilities mapped to CER themes)**

### **1 Governance & least privilege**

- **Unify identities:** Connect Microsoft [Entra ID](https://key2xs.com/integrations/entra-id-iloq?hsLang=nl), Okta, [SailPoint](https://key2xs.com/integrations/sailpoint-iloq?hsLang=nl), One Identity to electronic key systems via Key2XS.
- **Role & zone-based policies:** Grant access by role (e.g., “Rail Signaling Technician L2”) and **zones** (depots, signal boxes, trackside cabinets, sub-stations, airside doors, fuel farms, cranes, berth power).
- **Just-in-Time (JIT) keys:** Keys activate only for the approved job window and locations; expire automatically.

### **2 Incident readiness & continuity**

- **Break-glass with guardrails:** Emergency access that’s logged, geo/zone-constrained, and time-boxed.
- **Forensic audit trails:** Who accessed which asset, when, with which key, and under which change ticket.
- **Offline tolerance:** Keys and cylinders operate even with intermittent connectivity; sync when back online.

### **3 Supply-chain control**

- **Contractor onboarding/off-boarding:** Automate access windows per contract, task order, or permit-to-work.
- **Attestation flows:** Require periodic re-approval of contractor access; auto-revoke if attestations lapse.

### **4 Monitoring & detection**

- **Unified logs:** Send physical-access events to your SIEM/SOC alongside IT/OT telemetry to spot hybrid threats.
- **Risk signals:** Flag anomalous patterns (e.g., repeated after-hours attempts on signaling cabinets).

### **5 Compliance proof**

- **Evidence packs on demand:** Export audit-ready reports for inspections and post-incident reviews.
- **Policy verifiability:** Show that physical keys obey the same IAM policies as digital entitlements.
- **Data protection:** Key2XS uses pointer-based integrations so personal data can remain in your IAM; EU hosting and GDPR-aligned processing by design.

 

## **Mode-specific examples**

**Rail**

- Trackside & interlocking cabinets, signal boxes, power/telecom huts, depot workshops, rolling-stock maintenance bays.
- JIT access tied to work orders; automatic revocation at shift end; audit trail mapped to asset IDs.

**Aviation (airports & ANSP sites)**

- Airside doors, comms rooms, fuel farms, navigation aids shelters.
- Role-based zones (airside/landside/critical) with escorted-access rules and incident “hold & review” workflows.

**Maritime & ports**

- Gatehouses, cranes, berth power cabinets, ICS/OT rooms, bonded warehouses.
- Temporary vendor access for crane maintenance—valid only during berth slot time windows.

**Road, bridges & tunnels**

- Control rooms, ventilation and pump cabinets, SCADA panels in shafts and lay-bys.
- Emergency crews receive time-boxed keys for incident response; all actions logged to the SOC.

 

## **Reference architecture (high level)**

- **Northbound:** IAM ([Entra ID](http://www.microsoft.com)/[Okta](http://www.okta.com)/[SailPoint](https://www.sailpoint.com)/[One Identity](https://www.oneidentity.com)) → Key2XS policy engine.
- **Southbound:** Key2XS → Electronic key systems ([CLIQ](https://key2xs.com/integrations/assa-abloy-cliq?hsLang=nl), [iLOQ](https://key2xs.com/integrations/iloq?hsLang=nl), etc.).
- **Sidecar:** SIEM/SOC for event ingestion; ITSM/CMMS for work orders and approvals.
- **Edge reality:** Keys/cylinders support offline operation; mobile app for on-site activation where required.

![Key2XS Reference Architecture “We bridge the digital and physical access world”](https://key2xs.com/hs-fs/hubfs/Key2XS%20Reference%20Architecture%20%E2%80%9CWe%20bridge%20the%20digital%20and%20physical%20access%20world%E2%80%9D.png?width=1589&height=1093&name=Key2XS%20Reference%20Architecture%20%E2%80%9CWe%20bridge%20the%20digital%20and%20physical%20access%20world%E2%80%9D.png)

## **Fast path to value (90-day rollout)**

**Weeks 0–2 – Foundations**

Connect IAM; import org roles; inventory sites, zones, keys/cylinders; map contractors.

**Weeks 3–6 – Pilot & JIT**

Select a corridor/terminal/yard; enable JIT keys for maintenance & emergency crews; stream logs to SIEM.

**Weeks 7–10 – Scale & automate**

Add additional vendors/sites; switch on AI-assisted keyplan recommendations and SoD (segregation of duties).

Align SOC playbooks for hybrid incidents.

**Weeks 11–13 – Prove & optimize**

Demonstrate KPIs; finalize audit packs; tune policies and renewal/attestation cadences.

 

## **Example policies you can enforce with Key2XS**

- “**No standing keys** in critical zones; JIT only with ticket reference.”
- “**Contractor keys auto-expire** at end-of-shift and on contract termination.”
- “**Dual-approval** for airside critical cabinets; emergency override requires post-incident review.”
- “**SoD:** no single role grants both signaling access and network core access within the same 24-hour window.”

 

## **KPIs that matter for CER audits**

- Time to provision/revoke physical access.
- % of **JIT vs. standing** physical entitlements.
- Number of **access exceptions** and remediation time.
- **Contractor onboarding** time and attestation compliance.
- Mean time to **correlate** physical + cyber events in hybrid incidents.
- **Audit readiness**: time to compile evidence for a site/zone.

 

## **Procurement & integration checklist**

- Works with your IAM (Entra/Okta/SailPoint/One Identity).
- Supports your key system vendors (CLIQ, iLOQ, etc.) and mixed estates.
- JIT activation, offline operation, and emergency break-glass with full audit.
- SIEM/SOC, ITSM/CMMS integrations and API coverage.
- EU hosting & GDPR-aligned design (pointer-based identity).
- Evidence exports for inspections and post-incident reporting.

 

## **Business impact**

- **Risk reduction:** Fewer standing privileges; faster, safer incident response.
- **Operational efficiency:** No couriered keys or manual safes; less admin churn.
- **Compliance confidence:** Clear evidence for CER inspections and complementary NIS2 audits.
- **Scalability:** One policy layer across multi-vendor, multi-site estates.

 

### **Bottom line ![24879A0D-EC7F-4F5C-8B7B-6E74EFEAE2AA](https://key2xs.com/hs-fs/hubfs/24879A0D-EC7F-4F5C-8B7B-6E74EFEAE2AA.png?width=73&height=73&name=24879A0D-EC7F-4F5C-8B7B-6E74EFEAE2AA.png)**

CER pushes transport operators to **treat physical access like any other critical entitlement,** least privilege, JIT, monitored, and revocable. Key2XS makes that practical at scale, unifying your IAM, your vendors, and your field reality into one **policy-driven, auditable** framework.

![](https://key2xs.com/hubfs/1587550138006.jpeg)![](https://key2xs.com/hubfs/img/niels-bakker.png)![](https://key2xs.com/hubfs/1746630921693.jpeg)![](https://key2xs.com/hubfs/1696359051569.jpeg)

**Written by the Key2XS team**

Key2XS is founder-run. Questions about this piece land with the people who built the platform. [Talk to us](https://key2xs.com/contact?hsLang=nl).

## Keep reading

[![](https://key2xs.com/hubfs/19294161_m.png) **Keeping Rotterdam’s Refineries Safe with Key2XS and Proving CER Compliance**Sep 08, 2025](https://key2xs.com/news/keeping-rotterdams-refineries-safe-with-key2xs-and-proving-cer-compliance?hsLang=nl) [![](https://key2xs.com/hubfs/2keyholekey2xs.png) **Bridging Worlds: How Logical and Physical Access Are Converging and Why Key2XS Is Out in Front**Aug 18, 2025](https://key2xs.com/news/bridging-worlds-how-logical-and-physical-access-are-converging-and-why-key2xs-is-out-in-front?hsLang=nl) [![](https://key2xs.com/hubfs/hacker1_key2xs.png) **Anatomy of a Hacktivist Attack – and How Key2XS Helps Prevent It**Oct 13, 2025](https://key2xs.com/news/anatomy-of-a-hacktivist-attack-and-how-key2xs-helps-prevent-it?hsLang=nl)

## Govern the keys you already have

See identity, policy and physical keys in one 30-minute demo, scoped to your estate.

[Book a demo](https://key2xs.com/contact?hsLang=nl) [More in the journal](https://key2xs.com/news-archive?hsLang=nl)

### Contact us

[Wilhelmina van Pruisenweg 104, 2595 AN Den Haag](https://maps.google.com/?q=Wilhelmina+van+Pruisenweg+104+Den+Haag)

Kraanspoor 50, 1033 SE Amsterdam, The Netherlands 

[info@key2xs.com](mailto:info@key2xs.com) [+31(0)70 2045180](tel:+31(0)702045180)

### Platform

- [Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=nl)
- [Product](https://key2xs.com/products?hsLang=nl)
- [Integrations](https://key2xs.com/integrations?hsLang=nl)
- [ROI calculator](https://key2xs.com/roi-calculator?hsLang=nl)

### Compliance

- [CER Directive](https://key2xs.com/cer-directive?hsLang=nl)
- [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=nl)
- [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=nl)

### Company

- [SailPoint partnership](https://key2xs.com/sailpoint-partnership?hsLang=nl)
- [Resource center](https://key2xs.com/resources?hsLang=nl)
- [Events](https://key2xs.com/events?hsLang=nl)
- [News](https://key2xs.com/news-archive?hsLang=nl)
- [Contact](https://key2xs.com/contact?hsLang=nl)

[![Penetration tested and verified by Sekurno](https://key2xs.com/hubfs/img/badges/sekurno-pentest-badge-white.svg)](https://www.sekurno.com/verified/key2xs) [![KuppingerCole Analysts Rising Star 2026 badge for Key2XS](https://key2xs.com/hubfs/img/badges/kuppingercole-rising-star-2026-key2xs.svg)](https://key2xs.com/analyst-recognition?hsLang=nl)

---

![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg)

Key2XS, pronounced “key to access”

© 2026 Key2XS B.V. All rights reserved

<https://www.linkedin.com/company/key2xs>

[Privacy](https://key2xs.com/privacy-statement?hsLang=nl)  Cookie Preferences

Patent Pending Nr: 2040721 & 2041284

Key2XS & ActiveAuth are registered trademarks of Key2XS Assets B.V.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Key2XS",
    "url" : "https://key2xs.com/news/author/key2xs-2"
  },
  "dateModified" : "2026-03-05T10:23:36.477Z",
  "datePublished" : "2025-09-22T07:00:00.000Z",
  "headline" : "Using Key2XS in the Transportation Sector under the CER Directive",
  "image" : [ "https://key2xs.com/hubfs/205665854_m.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://key2xs.com/news/using-key2xs-in-the-transportation-sector-under-the-cer-directive",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://key2xs.com/hubfs/logo%20blue.svg"
    },
    "name" : "Key2XS B.V."
  }
}
```