Government estates are not just diverse, they are used by an unusually wide population: civil servants, external consultants on temporary contracts, outsourced facility and cleaning services, event organizers in civic venues, and field teams from public works. Each of them needs keys, and each arrival and departure is a change the key administration must catch.
In practice, it rarely catches all of them:
For a private company this is a risk. For a public body it is also an accountability problem: when an incident happens in an archive, a depot or a pumping station, the question “who could enter here, and on whose authority” will be asked publicly, and “we are not entirely sure” is not an answer a responsible authority can give.
Dutch public organizations work under the Baseline Informatiebeveiliging Overheid (BIO), which includes explicit controls for physical access to spaces where information and systems reside. NIS2 brings public administration entities into scope of EU cybersecurity law, including its requirement for appropriate policies governing access to premises. Municipalities operating critical infrastructure, such as sewage management or waterway installations, can additionally face CER obligations.
Common to all three frameworks: physical access must be governed, current and demonstrable. Key2XS makes it so by construction. Every key right exists because an identity holds a role that policy maps to that access, every change is logged in a tamper-evident audit trail, and every audit question about physical access is answered from the system in minutes.
Key2XS is middleware between the IAM system you already run and the digital locking system already on your buildings and installations. Nothing about your locks, keys or locking plan changes.
A typical flow: an external consultant joins a ministry programme for six months. Their identity is registered in the IAM with a contract end date, their programme role maps to exactly the offices and meeting areas they need, and Key2XS grants the matching key rights. On the contract end date, the access expires with the contract, without anyone needing to remember it. No exit checklist item, no key that lives on in a drawer.
For field operations, the same principle covers the technical estate: the public works team for district maintenance holds key rights to precisely the pumping stations, traffic cabinets and depots in their district, derived from their team assignment, updated in near real-time when the assignment changes.
Implementation fits within public IT reality: a standard integration is live in under two hours through pre-built connectors, with no custom development and no replacement of existing systems.
The platform is engineered for 99.99% availability, and all communication is encrypted with TLS 1.3 in transit and AES-256 at rest.