<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=7847562&amp;fmt=gif">
Home > Sectors

Physical access governance for government

Public organizations manage a remarkable variety of doors: town halls and civic offices, but also archives, depots, sewage pumping stations, traffic installations and storage for everything from ballot boxes to service vehicles. Key2XS connects your identity and access management system to your iLOQ or ASSA ABLOY CLIQ keys, so every one of those doors is governed by identity, aligned with policy, and accountable to the standards public organizations are held to.

Request a demo

Many hands, public accountability

Government estates are not just diverse, they are used by an unusually wide population: civil servants, external consultants on temporary contracts, outsourced facility and cleaning services, event organizers in civic venues, and field teams from public works. Each of them needs keys, and each arrival and departure is a change the key administration must catch.

In practice, it rarely catches all of them:

For a private company this is a risk. For a public body it is also an accountability problem: when an incident happens in an archive, a depot or a pumping station, the question “who could enter here, and on whose authority” will be asked publicly, and “we are not entirely sure” is not an answer a responsible authority can give.

BIO, NIS2 and the standards you answer to

Dutch public organizations work under the Baseline Informatiebeveiliging Overheid (BIO), which includes explicit controls for physical access to spaces where information and systems reside. NIS2 brings public administration entities into scope of EU cybersecurity law, including its requirement for appropriate policies governing access to premises. Municipalities operating critical infrastructure, such as sewage management or waterway installations, can additionally face CER obligations.

Common to all three frameworks: physical access must be governed, current and demonstrable. Key2XS makes it so by construction. Every key right exists because an identity holds a role that policy maps to that access, every change is logged in a tamper-evident audit trail, and every audit question about physical access is answered from the system in minutes.

How public organizations use Key2XS

Key2XS is middleware between the IAM system you already run and the digital locking system already on your buildings and installations. Nothing about your locks, keys or locking plan changes.

A typical flow: an external consultant joins a ministry programme for six months. Their identity is registered in the IAM with a contract end date, their programme role maps to exactly the offices and meeting areas they need, and Key2XS grants the matching key rights. On the contract end date, the access expires with the contract, without anyone needing to remember it. No exit checklist item, no key that lives on in a drawer.

For field operations, the same principle covers the technical estate: the public works team for district maintenance holds key rights to precisely the pumping stations, traffic cabinets and depots in their district, derived from their team assignment, updated in near real-time when the assignment changes.

Implementation fits within public IT reality: a standard integration is live in under two hours through pre-built connectors, with no custom development and no replacement of existing systems.

Works with what you already run

The platform is engineered for 99.99% availability, and all communication is encrypted with TLS 1.3 in transit and AES-256 at rest.

Frequently asked questions

Physical access governance for government, answered.

See it working across your organization

Get a guided walkthrough of how identity, policy and physical keys come together, from the town hall to the technical estate.