---
title: Physical Access Governance for Telecom | Key2XS
description: Identity-driven key management for network operators. Govern mast sites, exchanges, street cabinets and data centres, audit-ready for NIS2 and CER.
image: https://key2xs.com/hubfs/img/og-image.png
---

[![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg) ![Key2XS](https://key2xs.com/hubfs/img/logo-blue-horizontal.svg)](https://key2xs.com/?hsLang=en)

 Why Governance?

[Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en) [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=en) [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=en) Analyst recognition [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=en)

 Industries

[Government](https://key2xs.com/sectors/government?hsLang=en) [Utilities](https://key2xs.com/sectors/utilities?hsLang=en) [Water management](https://key2xs.com/sectors/water-management?hsLang=en) [Transport](https://key2xs.com/sectors/transport?hsLang=en) [Telecom](https://key2xs.com/sectors/telecom?hsLang=en)

 Platform

[Product](https://key2xs.com/products?hsLang=en) [How it works](https://key2xs.com/?hsLang=en#how-it-works) [Integrations](https://key2xs.com/integrations?hsLang=en) [Book a demo](https://key2xs.com/contact?hsLang=en)

 Partners

Technology partners [SailPoint](https://key2xs.com/sailpoint-partnership?hsLang=en) [One Identity](https://key2xs.com/partners/one-identity?hsLang=en) [Microsoft Entra ID](https://key2xs.com/partners/entra-id?hsLang=en) [Okta](https://key2xs.com/partners/okta?hsLang=en) [OpenText](https://key2xs.com/partners/opentext?hsLang=en) [iLOQ](https://key2xs.com/partners/iloq?hsLang=en) [ASSA ABLOY](https://key2xs.com/partners/assa-abloy?hsLang=en) Resell & Implementation partners [Hanab](https://key2xs.com/partners/hanab?hsLang=en)

 Resources

[Resource center](https://key2xs.com/resources?hsLang=en) [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=en) [Events](https://key2xs.com/events?hsLang=en) Meet us at Navigate [Navigate Austin · Oct 5-8](https://key2xs.com/events/sailpoint-navigate-austin?hsLang=en) [Navigate London · Nov 2-4](https://key2xs.com/events/sailpoint-navigate-london?hsLang=en) [ROI calculator](https://key2xs.com/roi-calculator?hsLang=en) [FAQ](https://key2xs.com/?hsLang=en#faq)

[News](https://key2xs.com/news-archive?hsLang=en) 

[Book a demo](https://key2xs.com/contact?hsLang=en) 

[Book a demo](https://key2xs.com/contact?hsLang=en)

Industries · Telecom

# Physical access governance for telecom

Mast sites, exchanges, street cabinets and data centres: a network is only as closed as its most remote door. Key2XS connects the IAM you already run to the keys already on your sites.

[Book a 30-minute demo](https://key2xs.com/contact?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en)

Key2XS console

TW

**T. Willems**Rigger · Tower contractor

Order 8841

Access rights · work order 8841

**Mast NL-0417**Granted

**Mast NL-0431**Granted

**Street cabinet C-88**Granted

**POP Amsterdam-2**Ends Fri

**Key updated**3 access rights · via Okta

07:45:12 **GRANT** mast-nl-0417 ← work-order-8841

**Thousands**of sites: masts, cabinets, exchanges

**< 2 hrs**standard integration, live

**99.99%**platform availability

**NIS2 + CER**digital infrastructure in scope

The problem

## Shared masts, subcontracted hands

Tower crews, fibre contractors and facilities firms all carry keys. Sites are shared, work is subcontracted, and every handover multiplies who can open what.

### Subcontractor chains

The operator contracts the tower firm; the tower firm hires the crew. The key does not know that.

### Shared sites

Co-location means more parties at the door than any one registry shows.

### 24/7 fault response

Night call-outs need doors open now, so keys are cut broad.

### Crew rotation

Riggers change per job; site keys outlive the work order.

The network carries everyone's traffic. The question a regulator asks is simple: *who can open your sites, right now?*

How it works

## Access that follows the identity

Middleware between your IAM and the key systems on your sites. Follow one tower crew through four events.

Event 1**Work order**Masts and cabinets on the order

Event 2**Reassigned**Moved to core maintenance

Event 3**Night call-out**Fault at 02:11

Event 4**Order closes**Crew rolls off

Call-out access active

Access network Core sites

*source: IAM*  
work-order: tower-maintenance / 8841  
*result:* 4 sites granted

The work order in your IAM becomes access rights for exactly the sites on it. Every right traces to the order, through the whole subcontractor chain.

*source: IAM*  
work-order: core-maintenance / 8907  
*result:* 4 withdrawn, 4 granted

The crew moves to core work; the rights move with them, in one movement, near real time.

the mast keys ride along to every next job.

*source: IAM*  
role: standby / on-call  
*result:* estate-wide, bounded

A fault at two in the morning needs doors open now. The on-call role grants broad access, bounded to the rotation, visible in the audit trail.

*source: IAM*  
status: order closed  
*result:* every site closed, logged

When the order closes or the contract ends, every site door closes with it, in the same movement. Logged.

Audit trail

07:45:12GRANTmast-nl-0417work order 8841

07:45:12GRANTmast-nl-0431work order 8841

07:45:13GRANTcabinet-c88work order 8841

16:20:04REVOKEmast-nl-0417order closed, auto

16:20:04LOGold rights closedsame movement

02:11:48GRANTexchange-zuidon-call role

02:11:49LOGevidence sealedaudit chain

chain intact · tamper-evident

NIS2 and CER

## Digital infrastructure, physically governed

NIS2 puts providers of public electronic communications networks in scope. CER names digital infrastructure a critical sector. Both ask who can physically reach the network.

**Who can enter this mast site, right now?**Live, per identity, work order and approval.

**Which subcontractors hold access today?**Every access right traces to a contract in your IAM.

**Show a year of changes for this exchange.**One tamper-evident trail. Minutes, not days.

Mechanics

## Governance that survives being offline

A street cabinet has no badge reader and a mast site has no receptionist. Rights travel with the key, and a withdrawal is enforced at the next key update.

### How rights travel

**Control plane**the decision

**The key**carries the rights

**The lock**no power, no network

The next time the key is used or updated it picks up its new rights. Revocation propagates the same way.

### What happens on withdrawal

**Right withdrawn**in the control plane

*revocation window*

**Enforced at the key**next update or check

Closed by the key system's own offline logic

Validity expiryBlacklist checkOnline update

Near real time, not instantaneous. Each key system closes the window with its own mechanism; Key2XS makes the decision centrally and logs the change.

Works with what you run

## Identity decides. Policy governs. Technology executes.

Middleware through standard interfaces. Locks, keys and the locking plan stay as they are.

Identity side

SailPointCertified partner Microsoft Entra ID Okta One Identity Manager OpenText Identity Manager

**Key2XS**

Identity decisions become access rights, with evidence.

Locking side

iLOQ ASSA ABLOY CLIQeCLIQ · PROTEC², certified ASSA ABLOY AccessASSA ACCESS · ASSA CUMULUS · ASSA PULSE ASSA ABLOY Traka

FAQ

## Telecom, answered

Our sites range from street cabinets to data centres. Is that one solution?

Yes. Key2XS governs access rights centrally regardless of site type. Masts, street cabinets, exchanges and data centres are all mapped to roles in the same flow.

Can subcontractor crews get access per work order?

Yes. Access follows the assignments and end dates in your IAM system. When the order or contract ends, the corresponding access rights are withdrawn automatically and the change is logged.

Does this help with NIS2 and CER audits?

Yes. Key2XS produces a continuous, tamper-evident audit trail linking every physical access right to an identity and a policy decision, so audit questions about physical access are answered in minutes instead of days.

Do we have to replace our locks or keys?

No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are.

How long does implementation take?

A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team.

## See it on your network

A guided walkthrough of how identity, policy and physical keys come together across masts, cabinets and core sites.

[Book a 30-minute demo](https://key2xs.com/contact?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en)

### Contact us

[Wilhelmina van Pruisenweg 104, 2595 AN Den Haag](https://maps.google.com/?q=Wilhelmina+van+Pruisenweg+104+Den+Haag)

Kraanspoor 50, 1033 SE Amsterdam, The Netherlands 

[info@key2xs.com](mailto:info@key2xs.com) [+31(0)70 2045180](tel:+31(0)702045180)

### Platform

- [Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=en)
- [Product](https://key2xs.com/products?hsLang=en)
- [Integrations](https://key2xs.com/integrations?hsLang=en)
- [ROI calculator](https://key2xs.com/roi-calculator?hsLang=en)

### Compliance

- [CER Directive](https://key2xs.com/cer-directive?hsLang=en)
- [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=en)
- [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=en)

### Company

- [SailPoint partnership](https://key2xs.com/sailpoint-partnership?hsLang=en)
- [Resource center](https://key2xs.com/resources?hsLang=en)
- [Events](https://key2xs.com/events?hsLang=en)
- [News](https://key2xs.com/news-archive?hsLang=en)
- [Contact](https://key2xs.com/contact?hsLang=en)

[![Penetration tested and verified by Sekurno](https://key2xs.com/hubfs/img/badges/sekurno-pentest-badge-white.svg)](https://www.sekurno.com/verified/key2xs) [![KuppingerCole Analysts Rising Star 2026 badge for Key2XS](https://key2xs.com/hubfs/img/badges/kuppingercole-rising-star-2026-key2xs.svg)](https://key2xs.com/analyst-recognition?hsLang=en)

---

![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg)

Key2XS, pronounced “key to access”

© 2026 Key2XS B.V. All rights reserved

<https://www.linkedin.com/company/key2xs>

[Privacy](https://key2xs.com/privacy-statement?hsLang=en)  Cookie Preferences

Patent Pending Nr: 2040721 & 2041284

Key2XS & ActiveAuth are registered trademarks of Key2XS Assets B.V.

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Key2XS governs access rights centrally regardless of site type. Masts, street cabinets, exchanges and data centres are all mapped to roles in the same flow."
    },
    "name" : "Our sites range from street cabinets to data centres. Is that one solution?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Access follows the assignments and end dates in your IAM system. When the order or contract ends, the corresponding access rights are withdrawn automatically and the change is logged."
    },
    "name" : "Can subcontractor crews get access per work order?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Key2XS produces a continuous, tamper-evident audit trail linking every physical access right to an identity and a policy decision, so audit questions about physical access are answered in minutes instead of days."
    },
    "name" : "Does this help with NIS2 and CER audits?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are."
    },
    "name" : "Do we have to replace our locks or keys?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team."
    },
    "name" : "How long does implementation take?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://key2xs.com",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "name" : "Telecom Sector",
    "position" : 2
  } ]
}
```