---
title: Physical Access Governance for Transport | Key2XS
description: Identity-driven key management for rail, public transport and road infrastructure. Govern trackside, depot and tunnel access, audit-ready for CER and NIS2.
image: https://key2xs.com/hubfs/img/og-image.png
---

[![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg) ![Key2XS](https://key2xs.com/hubfs/img/logo-blue-horizontal.svg)](https://key2xs.com/?hsLang=en)

 Why Governance?

[Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en) [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=en) [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=en) Analyst recognition [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=en)

 Industries

[Government](https://key2xs.com/sectors/government?hsLang=en) [Utilities](https://key2xs.com/sectors/utilities?hsLang=en) [Water management](https://key2xs.com/sectors/water-management?hsLang=en) [Transport](https://key2xs.com/sectors/transport?hsLang=en) [Telecom](https://key2xs.com/sectors/telecom?hsLang=en)

 Platform

[Product](https://key2xs.com/products?hsLang=en) [How it works](https://key2xs.com/?hsLang=en#how-it-works) [Integrations](https://key2xs.com/integrations?hsLang=en) [Book a demo](https://key2xs.com/contact?hsLang=en)

 Partners

Technology partners [SailPoint](https://key2xs.com/sailpoint-partnership?hsLang=en) [One Identity](https://key2xs.com/partners/one-identity?hsLang=en) [Microsoft Entra ID](https://key2xs.com/partners/entra-id?hsLang=en) [Okta](https://key2xs.com/partners/okta?hsLang=en) [OpenText](https://key2xs.com/partners/opentext?hsLang=en) [iLOQ](https://key2xs.com/partners/iloq?hsLang=en) [ASSA ABLOY](https://key2xs.com/partners/assa-abloy?hsLang=en) Resell & Implementation partners [Hanab](https://key2xs.com/partners/hanab?hsLang=en)

 Resources

[Resource center](https://key2xs.com/resources?hsLang=en) [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=en) [Events](https://key2xs.com/events?hsLang=en) Meet us at Navigate [Navigate Austin · Oct 5-8](https://key2xs.com/events/sailpoint-navigate-austin?hsLang=en) [Navigate London · Nov 2-4](https://key2xs.com/events/sailpoint-navigate-london?hsLang=en) [ROI calculator](https://key2xs.com/roi-calculator?hsLang=en) [FAQ](https://key2xs.com/?hsLang=en#faq)

[News](https://key2xs.com/news-archive?hsLang=en) 

[Book a demo](https://key2xs.com/contact?hsLang=en) 

[Book a demo](https://key2xs.com/contact?hsLang=en)

Industries · Transport

# Physical access governance for transport

Infrastructure managers and the operators on their networks, across rail, road, ports and airports. Key2XS connects the IAM you already run to the keys on both estates.

[Book a 30-minute demo](https://key2xs.com/contact?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en)

Key2XS console

RB

**R. de Boer**Fitter · Rail contractor

Corridor west

Access rights · project corridor-west

**Relay house KM 42.3**Granted

**Traction substation W12**Granted

**Tunnel service Zuid**Granted

**Depot Haarlem**Project end

**Key updated**3 access rights · via One Identity

23:58:41 **GRANT** relay-house-km42 ← corridor-west

**Hundreds of km**one governed line

**< 2 hrs**standard integration, live

**99.99%**around-the-clock operations

**NIS2 + CER**transport named explicitly

Who we serve

## Infrastructure and service providers

Across rail, road, ports and airports, transport splits in two: those who run the infrastructure and those who operate on it. Key2XS governs the keys on both sides.

Infrastructure

### Rail, road, port and airport infrastructure

The fixed estate: unmanned installations along networks, around harbours and across airfields.

Relay housesTraction substationsTunnel servicesControl cabinetsPerimeter gatesQuay and apron cabinets

Service providers

### Railway companies, public transport and terminal operators

The operational estate: depots, workshops and terminals, run around the clock by crews and contractors.

DepotsWorkshopsYardsStation technical roomsTerminalsFuel farms

Two estates, one governance model: access follows the identity on both.

The problem

## Where a key is a safety issue

Whoever can open a relay house or a tunnel service door is close to systems that keep vehicles moving and people safe. Four realities work against knowing who that is.

### Layered contracting

Main contractor, subcontractor, night crew. Key registration lags at every layer.

### Night windows

A crew needs one section for four hours; the key works for months.

### A linear estate

Assets stretch along hundreds of kilometres, so keys are broad by design.

### Incident questions

After a disruption, authorities want answers in hours, not after a week of reconstruction.

Every gap between who should have access and who can get in is a gap in *your safety case.*

How it works

## Access that follows the identity

Middleware between your IAM and the key systems on your infrastructure. Follow one corridor project through four events.

Event 1**Work package**Switch maintenance, corridor west

Event 2**Rescoped**Moved to depot overhaul

Event 3**Possession**Saturday, 01:00 to 05:00

Event 4**Project ends**Every layer, every door

Possession window active

Infrastructure · the line Service providers · depots and stations

*source: IAM*  
project: switch-maintenance / corridor-west  
*result:* 4 sites granted

The project registration becomes access rights for exactly the relay houses and technical buildings on the corridor, at every layer of subcontracting.

*source: IAM*  
project: overhaul / depot-haarlem  
*result:* 4 withdrawn, 4 granted

The next work package moves the crew to the depot; the rights move with them, in near real time.

the corridor keys stay in the van.

*source: IAM*  
window: possession / line-4  
*result:* line open, bounded

A night possession opens the line for four hours on top of the running package. Granted for the window, withdrawn when the line reopens.

*source: IAM*  
status: project closed  
*result:* every door closed, logged

When the project ends, every crew member's access ends with it, at every layer of subcontracting. The rights follow the registration, not the metal.

Audit trail

23:58:41GRANTrelay-house-km42project corridor-west

23:58:41GRANTtraction-sub-w12project corridor-west

23:58:42GRANTtunnel-service-zuidproject corridor-west

04:59:30REVOKEpossession, line 4window closed, auto

04:59:30LOGline reopenedrights withdrawn

18:00:07REVOKEall sites (16)project end, all layers

18:00:07LOGevidence sealedaudit chain

chain intact · tamper-evident

CER and NIS2

## A query, not a reconstruction

Transport is explicitly in scope of both directives: CER for the resilience of physical infrastructure, NIS2 for policies governing access to premises. The practical test is simple.

**Who held access to this relay house, on this date?**Any location, any date, on whose authority.

**Did the subcontractor crew lose access at project end?**At every layer, automatically, logged.

**What changed here in the last year?**One tamper-evident trail. Minutes, not days.

Mechanics

## Governance that survives being offline

A relay house along the track sees a key long before it sees a network. Rights travel with the key, and a withdrawal is enforced at the next key update.

### How rights travel

**Control plane**the decision

**The key**carries the rights

**The lock**no power, no network

The next time the key is used or updated it picks up its new rights. Revocation propagates the same way.

### What happens on withdrawal

**Right withdrawn**in the control plane

*revocation window*

**Enforced at the key**next update or check

Closed by the key system's own offline logic

Validity expiryBlacklist checkOnline update

Near real time, not instantaneous. Each key system closes the window with its own mechanism; Key2XS makes the decision centrally and logs the change.

Works with what you run

## Identity decides. Policy governs. Technology executes.

Middleware through standard interfaces. Locks, keys and the locking plan stay as they are.

Identity side

SailPointCertified partner Microsoft Entra ID Okta One Identity Manager OpenText Identity Manager

**Key2XS**

Identity decisions become access rights, with evidence.

Locking side

iLOQ ASSA ABLOY CLIQeCLIQ · PROTEC², certified ASSA ABLOY AccessASSA ACCESS · ASSA CUMULUS · ASSA PULSE ASSA ABLOY Traka

FAQ

## Transport, answered

We are a service provider, not the infrastructure manager. Is this for us?

Yes. Key2XS governs the keys you hold: depots, workshops, yards and station technical rooms, for your own staff and your contractors. Access follows your IAM either way.

Can access be limited to a project or work package?

Yes. Access rights follow the assignments in your IAM system. A project registration with an end date produces access that exists exactly as long as the work does, and every change is logged.

Much of our maintenance is done by subcontractors. Does that work?

Yes. Anyone registered in your IAM, including contractor and subcontractor staff, can be governed the same way. Access follows the registration, so it ends when the engagement ends, regardless of the layer of contracting.

Can we answer incident questions quickly?

Yes. The audit trail shows for any location who held access rights at any moment, on whose authority, and when rights changed. Questions that used to take days of reconstruction become queries.

Do we have to replace our locks or keys?

No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are.

How long does implementation take?

A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team.

## See it trackside

A guided walkthrough of how identity, policy and physical keys come together along the line and in the depots.

[Book a 30-minute demo](https://key2xs.com/contact?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en)

### Contact us

[Wilhelmina van Pruisenweg 104, 2595 AN Den Haag](https://maps.google.com/?q=Wilhelmina+van+Pruisenweg+104+Den+Haag)

Kraanspoor 50, 1033 SE Amsterdam, The Netherlands 

[info@key2xs.com](mailto:info@key2xs.com) [+31(0)70 2045180](tel:+31(0)702045180)

### Platform

- [Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=en)
- [Product](https://key2xs.com/products?hsLang=en)
- [Integrations](https://key2xs.com/integrations?hsLang=en)
- [ROI calculator](https://key2xs.com/roi-calculator?hsLang=en)

### Compliance

- [CER Directive](https://key2xs.com/cer-directive?hsLang=en)
- [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=en)
- [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=en)

### Company

- [SailPoint partnership](https://key2xs.com/sailpoint-partnership?hsLang=en)
- [Resource center](https://key2xs.com/resources?hsLang=en)
- [Events](https://key2xs.com/events?hsLang=en)
- [News](https://key2xs.com/news-archive?hsLang=en)
- [Contact](https://key2xs.com/contact?hsLang=en)

[![Penetration tested and verified by Sekurno](https://key2xs.com/hubfs/img/badges/sekurno-pentest-badge-white.svg)](https://www.sekurno.com/verified/key2xs) [![KuppingerCole Analysts Rising Star 2026 badge for Key2XS](https://key2xs.com/hubfs/img/badges/kuppingercole-rising-star-2026-key2xs.svg)](https://key2xs.com/analyst-recognition?hsLang=en)

---

![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg)

Key2XS, pronounced “key to access”

© 2026 Key2XS B.V. All rights reserved

<https://www.linkedin.com/company/key2xs>

[Privacy](https://key2xs.com/privacy-statement?hsLang=en)  Cookie Preferences

Patent Pending Nr: 2040721 & 2041284

Key2XS & ActiveAuth are registered trademarks of Key2XS Assets B.V.

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Key2XS governs the keys you hold: depots, workshops, yards and station technical rooms, for your own staff and your contractors. Access follows your IAM either way."
    },
    "name" : "We are a service provider, not the infrastructure manager. Is this for us?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Access rights follow the assignments in your IAM system. A project registration with an end date produces access that exists exactly as long as the work does, and every change is logged."
    },
    "name" : "Can access be limited to a project or work package?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Anyone registered in your IAM, including contractor and subcontractor staff, can be governed the same way. Access follows the registration, so it ends when the engagement ends, regardless of the layer of contracting."
    },
    "name" : "Much of our maintenance is done by subcontractors. Does that work?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. The audit trail shows for any location who held access rights at any moment, on whose authority, and when rights changed. Questions that used to take days of reconstruction become queries."
    },
    "name" : "Can we answer incident questions quickly?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are."
    },
    "name" : "Do we have to replace our locks or keys?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team."
    },
    "name" : "How long does implementation take?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://key2xs.com",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "name" : "Transport Sector",
    "position" : 2
  } ]
}
```