<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=7847562&amp;fmt=gif">
Home > Sectors

Physical access governance for utilities

Utilities run the most dispersed physical estates of any sector: substations, pumping stations, treatment plants, distribution stations and street cabinets, spread across entire regions and mostly unmanned. Key2XS connects your identity and access management system to your iLOQ or ASSA ABLOY CLIQ keys, so access to every one of those sites is governed by identity, granted by policy, and provable to any regulator.

Request a demo

Thousands of doors, no one at any of them

The access problem in utilities is unlike any office environment. A single grid or water operator can be responsible for thousands of lockable objects. Nobody sits at those locations to check a badge. Access is a key, and the key is the entire security model.

Day-to-day reality makes that model fragile:

Every one of those keys opens infrastructure whose failure makes the news. That is precisely why regulators stopped treating physical access as a facilities detail.

CER and NIS2 put your keys in scope

Utilities sit squarely in the scope of both major EU resilience frameworks. The CER Directive requires critical entities, explicitly including energy and drinking water, to take measures that ensure the resilience of their physical infrastructure. NIS2 requires appropriate policies for access to premises, recognizing that physical entry can compromise the systems inside.

In an audit, that translates into questions your key cabinet cannot answer:

With Key2XS, those answers come from a system rather than a reconstruction. Every key right traces back to an identity, a role and an approval, in one tamper-evident audit trail.

How utilities use Key2XS

Key2XS is middleware between the IAM system you already run and the digital locking system already on your assets. Nothing about your locks, keys or locking plan changes.

A typical flow: a service engineer is assigned to the “Region North” maintenance team in your IAM. Key2XS translates that role into key rights for exactly the substations and pumping stations in that region. Six months later the engineer moves to Region South: the old rights are withdrawn and the new ones granted in near real-time, without a single ticket to the key administration. When the engineer eventually leaves the company, the leaver process that disables their accounts also closes every door they could open, in the same movement.

For contractors, the same principle applies with an end date. Access follows the contract in your IAM, so when the project ends, the physical access ends with it instead of surviving in someone's van.

Implementation does not become another infrastructure project: a standard integration is live in under two hours, through pre-built connectors, with no custom development.

Works with what you already run

The platform is engineered for 99.99% availability, and all communication is encrypted with TLS 1.3 in transit and AES-256 at rest, matching the expectations of critical infrastructure operations.

Frequently asked questions

Physical access governance for utilities, answered.

See it working on your infrastructure

Get a guided walkthrough of how identity, policy and physical keys come together across a dispersed estate.