---
title: Physical Access Governance for Utilities | Key2XS
description: Identity-driven key management for grid operators, water and energy networks. Govern thousands of dispersed sites, audit-ready for CER and NIS2.
image: https://key2xs.com/hubfs/img/og-image.png
---

[![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg) ![Key2XS](https://key2xs.com/hubfs/img/logo-blue-horizontal.svg)](https://key2xs.com/?hsLang=en)

 Why Governance?

[Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en) [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=en) [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=en) Analyst recognition [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=en)

 Industries

[Government](https://key2xs.com/sectors/government?hsLang=en) [Utilities](https://key2xs.com/sectors/utilities?hsLang=en) [Water management](https://key2xs.com/sectors/water-management?hsLang=en) [Transport](https://key2xs.com/sectors/transport?hsLang=en) [Telecom](https://key2xs.com/sectors/telecom?hsLang=en)

 Platform

[Product](https://key2xs.com/products?hsLang=en) [How it works](https://key2xs.com/?hsLang=en#how-it-works) [Integrations](https://key2xs.com/integrations?hsLang=en) [Book a demo](https://key2xs.com/contact?hsLang=en)

 Partners

Technology partners [SailPoint](https://key2xs.com/sailpoint-partnership?hsLang=en) [One Identity](https://key2xs.com/partners/one-identity?hsLang=en) [Microsoft Entra ID](https://key2xs.com/partners/entra-id?hsLang=en) [Okta](https://key2xs.com/partners/okta?hsLang=en) [OpenText](https://key2xs.com/partners/opentext?hsLang=en) [iLOQ](https://key2xs.com/partners/iloq?hsLang=en) [ASSA ABLOY](https://key2xs.com/partners/assa-abloy?hsLang=en) Resell & Implementation partners [Hanab](https://key2xs.com/partners/hanab?hsLang=en)

 Resources

[Resource center](https://key2xs.com/resources?hsLang=en) [KuppingerCole Rising Star 2026](https://key2xs.com/analyst-recognition?hsLang=en) [Events](https://key2xs.com/events?hsLang=en) Meet us at Navigate [Navigate Austin · Oct 5-8](https://key2xs.com/events/sailpoint-navigate-austin?hsLang=en) [Navigate London · Nov 2-4](https://key2xs.com/events/sailpoint-navigate-london?hsLang=en) [ROI calculator](https://key2xs.com/roi-calculator?hsLang=en) [FAQ](https://key2xs.com/?hsLang=en#faq)

[News](https://key2xs.com/news-archive?hsLang=en) 

[Book a demo](https://key2xs.com/contact?hsLang=en) 

[Book a demo](https://key2xs.com/contact?hsLang=en)

Industries · Utilities

# Physical access governance for utilities

Thousands of unmanned sites. One governance model. Key2XS connects the IAM you already run to the keys already on your assets.

[Book a 30-minute demo](https://key2xs.com/contact?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en)

Key2XS console

MV

**M. Visser**Field engineer · Region North

Active

Access rights · role maintenance-north

**Substation Noord 12**Granted

**TS Veldweg 3**Granted

**PS Dijkring 7**Granted

**Cabinet A-114**Ends 31 Mar

**Key updated**4 access rights · via SailPoint

09:14:02 **GRANT** substation-noord-12 ← maintenance-north

**Thousands**of lockable objects, one estate

**< 2 hrs**standard integration, live

**99.99%**platform availability

**CER + NIS2**audit-ready evidence

The problem

## The key is the entire security model

Nobody checks a badge at a transformer station. Four everyday realities make that model fragile.

### Shifting patterns

Access needs change faster than key administration follows.

### Contractor churn

People change per project. Keys outlive the contract.

### On-call breadth

Standby keys open everything, and nobody dares narrow them.

### Revocation by mail

Accounts close centrally. Keys come back eventually, sometimes.

Every one of those keys opens infrastructure whose failure *makes the news.*

How it works

## Access that follows the identity

Middleware between your IAM and your locking system. Follow one field engineer through four events.

Event 1**Joiner**Assigned to Region North

Event 2**Mover**Reprovisioned to Region South

Event 3**On call**Standby rotation, this week

Event 4**Leaver**Leaves the company

On-call rotation active

Region North Region South

*source: IAM*  
assignment: maintenance / region-north  
*result:* 4 sites granted

A role in the IAM becomes access rights for exactly the Region North sites. No ticket, no key desk.

*source: IAM*  
assignment: maintenance / region-south  
*result:* 4 withdrawn, 4 granted

Old rights withdrawn, new ones granted, in one movement, near real time.

the Region North key stays in the van.

*source: IAM*  
role: standby / on-call  
*result:* estate-wide, bounded

Broad access, made explicit: granted by the on-call role, ended with the rotation.

*source: IAM*  
status: deactivated  
*result:* every door closed, logged

Disabling the accounts closes every door, in the same movement. Logged.

Audit trail

09:14:02GRANTsubstation-noord-12role maintenance-north

09:14:02GRANTts-veldweg-3role maintenance-north

09:14:03GRANTps-dijkring-7role maintenance-north

11:40:57REVOKEcabinet-a114contract ended, auto

11:40:58LOGblacklist scheduledestate policy

17:03:11REVOKEall sites (24)leaver, HR event

17:03:11LOGevidence sealedaudit chain

chain intact · tamper-evident

CER and NIS2

## Answers from a system, not a reconstruction

CER names energy and drinking water as critical sectors. NIS2 covers access to premises. Auditors ask three questions.

**Who can enter this substation, right now?**Live, per identity, role and approval.

**How fast is access withdrawn for a leaver?**In the same movement as the accounts.

**Show a year of changes for this site.**One tamper-evident trail. Minutes, not days.

Mechanics

## Governance that survives being offline

A substation sees a key long before it sees a network. Rights travel with the key, and a withdrawal is enforced at the next key update.

### How rights travel

**Control plane**the decision

**The key**carries the rights

**The lock**no power, no network

The next time the key is used or updated it picks up its new rights. Revocation propagates the same way.

### What happens on withdrawal

**Right withdrawn**in the control plane

*revocation window*

**Enforced at the key**next update or check

Closed by the key system's own offline logic

Validity expiryBlacklist checkOnline update

Near real time, not instantaneous. Each key system closes the window with its own mechanism; Key2XS makes the decision centrally and logs the change.

Works with what you run

## Identity decides. Policy governs. Technology executes.

Middleware through standard interfaces. Locks, keys and the locking plan stay as they are.

Identity side

SailPointCertified partner Microsoft Entra ID Okta One Identity Manager OpenText Identity Manager

**Key2XS**

Identity decisions become access rights, with evidence.

Locking side

iLOQ ASSA ABLOY CLIQeCLIQ · PROTEC², certified ASSA ABLOY AccessASSA ACCESS · ASSA CUMULUS · ASSA PULSE ASSA ABLOY Traka

FAQ

## Utilities, answered

Our assets are spread across the whole region. Does that matter?

No. Key2XS governs access rights centrally, regardless of how dispersed the locks are. Digital key systems like iLOQ, CLIQ and Traka are designed for exactly such estates, and Key2XS adds the identity layer on top.

Can we give contractors time-limited access?

Yes. Access follows the assignments and end dates in your IAM system. When the contract or project assignment ends, the corresponding access rights are withdrawn automatically and the change is logged.

Does this help with CER and NIS2 audits?

Yes. Key2XS produces a continuous, tamper-evident audit trail linking every physical access right to an identity and a policy decision, so audit questions about physical access are answered in minutes instead of days.

Do we have to replace our locks or keys?

No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are.

How long does implementation take?

A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team.

## See it on your infrastructure

A guided walkthrough of how identity, policy and physical keys come together across a dispersed estate.

[Book a 30-minute demo](https://key2xs.com/contact?hsLang=en) [CER Directive](https://key2xs.com/cer-directive?hsLang=en)

### Contact us

[Wilhelmina van Pruisenweg 104, 2595 AN Den Haag](https://maps.google.com/?q=Wilhelmina+van+Pruisenweg+104+Den+Haag)

Kraanspoor 50, 1033 SE Amsterdam, The Netherlands 

[info@key2xs.com](mailto:info@key2xs.com) [+31(0)70 2045180](tel:+31(0)702045180)

### Platform

- [Why Physical Access Governance?](https://key2xs.com/physical-access-governance?hsLang=en)
- [Product](https://key2xs.com/products?hsLang=en)
- [Integrations](https://key2xs.com/integrations?hsLang=en)
- [ROI calculator](https://key2xs.com/roi-calculator?hsLang=en)

### Compliance

- [CER Directive](https://key2xs.com/cer-directive?hsLang=en)
- [NIS2 Directive](https://key2xs.com/nis2-directive?hsLang=en)
- [EU Enforcement Tracker](https://key2xs.com/cer-tracker?hsLang=en)

### Company

- [SailPoint partnership](https://key2xs.com/sailpoint-partnership?hsLang=en)
- [Resource center](https://key2xs.com/resources?hsLang=en)
- [Events](https://key2xs.com/events?hsLang=en)
- [News](https://key2xs.com/news-archive?hsLang=en)
- [Contact](https://key2xs.com/contact?hsLang=en)

[![Penetration tested and verified by Sekurno](https://key2xs.com/hubfs/img/badges/sekurno-pentest-badge-white.svg)](https://www.sekurno.com/verified/key2xs) [![KuppingerCole Analysts Rising Star 2026 badge for Key2XS](https://key2xs.com/hubfs/img/badges/kuppingercole-rising-star-2026-key2xs.svg)](https://key2xs.com/analyst-recognition?hsLang=en)

---

![Key2XS](https://key2xs.com/hubfs/img/logo-white-horizontal.svg)

Key2XS, pronounced “key to access”

© 2026 Key2XS B.V. All rights reserved

<https://www.linkedin.com/company/key2xs>

[Privacy](https://key2xs.com/privacy-statement?hsLang=en)  Cookie Preferences

Patent Pending Nr: 2040721 & 2041284

Key2XS & ActiveAuth are registered trademarks of Key2XS Assets B.V.

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. Key2XS governs access rights centrally, regardless of how dispersed the locks are. Digital key systems like iLOQ, CLIQ and Traka are designed for exactly such estates, and Key2XS adds the identity layer on top."
    },
    "name" : "Our assets are spread across the whole region. Does that matter?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Access follows the assignments and end dates in your IAM system. When the contract or project assignment ends, the corresponding access rights are withdrawn automatically and the change is logged."
    },
    "name" : "Can we give contractors time-limited access?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Key2XS produces a continuous, tamper-evident audit trail linking every physical access right to an identity and a policy decision, so audit questions about physical access are answered in minutes instead of days."
    },
    "name" : "Does this help with CER and NIS2 audits?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are."
    },
    "name" : "Do we have to replace our locks or keys?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team."
    },
    "name" : "How long does implementation take?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://key2xs.com",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "name" : "Utilities Sector",
    "position" : 2
  } ]
}
```