Key2XS published an analysis on NIS2 and CER regarding identity governance and physical access for critical infrastructure assets.
Published
Signal category
Research & Knowledge
Quote
“Read our analysis”
— Key2XS team
Company
Key2XS
Key2XS enables organisations to fully automate and audit physical key management within their digital identity ecosystem
- Industry
- Security Systems Services
- Location
- The Hague, NL
- Company size
- 9 employees
Organisations have spent two decades building a control plane over digital access: lifecycle, policy, certification, audit. The assets that carry the service, substations, cabinets, pumping stations, technical rooms, sit outside it. Access there is granted locally, tracked in spreadsheets, never re-certified. Key2XS extends the identity control plane to physical access. Access is issued from the identity, granted through policy, reviewed alongside digital entitlements, and revoked when the identity or the contract ends. Across SailPoint, Microsoft Entra ID, Okta, One Identity and OpenText, and the key estates of ASSA ABLOY and iLOQ. One policy. One audit trail. Under NIS2 and CER, who can open the substation is a supervisory question, and the answer has to be evidence rather than intent. Even where there is no network, no reader and no badge. Offline cannot mean ungoverned. Built for government, utilities, water, transport and telecom.
Founded 2025