Access Control and Electronic Key Cabinets for Critical Infrastructure

Control and document physical access electronically – providing a foundation for KRITIS compliance. Developed in line with the Cyber Resilience Act to help operators meet their NIS2 obligations more effectively.

Request a non-binding quote

How We Secure Your Access Points

We do not view physical security as a single door or an individual key cabinet, but as an end-to-end access concept – from the site entrance to the key inside the cabinet. We combine vehicle access control, electronic access solutions, server rack security, and key and equipment management into one system in which permissions can be managed centrally and access events can be documented transparently.

deister solutions include RFID-based access control, electronic locking components, and key cabinets with centralized permission management and event logging.

The right solution depends on your existing infrastructure. Together with you, our team reviews your site, entrances, sensitive areas, server racks, as well as key and equipment processes. This helps identify where access is already sufficiently secured – and where security, traceability, or administrative efficiency could still be improved.

Five Zones, One Consistent Access Concept

Every zone has different requirements – and not every area needs the same technology. Select a zone to see what is possible.

Umspannwerk zone zahlen grün

Zone 1 – Perimeter and Vehicle Access

Umspannwerk zone 1
  • Long-range readers with a reading range of up to 7 m for vehicles and windshield transponders
  • License plate recognition as an alternative to UHF identification
  • Authorized license plates managed centrally, with every entry and exit logged

Zone 2 – Building Perimeter

Umspannwerk zone 2
  • Electronic access readers for high-traffic entrances
  • Secure RFID and mobile Credentials
  • Time-limited access using cipherQR
  • Every access event is recorded electronically

Zone 3 – Interior and Security-Sensitive Areas

Umspannwerk zone 3
  • Electronic door handles and cylinders
  • Wireless access solutions for existing doors
  • Different security levels for individual areas
  • Central management of access rights

Zone 4 – Server Room and Rack

Umspannwerk zone 4
  • Access control for server and technical rooms
  • Electronically secured server racks
  • Traceable access logs

Zone 5 – Keys and Equipment

Umspannwerk zone 5
  • Electronic key and equipment management
  • Automatic documentation of issue and return
  • Access restricted to authorized users
  • Central overview of availability and usage

Example: A Service Visit, Logged from Start to Finish

Arrival, access, maintenance, departure

Subdienstleister übersicht

Receive a QR Code

Subdienstleister ankunft QR

The contractor receives a personal, time-limited cipherQR code by email before the visit.

Secure Access to the Site

Zugang subdienstleister

At the perimeter, the QR code is verified. Access is granted only if the stored authorization is valid.

Collect Keys or Equipment

Subdienstleister entnahme schlüssel

Required keys or equipment are released electronically, and the issue is documented automatically.

Complete the Job

Subdienstleister repariert

The contractor can work only within the areas and permissions assigned for the task.

Leave in a Controlled Manner

Subdienstleister rückgabe schlüssel

Relevant access events are logged again when leaving. Keys and equipment are returned in a traceable manner.

Access Expires Automatically

Subdienstleister abreise QR

Once the defined time period expires, the QR code automatically becomes invalid.

Anwendung Karte vor Zutrittskontrollsytem

KRITIS Compliance Through Electronically Controlled Access

The German KRITIS-Dachgesetz requires operators of critical infrastructure to implement appropriate physical protection measures. Section 13 explicitly includes measures such as site protection, monitoring, detection, and access controls; operators must also document their resilience measures in a resilience plan.

Mechanical locks alone do not provide electronic event data. With our systems, access to buildings, areas, and cabinets can be controlled electronically and logged. This creates a technical basis for demonstrating and documenting physical access measures as part of your overall compliance approach.

CRA konform

Developed in Line with the CRA – Supporting Your NIS2 Compliance

We develop our products in line with the Cyber Resilience Act, including defined vulnerability management processes and long-term update support.

For operators subject to NIS2, supplier and supply-chain security are part of the wider risk-management framework. The German BSIG also addresses access control, the management of ICT systems, products and processes, and multi-factor or continuous authentication as relevant security measures.

With deister systems, you choose a manufacturer that takes these product-security requirements into account throughout the product lifecycle.

Welche branchen

Critical Infrastructure Looks Different Everywhere

KRITIS and NIS2 apply across a wide range of sectors – from energy and water to healthcare, transport, data centers, public administration, and industry.

deister systems are used in environments including municipal utilities, water facilities, hospitals, data centers and colocation facilities, transport operators, public authorities, and industrial companies.

That is why a sensible access concept does not start with a product. It starts with one question: Who needs access to which areas, keys, and equipment – and when?

Together with you, we review this structure and identify where existing solutions can be meaningfully complemented.

FAQ

Does electronic access control make me NIS2-compliant?

No. NIS2 compliance always applies to the operator as a whole and includes areas such as risk management, incident reporting, registration requirements, and governance. Access control addresses one clearly defined part of this framework: physical protection measures and their documentation.

This is exactly where deister can support you. Electronic access control, centrally managed permissions, and traceable access logs help secure and document physical access systematically. Commander Connect can be used to centrally manage and evaluate doors, keys, and other deister systems.

Which NIS2 requirements specifically address physical security?

Under the German BSIG, relevant measures include concepts and processes for access control and the management of ICT systems, products, and processes, as well as the use of multi-factor or continuous authentication solutions.

In practice, this can mean assigning access rights according to person, area, and time period, providing additional protection for particularly sensitive areas, and documenting access events transparently. deister combines electronic readers, locking systems, and centralized permission management into an end-to-end access concept.

Is securing the server room enough — or do we need access control at the rack?

That depends on who is allowed to enter the server room. If cleaning staff, facility management teams, external contractors, or multiple user groups have access, the server room door alone may no longer provide a sufficient security boundary.

With the deister SRL 1, access to individual server racks can also be electronically controlled and logged.

What does the Cyber Resilience Act have to do with our procurement?

The Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements. The CRA becomes fully applicable on 11 December 2027, while reporting obligations for actively exploited vulnerabilities and severe security incidents apply from 11 September 2026. Manufacturers are required, among other things, to address vulnerabilities during the support period and consider cybersecurity throughout the product lifecycle.

For operators, this means it is worth looking closely at the manufacturer when making purchasing decisions: How are vulnerabilities handled? How are security updates provided? And how long is the product supported? deister develops its connected systems with these requirements and long-term updateability in mind.

Important: CRA reporting obligations may also apply to certain products that were placed on the EU market before 11 December 2027. Other CRA obligations for previously marketed products generally depend on the applicable transitional provisions and whether the product is substantially modified.

Do we have to replace our existing locking system?

In many cases, a complete replacement is not necessary.

deister solutions can be integrated into existing infrastructure step by step. Electronic cylinders, door handles, and readers can be deployed specifically where the risk assessment identifies a higher need for protection. Existing areas can therefore be modernized gradually instead of replacing the entire system at once.

How does this work with data protection?

Access and key-issue data may constitute personal data. Purpose limitation, retention periods, the level of reporting detail and, where applicable, involvement of the works council should therefore be clarified before the system is introduced.

Commander Connect supports the technical administration and evaluation of this information: permissions, access events, keys, and other resources can be managed centrally, while reports can be configured individually and provided automatically.

However, deciding which data may be stored, evaluated, and retained – and for how long – remains an organizational and legal responsibility of the operator.

How Do We Determine Which Access Points Are Actually Critical?

Not every door and not every area requires the same technology. That is why deister reviews your existing infrastructure together with you – from the perimeter and buildings to sensitive interior areas, server racks, keys, and equipment.

This makes it possible to identify where adequate measures are already in place and where access control, traceability, or permission management could still be improved.


Kontakt aufnehmen

Request Your KRITIS / NIS2 Review

Where are there still gaps in your access logging? Where have you not yet found the right technical solution? And where could existing processes be improved?

We will be happy to review this with you – free of charge, with no sales obligation, remotely or on site.

Request a no-obligation consultation

oben