- Long-range readers with a reading range of up to 7 m for vehicles and windshield transponders
- License plate recognition as an alternative to UHF identification
- Authorized license plates managed centrally, with every entry and exit logged

Access Control and Electronic Key Cabinets for Critical Infrastructure
Control and document physical access electronically – providing a foundation for KRITIS compliance. Developed in line with the Cyber Resilience Act to help operators meet their NIS2 obligations more effectively.
How We Secure Your Access Points
We do not view physical security as a single door or an individual key cabinet, but as an end-to-end access concept – from the site entrance to the key inside the cabinet. We combine vehicle access control, electronic access solutions, server rack security, and key and equipment management into one system in which permissions can be managed centrally and access events can be documented transparently.
deister solutions include RFID-based access control, electronic locking components, and key cabinets with centralized permission management and event logging.
The right solution depends on your existing infrastructure. Together with you, our team reviews your site, entrances, sensitive areas, server racks, as well as key and equipment processes. This helps identify where access is already sufficiently secured – and where security, traceability, or administrative efficiency could still be improved.
Five Zones, One Consistent Access Concept
Every zone has different requirements – and not every area needs the same technology. Select a zone to see what is possible.

Example: A Service Visit, Logged from Start to Finish
Arrival, access, maintenance, departure


KRITIS Compliance Through Electronically Controlled Access
The German KRITIS-Dachgesetz requires operators of critical infrastructure to implement appropriate physical protection measures. Section 13 explicitly includes measures such as site protection, monitoring, detection, and access controls; operators must also document their resilience measures in a resilience plan.
Mechanical locks alone do not provide electronic event data. With our systems, access to buildings, areas, and cabinets can be controlled electronically and logged. This creates a technical basis for demonstrating and documenting physical access measures as part of your overall compliance approach.

Developed in Line with the CRA – Supporting Your NIS2 Compliance
We develop our products in line with the Cyber Resilience Act, including defined vulnerability management processes and long-term update support.
For operators subject to NIS2, supplier and supply-chain security are part of the wider risk-management framework. The German BSIG also addresses access control, the management of ICT systems, products and processes, and multi-factor or continuous authentication as relevant security measures.
With deister systems, you choose a manufacturer that takes these product-security requirements into account throughout the product lifecycle.

Critical Infrastructure Looks Different Everywhere
KRITIS and NIS2 apply across a wide range of sectors – from energy and water to healthcare, transport, data centers, public administration, and industry.
deister systems are used in environments including municipal utilities, water facilities, hospitals, data centers and colocation facilities, transport operators, public authorities, and industrial companies.
That is why a sensible access concept does not start with a product. It starts with one question: Who needs access to which areas, keys, and equipment – and when?
Together with you, we review this structure and identify where existing solutions can be meaningfully complemented.
FAQ
Does electronic access control make me NIS2-compliant?
No. NIS2 compliance always applies to the operator as a whole and includes areas such as risk management, incident reporting, registration requirements, and governance. Access control addresses one clearly defined part of this framework: physical protection measures and their documentation.
This is exactly where deister can support you. Electronic access control, centrally managed permissions, and traceable access logs help secure and document physical access systematically. Commander Connect can be used to centrally manage and evaluate doors, keys, and other deister systems.
Which NIS2 requirements specifically address physical security?
Under the German BSIG, relevant measures include concepts and processes for access control and the management of ICT systems, products, and processes, as well as the use of multi-factor or continuous authentication solutions.
In practice, this can mean assigning access rights according to person, area, and time period, providing additional protection for particularly sensitive areas, and documenting access events transparently. deister combines electronic readers, locking systems, and centralized permission management into an end-to-end access concept.
Is securing the server room enough — or do we need access control at the rack?
That depends on who is allowed to enter the server room. If cleaning staff, facility management teams, external contractors, or multiple user groups have access, the server room door alone may no longer provide a sufficient security boundary.
With the deister SRL 1, access to individual server racks can also be electronically controlled and logged.
What does the Cyber Resilience Act have to do with our procurement?
The Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements. The CRA becomes fully applicable on 11 December 2027, while reporting obligations for actively exploited vulnerabilities and severe security incidents apply from 11 September 2026. Manufacturers are required, among other things, to address vulnerabilities during the support period and consider cybersecurity throughout the product lifecycle.
For operators, this means it is worth looking closely at the manufacturer when making purchasing decisions: How are vulnerabilities handled? How are security updates provided? And how long is the product supported? deister develops its connected systems with these requirements and long-term updateability in mind.
Important: CRA reporting obligations may also apply to certain products that were placed on the EU market before 11 December 2027. Other CRA obligations for previously marketed products generally depend on the applicable transitional provisions and whether the product is substantially modified.
Do we have to replace our existing locking system?
In many cases, a complete replacement is not necessary.
deister solutions can be integrated into existing infrastructure step by step. Electronic cylinders, door handles, and readers can be deployed specifically where the risk assessment identifies a higher need for protection. Existing areas can therefore be modernized gradually instead of replacing the entire system at once.
How does this work with data protection?
Access and key-issue data may constitute personal data. Purpose limitation, retention periods, the level of reporting detail and, where applicable, involvement of the works council should therefore be clarified before the system is introduced.
Commander Connect supports the technical administration and evaluation of this information: permissions, access events, keys, and other resources can be managed centrally, while reports can be configured individually and provided automatically.
However, deciding which data may be stored, evaluated, and retained – and for how long – remains an organizational and legal responsibility of the operator.
How Do We Determine Which Access Points Are Actually Critical?
Not every door and not every area requires the same technology. That is why deister reviews your existing infrastructure together with you – from the perimeter and buildings to sensitive interior areas, server racks, keys, and equipment.
This makes it possible to identify where adequate measures are already in place and where access control, traceability, or permission management could still be improved.











