What you need to know
Door behavior during loss of server, network, controller communication, reader, lock power, or fire-interface state must be designed—not discovered. Test each distinct door safely against approved life-safety and security requirements.
Potentially affected
Access-controlled doors and gates, locks and strikes, readers, request-to-exit devices, door contacts, local controllers, power supplies and batteries, networks, host servers, fire-alarm interfaces, elevators, turnstiles, alarms, and operator procedures.
DSE recommendation
Create a door-by-door failure-state matrix from approved design documents, coordinate qualified stakeholders, test one controlled condition at a time without defeating life safety, verify local decisions and alarms, restore every bypass, and retain witnessed results.
Source facts: facility access control is a risk-based process, not one device
CISA’s Facility Access Control: An Interagency Security Committee Best Practice describes access control across the employee and visitor process, screening, authentication, and entry into nonpublic space. It presents physical access control systems as collections of technology that enforce local access policy and emphasizes risk-based decisions, operating procedures, ownership, and coordination.
NIST SP 800-53 Revision 5.1 includes controls for physical access authorization, enforcement, monitoring, emergency shutoff, emergency power, fire protection, and alternate controls. It is a federal security-control catalog. It does not dictate the correct lock behavior for a particular commercial door.
Actual behavior is governed by the approved door and life-safety design, adopted building and fire codes, accessibility requirements, authority having jurisdiction, manufacturer instructions, lease, insurer, and organizational risk decision. Terms such as “fail safe” and “fail secure” describe lock behavior when power is removed; they do not by themselves prove compliant egress, security, or complete system behavior. Only qualified personnel should alter or test life-safety interfaces.
DSE recommendation: maintain and exercise a door-state matrix
Create one record for every controlled opening, including each leaf where behavior differs. Record door and hardware type, lock function, normal power source, backup power, controller, network path, reader, request-to-exit, contact, emergency-release devices, fire-alarm relationship, mechanical override, monitored alarms, occupancy or special use, and the approved behavior for each credible failure.
- Validate the authority. Assemble approved drawings, hardware schedules, sequence of operation, code review, commissioning records, and manufacturer documentation. Resolve contradictions with the designer, fire-alarm provider, locksmith, security integrator, facility owner, and authority having jurisdiction as appropriate.
- Define distinct states. Address loss of host service, management network, controller-to-server communication, controller-to-reader communication, controller power, lock power, reader failure, request-to-exit failure, door-contact failure, battery depletion, fire input, emergency release, and return from each state. Do not assume one power cut represents them all.
- Plan a safe test. Obtain authorization, notify monitoring and affected occupants, provide guard or alternate control, preserve emergency egress, and establish stop and restoration criteria. Never disconnect a fire circuit, defeat required release, or create an occupied-space hazard merely to complete a checklist.
- Observe locally and centrally. At the door, test authorized entry, denied entry, free egress, relocking, mechanical operation, and door position. At the workstation, verify event text, timestamps, alarms, acknowledgments, maps, notifications, and whether a local offline decision later uploads correctly.
- Challenge cached behavior. Confirm which credentials and schedules the controller retains, how revocations reach it, what happens to newly enrolled credentials, and how long local operation can continue. Test only with designated credentials and avoid exposing production secrets in the report.
- Restore and prove normal. Reconnect one condition at a time, confirm batteries and supplies are healthy, restore alarms and bypasses, synchronize the controller, check queued events, test ordinary access and egress, and obtain witness signoff.
Record actual results beside the approved expectation. A mismatch is not automatically a software defect; it may reveal wiring, hardware, programming, documentation, or design disagreement. Treat any life-safety discrepancy as urgent and keep compensating measures until qualified resolution.
Retest after hardware, firmware, power, fire-alarm, network, schedule, or occupancy changes and on a risk-based cadence. The evidence should identify the exact opening and conditions tested. It should not claim that a sample door proves every door, or that one successful power-loss test covers every degraded state.
Stop the test on any unexpected egress restriction, uncontrolled unlock, smoke-control or fire-interface anomaly, damaged hardware, unstable power supply, or loss of the agreed alternate control. Keep the opening in the safest approved condition, notify the responsible authority, and do not resume until the discrepancy has an owner, compensating measure, and qualified retest plan.
Official references
- Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice.
- National Institute of Standards and Technology, SP 800-53 Revision 5.1, Physical and Environmental Protection control family.
Review the official source
CISA: Facility Access Control—An Interagency Security Committee Best Practice · Verified August 17, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE