This is an info Alert.
SnapKey Logo
  • Solutions
      • Solutions
      • SnapKey Residential
      • SnapKey Utility
      • SnapKey Public
      • SnapKey Logistics
      • SnapKey Sensors
      • Guest Check-in
      • Reactivatable Keys
      • Self-service Rentals
  • Industries
      • Industries
      • Utility companies
      • Residential buildings
      • Office buildings & Coworking spaces
      • Logistics
      • Holiday homes
      • Public restrooms
      • Construction sites
      • Unmanned stores
      • Temporary lockers
      • Virtual Keybox
  • Resources
      • Resources
      • Knowledge
      • Videos
      • API documentation
      • Trust & Security
      • System status
  • Partners
  • Company
      • Company
      • About us
      • Why SnapKey
      • Contact
auth.sign_inBook a demo

Energy Legislation and Access Control – Requirements for Critical Infrastructure

Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.
4. December 2025
5 min
Energy Legislation and Access Control – Requirements for Critical Infrastructure

Energy legislation sets specific requirements for physical security of critical infrastructure in the energy sector. With the implementation of the CER Directive and NIS2 in 2025, these requirements are being further enhanced.

This guide explains the key requirements and how SnapKey helps you meet them.


Legal Framework

National Energy Laws

Energy supply legislation requires grid operators to ensure:

  • Operational security in the supply network
  • Protection of critical facilities
  • Documentation and contingency planning

IT Security Regulations for Energy Sector

Requirements include:

  • Access control to critical systems
  • Logging of security events
  • Regular risk evaluation

CER Directive (EU 2022/2557)

Being implemented as national law:

  • Resilience of critical entities
  • Physical security and access control
  • Incident reporting

NIS2 Directive

Enhanced cybersecurity requirements that also include:

  • Physical security as part of cybersecurity
  • Access management and identity handling
  • Audit and documentation

Concrete Access Control Requirements

1. Documented Access

Requirement: The company must be able to document who has had access to critical facilities.

Traditional problem: Physical keys provide no traceability.

SnapKey solution: Automatic access log with timestamp, person, and location.


2. Authorized Personnel

Requirement: Only authorized personnel may have access to critical facilities.

Traditional problem: Keys get copied and shared.

SnapKey solution: Personal digital keys that cannot be copied.


3. Time-limited Access

Requirement: Temporary access must be time-limitable and revocable.

Traditional problem: Physical keys cannot be time-limited.

SnapKey solution: Precise time windows with automatic expiration.


4. Role-based Access Management

Requirement: Access must be assigned based on role and necessity.

Traditional problem: Everyone with a key has the same access.

SnapKey solution: Define exactly which locations each role has access to.


5. Audit and Reporting

Requirement: The company must be able to present documentation during inspections.

Traditional problem: Manual documentation is time-consuming and unreliable.

SnapKey solution: Exportable reports ready with one click.


Regulatory Inspections

Energy regulators oversee the energy sector and can require:

  • Presentation of access logs
  • Documentation of security procedures
  • Proof of risk evaluation
  • Incident reports

How to Prepare with SnapKey

  1. Automatic access log – All access is documented continuously
  2. Export for inspection – Generate report in minutes
  3. Historical data – View access going back in time
  4. Anomaly reports – Identify unusual patterns

Compliance Overview

Requirement Legal Basis SnapKey Supports
Access documentation Energy laws, CER ✅ Automatic
Authorization control NIS2, Security regulations ✅ Personal keys
Time-limited access CER, NIS2 ✅ Yes
Role separation NIS2 ✅ Role-based
Audit reports All ✅ One-click export
2FA for critical zones NIS2 recommendation ✅ eID integration
Offline function Practical requirement ✅ iLOQ battery-free

Implementation Timeline

2024

  • NIS2 adopted in EU
  • Preparation of national implementation

January 2025

  • NIS2 comes into force

Mid-2025

  • CER Directive implemented as national law

Ongoing

  • Energy regulators conduct inspections
  • Compliance documentation required

Practical Implementation with SnapKey

Step 1: Map Critical Facilities

Identify all locations requiring access control:

  • Transformer stations
  • Pump stations
  • Control rooms
  • Cable cabinets
  • Technical rooms

Step 2: Define Roles

Determine who should have access to what:

  • Own technicians
  • Operations managers
  • External contractors
  • Regulatory inspectors

Step 3: Implement SnapKey

  • Install iLOQ locks (or use existing)
  • Set up access profiles
  • Assign digital keys

Step 4: Run in Production

  • All access is logged automatically
  • Generate reports as needed
  • Adjust permissions continuously

FAQ

When do we need to be compliant?

NIS2 comes into force in January 2025. CER Directive is being implemented as national law in mid-2025. It's recommended to start implementation now.

What happens if we don't meet requirements?

Regulators can issue orders and in serious cases fines. Lack of compliance can also lead to reputational damage and increased insurance premiums.

Does SnapKey cover all legal requirements?

SnapKey covers requirements for physical access control and documentation. For full compliance, SnapKey should be combined with other security measures such as cybersecurity and contingency plans.

Can we use SnapKey to document for regulators?

Yes. SnapKey generates exportable reports in standard formats (Excel, PDF) that can be presented during inspections.


Get Started with Compliance

Let us review your situation and show how SnapKey can help you meet energy legislation requirements.

Book a Compliance Meeting

Additional Resources

  • CER Directive – Complete Guide
  • NIS2 Directive and Access Control
  • Access Control for Utilities
Related articles
Access Control for District Heating – Secure Access to Substations and Cabinets

Digital access control for district heating companies. Replace lockboxes with traceable access to heat substations, exchanger stations, and technical rooms.

Access Control for Electricity Grid and Substations – CER & NIS2 Ready

Secure access to transformer stations, grid components, and technical rooms. Meet CER and NIS2 with battery-free, offline access control from SnapKey.

NIS2 Directive – Access Control and Cybersecurity Requirements 2025

The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.


SnapKey Logo

SnapKey is your digital key for all types of locks. Easily open doors and locks directly from your smartphone, and enjoy fast, secure and flexible access without physical keys or extra apps. Perfect for private homes, businesses and shared spaces.

Solutions
SnapKey ResidentialSnapKey UtilitySnapKey PublicSnapKey LogisticsGuest Check-in
Developers
API documentationAPI referenceWebhooksChangelogSystem status
Company
About usWhy SnapKeyBecome a partnerKnowledgeVideosContact us
Legal
Terms & ConditionsPrivacy PolicyTrust & Security
Contact
SnapKey ApS+45 3242 9050info@snapkey.dk

© All rights reserved.