Energy Legislation and Access Control – Requirements for Critical Infrastructure
Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.

Energy legislation sets specific requirements for physical security of critical infrastructure in the energy sector. With the implementation of the CER Directive and NIS2 in 2025, these requirements are being further enhanced.
This guide explains the key requirements and how SnapKey helps you meet them.
Legal Framework
National Energy Laws
Energy supply legislation requires grid operators to ensure:
- Operational security in the supply network
- Protection of critical facilities
- Documentation and contingency planning
IT Security Regulations for Energy Sector
Requirements include:
- Access control to critical systems
- Logging of security events
- Regular risk evaluation
CER Directive (EU 2022/2557)
Being implemented as national law:
- Resilience of critical entities
- Physical security and access control
- Incident reporting
NIS2 Directive
Enhanced cybersecurity requirements that also include:
- Physical security as part of cybersecurity
- Access management and identity handling
- Audit and documentation
Concrete Access Control Requirements
1. Documented Access
Requirement: The company must be able to document who has had access to critical facilities.
Traditional problem: Physical keys provide no traceability.
SnapKey solution: Automatic access log with timestamp, person, and location.
2. Authorized Personnel
Requirement: Only authorized personnel may have access to critical facilities.
Traditional problem: Keys get copied and shared.
SnapKey solution: Personal digital keys that cannot be copied.
3. Time-limited Access
Requirement: Temporary access must be time-limitable and revocable.
Traditional problem: Physical keys cannot be time-limited.
SnapKey solution: Precise time windows with automatic expiration.
4. Role-based Access Management
Requirement: Access must be assigned based on role and necessity.
Traditional problem: Everyone with a key has the same access.
SnapKey solution: Define exactly which locations each role has access to.
5. Audit and Reporting
Requirement: The company must be able to present documentation during inspections.
Traditional problem: Manual documentation is time-consuming and unreliable.
SnapKey solution: Exportable reports ready with one click.
Regulatory Inspections
Energy regulators oversee the energy sector and can require:
- Presentation of access logs
- Documentation of security procedures
- Proof of risk evaluation
- Incident reports
How to Prepare with SnapKey
- Automatic access log – All access is documented continuously
- Export for inspection – Generate report in minutes
- Historical data – View access going back in time
- Anomaly reports – Identify unusual patterns
Compliance Overview
| Requirement | Legal Basis | SnapKey Supports |
|---|---|---|
| Access documentation | Energy laws, CER | ✅ Automatic |
| Authorization control | NIS2, Security regulations | ✅ Personal keys |
| Time-limited access | CER, NIS2 | ✅ Yes |
| Role separation | NIS2 | ✅ Role-based |
| Audit reports | All | ✅ One-click export |
| 2FA for critical zones | NIS2 recommendation | ✅ eID integration |
| Offline function | Practical requirement | ✅ iLOQ battery-free |
Implementation Timeline
2024
- NIS2 adopted in EU
- Preparation of national implementation
January 2025
- NIS2 comes into force
Mid-2025
- CER Directive implemented as national law
Ongoing
- Energy regulators conduct inspections
- Compliance documentation required
Practical Implementation with SnapKey
Step 1: Map Critical Facilities
Identify all locations requiring access control:
- Transformer stations
- Pump stations
- Control rooms
- Cable cabinets
- Technical rooms
Step 2: Define Roles
Determine who should have access to what:
- Own technicians
- Operations managers
- External contractors
- Regulatory inspectors
Step 3: Implement SnapKey
- Install iLOQ locks (or use existing)
- Set up access profiles
- Assign digital keys
Step 4: Run in Production
- All access is logged automatically
- Generate reports as needed
- Adjust permissions continuously
FAQ
When do we need to be compliant?
NIS2 comes into force in January 2025. CER Directive is being implemented as national law in mid-2025. It's recommended to start implementation now.
What happens if we don't meet requirements?
Regulators can issue orders and in serious cases fines. Lack of compliance can also lead to reputational damage and increased insurance premiums.
Does SnapKey cover all legal requirements?
SnapKey covers requirements for physical access control and documentation. For full compliance, SnapKey should be combined with other security measures such as cybersecurity and contingency plans.
Can we use SnapKey to document for regulators?
Yes. SnapKey generates exportable reports in standard formats (Excel, PDF) that can be presented during inspections.
Get Started with Compliance
Let us review your situation and show how SnapKey can help you meet energy legislation requirements.
Additional Resources
Related articles
Access Control for District Heating – Secure Access to Substations and Cabinets
Digital access control for district heating companies. Replace lockboxes with traceable access to heat substations, exchanger stations, and technical rooms.
Access Control for Electricity Grid and Substations – CER & NIS2 Ready
Secure access to transformer stations, grid components, and technical rooms. Meet CER and NIS2 with battery-free, offline access control from SnapKey.
NIS2 Directive – Access Control and Cybersecurity Requirements 2025
The NIS2 law introduces enhanced requirements for cybersecurity and access control for businesses in critical infrastructure. Learn about the new requirements and how to achieve compliance.