Physical Keys in a Credential Era: Where Metal Still Wins

A pin tumbler cylinder installed in 1975 will still open in 2035 if someone oils it occasionally. That sentence contains the entire argument for mechanical keys, and it is a stronger argument than the credential industry likes to admit. The interesting question is not whether metal keys are obsolete. It is which specific openings still belong to them.

The Dependency List Is Empty

Count what an electronic opening depends on before it will let you in. Power, either mains or a battery with a finite service life. Firmware that was written by someone who has since moved on. Often a network link to a panel. Increasingly a cloud service, which means a vendor’s continued existence, a valid subscription, a working internet connection, and a certificate that has not expired. A mobile credential adds a phone with charge and a working app.

A mechanical cylinder depends on the key and on the cylinder not being packed with grit. That is the whole list. This is not nostalgia; it is a materially shorter chain of things that can go wrong at the moment you need the door open.

Comparing Failure Modes Honestly

Systems should be judged by how they behave when they break, not when they work.

  • Mechanical: wear is gradual and gives warning. A key that sticks this month is telling you about next month. Total failure is rare, local to one cylinder, and repairable by any locksmith.
  • Standalone electronic: the common failure is a dead battery, which is predictable and cheap, provided somebody actually replaces batteries on a schedule and there is a documented override path.
  • Networked electronic: a panel, switch, or power failure can affect many doors at once. Correlated failure is the defining risk, and the fail-safe versus fail-secure choice determines whether you are locked out or locked open. That choice belongs to a fire and life safety conversation with your local authority having jurisdiction, not to a preference.
  • Cloud dependent: adds outages, account lockouts, subscription lapse, and eventual product discontinuation to the list, at which point the hardware may become unmanageable even though it is physically fine.

Resilience Is a Design Property

Continuity planning has a useful discipline here that transfers directly. CISA’s resilience planning guidance promotes building resilience into infrastructure across all phases of planning, design, construction, and maintenance rather than treating it as something added afterward, and it emphasizes understanding dependencies before committing to a design. Applied to building access, that means asking two questions during procurement rather than during an outage: what does this opening depend on, and what is the documented path in when that dependency is unavailable?

If the answer to the second question is a mechanical override cylinder, then you have not eliminated mechanical keys. You have reduced them to an emergency path that nobody maintains, which is worse than owning them deliberately.

Twenty Year Cost, Including Obsolescence

Purchase price flatters electronics. Over two decades, model the recurring items: batteries across every opening, software subscriptions, credential issuance and replacement, firmware maintenance, integrator service calls, and at least one platform migration when the vendor ends support for a generation of readers. That migration is the line item people omit and it is frequently the largest.

A mechanical system’s long tail is rekeying events and eventual cylinder replacement. It is lumpy and it is real, but it is not driven by a third party’s product roadmap. The comparison usually flips somewhere around the point where credential turnover becomes frequent enough that rekeying costs exceed the software overhead.

Different Threats, Not More or Less

A lost key is a physical, local, bounded problem. Someone holds a piece of metal, they have to travel to the door, and the exposure is the set of cylinders that key operates. You fix it by rekeying, and you know when you are done.

A compromised account is remote, potentially invisible, and not bounded by geography. An attacker with administrative credentials to an access platform may be able to issue themselves a credential, delete the log entry, and never appear on camera as anything other than an authorized person. The mitigations are entirely different: multifactor authentication on the administrative console, separation of duties, and log review. NIST’s Special Publication 800-53 Revision 5 catalogs these under access control, identification and authentication, and audit and accountability, and treats physical and environmental protection as a peer control family rather than a separate world. That framing is the right one: an electronic lock is an information system with a bolt attached.

Where Each One Wins

A hybrid design, chosen deliberately, beats an ideological one.

  • Electronic: high turnover openings, shared entrances, anything needing an audit trail, doors where remote revocation genuinely matters.
  • Mechanical: low traffic openings, mechanical rooms, storage, anything where a power or network failure must not matter, and the override path for every electronic opening.
  • Both: the highest value single opening in the building, so that defeating one technology does not defeat the door.

The goal is not to pick a winner. It is to make sure that no single dependency, whether a battery, a vendor, or a network, sits underneath every door you own.