By Johanna Wünsch, Senior Marketing Manager at ID-wareID-ware are finalists in nine categories at the 2026 SaaS Awards, including in ‘Best SaaS Solution for Finance or FinTech‘, ‘Best SaaS Newcomer‘, and ‘Best Bespoke or Specialized SaaS Innovation‘.

There is a paradox at the heart of modern enterprise security. Organizations that have invested millions in sophisticated digital identity infrastructure – e.g. zero-trust architectures or multi-factor authentication – often rely on spreadsheets, manual e-mail chains and disconnected legacy systems to manage who walks through their doors.

This is not a niche problem. It is a structural blind spot that affects organizations across every sector: healthcare, industry, finance, education, critical infrastructure. As the threat landscape steadily becomes more sophisticated, it is a gap that is increasingly difficult to ignore.

Digital IAM grew up, physical security did not

Over the past decade, digital identity and access management (IAM) has matured dramatically. The adoption of SAML 2.0, SCIM provisioning, cloud-based identity providers and zero-trust frameworks has transformed how organisations govern who accesses which digital resources. Joiners, movers and leavers are automatically provisioned and deprovisioned. Digital access rights are tied to roles, not individuals. Audit logs are centralized, searchable and exportable.

However, physical access has not kept pace. In most larger organizations today, the management of physical credentials (access cards, visitor passes, contractor permits) still operates in a separate silo. The HR system knows when an employee starts working or when the contract is terminated. The access management system does not necessarily receive that information in real time. The result is a persistent security risk: former employees with active access cards, contractors with permissions that outlast their engagement, visitors with no formal audit trail.

Physical credential mismanagement is a well-documented source of insider risk, yet it rarely receives the same governance attention as its digital counterpart.

Person scanning key card on a sleek access control reader to unlock an office door, illustrating modern digital security, authorized entry, and everyday corporate access procedures

The cyber-physical convergence problem

The security industry talks frequently about cyber-physical convergence, i.e. the integration of physical and logical access control into a unified framework. The concept is not new. Standards bodies, security consultancies and enterprise architects have advocated for converged identity governance for years.

In practice, convergence has proved elusive. There are several reasons for this.

First, physical access control systems have historically been vendor-locked, proprietary, and on-premises. Different buildings and sites of an organisation may run entirely different access control platforms. Integrating them requires either expensive middleware, bespoke development, or replacing the underlying infrastructure entirely: none of which is straightforward to justify in a capital expenditure conversation.

Second, physical identity has traditionally been treated as a hardware problem. The focus has been on the card or the reader, but not the data layer that governs them. The result is that the identity governance principles that are now standard in digital IAM have not been systematically applied to physical access.

Contactless check-in with smartphone at self-service access kiosk in modern office lobby, Gen Z hybrid work and smart building security concept, copy space.

What unified Physical Identity & Access Management (PIAM) actually requires

Closing the gap between physical and digital identity governance is not simply a matter of buying a new access control system. It requires a different way of thinking about what physical identity management is.

Consider what a real deployment looks like. A large educational institution with tens of thousands of students, staff, visitors and contractors and multiple distributed campuses throughout the country needs to manage credentials across all its locations, incorporating User Self-Service, and photo capture. That single use case captures the full complexity: scale, security, usability, distributed geography, and multiple user types, all within one credential management challenge. It is a picture repeated across thousands of organizations that have simply never had the right platform to address it.

At its core, Physical Identity & Access Management (PIAM) involves the same lifecycle as digital identity: onboarding, role assignment, access provisioning, change management, and offboarding. The difference is the credential, a smartcard rather than a password or token, and the enforcement point: a door, a turnstile or a gate rather than a login screen.

Effective PIAM therefore requires a single source of truth for identity data. If an employee changes department, their physical access should update automatically and not after a manual request is processed. It requires integration with existing HR and directory systems. Joiners, movers and leavers in the HR system should trigger automated workflows that provision or revoke physical credentials, in the same way that SCIM provisioning works for cloud applications. Organizations that have already invested in Microsoft Entra ID, Okta or similar platforms should be able to extend those investments into the physical domain.

Cross-system interoperability matters too. Most large organizations have more than one access control system. Any meaningful PIAM platform needs to be able to communicate with and govern access rights across heterogeneous infrastructure, without requiring organizations to rip and replace their existing physical security estate. Beyond access control itself, a mature PIAM platform also interoperates with the wider ecosystem of connected systems that rely on the same credential: payment and cashless vending systems, locker management, parking management, time and attendance, follow-me printing, and cafeteria systems. A single credential, governed from a single platform, can serve as the physical link between a person’s identity and every system they interact with across a site.

Full audit capability is equally essential. Regulatory frameworks including GDPR, ISO 27001, NIS2 or DORA increasingly require organizations to demonstrate that access rights are appropriate, reviewed and revocable in real time. That requires a complete, searchable audit log of credential issuance, access right changes and revocation events.

Woman Using Laptop To Manage User Access With Multi-factor Authentication.

The case for SaaS

For many years, the argument of many organizations against cloud delivery of PIAM platforms was straightforward: this is sensitive infrastructure, it needs to be on-premises installation, under our direct control.

That argument has weakened considerably. The very same logic was once applied to HR systems, ERP platforms and financial reporting, all of which have migrated to SaaS without meaningful loss of control for the organizations that use them. The question is not whether cloud delivery is inherently less secure, but whether it is designed, configured and governed appropriately.

There is a stronger case for SaaS delivery of PIAM than is often recognized. On-premises deployments are expensive to maintain, slow to update, and dependent on specialist internal expertise that many organizations do not have. They are also difficult to scale: a new site, a merger, a seasonal surge in contractor numbers all require manual provisioning effort.

SaaS platforms can address these constraints directly. Automated onboarding pipelines reduce deployment time from weeks to days. Infrastructure updates are applied by the vendor, not the customer’s IT team. Costs become operational rather than capital, and scale with usage rather than requiring upfront investment in hardware and licenses.

The shift mirrors what happened in digital IAM when organizations began migrating from on-premises LDAP directories to cloud-based identity providers. The initial resistance for reasons of security, control and compliance gave way as the cloud platforms matured and the operational benefits became undeniable.

A face scanner being used by a man to open a door at an office building. Control device for Security system. Device to control a security system.

Implications for compliance

The convergence of physical and digital identity management has implications beyond security and operational efficiency. It is increasingly a compliance and governance requirement.

NIS2, the updated EU directive on network and information security, explicitly addresses physical security measures for operators of essential services. DORA, the Digital Operational Resilience Act, requires financial entities to manage access rights (both physical and digital) within a formal governance framework. ISO 27001 includes physical security controls within its information security management system scope. The UK’s NCSC Cyber Assessment Framework goes further still, stating directly that organizations should protect physical access to networks and information systems supporting essential functions, to prevent unauthorized access, tampering or data deletion.

Sector-specific frameworks for critical national infrastructure across the UK and Europe set requirements for credential security, key management and access audit trails that many organizations currently cannot demonstrate compliance with from their existing physical access systems.

A unified PIAM platform that governs physical identity with the same rigor as digital identity makes compliance demonstrably easier. Access rights reviews can be conducted from a single interface. Joiners and leavers, visitors and contractors are handled by automated workflows rather than manual processes that rely on notification chains working correctly.

What needs to change

Physical identity management will not converge with digital IAM simply because the technology to enable it exists. Several things need to change at the organizational and industry level.

Governance ownership needs to be clarified. Physical and digital identity cannot be effectively managed as two separate domains indefinitely. Whether that means a converged security function, a shared platform with joint ownership, or a clear set of integration standards, the current siloed model is not sustainable.

Procurement conversations need to evolve. Buying an access control system and buying a PIAM platform are different things. The former focuses on hardware and readers; the latter focuses on data governance, lifecycle management and integration. Procurement processes that evaluate only the former will continue to produce the gap described in this article.

Investment decisions need to account for risk. The cost of managing physical identity manually – often resulting in security incidents, compliance failures, operational overhead and extended staff time – is rarely quantified and therefore rarely weighed against the cost of addressing it properly.

Employee accessing secure office building turnstile system

How enterprise security can move forward with a PIAM SaaS platform

Enterprise security has made remarkable progress in governing digital identity over the past decade. The same level of rigor has not yet been applied to Physical Identity & Access Management, i.e. to the credentials that open doors, grant site access, and in many cases determine who can reach the most sensitive physical assets an organization holds.

The tools to close that gap now exist. SaaS platforms built specifically for PIAM can deliver the lifecycle governance, cross-system integration, audit capability and compliance alignment that organizations need, but without the infrastructure overhead that has historically made on-premises solutions difficult to deploy and maintain at scale.

The question for security leaders is not whether PIAM needs to change, but how quickly that change can be made. The risk of leaving the gap open is no longer theoretical.

ID-ware is a specialist in Physical Identity and Access Management (PIAM), with over 20 years of experience delivering consultancy, software and services to enterprise and public-sector customers across Europe and beyond.

The ID-ware PIAM Suite is a SaaS platform that centralizes the complete lifecycle of physical identities, credentials and access rights across complex, multi-site organizations.

It integrates with HR systems, directory services and the existing physical access control infrastructure, enabling organizations to manage joiners, movers and leavers automatically, enforce role-based physical access policies, and maintain a full audit trail of credential issuance and access changes.

The platform’s modules cover Credential Management, Access Management, Visitor Management and Contractor Management, addressing the full range of physical identity types that enterprise and public-sector organizations need to govern.

PIAM Suite_EN

ID-ware also offers Credentials as a Service: end-to-end card personalization, encoding, printing and dispatch for organizations that require external support for credential production (e.g. universities during the enrolment periods of thousands of new students).

Customers operate in sectors including healthcare, finance, education, and critical infrastructure: environments where credential security, key sovereignty and regulatory compliance are non-negotiable requirements.

The PIAM Suite SaaS platform is a finalist in the SaaS Awards 2026.

About the Author: Johanna Wunsch

Johanna Wünsch is Senior Marketing Manager at ID-ware, a Physical Identity and Access Management (PIAM) specialist headquartered in The Hague/Netherlands, with operational offices in Frankfurt/Germany and London/UK. Based in Frankfurt, Johanna brings over 15 years of experience in the physical security sector, working for software manufacturers of vendor-agnostic platforms serving enterprise and public-sector organisations. At ID-ware, she creates content and drives awareness around PIAM, translating complex security & compliance challenges into clear, compelling narratives for enterprise and public-sector audiences.