Volume 133
Volume 133 | February 9, 2026
Click on the above image and use code sxst3gkbkn to hear the audio version.
Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.

The traditional Physical Access Control Systems (or PACs as we call them), as we know them, the historical orchestration layer that ties hardware, credentials, configuration, and policy into a unified system of record, is facing structural decline.
To be clear: this is an opportunity story…dare I say, a love story :) … not doom and gloom. Keep that in mind as you read on.
For decades, PACs served as the primary distribution channel for locks, readers, controllers, and peripherals, and were the primary purchasing decision along the way (“What system do you use?” = “What PACs do you use?”). Today, that position, coupled with traditional business models, programs, messaging, and go-to-market methods, is eroding from multiple directions.
As the industry shifts from door-first to identity-first, value has migrated to whoever controls the database. Hardware is opening up, middleware is aggregating, software players are delivering superior user experience, and AI-driven automation is collapsing configuration complexity. Traditional PACs who remain inward-focused and high-security-only leanings are being squeezed out of relevance.
This is a structural problem, not product and it is accelerating.

What are PACs, and why did they matter through a 1970 - 2020 lens?
At its core, a Physical Access Control System (PACs) is orchestration software. It ingests data from hardware (controllers, readers, locks), applies policy (who can access what, when, and how), and generates the system of record that governs doors, credentials, and identities across a facility or enterprise.
Another side note: As the community grows, I have been asked to define terms more often. Hence PACs (Physical Access Control Systems).
For decades, PACs were the center of gravity in the access control value chain. They were the integration point for disparate hardware ecosystems, the interface for managing credentials and permissions, the distribution channel for manufacturers, and the moat that locked customers into proprietary ecosystems.
PACs vendors built their businesses on three assumptions: hardware would remain fragmented and require proprietary integration, configuration would remain complex and require trained professionals, and identity would remain a feature inside access control, not the organizing principle of the category.
All three assumptions are now broken.
The five forces squeezing traditional PACs
I wrote in my book, The 6 Phase Changes Shaping Access Control(published 2020), that mainstream digital transformation trends were impacting the industry. While that is still true and COVID accelerated as I revisit it 6 years later, those trends are starting to have outcomes. Below are 5 forces I believe are accelerating the change to the historical structure (because of the mainstream ones):
-
Hardware Is opening up and so is the appetite for standards. The momentum for them, like OSDP and Aliro, is making hardware interoperable by default. Locks are becoming endpoints (not just products that lock and unlock). Readers are becoming sensors (not standalone things that go beep). Controllers are becoming edge compute nodes (not black boxes). IoT is being realized, and so is the need for standards. You can imagine a world in the not-too-distant future where hardware no longer needs PACs to function. It needs identity, policy, and orchestration. Still, those can now live anywhere and, in some cases, be part of a broader platform with access control as a feature of a larger value proposition. Traditional PACs vendors built their businesses on being the only integration point. As hardware opens up, that moat shifts.
-
Hardware companies are moving up the stack. Lock manufacturers are building or acquiring cloud platforms. Reader companies are shipping identity SDKs. Controller vendors are embedding AI at the edge and opening up to developers to build apps. Hardware companies no longer need to rely on PACs vendors to reach customers exclusively. They can deliver policy, provisioning, and orchestration directly through their own platforms. You are seeing this right now in multifamily, critical infrastructure, and even pickleball courts. It’s been this way in hospitality for a long time. As traditional hardware companies start to taste the sweet honey of recurring revenue, their investors expect more of it. Traditional PACs vendors built their businesses on being the distribution channel. As hardware companies verticalize, that channel gets replaced.
-
Configuration is becoming plug and play, and AI is only going to accelerate this. Modern platforms are rolling out natural language processing, declarative policy engines, and zero-touch provisioning to collapse configuration time from weeks to minutes. Operators can say “give all marketing employees access to the third floor on weekdays,” and the system translates that into a policy, provisions credentials, and automatically syncs hardware. The professional services moat that sustained PACs vendors is evaporating. Customers' expectations of what an integrator does during an install to deploy access control are shifting. They need an IT admin with a browser in some respects. Traditional PACs vendors built their businesses on complexity because someone downstream would configure it anyway. As configuration becomes plug-and-play, that complexity becomes a liability.
-
Middleware is aggregating. What used to be a dirty word, a new category of middleware platforms has emerged to abstract hardware, aggregate data, and deliver identity-as-a-service across multiple systems, among other things. These platforms sit between identity providers (Okta, Entra ID, Workday) and physical endpoints, translating IAM policy into physical access policy in real time. Identity becomes the system of record. PACs become an implementation detail tied to that new system of record. Traditional PACs vendors built their businesses on owning the card or fob details. As middleware aggregates identity, that ownership shifts upstream.
-
Software companies are delivering better UX. As much as I love DOS-like interfaces 🤮, modern software companies are using AI to automate provisioning, NLP to simplify policy, and modern UX design to make access control feel like SaaS, not industrial control software. Meanwhile, traditional PACs vendors are shipping Windows desktop apps that look like they were designed in 2005. It’s 2026, and there’s no excuse. Customers are choosing platforms that feel like software, not systems that think like hardware that has a side of software. Traditional PAC vendors built their businesses on control and the idea that “it doesn’t matter what it looks like as long as it works.” As software companies deliver better experiences, that control becomes irrelevant.
Who owns identity owns the future of this industry
The deeper pattern beneath all five forces is a single structural shift I've been writing about a lot lately: physical security is becoming an identity industry.
In the past, access control was organized around doors. In the new model, access control is organized around identity. You have a user with an identity in your IAM system. That identity has permissions that extend to both digital systems and physical spaces.
In that model, the PACs are not the center of gravity. The identity provider is. The PACs become a feature.
Whoever owns the identity database wins. And traditional PACs vendors do not own the identity database. The ones making moves are and can. The ones still using a pre 2020 strategy own a shadow database, a secondary system of record that duplicates identity, poorly syncs it, and struggles to integrate with modern IAM platforms.
That position is not defensible.
Why some PACs are not adapting
Some traditional PACs vendors are focused on their own architectures, their own roadmaps, and their own customer installed bases…based off of yesterday. They are waiting for competitors to blink, or they think “customers never rip and replace, so I’m good.” They are protecting margins and defending pricing models and not looking at the market from today forward. They love discussing market theory of yesterday.
Traditional PACs vendors have large installed bases, long customer relationships, and some have recently introduced cloud offerings and even have recurring revenue streams. Adapting would mean cannibalizing a good number of those relationships, retraining their channel, and rebuilding their products from scratch. They will likely have to replace some leaders, level up their employees, say goodbye to old relationships, and let some go. So it becomes self-fulfilling and “hard,” leading them to optimize for installed base retention rather than market growth.
The most fundamental reason some traditional PACs vendors are not adapting is that they do not believe identity is the organizing principle of the future. They believe whatever they have is what the market is (and then they survey their customers and put out reports supporting their strategy. It’s literally drinking their own bath water). Still, they think access control is about doors. Still, they feel the customer cares about controllers, readers, and protocols.
They are wrong.
Customers care about identity, provisioning, policy, and audit trails. Everything else is infrastructure. (Even if they have some customers who tell them differently. Its all noise, no signal).
So, what happens next? The squeeze will accelerate. In the next two to five years, we will see consolidation among traditional PACs vendors as installed bases shrink and new deals dry up. We will see vertical specialization as PACs vendors retreat into niche markets where complexity still matters. We will see platform displacement as identity-first platforms absorb the orchestration layer and reduce PACs to backend adapters.
Some traditional PACs vendors will adapt. Most will not and new ones will join the party.
The ones that survive will make one of three moves: become an identity platform, become a vertical specialist, or become middleware. The ones that do not make one of these moves will become legacy systems, maintained but not invested in, replaced but slowly.
The center of gravity has shifted.
Agree? Disagree? Who will own identity, and what role will access control play in that future?
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
