Why a door's "failure mode" is a real design decision, not an accident — and why the same building routinely uses both.
Every electronically controlled door has to answer one question that has nothing to do with normal operation: what should it do when power, the network link, or the access control panel itself is lost? There are exactly two possible defaults, and picking between them is a deliberate tradeoff between two things that are both, in the abstract, "security" — keeping people safe, and keeping an area protected. Which one wins during a failure isn't a matter of opinion. On many doors, it's dictated by fire and building code. On others, it's a conscious risk decision made by whoever designed the access control system.
Fail-safe means that when power or control signal is lost, the locking mechanism defaults to unlocked. An electronic door lock wired fail-safe releases the moment power drops — during a fire, a general power outage, or a control-panel failure — so people inside can get out even though the access control system driving it is dead. It prioritizes life safety over access security at the exact moment things are going wrong. Fail-secure (also called fail-locked) is the opposite default: on loss of power or control, the mechanism stays locked. A door wired fail-secure can't be opened just by cutting its power, so it prioritizes asset and area protection over convenient egress during that same failure. Neither behavior is a bug — both are the mechanism doing exactly what it was engineered to do.
Building and fire codes (NFPA 101 Life Safety Code, the International Building Code, and the local fire marshal's interpretation of them) typically mandate fail-safe operation on designated means of egress — the doors people are legally supposed to be able to exit through — specifically because a locked exit during a fire is one of the deadliest and most preventable failure modes a building can have. Those doors are usually also wired to release automatically on fire-alarm activation, independent of the access control system. High-security, non-egress spaces run the opposite calculation: if the door only protects an asset rather than a person's escape route, letting an attacker unlock it for free by pulling a breaker or cutting a cable is the greater risk, so it's specified fail-secure. A real facility routinely does both— main exits and stairwell doors fail-safe, a server room or vault fail-secure — all wired through the same access control platform, with the failure mode set per door hardware and per door's actual risk profile, not chosen once for the whole building.
This is false, and on a primary egress route it's a real, serious life-safety code violation risk. Fires are one of the most common causes of building power loss — and a fail-secure door on a designated fire-exit route means occupants can be physically trapped inside during exactly the event they most need to escape. That's precisely why fire and life-safety codes typically mandate fail-safe operation on egress doors, regardless of how security-conscious the rest of the facility is. "More secure" framing only applies to non-egress, asset-protection doors — a server room, a vault, an evidence room — never to a route someone is depending on to get out. Confusing the two isn't a stricter security posture; on an exit door, it's a code violation waiting to become a fatality.
Explains the two possible failure modes for an electronically controlled door — fail-safe (unlocks on power/control loss, prioritizing life safety) and fail-secure (stays locked on power/control loss, prioritizing asset protection) — and why real facilities deliberately mix both across a single building rather than picking one policy site-wide.
It's tempting to treat "locked" as the universally safer default and assume a well-secured facility should keep every door fail-secure. That reasoning ignores that a door's failure mode has to answer two competing questions at once: does it protect the people who need to get through it, or the asset/area behind it? On a designated exit route, those two goals point in opposite directions during a power loss, and life safety wins by code, not by preference.
Fire and building codes — NFPA 101 (Life Safety Code), the International Building Code, and the local Authority Having Jurisdiction's interpretation of them — typically mandate fail-safe operation on designated means of egress: main exits, stairwell doors, and other paths occupants are required to be able to use to leave the building. Those doors are usually also tied into the fire alarm system so they release on alarm activation independent of the access control platform itself. Non-egress doors protecting high-value or sensitive areas — server rooms, vaults, evidence rooms, some detention spaces — are not egress paths, so the code pressure reverses: they're frequently specified fail-secure so that cutting power can't be used as a way to force entry.
Because the decision is made door by door based on that door's actual risk profile, not once for the whole site. A hospital, office building, or industrial facility will typically run every designated exit fail-safe while running specific interior high-value rooms fail-secure — all wired through the same access control panel, with the failure mode set per door hardware (an electric strike can usually be configured either way; a magnetic lock is inherently fail-safe by nature, since removing power removes the magnetic holding force) and per local code requirement for that specific opening.
Neither, in the abstract — it depends entirely on what that specific door is protecting. Fail-safe protects the people who need to exit through it during a failure; fail-secure protects the asset or area behind it from a power-cut attack. The right choice is a per-door risk decision, and on egress paths it's usually not a choice at all — code dictates fail-safe.
Generally, yes. Designated means of egress — main exits, stairwell doors, other legally required exit paths — are typically required by life-safety and building codes (e.g., NFPA 101, the IBC, and local AHJ interpretation) to unlock on power loss and on fire alarm activation, because trapping occupants behind a locked door during a fire is one of the failure modes those codes exist to prevent.
Yes, and it's the normal case in practice, not an exception. A single access control system commonly drives fail-safe hardware on egress doors and fail-secure hardware on non-egress, high-security interior doors like a server room or vault, with the failure mode configured independently for each opening.
Yes. Electromagnetic locks (maglocks) are inherently fail-safe — removing power removes the magnetic holding force, so they release with no other wiring required. Electric strikes can be manufactured and wired as either fail-safe or fail-secure, which is why the specific strike model and wiring matter when a door's required failure mode is being specified.
No. Fail-secure only describes what happens on loss of power or control signal. Under normal operation, a fail-secure door still unlocks for valid credentials exactly like any other access-controlled door, and it must still be openable from the inside via request-to-exit hardware or panic hardware as required by code — fail-secure is not a substitute for meeting egress requirements.
Try our Cybersecurity Studio
More calculators, simulators, and guides for this discipline.