← Physical Security Engineering Studio
Concept Explainer · Physical Security

Fail-Safe vs. Fail-Secure Door Hardware

The exact same power outage, at the exact same door, produces two opposite hardware behaviors on purpose — and which one is correct is a life-safety code question, not a general security preference.

This is specifically about what an electrified door lock does when power drops — not a generic IT-systems "fail open vs. fail closed" framing, but the actual hardware behavior wired into a real door. A fail-safe electric lock unlocks the instant it loses power, because that door sits on a required means-of-egress path and people must never be trapped behind it during a power failure or a fire. A fail-secure electric lock does the opposite — it stays lockedwhen power drops, because that door protects something where uncontrolled access during an outage is itself the bigger risk, and the building has another compliant way out that doesn't run through it. Neither behavior is inherently "more secure." The building's egress requirements decide which one a given door is required to use.

The Setup

One power-loss event, two deliberately opposite hardware responses

An electrified lock — an electromagnetic lock, electric strike, or electrified mortise/panic hardware — has to be engineered with an explicit answer to one question: what does this door do the instant it loses electrical power, whether from a breaker trip, a building-wide outage, or a fire-alarm-initiated shutdown? There is no neutral answer; the hardware has to pick a side. Fail-safe hardware is wired so that de-energizing the lock releases it — power holds the door locked, and removing power removes the lock. This is the behavior required on doors that are part of a means-of-egress path, because life-safety and fire code generally will not accept any locking mechanism that could trap an occupant behind a dead or intentionally-cut circuit. Fail-secure hardware is wired the opposite way — power holds the door unlocked (or the lock is mechanically independent of power for locking), and removing power leaves it locked, because the door is not itself part of a required egress path and an outage is exactly the moment an attacker would want unsupervised access.

Same door, same outage — two configured outcomes

Branching event
ELECTRIFIED DOORlock energized, holding state⚡ POWER LOSS EVENToutage · breaker trip · fire-alarm shutdownconfigured asFAIL-SAFEconfigured asFAIL-SECURE🔓 UNLOCKSdoor releases the instantpower is removed🔒 STAYS LOCKEDdoor remains secured throughthe entire outageREQUIRED MEANS-OF-EGRESS DOORe.g. stairwell exit, corridor exit doorPriority: nobody is ever trappedbehind a dead or cut circuitdriven by fire / life-safety egress codeSECURITY-CRITICAL, NON-EGRESS DOORe.g. server room, cash room, evidence roomPriority: no uncontrolled accessduring the one moment it's vulnerablevalid only if door isn't the required exit routeEgress code decides which branch a given door must be configured as
Fail-safe
unlocks on power loss — egress priority
Required wherever the door is part of the means-of-egress path, so power failure or fire can never trap an occupant.
Fail-secure
stays locked on power loss — security priority
Used where the door is not a required egress route and an unsupervised opening during an outage is the greater risk.

Matching the hardware to the door's actual function

The choice is never "which one is more secure in general." It's "does this specific door sit on a required egress path, and if not, what does that door protect during an outage." A handful of common door types make the pattern concrete.

Door type → required behavior

5 examples
Door
Required mode
Why
Stairwell exit door
Fail-safe
On the required means-of-egress path — must unlock on power loss or fire-alarm signal
Main corridor exit door
Fail-safe
Same egress logic — occupants must never be trapped behind it during an outage
Server / data room
Fail-secure
Not a required egress route (another compliant exit exists) — an outage shouldn't hand out free access
Cash room / vault anteroom
Fail-secure
An unlocked door during a deliberately-cut power feed is itself the attack scenario being defended against
Evidence storage room
Fail-secure
Chain-of-custody integrity depends on continuous access control, including through outages
Why this works

The mode is picked by what the door protects and where it sits in the egress path, not by a general security instinct

Fire and life-safety egress code exists precisely because power fails, breakers trip, and fires cut circuits — and a locking mechanism that depends on power to release cannot be trusted to release when someone most needs it to. So any door that is part of a required means-of-egress path has to be fail-safe: no exception, because the cost of getting it wrong is someone trapped in a fire. A server room, cash room, or evidence room is a different situation entirely — it typically isn't itself a required egress route (occupants have another compliant way out that doesn't depend on that specific door), so the life-safety argument for fail-safe doesn't apply there. Once egress isn't the deciding factor, the security argument takes over, and for those rooms an outage is exactly the scenario a real attacker would try to engineer — cutting power to walk in unsupervised. Fail-secure closes that exact door. The two hardware modes aren't competing on which is "better" in the abstract; each one is the correct answer to a different question about a specific door.

Common misconception
"Fail-safe" means the door is safer, so it's the more secure choice — and "fail-secure" sounds riskier because it can trap someone.

The names are about who the outcome favors, not how good the outcome is. "Fail-safe" means the failure mode favors life safety — the door unlocks so no one is trapped. "Fail-secure" means the failure mode favors security — the door stays locked so no one gets unsupervised access. Neither word claims the door is generally "safer" or "more secure" overall; each just names which priority wins the instant power is lost. For a security-critical, non-egress door — a server room, a cash room, an evidence room — fail-secure is the deliberately more restrictive and more correctchoice, precisely because uncontrolled access during an outage is the real threat there, and there's no life-safety egress requirement pulling the other way. Specifying fail-safe on that door wouldn't make it "safer" — it would remove the one control that's actually doing work. The decision is never "which mode is inherently better"; it's "is this door on a required egress path," and code — not general security preference — answers that question for you.

Related Concept Explainers
REX vs. Door Position Switch
Read it →
Mantraps vs. Turnstiles
Read it →

Fail-Safe vs. Fail-Secure Door Hardware — Concept Explainer

Explains what electrified door lock hardware actually does on power loss: fail-safe hardware unlocks to guarantee egress on doors that are part of a required means-of-egress path, while fail-secure hardware stays locked to preserve security continuity on doors like server rooms, cash rooms, or evidence storage that are not required egress routes. Corrects the misconception that fail-safe is the generally more secure choice — egress code, not a security preference, determines which mode a given door must use.

What Fail-Safe Hardware Actually Does

Fail-safe electrified lock hardware — commonly electromagnetic locks or electrified panic hardware wired this way — is designed so that electrical power holds the door locked, and removing power (an outage, a breaker trip, or an intentional fire-alarm-initiated shutdown) releases the lock, unlocking the door. This is the required behavior for any door that forms part of a building's means-of-egress path, because fire and life-safety egress codes generally will not accept a locking mechanism that could leave an occupant trapped behind a dead or deliberately-cut circuit during a power failure or a fire.

What Fail-Secure Hardware Actually Does

Fail-secure electrified lock hardware — commonly electric strikes or electrified mortise locks wired this way — is designed the opposite way: power holds the door unlocked, or the lock is mechanically independent of the electrified state entirely, and removing power leaves the door locked. This is used on doors that are not themselves a required means-of-egress path, where an unsupervised opening during a power outage is a serious security risk in its own right — a server room, a cash room, or an evidence storage room, for example — and where occupants have another compliant way out that doesn't depend on that specific door.

Why the Choice Is a Code Question, Not a Security-Preference Question

The deciding factor is never "which mode is more secure in the abstract." It is: does this specific door sit on a required means-of-egress path? If yes, fail-safe is mandatory, full stop, because the cost of a wrong guess is someone trapped during a fire or outage. If no — if the door is not itself part of the required egress route and another compliant exit exists — the life-safety argument for fail-safe no longer applies, and the security argument for fail-secure can legitimately take over instead. Applicable building and fire codes (and the local AHJ) are what settle the egress question for a given door; a designer's general instinct about which mode "sounds safer" is not a substitute for that determination.

Why Fail-Secure Is Often the More Restrictive, Correct Choice

On a security-critical, non-egress door, fail-secure is deliberately the more restrictive option — and that is exactly the point. A cut or lost power feed is a scenario a real attacker might try to engineer specifically to defeat an electrified lock; if that same lock were fail-safe, cutting power would simply open the door for them. Fail-secure closes that exact avenue by keeping the door locked through the outage, at the cost of requiring a backup means of authorized entry (mechanical key override, battery backup, etc.) for legitimate use during a prolonged outage. That tradeoff is acceptable, and often required, precisely because the door in question is not the thing standing between occupants and safe egress.

Frequently asked questions

Can a door be both fail-safe and fail-secure at the same time?

No — a given locking mechanism is wired one way or the other for what happens on power loss. Some facilities use multiple locking devices at the same opening (for example, an electrified exit device paired with a separate access-control strike) with different behaviors, but each individual electrified lock component itself resolves to one behavior on power loss, not both.

Does fail-safe hardware mean the door has no security at all?

No. Fail-safe only defines behavior on power loss, not normal operating security. Under normal power, a fail-safe electrified lock still enforces access control exactly like any other electrified lock — badge readers, PINs, and monitoring all still apply. The fail-safe designation only governs the specific failure condition of losing power, which is why it can coexist with strong day-to-day access control on an egress door.

Who decides whether a specific door must be fail-safe?

The applicable building and fire code provisions governing means of egress, as interpreted and enforced by the local Authority Having Jurisdiction (AHJ) during plan review and inspection. A door's status as part of a required egress path — not a designer's security judgment — is what triggers the fail-safe requirement.

What happens to a fail-secure door during a prolonged power outage if someone needs legitimate access?

Fail-secure openings typically require a compliant backup means of entry that doesn't depend on the failed power feed — most commonly a mechanical key override built into the electrified hardware, or a battery/UPS backup sized to bridge shorter outages. That backup is a standard part of specifying fail-secure hardware correctly, not an afterthought.

Is an electromagnetic (mag) lock always fail-safe?

Electromagnetic locks are inherently fail-safe by their basic operating principle — the magnet only holds while energized, so removing power always releases it; there is no fail-secure version of a standalone mag lock. That is exactly why mag locks are common on egress doors but are not used alone on doors that require fail-secure behavior, where an electric strike or electrified mechanical lockset is used instead.

Does fire-alarm activation always unlock fail-safe doors, or only a general power outage?

Both. Fail-safe hardware on an egress door is typically wired to release both on loss of building power and on receipt of a fire-alarm signal even while normal power is still present, since a fire condition itself is the life-safety trigger the code is protecting against, independent of whether the power feed has actually failed.

🎓

Try our Physical Security Studio

More calculators, simulators, and guides for this discipline.

Related tools & guides

REX vs. Door Position Switch — Concept ExplainerMantraps vs. Turnstiles — Concept ExplainerAccess Control System DesignerIBC Egress and Locking Hardware: Code Compliance Guide