The exact same power outage, at the exact same door, produces two opposite hardware behaviors on purpose — and which one is correct is a life-safety code question, not a general security preference.
This is specifically about what an electrified door lock does when power drops — not a generic IT-systems "fail open vs. fail closed" framing, but the actual hardware behavior wired into a real door. A fail-safe electric lock unlocks the instant it loses power, because that door sits on a required means-of-egress path and people must never be trapped behind it during a power failure or a fire. A fail-secure electric lock does the opposite — it stays lockedwhen power drops, because that door protects something where uncontrolled access during an outage is itself the bigger risk, and the building has another compliant way out that doesn't run through it. Neither behavior is inherently "more secure." The building's egress requirements decide which one a given door is required to use.
An electrified lock — an electromagnetic lock, electric strike, or electrified mortise/panic hardware — has to be engineered with an explicit answer to one question: what does this door do the instant it loses electrical power, whether from a breaker trip, a building-wide outage, or a fire-alarm-initiated shutdown? There is no neutral answer; the hardware has to pick a side. Fail-safe hardware is wired so that de-energizing the lock releases it — power holds the door locked, and removing power removes the lock. This is the behavior required on doors that are part of a means-of-egress path, because life-safety and fire code generally will not accept any locking mechanism that could trap an occupant behind a dead or intentionally-cut circuit. Fail-secure hardware is wired the opposite way — power holds the door unlocked (or the lock is mechanically independent of power for locking), and removing power leaves it locked, because the door is not itself part of a required egress path and an outage is exactly the moment an attacker would want unsupervised access.
The choice is never "which one is more secure in general." It's "does this specific door sit on a required egress path, and if not, what does that door protect during an outage." A handful of common door types make the pattern concrete.
Fire and life-safety egress code exists precisely because power fails, breakers trip, and fires cut circuits — and a locking mechanism that depends on power to release cannot be trusted to release when someone most needs it to. So any door that is part of a required means-of-egress path has to be fail-safe: no exception, because the cost of getting it wrong is someone trapped in a fire. A server room, cash room, or evidence room is a different situation entirely — it typically isn't itself a required egress route (occupants have another compliant way out that doesn't depend on that specific door), so the life-safety argument for fail-safe doesn't apply there. Once egress isn't the deciding factor, the security argument takes over, and for those rooms an outage is exactly the scenario a real attacker would try to engineer — cutting power to walk in unsupervised. Fail-secure closes that exact door. The two hardware modes aren't competing on which is "better" in the abstract; each one is the correct answer to a different question about a specific door.
The names are about who the outcome favors, not how good the outcome is. "Fail-safe" means the failure mode favors life safety — the door unlocks so no one is trapped. "Fail-secure" means the failure mode favors security — the door stays locked so no one gets unsupervised access. Neither word claims the door is generally "safer" or "more secure" overall; each just names which priority wins the instant power is lost. For a security-critical, non-egress door — a server room, a cash room, an evidence room — fail-secure is the deliberately more restrictive and more correctchoice, precisely because uncontrolled access during an outage is the real threat there, and there's no life-safety egress requirement pulling the other way. Specifying fail-safe on that door wouldn't make it "safer" — it would remove the one control that's actually doing work. The decision is never "which mode is inherently better"; it's "is this door on a required egress path," and code — not general security preference — answers that question for you.
Explains what electrified door lock hardware actually does on power loss: fail-safe hardware unlocks to guarantee egress on doors that are part of a required means-of-egress path, while fail-secure hardware stays locked to preserve security continuity on doors like server rooms, cash rooms, or evidence storage that are not required egress routes. Corrects the misconception that fail-safe is the generally more secure choice — egress code, not a security preference, determines which mode a given door must use.
Fail-safe electrified lock hardware — commonly electromagnetic locks or electrified panic hardware wired this way — is designed so that electrical power holds the door locked, and removing power (an outage, a breaker trip, or an intentional fire-alarm-initiated shutdown) releases the lock, unlocking the door. This is the required behavior for any door that forms part of a building's means-of-egress path, because fire and life-safety egress codes generally will not accept a locking mechanism that could leave an occupant trapped behind a dead or deliberately-cut circuit during a power failure or a fire.
Fail-secure electrified lock hardware — commonly electric strikes or electrified mortise locks wired this way — is designed the opposite way: power holds the door unlocked, or the lock is mechanically independent of the electrified state entirely, and removing power leaves the door locked. This is used on doors that are not themselves a required means-of-egress path, where an unsupervised opening during a power outage is a serious security risk in its own right — a server room, a cash room, or an evidence storage room, for example — and where occupants have another compliant way out that doesn't depend on that specific door.
The deciding factor is never "which mode is more secure in the abstract." It is: does this specific door sit on a required means-of-egress path? If yes, fail-safe is mandatory, full stop, because the cost of a wrong guess is someone trapped during a fire or outage. If no — if the door is not itself part of the required egress route and another compliant exit exists — the life-safety argument for fail-safe no longer applies, and the security argument for fail-secure can legitimately take over instead. Applicable building and fire codes (and the local AHJ) are what settle the egress question for a given door; a designer's general instinct about which mode "sounds safer" is not a substitute for that determination.
On a security-critical, non-egress door, fail-secure is deliberately the more restrictive option — and that is exactly the point. A cut or lost power feed is a scenario a real attacker might try to engineer specifically to defeat an electrified lock; if that same lock were fail-safe, cutting power would simply open the door for them. Fail-secure closes that exact avenue by keeping the door locked through the outage, at the cost of requiring a backup means of authorized entry (mechanical key override, battery backup, etc.) for legitimate use during a prolonged outage. That tradeoff is acceptable, and often required, precisely because the door in question is not the thing standing between occupants and safe egress.
No — a given locking mechanism is wired one way or the other for what happens on power loss. Some facilities use multiple locking devices at the same opening (for example, an electrified exit device paired with a separate access-control strike) with different behaviors, but each individual electrified lock component itself resolves to one behavior on power loss, not both.
No. Fail-safe only defines behavior on power loss, not normal operating security. Under normal power, a fail-safe electrified lock still enforces access control exactly like any other electrified lock — badge readers, PINs, and monitoring all still apply. The fail-safe designation only governs the specific failure condition of losing power, which is why it can coexist with strong day-to-day access control on an egress door.
The applicable building and fire code provisions governing means of egress, as interpreted and enforced by the local Authority Having Jurisdiction (AHJ) during plan review and inspection. A door's status as part of a required egress path — not a designer's security judgment — is what triggers the fail-safe requirement.
Fail-secure openings typically require a compliant backup means of entry that doesn't depend on the failed power feed — most commonly a mechanical key override built into the electrified hardware, or a battery/UPS backup sized to bridge shorter outages. That backup is a standard part of specifying fail-secure hardware correctly, not an afterthought.
Electromagnetic locks are inherently fail-safe by their basic operating principle — the magnet only holds while energized, so removing power always releases it; there is no fail-secure version of a standalone mag lock. That is exactly why mag locks are common on egress doors but are not used alone on doors that require fail-secure behavior, where an electric strike or electrified mechanical lockset is used instead.
Both. Fail-safe hardware on an egress door is typically wired to release both on loss of building power and on receipt of a fire-alarm signal even while normal power is still present, since a fire condition itself is the life-safety trigger the code is protecting against, independent of whether the power feed has actually failed.
Try our Physical Security Studio
More calculators, simulators, and guides for this discipline.