NIS-2-Congress 2026: Physical security moves into focus
From 11 to 13 May 2026, the NIS-2-Congress will take place in Frankfurt, where Assa Abloy Sicherheitstechnik is setting a particular accent: in a workshop, the company will show why cyber resilience involves not only digital systems but also physical access control. The congress, which sees itself as an IT security dialogue for businesses, expects around 700 participants, more than 50 specialist and practical presentations as well as 16 workshops.
At the heart of Assa Abloy's appearance is the question of why, in the context of NIS2, companies must consistently secure not only their digital systems but also physical access to sensitive areas. This holistic view is becoming ever more important, since many security concepts have so far had a blind spot when it comes to the physical component.
NIS-2 implementation: many companies behind schedule
The timing of the event is highly topical: the EU cybersecurity directive NIS2 has been in force in Germany since the end of last year. At the beginning of March, the registration deadline for affected companies expired at the German Federal Office for Information Security (BSI). Since then, however, media reports have been piling up that the majority of companies have missed this step.
Particularly problematic: the legal protection for latecomers has now fallen away, and fines as well as tightened controls are looming. This makes clear how much catching up many organisations still have to do in terms of implementation, responsibilities and security strategy.
Physical access control as an underestimated factor
The Assa Abloy workshop takes up an important aspect that is often underestimated in the debate around compliance, cybersecurity and resilience: security concepts remain full of gaps if they focus solely on networks, endpoints and processes, but not on doors, entry points and real-world infrastructure.
Contrary to the widespread assumption, NIS2 also places strong requirements on physical access control. Looking at digital risks in isolation therefore falls short. Wherever availability, protection of critical areas and traceable access control are decisive, holistic strategies must be developed that consider IT security, organisation and physical protection together.
Workshop: integrating digital and physical security
On 12 May at 11:45 a.m., Business Development Managers Miriem Ajouri and Felix Steinhausen will demonstrate in their workshop how digital and physical security worlds can be connected in a tamper-proof, scalable and compliant way using electronic locking systems. The title of the workshop sums up the core message: "When attackers come through the door, no firewall will help: why physical security must be just as well protected as networks."
As Business Development Manager at Assa Abloy, Miriem Ajouri is responsible for the industry segment, while Felix Steinhausen looks after the critical infrastructure security segment together with colleagues from the Assa Abloy KRITIS team. Following the one-hour presentation in Room 3 and throughout the trade fair days, both speakers will be available on site to answer questions.
Practical relevance for companies
The importance of a holistic security strategy becomes particularly clear when you look at real-world threat scenarios. Cybercriminals have long since stopped using only digital attack vectors and also attempt to penetrate companies via physical entry points. Modern access control systems can play an important role here, not only regulating physical access but also supporting digital security processes.
For companies affected by NIS-2, this means in concrete terms: they must expand their security concepts and take both digital and physical components into account. This applies in particular to critical infrastructure, where the protection of sensitive areas is of decisive importance.
Outlook: holistic security as the standard
The NIS-2-Congress 2026 makes clear that the understanding of cybersecurity is changing. The strict separation between IT security and physical security is increasingly being dissolved. Instead, the focus is shifting to integrated solutions that link the two areas.
For the security industry, this means new opportunities but also new challenges. Providers of access control systems must increasingly be able to integrate their solutions into larger security ecosystems. At the same time, they have to meet the compliance requirements of NIS-2 while taking both technical and organisational measures into account.
The Assa Abloy workshop at the NIS-2-Congress is a prime example of how this integration can succeed and what practical steps companies need to take to adapt their security strategy accordingly.