Based on a global survey of 561 physical security and cyber security professionals, including administrators responsible for access control management, systems integrators, installers and end users, the report found that 78% of respondents consider the controller important or critical to their physical access control system (PACS) strategy, up from 72% in 2025. This growth reflects the controller's expanding role in the security environment. As it connects more devices, systems and applications across the security environment, organizations are placing greater importance on infrastructure that can address current requirements while supporting new capabilities over time.
Cyber security represents one of the clearest gaps between respondents’ requirements and their existing infrastructure. 32% say cyber security features are missing from their current controller systems, up from 21% in 2025. The gap comes as 74% reported cyber security and IT coordination have become more complex to manage, even as 86% say their organisations actively work to stay current with changing cyber security and data protection standards.
“Organisations recognise the cyber security risks facing connected access control systems, but the infrastructure in place isn’t always keeping pace,” said Steve Lucas, Vice President, Sales, Mercury Security. “As they look to modernise, users also want to protect existing investments. That makes interoperability increasingly important and puts more weight on choosing controller platforms that can address current security requirements while providing the flexibility to support what comes next.”
Additional findings from the report include:
Interoperability influences purchasing
69% of respondents identified interoperability as a critical factor in controller procurement, while 82% said backward and forward compatibility is important to future infrastructure planning. The findings point to a preference for gradual modernisation that protects existing investments while giving organisations the flexibility to adopt new capabilities over time.
Mobile credentials are influencing those decisions as well, with half of respondents already using or planning to adopt mobile solutions and 46% ranking mobile credential integration among the trends driving controller purchases.
Cloud demand is growing faster than deployment
Cloud connectivity ranked among the leading factors influencing controller purchases, cited by 56% of respondents, up from 50% in 2025. However, only 41% reported that their controllers are currently cloud-enabled, and 26% said cloud enablement is missing from their existing systems. The findings suggest interest in cloud capabilities is growing faster than current infrastructure can support them.
AI and advanced capabilities add new infrastructure demands
Behavioural analysis and anomaly detection rose from 44% in 2025 to 56% in 2026, while facial recognition was cited by 60%, and predictive security and threat prevention by 50%. As these applications advance, processing power, storage, connectivity, cyber security and integration architecture are becoming greater considerations in controller selection.
More than 39% of respondents are also exploring or have adopted edge computing within their security ecosystems, while 41% have integrated controller data with building occupancy and utilisation programmes, demonstrating how access control infrastructure can increasingly support applications beyond traditional door control.
Taken together, the findings show how controller selection is evolving from a hardware purchase into a longer-term infrastructure strategy. Organisations are balancing immediate priorities such as reliability and cyber security with the need to support future technologies, integrate with surrounding systems and modernise without replacing infrastructure all at once.


















