2026 study finds organizations placing greater importance on access controllers as cloud connectivity, AI and cybersecurity reshape physical security strategies
Organizations are placing greater strategic importance on the infrastructure supporting physical access control as cybersecurity requirements, cloud adoption, interoperability and emerging technologies continue to reshape enterprise security.
This is among the key findings of the 2026 Trends in Access Controllers Report released by Mercury Security, a global provider of open architecture access control hardware and an HID brand.
Based on a global survey of 561 physical security and cybersecurity professionals, including access control administrators, systems integrators, installers and end users, the report highlights the growing role of access controllers in connecting devices, systems and applications across modern security environments.
According to the study, 78% of respondents consider the controller important or critical to their physical access control system (PACS) strategy, up from 72% in 2025.
The findings indicate that organizations are increasingly evaluating controllers not simply as hardware components, but as part of a longer-term infrastructure strategy capable of supporting evolving security requirements and technologies.
Cybersecurity Gap Becomes More Visible
Cybersecurity emerged as one of the clearest areas where organizations see a gap between their requirements and existing infrastructure.
The report found that 32% of respondents said cybersecurity features are missing from their current controller systems, compared with 21% in 2025.
At the same time, 74% reported that cybersecurity and IT coordination have become more complex to manage. Despite these challenges, 86% said their organizations are actively working to stay current with changing cybersecurity and data protection standards.
“Organizations recognize the cybersecurity risks facing connected access control systems, but the infrastructure in place isn’t always keeping pace,” said Steve Lucas, Vice President, Sales, Mercury Security.
“As they look to modernize, users also want to protect existing investments. That makes interoperability increasingly important and puts more weight on choosing controller platforms that can address current security requirements while providing the flexibility to support what comes next,” Lucas added.
Interoperability Shapes Procurement Decisions
Interoperability is becoming a significant consideration as organizations seek to modernize their security infrastructure without necessarily replacing existing systems all at once.
69% of respondents identified interoperability as a critical factor in controller procurement, while 82% said backward and forward compatibility is important to future infrastructure planning.
The findings point toward a gradual approach to modernization, allowing organizations to preserve existing investments while introducing new technologies and capabilities over time.
Mobile credentials are also influencing procurement decisions. Half of respondents are already using or planning to adopt mobile solutions, while 46% identified mobile credential integration as one of the trends influencing controller purchases.
Cloud Adoption Outpaces Existing Infrastructure
Cloud connectivity is another area where demand appears to be moving faster than deployment.
The report found that 56% of respondents identified cloud connectivity as a leading factor influencing controller purchases, up from 50% in 2025.
However, only 41% reported that their controllers are currently cloud-enabled, while 26% said cloud enablement is missing from their existing systems.
The gap suggests that organizations increasingly recognize the potential value of cloud-connected access control, even as existing infrastructure may not yet support those capabilities.
AI Brings New Infrastructure Considerations
The growing use of artificial intelligence and advanced security applications is also influencing how organizations think about access control infrastructure.
Behavioral analysis and anomaly detection increased from 44% in 2025 to 56% in 2026 among technologies being considered. Facial recognition was cited by 60% of respondents, while predictive security and threat prevention was identified by 50%.
As these capabilities develop, access control environments may require greater consideration of processing power, storage, connectivity, cybersecurity and integration architecture.
The report also found that more than 39% of respondents are exploring or have adopted edge computing within their security ecosystems.
Meanwhile, 41% have integrated controller data with building occupancy and utilization programs, demonstrating how access control infrastructure is increasingly being used to support applications beyond conventional door access.
From Hardware Purchase to Long-Term Strategy
The findings collectively point to a broader shift in how organizations approach access control investments.
Rather than treating controllers as standalone hardware purchases, organizations are increasingly considering their role within a broader technology ecosystem—one that must accommodate cybersecurity requirements, existing systems, cloud connectivity, mobile credentials and emerging AI-powered applications.
For businesses planning modernization, the challenge is balancing immediate priorities such as reliability and cybersecurity with longer-term requirements for integration and technological flexibility.
The 2026 report underscores the importance of infrastructure that can evolve alongside an organization’s security needs, enabling businesses to modernize progressively while protecting existing investments and preparing for emerging capabilities.



