Fail-Safe or Fail-Secure? Choosing the Right Locking Logic for Access-Controlled Doors

Power-loss behavior, free egress and fire-alarm response are separate decisions that must be coordinated at each opening.

For: access-control integrators, security consultants, door-hardware specifiers and electrical contractors | Technical review: TOPTEK Access

Fail-safe and fail-secure describe the lock’s state when control power is removed; they do not by themselves define safe egress.

TL;DR Fail-safe locking releases the controlled side when power is removed; fail-secure locking remains secured on that side. Many mortise-lock applications can still provide mechanical free egress from inside in either mode. Select the mode from code, life-safety, security and emergency-operation requirements—then test power loss, fire alarm, controller failure and manual override as separate scenarios.

The quick answer

The phrase “fail safe” sounds universally safer, but uncontrolled unlocking during every power interruption can create a serious security problem. “Fail secure” sounds more secure, but it is unacceptable where power removal is required to unlock the means of egress. The correct answer depends on the opening’s code path and operating intent.

Document three states: normal power, loss of lock power and emergency-system activation. For each state, show who can enter, who can exit, which signals are monitored and how staff regain control.

Separate entry security from egress behavior

Fail-safe and fail-secure normally describe the electrically controlled side—often the outside lever or locking element—when power is removed. Free egress describes what an occupant can do from the egress side. A properly selected mortise lock may keep the outside secure during power loss while the inside lever remains mechanically free, but that must be verified for the exact function.

Do not use the electrical label as a substitute for a function description. State whether the inside lever retracts the latch at all times, whether a deadbolt is present, and whether any credential, sensor, key or special knowledge is required to exit.

Core principle Define each side of the door in each operating state. One two-word electrical label cannot describe the complete opening.

When fail-safe may be required

Fail-safe behavior is common where the applicable code or approved design requires the lock to release upon loss of power, activation of the fire-alarm system or another life-safety event. Electromagnetic locks and certain special locking arrangements often use this logic.

The exact release path matters. Removing controller data while lock power remains present is not the same as removing lock power. The design should identify the listed power supply, relay logic, fire-alarm interface and any local release device required by the authority having jurisdiction.

When fail-secure protects the opening

Fail-secure logic keeps the controlled side locked during power loss. It can be appropriate for perimeter, storage or other security-sensitive openings when code-compliant mechanical egress remains available. The mechanical key override and emergency access plan become especially important during a prolonged outage.

Security teams should decide whether the goal is to preserve perimeter security, protect assets, prevent re-entry or maintain compartmentation. Those goals may lead to different functions at doors that look identical.

Test more failures than a power switch

Commissioning should include normal credential grant, denied credential, loss of mains power, loss of lock power, controller reboot, network loss, broken communication, fire-alarm input, request-to-exit action and mechanical key operation. Confirm both the physical door state and the event reported to the access-control system.

UL Solutions notes that access and egress locking configurations can require integration with fire detection or suppression systems, fail-safe or fail-secure features, and other code provisions. The project’s code analysis and listed product configuration—not a generic diagram—should control the final circuit.

State-by-state approval matrix

Condition Fail-safe controlled side Fail-secure controlled side
Normal authorized command Unlocks as programmed Unlocks as programmed
Loss of lock power Releases/unlocks Remains locked on controlled side
Egress-side lever Must match scheduled mechanical egress function Must match scheduled mechanical egress function
Fire-alarm activation Follow approved code sequence May need separate release logic depending on arrangement
Mechanical key override Define whether and how it operates Critical for emergency/service access
Monitoring Verify door/lock status, not command alone Verify door/lock status, not command alone

Electrified mortise-lock example: the exact mechanical function and powered state must be read together.

Fail-mode selection checklist

Identify the applicable building, fire, accessibility and security requirements.

Describe entry and egress separately for normal, power-loss and emergency states.

Confirm the exact lock function, handing and inside-lever behavior.

Define which circuit loses power and which controller/fire-alarm relay initiates it.

Check voltage, current, inrush/holding load and listed power-supply capacity.

Specify mechanical key override and emergency access responsibility.

Monitor physical door/lock condition where required—not just relay command.

Witness and record every scenario at the completed opening.

What a capable manufacturing partner should provide

TOPTEK’s electronic locks and access-control devices include ANSI and EN mortise-lock formats. Selection should be made by exact function, voltage and operating logic rather than by appearance or a generic “electric lock” description.

For a new platform, use a joint hardware-and-electrical review. TOPTEK’s electronic engineering capabilities can support interface confirmation, prototype operation and controller-side questions before site deployment.

Frequently asked questions

Does fail-secure mean occupants are locked inside during power loss?

Not necessarily. Many mortise-lock functions preserve mechanical free egress from inside while the outside remains secure. Verify the exact lock and code path.

Does a fire alarm always need to remove lock power?

Requirements depend on the locking arrangement and jurisdiction. The approved code sequence and authority having jurisdiction should determine the interface.

Is relay status proof that the door unlocked?

No. A controller command confirms intended state, not necessarily physical bolt or lever condition. Use appropriate monitoring where the risk requires it.

Integration takeaway Put the opening into a state matrix before choosing the fail mode. TOPTEK can match the required mechanical function and electrical behavior to a specific lock platform for prototype and system testing.