Key takeaways
- Fail safe means unlocked from the secure side without power; fail secure means locked from the secure side without power.
- The fail state describes the outside of the door, not the egress side; free egress must survive both configurations.
- A maglock is fail safe by design, because power is what holds the armature to the magnet.
- Many electric strikes and electrified locks are available in either configuration, so the installed setup decides the behavior, not the hardware family.
- Predict the power-loss behavior first, then verify it with a controlled power-off test from both sides of the door.
- On fire-rated, egress, and special locking openings, the approved plans, product listings, adopted code, and authority having jurisdiction decide the fail state.
Definitions
What do fail safe and fail secure actually mean?
Both terms answer one question: when the electrified locking hardware loses power, what happens on the secure or outside side of the door? Fail-safe hardware is unlocked from the secure side when power is removed. Fail-secure hardware is locked from the secure side when power is removed, and inside egress is generally still free.
Another way to hold the distinction: fail-safe hardware requires power to stay locked, and fail-secure hardware requires power to unlock. A magnetic lock only grips while energized, so it is inherently fail safe. An electric strike that keeps its keeper fixed until a release signal arrives is operating fail secure.
The terms describe the locking hardware, not the door, the reader, or the access system as a whole. One building can correctly contain both behaviors a few feet apart, because each opening carries its own approved design. Treating fail safe and fail secure as a building-wide setting, rather than a per-opening property, is where most confusion starts.
Reference side
The fail state describes the secure side, not the egress side.
The most common mistake property teams make with these terms is assuming that fail secure means people could be locked inside during an outage. The fail state is defined from the secure or outside side of the door. It does not automatically describe what happens on the egress side, where levers, push pads, exit devices, or request-to-exit sensors are expected to allow free exit whether or not power is present.
A fail-secure storefront entry, for example, keeps the outside leaf locked during a power outage while the interior hardware still retracts the latch mechanically. A fail-safe maglock releases entirely, changing behavior on both sides at once. Those are very different outcomes for security, and neither one is a statement about whether occupants can leave.
Keeping the two sides separate is what makes conversations with installers and inspectors precise. An opening can be correct on one side and wrong on the other, and only a question that names the side will surface which is which.
Hardware map
How does each common electrified lock behave when power drops?
Hardware family narrows the expected behavior, but the ordered configuration and the installed wiring decide it. Use typical behavior as a starting prediction, never as the final answer.
| Hardware | Typical fail state | What to confirm at the opening |
|---|---|---|
| Magnetic lock | Fail safe. Power holds the door-mounted armature against the frame-mounted magnet, so removing power releases the opening | That every approved release path works, that the door swings freely after release, and that the release sequence is documented |
| Electric strike | Configurable. Many models are ordered or field-set as fail secure, and voltage, current, duty, and fail state are selection decisions | The installed configuration, that the door closes and latches with power off, and that the keeper releases cleanly on command without preload |
| Electrified lockset or exterior trim | Available in both configurations. The solenoid or motor lives in the lock or trim rather than the frame | Handing and function, whether a mechanical key override applies, and that inside egress operates independently of power |
| Power supply with battery backup | Delays the fail state rather than changing it. The approved power-loss behavior still applies once backup is exhausted | Backup capacity, which openings the supply serves, and whether a fire-alarm interface removes power intentionally |
Selection
Which openings call for fail safe, and which call for fail secure?
Perimeter and exterior entries
These openings are often specified fail secure so that a neighborhood outage does not unlock the building from outside. The egress-side hardware continues to let occupants out mechanically, which is why the fail state and the exit path can be decided independently.
Maglock-controlled openings
A maglock is fail safe by nature, so choosing one is choosing that behavior. What still needs deliberate design is the release logic around it: request-to-exit devices, access-granted timing, fire and life-safety interfaces, and power loss all form one approved sequence.
Fire-rated openings
A rated door must close completely and positively latch, so its locking arrangement is typically designed to keep the latch engaged regardless of power. Component listings, the opening's label, and the approved documents control what may be installed or changed there.
Special locking arrangements
Delayed egress and sensor-release arrangements are permitted only where the adopted code, the approved plans, and the authority having jurisdiction allow them. On these openings the fail state is part of an approved design, not a preference a service visit can change.
Verification
How do you verify what is actually installed?
Labels, invoices, and memories drift; the installed behavior is the fact. A short verification pass answers four questions about any electrified opening.
- Predict first. Before anyone removes power, have the installer or service provider state what the secure side and the egress side should each do. A confident, specific prediction is itself evidence of a documented design.
- At rest: is the door secure and is the reported status correct at the controller?
- Valid access: does the lock release for the intended time when a credential is accepted?
- Free egress: can occupants exit without a key, special knowledge, or special effort?
- Power loss: with power removed under controlled conditions, does the opening assume the approved fail state, tested from both sides of the door?
- For a fail-secure strike, confirm the door still closes and latches with power off; for a maglock, confirm the door releases and swings freely.
- Coordinate before testing openings tied to fire alarms, rated assemblies, or special locking arrangements, and record the results with photos in the opening's file.
System behavior
Power loss is a designed event, not an accident.
In a healthy access control system, the power supply is a deliberate node with a specified voltage, current budget, and backup arrangement. Battery backup does not make the fail state irrelevant; it postpones the moment the fail state applies. An opening that must be correct at that moment has to be designed for it, not discovered during the first sustained outage.
Power removal is also used on purpose. Fire and life-safety interfaces are commonly designed to cut lock power so that fail-safe hardware releases as part of an approved sequence. That is the system working as intended, which is why bypassing a release device or improvising the sequence is never an acceptable field fix.
Decisions about which fail state an opening should have belong to the approved plans, the product listings and manufacturer instructions, the adopted code, and the authority having jurisdiction. A property team's role is to know what was approved, verify that the installed behavior matches it, and stop and escalate when the two disagree.
Common questions
Questions about fail-safe and fail-secure hardware
Is fail secure dangerous in a fire?
Not when the opening is designed correctly, because the fail state describes the outside of the door. The egress side uses mechanical hardware or an approved release sequence that lets occupants exit without power. What matters is verifying that free egress and any required alarm-interface release actually work, under the adopted code and the authority having jurisdiction.
Is a maglock fail safe or fail secure?
A maglock is fail safe. It is a two-piece assembly in which power holds the door-mounted armature against the frame-mounted magnet, so removing power releases the opening on both sides. Because of that, every maglock opening depends on a documented set of release paths, including normal egress, access-granted release, fire and life-safety release, and power loss.
Can an electric strike be changed from fail secure to fail safe?
Many models are ordered in either configuration or can be field-converted, but the change is not a casual one. The manufacturer's current documentation, the product listing, and the opening's requirements control. On a fire-rated opening the door must positively latch, so fail-state changes there require verification against the label and approvals rather than a preference at the door.
Does battery backup mean the fail state never matters?
No. Backup power delays the fail state; it does not change it. Once batteries are exhausted, the opening assumes its designed power-loss behavior, and some systems intentionally remove lock power on a fire-alarm signal regardless of backup. The approved behavior has to be correct at that moment, which is why it is tested rather than assumed.
Who decides whether an opening should be fail safe or fail secure?
The approved plans and hardware schedule, the product listings and manufacturer instructions, the adopted code, and the authority having jurisdiction. Property teams choose priorities, such as keeping a perimeter locked during outages, but rated, egress, and special locking openings carry requirements that override preference. When documentation is unclear, the right move is to verify before changing anything.

Sources and further reading
These references support the general technical guidance. The right answer for a specific opening still depends on the property and the authorities responsible for the project.
