Access control · Comparison guide

Fail Safe vs. Fail Secure: What Your Door Does When Power Drops

Fail-safe hardware unlocks from the secure side when power is removed; fail-secure hardware stays locked. Egress-side behavior is separate and must remain free in either configuration.

Low-voltage door release hardware detail at a Bay Area commercial opening.
Field contextThe fail state of an opening lives in its release hardware and how that hardware is powered and configured.
Quick answer

Fail safe and fail secure describe what an electrified lock does on its secure or outside side when power is removed. Fail-safe hardware unlocks; a maglock is the classic example because power is the only thing holding it closed. Fail-secure hardware stays locked from outside, and many electric strikes are ordered or configured this way. Neither term describes the egress side, because occupants must still exit freely under either configuration. To confirm what an opening actually has, predict the behavior, then have a qualified technician remove power and test both sides of the door.

Key takeaways

  • Fail safe means unlocked from the secure side without power; fail secure means locked from the secure side without power.
  • The fail state describes the outside of the door, not the egress side; free egress must survive both configurations.
  • A maglock is fail safe by design, because power is what holds the armature to the magnet.
  • Many electric strikes and electrified locks are available in either configuration, so the installed setup decides the behavior, not the hardware family.
  • Predict the power-loss behavior first, then verify it with a controlled power-off test from both sides of the door.
  • On fire-rated, egress, and special locking openings, the approved plans, product listings, adopted code, and authority having jurisdiction decide the fail state.

Definitions

What do fail safe and fail secure actually mean?

Both terms answer one question: when the electrified locking hardware loses power, what happens on the secure or outside side of the door? Fail-safe hardware is unlocked from the secure side when power is removed. Fail-secure hardware is locked from the secure side when power is removed, and inside egress is generally still free.

Another way to hold the distinction: fail-safe hardware requires power to stay locked, and fail-secure hardware requires power to unlock. A magnetic lock only grips while energized, so it is inherently fail safe. An electric strike that keeps its keeper fixed until a release signal arrives is operating fail secure.

The terms describe the locking hardware, not the door, the reader, or the access system as a whole. One building can correctly contain both behaviors a few feet apart, because each opening carries its own approved design. Treating fail safe and fail secure as a building-wide setting, rather than a per-opening property, is where most confusion starts.

Reference side

The fail state describes the secure side, not the egress side.

The most common mistake property teams make with these terms is assuming that fail secure means people could be locked inside during an outage. The fail state is defined from the secure or outside side of the door. It does not automatically describe what happens on the egress side, where levers, push pads, exit devices, or request-to-exit sensors are expected to allow free exit whether or not power is present.

A fail-secure storefront entry, for example, keeps the outside leaf locked during a power outage while the interior hardware still retracts the latch mechanically. A fail-safe maglock releases entirely, changing behavior on both sides at once. Those are very different outcomes for security, and neither one is a statement about whether occupants can leave.

Keeping the two sides separate is what makes conversations with installers and inspectors precise. An opening can be correct on one side and wrong on the other, and only a question that names the side will surface which is which.

Hardware map

How does each common electrified lock behave when power drops?

Hardware family narrows the expected behavior, but the ordered configuration and the installed wiring decide it. Use typical behavior as a starting prediction, never as the final answer.

Typical power-loss behavior of common electrified locking hardware
HardwareTypical fail stateWhat to confirm at the opening
Magnetic lockFail safe. Power holds the door-mounted armature against the frame-mounted magnet, so removing power releases the openingThat every approved release path works, that the door swings freely after release, and that the release sequence is documented
Electric strikeConfigurable. Many models are ordered or field-set as fail secure, and voltage, current, duty, and fail state are selection decisionsThe installed configuration, that the door closes and latches with power off, and that the keeper releases cleanly on command without preload
Electrified lockset or exterior trimAvailable in both configurations. The solenoid or motor lives in the lock or trim rather than the frameHanding and function, whether a mechanical key override applies, and that inside egress operates independently of power
Power supply with battery backupDelays the fail state rather than changing it. The approved power-loss behavior still applies once backup is exhaustedBackup capacity, which openings the supply serves, and whether a fire-alarm interface removes power intentionally

Selection

Which openings call for fail safe, and which call for fail secure?

Perimeter and exterior entries

These openings are often specified fail secure so that a neighborhood outage does not unlock the building from outside. The egress-side hardware continues to let occupants out mechanically, which is why the fail state and the exit path can be decided independently.

Maglock-controlled openings

A maglock is fail safe by nature, so choosing one is choosing that behavior. What still needs deliberate design is the release logic around it: request-to-exit devices, access-granted timing, fire and life-safety interfaces, and power loss all form one approved sequence.

Fire-rated openings

A rated door must close completely and positively latch, so its locking arrangement is typically designed to keep the latch engaged regardless of power. Component listings, the opening's label, and the approved documents control what may be installed or changed there.

Special locking arrangements

Delayed egress and sensor-release arrangements are permitted only where the adopted code, the approved plans, and the authority having jurisdiction allow them. On these openings the fail state is part of an approved design, not a preference a service visit can change.

Verification

How do you verify what is actually installed?

Labels, invoices, and memories drift; the installed behavior is the fact. A short verification pass answers four questions about any electrified opening.

  • Predict first. Before anyone removes power, have the installer or service provider state what the secure side and the egress side should each do. A confident, specific prediction is itself evidence of a documented design.
  • At rest: is the door secure and is the reported status correct at the controller?
  • Valid access: does the lock release for the intended time when a credential is accepted?
  • Free egress: can occupants exit without a key, special knowledge, or special effort?
  • Power loss: with power removed under controlled conditions, does the opening assume the approved fail state, tested from both sides of the door?
  • For a fail-secure strike, confirm the door still closes and latches with power off; for a maglock, confirm the door releases and swings freely.
  • Coordinate before testing openings tied to fire alarms, rated assemblies, or special locking arrangements, and record the results with photos in the opening's file.

System behavior

Power loss is a designed event, not an accident.

In a healthy access control system, the power supply is a deliberate node with a specified voltage, current budget, and backup arrangement. Battery backup does not make the fail state irrelevant; it postpones the moment the fail state applies. An opening that must be correct at that moment has to be designed for it, not discovered during the first sustained outage.

Power removal is also used on purpose. Fire and life-safety interfaces are commonly designed to cut lock power so that fail-safe hardware releases as part of an approved sequence. That is the system working as intended, which is why bypassing a release device or improvising the sequence is never an acceptable field fix.

Decisions about which fail state an opening should have belong to the approved plans, the product listings and manufacturer instructions, the adopted code, and the authority having jurisdiction. A property team's role is to know what was approved, verify that the installed behavior matches it, and stop and escalate when the two disagree.

Common questions

Questions about fail-safe and fail-secure hardware

Is fail secure dangerous in a fire?

Not when the opening is designed correctly, because the fail state describes the outside of the door. The egress side uses mechanical hardware or an approved release sequence that lets occupants exit without power. What matters is verifying that free egress and any required alarm-interface release actually work, under the adopted code and the authority having jurisdiction.

Is a maglock fail safe or fail secure?

A maglock is fail safe. It is a two-piece assembly in which power holds the door-mounted armature against the frame-mounted magnet, so removing power releases the opening on both sides. Because of that, every maglock opening depends on a documented set of release paths, including normal egress, access-granted release, fire and life-safety release, and power loss.

Can an electric strike be changed from fail secure to fail safe?

Many models are ordered in either configuration or can be field-converted, but the change is not a casual one. The manufacturer's current documentation, the product listing, and the opening's requirements control. On a fire-rated opening the door must positively latch, so fail-state changes there require verification against the label and approvals rather than a preference at the door.

Does battery backup mean the fail state never matters?

No. Backup power delays the fail state; it does not change it. Once batteries are exhausted, the opening assumes its designed power-loss behavior, and some systems intentionally remove lock power on a fire-alarm signal regardless of backup. The approved behavior has to be correct at that moment, which is why it is tested rather than assumed.

Who decides whether an opening should be fail safe or fail secure?

The approved plans and hardware schedule, the product listings and manufacturer instructions, the adopted code, and the authority having jurisdiction. Property teams choose priorities, such as keeping a perimeter locked during outages, but rated, egress, and special locking openings carry requirements that override preference. When documentation is unclear, the right move is to verify before changing anything.

Elwin technician servicing an access control panel at a Bay Area property.
Field practiceElwin verifies the fail state at the opening, not on the spec sheet. When Elwin scopes access control work at Bay Area properties, the power-off behavior of each electrified opening is predicted first, then tested from both sides under controlled conditions. Openings that touch fire, egress, or special locking requirements are documented and coordinated before any configuration changes are proposed.

Sources and further reading

These references support the general technical guidance. The right answer for a specific opening still depends on the property and the authorities responsible for the project.

  1. Allegion: Fail Safe vs. Fail Secure hardware explainer
  2. Allegion: Door Hardware 101 education article
  3. Schlage: M450/M452 electromagnetic lock product information
  4. Schlage: PS906 power supply product information
  5. Securitron (ASSA ABLOY): XMS request-to-exit motion sensor product information

Bring the opening into one clear scope.

Elwin reviews the doors, hardware, wiring, system conditions, and operating needs before recommending the work.