Mercury Security has unveiled its 2026 Trends in Access Controllers Report, highlighting increased emphasis on the role of controllers in physical access control systems.
The report explores how shifting cybersecurity demands, interoperability, cloud integration, and emerging technology trends are influencing long-term strategies for access control hardware. Conducted through a global survey of 561 professionals in the security and cybersecurity sectors, the findings indicate that 78% now deem controllers crucial to their physical access control system (PACS) strategies, rising from 72% in 2025. This shift underscores an expanding function of controllers in integrating various systems and devices within the security landscape.
Data protection standards
One of the significant insights from the report is a notable gap between the cybersecurity needs of organisations and their current infrastructure. The number of respondents indicating a lack of cybersecurity features in their controllers has increased from 21% in 2025 to 32% in 2026.
Despite this, 86% of organisations are actively updating their cybersecurity measures
Despite this, 86% of organisations are actively updating their cybersecurity measures, although 74% find coordination with IT management more complex. Steve Lucas, Vice President of Sales at Mercury Security, explained, "Organisations recognise the cybersecurity risks facing connected access control systems, but the infrastructure in place isn’t always keeping pace." He emphasised the importance of interoperability and selecting adaptable controller platforms that can meet current and future security challenges.
Driving controller purchases
The report reveals that 69% of respondents consider interoperability a critical aspect of controller procurement, and 82% stress the importance of backward and forward compatibility in infrastructure planning.
This suggests a trend towards gradual modernisation that safeguards existing investments. Furthermore, mobile credential integration is becoming increasingly important, with 50% of professionals using or planning to use mobile solutions and 46% identifying it as a key purchasing factor.
Cloud Demand and Advanced Capabilities
Cloud connectivity continues to be a significant driver behind controller purchases
Cloud connectivity continues to be a significant driver behind controller purchases, with interest increasing from 50% in 2025 to 56% in 2026. Despite this growth in demand, only 41% report having cloud-enabled controllers, and 26% state their systems currently lack this capability, pointing to a gap between interest and infrastructure readiness.
As new technologies advance, additional requirements for infrastructure arise. The interest in capabilities such as behavioural analysis and anomaly detection grew to 56% from the previous year, while facial recognition was noted by 60%. Furthermore, predictive security and threat prevention are important considerations for half of the survey participants. Over 39% are venturing into edge computing, and 41% have already merged controller data with occupancy and utilisation programs, indicating that access control systems are increasingly being used beyond their traditional roles.
These findings suggest that controller selection is transitioning from straightforward hardware purchases to integral parts of long-term infrastructure planning. Organisations are now tasked with balancing the need for immediate reliability and cybersecurity against the ongoing requirement to accommodate future advancements and system integrations, all without entirely overhauling existing infrastructure.
Mercury Security, a pioneer in open architecture access control hardware and an HID brand, releases its 2026 Trends in Access Controllers Report, revealing how changing cybersecurity requirements, interoperability needs, cloud adoption and emerging technologies are putting greater emphasis on the role controllers play in long-term physical access control strategy.
Based on a global survey of 561 physical security and cybersecurity professionals, including administrators responsible for access control management, systems integrators, installers and end users, the report found that 78% of respondents consider the controller important or critical to their physical access control system (PACS) strategy, up from 72% in 2025. This growth reflects the controller's expanding role in the security environment. As it connects more devices, systems and applications across the security environment, organisations are placing greater importance on infrastructure that can address current requirements while supporting new capabilities over time.
Data protection standards
Cybersecurity represents one of the clearest gaps between respondents’ requirements and their existing infrastructure. 32% say cybersecurity features are missing from their current controller systems, up from 21% in 2025. The gap comes as 74% reported cybersecurity and IT coordination have become more complex to manage, even as 86% say their organisations actively work to stay current with changing cybersecurity and data protection standards.
“Organisations recognise the cybersecurity risks facing connected access control systems, but the infrastructure in place isn’t always keeping pace,” said Steve Lucas, Vice President, Sales, Mercury Security. “As they look to modernise, users also want to protect existing investments. That makes interoperability increasingly important and puts more weight on choosing controller platforms that can address current security requirements while providing the flexibility to support what comes next.”
Driving controller purchases
Additional findings from the report include:
Interoperability influences purchasing
69% of respondents identified interoperability as a critical factor in controller procurement, while 82% said backward and forward compatibility is important to future infrastructure planning. The findings point to a preference for gradual modernisation that protects existing investments while giving organisations the flexibility to adopt new capabilities over time.
Mobile credentials are influencing those decisions as well, with half of respondents already using or planning to adopt mobile solutions and 46% ranking mobile credential integration among the trends driving controller purchases.
Cloud demand is growing faster than deployment
Cloud connectivity ranked among the leading factors influencing controller purchases, cited by 56% of respondents, up from 50% in 2025. However, only 41% reported that their controllers are currently cloud-enabled, and 26% said cloud enablement is missing from their existing systems. The findings suggest interest in cloud capabilities is growing faster than current infrastructure can support them.
AI and advanced capabilities add new infrastructure demands
Behavioural analysis and anomaly detection rose from 44% in 2025 to 56% in 2026, while facial recognition was cited by 60%, and predictive security and threat prevention by 50%. As these applications advance, processing power, storage, connectivity, cybersecurity and integration architecture are becoming greater considerations in controller selection.
More than 39% of respondents are also exploring or have adopted edge computing within their security ecosystems, while 41% have integrated controller data with building occupancy and utilisation programs, demonstrating how access control infrastructure can increasingly support applications beyond traditional door control.
Taken together, the findings show how controller selection is evolving from a hardware purchase into a longer-term infrastructure strategy. Organisations are balancing immediate priorities such as reliability and cybersecurity with the need to support future technologies, integrate with surrounding systems and modernise without replacing infrastructure all at once.