Two words get used interchangeably on almost every project, and they are not interchangeable. One of them describes a door that opens when the building loses power. The other describes a door that does not. Getting it backwards on the wrong opening is how a security decision becomes a life-safety incident.
What the words mean
Fail-safe and fail-secure describe exactly one thing: the state of the locking hardware when electrical power is removed from it.
- Fail-safe hardware unlocks when power is removed. It is energised to lock. Power failure means the door can be opened from both sides.
- Fail-secure hardware stays locked when power is removed. It is energised to release. Power failure means the door remains locked from the outside.
That is the whole definition. Notice what it does not say. It says nothing about whether people can get out, nothing about fire, nothing about whether the door is safe. The word “safe” in fail-safe refers to the asset being accessible, not to the occupants being protected — which is precisely why the term misleads people who are meeting it for the first time in a submittal.
The confusion has a cost. A stairwell door specified fail-secure because “secure sounds more secure” can trap people on a landing during an evacuation. A server room door specified fail-safe because “safe sounds safer” unlocks itself during exactly the power event an intruder might have caused. Both mistakes are common, and both are made by people acting in good faith on the plain English meaning of the words.
Egress is a third idea
Here is the thing that resolves most of the confusion: on the vast majority of doors, getting out has nothing to do with the electronics at all.
From inside a space, a person must be able to leave. In normal design that is guaranteed mechanically — a lever, a panic bar, an exit device whose latch retracts when someone pushes it, regardless of what the access control panel thinks, regardless of whether the building has power, regardless of whether the person has a credential or knows anything about the system. Electrified hardware on such a door controls entry from the outside; it does not control the way out.
So for a typical office, storeroom or tenant door with an electric strike and a lever on the inside, the fail-safe versus fail-secure question is genuinely only about what happens to entry in a power cut. Egress is already handled, and it is handled by ironmongery, not by software.
The exceptions are the doors where the electronics are in the egress path: electromagnetic locks, electrified hardware with no mechanical release on the secure side, delayed-egress devices, controlled-egress arrangements in certain healthcare settings, and turnstiles or portals. On those, the design has to guarantee release, and it has to guarantee it in the ways the codes prescribe.
Fire-rated doors and magnetic locks
Two categories of opening take the decision out of your hands.
Fire-rated door assemblies have to latch positively so the leaf stays shut and the assembly performs as tested. A fail-safe electric strike, which releases the latch when power is lost, is generally incompatible with that requirement — a fire is exactly the event that takes the power out. On rated openings the usual answer is fail-secure hardware, with egress provided mechanically from the inside. The assembly, its label and what may be field-modified are governed by NFPA 80, and the answer is not a matter of preference.
Electromagnetic locks are inherently fail-safe — they hold only while energised — and they hold the door shut without latching it. Because the electronics sit directly in the egress path, codes attach conditions: release on loss of power, release on fire alarm activation, and a release initiated by the occupant at the door itself. The governing documents are NFPA 101 and the International Building Code, with the fire alarm interface under NFPA 72.
A caution about section numbers: the provisions covering access-controlled and electrically locked egress doors have been renumbered and reorganised between editions, and jurisdictions adopt on their own schedule. Cite the document and the edition your Authority Having Jurisdiction has adopted, and confirm the arrangement with them before installation rather than after. A number copied from a forum post about a different code cycle is worse than no citation at all.
Deciding door by door
Work through four questions for each opening, in order. They resolve nearly every case.
- Is this door in a required means of egress, and is the electronics in the way out? If yes, the life-safety requirements decide the answer and the security preference does not get a vote. Get the AHJ’s position in writing.
- Is the assembly fire-rated? If yes, it must latch. That normally means fail-secure hardware, with mechanical egress.
- What is the failure you are actually protecting against? A power cut that locks staff out of a plant room at three in the morning is a real operational cost. A power cut that unlocks a records room is a real security cost. Name which one matters here.
- What happens in the window before standby power engages? A door backed by a battery or a generator behaves differently in a short outage than in a long one. Decide what the door does at minute one and at hour six.
Two practical patterns fall out of this. Perimeter and sensitive interior doors are usually fail-secure, with mechanical egress from inside and a key override for emergency services. Doors where being locked out creates a safety or operational hazard — some plant rooms, some interlocks, some doors on a refuge path — are usually fail-safe, with the security compensated by other means. Neither pattern is a rule; both are starting points for a conversation that ends with a named decision.
Write the reason down
The deliverable that prevents all of this from unravelling is a door-by-door matrix: one row per opening, with the lock type, the locking mode, the reason for that mode, the egress method, the fire alarm interface if any, the alarms and the access groups. It is the most-read sheet in a security package and the one most often produced last.
The “reason” column earns its place after an incident. When somebody asks in six months why the loading dock door unlocked during the outage, the answer should be a line of text written by a named person during design, not a reconstruction by whoever is still employed. That column is also what makes a later change safe: you can tell whether the original reason still applies.
If you want the whole opening covered rather than just the locking mode, the printable door schedule checklist walks all six areas — the opening, hardware, electronics, power and pathway, life safety, and acceptance — one line at a time. And the chain from credential to lock is laid out in Access control fundamentals.
Who wrote this, and what we sell. LA CCTV Supply provides security consulting and system design, sells the equipment and trains your people. We are not an installing contractor: installation is performed by your licensed contractor, except for small non-permitted work under $1,000 all-inclusive, which we can handle directly.
Nothing above is legal, code or accreditation advice. Requirements for your project are set by your Authority Having Jurisdiction, your engineer of record, your contracting officer or your Accrediting Official — and where a figure depends on your building, we have said so rather than inventing one.
