What's new?

If the certificate expires, access should also expire.

Zutritt, der an den Zertifizierungsstatus geknüpft ist. Läuft ein Sicherheitszertifikat ab, wird der Zutritt automatisch am selben Tag entzogen. Keine manuelle Nachverfolgung.

Posted by
Lizelle Maas
Posted date
July 27, 2026

In many companies, access and certification are managed in two separate places. Certification is stored in a training record, a spreadsheet, or a compliance system, while access rights reside in the access control system. The connection between the two is a person who is expected to remember to update one when the other changes.

That works, until someone gets hurt.

An example illustrates what an expired certification actually means. Someone completes radiation safety training and is granted access to a specialized lab. Two years later, the certification expires. The training record shows it as expired, but the access control system still shows the door as open. If that person enters the area and something goes wrong, the company has granted access to a hazardous area without a documented valid certification. The gap between the two systems has become a liability issue.

Certificate-based access control closes exactly this gap.

Access tied to a condition

IDfunction PIAM automatically assigns access profiles based on policies. A policy links a condition to the access profile it controls. If the condition is met, access is granted. If it is not, access remains denied.

A certificate policy is one type of these policies. It links a certificate type to the access profile it controls, so that access depends directly on the certification status. This could be a security qualification, technical training, medical clearance, or any similar requirement your company already tracks. The mechanism remains the same, regardless of the certificate type or the number of locations involved.

The crucial difference: access is no longer something a person has to grant and then revoke. It becomes a direct consequence of the certification itself.

How it works in practice

The process follows the logic you would expect if access and certification were properly connected.

The certification is stored in the individual's profile, along with its validity period and a supporting document. A certificate policy links this certificate type to the access profile it controls for one or more facilities. The access profile is activated automatically, and its validity corresponds exactly to the validity period of the certificate.

Before expiration, a configurable workflow sends reminders—early on and again shortly before the deadline—and can also notify facility or compliance managers. If the certificate is renewed, access continues without interruption. If it expires, access is automatically revoked that same day.

No manual tracking. No gap between the data record and reality.

Why this is more than just a convenience

In high-risk and critical infrastructure environments, certification is not a formality. It is proof that a company has fulfilled its legal and safety obligations before granting someone access.

A safety certification does not prove that a person performs a task correctly. It proves that the company provided the required training and verified it before granting access. This distinction is critical if something goes wrong. If an incident occurs and the person had a valid, documented certification, the company has fulfilled its duty of care. If that person was in a restricted area with an expired certification that no one had revoked, the company bears the responsibility.

Directly linking access to certification status changes where this risk lies. If a certificate expires, the person is notified in advance, and access is automatically revoked the moment the certificate loses its validity. The company no longer relies on someone manually noticing the expiration. It can prove with a complete audit trail that no access was active without a valid certification in place.

For regulated and safety-critical environments, this is not just an operational nicety. It is the difference between managed risk and uncontrolled exposure.

What actually changes

The difference is most apparent when comparing the before and after.

Currently, certificates are tracked manually across multiple facilities. Renewal reminders are handled manually or are missing entirely. There is a constant risk of an expired certification existing alongside active access. Furthermore, access updates lag behind certificate renewals because someone has to perform them manually.

With certificate-based access control, a single record manages both the certificate and access. Renewal notifications are sent automatically before expiration. Access expires automatically as soon as the certificate expires. And a renewal updates access instantly, without a second step.

Every grant, renewal, and revocation is logged in the certificate record. The audit trail is thus created as a byproduct of the system's operation, rather than something that has to be compiled after the fact.

Beyond a single certificate

The same mechanism scales to meet your requirements. Additional certificate types. Policies that span multiple facilities. Approval steps where you want them. The system can also integrate with online training services, allowing IDfunction PIAM to automatically assign the certificate and access profile as soon as someone completes a required training course.

The principle behind it remains constant: if access is tied to a qualification, it should exist with that qualification and expire with it. Not in a separate system, and not in the memory of a single person.

About us
For more than two decades, evolutionID has helped organizations bring clarity and control to identity and access. We focus on what matters most: secure, reliable processes that are simple to operate and built to last.

We bring together Physical Identity & Access Management (PIAM), card and employee management, and RFID‑supported workflows into one coherent approach. Our modular building blocks allow identity and access systems to adapt over time—without disrupting what already works. The result is less complexity, more transparency, and greater confidence in everyday operations.

As a long‑term partner, we guide our customers step by step—from analysis and architecture to implementation, migration, and ongoing support. With teams in Munich, Bonn, and Frankfurt, we work closely with organizations across the DACH region to create access infrastructures that stay secure, stable, and ready for what comes next.