Division 08

Fail Safe vs Fail Secure: The Electrified Hardware Decision the Schedule Won't Make for You

Manoj TiwariJuly 9, 20268 min read

Fail safe hardware unlocks when power is lost. Fail secure hardware stays locked when power is lost. Those two sentences are the whole vocabulary lesson — and almost none of the decision. The decision is about what should happen at one specific opening during the worst ten minutes of that building's year, and it is the single most common thing an electrified hardware line on a schedule fails to justify.

What do fail safe and fail secure actually mean?

The terms describe one thing only: the locked state of the hardware when its power supply drops.

Power ON Power LOST
Fail safe Locked (energized to stay locked) Unlocked
Fail secure Unlocked only when signaled Locked

Fail safe lets people through when the lights go out — into shelter, into a stairwell, back into a floor. It also lets anyone through every time power flickers.

Fail secure keeps the opening protected during an outage. It also keeps out the people who may urgently need to get in — or keeps occupants from re-entering the building they just evacuated.

Same door. Opposite defaults. Both are routinely specified, and both are correct — for different contexts.

Which products can even be one or the other?

Part of the confusion is that the choice doesn't exist uniformly across product families:

  • Electromagnetic locks are fail safe by physics. A maglock holds only while energized. Cut power and it releases. There is no fail secure maglock; if the schedule implies one, something upstream is wrong.
  • Electric strikes can be either. The keeper is spring-loaded one way or the other; you order the mode explicitly.
  • Electrified lever trim and electrified mortise locks can be either. This is where most schedule ambiguity lives, because the mode is one suffix among many in a long configured part number.
  • Electric latch retraction (EL) exit devices are effectively fail secure from the outside — power retracts the latch; no power means the latch stays projected — while egress from the inside stays free and mechanical, always.

That last point deserves its own sentence, because it is the most common misreading in the field: fail safe vs fail secure is about entry, not egress. Life-safety codes require free egress from the inside regardless of mode. A fail secure lock on an exit door does not trap anyone inside; the panic hardware or lever always works from the egress side. The mode only governs whether someone outside the door can get through it when power is gone.

When is fail safe the right answer?

The classic driver is re-entry. High-rise codes commonly require that occupants who enter a stairwell during an emergency can leave it again — onto a floor, not just at the ground level — so stairwell doors with electrified trim are typically fail safe: alarm or power loss unlocks them from the stair side. A stairwell full of smoke with locked doors on every level is the scenario the requirement exists to prevent.

The second driver is shelter. Doors where people outside may need to get in during an emergency — lobby entries in severe-weather regions, campus buildings that serve as refuge points — get specified fail safe so a power outage doesn't strand people outside.

The cost of fail safe is that security disappears exactly when the building is most chaotic. Every brownout is an unlocked door.

When is fail secure the right answer?

Almost everywhere the concern is what a power outage would otherwise open. Perimeter doors, stockrooms, server rooms, pharmacies, records rooms — anywhere an outage should not become an invitation. Fail secure is also the default answer where the owner's insurance or security policy assumes doors stay locked unattended.

The cost of fail secure is the mirror image: the person with a legitimate, urgent need to get in — a responder, a resident, an employee sheltering from weather — meets a locked door until someone restores power or arrives with a key. (Mechanical key override is not an optional nicety on fail secure openings; it is the contingency plan.)

The fail-safe strike that almost voided a fire rating: the hardware schedule names the strike, the fire-alarm matrix names the trigger, and nobody owns what the latch does in a fire — on a fire door the latch must stay engaged, and fail-safe releases it

Why the schedule won't tell you

Lori Greene posted a photo on iDigHardware that makes the point better than any paragraph: a panic device with fail safe lever trim — and a chain wrapped around the door. Her question: "Why is the lever trim fail safe? Why not fail secure?" The hardware was doing exactly what the schedule called for. Somebody in the field disagreed with the schedule strongly enough to reach for a chain.

In the comments, a contractor described a college dormitory whose lobby was specified fail secure — until a hurricane knocked out power during construction and students got locked out of an adjacent building. The team flipped the spec to fail safe so people could shelter. Two opposite specs on the same kind of door, both internally consistent, both wrong for the context that came next.

An internally consistent schedule line is not the same thing as a justified one. The mode arrives encoded as a suffix — a couple of characters in a seventeen-field part number — with no trace of why. Review processes that check "is this a valid, orderable configuration?" will pass a fail safe suffix that should have been fail secure every single time, because both are valid and both are orderable.

The questions to ask before the PO goes out

For every electrified opening on the schedule, the review question is not "is this configuration valid?" but "does the failure mode match the building's plan for this door?" Concretely:

  1. What happens at this door during a power outage? Who is on each side of it, and which direction does the risk point?
  2. Is this door in a re-entry path? Stairwell and high-rise re-entry requirements typically force fail safe. Verify against the code edition and the authority having jurisdiction — not against habit.
  3. Is the mode consistent with the access-control design? A fail secure strike paired with a maglock on the same opening is a contradiction someone will discover at commissioning.
  4. Is there a mechanical override? Fail secure without a key plan is a lockout waiting for a storm.
  5. Does the fire alarm interface match the mode? Alarm-triggered unlock is a separate input from power failure; confirm which events the spec intends to unlock the door, and whether the hardware as configured does that.

The pattern behind the question

Notice what kind of problem this is. Nobody bought bad hardware. The part number was valid, the configuration orderable, the installation correct. What failed was a piece of context — why this mode, at this door, in this building — that never traveled with the schedule line.

Most expensive Division 08 errors have this shape. The information existed at specification time, got compressed into a suffix, and the suffix outlived the reasoning. A senior estimator catches it by asking the same question Lori asked, reflexively, at every electrified opening. That reflex is exactly the kind of check that should run on every line of every schedule — which is what we build at Conversant: review that asks the expert's questions at estimating time, so the mismatch surfaces before fabrication instead of during the inspection walk, or worse, as a chain around a panic device.