What's new?

SicherheitsExpo München 2026: What We Saw, What We Learned, What's Next

A recap of SicherheitsExpo München 2026: NIS2, self-service kiosks, IDfunction Check-in connected live to IDfunction PIAM, and CTO Mohsen on building PIAM systems around evidence.

Posted by
Lizelle Maas
Posted date
July 9, 2026

Two days, one stand. At times, over 20 people gathered at our stand at once. SicherheitsExpo München 2026 was a reminder of why in-person demos matter so much. Nothing communicates what a system can actually do quite like watching someone use it live and talking to the people who built it.

The technical side held up without a single hiccup across both days, so we could focus on what mattered more: the conversations. Here's what stood out.

NIS2 and KRITIS-Dachgesetz dominated the conversation

If one topic came up at nearly every stand we visited and in most presentations, it was regulatory pressure. NIS2 and the KRITIS-Dachgesetz are driving real budget and operational conversations for security teams right now. Visitors weren't asking whether they need to prepare. They were asking how fast and with what.

Self-service onboarding is becoming the standard

Self-service kiosks were all over the floor this year, including on the same hardware we use. We run IDfunction Check-in on the Pyramid Computer POLYTOUCH CURVE, and we weren't the only ones. That's good hardware, and it meant people had something to compare us against.

That's where we won. Most of what we saw was a kiosk doing check-in: verify identity, get badge, done. Ours goes a step further. Along with identity verification, we ran a liveness detector that confirms a real person stands at the device, not a photo. The kiosk connected live to IDfunction PIAM, so people could watch a new identity get onboarded in real time: profile created, information populated, and ready for access rights to be issued. We also talked through interesting use cases, including compliance and certification checks when a worker or visitor arrives at a site.

That's the part people leaned in for: someone walks up, checks in once, and the same system handles everything that matters. Who they are. Whether they're cleared. What they're actually allowed to access. All in that moment, all in one place, without three separate tools and a hope that the data lines up afterward.

That's what made people stop and ask questions. We ran out of demo slots on day one. People came back the next morning just to get five minutes with it.

CDO Florian Schön demonstrates IDfunction-Check-in.

AI is everywhere in security. Access control is the exception, so far.

One thing we noticed: AI-driven insights showed up everywhere in camera systems, image analysis, and alarm monitoring. Flagging anomalies, recognizing patterns, that kind of thing. But in physical access control specifically, AI adoption is still early. Few vendors on the floor were doing much with it in this space yet.

That's not a knock on the industry. It's a genuinely hard problem to get right in a domain where a false positive or a missed signal has real consequences. We'd rather move carefully and build trust into it than rush something out for the sake of a demo.

That said, we're not just watching from the sidelines. We've been working on something internally that uses AI to take a big chunk of the setup work off a customer's plate when a new PIAM system goes live, the kind of work that normally takes days. It's not public yet. If you were at our stand and asked what's next, this is what we were smiling about.

On the Main Stage: Mohsen on Building PIAM Systems

"Most companies can already say who has access. Few can say why. This very question, and the proof behind it, distinguishes a PIAM system that truly works from one that merely appears to."

Our CTO Mohsen also took the stage this year, walking the room through what actually goes into building a PIAM system, beyond what fits on a trade show banner. A few of the core points:

"Don't build on assumptions. Build on tested hypotheses."

This is the one sentence Mohsen keeps coming back to as the difference between a system implementation that succeeds and one that doesn't.

The hard part isn't knowing who has access. It's knowing why. Most organizations can already answer who. Very few can produce the evidence trail behind why: who invited someone, under what contract, and what justifies revoking access later.

"Unified" means the full identity lifecycle, not just one database. The system tracks digital and physical access as one continuous lifecycle across every connected system, until it becomes the ground truth other systems can rely on.

We're preparing the full interview as a separate video and will publish it here once it's ready.

CTO, Mohsen Arjmandi on the Main Stage at SicherheitsExpo Munich 2026

Looking ahead

Seeing IDfunction Check-in draw a crowd, hearing people work through NIS2 timelines out loud, and fielding real technical questions on the workflow engine all confirmed the direction we're building in. It's also a useful gut-check on where the industry still has open questions, particularly around AI in access control, which is clearly the next frontier.

CEO, Ali Gülüm presents IDfunction Production.

Next stop

SicherheitsExpo Alpe Adria in Klagenfurt this October. We will be there with a long-time partner showcasing the value of strong partnerships in the industry.

About us
For more than two decades, evolutionID has helped organizations bring clarity and control to identity and access. We focus on what matters most: secure, reliable processes that are simple to operate and built to last.

We bring together Physical Identity & Access Management (PIAM), card and employee management, and RFID‑supported workflows into one coherent approach. Our modular building blocks allow identity and access systems to adapt over time—without disrupting what already works. The result is less complexity, more transparency, and greater confidence in everyday operations.

As a long‑term partner, we guide our customers step by step—from analysis and architecture to implementation, migration, and ongoing support. With teams in Munich, Bonn, and Frankfurt, we work closely with organizations across the DACH region to create access infrastructures that stay secure, stable, and ready for what comes next.