A supermarket with 17 doors and five master keys loses one master key. The bill to rekey the building conventionally comes to about $1,068. That figure comes from the Loss Prevention Research Council’s retail lock-program survey: 25 loss-prevention members answered questions about their lock systems in fall 2018, and InstaKey, a vendor that sells rekeyable locks, published the results in July 2019 (LPRC/InstaKey survey). It is one illustrative scenario from a small, sponsored, retail-only sample. It is also the only rekeying-cost study anyone has located with a disclosed sample size and method. A facility manager in Kentucky running 40 doors, or 80, or 150, does not have a better public number to start from. This post builds one, using the reader’s own door count instead of a supermarket’s.
What one lost master key actually costs
The LPRC scenario is specific: 17 doors, five master keys, one lost master key, conventional rekeying (new cylinders and pins, not a rekeyable-core swap). The result was roughly $1,068. Nothing in the survey says how that number splits between hardware, locksmith labor, and downtime, so this piece will not guess at that breakdown.
What the survey does establish, plainly, is the trigger. Lost or stolen keys were the primary reason retail lock and rekey events happened in the first place, ahead of any other cause the survey tracked. A facility does not typically rekey because a lock wore out. It rekeys because someone can no longer account for a key that opens more than one door.
The caveats matter. Twenty-five retailers is a small sample, retail only, and seven years old. InstaKey, which distributed the results, sells rekeyable locks and has a direct interest in a study that makes conventional rekeying look expensive. None of that makes the $1,068 figure wrong. It makes it one data point, from one industry, at one point in time.
Turnover is the real driver
Keys do not lose themselves. Someone who is holding one leaves the building, changes jobs, gets terminated, or forgets where they set it down. The LPRC survey names lost or stolen keys as the trigger; staff turnover is the mechanism that puts a key in a position to be lost in the first place.
The U.S. Bureau of Labor Statistics tracks how often that happens across the whole economy. In 2024, the annual average monthly quits rate across all nonfarm industries was 2.1 percent (BLS JOLTS news release USDL-25-0331, published March 11, 2025, reporting full-year 2024 annual averages). That is a general labor-market figure, not a security statistic, and it says nothing about who was holding a master key when they walked out. But it is a reasonable baseline, and a facility manager can multiply it by headcount to get a rough sense of how many departures a year are coming.
Why most facilities can’t say how often they rekey
Here is the part of the LPRC survey that should bother a facilities manager more than the dollar figure does: most of the retailers who answered the questionnaire could not say how often they rekeyed in a given year. Not the cost, the frequency. A cost you cannot track is a cost you cannot budget for, and it gets paid anyway, invisibly, as a locksmith invoice that never rolls up into anything a manager reports on.
That is the practical argument for tracking rekey events at all, independent of whatever system a facility ends up running. If nobody can say how many times the locks changed last year, nobody can say whether this year is getting better or worse.
What credential systems change, and what they don’t
A credential-based access control system, cards, fobs, or a mobile credential on a phone, changes what happens after someone leaves. Instead of pulling cylinders and cutting new keys across a building, an administrator deactivates one credential in software. The building’s doors do not need to be touched.
That is a real difference in response, not in whether the problem exists. Credentials get lost too, and a misplaced card or an unrecovered phone still needs attention. Credential systems change the cost and speed of that response. They do not make lost credentials free, and they do not remove the need to manage who has access.
Most installed hardware is still not credential-based in the way people picture when they hear the term. Single-factor authentication, keycards and PIN pads, held 63.70 percent of the global market for these systems in 2025, per a Mordor Intelligence market-research estimate published in January 2026. That is a market-sizing model, not a survey with a disclosed sample. Mobile credentials are growing from a smaller base: 39 percent of organizations used mobile access credentials as of a survey fielded between November 2023 and January 2024, up from 32 percent in the prior version of the same report, based on 1,223 responses, in a report HID published with IFSEC Insider (State of Physical Access Trend Report 2024). IFSEC Insider stopped publishing in February 2025, and that download still requires registration. The shift is underway, not a wholesale replacement.
Why hybrid is what most buyers are choosing
Given that, the realistic move for most facilities is not a full cutover to a single cloud-based credential system on day one. It is a mixed deployment: some doors on credentials, some still keyed, decided door by door on turnover and risk rather than as an all-or-nothing conversion.
That is also what the survey data says buyers are actually planning. Among end users surveyed by Genetec between August and September 2024, 43 percent said they preferred a hybrid approach, mixing cloud and on-premise systems, over the next five years, compared with 18 percent who wanted to go fully cloud and 17 percent who planned to stay fully on-premises. Sixty-six percent of the consultants in the same survey said they would recommend hybrid to their clients. The survey included 5,696 respondents after data cleansing (Genetec, 2025 State of Physical Security Report). Hybrid was the plurality choice in that survey, not a fallback.
A worked estimate: run this on your own numbers
None of the figures above were built for a particular Kentucky facility. Here is how to turn them into something usable.
Count the doors on the property that share one master key system, meaning a lost master key for any one of them means rekeying all of them. Call that number D.
Then get an actual quote. The right way to price a conventional rekey is to call a locksmith or an integrator and ask what it costs for your door count and hardware. Absent that quote, the LPRC scenario offers a rough placeholder: $1,068 for 17 doors works out to about $62.82 per door. That is not a validated per-door rate, just one survey’s total divided evenly across its own door count. Multiply D by $62.82 and treat the result as a placeholder, not a budget figure.
For the frequency side, multiply total headcount by 0.021, then by 12, using the BLS national average quits rate (headcount x 0.021 x 12). This is a simple multiplication of a monthly rate, not a compounded figure, and it says nothing about a specific workforce. Treat it as a starting baseline, not a forecast.
Then apply what only the reader knows: what share of departing staff typically hold a master key or an all-doors credential. A small maintenance and management group might run 5 to 10 percent of departures. Looser key circulation pushes the share higher. Multiply annual departures by that share for an estimated count of master-key-holder departures per year.
Multiply that count by the per-event rekey cost for a rough annual exposure figure. As an illustration, not a real client’s numbers: a 40-door facility with 75 employees and 8 percent master-key turnover runs as follows. Per-door placeholder cost: 40 x $62.82, about $2,513. Annual departures: 75 x 0.021 x 12, about 19. Master-key-holder departures: 19 x 0.08, roughly 1.5 a year. Estimated annual exposure: 1.5 x $2,513, about $3,770 a year, before service calls short of a full rekey and before staff time spent tracking keys.
That figure is napkin math from a placeholder per-door cost and a national turnover average, not a quote. It still gives a facility something to compare against an actual quote for a credential-based system on its highest-turnover doors.
What this looks like when it’s handled well
Versys works across a range of buildings and systems, and access control for the storage industry is one of the areas the company has focused on specifically. The company runs cloud-hosted systems that keep ongoing maintenance low, and it also installs local, stand-alone hardware that carries a recurring cost instead of a cloud subscription. Which one fits depends on internet reliability, how many locations need to share one system, how much IT support is already on hand, and how the doors get used.
That two-path setup matches what the Genetec survey found about how most buyers are moving: converting the doors with the most turnover and risk first, and leaving lower-risk doors on existing hardware until there is a reason to change them. It is not a pitch for ripping out every lock at once. For a Kentucky facility still running all metal keys, the useful first step is running the numbers above on its own door count and turnover, then calling Versys at (270) 358-2200 to compare that estimate against an actual quote for the doors that matter most.
