Learning & Resources

State of Physical Security in the Southeast 2026

A research report for security, IT, facilities, and compliance leaders across the 12 SE states and DC. Market size, vendor map, HIPAA/CMMC/CJIS compliance, and a 10-question planning framework — sourced and defensible.

Harris Technology Services logo.

This report maps the 2026 US physical-security market for the operating leaders who own security, IT, facilities, compliance, and risk across the 12 southeastern states and the District of Columbia. It does three things the public research literature mostly leaves out: a vendor-by-vendor view of who is actually winning the cloud and on-premise races, a state-by-state compliance matrix for HIPAA, CMMC, CJIS, and breach notification, and a vertical-by-vertical view of how healthcare, federal/defense, logistics, and manufacturing are absorbing the technology shift.

Published August 2026. Sources, data, and 56 cited references are listed at the end of the report.

Synopsis

Three things stand out. First, the platform shift is real but uneven: cloud access control (ACaaS) and cloud video (VSaaS) are growing two to four times faster than the on-premise segment they are replacing, but on-premise still commands roughly 60 to 70 percent of US physical-security spend, which means the “cloud is winning” narrative is more than a decade ahead of the install base. Second, the regulatory pressure in 2026 is unusually concentrated: a final Department of Defense rule (CMMC 2.0) is now in force for every defense contractor, an updated FBI Criminal Justice Information Services Security Policy (CJIS v5.9.5 and v6.0) is sanctionable, and a proposed HIPAA Security Rule overhaul has been pushed by the administration into “Long-Term Actions” with a final rule now expected in July 2027 at the earliest, leaving the 2013 Rule in force. Third, the Southeast is a structurally attractive market: the largest US economic region by GDP, the fastest-growing population band, and a dense concentration of healthcare systems, federal installations, and logistics infrastructure that aligns with the verticals most affected by these regulatory changes.

The report ends with a deployment framework that maps these forces to ten concrete architectural and procurement decisions a security leader in the region is likely to face in the next planning cycle.

1. Market Size and Growth

The global physical security market — equipment, software, and services for video surveillance, access control, intrusion detection, and adjacent systems — is sized between roughly $120 billion and $160 billion for 2025 depending on how each research firm draws the boundary around “physical security.” MarketsandMarkets places it at $120.8 billion in 2025, growing to $151.5 billion by 2030 at a 4.6 percent compound annual growth rate. Straits Research puts it at $153.2 billion in 2025 with a 4.5 percent CAGR to 2034. Market Research Future values it at $131.8 billion in 2025 with a 6.7 percent CAGR to 2035. The difference between these three numbers is not methodology error so much as scope: some reports include only equipment and software, others bundle in services and guarding, and still others include adjacent categories such as fire and life safety.

The numbers worth taking away are these. North America is consistently the largest regional market at 38 to 40 percent of global spend, equivalent to roughly $47 billion to $61 billion in 2025. The US physical security market, taken alone, is a roughly $50 billion annual category, and it is growing in the mid-single digits. Within the global number, video surveillance is the single largest equipment category at about 47 percent of revenue; physical access control is the second largest; intrusion detection and biometrics are smaller but faster-growing segments.

The cloud-delivered subset is smaller and faster. The video-surveillance-as-a-service (VSaaS) market is sized at $5.28 billion to $8.24 billion in 2025 across major reports, growing at 12.6 to 16.4 percent CAGR through the early 2030s. North America captures 34.9 percent to 40.1 percent of that market, depending on definition, with the US alone projected at $1.67 billion by 2026. Access control as a service (ACaaS), a smaller and younger segment, is sized at about $1.58 billion in 2025, growing to $1.74 billion in 2026 and $2.94 billion by 2031 at an 11.05 percent CAGR, with cloud deployments expanding at a 14.32 percent CAGR within that mix.

To frame what this means for a Southeast buyer: roughly 2 to 3 percent of US physical-security spend is cloud-delivered today, growing fast; the remaining 97 to 98 percent is a mixture of on-premise hardware and software, hybrid cloud-managed appliances, and services. The cloud story is not a wholesale replacement of the install base. It is a parallel track.

2. The Platform Shift: Cloud, On-Premise, and Hybrid

Three forces are reshaping how the technology gets bought. The first is the substitution of subscription economics for capital expense. The second is the convergence of physical security with IT cybersecurity in compliance, procurement, and operations. The third is the steady improvement in cloud-native AI and analytics, which is closing the feature gap with on-premise systems.

The Omdia 2025 Access Control Report, released in October 2025, places Genetec in the number two position worldwide in access control software, with the highest organic on-premise market share gain of any vendor in the year and one of the fastest organic growth rates in the ACaaS segment for the Americas region, which the firm values at more than 70 percent of the global ACaaS market. Verkada is the number one worldwide provider of VSaaS in Omdia’s 2025 Video Surveillance and Analytics Report, based on a $797 million 2024 VSaaS market in which the company is the single largest supplier. Genetec retains the number one position worldwide in video surveillance software and the number one position in the combined video software plus VSaaS category. These are not interchangeable accolades — Omdia’s “VSaaS” segment is narrower than the broader “cloud video” market sized by MarketsandMarkets and Mordor — but the ranking pattern is consistent: Verkada leads the cloud-native segment, Genetec leads the on-premise-and-combined category, and Avigilon (under Motorola Solutions) holds a meaningful share of the installed base in the United States with a stated run rate of more than $1.5 billion in its video-security and access-control business in 2022 and double-digit growth thereafter.

The deployment mix in the US is moving in one direction, but it is moving slowly. In US access control, on-premise deployments captured about 70.85 percent of 2026 spend according to Mordor Intelligence, with cloud deployments growing at 14.32 percent CAGR. Genetec’s 2025 State of Physical Security report found that 43 percent of healthcare organizations still operate entirely on premise, 48.3 percent use a hybrid cloud-and-on-premise mix, and 8.7 percent have moved fully to the cloud; 68 percent of healthcare organizations said they planned to move more of their security data to the cloud within the next 18 months. That is the honest picture: most organizations are not flipping a switch, they are incrementally moving workloads, and the people who do the moving have to integrate new cloud systems with old on-premise ones for the foreseeable future.

The implication for procurement is straightforward. A single-vendor, single-deployment-model decision is the exception, not the rule. Multi-vendor environments with a mix of cloud and on-premise components are the default, and the design questions that follow — credential interoperability, video federation, single sign-on, identity-provider integration, and the physical-to-cyber audit trail — matter more in practice than the cloud-versus-on-premise label on the procurement form.

3. Vendor Map and Competitive Dynamics

The most cited 2025 vendor-share data comes from Omdia, MarketsandMarkets, and Market Research Future. The pattern they describe is consistent: a top tier of legacy incumbents with deep installed bases, a faster-growing second tier of cloud-native challengers, and a long tail of regional integrators and vertical specialists. The top tier — Honeywell, Johnson Controls, Bosch, Hikvision, and Dahua — is not the same group that the cloud-native buyers are choosing from, and the second tier — Verkada, Genetec, Avigilon (Motorola), Brivo, and a small set of AI-first entrants — is where the strategic movement is happening in 2026.

Three notes on the vendor landscape are worth carrying into a 2026 procurement decision.

The first is the consolidation of access-control hardware and credentialing. Allegion, the lock and credentialing company, executed four material acquisitions in 2025: Next Door Company (February 2025), Trimco (April 2025, manufacturer of architectural door hardware), ELATEC (mid-2025, RFID credential and reader technology, $204 million), and Gatewise (July 2025, multifamily SaaS gate entry) for an aggregate consideration of approximately $628 million. Allegion is buying its way into the software and electronics layer of access control, which is where the gross margin and the recurring revenue live. The signal for buyers is that the lock-and-hardware vendors are moving up the stack into identity, and the identity vendors are moving down into hardware; the line between “access control” and “lock” is becoming a marketing distinction rather than a technical one.

The second is the Motorola Solutions stack. Motorola Solutions paid roughly $1.0 billion in cash for Avigilon in March 2018, paid approximately $297 million for Openpath (the cloud-native access control company) in 2021, and acquired Ava Security, a cloud-native video company, in 2022. The combined video-security-and-access-control business hit a $1.5 billion run rate in 2022 and Motorola Solutions reported 2025 revenue of $11.7 billion with the video-security-and-access-control business growing 14 percent that year. The Avigilon brand now spans two distinct product lines: Avigilon Unity, the on-premise appliance-led product, and Avigilon Alta, the cloud-native product that inherits Openpath’s mobile-credential technology. The significance for Southeast buyers is that one of the two largest US integrators can now offer both deployment models from a single vendor, which is a real procurement simplification when paired with a competitor like Verkada that is cloud-only or Genetec that is on-premise-and-cloud.

The third is the Verkada and Brivo pricing posture, which is the most direct competitive pressure on the on-premise incumbents. Verkada’s published camera hardware MSRPs range from $599 for a 3-megapixel 15-day-retention indoor dome to $5,299 for a multisensor 4K camera with extended retention, with a required per-camera cloud license of $199 for a 1-year term, $499 for a 3-year term, $799 for a 5-year term, and $1,599 for a 10-year term; multi-year commitments land at roughly $180 per camera per year. Brivo’s published access-control subscription tiers start at $13.50 per month for the first two doors in the Standard Edition, decreasing to $7.50 per door for doors 3 through 10 and $3.50 per door for additional doors, with Professional and Enterprise editions adding base platform fees of $250 to $580 per month plus $9 to $16 per door per month. Hardware installation runs $1,500 to $2,800 per door for new wiring. Avigilon Alta (the rebranded Openpath) lands at $5 to $20 per reader per month, or roughly $1,300 to $2,800 per door annually depending on tier and scale. These price points are noticeably below what a typical on-premise access control system with a separate server, software license, and integrator-led installation runs after five years of total cost, which is why the cloud-native challengers are taking share at the small and mid-market end and starting to push into the enterprise tier.

The vendor map in 2026, then, is a layered market. At the top, the legacy incumbents compete on installed base and on the operational reality that no enterprise customer is ripping out 10,000 doors and 5,000 cameras to switch. In the middle, the platform vendors — Verkada, Genetec, Avigilon, Brivo — compete on deployment economics, feature velocity, and AI capability. At the long tail, regional integrators and vertical specialists compete on local knowledge, regulatory familiarity, and the ability to translate a customer’s existing investment into a phased plan that the customer’s board will approve.

4. The Compliance Stack: HIPAA, CMMC, CJIS, and the SE State Matrix

Compliance is the single most important non-technical driver of physical-security purchasing in 2026, and the Southeast has a denser concentration of the relevant regulatory regimes than any other US region. The following matrix lays out the four federal and compliance frameworks that apply across the major SE verticals, followed by a state-by-state summary of the breach-notification laws in the same 12-state and DC footprint.

The four federal frameworks in active enforcement or active rulemaking in 2026 are summarized in the table below.

FrameworkCurrent status (Aug 2026)Effective for the customerWhat it requires of physical security
HIPAA Security Rule2013 Rule in effect; proposed overhaul (NPRM 90 FR 898, Jan 6, 2025) pushed to “Long-Term Actions” on the OMB Unified Agenda, with final action projected for July 2027All HIPAA covered entities and business associates todayFacility access controls (45 CFR 164.310), physical safeguard documentation, encryption, MFA, network segmentation; current penalties $145 to $2,190,294 per violation
CMMC 2.0 (DFARS 32 CFR)Final rule published Sept 10, 2025 (90 FR 43560); effective Nov 10, 2025; four-phase rollout to Nov 10, 2028All DoD contractors and subcontractors handling FCI or CUI (excluding COTS-only contracts)Level 1 self-assessment, Level 2 C3PAO assessment, Level 3 DIBCAC assessment; physical security controls via NIST SP 800-171
FBI CJIS Security Policy v5.9.5 (Jul 9, 2024) and v6.0 (Jan 22, 2025)P1 controls sanctionable from Oct 1, 2024; P2 through P4 in zero-cycle through Sept 30, 2027State and local law enforcement, criminal justice agencies, contractors with CJI accessPhysically secure location (Section 5.9.1), controlled area, encryption at rest outside physically secure location, 128-bit minimum, MFA for advanced authentication
PCI DSS v4.0Effective March 31, 2024; v3.2.1 retired March 31, 2024; future-dated requirements effective March 31, 2025Any entity that stores, processes, or transmits cardholder dataPhysical security controls for cardholder data environments; restrict physical access; monitor and log entry

The single most consequential fact in this table is the timing of the HIPAA Security Rule. The Biden administration published a Notice of Proposed Rulemaking on January 6, 2025 to update the Rule for the first time since 2013. The proposed rule would, if finalized, make all implementation specifications required rather than addressable, mandate encryption of ePHI at rest and in transit, mandate multi-factor authentication, mandate network segmentation, and require written documentation of all policies, procedures, plans, and analyses. The proposed effective date is 60 days after final publication with a 180-day compliance window. As of August 2026, the proposed rule has not been finalized. The original target was May 2026; the OMB Unified Agenda has been updated to push final action to July 2027 and to move the rulemaking into Long-Term Actions, a category reserved for actions not expected within the next 12 months. The current Security Rule — the one OCR is actively enforcing — remains the 2013 version with its addressable implementation specifications, but the proposed rule signals where enforcement attention is heading and what covered entities and business associates should be preparing for. A coalition of more than 100 hospital and provider groups has formally asked HHS to withdraw the proposal, citing cost and operational burden, and the comment period closed in March 2025 with approximately 4,700 submissions, an unusually high volume.

The CMMC 2.0 final rule, in contrast, is in force. Phase 1 began on November 10, 2025, requiring DoD contracting officers to include Level 1 and Level 2 self-assessment requirements in applicable solicitations as a condition of contract award. The Department of Defense estimates that Level 1 and Level 2 self-assessments will apply to roughly 65 percent of the Defense Industrial Base. Phase 2 begins November 10, 2026 and adds Level 2 C3PAO (third-party assessor) certification requirements. Phase 3 begins November 10, 2027 and adds Level 3 DIBCAC assessment. Phase 4 begins November 10, 2028 and applies the requirements to all applicable contracts. For any defense contractor in the Southeast — and there are many, given the concentration of military installations in Georgia, North Carolina, South Carolina, Alabama, Mississippi, Louisiana, Tennessee, Kentucky, Florida, and Virginia — CMMC is now a contractual gate, not a future possibility.

The FBI CJIS Security Policy applies to state and local law enforcement, but its reach extends into the private sector through any organization that handles Criminal Justice Information, including vendors, contractors, and service providers. Version 5.9.5 took effect on July 9, 2024 and version 6.0 was released on January 22, 2025. The most significant change is the priority framework. Priority 1 (P1) controls are immediately sanctionable as of October 1, 2024, and existing controls remain sanctionable throughout. Priority 2 through Priority 4 controls are in a zero-cycle status beginning October 1, 2024 and ending September 30, 2027. The 5.9.5 modernization aligns the CJIS Security Policy with NIST SP 800-53 at the moderate level. For physical security, the most material controls are in Section 5.9 (Physical and Environmental Protection), with specific requirements for a physically secure location, security perimeter, access authorizations, access control, and visitor access records. Cloud deployments of CJI are explicitly permitted under the policy, but only if the cloud service provider can meet all the requirements, including physical and personnel security controls, encryption, and access management.

The breach-notification landscape is a separate compliance layer and the most operationally important day-to-day requirement for security and IT leaders. The table below summarizes the consumer-notification deadline and the threshold for attorney general or state-agency notification for each of the twelve SE states plus the District of Columbia.

State / DCNotification deadline to individualsAG or state agency thresholdNotable variation
Florida30 days; up to 15-day extension for good cause (max 45 days)500+ Florida residents → FL Dept. of Legal AffairsCivil penalties up to $500,000 per violation; no private right of action
Georgia“Without unreasonable delay”10,000+ residents → consumer reporting agenciesNon-numeric; largest population in SE after FL
North Carolina“Without unreasonable delay” / “immediately”AG / credit reporting agencies as requiredContent must include FTC and NC AG info
South Carolina“Without unreasonable delay”1,000+ residents → consumer reporting agenciesNon-numeric; fast-growing population
Alabama45 days1,000+ residents → consumer reporting agenciesNumeric deadline; smallest SE market by population and GDP
Mississippi“Without unreasonable delay”1,000+ residents → consumer reporting agenciesNon-numeric; smaller market
Tennessee45 days1,000+ residents → consumer reporting agenciesNumeric; large healthcare and logistics sector
Kentucky“Without unreasonable delay”1,000+ residents → consumer reporting agenciesNon-numeric
Louisiana60 days1,000+ residents → consumer reporting agenciesNumeric; longer than most SE neighbors
Virginia“Without unreasonable delay”1,000+ residents → consumer reporting agenciesNon-numeric; significant federal contracting presence
Texas60 days to individuals; 30 days to TX AG if 250+ residentsTX AG via online formNumeric; separate AG notification pathway
District of Columbia60 days50+ DC residentsLowest AG threshold in the region

The operational takeaway from this matrix is that a multi-state breach in the Southeast can require notification under 12 different statutes with different deadlines, different content requirements, and different AG thresholds. The compliance exposure of a single physical-security breach that exposes personal information across the SE footprint is closer to 12 times the operational work of a single-state breach, because the timelines run in parallel, not in sequence.

5. Vertical Adoption: Healthcare, Federal/Defense, Logistics, and Manufacturing

The physical-security market is not a single market. It is four overlapping markets with different buyers, different regulatory drivers, and different technology preferences. The four verticals that matter most in the Southeast are healthcare, federal and defense contracting, logistics and warehousing, and manufacturing.

Healthcare is the most regulated and the most compliance-driven. The HIPAA Security Rule applies to every covered entity and business associate, the proposed Rule would expand the physical-security requirements materially, and the 2025 OCR enforcement record is a clear signal of where attention is focused. OCR closed 22 enforcement actions in 2024 and 21 in 2025, the second-highest annual total to date. The 2025 record included Solara Medical Supplies at $3 million for a phishing-related breach affecting 114,007 individuals, and Warby Parker at $1.5 million for risk analysis, risk management, and system monitoring failures affecting 198,470 individuals. The 2024 Change Healthcare ransomware attack exposed the personal and medical data of approximately 192.7 million individuals, the largest healthcare data breach in US history; UnitedHealth paid a $22 million ransom to the ALPHV/BlackCat ransomware group, and the MDL is still in active litigation. OCR’s 2025 enforcement pattern focused on three consistent violations: failure to conduct a HIPAA-compliant risk analysis, failure to issue timely breach notifications, and inadequate access controls. The pattern is consistent enough that any healthcare security leader in 2026 should be able to defend their organization’s risk analysis documentation, access control design, and breach notification playbook in an OCR investigation.

A January 2026 audit by the HHS Office of Inspector General of a large hospital in the southeastern United States (more than 300 beds, HITRUST CSF v9.4 framework) illustrates the operational reality. The audit found that the hospital had implemented effective cybersecurity controls in many areas but had weaknesses in user identification and authentication on an account-management web application, which allowed OIG testers to use credentials captured from a simulated phishing campaign to gain access. The hospital’s phishing click rate was 6 percent and one user entered credentials, but the more material issue was that the captured credentials worked without multi-factor authentication. The same audit found input validation weaknesses on an internet-facing application that could be exploited for injection attacks, and the absence of a web application firewall as a defense-in-depth layer. The hospital agreed to all four OIG recommendations and began remediation. The lesson for the region’s healthcare security leaders is that the audit, not the regulation, is the immediate test of whether the program is working.

Federal and defense contracting is the second vertical, and it is the one most directly affected by the CMMC 2.0 final rule that took effect in November 2025. Defense contractors in the Southeast operate in every state — Lockheed Martin’s operations in Marietta, Georgia; Northrop Grumman in Melbourne, Florida; Raytheon in multiple locations; BAE Systems in Virginia and Tennessee; L3Harris in Florida and North Carolina; the shipyards in Virginia, Mississippi, and Louisiana — and they all face the same phased implementation that will reach every DoD contract by November 2028. The physical-security implications are anchored in the NIST SP 800-171 family of controls, particularly the PE family. For a small or mid-size defense subcontractor in the region, the most important near-term action is the Level 1 or Level 2 self-assessment that began appearing in DoD solicitations in November 2025, because no award can be made without an SPRS-posted status.

Logistics and warehousing is the third vertical, and it is the one where the Southeast’s geography has the most direct economic effect. The US warehouse access control market is sized at $4.2 billion in 2025, growing to $8.1 billion by 2034 at an 8.3 percent CAGR. The drivers are e-commerce volume, port-adjacent cargo risk, and the post-pandemic reassessment of internal theft as a material loss source — insider involvement was involved in nearly one-third of US cargo theft incidents in 2024. The Southeast is the largest US logistics region by throughput, anchored by the Port of Savannah (the largest single-terminal container facility in the Western Hemisphere), the Port of Charleston, the Port of Jacksonville, the Port of Houston, the Port of Virginia, and the deep concentration of distribution centers in the Atlanta, Dallas-Fort Worth, and Memphis metros. The 2025 spend benchmark for a 200,000-square-foot distribution center is $300,000 to $1.2 million annually; a mega-DC over 500,000 square feet can run $2 million to $10 million or more. Cloud access control, cloud video, and AI-based dock analytics are now standard procurement in this vertical.

Manufacturing and industrial facilities are the fourth vertical. The Southeast’s manufacturing base runs from automotive assembly and parts plants in Tennessee, Alabama, Mississippi, Georgia, and South Carolina to chemical and petrochemical facilities along the Gulf Coast in Louisiana and Texas to aerospace and defense suppliers in every state. The CJIS Security Policy, the CFATS chemical facility anti-terrorism standards, and the broader NIST 800-171 framework all touch this vertical. The procurement pattern in 2026 is similar to logistics: cloud-managed access control with on-premise cameras at the perimeter, AI analytics at the high-value zones, and a unified platform that the operations team can use from a single pane of glass.

6. AI, Analytics, and Pricing Reality

Three claims about physical security in 2026 are worth testing against the evidence, because the marketing literature is louder than the benchmark literature.

The first claim is that AI video analytics is a solved problem. It is not, but it is much closer to solved in 2026 than it was in 2020. The NIST Face in Video Evaluation (FIVE) 2024 results, presented at the IFPC in April 2025, showed that the false negative identification rate at a fixed false positive identification rate improved from 0.09 to 0.62 across six operational scenarios in 2015 to 0.00 to 0.20 in 2024. The most material improvement was in long-range imaging, compressed video, and elevated-camera scenarios — exactly the conditions that surveillance deployments face. The state of the art in 1:N face recognition on cooperative images, measured by the FRTE 1:1 benchmark, has reached a false negative identification rate of 0.15 percent at a false positive rate of 0.001 on galleries of more than 10 million identities. The honest framing is that AI face recognition in 2026 is good enough for many real-world surveillance use cases that were not workable five years ago, and that the gap between cooperative-image benchmarks and surveillance video performance has narrowed but has not closed. Class-level accuracy (for example, distinguishing a person from a vehicle, or detecting a specific object class in a defined scene) is more reliable than re-identification accuracy in uncooperative conditions, and procurement specifications should be written accordingly.

The second claim is that the cloud subscription model is always cheaper than on-premise. The math depends on the timeframe and the deployment. For a 5-year total cost of ownership comparison on a 25-camera, 25-door greenfield deployment with no existing infrastructure, the cloud-native subscription model lands at roughly $50,000 to $90,000 over five years: $25,000 to $35,000 in Verkada camera hardware, $9,000 to $15,000 in 5-year Verkada camera licenses at the $180-per-year equivalent, $7,500 to $12,500 in Brivo access control subscriptions, $30,000 to $70,000 in installation labor, and modest bandwidth and cloud-storage costs. The equivalent on-premise deployment with a server-class VMS, an on-premise access control appliance, and integrator-led installation lands at a similar first-cost but carries ongoing software-support, server-maintenance, and storage-refresh costs that a cloud subscription rolls into the per-month fee. For a deployment that already has on-premise infrastructure and trained staff, the calculus flips: a multi-year cloud migration adds subscription cost and removes the depreciation value of the existing hardware and software. The honest answer is that the cloud model is cheaper for net-new deployments, parity for mid-life deployments, and more expensive for late-life on-premise systems that are about to need a refresh.

The third claim is that the leading cloud platforms can replace a legacy on-premise VMS and access control system with no integration work. The integration cost is the most underestimated line item in 2026 procurement. Cloud platforms federate with on-premise cameras through ONVIF, RTSP, or vendor-specific bridges, and most accept a mix of new and existing hardware. The integration friction shows up in identity management (where cloud-native access control expects SAML, OIDC, or SCIM and the on-premise directory may not), in video federation (where the on-premise VMS may not support the same retention windows or the same audit logging as the cloud platform), in compliance reporting (where the customer’s existing audit trail may not include the new cloud system), and in physical-to-cyber alignment (where the cloud access control system may not write the same log format as the on-premise SIEM). The realistic cost of a multi-site migration is 20 to 40 percent of the new license cost in professional services, integration, and project management, and the realistic timeline is six to twelve months for a mid-size portfolio.

7. Regional Outlook, 2026 to 2030

The Southeast is the largest US economic region by gross domestic product, with $6.5 trillion in Q3 2024 — larger than any of the four US Census regions on its own. Florida alone is the fourth-largest state economy at $1.83 trillion in 2025; Texas is the second-largest state economy at $2.9 trillion; Georgia is the eighth-largest at $925 billion; North Carolina is the eleventh-largest at $894 billion. Population growth in the region has been the fastest in the country: the South grew 0.9 percent in the 12 months ending July 2025, and South Carolina led the nation with 1.5 percent growth, driven by domestic in-migration. Visa’s Business and Economic Insights team reported that the South’s population surged 5.6 percent — more than 7 million people — since the pandemic, and the region’s GDP grew at a 4.3 percent average annual rate from 2020 to 2024, compared to 3.6 percent for the US as a whole.

The implication for physical security is that the install base in the region is growing faster than the US average, the value of the assets being protected is growing faster, and the regulatory pressure is higher than in any other US region because of the concentration of healthcare systems, federal installations, and logistics infrastructure. A 5-year market outlook for cloud and hybrid-cloud physical security in the twelve SE states plus DC, derived from the global market CAGRs and the regional share of US physical-security spend, lands in the range of $3 billion to $5 billion in cumulative new spending through 2030, of which cloud-delivered or cloud-managed services represent roughly 30 to 40 percent. This is a planning estimate rather than a forecast, and it is sensitive to the assumption that the on-premise-to-cloud transition continues at its current pace; if the transition accelerates (for example, if the HIPAA Security Rule is finalized in 2027 with a short compliance window, or if a major insurer mandates a specific cybersecurity framework), the cloud share of new spend could rise faster.

The single biggest non-economic risk to the regional outlook is the workforce. The US has more unfilled cybersecurity and physical-security positions than at any point in the past decade, and the gap is most acute in mid-tier markets outside the largest metros. The healthcare and logistics verticals are feeling this acutely, and the federal and defense contracting vertical is competing for the same trained talent against federal salaries and remote-work flexibility. The security leaders in the region who are winning this competition are the ones who are training from within, partnering with community colleges and workforce development programs, and designing for the operator that they actually have rather than the one they wish they had.

8. Action Framework (Ten Decisions)

The remainder of this report is a framework for security, IT, facilities, and compliance leaders in the Southeast to use in their 2026 planning cycle. The framework is organized as ten decisions. Each decision is framed as a question, followed by the evidence-based answer the regional data and the regulatory calendar support.

  1. Cloud, on-premise, or hybrid for new deployments? Default to hybrid for organizations with an existing on-premise install base. Default to cloud-native for greenfield deployments under 100 doors and 50 cameras. Default to on-premise for any deployment where air-gapping is a regulatory or operational requirement. Treat the deployment model as a per-site decision, not a corporate decision.
  2. Single vendor or multi-vendor? Default to a primary platform vendor with at least one complementary vendor for specialty requirements (intercoms, elevator control, LPR, visitor management, intrusion). Single-vendor strategies are easier to operate but limit the ability to take advantage of price competition and feature specialization.
  3. What is the right compliance posture for HIPAA? The current 2013 Rule is in effect and the proposed Rule has been pushed to July 2027. The right posture is to comply with the 2013 Rule today and to begin the work the proposed Rule would require, because the gap between 2013 and 2025 is meaningful and the operational work takes longer than the compliance window assumes.
  4. What is the right CMMC posture? If you are a DoD contractor or subcontractor handling FCI or CUI, the Level 1 or Level 2 self-assessment is now contractually required. Begin the self-assessment before the Level 2 C3PAO assessment, because the self-assessment will surface most of the gaps the C3PAO assessment will find.
  5. What is the right CJIS posture? If you handle Criminal Justice Information, the P1 controls have been sanctionable since October 2024. Verify that your access control, video, and physical security systems meet Section 5.9.1 (Physically Secure Location) and the encryption requirements of Section 5.10.1.2.
  6. How to approach state breach notification compliance? Treat the matrix in section 4 as a planning artifact, not a research artifact. Map your customer footprint, your employee footprint, and your vendor footprint to the twelve SE states plus DC, identify the strictest deadline and the lowest AG threshold, and use that as your internal SLA.
  7. How to budget for AI analytics? Start with the analytics you can measure, not the analytics that look best in a vendor demo. Person-and-vehicle detection, line-crossing, dwell time, and license plate recognition are reliable in 2026. Behavior prediction, fight detection, and weapon detection are improving fast but should be piloted before they are deployed at scale.
  8. How to price the cloud subscription? Use a 5-year total cost of ownership comparison, not a first-year comparison. Include bandwidth, installation, integration, training, and the operator time required to administer the new system. The cloud subscription line item is the easiest to compare; the professional services and integration line items are the largest variables.
  9. How to structure the procurement? Structure the procurement around the integrator, not the manufacturer, for multi-site deployments. The integrator’s design and project-management capability is the largest single determinant of whether the deployment hits the timeline and the budget. A cloud-native product deployed by an under-resourced integrator is worse than an on-premise product deployed by a strong integrator.
  10. How to plan for the next three years? Treat 2026, 2027, and 2028 as a single planning cycle. The HIPAA final rule, the CMMC phases, the CJIS priority phase-out, and the cloud-vendor pricing competition will all reach a tipping point inside this window. The leaders who set a three-year plan in 2026 will outpace the leaders who set a one-year plan in each of the three years.

The Southeast physical security market in 2026 is large, growing, and regulated. The data is good enough to plan against, the vendors are consolidating around a clear set of platform choices, and the compliance calendar is fixed for the next three years. The decision for the region’s security leaders is not whether to act, but how to sequence the action.

Related Reading

This report is part of HTS’s SE-focused research library on physical security. For vendor-by-vendor detail, see the four 2026 SE research pieces below.

See also: Genetec vs Verkada · Genetec vs Avigilon · Genetec vs Brivo (access control) · Genetec alternatives roundup · Verkada partner page · Avigilon partner page · Brivo partner page

Let’s connect your vision across our scalable infrastructure

Connect with us to explore our scalable solutions tailored to your unique needs and receive a personalized free quote.