choosing the right smart access control system for 1 0 44882
choosing the right smart access control system for 1 0 44882

Choosing the Right Smart Access Control System for Commercial Buildings.

Industry

Ask a facilities team what access control system their building runs and you will usually get the name of the software. Ask what protocol the readers speak to the controller, who holds the encryption keys, and what happens to the doors if the internet connection drops, and the room goes quiet. Those three answers matter more than the brand on the dashboard.

A commercial access control system should be specified from the door outwards, not from the software inwards. Decide the credential type, then the reader-to-controller protocol, then where the system is hosted, and only then compare platforms. Most of the cost and nearly all of the security risk sit in the first two decisions, and they are the hardest to reverse once the cabling is in.

The short version

  • Four parts make up any system: door hardware, readers, controllers and management software. They are usually bought together and should be judged separately.
  • OSDP has replaced Wiegand as the reader protocol worth specifying, and it has been an international standard since 2020.
  • Cloud, on-premise and hybrid hosting differ mainly in who carries the maintenance burden, not in how secure they are.
  • Biometric credentials bring data protection obligations that card and mobile credentials do not.

The four parts you are actually buying

Every commercial access control installation reduces to the same four layers, whatever the vendor calls them. Treating them as one product is how buildings end up locked into a single supplier for a decade.

  • Door hardware. Electric strikes, maglocks, request-to-exit devices and door position sensors. This is the layer that has to satisfy fire and egress rules, and it is the layer least affected by software fashion.
  • Readers. The visible part, and the part most exposed to tampering because it sits on the unsecured side of the door.
  • Controllers. The panels that hold the access decisions. A well-specified controller keeps granting and refusing access when the network is down.
  • Management software. Where credentials are issued, revoked and audited. Easiest layer to change later, and the one buyers spend the most time evaluating.

Choosing the credential

The credential determines the user experience, the administrative workload and the legal exposure of the whole system, so it deserves deciding first rather than last.

Smart cards and fobs

Modern contactless smart cards hold cryptographic keys rather than a simple readable number, which is the difference between a credential that can be cloned at a distance and one that cannot. The administrative cost is real: cards get lost, and every replacement is a small piece of work. In exchange, revoking a card is instant and carries no privacy consequences.

Mobile credentials

Issuing credentials to a phone removes the physical logistics almost entirely, which is why mobile credentials have become the default for multi-tenant offices and for organisations with high staff turnover. The dependency to plan for is the handset: policies need to cover what happens when a phone is lost, replaced or has a flat battery at eight in the morning.

Biometrics

Fingerprint and face recognition remove the credential from the equation altogether, which is genuinely useful for a small number of high-security doors. They also change the nature of what the system stores. Under the EU General Data Protection Regulation, biometric data processed for the purpose of uniquely identifying a person falls into a special category with a higher bar for lawful processing, and several European regulators have taken a restrictive view of biometric entry systems in ordinary workplaces. Rules differ by jurisdiction, so this is a question for legal counsel in the country of installation rather than for the integrator.

The reader on the wall is the only part of the system an intruder can reach without already being inside.

The protocol nobody asks about, and should

The link between a reader and its controller is the least glamorous specification in the whole project and the one that most often turns out to be the weak point. For decades that link was Wiegand, which sends credential data in one direction and in clear, with no supervision of the cable. Anyone able to reach the wiring behind a reader can capture or inject credentials on a Wiegand line.

The replacement is the Open Supervised Device Protocol, developed by the Security Industry Association. OSDP runs over RS-485, communicates in both directions, supervises the connection so a cut cable raises an alarm, and encrypts credential traffic using AES-128 through its Secure Channel. It was approved as an international standard by the International Electrotechnical Commission in May 2020 and is published as IEC 60839-11-5, with SIA releasing version 2.2.2 in October 2024. Interoperability has followed: SIA’s OSDP Verified programme had independently validated more than 200 products from over 30 manufacturers by mid-2026, according to the association’s own figures.

For any new installation, or any refurbishment where cabling is being touched, specifying OSDP with Secure Channel enabled costs almost nothing extra and closes a well-documented attack path. Enabled is the operative word: the protocol supports encryption, but installations are routinely commissioned with it switched off.

Where the system should live

Hosting is usually presented as a security question. In practice it is a question about who carries the maintenance work and who is accountable when something breaks, and buildings of different sizes answer it differently.

Model Suits Main advantage What you take on
Cloud hosted Multi-site estates, tenants without IT staff One interface across sites, updates handled by the vendor Ongoing subscription, dependency on the provider’s continuity
On premise Single sites with an internal IT function, restricted environments Full control of data location and retention Patching, backups and hardware refresh become your job
Hybrid Estates migrating from legacy panels Local decisions kept at the controller, administration centralised Two things to maintain instead of one

Whichever model is chosen, ask one question before signing: what does the system do offline? Controllers that cache their access rules keep the building working through a network outage. Controllers that defer every decision upstream turn an internet problem into a door problem.
Reader and controller of a smart access control system installed at a commercial building entrance

What integration is worth, and what it costs

Access control data is useful well beyond the door. Because the system knows which zones are occupied, it can drive lighting and ventilation schedules, and that is where the operational savings in connected building projects usually come from rather than from the security function itself. Integration with video also shortens investigations considerably, since an access event and the footage attached to it stop being two separate searches.

The cost of integration is coupling. Every link between systems is a link that has to survive both vendors’ upgrade cycles, and open interfaces matter more here than feature lists. This is a different exercise from the residential automation market, where the products are chosen for convenience rather than for a ten-year maintenance horizon, a distinction we set out in our comparison of building automation and smart home systems.

A sequence that avoids the common mistakes

  1. Count and classify the doors. Perimeter, internal, high-security and out-of-hours doors have different requirements and different budgets. A flat specification across all of them overspends in one place and underspends in another.
  2. Fix the credential policy. Decide what staff, contractors and visitors each carry, and how each is revoked, before looking at any product.
  3. Specify OSDP with Secure Channel in the tender documents, and require proof it is enabled at handover rather than merely supported.
  4. Confirm offline behaviour and egress compliance with the fire strategy for the building. Access control that conflicts with escape routes is not a negotiable detail.
  5. Then compare platforms, on the strength of their audit trail, their administration workload and their published interfaces.

Questions buyers keep raising

Can an existing Wiegand installation be upgraded without recabling?

Often yes. OSDP runs over two-wire RS-485, and many Wiegand installations have enough conductors in place to be repurposed, though this depends on the cable type and length. Converter modules also exist for phased migrations, at the cost of keeping a legacy segment in the system.

How long should access logs be kept?

Long enough to be useful for investigations, and no longer than the applicable data protection rules allow. Log retention is personal data processing in most jurisdictions, so the retention period should be a documented decision rather than a default left at whatever the software shipped with.

Does a smaller building need controllers at all?

Networked smart locks can cover a handful of doors without a conventional panel, which suits small offices well. The trade-off is that battery-powered locks add a maintenance routine, and their reporting is usually less granular than a wired controller’s.

What single specification improves security the most?

Encrypted, supervised communication between reader and controller. It is inexpensive, it is standardised, and it removes the attack that requires the least skill to carry out.

Looking at the wider building systems stack?

Access control rarely stays a standalone project. Our overview of where connected buildings are heading covers how these systems are expected to fit together.

Read the smart buildings overview

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *