Guide · 10 min read

Prox Cards vs Smart Cards vs Mobile Credentials

For property managers, IT directors, agency facilities staff and estimators choosing an access credential or replacing one. This guide compares 125 kHz proximity cards, 13.56 MHz smart credentials and mobile credentials on security, cost, issuance, revocation and lifecycle, and gives the sequence for migrating an occupied building without locking anyone out.

Published
September 12, 2026
By
Telelink Business Services
CSLB #472017 · Licensed C-7 contractor Access credential card with radio waves

The short answer

A 125 kHz proximity card broadcasts a fixed number with no encryption and can be copied with inexpensive handheld tools, so it should not be the end state for any building. A 13.56 MHz smart credential authenticates with the reader through an encrypted exchange, but not all 13.56 MHz is equal: several early implementations were broken in published research, so the security depends on the specific technology and on how the keys are managed. Mobile credentials over Bluetooth or NFC are issued and revoked from the management console with nothing to print or collect, at the cost of per user licensing and the practical reality that some tenants and staff will not install an app. Most commercial migrations install dual frequency readers so old and new credentials work at the same door until the last old credential is retired.

Key points
125 kHz proxFixed number, no encryption, easily copied
13.56 MHz smartEncrypted exchange; depends on the technology
MobileBLE or NFC, per user license, instant revocation
Reader protocolOSDP v2 Secure Channel, IEC 60839-11-5:2020
Migration toolDual frequency readers, no lockouts
LicenseCSLB #472017, C-7 Low Voltage Systems

125 kHz proximity: what it is and why it persists#

A 125 kHz proximity card is a passive antenna and a chip that does one thing: when a reader energizes it, it broadcasts a fixed number. There is no encryption, no authentication and no challenge. The reader hears the number, passes it to the controller, and the controller looks it up in a list.

That design is from an era when the tools to intercept and replay a low frequency signal were laboratory equipment. They are not anymore. Handheld cloners are sold openly, some retail key duplication kiosks will copy common prox formats, and a writable card replays the captured number in a way no reader or controller can distinguish from the original. Access control software cannot help here, because from the door’s point of view nothing unusual happened.

Prox persists anyway, for reasons that are practical rather than technical. It is installed in an enormous number of buildings. The cards are inexpensive, the readers are inexpensive, the technology is universally interoperable, and it works with gloves, in the rain, and through a wallet. Ripping it out is a project with a budget, and the failure mode it creates is invisible until an incident.

The right position is narrow: prox is acceptable during a migration so nobody is locked out, and it is not acceptable as the end state. Any building with a facilities budget and a multi year horizon should have a written plan to retire it, even if the plan runs over three budget years.

13.56 MHz smart credentials, and why not all are equal#

A 13.56 MHz smart credential does something a prox card cannot: it and the reader authenticate each other before any credential data moves, using keys stored on both sides. A captured transmission is not replayable, because the exchange differs every time.

The detail that gets missed is that the frequency describes the radio, not the cryptography. Several early 13.56 MHz implementations were broken publicly. MIFARE Classic, which uses the proprietary Crypto1 cipher, was the subject of published academic attacks that made practical cloning possible. HID’s legacy iCLASS was likewise the subject of published cryptanalysis. Cards using those technologies are still in service in many buildings and are still sold. Specifying “13.56 MHz” on a drawing buys nothing on its own.

What to specify instead is the actual technology and the key management model. MIFARE DESFire EV3 and HID Seos are the technologies commonly specified for new commercial work in California. Beyond the name, three questions decide whether the deployment is actually secure: are the credentials programmed with keys unique to this customer rather than the manufacturer’s published default keys, who holds those keys, and what happens to the system if the key holder is replaced. A DESFire deployment left on the manufacturer’s published default keys can be read by anyone who knows those keys, which leaves the building no better protected than it was on prox and costs considerably more.

The link between the reader and the controller deserves the same attention. Wiegand is a one way, unencrypted interface that has been the default for decades and can be tapped at the reader to capture credential data. OSDP version 2 with Secure Channel is bidirectional and encrypted, supervises the reader so a removed or substituted reader raises an alarm, and was published as an international standard, IEC 60839-11-5:2020. Specify OSDP with Secure Channel on new work, and specify it on retrofits where the existing cabling supports it.

Mobile credentials over Bluetooth and NFC#

A mobile credential puts the credential in an app on the user’s phone, presented over Bluetooth Low Energy at a distance or NFC on a tap. The cryptography is comparable to a current smart card, and the operational differences are what actually matter.

Issuance is an email or text with an enrollment link. Nothing is printed, encoded, mailed or handed across a leasing desk. Revocation happens from the management console and takes effect the moment the reader or controller syncs, with no card to chase down. For an organization that onboards and offboards people constantly, that is the entire argument.

The costs are real. Mobile credentials are licensed per user on most platforms, sometimes bundled into the per door subscription, which on cloud access platforms runs roughly $150 to $600 per door per year, about $12 to $50 per door per month, as a California commercial planning range as of 2026. Readers that support both a phone and a card cost more than card only readers. And the practical reality is that a portion of any population will not install an app: residents who do not want a property management app on a personal phone, employees using a personal device without a policy that covers it, older phones that the platform does not support, and contractors who need access for two days.

Plan every mobile deployment with a physical fallback. A dual technology reader that accepts a smart card and a phone costs slightly more and removes the entire class of problem, including the dead battery lockout at 6 a.m.

PIN, multi-factor and biometrics at sensitive doors#

Credentials answer what a person carries. At a small number of doors that is not enough.

A PIN keypad at the reader adds something the person knows to something they carry. It belongs at telecom and server rooms, pharmacy and medication storage, cash handling, records rooms and high value storage, and it costs almost nothing beyond the keypad reader. Two factor at four doors is a better investment than a credential upgrade at forty, if the budget only stretches one way.

Biometrics remove the shared credential problem entirely, because a fingerprint or face cannot be handed to a coworker. They also introduce a data category with its own exposure. The California Consumer Privacy Act as amended treats biometric information processed to identify a person as sensitive personal information, which carries notice and use limitation obligations, and collecting biometrics from employees or residents is a decision for the owner’s counsel rather than for a specification writer. Where a project does specify biometrics, settle in advance where the template is stored, whether it stays on a card or on the reader, how it is deleted when a person leaves, and what the notice says.

Comparing the credential options side by side#

125 kHz prox13.56 MHz smart credentialMobile (BLE or NFC)
How it authenticatesBroadcasts a fixed number in the clearEncrypted mutual authentication with the readerEncrypted exchange from an app on the phone
Copy resistanceCopied in seconds with inexpensive toolsStrong on current technology with customer keys; weak on broken legacy implementationsStrong; bound to the device and revocable
Credential costLowest per cardA few dollars more per cardPer user license, usually annual
Reader costLowestModerateModerate to high, especially dual technology
IssuanceEncode and hand over a cardEncode and hand over a card, plus key managementSend an enrollment link; the user does the rest
RevocationDelete in software; the card still opens any other system reading that formatDelete in software; the card cannot be repurposedRevoke from the console; nothing to collect
User experienceWorks with gloves, in weather, through a walletSameHands free on Bluetooth, tap on NFC; a dead battery is a lockout
Lifecycle fitPoor where turnover is high; cards are rarely returnedGood if a return process existsStrong; no physical inventory to track
Where it belongsLegacy only, during a migrationDefault for new commercial systemsStaff, tenants willing to use an app, contractors and temporary access

The pattern is that prox loses on security, smart cards win on universality, and mobile wins on lifecycle. Most commercial buildings end up running smart cards and mobile together on dual technology readers, which is why the reader decision matters more than the credential decision. Our access control systems page covers how the readers, controllers and power supplies are specified, and the cloud vs on-premise access control guide covers where the credential database lives.

Running a phased migration without locking anyone out#

An occupied building cannot lose its entry security for an afternoon, and a resident who cannot get in at 10 p.m. is a bigger problem than a cloned card. The sequence below is what keeps both true.

StepWhat happensWho is affected
1. InventorySurvey every opening, reader model, wiring type and credential format, and count active credentialsNobody; survey only
2. Set the end stateChoose the smart credential technology, the key management model, whether mobile is included, and OSDP with Secure Channel where the wiring allowsDesign team
3. Install dual frequency readersNew readers accept both the existing prox and the new smart credentialNobody notices a change
4. Issue new credentials in wavesStaff first, then tenants by floor, wing or building, with written notice and a staffed help windowOne group at a time
5. Watch the logsA weekly count of prox reads shows exactly how long the tail isAdministrator only
6. Announce a cutoff datePublish it, extend once if a group is behind, and staff the final weekRemaining holdouts
7. Disable 125 kHz at the readerTurn off the prox side in reader configuration, with a documented rollback held for 30 daysAnyone who ignored the notices
8. Retire the formatDelete old credential records, dispose of returned cards, update as-builts and administrator documentationRecords only

Steps 3 and 5 are what make this work. Dual frequency readers mean the migration has no cutover moment, and the log count replaces guessing about whether the population has moved. Extending the cutoff once is normal and should be planned for rather than treated as a failure.

We used this approach on occupied renovations at Little Tokyo Towers in Los Angeles and Horton House in San Diego, where residents stayed in place through the work and entry security had to function every night of the project. Our guide to low voltage work in occupied buildings covers the noticing and scheduling side of the same problem.

Credential lifecycle in high turnover buildings#

In a building with steady turnover, the technology matters less than the workflow around it. A DESFire deployment where nobody deactivates departed residents is less secure than a prox deployment with a disciplined offboarding process, because an active credential in the wrong hands opens the door regardless of how well it is encrypted.

Four things decide whether the lifecycle works. First, one system of record: the property management system, the HR directory or the access platform, with the others following it, never three lists maintained by hand. Second, a trigger that fires automatically, such as an identity provider sync that deactivates the badge when the account is closed, or a documented move out checklist that includes credential revocation as a line item with a signature. Third, an audit anybody can run: a monthly report of active credentials compared against the current rent roll or employee roster, with a written expectation of who reviews it. Fourth, a defined process for contractors, vendors and temporary staff, with expiring credentials rather than permanent ones.

This is where mobile credentials earn their licensing cost. Revocation is instant, there is no card to recover from someone who has already moved out, and issuance does not require the new resident to be physically present at a leasing office during business hours. In multifamily and affordable housing, where turnover is constant and the leasing office is the administrator, that difference shows up every month rather than once at commissioning. Cost planning for the whole system is covered in our access control installation cost guide.

Next step#

Send the door schedule, the credential format in use today and the count of active credentials, and we will return a migration scope with the reader swaps, credential quantities, licensing and the cutover sequence written out. Start at request a bid. If the credential decision is still open, tell us the turnover rate and who administers the system, and we will say which way we would go and why.

This article is general information for planning and specification, not a bid, engineering advice or legal advice. Codes and standards change; confirm the current edition with the authority having jurisdiction. Scope and price for a specific building come only in a written proposal.

FAQ

Questions we hear about this

Can a 125 kHz prox card really be copied that easily?

Yes. The card transmits a fixed number with no encryption and no authentication, so any reader that can hear it can record it and any writable card can replay it. Handheld cloners are sold openly and some retail key kiosks will duplicate common formats. Nothing about the access control software prevents it, because the copy is indistinguishable from the original at the door.

Link to this answer
Is every 13.56 MHz card secure?

No, and this is the detail that gets missed. The frequency describes the radio, not the cryptography. MIFARE Classic, which uses the Crypto1 cipher, was broken in published academic research, and HID's legacy iCLASS was the subject of published cryptanalysis as well. Current technologies such as MIFARE DESFire EV3 and HID Seos are the ones commonly specified today. Ask what specific technology is being quoted and who holds the keys.

Link to this answer
Do mobile credentials replace cards entirely?

Rarely. Plan every mobile deployment with a card or fob fallback. Some tenants and staff will not install an app, some phones are not supported, contractors and visitors need short term access, and a dead battery is a lockout. A dual technology reader that accepts both a smart card and a phone avoids the problem entirely.

Link to this answer
What does a credential migration cost per door?

Replacing a reader is a fraction of a full door. As a California commercial planning range as of 2026, a complete access controlled door runs roughly $2,000 to $6,000 for the access control side before electrified hardware, cloud licensing and any elevator or gate work. A reader swap on an existing, working door with reusable cabling is well below that, and the credentials and licensing are separate.

Link to this answer
Should we use biometrics at high security doors?

Sometimes, and only after counsel reviews it. Biometrics remove the shared credential problem, but the California Consumer Privacy Act as amended treats biometric information processed to identify a person as sensitive personal information, which brings notice and use limitations. A PIN added to a card at a small number of sensitive doors gets most of the benefit with none of the data collection.

Link to this answer
Can we migrate an occupied building without locking residents out?

Yes, and it is the normal case. Dual frequency readers go in first so existing credentials keep working, new credentials are issued in waves with written notice and a staffed help window, prox usage is monitored in the logs until the tail is gone, and only then is the old format disabled. Little Tokyo Towers and Horton House were both fully occupied during their access control work.

Link to this answer

Question not answered here? Ask a person who does this work.

Call (916) 340-7503Email usOr send drawings to bid
TELELINKBusiness Services

Ready to put this on a real building?

Send over the drawings or describe the scope. We will tell you what we would take on, what we would coordinate out, and what it will take to do it right.