The short answer
A 125 kHz proximity card broadcasts a fixed number with no encryption and can be copied with inexpensive handheld tools, so it should not be the end state for any building. A 13.56 MHz smart credential authenticates with the reader through an encrypted exchange, but not all 13.56 MHz is equal: several early implementations were broken in published research, so the security depends on the specific technology and on how the keys are managed. Mobile credentials over Bluetooth or NFC are issued and revoked from the management console with nothing to print or collect, at the cost of per user licensing and the practical reality that some tenants and staff will not install an app. Most commercial migrations install dual frequency readers so old and new credentials work at the same door until the last old credential is retired.
| 125 kHz prox | Fixed number, no encryption, easily copied |
|---|---|
| 13.56 MHz smart | Encrypted exchange; depends on the technology |
| Mobile | BLE or NFC, per user license, instant revocation |
| Reader protocol | OSDP v2 Secure Channel, IEC 60839-11-5:2020 |
| Migration tool | Dual frequency readers, no lockouts |
| License | CSLB #472017, C-7 Low Voltage Systems |
125 kHz proximity: what it is and why it persists#
A 125 kHz proximity card is a passive antenna and a chip that does one thing: when a reader energizes it, it broadcasts a fixed number. There is no encryption, no authentication and no challenge. The reader hears the number, passes it to the controller, and the controller looks it up in a list.
That design is from an era when the tools to intercept and replay a low frequency signal were laboratory equipment. They are not anymore. Handheld cloners are sold openly, some retail key duplication kiosks will copy common prox formats, and a writable card replays the captured number in a way no reader or controller can distinguish from the original. Access control software cannot help here, because from the door’s point of view nothing unusual happened.
Prox persists anyway, for reasons that are practical rather than technical. It is installed in an enormous number of buildings. The cards are inexpensive, the readers are inexpensive, the technology is universally interoperable, and it works with gloves, in the rain, and through a wallet. Ripping it out is a project with a budget, and the failure mode it creates is invisible until an incident.
The right position is narrow: prox is acceptable during a migration so nobody is locked out, and it is not acceptable as the end state. Any building with a facilities budget and a multi year horizon should have a written plan to retire it, even if the plan runs over three budget years.
13.56 MHz smart credentials, and why not all are equal#
A 13.56 MHz smart credential does something a prox card cannot: it and the reader authenticate each other before any credential data moves, using keys stored on both sides. A captured transmission is not replayable, because the exchange differs every time.
The detail that gets missed is that the frequency describes the radio, not the cryptography. Several early 13.56 MHz implementations were broken publicly. MIFARE Classic, which uses the proprietary Crypto1 cipher, was the subject of published academic attacks that made practical cloning possible. HID’s legacy iCLASS was likewise the subject of published cryptanalysis. Cards using those technologies are still in service in many buildings and are still sold. Specifying “13.56 MHz” on a drawing buys nothing on its own.
What to specify instead is the actual technology and the key management model. MIFARE DESFire EV3 and HID Seos are the technologies commonly specified for new commercial work in California. Beyond the name, three questions decide whether the deployment is actually secure: are the credentials programmed with keys unique to this customer rather than the manufacturer’s published default keys, who holds those keys, and what happens to the system if the key holder is replaced. A DESFire deployment left on the manufacturer’s published default keys can be read by anyone who knows those keys, which leaves the building no better protected than it was on prox and costs considerably more.
The link between the reader and the controller deserves the same attention. Wiegand is a one way, unencrypted interface that has been the default for decades and can be tapped at the reader to capture credential data. OSDP version 2 with Secure Channel is bidirectional and encrypted, supervises the reader so a removed or substituted reader raises an alarm, and was published as an international standard, IEC 60839-11-5:2020. Specify OSDP with Secure Channel on new work, and specify it on retrofits where the existing cabling supports it.
Mobile credentials over Bluetooth and NFC#
A mobile credential puts the credential in an app on the user’s phone, presented over Bluetooth Low Energy at a distance or NFC on a tap. The cryptography is comparable to a current smart card, and the operational differences are what actually matter.
Issuance is an email or text with an enrollment link. Nothing is printed, encoded, mailed or handed across a leasing desk. Revocation happens from the management console and takes effect the moment the reader or controller syncs, with no card to chase down. For an organization that onboards and offboards people constantly, that is the entire argument.
The costs are real. Mobile credentials are licensed per user on most platforms, sometimes bundled into the per door subscription, which on cloud access platforms runs roughly $150 to $600 per door per year, about $12 to $50 per door per month, as a California commercial planning range as of 2026. Readers that support both a phone and a card cost more than card only readers. And the practical reality is that a portion of any population will not install an app: residents who do not want a property management app on a personal phone, employees using a personal device without a policy that covers it, older phones that the platform does not support, and contractors who need access for two days.
Plan every mobile deployment with a physical fallback. A dual technology reader that accepts a smart card and a phone costs slightly more and removes the entire class of problem, including the dead battery lockout at 6 a.m.
PIN, multi-factor and biometrics at sensitive doors#
Credentials answer what a person carries. At a small number of doors that is not enough.
A PIN keypad at the reader adds something the person knows to something they carry. It belongs at telecom and server rooms, pharmacy and medication storage, cash handling, records rooms and high value storage, and it costs almost nothing beyond the keypad reader. Two factor at four doors is a better investment than a credential upgrade at forty, if the budget only stretches one way.
Biometrics remove the shared credential problem entirely, because a fingerprint or face cannot be handed to a coworker. They also introduce a data category with its own exposure. The California Consumer Privacy Act as amended treats biometric information processed to identify a person as sensitive personal information, which carries notice and use limitation obligations, and collecting biometrics from employees or residents is a decision for the owner’s counsel rather than for a specification writer. Where a project does specify biometrics, settle in advance where the template is stored, whether it stays on a card or on the reader, how it is deleted when a person leaves, and what the notice says.
Comparing the credential options side by side#
| 125 kHz prox | 13.56 MHz smart credential | Mobile (BLE or NFC) | |
|---|---|---|---|
| How it authenticates | Broadcasts a fixed number in the clear | Encrypted mutual authentication with the reader | Encrypted exchange from an app on the phone |
| Copy resistance | Copied in seconds with inexpensive tools | Strong on current technology with customer keys; weak on broken legacy implementations | Strong; bound to the device and revocable |
| Credential cost | Lowest per card | A few dollars more per card | Per user license, usually annual |
| Reader cost | Lowest | Moderate | Moderate to high, especially dual technology |
| Issuance | Encode and hand over a card | Encode and hand over a card, plus key management | Send an enrollment link; the user does the rest |
| Revocation | Delete in software; the card still opens any other system reading that format | Delete in software; the card cannot be repurposed | Revoke from the console; nothing to collect |
| User experience | Works with gloves, in weather, through a wallet | Same | Hands free on Bluetooth, tap on NFC; a dead battery is a lockout |
| Lifecycle fit | Poor where turnover is high; cards are rarely returned | Good if a return process exists | Strong; no physical inventory to track |
| Where it belongs | Legacy only, during a migration | Default for new commercial systems | Staff, tenants willing to use an app, contractors and temporary access |
The pattern is that prox loses on security, smart cards win on universality, and mobile wins on lifecycle. Most commercial buildings end up running smart cards and mobile together on dual technology readers, which is why the reader decision matters more than the credential decision. Our access control systems page covers how the readers, controllers and power supplies are specified, and the cloud vs on-premise access control guide covers where the credential database lives.
Running a phased migration without locking anyone out#
An occupied building cannot lose its entry security for an afternoon, and a resident who cannot get in at 10 p.m. is a bigger problem than a cloned card. The sequence below is what keeps both true.
| Step | What happens | Who is affected |
|---|---|---|
| 1. Inventory | Survey every opening, reader model, wiring type and credential format, and count active credentials | Nobody; survey only |
| 2. Set the end state | Choose the smart credential technology, the key management model, whether mobile is included, and OSDP with Secure Channel where the wiring allows | Design team |
| 3. Install dual frequency readers | New readers accept both the existing prox and the new smart credential | Nobody notices a change |
| 4. Issue new credentials in waves | Staff first, then tenants by floor, wing or building, with written notice and a staffed help window | One group at a time |
| 5. Watch the logs | A weekly count of prox reads shows exactly how long the tail is | Administrator only |
| 6. Announce a cutoff date | Publish it, extend once if a group is behind, and staff the final week | Remaining holdouts |
| 7. Disable 125 kHz at the reader | Turn off the prox side in reader configuration, with a documented rollback held for 30 days | Anyone who ignored the notices |
| 8. Retire the format | Delete old credential records, dispose of returned cards, update as-builts and administrator documentation | Records only |
Steps 3 and 5 are what make this work. Dual frequency readers mean the migration has no cutover moment, and the log count replaces guessing about whether the population has moved. Extending the cutoff once is normal and should be planned for rather than treated as a failure.
We used this approach on occupied renovations at Little Tokyo Towers in Los Angeles and Horton House in San Diego, where residents stayed in place through the work and entry security had to function every night of the project. Our guide to low voltage work in occupied buildings covers the noticing and scheduling side of the same problem.
Credential lifecycle in high turnover buildings#
In a building with steady turnover, the technology matters less than the workflow around it. A DESFire deployment where nobody deactivates departed residents is less secure than a prox deployment with a disciplined offboarding process, because an active credential in the wrong hands opens the door regardless of how well it is encrypted.
Four things decide whether the lifecycle works. First, one system of record: the property management system, the HR directory or the access platform, with the others following it, never three lists maintained by hand. Second, a trigger that fires automatically, such as an identity provider sync that deactivates the badge when the account is closed, or a documented move out checklist that includes credential revocation as a line item with a signature. Third, an audit anybody can run: a monthly report of active credentials compared against the current rent roll or employee roster, with a written expectation of who reviews it. Fourth, a defined process for contractors, vendors and temporary staff, with expiring credentials rather than permanent ones.
This is where mobile credentials earn their licensing cost. Revocation is instant, there is no card to recover from someone who has already moved out, and issuance does not require the new resident to be physically present at a leasing office during business hours. In multifamily and affordable housing, where turnover is constant and the leasing office is the administrator, that difference shows up every month rather than once at commissioning. Cost planning for the whole system is covered in our access control installation cost guide.
Next step#
Send the door schedule, the credential format in use today and the count of active credentials, and we will return a migration scope with the reader swaps, credential quantities, licensing and the cutover sequence written out. Start at request a bid. If the credential decision is still open, tell us the turnover rate and who administers the system, and we will say which way we would go and why.
This article is general information for planning and specification, not a bid, engineering advice or legal advice. Codes and standards change; confirm the current edition with the authority having jurisdiction. Scope and price for a specific building come only in a written proposal.