Guide
Fob, card, mobile or biometric: which access control credential
Updated
The credential decision quietly sets your running cost for the next ten years, and it is the one part of the specification a non-specialist can genuinely judge.
The five options
| Credential | Strength | Weakness |
|---|---|---|
| Keypad or PIN | Cheapest per door, no credentials to issue or lose | Codes get shared, so there is no meaningful audit trail of who entered |
| Proximity fob | Cheap, robust, familiar, easy to issue and revoke | Easy to lose and, on older low-frequency technology, easy to clone |
| Smart card | Doubles as photo ID, supports encrypted credentials | Printing and reissuing cards is an ongoing cost and an admin job |
| Mobile credential | Nothing to issue or collect back, instant revocation, works well across sites | Per-user licence, and you need a policy for staff who will not use a personal phone |
| Fingerprint or face | Nothing to lose or lend, strongest link between person and entry | Highest cost per door and it processes biometric data, which is special category personal data |
The question that decides it
How often do people join, leave or lose things? A stable office of thirty with low turnover is well served by fobs. A warehouse with agency staff, a school with visitors and contractors, or a business across five sites will spend more on issuing and chasing fobs than it would on mobile licences. Work out your annual churn and the true cost per credential, including the admin time, before you decide.
Encryption is not optional any more
Older 125kHz proximity technology can be copied with equipment that costs very little, which matters if the door protects stock, cash, controlled drugs or personal data. Modern encrypted 13.56MHz credentials and secure reader-to-controller protocols are the standard answer. Ask any installer, in writing, which credential technology and which reader-to-controller protocol they are proposing, and whether it is encrypted.
Biometrics: read this first
Fingerprint and facial recognition readers process biometric data used to uniquely identify a person, which is special category data under UK data protection law. That means you need an Article 9 condition as well as a lawful basis, you will normally need a data protection impact assessment because you are monitoring people at a workplace, and you need a genuine answer to the question of what happens for staff who object. The ICO's surveillance guidance is explicit that a DPIA is required for processing likely to result in high risk, including monitoring individuals at a workplace (ICO). None of that makes biometrics wrong, it makes them a decision rather than a default.
Mixing credentials
Most systems will read more than one credential type, so you can put mobile on the front door for staff, fobs on the loading bay for drivers, and a keypad on the bin store. Ask whether the readers proposed support more than one technology, because retrofitting a second credential later means changing readers.