Commercial Access Control Guide

Key Card vs Fob vs Mobile Access Control in Los Angeles: Which Credential Should Your Office Actually Use?

Most Los Angeles offices are running a card technology standardised in 1996 over reader wiring designed before it, and nobody in the building knows. This guide covers what each credential actually protects against, the wiring decision hiding behind the credential decision, and the nine questions that make two access control quotes comparable. Innov8av is a California C-10 Electrical contractor (CSLB #1043428) and BSIS Alarm Company Operator (ACO 7755), working across Los Angeles since 2016.

Updated September 14, 2026 12 min read Offices, warehouses & multi-tenant buildings
HomeLearning CenterKey Card vs Fob vs Mobile Access Control
The short answer

Specify an encrypted smart card or a phone — then specify OSDP to the reader

Two answers cover almost every Los Angeles office. Staff carry either an encrypted 13.56 MHz smart card (DESFire EV3, iCLASS SE or Seos class) or a mobile credential in the phone they already own. Then insist the readers talk to the controller over OSDP with Secure Channel switched on, not Wiegand. The credential is the reversible decision — you can re-badge eighty people in an afternoon. The reader wiring is the decision that ends up inside the walls, and changing it later means pulling cable through a finished, occupied office.

The two decisions hiding inside “what card?”

When a facility manager asks “card, fob or phone?”, only one of the two decisions that matter is on the table. The other almost never gets discussed, and it is the one that costs money to change.

  • Decision one — what the person carries. Card, fob, phone, fingerprint, PIN. This is the cheap decision: credentials are consumables, and re-badging a floor is an afternoon of work.
  • Decision two — how the reader talks to the controller. Wiegand or OSDP. Whoever specifies the cable decides it, it is invisible afterwards, and it determines whether the reader on the outside of your door is a sealed device or an open microphone. Changing it later means new cable to every reader.

Get decision two right and decision one becomes low-stakes. Get it wrong and the best credential in the world is defeated by a device that fits behind the reader faceplate — see the Wiegand section below.

The credential comparison

Two short tables, because the security question and the administration question have different answers. First, what each credential resists:

CredentialHow hard is it to copy?Where it fits
125 kHz prox card or fob
HID Prox, EM4100, AWID
Trivial. No encryption at all; a handheld duplicator sold online for about $30 reads and writes it.Legacy systems only. Do not specify it on a new project.
MIFARE Classic
13.56 MHz, Crypto-1
Broken. Public attacks recover the keys; some widely sold chips also carry a hardware backdoor (see below).Nowhere in a security application. Fine for a vending machine.
Encrypted smart card
DESFire EV3, iCLASS SE, Seos
Hard. AES-128 mutual authentication — the reader has to prove it knows the key before the card answers. Not copyable with consumer tools.The default for offices, labs, warehouses and multi-tenant buildings.
Mobile credential
phone or watch, NFC or Bluetooth
Hard, and the secret lives in the phone’s secure hardware rather than a card you can leave on a desk.Offices where everyone already carries a company-associated phone.
Biometric
fingerprint, face, palm
Not copyable in the card sense, but it introduces a privacy obligation. See the California section.A second factor on a handful of high-value doors — not a whole building.
PIN keypadShoulder-surfed, shared and written on a sticky note. Useful only in combination.Second factor after hours, or a back-up for a door nobody uses.

Then the part that decides your Monday mornings — issuing, revoking and paying for the things:

CredentialIssuing and revokingCost pattern
Prox / MIFARE Classic cardOrder plastic, hold stock, hand it over, chase it on the last day. A card not returned is a card still in the world.Cheapest per credential, highest hidden cost when a card walks.
Encrypted smart cardSame physical workflow, but revoking in software genuinely ends access — there is no copy to worry about.Modest premium per card. One-off.
Mobile credentialIssued and revoked from a dashboard in seconds. Nothing to order, nothing to collect, and people notice a missing phone faster than a missing badge.Often an annual fee per user. Ask for the number before you like the demo.
BiometricEnrolment is in person; revocation is instant; the template is a record you now hold and must account for.Reader cost is higher and the compliance overhead is real.

Notice what is missing from both tables: controller brand names. That is deliberate. Almost every mainstream platform can be specified well or badly — quality is set by the credential technology, the reader protocol, the cable and the commissioning, not the logo on the panel.

Why the prox card in your pocket is a copy waiting to happen

The 125 kHz proximity card is still the most common credential in Los Angeles commercial buildings, and it does exactly one thing: on entering a reader’s field it announces its number to anybody who asks. No encryption, no authentication, and no way for the card to tell your reader from an attacker’s.

The number it announces is usually the standard 26-bit Wiegand format (HID calls it H10301): two parity bits, an 8-bit facility code and a 16-bit card number. That is 256 facility codes and 65,536 card numbers — about 16.7 million unique combinations for the entire planet, in an open format any manufacturer may produce and nobody centrally tracks. Duplicate cards are in circulation as a matter of arithmetic, and the facility code is frequently printed on the box the cards arrived in.

The practical consequences for a building manager are short:

  • A card can be copied in seconds by anyone who gets near it — a jacket on a chair, a lanyard on a desk, a badge in a queue.
  • Collecting the plastic back on someone’s last day proves nothing about whether a copy exists.
  • Because the format is open, a card from another building can match yours by coincidence.

If your system uses prox, you rarely need a new controller — in most cases you replace readers and credentials and keep the head end, which is exactly the kind of scope we cost out during a free on-site assessment.

“13.56 MHz” is not an answer

Salespeople move customers from 125 kHz to “13.56 MHz” and call it a security fix. Frequency is not security. MIFARE Classic runs at 13.56 MHz and its Crypto-1 cipher has been publicly broken for years.

It got worse in 2024. Researchers at Quarkslab published work on the “static encrypted nonce” variant of MIFARE Classic-compatible cards and, in the process, found a hardware backdoor: a single bit in the command field switches the card from normal key authentication to a backdoor key, letting anyone who knows it read the memory and recover every user-defined key — even fully diversified ones — with a few minutes of physical access to the card. The work named the Shanghai Fudan Microelectronics FM11RF08S, FM11RF08, FM11RF32 and FM1208-10, along with NXP MF1ICS5003/5004 and Infineon SLE66R35 parts.

So the useful question to a bidder is never “what frequency?” It is “which chip, by name?” and the answer should be a part number you can look up.

What good actually looks like: encrypted cards and phones

The modern secure credentials — MIFARE DESFire EV3, HID iCLASS SE and HID Seos — all use AES-128 mutual authentication. The reader must prove it holds the right key before the card reveals anything, which is why consumer copying tools get nothing useful from them. Of the three, DESFire EV3 additionally carries a Common Criteria EAL5+ evaluation, an independent security assessment the other two have not published.

Mobile credentials solve a different problem: administration. Nothing to order, nothing to collect, revocation in seconds, and a behavioural advantage — people lend a badge without thinking and do not lend a phone. The honest trade-offs are a flat battery, whatever your BYOD policy says, and a per-user annual fee on many platforms. Many offices issue both: mobile for staff, a physical encrypted card for contractors, visitors and the person whose phone died.

Aliro 1.0, and whether you should wait for it

On 26 February 2026 the Connectivity Standards Alliance released Aliro 1.0, a credential and communication standard meant to end the fragmentation in mobile access. It uses asymmetric cryptography so the phone and the reader authenticate each other, and it supports three transports: NFC for tap, Bluetooth LE for a longer-range deliberate unlock, and Bluetooth LE plus ultra-wideband for hands-free entry. It is designed to work where there is no network — underground garages, elevators — which is where most mobile access disappoints people today.

The reason it matters commercially is the wallet commitments: Apple, Google and Samsung have all agreed to align their mobile wallets with Aliro, and the Alliance lists Allegion, Aqara, HID, Kastle, Kwikset, Last Lock, Nordic Semiconductor, Nuki, NXP, Qorvo and STMicroelectronics among the companies expected to certify first.

Should you delay a build-out to wait for it? No. Aliro is entering certification and commercialisation now, not shipping at scale in Los Angeles offices. Delaying an occupancy date for an unreleased credential standard is a bad trade. What you should do instead costs nothing:

  • Put the question in the bid documents — are these readers firmware-upgradeable, and does the manufacturer have a stated Aliro path?
  • Understand which part is expensive to replace. Credentials are cheap. Controllers are moderate. Readers are the expensive item, because replacing one means a technician, a lift or a ladder, a door, and sometimes a repaint.
  • Get the answer in writing from every bidder, so the cheapest quote can be compared honestly against the one that is $40 a reader more expensive because the hardware has a future.

The decision that is actually in the walls: Wiegand vs OSDP

Here is the part that almost no quote explains. Between the reader on the wall and the controller in the closet there is a protocol, and for most of the installed base in Los Angeles it is Wiegand — the interface the Security Industry Association standardised as AC-01 back in 1996. Wiegand is one-way, unencrypted, unauthenticated and unsupervised: the controller cannot tell whether the reader is healthy, has been removed, or has been tampered with.

That has a well-documented consequence. At Black Hat in 2015, researchers demonstrated BLEKey, a Bluetooth implant that taps the Wiegand data wires behind a reader. The reader cover is four screws; the team demonstrated fitting the implant in 60 seconds. A commercially sold equivalent, the ESPKey, stores up to 80,000 credential bitstreams and replays them on demand through its own web interface.

Read that again with your credential choice in mind. The implant sits after the card has been decoded, so it does not care whether the badge was a $2 prox card or a $12 encrypted smart card. Over Wiegand wiring, a cheap implant defeats an expensive credential. Anyone selling you a credential upgrade without mentioning the reader protocol is selling you half a system.

OSDP is the answer, and it is not new or exotic. It was created in 2008 by HID Global, Mercury Security and Lenel, handed to the Security Industry Association in 2012, approved by the International Electrotechnical Commission in May 2020 as IEC 60839-11-5:2020, and most recently updated by SIA as version 2.2.2 in October 2024. What it changes:

  • Encryption. OSDP Secure Channel adds AES-128 encryption and authentication between reader and controller — the same profile the US federal government requires.
  • Supervision. The link is bidirectional and constantly monitored, so a reader that is unplugged, removed or interfered with raises an event instead of silently going quiet.
  • Two wires instead of twelve. OSDP runs over RS-485 and supports multi-drop, so several readers can share one home run instead of each demanding its own bundle back to the panel.

And the reason this is a rough-in decision rather than a settings change — the cable itself:

WiegandOSDP (RS-485)
Practical run lengthAbout 500 ft on 18 AWG; roughly 300 ft on 20 AWGUp to 1,200 m (4,000 ft) per segment on heavier gauge; 22–20 AWG for runs to about 1,000 ft
TopologyOne home run per readerMulti-drop — several readers on one run
Cable specMulti-conductor shielded, 12+ conductors in practiceShielded twisted pair, 100–130 Ω characteristic impedance; 22 AWG / 120 Ω is the common OSDP part

Those distances decide where the controller can physically live. In a single-floor suite it rarely bites. In a warehouse, a multi-floor tenancy or a campus with a gate, the 500-foot Wiegand ceiling is what forces extra panels, extra enclosures, extra power and extra pathways into the budget — all of which are cheaper to avoid at rough-in than to discover at trim. If you are already planning a fit-out, this belongs in the same conversation as the rest of the low-voltage scope and the structured cabling.

Two more practical notes. You do not have to rip out a Wiegand system to start: the normal path is to identify the highest-risk doors, fit OSDP readers with converters onto the existing panel, and convert the rest at refresh. And when you specify OSDP, ask for products carrying SIA OSDP Verified — SIA’s own conformance testing programme — because “OSDP-capable” on a datasheet and Secure Channel actually enabled on your site are two different things.

Fingerprints at the door: what California law actually says

Biometric readers get sold on convenience and bought on instinct. Two California provisions are worth knowing before you enrol a single employee, and neither is the one vendors usually quote at you.

1. Biometric data is “sensitive personal information.” Under the CPRA amendments to the CCPA, biometric information processed for the purpose of uniquely identifying a person is sensitive personal information under Civil Code § 1798.140(ae). That brings a notice-at-collection duty and a consumer right to limit its use. The employment-context exemption expired on 1 January 2023, so your employees count as people with those rights, not just your customers.

2. Labor Code § 1051 is narrower than people think — and sharper. It makes it a misdemeanor to require, as a condition of getting or keeping a job, that an employee or applicant be photographed or fingerprinted by a person who wants those photographs or fingerprints in order to furnish them to another employer or a third person, where they could be used to the employee’s detriment. It is not a ban on fingerprint time clocks or fingerprint door readers. It is a rule about who else ends up holding the print — which is exactly the question a cloud-hosted biometric platform raises.

So the three questions to put to any biometric vendor, in writing, are: where is the template stored, who else can access it, and what happens to it when the employee leaves. And it is worth saying plainly, because fear is sold here: California has no stand-alone biometric statute with a private right of action of the kind Illinois has under BIPA. The CCPA’s private right of action is limited to certain data breaches. That is a reason to store templates carefully, not a reason to panic.

The design answer for most Los Angeles offices is unglamorous. Biometrics belong on a handful of openings where the consequence of a shared badge is serious — a server room, a cash office, a pharmacy or evidence room — as a second factor behind a card or a phone, never as the only way in. And whatever you put on the door, the egress side is governed by the building code, not by your security preference; that detail sits in the code and permit guide.

What it costs, and where the money actually goes

Innov8av’s published planning range for access control is $3,000 to $40,000+, and structured cabling runs $3,000 to $30,000+. Those are planning ranges, not quotes — we do not price a system sight unseen. Every project gets a free on-site assessment and a written line-item proposal with model numbers.

The reason the range is that wide is that the cost driver is doors, not credentials. Each controlled opening needs a reader, a lock or strike, a door position switch, a request-to-exit device, power, and a cable path that may cross a fire-rated wall. Credentials are a rounding error at twenty-five users and a genuine line item at five hundred.

Three things make two access control quotes impossible to compare: the reader protocol (a Wiegand job and an OSDP job are not the same job, nor are the cable counts behind them); the cable specification (pair count, gauge, and plenum rating where the code requires it — the silent substitution here is the commonest reason a low bid is low); and recurring cost, because a cheaper installation with a per-head subscription can cost more by year three. That last comparison is laid out in the cloud versus on-premise guide.

Nine questions to put in writing before you sign

Hand this to every bidder. The answers are short, they are checkable, and the differences between them will tell you more than the price line.

  1. Which credential chip, by name? The answer should be a part number — DESFire EV3, iCLASS SE, Seos — not “13.56 MHz” and not “encrypted.”
  2. Wiegand or OSDP between reader and controller? If OSDP, is Secure Channel enabled on our site, or merely supported by the hardware?
  3. Are the readers SIA OSDP Verified?
  4. What is the cable specification per door — pair count, gauge, shielded or not, and plenum-rated where required?
  5. Are the readers firmware-upgradeable, and to what? Ask specifically about Aliro.
  6. Who holds the credential encryption keys — us, or you? If you leave, can we still issue cards?
  7. If mobile: what is the per-user cost per year, and what happens to our credentials if we change providers?
  8. If biometric: where do templates live, and who else can read them?
  9. What is handed over at closeout? Door schedule, as-built drawings, cable test results, a controller configuration backup, and administrator credentials that belong to you.

Question six catches more people than the rest combined. On some platforms the installer holds the keys that let credentials be issued, and a customer who wants to change contractors discovers the system is not really theirs.

Why Innov8av for an access control project in Los Angeles

We are a California C-10 Electrical contractor, CSLB #1043428, and a BSIS Alarm Company Operator, ACO 7755 — both verifiable in seconds on the CSLB and DCA websites, and worth checking on every bidder, not just us. Working across Los Angeles County since 2016, insured and bonded, our own technicians rather than subcontractors, a one-year parts-and-labor warranty on every installation, 5.0 across 22 verified Reviews.io reviews, BBB A+, English and Spanish.

That licence combination matters here because access control is a cabling project wearing a security badge. Since we are the low-voltage contractor as well as the alarm company, the OSDP home run gets pulled to the right specification the first time, the pathway is coordinated with the other trades before the ceiling closes, and nobody negotiates between two vendors over whose cable it is. Existing clients get same-day response on service calls.

Want a straight answer on what your building needs? Text or call (805) 517-4668, or book a free on-site assessment. You will get a written line-item proposal with model numbers — including the reader protocol, in writing.

Related resources

Access control systems in Los Angeles
Service

Access Control Systems

Service page
Design, installation and service of commercial access control across Los Angeles County.
Open page
What access control costs in Los Angeles
Cost

Access Control Cost

Planning guide
What drives the price per door, and the ranges to plan around before you get quotes.
Open page
Cloud versus on-premise access control
Compare

Cloud vs On-Premise

Comparison
Where the recurring cost lives, who holds your data, and what happens when the internet drops.
Open page
Office build-out low-voltage checklist
Build-out

Office Build-Out Checklist

Guide
Cabling, cameras and access control in one tenant-improvement scope, with the schedule.
Open page

Frequently Asked Questions

Can someone copy my office key card?

If it is a 125 kHz proximity card — HID Prox, EM4100, AWID and similar — then yes, easily. Those cards carry no encryption and announce their number to any reader that asks, and handheld duplicators that read and write them sell online for around $30. The same is true of MIFARE Classic cards at 13.56 MHz, whose cipher has been publicly broken. Encrypted smart cards such as DESFire EV3, iCLASS SE and Seos use AES-128 mutual authentication, meaning the reader must prove it knows the key before the card answers, and they are not copyable with consumer tools. If you do not know which type you hold, we can identify it during a free on-site assessment.

What is the difference between a key card and a key fob?

Usually nothing but the shape. A fob is the same chip in a plastic keyring instead of a credit-card-sized card, and it is read by the same reader with the same security — or the same lack of it. The security question is the technology inside, not the form factor. Cards win where you want a photo ID printed on the credential; fobs win where staff wear them on a keyring and cards get bent. Both cost roughly the same at the technologies worth buying.

Is mobile access control more secure than a card?

Comparable on cryptography, better on administration and human behaviour. A good mobile credential keeps its secret in the phone’s secure hardware, and a modern encrypted card keeps its secret in a secure element — both use strong mutual authentication. The real difference is what people do: badges get lent to colleagues, left on desks and handed in late; phones get carried, guarded and missed within minutes. Mobile also lets you revoke access in seconds without chasing anybody for plastic. The trade-offs are flat batteries, your BYOD policy and a per-user annual fee on many platforms — ask for that number before the demo wins you over. Many offices issue both, with cards kept for contractors and visitors.

Should I wait for Aliro before buying an access control system in 2026?

No — but do write it into the bid. The Connectivity Standards Alliance released the Aliro 1.0 specification on 26 February 2026, with Apple, Google and Samsung committed to aligning their wallets with it, and it supports NFC, Bluetooth LE and Bluetooth LE plus ultra-wideband for hands-free entry. It is entering certification and commercialisation now, not shipping at scale in Los Angeles buildings, so delaying an occupancy date for it is a bad trade. What is free is asking every bidder whether their readers are firmware-upgradeable and whether the manufacturer has a stated Aliro path. Readers are the expensive item to replace — credentials are not.

What is OSDP, and do I actually need it?

OSDP is the Open Supervised Device Protocol — the modern replacement for Wiegand between a reader and its controller. It was created in 2008, given to the Security Industry Association in 2012, approved by the International Electrotechnical Commission in May 2020 as IEC 60839-11-5:2020, and updated by SIA as version 2.2.2 in October 2024. It matters because Wiegand is unencrypted and unsupervised: implants such as BLEKey, demonstrated at Black Hat in 2015, and the commercially sold ESPKey fit behind a reader in about a minute and capture or replay credential data no matter how good your card is. OSDP Secure Channel adds AES-128 encryption and authentication, supervises the link so a removed reader raises an alarm, and runs over RS-485, which supports far longer cable runs and lets several readers share one home run. If you are cabling a new space, specify OSDP now — the cable is the part you cannot change cheaply later.

Can we use fingerprints for employee access in California?

Yes, with care, and the constraint is mostly about who else ends up with the data. Under the CPRA, biometric information used to identify a person is “sensitive personal information” under Civil Code § 1798.140(ae), which carries a notice-at-collection duty and a right to limit use — and the employment exemption expired on 1 January 2023, so employees are covered. Separately, Labor Code § 1051 makes it a misdemeanor to require, as a condition of employment, that someone be fingerprinted or photographed by a person who wants those records in order to furnish them to another employer or a third person where they could be used to the employee’s detriment. California has no Illinois-style biometric private right of action. Practically: ask any vendor in writing where templates are stored, who can access them and what happens at termination, and use biometrics as a second factor on a few high-value doors rather than on the whole building.

Related: Access control · Access control cost · Cloud vs on-premise · Build-out checklist · Structured cabling

Service Areas  |  All Services
Scroll
📞 Call — same-day response Text us