How to Evaluate Access Control Companies

The access control companies worth hiring are the ones that let you keep ownership of your credential data, hand you a working export when the contract ends, and build on open standards instead of a closed proprietary system.

Most buyers compare access control companies on price per door and installation speed, then discover the real cost only after the contract is signed. A properly scoped access control system is a ten year commitment to a vendor’s data policies, service response times, and hardware roadmap, not a one time purchase. This guide sets out the provider categories active in the market today, the questions that separate a durable vendor relationship from a costly one, and the compliance checks that matter for United States buyers.

  • There are 5 distinct provider categories active in the market, from national integrators to cloud native platform vendors.
  • Most readers in the field use 125 kHz proximity cards or 13.56 MHz smart cards built on the ISO/IEC 14443 standard.
  • OSDP, which replaced the older Wiegand interface for reader-to-controller wiring, supports AES-128 encryption in its Secure Channel mode.
  • Federal agencies, federal contractors, and many grant funded state and local agencies must confirm NDAA Section 889 compliance before purchasing.
  • Government buyers issuing PIV credentials under FIPS 201 need a system certified to handle that credential format specifically.

The Provider Categories You Will Meet in a Bid

Access control companies fall into a small number of business models, and knowing which one you are talking to tells you what to expect before the first meeting ends.

  • National integrators that install and service systems across many regions, usually reselling a manufacturer’s platform.
  • Regional or local integrators that typically support one or two manufacturer platforms.
  • Manufacturer direct sales teams, where the company that builds the panel or software also sells and supports it.
  • Cloud native platform vendors that sell software first and treat door hardware as a supporting component.
  • Locksmith and door hardware led firms that add access control software from a third party.

The table below compares how these categories typically handle the questions that matter most.

Provider Category Data Ownership Terms Contract End Export Encryption Key Control
National integrator Set by the underlying manufacturer platform, not the integrator Depends on the platform’s own export tool Held by the platform vendor in most cases
Regional or local integrator Depends on which manufacturer platform is installed Requires the manufacturer’s cooperation Held by the platform vendor in most cases
Manufacturer direct Defined in the manufacturer’s own customer contract Usually available through a built in export tool Held by the manufacturer unless negotiated otherwise
Cloud native platform vendor Defined in the vendor’s terms of service Varies widely, confirm before signing Held by the vendor unless a bring your own key option exists
Locksmith or door hardware led firm Set by the third party software partner, not the firm Requires the third party’s cooperation Held by the third party software partner

Who Actually Owns Your Credential Data

The company that hosts your badge, PIN, and biometric records, not the company that installed your card readers, is the one that decides what happens to your credential data.

Ask every finalist to put data ownership in writing rather than in a sales deck. A clean answer states plainly that the customer owns all credential and event data, that the vendor may not resell or repurpose it, and that ownership survives a change of vendor. Security teams handling government or critical infrastructure sites can also reference identity and access management guidance published by the National Institute of Standards and Technology, including the FIPS 201 standard that defines PIV credential requirements for federal agencies, when writing these requirements into an RFP. Where the system stores biometric templates rather than just a badge number, several states set stricter rules; Illinois’ BIPA, for example, requires written consent before collection and a defined retention limit tied to the purpose the data was collected for.

Cloud Storage Versus On Premise Storage

A cloud hosted platform centralizes updates and remote management, and it also means your data sits on infrastructure you do not control unless the contract says otherwise. An on premise or hybrid deployment keeps credential data on servers inside your own facility, which matters more for government sites, utilities, and other locations where data residency is a compliance requirement rather than a preference.

What Happens When the Contract Ends

A written export and transition clause is the only real guarantee that you will not lose years of access history, badge photos, and door schedules when you switch systems.

Before you sign, ask for the exact file format of an end of contract export, whether migration hours are included or billed separately, and how long the outgoing vendor retains your data after the account closes. A vendor that cannot answer these questions in writing has not thought past the sale.

Open Architecture or Proprietary Lock In

An access control company that will not confirm, in writing, which reader and controller protocols it supports is signaling a proprietary lock in strategy rather than an open one.

Open architecture means the panels, readers, and software can talk to hardware from other manufacturers if you ever need to expand or replace a component. Proprietary systems save the vendor money on support calls and cost you flexibility for the life of the contract. A general overview of access control concepts is a useful reference when comparing vendor terminology.

Reader and Credential Formats to Name in the RFP

Ask specifically about OSDP support, which replaced the older Wiegand protocol for communication between readers and controllers, and about credential formats including 125 kHz proximity cards and 13.56 MHz smart cards built on the ISO/IEC 14443 standard. For sites with exterior readers, ask whether the hardware carries an IP65 or IP66 rating under IEC 60529 for weather resistance and an IK10 rating under IEC 62262 for impact resistance, since a reader without either spec is a maintenance problem waiting to happen on an outdoor door. Panels connecting over standard IP networking are also bound by the 100-meter Cat6 run length set in the TIA/EIA-568 standard, the same limit that applies to any PoE camera sharing that switch.

The True Cost of Ownership Beyond the Hardware Invoice

Software licensing, network or cellular connectivity, firmware update policy, and technician response time typically cost more over five years than the door hardware itself.

Ask for the all in annual cost per door for years two through five, not just the installation quote, and whether firmware and security patches are included in that fee.

Service Level Terms Worth Putting in Writing

A service level agreement should state a maximum response time for a door that fails locked, whether after hours emergency support is included, and whether the vendor stocks spare parts locally. A verbal promise of fast service is not a service level agreement.

NDAA Compliance and Integration With What You Already Run

Federal agencies, federal contractors, and many state and local agencies that receive federal grant funding can only accept access control hardware that complies with NDAA Section 889 restrictions on certain named manufacturers. This applies with particular weight to homeland security and critical infrastructure buyers, where a single non-compliant camera or panel in the bill of materials can jeopardize an entire federal contract. See our dedicated guide to NDAA compliance for how the restriction applies component by component, not just brand by brand.

Ask any finalist for a written NDAA Section 889 compliance statement covering every camera, panel, and reader in the bill of materials, including parts built by a subcontractor. OEM relationships mean a restricted component can sit inside hardware carrying an unrelated brand name, so the statement needs to name the chipset and sensor origin, not just the label on the box. Critical infrastructure buyers can also review guidance from the Cybersecurity and Infrastructure Security Agency. Confirm too how the system integrates with tools you already operate, including facial recognition and video search, since access control rarely works in isolation, and any camera added to that mix should speak a standard ONVIF Profile S or Profile T stream, drawing up to 15.4 watts under 802.3af or up to 30 watts under 802.3at, rather than a proprietary format only one vendor’s software can read.

Questions to Put in Writing Before You Sign

  • Who owns the credential and event data, in plain language, not a link to a privacy policy.
  • What format does an end of contract export take, and is a sample available to review.
  • Which reader and controller protocols does the system support today, named specifically.
  • Who holds the encryption keys for data at rest and in transit.
  • What is the guaranteed response time for a door that fails locked.
  • Is firmware and security patching included in the annual fee or billed separately.
  • Can the vendor provide a written NDAA Section 889 compliance statement for every component.
  • What does integration with an existing video management system actually require.

Frequently Asked Questions

What is the biggest mistake buyers make when choosing access control companies?

Comparing only the price per door and installation timeline, while leaving data ownership, contract end terms, and service response commitments out of the written agreement. Those items determine the real cost long after installation day.

Is a cloud based access control system less secure than an on premise one?

Not inherently. Security depends on how encryption keys are managed and how quickly patches are applied, not on where the servers sit. Ask for specifics rather than assuming either model is automatically safer.

What does NDAA Section 889 mean for an access control purchase?

It restricts federal agencies, federal contractors, and many grant funded state and local agencies from purchasing certain named manufacturers’ video surveillance and telecommunications equipment. Access control hardware that includes cameras or components sourced from a restricted manufacturer needs a written compliance statement too.

Should I choose a manufacturer direct provider or a local integrator?

It depends on the size of the site and the service model you need. A manufacturer direct relationship can mean faster access to firmware updates, while a strong local integrator can offer faster on site response for hardware issues. Ask each finalist how they handle the part the other model is usually better at.

How long should an access control contract run before I can renegotiate terms?

There is no universal answer, since it depends on hardware amortization and the vendor’s own policy. What matters more is whether the contract includes a clear data export clause and a defined exit process, so that renewal, not lock in, is what keeps you with a vendor.

What is FIPS 201 and why would it come up in an access control bid?

FIPS 201 is the federal standard that defines Personal Identity Verification, or PIV, credentials used by U.S. government agencies. A government buyer needs a system certified to issue and read PIV credentials specifically, which is a narrower requirement than general support for 125 kHz or 13.56 MHz cards.

Argu was built for the buyer who has already lived through a bad access control decision. Rather than asking you to replace the cameras and panels you already own, Argu layers a vision agent on top of your existing access control and video infrastructure, described in plain language instead of a proprietary rules engine. If you are evaluating providers, talk to Argu about your security stack.

Last updated: September 2026

Sharing the post:

Monitor & Secure your perimeter today!

Schedule a demo to see the AI agent run on your own footage.

Get a Custom Demo

See how the agent performs on your specific environment.

Join world-class security teams

By submitting this form, you agree to our Privacy Policy. Your data is encrypted.

Seamless Integration With

Related Posts

Critical Infrastructure Security: Definition and Scope

Critical infrastructure security protects power, water, ports, and communications systems designated vital by CISA....

Video Redaction: What It Is and Why It Is Required

Video redaction blurs or masks identifiable people and plates before footage is shared, often a...

False Alarm Rate: Why It Matters More Than Detection

False alarm rate is the share of security alerts that are not real events. See...

Occupancy Analytics: What It Measures and Why

Occupancy analytics counts people in a space or zone in real time using existing cameras,...

What Is ANPR? Automatic Number Plate Recognition

ANPR reads vehicle license plates from live video in real time. See how it works,...

Best AI Video Analytics Companies in 2026

Ten AI video analytics and video surveillance companies compared on sourced facts: founding, HQ, core...