---
title: "Physical Access Control"
description: "Door access systems built on OSDP and encrypted credentials, integrated with your identity directory so leavers lose the badge and the login together."
url: "https://nixit.io/services/access-control/"
lang: "en"
---
# Physical Access Control

Access control designed as part of identity, not separately: encrypted credentials, audited doors and offboarding that closes every door at once.

A company we assessed had a tidy access control system with a well-maintained cardholder database. It also had a box of thirty unassigned spare cards in a drawer, twelve active badges belonging to people who had left, and readers wired with Wiegand on the outside face of the building, where the cable could be reached with a screwdriver. The system produced convincing reports. It did not control access.

Access control is an identity problem that happens to involve doors. Treated as a facilities purchase, it drifts out of step with who actually works at the company. Treated as part of identity, it stays accurate on its own.

## Credentials and the reader link

Two weaknesses account for most of what we find. The first is the credential itself: 125 kHz proximity cards and MIFARE Classic offer no real cryptographic protection, and cheap handheld cloners copy them in seconds without the holder noticing. Replacing them with DESFire EV3 or an equivalent removes an entire category of attack for the price of new cards and, sometimes, new readers.

The second is the link between reader and controller. Wiegand carries the card number in clear with no authentication, on wiring that frequently runs through the unsecured side of the door. OSDP with Secure Channel encrypts that connection and reports tampering or disconnection. Migration can be staged, since many readers support both, and we prioritise perimeter and high-value doors first.

Mobile credentials on phones are a reasonable option where the population is largely employees with company devices, and they simplify issuing and revoking. They are less suitable where you must admit contractors and visitors who will not install anything.

## Joining access control to identity

The most valuable integration is the least visible one. When the access system reads its population from the same directory as everything else, an employee's departure removes their badge automatically at the same moment it disables their accounts. Nobody has to remember. Access reviews can then treat "who can open the data centre door" as one more question alongside "who can reach the finance system", answered from a single review rather than two disconnected ones.

This also fixes visitor and contractor handling, which is where controls usually leak. Time-limited credentials that expire automatically are far more reliable than an intention to collect a card back at the end of a project.

## Doors, rules and emergencies

A door schedule states, for each door, who may pass, at which times, and what happens when power fails or the fire alarm activates. Escape routes must release; secure rooms may not. Getting this wrong is a life-safety matter, so it is agreed in writing and verified against fire regulations rather than inherited from a default setting.

Higher-security areas can use anti-passback to prevent a card being handed back through a door, interlocks so two doors cannot be open at once, or two-person rules for sensitive rooms. These are worth applying selectively, where the risk justifies the friction.

## Evidence

Every door event is logged, and that log is the reason auditors take the system seriously. ISO 27001 and NIS2 both expect physical access to controlled areas to be restricted and reviewable, and a complete event history answers those questions directly. Door logs are also personal data, so retention is defined and access to the log is itself controlled.

Combined with camera footage, door events become genuinely useful: an alarm at a specific reader at a specific second points straight to the relevant clip instead of an afternoon of searching.

## Who this is for

This suits organisations running an ageing badge system nobody fully trusts, companies subject to ISO 27001 or NIS2 that must evidence physical controls, sites where an audit has flagged former employees holding valid credentials, and anyone planning an office move who would rather design this once than inherit it.

We handle the technical design, the credential and protocol decisions, the identity integration and the compliance evidence. Where national regulation requires a licensed security company to install the physical equipment, we work with one while remaining responsible for the design and the systems it depends on.

## Outcomes

Leavers lose building access the day they leave, without anybody remembering to arrange it. Credentials cannot be cloned from a pocket. When an auditor asks who could enter a given room last quarter, the answer is a report rather than an investigation.

## What you get

- Door schedule defining who passes where, when, and what happens in an emergency
- Encrypted credentials on OSDP Secure Channel, replacing Wiegand and cloneable cards
- Access control integrated with the identity directory and the leaver process
- Complete, tamper-evident audit trail of door events with defined retention
- Documented fail-safe and fail-secure behaviour agreed with fire safety requirements

## Technologies

HID, Suprema, Nedap, 2N, Axis, OSDP, MIFARE DESFire EV3, Microsoft Entra ID

## Frequently asked questions

### Are our existing proximity cards a problem?

If they are 125 kHz proximity or MIFARE Classic, then yes. Those technologies have no meaningful cryptography, and a cloner costs very little and copies a card in seconds from a pocket's distance. Modern credentials such as MIFARE DESFire EV3 or SEOS use mutual authentication with diversified keys and cannot be copied that way. Most readers can be migrated gradually, running both formats during transition.

### What is wrong with Wiegand wiring?

Wiegand is a 1980s protocol with no encryption and no authentication between reader and controller. Anyone who can reach the wiring on the unsecured side of a door can capture credentials or inject a valid card number directly. OSDP with Secure Channel encrypts that link and detects tampering and disconnection. For any new installation it should be the default, and for existing sites it is the single highest-value upgrade.

### Should access control connect to our HR or identity system?

Yes, and this is where most of the benefit is. When physical access is managed separately, badges stay active long after people leave, because the process depends on somebody remembering to tell the facilities team. Driving both from the same directory means one offboarding action removes network access and door access together, and access reviews can cover physical doors alongside applications.

### Can we use fingerprints or facial recognition?

Technically yes, but biometric data is a special category under GDPR and needs an explicit lawful basis, not merely convenience. Several European supervisory authorities have ruled against biometric attendance systems where a card would have worked, because the processing was not proportionate. Where biometrics genuinely fit, we favour templates stored on the credential rather than in a central database, which reduces the consequences of a breach considerably.

### What happens to the doors during a power failure or a fire?

That is decided per door before installation, not left to the hardware default. Escape routes must release so people can get out, which usually means fail-safe locks tied into the fire alarm, while a server room may need to stay locked. The distinction has life-safety and insurance implications, so we document it per door and confirm it against local fire regulations rather than assuming.

