25 Jun 2026

In logistics hubs, production facilities and distribution centers, the access control system is invisible—until it isn't. For decades, the 125 kHz card has been the workhorse of industrial credentialing: inexpensive, reliable and universally understood. It does exactly what it has always done. That consistency has served many organizations well, even as security needs and credential From authentication to smart buildings, gain expert insights about unified access.

The same card technology that opened the warehouse gate in 2005 is opening it today. And while operations teams have upgraded conveyors, ERP systems and warehouse management platforms, the front door has often remained on technology selected for an earlier era.

Major operational event

Why? It is rarely about a lack of awareness. More often, organizations are balancing cost, time and operational risk. In a facility that never stops, a full systemwide upgrade can feel less like a routine project and more like a major operational event.

The path forward is continuous modernisation: deploying an agile access layer that adapts to new security requirements and credential technologies over time, rather than replacing everything at once. Universal reader technology makes that possible, without the “Big Bang” shutdown.

Why legacy systems can benefit from modernisation

The 125 kHz card (also named proximity, prox or low-frequency) helped set a practical standard for convenience and broad compatibility, but many organizations are now evaluating where its security model can be improved by newer options:

  • Increased cryptographic protection. Traditional low-frequency credentials transmit a fixed identifier, which can make them harder to align with today’s expectations for encrypted and dynamic authentication.
  • Increased credential validation. Traditional proximity systems do not provide the kind of mutual authentication or challengeresponse mechanisms that are increasingly common in newer credential platforms.
  • Better protection from duplication/cloning. Because the credential model is comparatively simple, 125 kHz cards present fewer barriers to duplication or cloning than modern encrypted credentials which are inherently designed to better distinguish authorized users from copied identifies.
  • An opportunity to secure the full path. Many legacy deployments also rely on Wiegand communication between reader and controller, creating a strong case for modernisation to encrypted, supervised protocols that help protect credential data in transit.
  • Keeping the interoperability benefit of Prox. Newer open standard provides the same interoperability benefits while addressing improved security.

The opportunity for the front door

At the same time, security teams face an expanding threat landscape and compliance requirements

A traditional access control upgrade is not just a technology swap. It means new readers at every door, new credentials issued to every employee and contractor, platform reconfiguration and installation labor across a facility that cannot afford to stop. Against that backdrop, the rational choice is often to do nothing.

At the same time, security teams face an expanding threat landscape and compliance requirements that increasingly demand encrypted credentials. And with Apple Wallet corporate badges and BLE mobile credentials moving into the mainstream, employees and contractors will soon expect to use their phone as their badge, at least as an option if not the primary means of credential presentation. Four specific friction points keep organizations locked in place long after they know they should move.

  • The logistical bottleneck - Replacing a proximity-based system has traditionally meant doing everything at once: new readers, new credentials, new platform configuration, every employee and contractor rebadged before the cutover date. For a site running 24/7 with extensive staff and rotating contractors, that isn’t just an upgrade. It’s a logistical nightmare requiring a hard shutdown. The rebadging event alone, coordinating hundreds or thousands of people through a credential transition on a fixed timeline, can consume weeks of HR and security operations bandwidth.
  • The Credential Soup - Most logistics organizations are not running one clean credential population. They are running three or four: legacy prox for permanent staff, a different format inherited from an acquisition, a contractor badge system managed by a third party, a mobile pilot that never fully rolled out. None of them talk to each other, and no single reader handles all of them.
  • Frozen Infrastructure - Static readers support only the credential formats they shipped with or have limited format support for updates. When a new vulnerability is disclosed or a new mobile standard is released, the hardware has no path to adapt. The only option is physical replacement, which means another capital project, more installation labor, and the same shutdown risk all over again.
  • The Cyber-Physical Gap - IT departments run zero-trust architectures and encrypt everything on the network. Then the same organization unlocks its server room with a Wiegand-protocol reader transmitting credentials in plain text. The IT security perimeter ends at the network edge. The physical front door is a different conversation entirely, and often nobody's budget.

The way forward: Continuous modernisation of access credentials

A continuous modernisation plan is both easier and more cost-effective than a one-time “rip-and-replace” event

The answer to the Big Bang problem is not a better-planned Big Bang. It is a fundamentally different approach to access infrastructure that treats modernisation as an ongoing capability rather than a one-time event.

A continuous modernisation plan is both easier and more cost-effective than a one-time “rip-and-replace” event. It significantly lowers the labor and logistical costs of rebadging the entire organization at once and eliminates the need for forced downtime entirely. Instead, organizations upgrade incrementally (by site, by department, or as credentials expire), keeping operations running and spreading costs over time. And with future-proof universal reader technology, the reader stops being a fixed asset and becomes a platform that continues to evolve as needs change.

Start with a universal infrastructure

The foundation of continuous modernisation is a universal reader that can handle whatever credentials are already in the building (legacy proximity, modern smart cards, mobile credentials) while remaining ready for whatever comes next. As access technologies continue to evolve, support for additional credential formats and security approaches can be added through firmware updates rather than hardware replacement, ensuring a secure and future-proof access system.

The burden can further be eased by the use of a universal credential that can support existing formats along with new formats, enabling the credentials to work on existing readers as well as new readers.

Let old and new credentials coexist

Legacy 125 kHz cards continue to function in parallel until the organization is ready to retire them

With a multi-technology reader in place, the rebadging process becomes a rolling transition rather than a synchronized event.

New employees get modern credentials from day one. Existing staff transition as badges are renewed or departments are prioritised. Legacy 125 kHz cards continue to function in parallel until the organization is ready to retire them. Eventually, 125 kHz support or insecure credential support can be switched off, cleanly and deliberately, via a remote firmware update. That means no forced downtime, and no mass confusion at the turnstiles. This applies equally to secure migration to either modern symmetric credentials (such as HID Seos or LEAF) or emerging asymmetric credentials (such as PKOC, Aliro or LEAF Verified).

Secure the whole chain, not just the card

Upgrading credentials without addressing the communication layer is only half the job. Moving from Wiegand to OSDP Secure Channel (a bidirectional, AES-128 encrypted protocol) closes the replay attack vulnerability and adds tamper detection between reader and controller.

Modern credentials and a secure communication layer together protect the entire authentication chain, from the card or smartphone all the way to the access control platform. This becomes critical when the reader is handling the decryption of a secure credential and then communicating to the panel in clear text. OSDP encrypts this last step of communication, while also offering industry best practices for managing reader devices.

Choose infrastructure that doesn't choose for you

Interoperability is not just a convenience feature. It is a strategic asset

Interoperability is not just a convenience feature. It is a strategic asset. A facility running universal reader infrastructure compatible with most transponder technologies and credential formats (physical and mobile) is insulated from vendor lock-in and the next credential transition.

Universal readers also act as merger-and-acquisition insurance: when a company acquires a facility running a different badge system or a contractor arrives with an unfamiliar card format, existing readers can be configured to accept the new credentials from day one. As access technologies and credential standards continue to evolve, organizations with adaptable reader infrastructure will absorb that shift as a firmware update. Those without it will face another capital project.

A market in motion: beyond legacy credentials

Emerging open standards (which reduce vendor dependency) and widely adopted proprietary platforms are both moving the market toward stronger cryptography. These credentials can be delivered on physical smart cards, mobile devices or both. Organizations selecting reader infrastructure today should ensure it is prepared to support this transition without requiring a hardware swap.

Several initiatives are gaining significant traction:

  • LEAF Identity: An interoperable credential framework built on strong symmetric encryption, already deployed across a meaningful number of installations and a proven replacement path for legacy proximity systems
  • LEAF Verified: A nextgeneration physical access credential platform built on NXPs MIFARE DUOX that uses publickey cryptography to eliminate traditional shared key management and enable interoperable, vendorneutral access control.
  • PKOC (Public Key Open Credential): An open, vendor-agnostic credential specification from the Physical Security Interoperability Alliance using asymmetric public key cryptography, in which the private key never leaves the device and a derivative of the public key is the credential
  • Aliro: An open mobile-first credential standard released in February 2026 by the Connectivity Standards Alliance (CSA), the organization behind the Matter smart home standard. Backed by Apple, Google, Samsung, and 220+ industry members providing native wallet, offline device support and mailbox features on top of asymmetric public key cryptography.
  • HID Seos: A widely deployed proprietary credential platform that continues to drive responsible, large-scale secure symmetric-based encrypted deployments across small to enterprise environments for both card and mobile deployment, including wallet.

Security that scales

The same principles apply equally to a single site or a logistics operator running 5,000 employees

The same principles apply equally to a single site or a logistics operator running 5,000 employees across a dozen sites. Because no single cutover date is required, a large organization can sequence the migration by site, by department or by credential expiry cycle. The operational risk that makes a traditional upgrade unthinkable at scale becomes manageable when the transition is invisible to the people walking through the doors.

The pressure to act is reaching a tipping point. Apple Wallet corporate badges and BLE mobile credentials are arriving in earnest in 2026, as well as asymmetric smart card options. These technologies are rapidly moving from isolated pilots into mainstream enterprise deployment across logistics, manufacturing and production environments.

Evolve security infrastructure

Organizations that have already invested in universal reader and credential infrastructure that is firmware-updateable and mobile-ready will absorb that shift without a second thought. Those that haven't will face another rip-and-replace decision just as the mobile credential wave hits.

Organizations that have already invested in universal reader and credential infrastructure

Continuous modernisation is not a one-time project. It is a permanent capability: the ability to evolve security infrastructure at the organization's own pace, without forced downtime, without mass rebadging events, and without being held hostage to the next credential transition.

Organizations that build that capability today are not just solving a security problem. They are future-proofing the way their facilities move.

Universal access from ELATEC

ELATEC's TWN4 universal readers are built on an agnostic design strategy: multi-technology, multi-frequency, and software-configurable, so organizations are not locked into a single credential technology or vendor.

Key capabilities across the TWN4 family:

  • Support for 100+ physical and mobile credentials and 60+ transponder technologies
  • RFID, NFC, and BLE in a single reader platform
  • Software-configurable via the ELATEC DevPack: credential formats, encryption settings, and security protocols can be updated remotely without hardware replacement
  • Supports backward and forward compatibility as new standards emerge
  • Available in a range of form factors for door access, desktop enrollment, OEM integration, and industrial applications