
RFID Credential Formats for Smarter Access
- loktec
- 6 hours ago
- 6 min read
A card that opens one door but fails at another is rarely just a card problem. It is usually evidence of an unclear credential strategy: incompatible reader technology, a legacy card number range, poor encoding controls or an access-control platform that has outgrown its original design. Understanding RFID credential formats helps organisations specify access control that remains secure, manageable and practical as sites, teams and risks change.
For facilities, security and IT teams, the challenge is not simply choosing a fob, card or mobile pass. The credential must work with the selected readers, communicate the correct identity to the controller, support the required level of security and fit daily operational processes. That includes issuing and withdrawing permissions, accommodating contractors, managing lost cards and maintaining a clear audit trail.
What RFID credential formats actually mean
The term RFID credential format can describe several related, but different, elements. Treating them as one decision is a common cause of expensive compatibility issues.
First, there is the radio technology used between the credential and reader. This determines whether a card or fob can be read at all. Second, there is the data held on the credential - such as a card number, site code or encrypted application data. Third, there is the output format sent from the reader to the access-control panel, often using a traditional Wiegand interface or a more secure supervised protocol. Finally, there is the identity format within the access-control software, where a credential is matched to a person, access group and permission schedule.
A system can appear compatible at one level while failing at another. For example, two credentials may both operate at 13.56 MHz, yet use different applications, encryption keys or data layouts. The reader may detect both cards but only recognise one as a valid authorised credential.
The main RFID credential formats in commercial access control
Low-frequency 125 kHz credentials
Low-frequency credentials, commonly described as proximity cards or prox cards, have been widely used for decades. They are simple, dependable and often found on established commercial, industrial and multi-occupancy sites. Many operate by presenting an unencrypted identifier to the reader.
Their advantage is familiarity and broad legacy compatibility. Their limitation is security. A fixed, easily read identifier can be copied with relatively accessible equipment, particularly where the card number is the only factor protecting an entrance. For a low-risk internal door, an existing low-frequency estate may remain proportionate. For new systems protecting critical assets, plant areas, server rooms, finance operations or sensitive records, it is seldom the preferred long-term choice.
Organisations should also be cautious with generic labels such as ‘125 kHz compatible’. The frequency alone does not confirm the card number structure, manufacturer arrangement or reader compatibility. A controlled test against the actual system is more reliable than an assumption based on a product description.
High-frequency 13.56 MHz credentials
High-frequency credentials operate at 13.56 MHz and support more sophisticated data handling. This category includes common technologies such as MIFARE and HID iCLASS, but these are not automatically interchangeable. Each may use its own applications, sectors, keys and security mechanisms.
MIFARE Classic remains common in legacy estates because it is economical and has historically supported access control, cashless vending, printing and other building functions. However, its original security architecture is no longer considered appropriate for new higher-security deployments. Where MIFARE Classic is already in place, its risks should be assessed in the context of the doors protected, reader configuration and any additional security measures.
For new deployments, credentials using modern cryptography, such as MIFARE DESFire EV3 or equivalent secure technologies, offer stronger protection against cloning and unauthorised data access. They can support mutually authenticated communication between reader and credential, encrypted data and more controlled key management. These capabilities matter most where a credential grants access to high-value areas or is used across multiple buildings and applications.
Mobile credentials
Mobile credentials use a managed identity on a smartphone rather than a physical card. Depending on the platform and handset, they may communicate through Near Field Communication or Bluetooth Low Energy. They are well suited to organisations with frequent staff movement, flexible workplaces, multiple sites or a desire to reduce the handling of physical cards.
Their value is operational as much as technical. A new starter can receive a credential without waiting for a card to be printed and posted. Permissions can be amended remotely, while a lost phone can be removed from the access-control system without rekeying doors or recovering a physical fob. Mobile should not be viewed as a universal replacement, however. Visitor access, shared operational devices, workforce preferences and sites where personal phones are restricted may still require cards or fobs.
A mixed estate is often the sensible answer. Secure physical credentials can serve operational staff, contractors or controlled environments, while mobile access supports office users and rapid administration.
Card format is not the same as card technology
The word ‘format’ is frequently used to mean the number programmed into a card. In a traditional arrangement, the reader sends a facility code and card number to the controller. A 26-bit Wiegand format is a familiar example, although numerous proprietary and custom formats are used.
This approach can work, but it needs careful governance. If two suppliers issue cards using overlapping numbers, or a site expands without a defined numbering plan, duplicate identities can enter the system. A copied card may also be difficult to identify if the system relies only on a predictable serial number.
For organisations retaining Wiegand-based panels, the format should be documented precisely: bit length, facility code, card number range, leading zeros, parity arrangement and intended site allocation. That information is operationally valuable during reader replacement, system migration and incident investigation.
Where possible, secure reader-to-controller communication should also be considered. Wiegand wiring is widely understood but can expose credential data between reader and panel. Supervised, encrypted alternatives such as OSDP improve resistance to interception and tampering, while providing stronger device oversight. This is particularly relevant for externally mounted readers, remote gates and doors in publicly accessible areas.
Choosing the right level of credential security
The appropriate choice depends on the risk at each door, not on a single technology preference across the whole estate. A staff entrance to a general office, a loading-bay gate, a pharmaceutical store and a cash-handling room do not present the same threat profile.
A proportionate specification considers what an intruder could gain by cloning, stealing or misusing a credential. It also considers the likely impact of downtime. A door that protects a server room may justify encrypted credentials, secure reader communications and multi-factor authentication. A low-risk cupboard may not.
Four practical questions help establish the right direction:
What assets, information or operational processes does each access point protect?
Could a copied credential create a material safety, financial or compliance risk?
Will the site need to issue credentials across several locations, tenants or departments?
How quickly must access permissions be granted, changed and revoked?
The answer may lead to different credential types within one managed system. The key is that the policy is deliberate, documented and maintainable.
Plan for migration, not just installation
Many organisations cannot replace every reader and credential overnight. A staged migration can preserve continuity while moving the highest-risk doors onto a stronger platform first. Dual-technology readers may support both a legacy card population and new secure credentials during the transition, reducing disruption for staff and avoiding a sudden mass reissue.
Migration should begin with a survey of installed readers, controllers, door hardware, existing card stocks and access-control databases. The current credential format needs verification rather than assumption. It is also worth reviewing inactive cards, duplicate records, shared credentials and old contractor permissions before transferring data into a new platform.
This is where technical design has a direct operational benefit. A well-planned migration can reduce unnecessary card volumes, improve audit accuracy and establish a clean credential lifecycle from issue through to revocation. It also gives organisations a clear route to integrate visitor management, smart lockers, key cabinets and other controlled assets where appropriate.
Key management is part of the security model
Secure RFID credentials depend on more than the card itself. Cryptographic keys, card programming procedures, reader configuration and supplier controls all require management. If the same default keys are used widely, or if programming rights are poorly controlled, even a capable credential technology can be weakened.
Organisations should establish who may order credentials, who holds encoding authority, how numbering ranges are allocated and how lost or damaged cards are dealt with. Security teams should be able to confirm that credentials issued by different departments or sites cannot accidentally conflict.
For larger estates, a managed access-control platform can centralise these controls and provide clearer reporting. SALTO systems, for example, can support intelligent credential management alongside remotely administered permissions, helping teams reduce the administrative burden associated with physical keys and disconnected access records.
Specify for the next operational change
The right RFID credential format is the one that supports the organisation’s security posture now without restricting its next move. That may mean accommodating a legacy credential temporarily, selecting encrypted high-frequency cards for new secure areas, or introducing mobile access where faster onboarding will make a measurable difference.
Before ordering credentials in volume, test the proposed format on representative doors, confirm the full identity path from reader to software, and agree who will manage the data and keys after commissioning. With this foundation in place, access control becomes more than a door-opening mechanism: it becomes dependable infrastructure for controlling risk, supporting people and keeping operations moving.





.png)
Comments