Access Control Systems

Read revision 4

Revision 4 · Aug 26, 2026 +340 −227

Corpus sync: neutrality remakes, note hygiene, datasheet relocation, transformer-split cross-refs
Showing changes from Rev 3 to Rev 4 in Access Control Systems.
---
title: Access Control Systems
…41 unchanged lines
# Referenced Standards {toc}
+## Where the contract documents, the adopted building code, or a referenced standard conflict, the more stringent requirement shall govern unless the Engineer of Record directs otherwise in writing.
+
## Equipment, materials, software, and installation shall comply with the latest adopted edition of the following standards.
…26 unchanged lines
| ISO/IEC 7816 | Identification cards — Integrated circuit cards |
−## Where the contract documents, the adopted building code, or a referenced standard conflict, the more stringent requirement shall govern unless the Engineer of Record directs otherwise in writing.
−
# Submittals {toc}
…25 unchanged lines
- "OSDP configuration documentation"
- "Cybersecurity hardening plan"
−default: "Product data for head-end, controllers, readers, credentials, power supplies, REX, DPS, modules"
+default:
+ - "Product data for head-end, controllers, readers, credentials, power supplies, REX, DPS, modules"
+ - "System riser diagram"
+ - "Door schedule cross-referenced to door, frame, and hardware schedule"
+ - "Controller panel schedules with point assignments"
+ - "Head-end architecture diagram"
+ - "Sequence-of-operations matrix"
+ - "Battery calculations for each power supply"
+ - "OSDP configuration documentation"
+ - "Cybersecurity hardening plan"
```
…15 unchanged lines
- "Installer qualifications and factory training certificates"
- "Proposed acceptance test plan with procedures, schedule, personnel, and forms"
−default: "Manufacturer's installation instructions retained on site"
+default:
+ - "Manufacturer's installation instructions retained on site"
+ - "Installer qualifications and factory training certificates"
+ - "Proposed acceptance test plan with procedures, schedule, personnel, and forms"
```
…21 unchanged lines
- "Warranty documentation"
- "Manufacturer service contact list"
−default: "Accepted acceptance test report"
+default:
+ - "Accepted acceptance test report"
+ - "As-built system drawings with final addresses"
+ - "Head-end programming record"
+ - "Administrator credentials and encryption key turnover package"
+ - "Operation and maintenance manual"
+ - "Warranty documentation"
+ - "Manufacturer service contact list"
```
…2 unchanged lines
## Installer Qualifications {toc}
+### The access control system shall be installed by a contractor regularly engaged in the design and installation of electronic access control systems with documented experience on at least three projects of comparable size and complexity within the past five years.
+
+### The factory certification held by the installer-in-charge shall be as indicated in the datasheet.
+
```datasheet
label: Installer Factory Certification
type: radio
options:
- "Required for the specific controller platform"
− - "Required for controller platform and head-end software"
− - "Not required (installer qualifications by experience only)"
−default: "Required for controller platform and head-end software"
+ - "Required for the controller platform and the head-end software"
+ - "Not required (qualification by documented project experience)"
+default: "Required for the specific controller platform"
```
−### The access control system shall be installed by a contractor regularly engaged in the design and installation of electronic access control systems with documented experience on at least three projects of comparable size and complexity within the past five years.
+### The installer-in-charge shall be present on site during programming, head-end configuration, and acceptance testing.
−### The installer-in-charge shall hold factory certification on the specific controller platform being installed and shall be present on site during programming, head-end configuration, and acceptance testing.
−
### Personnel making low-voltage terminations at controllers and readers shall be trained in the manufacturer's wiring methods, in OSDP Secure Channel commissioning, and in the project's cybersecurity hardening procedures.
…22 unchanged lines
## Indoor and Exterior Equipment Ratings {toc}
+### Access control equipment installed in indoor, conditioned, occupiable spaces shall be rated for 0°C to 50°C ambient operating temperature and 0 to 85 percent non-condensing humidity.
+
+### Equipment installed in unconditioned spaces, electrical rooms, attics, or telecommunications rooms shall be confirmed against the extreme conditions of the space.
+
+### Readers installed at exterior openings shall be rated for the local exterior temperature extremes.
+
+### The enclosure rating of readers at exterior openings shall be as indicated in the datasheet.
+
```datasheet
−label: Exterior Reader Environmental Rating
+label: Exterior Reader Enclosure Rating
type: select
options:
− - "IP55 / NEMA 3R"
− - "IP65 / NEMA 4"
− - "IP66 / NEMA 4X (corrosive or wash-down environments)"
−default: "IP65 / NEMA 4"
+ - "NEMA 3R (IP55)"
+ - "NEMA 4 (IP65)"
+ - "NEMA 4X (IP66)"
+default: "NEMA 4 (IP65)"
```
−### Access control equipment installed in indoor, conditioned, occupiable spaces shall be rated for 0 °C to 50 °C ambient operating temperature and 0 to 85 percent non-condensing humidity.
+### Readers in corrosive, coastal, or wash-down environments shall be rated NEMA 4X.
−### Equipment installed in unconditioned spaces, electrical rooms, attics, or telecommunications rooms shall be confirmed against the extreme conditions of the space.
−
−### Readers installed at exterior openings shall be rated for the local exterior temperature extremes and shall carry an enclosure rating appropriate to the exposure.
−
## Sprinkler and Plenum Exposure {toc}
…4 unchanged lines
# System Architecture {toc}
+## The system architecture shall be as indicated in the datasheet.
+
```datasheet
label: System Architecture
type: radio
options:
− - "Networked, on-premises head-end (default)"
+ - "Networked, on-premises head-end"
- "Networked, cloud-managed head-end"
- "Hybrid (on-premises controllers, cloud-hosted management)"
− - "Standalone per door (small projects only)"
−default: "Networked, on-premises head-end (default)"
+ - "Standalone per door"
+default: "Networked, on-premises head-end"
```
−## The access control system shall be configured as a networked architecture with a central head-end software platform, intermediate door controller panels distributed throughout the building, and reader-side devices at each controlled opening.
+## The access control system shall comprise a head-end software platform, intermediate door controller panels distributed throughout the building, and reader-side devices at each controlled opening.
## The head-end shall hold the system of record for users, credentials, and access privileges.
…7 unchanged lines
## Controller Topology {toc}
+### The controller topology shall be as indicated in the datasheet.
+
```datasheet
label: Controller Topology
type: radio
options:
− - "Multi-door panel (4-, 8-, or 16-reader panels in centralized cabinets)"
+ - "Multi-door panel (reader panels in centralized cabinets)"
- "Controller-per-door (edge controller adjacent to each opening)"
− - "Hybrid (centralized panels for grouped doors, edge controllers where pathway is impractical)"
−default: "Multi-door panel (4-, 8-, or 16-reader panels in centralized cabinets)"
+ - "Hybrid (centralized panels for grouped doors, edge controllers elsewhere)"
+default: "Multi-door panel (reader panels in centralized cabinets)"
```
+### The panel size serving each group of controlled openings shall be as indicated in the datasheet.
+
```datasheet
−label: Maximum Doors per Centralized Panel
+label: Centralized Panel Size
type: select
+drawing_ref: "access control riser diagram"
options:
- "2-reader panel"
- "4-reader panel"
- "8-reader panel"
- "16-reader panel"
−default: "8-reader panel"
+default: deferred
```
…4 unchanged lines
## Equipment Location {toc}
−### The head-end server shall be located in [[drawing: as indicated on the head-end architecture drawing]].
+### The head-end server shall be located in [[drawing: as indicated on the contract documents]].
### Controllers shall be located in [[drawing: as indicated on the panel location plan]] in secure equipment closets or IT rooms with physical access restricted to authorized personnel.
# Door Controllers {toc}
+## Door controllers (panels) shall be UL 294 listed devices providing autonomous access decision capability, supervised reader and input/output circuits, encrypted communication to the head-end, and a local cache of the rule set sufficient to operate during head-end outage.
+
+## The controller-to-head-end communication method shall be as indicated in the datasheet.
+
```datasheet
label: Controller-to-Head-End Communication
type: radio
options:
− - "TCP/IP over Ethernet with TLS 1.2 or higher (default)"
+ - "TCP/IP over Ethernet with TLS 1.2 or higher"
- "TCP/IP over Ethernet with TLS 1.3"
− - "Wireless (802.11) — only where wired pathway is impractical"
−default: "TCP/IP over Ethernet with TLS 1.2 or higher (default)"
+ - "Wireless (802.11) with TLS 1.2 or higher"
+default: "TCP/IP over Ethernet with TLS 1.2 or higher"
```
−## Door controllers (panels) shall be UL 294 listed devices providing autonomous access decision capability, supervised reader and input/output circuits, encrypted communication to the head-end, and a local cache of the rule set sufficient to operate during head-end outage.
+## Controller-to-head-end communication shall be encrypted at TLS 1.2 or higher whichever transport is selected.
−## Controllers shall communicate to the head-end over TCP/IP using TLS 1.2 or higher.
−
## Wireless controller-to-head-end communication shall not be used except where a wired pathway is genuinely impractical.
…2 unchanged lines
## Reader-to-Controller Protocol {toc}
+### The reader-to-controller protocol shall be as indicated in the datasheet.
+
```datasheet
label: Reader-to-Controller Protocol
type: radio
options:
− - "OSDP v2.2 with Secure Channel (default)"
− - "OSDP v2.1 with Secure Channel (where v2.2 not available)"
− - "Wiegand (legacy only — not for new installations)"
−default: "OSDP v2.2 with Secure Channel (default)"
+ - "OSDP v2.2 with Secure Channel"
+ - "OSDP v2.1 with Secure Channel"
+ - "Wiegand (existing legacy reader infrastructure)"
+default: "OSDP v2.2 with Secure Channel"
```
−### OSDP v2.2 with Secure Channel shall be the default reader-to-controller protocol.
−
### New installations shall not use Wiegand except where the Owner has a legacy reader infrastructure that cannot be replaced in the project scope.
…2 unchanged lines
## Controller Inputs, Outputs, and Supervision {toc}
+### Each controller shall provide inputs for door position switch, request-to-exit, and tamper, and outputs for lock control.
+
+### The extent of circuit supervision shall be as indicated in the datasheet.
+
```datasheet
label: Input and Output Supervision
type: radio
options:
− - "Required on all controller inputs and outputs (default)"
+ - "Required on all controller inputs and outputs"
- "Required on inputs only"
− - "Not required (only for non-critical, low-security openings)"
−default: "Required on all controller inputs and outputs (default)"
+ - "Not required (non-critical, low-security openings)"
+default: "Required on all controller inputs and outputs"
```
−### Each controller shall provide supervised inputs for door position switch, request-to-exit, and tamper, and supervised outputs for lock control.
−
### End-of-line resistors shall be installed per the manufacturer's instructions to enable line supervision; cut, shorted, or grounded reader and input wiring shall be detected and reported.
…4 unchanged lines
# Credential Readers {toc}
+## Readers shall be UL 294 listed and shall communicate to the controller over the reader-to-controller protocol indicated in the datasheet.
+
+## Readers shall be selected for the credential technology specified below.
+
+## The reader mounting method at each controlled opening shall be as indicated in the datasheet.
+
```datasheet
label: Reader Mounting
type: radio
+drawing_ref: "access control door schedule"
options:
− - "Surface mount on door frame mullion or adjacent wall"
− - "Flush / mullion mount within frame profile"
− - "Surface mount on pedestal (parking and exterior gate applications)"
−default: "Surface mount on door frame mullion or adjacent wall"
+ - "Surface mount on the door frame mullion or adjacent wall"
+ - "Flush mount within the frame profile"
+ - "Surface mount on a pedestal or bollard (parking and exterior gate openings)"
+default: deferred
```
+## The reader form factor shall be as indicated in the datasheet.
+
```datasheet
label: Reader Form Factor
type: select
options:
- "Mullion (narrow profile for door frame mounting)"
− - "Wall switch (single-gang) — interior typical"
− - "Wall switch (mullion-width) — exterior typical"
− - "Wall switch (keypad-equipped) — high-security or two-factor"
−default: "Mullion (narrow profile for door frame mounting)"
+ - "Wall switch, single-gang"
+ - "Wall switch, mullion-width"
+ - "Wall switch with integral keypad"
```
−## Readers shall be UL 294 listed and shall communicate to the controller using OSDP v2.2 with Secure Channel as specified above.
+## A keypad-equipped reader is required at any opening where two-factor authentication is specified. {note}
−## Readers shall be selected for the credential technology specified below.
−
## Reader Mounting Height {toc}
+### The reader centerline height above finished floor shall be as indicated in the datasheet.
+
```datasheet
label: Reader Height (Centerline Above Finished Floor)
…3 unchanged lines
min: 34
max: 48
− setpoints: [40, 42, 44, 48]
+ setpoints: [34, 40, 42, 44, 48]
default: 42
```
…11 unchanged lines
## Two-Factor Authentication {toc}
+### The extent of two-factor authentication shall be as indicated in the datasheet.
+
```datasheet
−label: Two-Factor Authentication at High-Security Openings
+label: Two-Factor Authentication
type: radio
options:
- "Not required (single-factor card or mobile credential)"
− - "Required at designated high-security openings (card + PIN)"
− - "Required at all openings"
+ - "Required at designated high-security openings (credential + PIN)"
+ - "Required at all openings (credential + PIN)"
default: "Not required (single-factor card or mobile credential)"
```
…5 unchanged lines
# Credentials {toc}
+## The primary credential technology shall be as indicated in the datasheet.
+
```datasheet
label: Primary Credential Technology
type: radio
options:
− - "13.56 MHz smart card — MIFARE DESFire EV2/EV3 (default)"
− - "13.56 MHz smart card — iCLASS SEOS"
− - "Mobile credential — BLE and NFC"
− - "Combined smart card and mobile credential"
− - "125 kHz proximity (legacy — not for new installations)"
−default: "13.56 MHz smart card — MIFARE DESFire EV2/EV3 (default)"
+ - "13.56 MHz contactless smart card, AES-128 mutual authentication (ISO/IEC 14443)"
+ - "Mobile credential over Bluetooth Low Energy and NFC"
+ - "Combined 13.56 MHz smart card and mobile credential"
+ - "125 kHz proximity (existing legacy credential population)"
+default: "13.56 MHz contactless smart card, AES-128 mutual authentication (ISO/IEC 14443)"
```
−## The default credential shall be a 13.56 MHz smart card based on MIFARE DESFire EV2 or EV3 technology, with mutual authentication and AES-128 encryption between card and reader.
+## A smart card credential shall perform mutual authentication with the reader using AES-128 or stronger encryption with diversified, issuer-managed keys.
−## 125 kHz proximity credentials (HID Prox and equivalents) shall not be used for new installations.
+## 125 kHz proximity credentials shall not be used for new installations.
## Where the Owner has an existing 125 kHz population, the migration plan to a contemporary credential shall be documented in the closeout package.
…7 unchanged lines
## Federal Credential Interoperability {toc}
+### Federal credential interoperability shall be as indicated in the datasheet.
+
```datasheet
label: Federal Credential Interoperability (FIPS 201 / PIV)
…12 unchanged lines
## Credential Quantity {toc}
+### The initial credential quantity furnished shall be as indicated in the datasheet.
+
```datasheet
label: Initial Credential Quantity
…3 unchanged lines
min: 50
max: 5000
− setpoints: [100, 250, 500, 1000, 2500]
−default: 250
+ setpoints: [50, 100, 250, 500, 1000, 2500, 5000]
```
…10 unchanged lines
## Default Lock Type {toc}
+### The project's default electrified locking device type shall be as indicated in the datasheet.
+
```datasheet
label: Default Electrified Locking Device Type
type: select
options:
− - "Electric strike (fail-secure) on standard mechanical lock"
+ - "Electric strike (fail-secure) on a standard mechanical lock"
- "Electrified cylindrical or mortise lock (free-egress)"
− - "Electric exit device (free-egress, exit-only or full-feature)"
− - "Electromagnetic lock (avoid where possible — see policy below)"
+ - "Electric exit device (free-egress)"
+ - "Electromagnetic lock"
default: "Electrified cylindrical or mortise lock (free-egress)"
```
−### The default lock type shall be an electrified cylindrical or mortise lock that preserves free mechanical egress at all times by operating the lever from the egress side without electrical action.
+### An electrified cylindrical or mortise lock preserves free mechanical egress at all times because the egress-side lever operates the latch without any electrical action, which is why it is the baseline selection here. {note}
−### The lock shall secure the latch on the access side and release the access-side lever or trim on a valid credential or REX signal; the egress-side lever shall always operate the latch mechanically.
+### The lock shall secure the latch on the access side and shall release the access-side lever or trim on a valid credential or REX signal.
+### Where the locking device includes an egress-side lever, that lever shall always operate the latch mechanically.
+
## Electromagnetic Locks {toc}
…6 unchanged lines
## Fail-Safe vs. Fail-Secure {toc}
+### Fail-safe or fail-secure operation at each controlled opening shall be as indicated in the datasheet.
+
```datasheet
−label: Default Fail-Safe vs. Fail-Secure Policy
+label: Fail-Safe / Fail-Secure Operation
type: radio
+drawing_ref: "access control door schedule"
options:
− - "Fail-secure default (locked on power loss) for offices, suites, and tenant openings"
− - "Fail-safe default (unlocked on power loss) for stairwell discharge and life-safety egress"
− - "Per-door determination by code analysis"
−default: "Per-door determination by code analysis"
+ - "Fail-secure (locked on loss of power)"
+ - "Fail-safe (unlocked on loss of power)"
+default: deferred
```
−### Fail-safe vs. fail-secure shall be determined per opening by the means-of-egress analysis.
+### Fail-safe or fail-secure operation shall be determined for each opening by the means-of-egress analysis.
−### A stairwell discharge door that must release on a building power failure to permit exit shall be fail-safe; an office suite door that must remain secured on a power failure to protect the contents shall be fail-secure.
+### A stairwell discharge door that must release on a building power failure to permit exit is fail-safe; an office suite door that must stay secured on a power failure to protect its contents is fail-secure. {note}
−### The Engineer shall determine the policy for each opening; this standard does not establish a single default that overrides the code analysis.
+### The Engineer of Record shall make the fail-safe or fail-secure determination for each opening and shall record it on the access control door schedule.
## Lock State Monitoring {toc}
+### Lock state monitoring shall be as indicated in the datasheet.
+
```datasheet
label: Lock State Monitoring
type: radio
options:
− - "Lock state monitored at controller via supervised contact (default)"
+ - "Lock state monitored at the controller via supervised contact"
- "Door position only (lock state not directly monitored)"
−default: "Lock state monitored at controller via supervised contact (default)"
+default: "Lock state monitored at the controller via supervised contact"
```
−### Lock state monitoring — a supervised contact on the lock confirming the lock is mechanically secured — shall be the default where the hardware supports it.
+### Lock state monitoring is a supervised contact on the lock that confirms the lock is mechanically secured. {note}
### Monitoring only door position (closed vs. open) does not detect a latch that has failed to engage or has been propped; lock state monitoring is the means by which the system detects a door that is closed but unlocked. {note}
# Request to Exit {toc}
+## A request-to-exit (REX) device shall be provided at every controlled opening to indicate that an authorized egress is occurring and to suppress the door-forced-open alarm during egress.
+
+## REX devices shall be supervised by the controller.
+
+## The primary REX device shall be as indicated in the datasheet.
+
```datasheet
label: Primary REX Device
type: radio
options:
− - "Passive infrared (PIR) motion sensor over the door (default)"
+ - "Passive infrared (PIR) motion sensor over the door"
- "Integrated REX switch in the lock or exit device"
− - "Wall-mounted push-to-exit button (mag lock applications only)"
− - "Combination PIR + integrated lock REX (high-traffic openings)"
−default: "Passive infrared (PIR) motion sensor over the door (default)"
+ - "Wall-mounted push-to-exit button"
+ - "Combination PIR and integrated lock REX"
+default: "Passive infrared (PIR) motion sensor over the door"
```
−## A request-to-exit (REX) device shall be provided at every controlled opening to indicate that an authorized egress is occurring and to suppress the door-forced-open alarm during egress.
+## A PIR motion sensor shall be mounted directly above the door on the egress side and aimed at the floor immediately inside the opening.
−## REX devices shall be supervised by the controller.
−
−## A PIR motion sensor mounted directly above the door on the egress side, aimed at the floor immediately inside the opening, shall be the default REX device.
−
## Integrated lock REX (a switch in the exit device or lever) shall be used as a supplement where the hardware supports it.
−## A PIR sensor is the default because it triggers on actual egress traffic without requiring the user to take any action, and an integrated REX is a more deterministic indicator that the door is being operated for egress and complements the PIR. {note}
+## A PIR sensor is the baseline because it triggers on actual egress traffic without requiring the user to take any action, and an integrated REX is a more deterministic indicator that the door is being operated for egress and complements the PIR. {note}
## Push-to-Exit Buttons {toc}
…5 unchanged lines
## REX Behavior at Door Position {toc}
−```datasheet
−label: REX Behavior at Door Position
−type: radio
−options:
− - "REX suppresses forced-open alarm; lock remains under access control (free-egress hardware, default)"
− - "REX releases lock; door physically unlocks on REX trigger (mag lock openings)"
−default: "REX suppresses forced-open alarm; lock remains under access control (free-egress hardware, default)"
−```
+### REX behavior is fully determined by the locking device selected — free-egress hardware needs only alarm suppression, while a mag lock has no mechanical bypass and must be electrically released — so it is stated here as a requirement rather than offered as a project selection. {note}
−### For free-egress hardware (electrified mortise, cylindrical, or exit device), REX shall suppress the forced-open alarm but shall not unlock the door.
+### For free-egress hardware (electrified mortise, cylindrical, or exit device), REX shall suppress the forced-open alarm and shall not unlock the door.
−### For mag lock openings, REX or the push-to-exit button shall actually unlock the door because the mag lock has no mechanical bypass.
+### For mag lock openings, REX or the push-to-exit button shall unlock the door.
# Door Position Switches {toc}
+## A door position switch (DPS) shall be provided at every controlled opening to monitor whether the door is closed.
+
+## DPS contacts shall be supervised by the controller.
+
+## The controller shall report and log forced-open, held-open, and propped-open conditions.
+
+## The door position switch type shall be as indicated in the datasheet.
+
```datasheet
label: Door Position Switch Type
type: radio
options:
− - "Concealed magnetic reed switch in door frame (default)"
+ - "Concealed magnetic reed switch in the door frame"
- "Surface-mounted magnetic switch"
− - "Door-mounted high-security balanced magnetic switch"
−default: "Concealed magnetic reed switch in door frame (default)"
+ - "Door-mounted balanced magnetic switch"
+default: "Concealed magnetic reed switch in the door frame"
```
−## A door position switch (DPS) shall be provided at every controlled opening to monitor whether the door is closed.
+## A concealed switch is installed in the head of the door frame with a matching magnet set in the top edge of the door. {note}
−## DPS contacts shall be supervised by the controller, and the controller shall report and log forced-open, held-open, and propped-open conditions.
+## Surface-mounted switches shall be used only on retrofit projects where concealed installation is not practical.
−### A concealed magnetic reed switch installed in the head of the door frame with a matching magnet in the top edge of the door shall be the default for new construction.
+## Balanced magnetic switches shall be specified at high-security openings where defeat by an external magnet must be prevented.
−### Surface-mounted switches shall be used only on retrofit projects where concealed installation is not practical.
+## Door Held-Open Time {toc}
−### Balanced magnetic switches shall be specified at high-security openings where defeat by an external magnet must be prevented.
+### The door held-open timer sets how long the door may remain open after a valid access before a held-open alarm is generated. {note}
−## Door Held-Open Time {toc}
+### The door held-open time shall be as indicated in the datasheet.
```datasheet
…4 unchanged lines
min: 15
max: 120
− setpoints: [30, 45, 60, 90]
+ setpoints: [15, 30, 45, 60, 90, 120]
default: 45
```
−### The door held-open timer shall determine how long the door may remain open after a valid access before a held-open alarm is generated.
−
### High-traffic openings or openings used for material movement may extend the timer with the Engineer's approval.
−### The held-open alarm shall be local at the door (annunciator at the door if specified) and remote at the head-end.
+### The held-open alarm shall be annunciated at the head-end, and at the door where a local annunciator is specified.
−### The default of 45 seconds accommodates normal cart and accessibility usage. {note}
+### A 45-second baseline accommodates normal cart and accessibility usage. {note}
## Forced-Open Alarm Routing {toc}
+### The routing of the forced-open alarm shall be as indicated in the datasheet.
+
```datasheet
label: Forced-Open Alarm Routing
…6 unchanged lines
```
+### Routing to a local annunciator or to a monitoring service is an Owner security-program decision; head-end notification alone is the baseline because the head-end is the system of record for every access event. {note}
+
# Power Supplies and Battery Backup {toc}
…4 unchanged lines
## Lock Voltage {toc}
+### The lock control voltage shall be as indicated in the datasheet.
+
```datasheet
label: Lock Voltage
type: radio
options:
− - "24 VDC (default for runs exceeding 50 ft and for higher-current locks)"
− - "12 VDC (short runs and low-current locks only)"
−default: "24 VDC (default for runs exceeding 50 ft and for higher-current locks)"
+ - "24 VDC"
+ - "12 VDC"
+default: "24 VDC"
```
+### 12 VDC shall be used only where the voltage drop calculation confirms adequate voltage at the lock under worst-case current.
+
+### 24 VDC is the baseline because the higher voltage reduces conductor sizing and tolerates longer runs without unacceptable voltage drop. {note}
+
+### The reader and controller logic voltage shall be as indicated in the datasheet.
+
```datasheet
label: Reader and Controller Logic Voltage
type: radio
options:
− - "12 VDC from controller-integrated supply (default)"
− - "Power over Ethernet (PoE/PoE+) where reader and controller support it"
+ - "12 VDC from the controller-integrated supply"
+ - "Power over Ethernet (PoE / PoE+)"
- "Separate 24 VDC supply for readers"
−default: "12 VDC from controller-integrated supply (default)"
+default: "12 VDC from the controller-integrated supply"
```
−### 24 VDC shall be the default lock voltage.
+### Power over Ethernet shall be used only where both the reader and the controller are listed for it.
−### 12 VDC may be used only for short runs and low-current devices where the voltage drop calculation confirms adequate voltage at the lock under worst-case current.
−
−### 24 VDC is the default because the higher voltage reduces conductor sizing and tolerates longer runs without unacceptable voltage drop. {note}
−
## Battery Backup {toc}
+### The battery standby duration shall be as indicated in the datasheet.
+
```datasheet
label: Battery Standby Duration
…23 unchanged lines
# Cabling {toc}
+## All access control system cabling shall comply with NEC Article 725 (Class 2 circuits) for low-voltage portions and with NEC Article 800 and ANSI/TIA-568 for structured cabling portions.
+
+## Plenum-rated cable shall be used in plenum spaces.
+
+## Cable in concealed spaces, cable trays, and accessible ceilings shall be supported per NEC and per the cable manufacturer's instructions; cable shall not be supported by ceiling tile grid or other building systems not intended for cable support.
+
+## A composite cable that bundles reader, lock, REX, and DPS conductors in a single jacket installs in one pull, reduces conduit fill, and simplifies door cabling, which is why it is the baseline reader-cable selection. {note}
+
+## Where the lock current exceeds the rating of the composite cable's lock conductors, a separate lock cable shall be pulled and the reader cable shall carry only reader, REX, and DPS conductors.
+
+## The controller-to-head-end cable shall be as indicated in the datasheet.
+
```datasheet
label: Controller-to-Head-End Cable
type: select
options:
− - "Category 6 UTP, plenum-rated where applicable (default)"
− - "Category 6A UTP, plenum-rated where applicable"
− - "Multimode optical fiber for long runs or electrically noisy paths"
−default: "Category 6 UTP, plenum-rated where applicable (default)"
+ - "Category 6 UTP"
+ - "Category 6A UTP"
+ - "Multimode optical fiber"
+default: "Category 6 UTP"
```
+## The reader cable shall be as indicated in the datasheet.
+
```datasheet
label: Reader Cable (Controller to Reader)
type: select
options:
− - "Composite 22 AWG/6-conductor shielded with 18 AWG/4-conductor (default for reader + lock + REX)"
− - "22 AWG/6-conductor overall-shielded twisted pair (reader only; separate lock cable)"
− - "Category 6 UTP for OSDP (where manufacturer supports it)"
−default: "Composite 22 AWG/6-conductor shielded with 18 AWG/4-conductor (default for reader + lock + REX)"
+ - "Composite 22 AWG/6-conductor shielded with 18 AWG/4-conductor"
+ - "22 AWG/6-conductor overall-shielded twisted pair"
+ - "Category 6 UTP for OSDP"
+default: "Composite 22 AWG/6-conductor shielded with 18 AWG/4-conductor"
```
+## The lock cable shall be as indicated in the datasheet, sized by the voltage drop calculation required below.
+
```datasheet
label: Lock Cable (Power Supply to Lock)
type: select
options:
− - "18 AWG/2-conductor (locks within voltage-drop tolerance at 24 VDC)"
− - "16 AWG/2-conductor (longer runs or higher-current locks)"
− - "14 AWG/2-conductor (long runs or magnetic locks)"
−default: "18 AWG/2-conductor (locks within voltage-drop tolerance at 24 VDC)"
+ - "18 AWG/2-conductor"
+ - "16 AWG/2-conductor"
+ - "14 AWG/2-conductor"
```
+## The REX and DPS cable shall be as indicated in the datasheet.
+
```datasheet
label: REX and DPS Cable
type: radio
options:
− - "22 AWG/2-conductor shielded per device (default within composite)"
− - "18 AWG/2-conductor shielded (long runs only)"
−default: "22 AWG/2-conductor shielded per device (default within composite)"
+ - "22 AWG/2-conductor shielded per device"
+ - "18 AWG/2-conductor shielded"
+default: "22 AWG/2-conductor shielded per device"
```
+## Cable pathways shall be as indicated in the datasheet.
+
```datasheet
label: Cable Pathways
…4 unchanged lines
- "Bridle rings or J-hooks in accessible ceilings (per TIA-569)"
- "Plenum-rated cable in plenums per NEC Article 300"
−default: "Conduit (EMT) in unfinished spaces and where required by code"
+default:
+ - "Conduit (EMT) in unfinished spaces and where required by code"
+ - "Bridle rings or J-hooks in accessible ceilings (per TIA-569)"
+ - "Plenum-rated cable in plenums per NEC Article 300"
```
−## All access control system cabling shall comply with NEC Article 725 (Class 2 circuits) for low-voltage portions and with NEC Article 800 and ANSI/TIA-568 for structured cabling portions.
−
−## Plenum-rated cable shall be used in plenum spaces.
−
−## Cable in concealed spaces, cable trays, and accessible ceilings shall be supported per NEC and per the cable manufacturer's instructions; cable shall not be supported by ceiling tile grid or other building systems not intended for cable support.
−
−## Composite access control cables that bundle reader, lock, REX, and DPS conductors in a single jacket shall be the default for door cabling because they install in one pull, reduce conduit fill, and simplify cabling.
−
−## Where the lock current exceeds the rating of the composite cable's lock conductors, a separate lock cable shall be pulled and the reader cable shall carry only reader, REX, and DPS conductors.
−
## Voltage Drop and Separation {toc}
…12 unchanged lines
## Network Segmentation {toc}
+### The network segmentation method shall be as indicated in the datasheet.
+
```datasheet
label: Network Segmentation
type: radio
options:
− - "Dedicated VLAN, isolated from general user and IT networks (default)"
+ - "Dedicated VLAN, isolated from general user and IT networks"
- "Dedicated physical network"
− - "Shared network segment (not acceptable)"
−default: "Dedicated VLAN, isolated from general user and IT networks (default)"
+default: "Dedicated VLAN, isolated from general user and IT networks"
```
−### Access control controllers, the head-end server, and any management workstations shall reside on a dedicated VLAN isolated from general user, guest, and untrusted networks.
+### Access control controllers, the head-end server, and any management workstations shall not share a network segment with general user, guest, or untrusted networks.
### Firewall rules shall restrict the access control VLAN to the specific protocols and destinations required for operation and management.
…3 unchanged lines
## Default Credentials and Initial Hardening {toc}
+### The Contractor shall perform the initial hardening steps indicated in the datasheet before the system is placed in service.
+
```datasheet
label: Default Credentials and Initial Hardening
…5 unchanged lines
- "Unused services and ports on controllers disabled"
- "Firmware updated to current vendor-supported version at substantial completion"
−default: "All factory default passwords on controllers, readers, and head-end changed before commissioning"
+default:
+ - "All factory default passwords on controllers, readers, and head-end changed before commissioning"
+ - "Administrator accounts use unique passwords meeting Owner's password policy"
+ - "Service and maintenance accounts use distinct credentials from administrators"
+ - "Unused services and ports on controllers disabled"
+ - "Firmware updated to current vendor-supported version at substantial completion"
```
## Reader-to-Controller Encryption {toc}
−```datasheet
−label: Reader-to-Controller Encryption
−type: radio
−options:
− - "OSDP Secure Channel enabled with site-specific keys (default)"
− - "OSDP installation mode keys (not acceptable for production)"
− - "Unencrypted Wiegand (not acceptable for new installations)"
−default: "OSDP Secure Channel enabled with site-specific keys (default)"
−```
+### Reader-to-controller encryption is fully determined by the protocol selected under Reader-to-Controller Protocol, so it is stated here as a requirement rather than offered as a second selection. {note}
### OSDP Secure Channel shall be enabled at commissioning using site-specific keys, not installation-mode default keys.
…3 unchanged lines
## Audit Log Retention {toc}
+### The audit log retention period shall be as indicated in the datasheet.
+
```datasheet
label: Audit Log Retention
…7 unchanged lines
```
−### The head-end shall retain access and exception event logs for a minimum of 365 days; the Owner may extend retention per their security policy or regulatory obligation.
+### The head-end shall retain access and exception event logs for not less than 365 days.
### Logs shall be exportable in a documented format for review and for archiving to long-term storage.
# Fire Alarm Interface and Egress Release {toc}
+## The access control system shall interface to the fire alarm system as required by NFPA 101 and the AHJ.
+
+## The fire alarm release interface shall be as indicated in the datasheet.
+
```datasheet
label: Fire Alarm Release Interface
type: radio
options:
− - "Hardwired dry contact from FACU to dedicated release relay at each lock requiring release (default)"
− - "Dry contact from FACU to power supply for all locks on that supply"
− - "Software interface from FACU to access control head-end (not acceptable as sole release path)"
−default: "Hardwired dry contact from FACU to dedicated release relay at each lock requiring release (default)"
+ - "Hardwired dry contact from FACU to a dedicated release relay at each lock requiring release"
+ - "Hardwired dry contact from FACU to the power supply serving all locks on that supply"
+default: "Hardwired dry contact from FACU to a dedicated release relay at each lock requiring release"
```
−## The access control system shall interface to the fire alarm system as required by NFPA 101 and the AHJ.
−
## The interface shall release locks that must be released on fire alarm and shall do so independently of the head-end and independently of the network.
…10 unchanged lines
## Delayed-Egress Openings {toc}
+### The use of delayed-egress hardware shall be as indicated in the datasheet.
+
```datasheet
label: Delayed-Egress Opening Configuration
type: radio
options:
- "Not used"
− - "Used at designated openings per NFPA 101 7.2.1.6.1 with AHJ approval"
+ - "Used at designated openings"
default: "Not used"
```
…17 unchanged lines
## Directory and SSO Integration {toc}
+### Administrator and operator accounts shall be authenticated through the Owner's directory or identity provider where one exists, so that administrator account lifecycle — provisioning, password rotation, and deprovisioning on departure — is managed centrally.
+
+### The administrator authentication method shall be as indicated in the datasheet.
+
```datasheet
label: Directory and SSO Integration
type: radio
options:
− - "LDAP/Active Directory integration for administrator authentication (default for on-prem)"
− - "SAML 2.0 or OIDC for administrator authentication (default for cloud)"
− - "Local administrator accounts only (small projects)"
−default: "LDAP/Active Directory integration for administrator authentication (default for on-prem)"
+ - "LDAP / Active Directory integration for administrator authentication"
+ - "SAML 2.0 or OIDC for administrator authentication"
+ - "Local administrator accounts (no directory or identity provider available)"
+default: "LDAP / Active Directory integration for administrator authentication"
```
−### Administrator and operator accounts shall be authenticated through the Owner's directory or identity provider where one exists, so that administrator account lifecycle — provisioning, password rotation, and deprovisioning on departure — is managed centrally.
+### A cloud-hosted head-end shall authenticate administrators through SAML 2.0 or OIDC unless local administrator accounts are indicated in the datasheet.
−### Local-only administrator accounts shall be limited to a break-glass account for recovery from directory outage.
+### Where directory or identity provider integration is indicated in the datasheet, local administrator accounts shall be limited to a break-glass account for recovery from a directory outage.
## Software Deployment {toc}
+### The head-end software deployment model shall be as indicated in the datasheet.
+
```datasheet
label: Software Deployment
type: radio
options:
− - "On-premises server (Windows or Linux per manufacturer support)"
+ - "On-premises server"
- "Vendor-hosted cloud (SaaS)"
- "Owner-hosted cloud (private cloud or Owner's IaaS)"
−default: "On-premises server (Windows or Linux per manufacturer support)"
+default: "On-premises server"
```
+### The server operating system shall be one for which the head-end manufacturer publishes current support.
+
## Backup and Recovery {toc}
+### The backup and recovery provisions shall be as indicated in the datasheet.
+
```datasheet
label: Backup and Recovery
…4 unchanged lines
- "Documented recovery procedure tested at acceptance"
- "High-availability configuration with secondary head-end"
−default: "Daily automated database backup"
+default:
+ - "Daily automated database backup"
+ - "Weekly off-site backup copy"
+ - "Documented recovery procedure tested at acceptance"
```
…4 unchanged lines
# User Management and Audit {toc}
+## The system shall maintain a credential record for every user that includes at minimum the user's identifier, the credential type and serial, the issue and expiration date, the access privilege set assigned, and the status (active, suspended, revoked).
+
+## Credentials shall expire at the interval indicated in the datasheet and shall require an affirmative renewal action.
+
```datasheet
−label: Credential Expiration Default
+label: Credential Expiration Interval
type: select
options:
…6 unchanged lines
```
−## The system shall maintain a credential record for every user that includes at minimum the user's identifier, the credential type and serial, the issue and expiration date, the access privilege set assigned, and the status (active, suspended, revoked).
−
−## Credentials shall expire by default at a date set per the Owner's policy and shall require an affirmative renewal action.
−
## Access Privilege Assignment {toc}
…6 unchanged lines
## Time and Holiday Schedules {toc}
+### The time schedules to be configured shall be as indicated in the datasheet.
+
```datasheet
label: Time Schedules
type: checkbox
options:
− - "Business hours (default)"
− - "Extended hours (weekdays, longer)"
+ - "Business hours"
+ - "Extended weekday hours"
- "24/7"
− - "Weekend / off-hours only"
+ - "Weekend and off-hours"
- "Custom per role or per door"
−default: "Business hours (default)"
+default: "Business hours"
```
…10 unchanged lines
# Testing and Commissioning {toc}
+## Acceptance testing shall be performed by the Contractor, witnessed by the Engineer or the Owner's designated representative, and documented on the project test forms.
+
+## The acceptance test scope shall be as indicated in the datasheet.
+
```datasheet
label: Acceptance Test Scope
−type: checkbox
+type: radio
options:
− - "Every controlled opening tested individually (default)"
− - "Sampling acceptable (large projects, per Engineer)"
−default: "Every controlled opening tested individually (default)"
+ - "Every controlled opening tested individually"
+ - "Sampling of representative openings as approved by the Engineer"
+default: "Every controlled opening tested individually"
```
−## Acceptance testing shall be performed by the Contractor, witnessed by the Engineer or the Owner's designated representative, and documented on the project test forms.
+## Testing shall not begin until installation is complete and the system has operated under normal conditions for the burn-in period indicated in the datasheet.
−## Testing shall not begin until installation is complete and the system has operated under normal conditions for a burn-in period of not less than seven calendar days.
+```datasheet
+label: Burn-In Period Before Acceptance
+type: range
+unit: days
+options:
+ min: 3
+ max: 30
+ setpoints: [3, 7, 14, 30]
+default: 7
+```
## Per-Opening Acceptance Test {toc}
…11 unchanged lines
- OSDP Secure Channel is confirmed enabled on every reader and the installation-mode keys have been replaced
−```datasheet
−label: Burn-In Period Before Acceptance
−type: range
−unit: days
−options:
− min: 3
− max: 30
− setpoints: [7, 14, 30]
−default: 7
−```
−
## Correction and Report {toc}
…58 unchanged lines
- Backup and recovery: confirm a backup ran, perform a restore drill
+## The training duration shall be as indicated in the datasheet.
+
```datasheet
label: Training Hours
…7 unchanged lines
```
−### Training shall be delivered on the installed system, not on a generic demonstration platform, so that the Owner's personnel are trained on the actual configuration, naming conventions, and door schedule of the project.
+## Training shall be delivered on the installed system, not on a generic demonstration platform, so that the Owner's personnel are trained on the actual configuration, naming conventions, and door schedule of the project.
−### Training materials shall be left with the Owner.
+## Training materials shall be left with the Owner.
# Delivery, Storage, and Handling {toc}
…11 unchanged lines
# Warranty {toc}
+## The Contractor shall warrant the system installation, including all wiring, terminations, programming, and integration, for the period indicated in the datasheet.
+
```datasheet
label: Installation Warranty Period
…6 unchanged lines
```
+## The software support and maintenance term shall be as indicated in the datasheet.
+
```datasheet
label: Software Support and Maintenance Agreement
type: radio
options:
− - "Manufacturer software maintenance for 1 year (default; includes firmware updates and security patches)"
+ - "Manufacturer software maintenance for 1 year"
- "Manufacturer software maintenance for 3 years"
− - "Owner self-maintains after substantial completion (perpetual license only)"
−default: "Manufacturer software maintenance for 1 year (default; includes firmware updates and security patches)"
+ - "Owner self-maintains after substantial completion (perpetual license)"
+default: "Manufacturer software maintenance for 1 year"
```
−## The Contractor shall warrant the system installation, including all wiring, terminations, programming, and integration, for a minimum of 1 year from substantial completion.
−
## Manufacturer warranties on individual products (controllers, readers, power supplies, batteries) shall be passed through to the Owner.
## The software maintenance term shall include firmware updates for controllers and readers, security patches for the head-end, and access to technical support.
−## Lapsed maintenance has been the cause of unresolved vulnerabilities on installed systems; the Owner shall be advised at turnover of the renewal schedule. {note}
+## Lapsed maintenance has been the cause of unresolved vulnerabilities on installed systems; the Owner shall be advised at turnover of the renewal schedule.
# Spare Parts {toc}
…11 unchanged lines
- "One battery per installed power supply"
- "10 percent overage on credentials (minimum 25)"
− - "One controller per installed model (large projects)"
−default: "One reader per installed reader model (minimum one)"
+ - "One controller per installed model"
+default:
+ - "One reader per installed reader model (minimum one)"
+ - "One door position switch (concealed and surface, as installed)"
+ - "One REX device per installed type"
+ - "One power supply per installed model"
+ - "One battery per installed power supply"
+ - "10 percent overage on credentials (minimum 25)"
```
## Spare parts shall be stored by the Owner in the equipment room or designated storage area with the system documentation.
## The spare parts list shall be included in the closeout package.

View current revision