Skip to content
Guides

Share this guide

Email a colleague Share on LinkedIn

entrybit.net/guides/access-control-readers/

Readers

Access Control Readers: How to Choose the Right Reader for Your System

Which reader types exist, how a reader talks to the controller, the real differences between RFID, MIFARE DESFire, NFC and Bluetooth — and what to check before anything goes on the wall.

Published 9 min read

An access control reader is the component every single user touches on the way into the building. Whether the credential is a card, a phone, or a QR code, identification always starts at the reader.

Choosing the right reader affects your security level, day-to-day convenience, and the ability of the access control system to keep pace with the business as its needs change.

It is also the component that stays on the wall the longest. A reader costs little compared with the rest of the system, but replacing one later is never just a component swap: it touches cabling, the wall, the cards already issued to employees, and every entry point individually. Getting the choice right at design time is worth more than any saving at purchase.

In this guide, we explain which reader types exist, how they work, how they connect to the controller, and what to check before choosing a reader for an access control system.

What Is an Access Control Reader?

An access control reader is the component that lets a user identify to the access control system.

The reader is usually installed beside the door, gate, or entry point and connects to the controller over dedicated cabling. When a card, a phone, or another credential is presented, the reader captures the data and passes it on to the controller.

It is important to understand that the reader does not decide whether to open the door. Its job is to read the credential and hand the data to the controller, which checks permissions and decides whether to allow entry. Even when the reader flashes green, the decision itself was made somewhere else.

That separation is not a technical footnote. It is why a reader on its own is not an access control system, and it is also why the system keeps enforcing the permissions you defined when the cloud is unreachable: the permissions live on the controller, not in the reader.

Want the full picture? Read the complete guide to choosing an access control system →

How Does a Reader Connect to the Controller?

Which cards a reader can read is only half the picture. The other half is which language it speaks to the controller, and that detail has a direct effect on the security of the whole installation.

Wiegand

Wiegand is the oldest and most widespread reader-to-controller protocol. It is simple, works with almost any existing installation, and needs minimal wiring — but it is one-way and unencrypted. Anyone who reaches the wiring behind the reader can listen in and read card numbers as they pass.

OSDP over RS-485

OSDP is the modern standard for reader-to-controller communication. It runs over an RS-485 bus and is bidirectional, which buys several things Wiegand cannot offer:

  • The link between reader and controller can be encrypted (Secure Channel), so tapping the cable no longer exposes card numbers.
  • The controller knows whether the reader is connected and healthy, so disconnecting a reader becomes an event the system reports rather than silence.
  • Reader feedback — LEDs and beeper — can be driven from the system’s own settings.
  • Several readers can share one bus, over cable runs far longer than Wiegand allows.

For a new installation, choose readers that support OSDP even if the first phase is wired otherwise. For an installation that already exists, a controller fluent in both protocols lets readers be replaced at whatever pace suits the organization instead of all at once.

Want to see what the controller itself does? Meet the EntryBit access controllers →

Which Reader Types Exist?

Access control readers support a range of credentials, each suited to different needs.

RFID Readers

RFID readers are the most common solution in access control systems. The user presents a dedicated card or fob, and the reader captures the data and passes it to the controller.

Not every RFID reader is equivalent, though. Older 125 kHz cards transmit a fixed number with no encryption and no authentication, so they can be cloned with readily available equipment. Cards on 13.56 MHz, the MIFARE family foremost among them, support mutual authentication and encryption. If the installation is new, there is no reason to start it on 125 kHz.

MIFARE DESFire Readers

Readers that support MIFARE DESFire cards provide a higher level of security and suit organizations where protecting the credential itself matters.

With these cards, the identifier is not simply read off the card. Reader and card perform an encrypted mutual authentication, so a forged card cannot impersonate a genuine one even when it presents the same number. That is why organizations replacing legacy cards usually replace them with DESFire.

NFC Readers

NFC readers let a phone or another supported device act as the credential, much like a contactless payment. The user brings the phone close to the reader, which reads the credential and passes it to the controller.

The practical advantage is that the employee already carries the phone, so there is nothing to issue, distribute, or replace.

Bluetooth Readers

Readers that support Bluetooth allow identification by phone without holding it against the reader. Depending on how the system is configured, the door can open while the phone is within range, which improves convenience in a range of scenarios.

That range is also what needs attention. Where two doors sit close together, or where people walk past a door without intending to enter, it is worth reducing the range or requiring a deliberate action from the user so doors do not open for people who were only passing by.

Keypad and PIN Readers

Keypad readers allow identification with a personal code, and in many systems they earn their place in combination: a card followed by a code, as two-factor authentication for sensitive areas.

Check that the system stores codes hashed rather than in plain text, and that the keypad itself resists both wear and shoulder-surfing, so a code cannot be guessed from the wear pattern on the buttons.

QR Code Readers

These readers are aimed mainly at visitor management and temporary permissions, where the user presents a QR code sent to them in advance.

Their advantage is that nothing has to be issued: the visitor gets a code before arriving, enters within the window defined for them, and the permission expires on its own. This is the common answer for lobbies, parking, and visitor entrances.

Multi-Technology Readers

Some readers read several technologies at once — a legacy card, a DESFire card, and a phone. A reader like that is what turns a technology migration from a replacement project into a gradual process: the readers stay, the cards change at the organization’s own pace, and during the transition both card types work at the same door.

Want to compare the credentials themselves? Read about the credentials the platform supports →

Where the Reader Is Installed, and Why It Changes the Choice

The environment a reader sits in matters no less than the technology it supports.

Outdoors, a reader is exposed to rain, dust, sun, and temperature extremes, so check its ingress protection rating (IP) and the operating temperature range it is specified for. At public entrances, look at the housing and the mounting as well, so the reader cannot be pried off easily to expose the wiring behind it.

The mounting surface matters too. Fitting a reader to a metal frame or a narrow aluminium profile shortens the read range of RFID readers, which is exactly why narrow mullion readers are made for glass and aluminium doors.

The small details that shape daily use are worth attention as well: mounting height, the visual and audible feedback the reader gives, and whether it is obvious to the user where to present the card. At an entrance hundreds of people pass through each day, a second of hesitation adds up to a queue.

What to Check Before Choosing a Reader

Choosing a reader is not only about the credential in use today.

Before choosing, it is worth checking:

  • Which credentials it supports.
  • Which protocol it speaks to the controller, and whether it supports OSDP.
  • Whether it is rated for indoor or outdoor installation.
  • Whether it resists water and dust.
  • Whether it suits the existing system.
  • Whether its form factor fits the frame or door it will be mounted on.
  • Whether it will allow the system to expand later.
  • Whether the reader allows a future move to more secure cards or to mobile phones without replacing the readers already installed.

Getting this right at design time can save a reader replacement later and let the system keep evolving alongside the needs of the business.

How Do You Choose the Right Reader?

Choosing a reader is not only about the credential in use today. Match the reader to the nature of the project, the installation environment, and the organization’s future plans.

An outdoor entrance, for example, needs a reader that stands up to the weather, while many offices find that phones need to work as credentials alongside cards.

In practice, most installations fall into one of three cases. A main office entrance suits a multi-technology reader supporting both card and phone, so each employee uses whichever they prefer. A sensitive area, such as a server room or a stockroom, suits a reader with a keypad so the system can require card and code together. A visitor entrance or parking gate suits a QR-code-based solution, which requires nothing to be issued in advance.

If the system is expected to expand, choose a reader that supports several credentials and modern technologies, so new capabilities can be added without replacing every reader.

Common Mistakes When Choosing a Reader

  • Choosing on price alone. The gap between a basic reader and a multi-technology one is far smaller than the cost of replacing every reader in three years.
  • Staying on a legacy technology only because it is already in use, even when the installation itself is new.
  • Specifying an indoor reader for an outdoor entrance. This is the fault that comes back every winter.
  • Choosing a single-technology reader, and with it locking the organization to those cards for the life of the system.
  • Ignoring the protocol to the controller, then discovering the link between reader and controller cannot be encrypted.
  • Forgetting the exit side. Where exits must be logged or restricted, a request-to-exit button is not enough and a reader is needed on both sides of the door.

Summary

The reader is where the user meets the access control system. It is responsible for reading the credential and passing it to the controller, which makes the decision on entry.

When choosing one, look past today’s needs: which credentials it supports, which protocol it speaks to the controller, whether it suits the installation environment, and whether it will let the organization adopt a new technology without dismantling what is already on the wall.

A reader chosen well keeps serving the system when the cards change, when employees move to their phones, and when new doors are added.

Frequently asked questions

What is the difference between a reader and a controller?

The reader captures the credential and passes the data to the controller. The controller is what checks permissions and decides whether to unlock the door, which is why a reader on its own is not an access control system.

Can employees use a phone instead of a card?

Yes. Readers that support NFC or Bluetooth let people identify with their phone. Many systems run both credentials side by side, so one employee can badge with a card and another with a phone at the very same door.

Does moving to more secure cards mean replacing the readers?

If a reader supports only one technology, moving to a more secure card means replacing readers. A multi-technology reader reads several card types at once, so cards can be swapped gradually without touching the readers already installed.

Can a reader be installed at an outdoor entrance?

Yes, provided the reader is rated for it. For outdoor installations, check the ingress protection rating (IP), the operating temperature range, and how well the housing resists tampering.

Do I need a reader on the exit side too?

Only if you need to log or restrict exits. Many doors use a request-to-exit button on the inside, which means the system records entries but not exits. Features like anti-passback require a reader on both sides.

Preview

Read this
New tab