null

Proximity Card Security: 125kHz Risks, Dual Authentication & Upgrade Options

31st Aug 2026

Proximity Card Security: 125kHz Risks, Dual Authentication & Upgrade Options

125kHz proximity card systems have been used in commercial access control for decades. They are convenient, widely deployed, and compatible with a large installed base of readers and access control systems.

For many organizations, there is no immediate reason to replace an existing proximity card system that continues to meet operational and security requirements.

However, traditional 125kHz proximity technology was developed before many of today's credential security capabilities became available. Organizations using legacy proximity credentials should understand those limitations—particularly when the same credential technology is being used to protect higher-risk areas.

The good news is that improving proximity card security does not necessarily require replacing an entire access control system at once.

Organizations can strengthen an existing system through better credential management, additional authentication at sensitive doors, modern reader-to-controller communication, multi-technology readers, and phased migration to newer smart credential technologies.

This guide explains the security considerations associated with 125kHz proximity cards, how card + PIN authentication can add another layer of protection, and when upgrading to newer smart credentials may make sense.

How Does a 125kHz Proximity Card System Work?

A traditional proximity access control system typically includes several components:

  • A 125kHz proximity card or key fob
  • A compatible proximity reader
  • An access control panel or controller
  • Access management software
  • Electrified locking hardware
  • Door monitoring and related security devices

When a proximity credential is presented to a compatible reader, the reader obtains the credential information and passes relevant data to the access control system.

The system then determines whether that credential is authorized for that particular door at that particular time.

Traditional 125kHz proximity credentials are passive, meaning they do not require their own battery. Energy from the reader allows the credential to communicate when it is within the reader's operating range.

ID Enhancements supplies a wide selection of 125kHz proximity credentials for organizations using compatible access control systems.

Why 125kHz Proximity Card Security Deserves Attention

Traditional proximity credentials were designed primarily to provide convenient electronic identification.

They generally do not provide the same cryptographic authentication capabilities available with newer smart credential technologies.

That does not mean every proximity system is inherently inappropriate or must immediately be replaced.

It does mean that organizations should evaluate the credential as one layer of the overall physical access control system, particularly at doors protecting sensitive information, high-value assets, critical infrastructure, or restricted operations.

Potential security considerations include:

  • Credential copying or duplication risk
  • Lost or stolen credentials
  • Credential sharing
  • Reader-to-controller communication
  • Tailgating
  • Delayed credential deactivation
  • Excessive access permissions
  • Lack of additional authentication at higher-risk doors

Understanding these limitations helps organizations decide where existing proximity technology remains appropriate and where additional controls may be warranted.

Credential Copying and Legacy Proximity Technology

One of the most frequently discussed limitations of traditional 125kHz proximity technology is its reliance on relatively simple credential identification compared with newer cryptographically protected smart credential platforms.

Organizations should therefore avoid assuming that possession of a proximity card alone provides strong proof of the identity of the person presenting it.

A more useful security question is:

What would happen if this credential were lost, shared, copied, or otherwise used by someone other than the person to whom it was issued?

For a general employee entrance, the organization's risk assessment may determine that an existing proximity system combined with other physical security measures is appropriate.

For a server room, data center, pharmaceutical storage area, executive area, or other sensitive location, additional authentication or stronger credential technology may be justified.

This risk-based approach allows organizations to improve security where it matters most rather than treating every door identically.

Wiegand and Reader-to-Controller Security

Credential technology is only one part of access control security.

Another consideration is the communication between the reader at the door and the access control panel.

Many legacy access control installations use Wiegand for reader-to-controller communication.

Wiegand has been widely supported for many years, but it was not designed with the security capabilities available in newer communication protocols.

OSDP, Open Supervised Device Protocol, provides a modern alternative for communication between compatible readers and access control panels.

When properly implemented with OSDP Secure Channel, communications between compatible devices can be authenticated and encrypted.

This distinction is important: simply having OSDP-capable hardware does not necessarily mean Secure Channel has been enabled or properly configured.

Organizations evaluating an access control upgrade should therefore consider both:

  1. Credential-to-reader security
  2. Reader-to-controller security

Replacing a legacy credential with a newer smart card improves only part of the security architecture if other parts of the system remain unchanged.

Lost, Stolen and Shared Proximity Cards

One of the most common access control vulnerabilities has nothing to do with sophisticated technology.

It is ordinary credential management.

A proximity card identifies a credential. By itself, it does not prove that the person presenting the card is the individual to whom it was originally assigned.

Potential problems include:

  • Employees sharing cards
  • Cards being loaned to contractors or coworkers
  • Lost cards remaining active
  • Former employee credentials remaining enabled
  • Duplicate active credentials
  • Employees retaining access they no longer require

Organizations can reduce these risks through straightforward credential-management practices:

  • Assign every credential to an individual user
  • Prohibit credential sharing
  • Establish immediate lost-card reporting procedures
  • Disable lost credentials promptly
  • Remove access when employment ends
  • Review active credentials periodically
  • Adjust permissions when employee responsibilities change
  • Investigate unusual access activity where appropriate

Technology works best when supported by disciplined credential-management policies.

Tailgating Is Not a Credential Problem

Even the strongest credential technology cannot independently prevent an unauthorized person from following an authorized employee through an open door.

This is commonly called tailgating or piggybacking.

Addressing it may require additional physical and procedural controls such as:

  • Door position monitoring
  • Propped-door alerts
  • Video surveillance
  • Security personnel
  • Turnstiles
  • Controlled vestibules
  • Employee awareness and training

This illustrates an important principle of physical access control:

No credential should be treated as the entire security system.

Effective physical security uses multiple layers appropriate to the risk of the facility and individual entry point.

What Is Dual Authentication in Physical Access Control?

Dual authentication requires more than one authentication step before access is granted.

A common physical access configuration is:

Something you have: an access card or key fob

plus

Something you know: a PIN

This is commonly implemented through a reader that combines credential reading with a keypad.

For example, an employee may present a proximity card and then enter a PIN before the access control system grants entry.

If the credential is lost or copied, possession of the credential alone may no longer be sufficient to open that door.

Likewise, knowing the PIN without possessing the required credential would not satisfy both authentication requirements.

Does Card + PIN Make a Proximity Card More Secure?

Card + PIN does not change the underlying security technology inside a 125kHz proximity card.

Instead, it adds another authentication requirement to the access decision.

That distinction is important.

The proximity credential itself remains the same, but the system no longer relies solely on possession of that credential.

Card + PIN can therefore reduce the usefulness of a lost, stolen, or copied credential when the additional PIN remains unknown.

It does not eliminate every risk. For example, an employee could intentionally share both a credential and PIN.

For that reason, additional authentication should be considered one part of a layered physical security strategy rather than a complete solution by itself.

Where Does Card + PIN Make the Most Sense?

Requiring a PIN at every employee entrance may create unnecessary friction, particularly at high-volume entry points.

A risk-based approach can be more practical.

Organizations may consider additional authentication for areas such as:

  • Server rooms
  • Data centers
  • Network infrastructure areas
  • Pharmaceutical or controlled-material storage
  • Research facilities
  • High-value inventory
  • Restricted financial areas
  • Critical infrastructure
  • Executive or highly restricted areas

General office entrances may continue using a single credential where the organization's risk assessment determines that level of authentication is appropriate.

NIST's guidance for using PIV credentials in facility access illustrates the broader principle of selecting authentication mechanisms according to risk in federal PIV environments.

Commercial organizations can apply the same general risk-based concept while selecting technologies appropriate for their own access control systems.

Keypad Readers for Additional Authentication

Organizations using existing proximity credentials may be able to introduce card + PIN authentication at selected doors through compatible keypad readers.

This can be particularly useful when an organization wants to strengthen selected entry points without immediately replacing every credential in the facility.

ID Enhancements offers several keypad and multi-technology reader options.

The HID Signo 20K Reader with Keypad and HID Signo 40 Reader with Keypad are designed for access control environments requiring credential reading plus keypad functionality.

Depending on the specific model and configuration, HID Signo readers can support legacy 125kHz credentials as well as multiple 13.56MHz credential technologies. This makes them particularly useful when an organization wants to maintain compatibility with existing credentials while preparing for a future migration.

Other multi-technology keypad options include the Kantech KT-SG-MT-KP2 Multi-Technology Single-Gang Reader with Keypad and Allegion MTK15 aptiQ Multi-Technology Reader with Keypad.

For compatible CDVI environments, the CDVI KPAD Krypto Mobile Keypad-Reader provides another option for organizations evaluating keypad and mobile credential capabilities.

Reader compatibility, credential support, controller compatibility, communication protocol, and configuration should always be confirmed before purchasing replacement or upgrade hardware.

When Should You Upgrade Beyond 125kHz Proximity?

Adding another authentication requirement can improve the security of an existing proximity system, but it does not convert the underlying proximity credential into a modern cryptographic smart credential.

Organizations evaluating a longer-term upgrade may want to consider newer credential technologies.

Modern smart credential platforms can provide stronger authentication and cryptographic capabilities when used with compatible readers and properly configured access control systems.

Potential upgrade technologies include:

  • HID Seos
  • MIFARE DESFire
  • Other modern smart credential platforms supported by the organization's reader infrastructure

ID Enhancements offers a range of HID iCLASS and smart credentials as well as MIFARE DESFire credentials for compatible access control environments.

The exact security capabilities vary by credential technology and generation. Organizations should not assume that every credential operating at 13.56MHz provides the same authentication or encryption features.

Using Multi-Technology Readers for a Phased Migration

Replacing every reader and every credential simultaneously may not be practical.

A phased migration can allow organizations to move from legacy proximity technology toward newer smart credentials over time.

Multi-technology readers can be especially valuable during this process because compatible models may support both legacy 125kHz proximity credentials and newer 13.56MHz smart credentials.

For example, an organization might:

  1. Install multi-technology readers at selected doors.
  2. Continue accepting existing proximity credentials during the transition.
  3. Begin issuing newer smart credentials to selected employees.
  4. Expand the newer credential technology across additional users and doors.
  5. Retire legacy credential support when operationally appropriate.

HID Signo readers, for example, are available in configurations supporting legacy 125kHz credentials as well as technologies including Seos, iCLASS, MIFARE Classic and MIFARE DESFire.

This type of migration strategy can reduce operational disruption while giving organizations a defined path toward newer credential technology.

Proximity Cards vs. Smart Credentials vs. Card + PIN

Security Consideration

125kHz Proximity

Modern Smart Credential

Card + PIN

Basic electronic access

Yes

Yes

Yes

Additional cryptographic credential capabilities

Generally limited

Technology-dependent

Depends on credential

Requires second authentication step

No

Not necessarily

Yes

Helps if credential is lost or copied

Limited

Technology-dependent

Yes, if PIN remains unknown

Prevents intentional credential sharing

No

Not necessarily

Not completely

Reader-to-controller security

Depends on system

Depends on system

Depends on system

Suitable for phased migration

Existing baseline

Upgrade destination

Can be intermediate or permanent layer

Reader compatibility required

Yes

Yes

Yes

The best option depends on the facility, existing infrastructure, security requirements, and risk associated with each controlled area.

A Practical Roadmap for Improving a Legacy Proximity System

Improving proximity card security does not necessarily require a complete system replacement.

A phased approach can prioritize the areas with the greatest security impact.

Phase 1: Inventory the Existing System

Start by documenting:

  • Credential technologies currently in use
  • Reader manufacturer and model
  • Reader-to-controller communication
  • Access control panels
  • Credential formats
  • High-risk doors
  • Active credential population
  • Lost or unaccounted-for credentials
  • Existing card + PIN capabilities
  • Reader support for newer credential technologies

This inventory provides the information needed to determine which improvements are possible without replacing existing infrastructure.

Phase 2: Strengthen Credential Management

Before buying new hardware, address administrative weaknesses.

Review:

  • Active employee credentials
  • Former employee credentials
  • Lost-card procedures
  • Contractor credentials
  • Temporary credentials
  • Shared credentials
  • Access schedules
  • Excessive permissions
  • Dormant credentials

Removing unnecessary or outdated access can improve security immediately without changing credential technology.

Phase 3: Add Additional Authentication Where Risk Justifies It

Identify doors where possession of a credential alone may not provide sufficient assurance.

Compatible keypad readers may allow card + PIN authentication at selected locations while preserving the existing proximity credential population.

Phase 4: Evaluate Reader Communication

Determine whether existing readers communicate with access control panels using Wiegand or OSDP.

Where supported, organizations planning upgrades should evaluate OSDP and OSDP Secure Channel as part of the reader and controller architecture.

Phase 5: Plan Credential Migration

If the organization's risk assessment supports moving away from legacy proximity technology, identify the future credential platform before replacing readers.

A migration plan should consider:

  • Future credential technology
  • Existing card population
  • Reader compatibility
  • Controller compatibility
  • Mobile credential plans
  • Multi-technology requirements
  • Budget
  • User transition
  • Credential issuance procedures

There is no universal migration timeline. The appropriate pace depends on the organization, infrastructure, budget, and security objectives.

Frequently Asked Questions About Proximity Card Security

Are 125kHz proximity cards still appropriate for access control?

They can be.

125kHz proximity credentials remain widely used in existing commercial access control systems and may be appropriate for applications where their capabilities match the organization's security requirements.

Higher-risk environments may justify additional authentication or migration to newer credential technologies.

The decision should be based on risk rather than frequency alone.

Can 125kHz proximity cards be copied?

Traditional 125kHz proximity technologies generally do not provide the same cryptographic authentication capabilities available with modern smart credentials, which can make credential duplication a security consideration.

Organizations concerned about credential duplication should evaluate stronger credential technologies, additional authentication, and the overall access control architecture.

Does adding a PIN make a proximity card more secure?

Adding a PIN does not change the technology inside the proximity credential.

It adds another authentication requirement.

A lost or copied credential may therefore be insufficient to gain access at a door requiring both the credential and the correct PIN.

What is the difference between Wiegand and OSDP?

Wiegand is a widely deployed legacy method for communication between access control readers and controllers.

OSDP is a newer communication protocol designed for access control applications and provides additional capabilities.

When OSDP is implemented with Secure Channel, compatible devices can use authenticated and encrypted communication between the reader and access control panel.

Does replacing proximity cards require replacing every reader?

Not necessarily.

It depends on the installed readers and the credential technology selected for the upgrade.

Some multi-technology readers support both legacy 125kHz credentials and newer 13.56MHz technologies, which can support a phased migration.

Are all 13.56MHz smart cards equally secure?

No.

Frequency does not determine security.

Different 13.56MHz technologies use different authentication, encryption, memory, and key-management architectures.

MIFARE Classic, MIFARE DESFire, HID iCLASS, HID Seos and other credential technologies should not be treated as interchangeable simply because they operate at the same frequency.

Is card + PIN the same as two-factor authentication?

Card + PIN can represent two different authentication factors when the system requires both possession of the physical credential and knowledge of the PIN.

The implementation and authentication policy must actually require both factors for access.

How can I tell whether my current reader supports newer smart credentials?

Start with the reader manufacturer and exact model number.

Reader specifications can identify supported frequencies, credential technologies, interfaces, and configuration options.

Do not assume compatibility based solely on the reader brand or appearance.

Upgrade Your Proximity Card System at Your Own Pace

An existing 125kHz proximity system does not automatically need to be replaced simply because newer credential technologies are available.

The better question is whether the current system provides an appropriate level of security for the areas it protects.

For some organizations, better credential management may be the most important improvement. Others may benefit from card + PIN authentication at selected doors. Facilities planning longer-term modernization may choose multi-technology readers and gradually migrate employees toward newer smart credentials.

ID Enhancements supplies products for each stage of that process, including:

Not Sure What Your Existing System Supports?

Before purchasing new credentials or readers, identify the manufacturer and model of your existing reader, the credential technology currently in use, the credential format, and the access control system or panel when possible.

That information can help determine whether your existing proximity credentials should be retained, whether card + PIN can be added, or whether your installed reader infrastructure can support a phased migration to newer credential technology.

Explore ID Enhancements' 125kHz proximity credentials, HID iCLASS and smart credential options, and MIFARE DESFire credentials to compare technologies for your access control environment.

Customer Reviews