Evaluating an access control quote means scoring proposals from different suppliers against the same criteria (scope, card security, data ownership, integration, data protection compliance and support) rather than on price alone. The reliable method is to build a weighted scoring matrix, rule out quotes with red flags, and verify the shortlist with a scenario-based demonstration.
This article picks up once the quotes have landed on your desk. We covered the cost lines and how to request comparable quotes in what an access control system costs; here the focus is on working out which of those proposals will actually do the job. Every related article lives in our access control and attendance hub.
Why access control quotes refuse to line up
Procurement, HR and IT face three proposals. One is a hardware list full of reader models and quantities. The second leads with software but mentions cabling only as "to be prepared by the client". The third is a single page with a single total.
These documents are not answering the same question. Each supplier has read your requirement through the limits of its own product, so the lowest total is often simply the narrowest interpretation. Read every quote against your own requirement list, not the supplier's vocabulary. If that list does not exist yet, our guide to writing technical specifications helps.
Three things make comparison hard:
- Terminology: "controller", "terminal" and "panel" mean different things to different suppliers.
- Hidden assumptions: one quote handles time and attendance with a separate device, another with the same card read, and neither says so.
- Vague after-sales terms: post-warranty support, software updates and who makes permission changes are frequently missing altogether.
What choosing the wrong quote costs
A poor choice rarely shows on the first invoice. The pattern is well documented in enterprise software: Panorama Consulting's 2026 ERP Report found that more than a quarter of surveyed organisations went over budget, with an unexpected need for additional technology the leading reason. The data comes from ERP projects, but access control carries a similar risk: a second attendance device or a payroll export missing from the quote becomes a separate purchase.
The second cost is security. An access control supplier usually connects remotely to your server, cloud panel or network, so choosing a supplier also means choosing a security partner:
According to the Verizon 2026 Data Breach Investigations Report, breaches involving a third party rose by 60% on the previous year and now account for 48% of all breaches. (Verizon 2026 Data Breach Investigations Report)
The third is personal data. Card numbers, entry and exit times and fingerprint templates are employee data, and in Türkiye they fall under Law No. 6698 on the Protection of Personal Data (KVKK), the country's GDPR-style framework. The Turkish Data Protection Authority received 328 data breach notifications in 2025 (KVKK 2025 Annual Activity Report). If a quote does not say how records are stored, who sees them and when they are deleted, you will find out after an incident.
Access control quote evaluation in seven steps
- Number your requirements. Put entry points, permission rules, attendance, canteen, visitors and integrations on one list, then look for each item in every quote. We explain the role of cards, readers, controllers and software in our card access control system guide; the list should cover each of them.
- Build a scope-levelling table. Requirements go in rows and suppliers in columns; each cell reads "meets", "partly" or "missing", with the page reference. Every empty cell becomes a question back to the supplier.
- Screen out red flags. Any quote that trips one of the warning signs below is parked until the supplier explains it in writing, whatever the price.
- Score with weights. Give each criterion a weighting and score every quote from 1 to 5. Leave price until last so it does not steer the rest of the scoring.
- Ask for a scenario-based demo. Instead of the standard presentation, ask to see three or four of your critical scenarios run live.
- Take up references and visit a site. A similar-sized installation in daily use tells you more than any slide deck.
- Carry it into the contract. Acceptance criteria, data handover, support terms and responsibility for permission changes only bind once they are in the contract; how to keep watch after signing is covered in supervising software contractors.
The same framework works for larger purchases such as ERP; the differences are set out in our guide to evaluating ERP proposals.
An access control scoring matrix
Fill in the matrix below alongside the quotes. The weightings are illustrative; a hospital and a warehouse will not weight things the same way.
| Criterion | Weighting | What to look for | Red flag |
|---|---|---|---|
| Card and reader security | ×3 | Encrypted 13.56 MHz cards; QR and biometric options | 125 kHz only, easily cloned cards |
| Permission management | ×3 | Role- and zone-based rules; changes made in-house | A service call for every change |
| Behaviour during outages | ×2 | Written description of door behaviour when network or power fails | Nothing beyond "the system never goes down" |
| Attendance, canteen and payroll | ×2 | Attendance logged from the same read; defined payroll export | Separate device, separate software, manual transfer |
| Data protection and audit trail | ×2 | Retention periods, anonymisation, role-based viewing | Card numbers in plain text; everyone sees every record |
| Data ownership and exit | ×2 | Record export; data handover when the contract ends | Data only available in the supplier's format |
| Support and updates | ×2 | Response terms, update policy | Nothing beyond "during the warranty period" |
| Total cost | ×1 | Five-year total, cost of expansion | Cabling and installation excluded |
Card cloning is the most technical row in the matrix; we explain the difference between frequencies in 125 kHz vs 13.56 MHz cards and the real-world risk in access card cloning.
The outage row matters just as much: the quote should state in writing whether doors stay locked or open when the network or power fails, and how records are synchronised afterwards. What to ask about outages is covered in access control offline mode.
Six warning signs in a quote
Screen before you score. These phrases suggest a quote is incomplete or risky:
- "Cabling and infrastructure by the client." A sign that the quote was written without a site survey.
- Closed controllers, closed cards. If no other manufacturer's readers or cards will work, changing systems later becomes expensive; we describe this trap in replacing legacy access control.
- A single line for fingerprints. Biometric data is special-category personal data under KVKK; if the legal basis for processing it and an alternative method for employees who do not want to use biometrics are not addressed, ask the questions in biometric attendance and data protection.
- Unclear remote access. How does the supplier connect, with which account, and who approves it? A structured version of these questions is in our third-party vendor security assessment guide.
- Reports "available on request". If timesheets, the who-is-on-site list and audit reports are not built in, each report becomes chargeable extra work.
- No acceptance test. If the quote does not say which scenarios must work for the job to count as delivered, the supplier gets to define "finished".
Verifying a quote with a demo and a pilot
A quote is a promise; a demo shows what that promise looks like in practice. Ask the supplier to run your scenarios rather than its own presentation: an employee's department change flowing through to every door, a late arrival on the night shift appearing in the timesheet, a visitor's entry and exit, and the list of people still inside during an emergency. To test how doors behave when the fire alarm sounds, use the questions in access control and fire alarm integration. If you want to stop card sharing on consecutive entries, add an anti-passback scenario too.
On larger sites, a pilot on a single door or zone is the most reliable check. Watch who sets up the rules during the pilot and how much effort it takes. Also test whether timesheets genuinely reach payroll without month-end manual fixes, using the checkpoints in time and attendance payroll integration.
How we prepare a quote at Digital Bridge
We do not sell off-the-shelf packages, so our quote always follows a site survey. We start with a needs analysis, then inspect entry points, existing doors, turnstiles and barriers, cabling and network infrastructure on site. The written quote shows scope, phases and price separately, mapped to the rows of your scoring matrix.
On card access control projects where high-security rooms call for fingerprint access, we list it as a separate line with its data protection rationale. Where timesheets need to reach payroll, we include the integration on the HR and payroll management side in the scope. For questions about privacy notices and retention policies for employee data, our data protection compliance team joins the process.
Software and hardware come from the same team, so demo and pilot questions never wait on a manufacturer. Where custom hardware is needed, the technical feasibility study is free of charge.
What you will see in a SmartPass quote
SmartPass answers several rows of the scoring matrix directly. Card access control, time and attendance and canteen meal counting run in one system: a single card read opens the door, records attendance and, where the employee is entitled, deducts a meal. So a SmartPass quote has no separate attendance device or canteen software line.
Take a factory with a gatehouse, production, a warehouse and an office zone. Staff carry permanent 13.56 MHz cards and visitors receive single-use, time-limited QR codes; both are read on the same terminal and follow the same permission rules. Rules are written in plain language, such as "the production team may enter the Warehouse zone during working hours". When two rules conflict, the system states which one applies, and changes can be tested in the rule simulator first. In an emergency, every door locks with a single action and the people inside are listed by zone.
On the data protection row, card numbers are never stored in plain text, records past their retention period are anonymised, every change is logged with its old and new value, and the auditor role is read-only. The pricing model is three transparent lines: hardware you buy and own, installation based on the number of doors, and a per-terminal subscription. Card design is included and card printing appears as a separate line, so each line maps cleanly onto the matrix.
Next step
Gather your requirement list and the quotes you already have. Get in touch and we will plan a site survey, then present a written SmartPass quote laid out against the rows of your scoring matrix.