Mobile access control is an access control setup in which an employee's or visitor's smartphone replaces the access card for opening doors, turnstiles and barriers. The phone is tapped on the reader via NFC, brought close over Bluetooth (BLE), or shows a short-lived QR code. Whichever method you choose, the central access system, not the phone, decides who gets in.
Why everyone is asking about phone-based entry
Every organisation that runs card access knows the small daily frictions: the employee who left their card at home, the contractor waiting for a replacement, the visitor who walks off with a badge. Printing, issuing and collecting cards is an invisible workload. The phone, meanwhile, is the one device people almost never leave behind.
Phone ownership is not a barrier in Türkiye either. According to BTK's Quarterly Market Data Report for Q1 2026, the Turkish telecoms regulator counted 85.96 million real mobile users excluding M2M at the end of March 2026, a penetration rate of about 100.3%. The market is moving the same way: MarketsandMarkets' access control forecast expects the global access control market to grow from USD 10.62 billion in 2025 to USD 15.80 billion by 2030, driven by IoT-based security and cloud platforms.
So "can we open the doors with our phones?" now comes up in nearly every access project. It is a fair question, but the answer is not a single technology. Mobile access touches the reader hardware, the phone operating systems, network connectivity and data protection rules all at once. If you have not yet pinned down the building blocks of card access, start with our card access control system guide; mobile credentials sit on top of that structure.
The cost of getting mobile access wrong
The first cost is technical, and it comes from assuming the phone behaves the same everywhere. The iPhone is the clearest example. Apple has opened NFC card emulation to third-party apps, including corporate badges, through its "NFC & SE Platform". However, the list of eligible territories on Apple's NFC & SE Platform developer page does not currently include Türkiye, so an NFC scenario that works on Android may not work for the managers carrying iPhones.
The second cost is legal. Türkiye's data protection law, KVKK, is broadly modelled on EU data protection law, and its Board has listed examples of methods employers can use for attendance instead of biometrics:
In its public announcement on principle decision 2026/921, the Turkish Personal Data Protection Authority lists alternatives such as "encrypted card or PIN-based systems", traditional signed paper timesheets, "RFID/NFC ID cards" and manual entry under supervision. (KVKK announcement on decision 2026/921)
This suggests that, for attendance, card credentials are seen as a less intrusive option than fingerprints. Phone-based methods that process no biometric data can be assessed in the same way; we cover the detail in biometric attendance and data protection. Phones still generate personal data, though. A log of which device was used at which door, and when, falls under KVKK and must be limited to its purpose and kept proportionate.
The third cost is operational and usually surfaces after go-live. Mobile access without a defined fallback means queues at the turnstile at shift change: flat batteries, apps that will not open and permissions wiped by an update all land on the security desk. Swapping card handouts for "my phone won't read" calls is a common disappointment with mobile access.
Mobile access control methods compared: NFC, BLE, QR and remote unlock
There are four ways to build phone-based entry. They differ in how the phone talks to the reader and how much they depend on the network.
| Method | How it works | Strength | Watch out for |
|---|---|---|---|
| NFC (phone as card) | Phone is tapped on the reader; an app emulates the card credential | Closest to the card habit, fast | iPhone regional and contractual limits; reader must support it |
| Bluetooth (BLE) | App sends the credential when the phone approaches the reader | Entry without taking the phone out | Poorly tuned range can open doors unintentionally; battery and permission settings |
| Time-limited QR | A short-lived QR on screen is read by the terminal's camera | Works on any phone, no app required | Needs short expiry and single-use rules against screenshot sharing |
| Remote unlock | A button in the app opens the door via the server | An authorised person can open the door from elsewhere (e.g. for a delivery or a waiting guest) | Needs internet; does not prove the person is at the door |
The practical conclusion is to choose by user group rather than lock into one method. Staff can keep the card as the primary credential, with the phone as a second one. For visitors and contractors, a time-limited QR is usually the lowest-friction route, as we show in our QR code visitor access guide. How plates and driver credentials work together at the vehicle gate is covered in our vehicle access control system guide.
For NFC, the reader's frequency and card type matter too. Phone NFC runs at 13.56 MHz, so older 125 kHz readers will not see the phone at all. The difference is explained in 125 kHz vs 13.56 MHz cards. The cloning weakness of older cards is covered in access card cloning risk.
Seven steps to a safe mobile access rollout
- Separate your user groups. Decide which credential applies to permanent staff, shift workers, contractors, visitors and managers. Not every phone is company-owned, and using a personal phone should be voluntary and needs a clear privacy notice under KVKK. How this split works where guests and staff share one building is described in hotel staff access control.
- Audit your readers. List each reader's frequency, whether it reads QR codes and whether it supports Bluetooth. The number of readers to replace is often one of the biggest budget lines.
- Define the fallback first. Nobody should be stuck at the door because of a flat battery, a lost phone or an app that will not start. A card, a PIN or a temporary QR issued by security should be a written fallback.
- Test offline behaviour. Know which methods keep working when the network drops; this is why rule sets should be held on the terminal. See access control offline mode for the detail.
- Make sharing hard. QR codes should be short-lived and single-use, and the same credential should not be able to enter twice in a row. That rule is called anti-passback.
- Extend account security to the door. The phone app is an extension of the corporate account; a weak screen lock or password means a weak door. We cover the basics in business password security.
- Start with a small pilot. Run a two- to three-week trial on one door with one team, and measure read speed, failed entries and user complaints before rolling out further.
If you are building the phone app yourselves, there is also a platform decision: separate Android and iOS apps, or one shared codebase? We compare the options in native vs cross-platform apps.
How we deliver mobile access at Digital Bridge
We treat mobile access as part of the access system rather than an app install. Because software and hardware are built by the same team, you have one point of contact from reader to dashboard.
- Discovery and requirements. We walk every door, turnstile and barrier, record which credentials the existing readers support and map your user groups. If your current card access control hardware can be kept, we say so in writing; the technical feasibility assessment for hardware is free of charge.
- Choosing the method. Together we settle which credential each group uses, the fallback route and offline behaviour, then prepare a written proposal covering scope, phases and cost.
- Where an app is needed. If you need a bespoke mobile credential or remote-unlock app, our mobile app development team designs it around the access system's permission rules.
- Pilot and integration. We pilot on a single door, then connect HR, visitor and identity systems through system integrations. For retention periods and privacy notices we support you through data protection compliance consultancy.
SmartPass: cards and phones under the same rules
Our own product, SmartPass, reads 13.56 MHz RFID cards and time-limited QR codes on the same terminal. A typical setup: staff use a permanent card, while a visitor or day contractor enters with a single-use QR sent to their phone. Both follow the same permission rules, so a visitor's QR is valid only for the zone and time window defined for them.
Rules are written in plain language, such as "The production team may enter the Warehouse zone during working hours." When two rules conflict, SmartPass states clearly which one wins, and a rule simulator lets you test a change before it goes live. In an emergency every door can be locked in a single action, with a zone-by-zone list of who is inside at that moment.
SmartPass never stores card numbers in plain text, only an irreversible hash. Records past their retention period are anonymised, and every change is written to an audit trail with old and new values. The same card read that opens the door also creates the attendance record, so no separate time clock is needed. For the criteria to use when picking attendance software, see choosing time and attendance software.
On the phone side, SmartPass currently offers the time-limited QR. If your organisation requires phones to be read like NFC cards, or Bluetooth entry, we assess that as a separate item during discovery and share a written feasibility view.
Next step
Before you get in touch, note three things: the number of doors and readers, your user groups, and the rough Android/iPhone split among your staff. Then reach us through our contact page and we will check together whether your existing readers can work with phones. For more guides on card access, attendance and visitor management, visit our Access Control & Attendance hub.