Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Access Control & Attendance

125kHz vs 13.56MHz Access Cards: Which RFID Technology Should Your Access Control Use?

125kHz vs 13.56MHz access cards compared on security, cloning risk, memory and phone support, plus a practical plan for moving a site to newer cards.

8 min read  · Digital Bridge Engineering Team
125kHz vs 13.56MHz Access Cards: Which RFID Technology Should Your Access Control Use?

The key difference between 125kHz and 13.56MHz access cards is security. Most 125kHz ("prox") cards broadcast a fixed number without encryption and can be copied with an inexpensive device. 13.56MHz cards can support mutual authentication, encrypted memory and several applications on one card. For a new access control installation, choose 13.56MHz with a current, encrypted card family.

Two cards that look identical but do different jobs

Hand someone a plain white PVC card and they cannot tell its frequency by looking at it. They hold it to the reader, hear the beep and the door opens. The difference lies in what happens between card and reader in that half-second.

A 125kHz card draws power from the reader's field and transmits the ID number written into it at the factory. The reader passes that number to the system, which checks whether it is authorised. There is no "prove it" step: anyone who knows the number can be that card.

A 13.56MHz card can carry a microprocessor or secure memory. The reader asks it an encrypted question to confirm it is genuine, and the card can only produce the right answer with the secret key it holds. That turns the card into more than a number: canteen meal balances, zone permissions or another application's data can sit in separate, protected areas. Asset and stock tracking, by contrast, uses UHF RFID for bulk reads at a distance; see RFID inventory and asset tracking.

Many organisations still run 125kHz cards on a system installed years ago. That is common and not a failing in itself, but you need to know what it does and does not protect. We explain how to replace such a system without disrupting doors, cards or payroll in replacing a legacy access control system.

Side-by-side comparison: 125kHz vs 13.56MHz

Criterion125kHz (LF, proximity)13.56MHz (HF)
What is readUsually just a fixed ID numberID plus encrypted memory areas
AuthenticationNone; the number is sent in the clearMutual authentication (depends on card family)
Cloning riskHigh; can be copied with cheap toolsLow with current encrypted cards
Multiple applicationsNot in practicePossible in separate sectors or applications
Phone (NFC) compatibilityNoNFC works on the same frequency
Relevant standardsManufacturer-specific formatsISO/IEC 14443, ISO/IEC 15693
Card and reader costGenerally lowerGenerally somewhat higher

One point in that table deserves emphasis: 13.56MHz on its own is not a guarantee of security. The encryption on some older 13.56MHz card families was broken years ago, and many installations configure the reader to read only the card's serial number (UID), never touching the encrypted memory. In that case a 13.56MHz card is almost as easy to imitate as a 125kHz one. The right question is not "which frequency?" but "how does the reader verify the card?"

The cost of staying on legacy card technology

A cloneable card is a gap that even the guard at the gate cannot see: a copy produces exactly the same log entry as the original. Anyone reviewing the access logs sees an "authorised" person going in. It is also one of the first things testers try in a penetration test that covers physical security: copying the card of an employee they pass in the corridor in a few seconds. How to spot a cloned card in the logs and shut it down is covered in access card cloning risk.

This is not a theoretical or niche risk. In HID Global's survey of more than 1,200 security professionals, one in three companies still supported 125kHz low-frequency proximity cards, and nearly 30% still had systems using magnetic stripe cards (HID 2024 State of Physical Access Control Report, as reported by CampusIDNews).

The same research found that 39% of organisations now actively use mobile identities. (HID Global, 2024 State of Physical Access Control)

The move to mobile credentials affects the frequency decision directly: phone NFC operates at 13.56MHz and cannot talk to 125kHz readers. An organisation investing in 125kHz today may have to replace its readers again when it wants phone-based entry or QR visitor access tomorrow. Phone-based entry methods are covered in detail in our mobile access control guide.

The market is heading the same way. MarketsandMarkets forecasts that the global access control market will grow from USD 10.62 billion in 2025 to USD 15.80 billion by 2030 (MarketsandMarkets, Access Control Market – Global Forecast to 2030), with cloud platforms and IoT-based systems among the drivers, both of which are built on current, encrypted credential technology.

A five-step framework for choosing the right card

  1. Define risk by zone. A car park entrance and a server room do not need the same level of assurance. High-risk zones require encrypted authentication; in low-risk areas convenience can take priority. For card + PIN or biometric options, see our fingerprint vs card vs face recognition comparison.
  2. Take stock of what you have. How many cards are in circulation, which reader models are installed, and how does each reader verify each card? The problem is often not the card but a reader set up to read only the serial number.
  3. Choose the card family together with key management. Current AES-encrypted card families offer strong protection, but decide up front who holds the encryption keys, how they are loaded during card printing and what happens if they are lost.
  4. Plan a phased migration. Dual-frequency readers and dual-technology cards let you migrate without replacing every employee's card overnight. Start with critical zones, then general areas.
  5. Remember the personal data. Once a card number is linked to an employee, it is personal data. How it is stored, who can see it and how long it is kept all form part of KVKK compliance under Türkiye's personal data protection law.

Card choice also shapes total system cost; we break the cost items down in access control system cost, and cover the basics in our card access control system guide.

How Digital Bridge handles card migration

Because hardware and software are handled by the same team, we treat a card migration as a single piece of work:

  1. Site inventory and risk map. We inspect your readers, card types and zones on site and work out which door needs which level of assurance. Technical feasibility for hardware is free of charge.
  2. Hardware design and installation. Under our card access control service we install 125kHz and 13.56MHz readers, locks and door controllers, turnstiles and barriers, and design a layout that reads both technologies during the transition.
  3. High-security points. Where a card alone is not enough, we combine it with a second factor such as fingerprint access.
  4. Security and compliance. We address card and key management through our cyber security consultancy, and the storage of card data through data protection compliance.
  5. Integration. We connect access data to your HR, payroll or ERP systems through system integrations.

SmartPass: 13.56MHz cards and time-limited QR on one terminal

SmartPass, our own product, uses 13.56MHz RFID cards for staff and single-use, time-limited QR codes for visitors. Both are read on the same terminal and follow the same permission rules, so the frequency decision and the visitor management decision are not made separately.

In SmartPass, card security continues into the database: card numbers are not stored in plain text but as an irreversible hash. Even someone with database access cannot extract a list of card numbers. Records past their retention period are anonymised, every permission change is written to an audit trail with its old and new value, and the auditor role is read-only.

Here is a concrete scenario. A manufacturing site is moving from an old 125kHz system to SmartPass. It issues 13.56MHz cards first for critical zones such as the server room and warehouse. Rules are written in plain language: "The warehouse team may enter the Warehouse zone during working hours." The rule simulator shows, before anything goes live, whether the new rule clashes with an existing one; if it does, the system states clearly which rule applies. The same card deducts a meal in the canteen and creates an attendance record at the door, with no separate time clock needed.

Next step

If you do not know what frequency the card at your door uses, or how the reader verifies it, that is the first thing to find out. Send us one card and the reader model, and we will assess the current set-up and the options for a phased migration together. For a proposal or site visit, use our contact page.

For the physical layer that sits behind the reader, see our guide to types of turnstiles; every related article is in our access control and attendance hub.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

Can 125kHz and 13.56MHz cards work on the same reader?

A standard reader only reads its own frequency: a 125kHz reader cannot see a 13.56MHz card, and vice versa. For migrations there are dual-technology readers that read both frequencies, and cards that carry both chips. That lets you move over in phases, starting with high-risk zones, without replacing every card and reader on the same day.

Can 125kHz cards really be copied?

Yes. Most 125kHz proximity cards transmit a fixed ID number without encryption. That number can be read from a few centimetres away with cheap, widely available devices and written to a blank card, and the reader cannot tell the copy from the original. That is why a 125kHz card on its own is not recommended for server rooms, stores or other high-risk zones.

If I use 13.56MHz cards, am I safe?

Not necessarily. The encryption on some older 13.56MHz cards has been broken, and many systems read only the card's serial number rather than its encrypted memory, which makes the card almost as easy to imitate as a 125kHz one. You need a current encrypted card family and readers configured to verify the card cryptographically.

What is a MIFARE card and how does it relate to 13.56MHz?

MIFARE is a widely used family of smart cards that runs at 13.56MHz and is based on the ISO/IEC 14443 standard. A large share of the 13.56MHz cards used in access control belong to this family. It includes generations with very different security levels, so choose a current encrypted version rather than a legacy one and configure your readers to match.

Which frequency do I need for phone-based access?

Phone NFC works at 13.56MHz and is not compatible with 125kHz. If you plan mobile credentials or QR access in future, choosing 13.56MHz readers that can also scan QR codes now avoids a second hardware refresh later. For visitors, a QR code can sit on a phone or on paper, which removes the need to hand out cards at all.

Which card technology does SmartPass use?

SmartPass reads 13.56MHz RFID cards for staff and single-use, time-limited QR codes for visitors on the same terminal, and both follow the same permission rules. Card numbers are never stored in plain text; they are kept as an irreversible hash, so even someone with database access cannot extract a list of card numbers. Records are anonymised once their retention period ends.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.