The key difference between 125kHz and 13.56MHz access cards is security. Most 125kHz ("prox") cards broadcast a fixed number without encryption and can be copied with an inexpensive device. 13.56MHz cards can support mutual authentication, encrypted memory and several applications on one card. For a new access control installation, choose 13.56MHz with a current, encrypted card family.
Two cards that look identical but do different jobs
Hand someone a plain white PVC card and they cannot tell its frequency by looking at it. They hold it to the reader, hear the beep and the door opens. The difference lies in what happens between card and reader in that half-second.
A 125kHz card draws power from the reader's field and transmits the ID number written into it at the factory. The reader passes that number to the system, which checks whether it is authorised. There is no "prove it" step: anyone who knows the number can be that card.
A 13.56MHz card can carry a microprocessor or secure memory. The reader asks it an encrypted question to confirm it is genuine, and the card can only produce the right answer with the secret key it holds. That turns the card into more than a number: canteen meal balances, zone permissions or another application's data can sit in separate, protected areas. Asset and stock tracking, by contrast, uses UHF RFID for bulk reads at a distance; see RFID inventory and asset tracking.
Many organisations still run 125kHz cards on a system installed years ago. That is common and not a failing in itself, but you need to know what it does and does not protect. We explain how to replace such a system without disrupting doors, cards or payroll in replacing a legacy access control system.
Side-by-side comparison: 125kHz vs 13.56MHz
| Criterion | 125kHz (LF, proximity) | 13.56MHz (HF) |
|---|---|---|
| What is read | Usually just a fixed ID number | ID plus encrypted memory areas |
| Authentication | None; the number is sent in the clear | Mutual authentication (depends on card family) |
| Cloning risk | High; can be copied with cheap tools | Low with current encrypted cards |
| Multiple applications | Not in practice | Possible in separate sectors or applications |
| Phone (NFC) compatibility | No | NFC works on the same frequency |
| Relevant standards | Manufacturer-specific formats | ISO/IEC 14443, ISO/IEC 15693 |
| Card and reader cost | Generally lower | Generally somewhat higher |
One point in that table deserves emphasis: 13.56MHz on its own is not a guarantee of security. The encryption on some older 13.56MHz card families was broken years ago, and many installations configure the reader to read only the card's serial number (UID), never touching the encrypted memory. In that case a 13.56MHz card is almost as easy to imitate as a 125kHz one. The right question is not "which frequency?" but "how does the reader verify the card?"
The cost of staying on legacy card technology
A cloneable card is a gap that even the guard at the gate cannot see: a copy produces exactly the same log entry as the original. Anyone reviewing the access logs sees an "authorised" person going in. It is also one of the first things testers try in a penetration test that covers physical security: copying the card of an employee they pass in the corridor in a few seconds. How to spot a cloned card in the logs and shut it down is covered in access card cloning risk.
This is not a theoretical or niche risk. In HID Global's survey of more than 1,200 security professionals, one in three companies still supported 125kHz low-frequency proximity cards, and nearly 30% still had systems using magnetic stripe cards (HID 2024 State of Physical Access Control Report, as reported by CampusIDNews).
The same research found that 39% of organisations now actively use mobile identities. (HID Global, 2024 State of Physical Access Control)
The move to mobile credentials affects the frequency decision directly: phone NFC operates at 13.56MHz and cannot talk to 125kHz readers. An organisation investing in 125kHz today may have to replace its readers again when it wants phone-based entry or QR visitor access tomorrow. Phone-based entry methods are covered in detail in our mobile access control guide.
The market is heading the same way. MarketsandMarkets forecasts that the global access control market will grow from USD 10.62 billion in 2025 to USD 15.80 billion by 2030 (MarketsandMarkets, Access Control Market – Global Forecast to 2030), with cloud platforms and IoT-based systems among the drivers, both of which are built on current, encrypted credential technology.
A five-step framework for choosing the right card
- Define risk by zone. A car park entrance and a server room do not need the same level of assurance. High-risk zones require encrypted authentication; in low-risk areas convenience can take priority. For card + PIN or biometric options, see our fingerprint vs card vs face recognition comparison.
- Take stock of what you have. How many cards are in circulation, which reader models are installed, and how does each reader verify each card? The problem is often not the card but a reader set up to read only the serial number.
- Choose the card family together with key management. Current AES-encrypted card families offer strong protection, but decide up front who holds the encryption keys, how they are loaded during card printing and what happens if they are lost.
- Plan a phased migration. Dual-frequency readers and dual-technology cards let you migrate without replacing every employee's card overnight. Start with critical zones, then general areas.
- Remember the personal data. Once a card number is linked to an employee, it is personal data. How it is stored, who can see it and how long it is kept all form part of KVKK compliance under Türkiye's personal data protection law.
Card choice also shapes total system cost; we break the cost items down in access control system cost, and cover the basics in our card access control system guide.
How Digital Bridge handles card migration
Because hardware and software are handled by the same team, we treat a card migration as a single piece of work:
- Site inventory and risk map. We inspect your readers, card types and zones on site and work out which door needs which level of assurance. Technical feasibility for hardware is free of charge.
- Hardware design and installation. Under our card access control service we install 125kHz and 13.56MHz readers, locks and door controllers, turnstiles and barriers, and design a layout that reads both technologies during the transition.
- High-security points. Where a card alone is not enough, we combine it with a second factor such as fingerprint access.
- Security and compliance. We address card and key management through our cyber security consultancy, and the storage of card data through data protection compliance.
- Integration. We connect access data to your HR, payroll or ERP systems through system integrations.
SmartPass: 13.56MHz cards and time-limited QR on one terminal
SmartPass, our own product, uses 13.56MHz RFID cards for staff and single-use, time-limited QR codes for visitors. Both are read on the same terminal and follow the same permission rules, so the frequency decision and the visitor management decision are not made separately.
In SmartPass, card security continues into the database: card numbers are not stored in plain text but as an irreversible hash. Even someone with database access cannot extract a list of card numbers. Records past their retention period are anonymised, every permission change is written to an audit trail with its old and new value, and the auditor role is read-only.
Here is a concrete scenario. A manufacturing site is moving from an old 125kHz system to SmartPass. It issues 13.56MHz cards first for critical zones such as the server room and warehouse. Rules are written in plain language: "The warehouse team may enter the Warehouse zone during working hours." The rule simulator shows, before anything goes live, whether the new rule clashes with an existing one; if it does, the system states clearly which rule applies. The same card deducts a meal in the canteen and creates an attendance record at the door, with no separate time clock needed.
Next step
If you do not know what frequency the card at your door uses, or how the reader verifies it, that is the first thing to find out. Send us one card and the reader model, and we will assess the current set-up and the options for a phased migration together. For a proposal or site visit, use our contact page.
For the physical layer that sits behind the reader, see our guide to types of turnstiles; every related article is in our access control and attendance hub.