Replacing controllers is a day of work per enclosure. Everything that makes a migration difficult sits either side of that day.
The work that decides the outcome is the inventory, the credential audit, the access-level cleanup and the verification of what the field wiring can actually carry. Skip any of those and the problems appear at cutover, in an occupied building, at night, with a rollback window that is already closing.
What follows is the sequence that keeps that from happening, in the order the work should be done.
Inventory what exists, not what the drawings say
Assume the as-built documentation is wrong. It was accurate at handover and has been drifting since. Doors have been added on spare points, panels repurposed, readers replaced with a different model, and at least one enclosure will contain something nobody in the building can explain.
The inventory has to be physical. Every enclosure opened, every board model and revision recorded, every address confirmed against the software, every door listed with the lock type, whether it is fail-safe or fail-secure, whether the door position switch and request-to-exit device are present and supervised, and which power supply feeds it. Reader model and mounting per door. Cable type and, where it can be established, the run topology.
Two findings recur often enough to plan for. First, spare capacity that is not spare, because a point has been used for something undocumented such as an intrusion input or an interface to another system. Second, doors present in the field that do not exist in any drawing, usually added during a fit-out by a different contractor.
Audit the credentials before choosing anything
Credential formats accumulate. A site that has been operating for fifteen years has usually been through at least two card orders and one acquisition or reorganization, and the population reflects that. Expect several bit lengths in circulation, more than one facility code, and a set of cards nobody can account for.
This matters because a card format is a bit-length and a bit-layout, and the reading device and the controller both need to agree on it. Migrate to a platform or a reader configuration that does not carry every format currently in use and a portion of the cardholder population stops working at cutover. The cards read. The bits arrive. The controller cannot interpret them, and the event log fills with reads that produce no cardholder match. It is a distinctive failure and an avoidable one.
The audit is a report of every credential format and facility code in the active cardholder set, with counts. That report drives three decisions: which formats the new readers must be configured to accept, which formats are small enough in number to reissue instead, and whether this is the point to move credential technology entirely. If it is, that is a separate project running alongside, not a subtask.
- Formats and bit lengths in circulation, with a count per format, taken from live data rather than from the original specification.
- Facility codes in use, including any duplicates across formats.
- Orphaned records. Cardholders with no credential, credentials with no cardholder, and records not used in over a year.
- Duplicates. The same person present two or three times from different data loads, each with different access.
- Expiry and activation dates that were set once and never enforced.
Do not migrate access levels one for one
Access levels accumulate faster than credentials. Every exception granted over a decade tends to become a permanent level, and a mature system commonly holds several times more levels than it has meaningful groups of people. Copying that structure into the new system reproduces a mess that will then be difficult to unpick for another decade.
The migration is the only convenient opportunity to rationalize it. Report every access level with the number of cardholders assigned. Levels with one or two holders are almost always exceptions that should be expressed differently. Levels with zero holders should not be migrated at all. Levels whose names reference a department that no longer exists need an owner before they move.
This work is not technical and does not need a technician. It needs whoever owns access policy, and it needs to start early, because it is the task most likely to be late.
Verify what the field wiring can carry
The cable and pathways are the most valuable thing on site and the most commonly assumed. Reuse is usually possible and always needs verifying.
The specific trap is the move from Wiegand to OSDP. Wiegand is a point-to-point interface and tolerates a home-run star layout, mixed cable and a single unshielded run to each reader. OSDP is RS-485: a multi-drop bus with a bounded total length, termination at the two physical ends, a single shield ground, and a strong preference for a proper twisted pair. A star layout that has carried Wiegand reliably for ten years becomes a set of unterminated stubs the moment it carries a bus, and the resulting faults are intermittent, distance-dependent and difficult to attribute after the fact.
Verify before committing: cable type and pair count per run, measured run lengths, the actual topology from panel to device, and whether shields are present and correctly grounded. Where a run does not qualify, the options are to keep that reader on the old interface, to convert the run to a compliant topology, or to accept a new run. All three are cheaper as a planning decision than as a cutover discovery.
Cutover, in door groups
A whole-site cutover concentrates all of the risk in one window and removes the rollback. Groups spread it.
- 01 Pick a low-consequence pilot group — A small set of doors, mixed types, low traffic, no life-safety interlock. The purpose is to learn what the site does that the plan did not anticipate.
- 02 Freeze the old configuration — Take a full backup of the legacy database and store it somewhere the project cannot overwrite. This is the rollback.
- 03 Load and reconcile cardholder data — Import into the new system and reconcile counts by format and by access level. Differences found here are data problems. Differences found after cutover are incidents.
- 04 Cut the group and test every door twice — Valid read, invalid read, request-to-exit, door position reporting, held and forced alarms, and free egress. Test from both sides where both sides have hardware.
- 05 Verify fail-safe and fail-secure behaviour is unchanged — Drop power to each door and confirm it behaves exactly as it did before the work, and as the door schedule and the authority having jurisdiction require.
- 06 Verify the fire alarm interface — Any door released on fire alarm must be re-verified after a controller change, witnessed, and recorded. This is not optional and it is not a software test.
- 07 Confirm alarms arrive where they are watched — A correctly reporting door whose alarm routes to a monitor that no longer exists is a door that reports nothing.
- 08 Hold the group for a week before the next one — Most defects surface across a full operating cycle, including a weekend and a shift change. Cutting the next group before that cycle completes copies the defect forward.
Running two systems in the interim
Between the first group and the last, the site operates two access-control systems. That state needs to be designed rather than tolerated. Decide who administers each, how a new starter gets credentials during the overlap, how a lost card is revoked in both, and how an operator knows which system holds a given door. Print the door-to-system map and put it where the control room can see it.
The overlap period is also where schedule slip is most costly, because staff are maintaining two sets of records manually. Keep it short and keep it staffed.
If the decision to migrate is not yet settled, work through repairing versus replacing a security system first. If the head end is also moving version, the compatibility work is in preparing for a Genetec or C•CURE upgrade.
Scope the migration before it is quoted
Inventory, credential audit and wiring verification produce a scope that holds. Guesswork produces change orders.