The demo is very good. Someone walks up to a door, the phone stays in their pocket, the lock releases. No card, no fob, no lanyard, no re-badging Saturday. Then the salesperson revokes the credential from a laptop while you watch, and the same phone stops working at the same door.
That demo is honest. Mobile credentials really do fix things that plastic never fixed, and this article is not an argument against them. It is an argument for going in with the full invoice — the operational one, not just the financial one — because the parts that get left out of the demo are the parts you will manage for the next decade.
What it genuinely fixes
Issue and revoke stop being physical events. With cards, adding a person means someone finds the card stock, encodes a credential, prints it, and hands it over — and removing a person means getting the card back, which is the step that reliably fails. A mobile credential is issued from a console and revoked from a console. The gap between "this person no longer works here" and "this person can no longer open the door" collapses from whenever-the-card-comes-back to now.
No card stock, no printer, no drawer. Every building that runs cards has a drawer. In it are blanks, a handful of encoded-but-unassigned credentials, some returned cards nobody deactivated, and a printer ribbon. That drawer is a small unmanaged inventory of working keys, and mobile removes it entirely.
Lending is harder. Not impossible — a determined person can hand over an unlocked phone, and a determined person can also just hold the door. But handing your phone to a coworker for a shift is a meaningfully bigger ask than handing over a fob, because the phone is also your messages, your banking, and your photographs. The friction is social rather than technical, and social friction is the kind that actually holds.
Loss gets noticed on a completely different timescale. This is the underrated one. People notice a missing phone within minutes, because they reach for it constantly and because it is worth something. A lost access card can go unmissed for weeks — nobody reaches for the parkade fob between Friday and Monday, and a card that lives permanently in a jacket pocket can be gone an entire season before anyone realizes. Since a credential is only as good as the speed at which its loss is reported, moving the credential onto the object people track obsessively is a real security improvement, independent of any cryptography.
And the credential itself is generally stronger. Mobile schemes are built on modern encrypted exchanges rather than the open broadcast that legacy proximity cards use. If your building is still on beige prox fobs, that gap is the larger part of the story, and we have written about it separately in the access-card upgrade trap — including the reason new credentials alone change nothing until the readers stop accepting the old ones.
The dependencies nobody mentions at the demo
Everything above is true. Here is the other column.
The phone has to have charge. A card is a passive object with no battery and no failure mode short of snapping it in half. A phone is a device with a duty cycle, and the person carrying it also uses it for eight hours of everything else. Some handsets keep a credential available for a period after the battery is nominally flat, and some do not — that behaviour depends on the phone model, the operating system, and the platform, and it is not a property of your access control system that you can specify. Plan for the dead-phone case as a normal event, because it is one.
The reader has to speak the phone's radio, and the phone's scheme. This is the assumption that quietly breaks retrofits. A reader that reads your existing cards does not automatically read phones. Mobile credentials are presented over short-range radio — the tap-range interface, or the longer-range Bluetooth one — and the reader has to support the relevant radio and the specific vendor's mobile credential scheme. Two readers that look identical on the wall can differ on exactly this. Sometimes the readers already in place are capable and only need configuration and licensing; sometimes they need replacing at every door. That is a large fork in the cost of the project, and the only way to know which side you are on is to have someone identify the reader models before anyone writes a proposal.
It rides on a wire you may not have thought about. Presenting a credential is the front half of the transaction. The reader still has to tell a controller what it saw, over the cabling behind the wall — which in a great many BC buildings is a legacy, unencrypted, unsupervised link. Modernizing the credential while leaving that untouched improves one half of the path. The wire between your card reader and the door covers the other half.
There is a licensing model attached, and it does not work like card stock. Cards are a purchase: you buy them, you own them, and if you stop buying more, the ones in circulation keep working forever. Mobile credentials are licensed. The models vary — per credential, per reader, subscription, term-based, sometimes a mix — and they are not equivalent to each other in the way a purchase is. We are not going to quote you numbers for any of them, because pricing varies by vendor, by volume and by year, and a security company inventing a figure to make a point is doing something you should not trust. What you should do is ask three specific questions and get the answers in writing: what triggers a charge, what happens when a person leaves and their credential is revoked, and what happens to credentials already in circulation if you stop paying. That last question is the one that matters most and gets asked least.
