Access control · EN 60839-11-1
Access control designed door by door. The right people in, and everyone out.
The grade of an access control system is not set by the reader. It is set by the credential, the cable, the controller, the locking hardware and what each door does when the fire alarm sounds. S3 designs and specifies the whole system; the licensed security company you choose installs it, and S3 checks that what was designed is what gets built.
What we decide in the design
EN 60839-11-1 assigns the security grade per access point. That is why the design is written door by door.
The grade of each door
Starting from the risk analysis, each access point is assigned a grade under EN 60839-11-1, which defines four grades and the functions each one requires. A plant room and an office door do not need the same thing. Raising the whole building to the highest grade adds cost without better protecting what matters.
Credential and reader
We rule out 125 kHz proximity: those cards can be copied with tools anyone can buy, and the copy opens the door just like the original. Moving to 13.56 MHz is not enough either: some cards at that frequency use broken encryption. We specify credentials with strong encryption and mutual authentication, using keys unique to the site and held by the client, not the installer. Where the risk justifies it, a second factor: PIN or biometrics.
Reader to controller: OSDP with secure channel
Wiegand sends the card number unencrypted and in one direction only; a device spliced into the cable can capture and replay it. OSDP (EN IEC 60839-11-5) is bidirectional: the controller supervises the reader and detects when it stops responding. With the secure channel, the communication is also encrypted. The specification requires the secure channel to be enabled, not just OSDP-capable readers.
The controller, on the protected side
The controller, the relay that releases the door and the power supply sit inside the protected area, in an enclosure with tamper detection and backup power. Only the reader is left on the outside. Whoever tears it off finds an encrypted cable, not the release.
Locking hardware, escape and fire
For each door we set the locking device (magnetic lock or electric strike), how it behaves on power loss, the door position contact and the signal that releases it on a fire alarm. On escape doors, the exit hardware is determined by the Spanish Building Code (CTE) and the fire protection design. Access control adapts to that hardware, not the other way round.
Anti-passback and interlocks
Anti-passback where you need to know who is inside: a credential that has entered cannot enter again without having left. Interlocked airlocks where both doors must never be open at the same time. Each rule has its emergency exception in writing, and how it is reset afterwards.
Events, visitors and integration
Forced door, door held open, rejected credential and duress alert: each event has a priority, a recipient and, where there is a camera, its associated image. Visitors receive credentials that expire. If the reader sets or unsets the intrusion system, that part also meets the alarm system standards, as EN 60839-11-1 requires; for intrusion, the EN 50131 series.
Typical failures we design out
- Typical failure
- 125 kHz proximity cards: copied with little effort, and the copy opens the door just like the original.
- In the design
- 13.56 MHz credentials with strong encryption and site-specific keys. If old cards have to coexist for a while, the specification sets the migration plan and the date they stop working.
- Typical failure
- A controller in the ceiling void on the unsecured side, or a reader wired over Wiegand: whoever reaches the cable opens the door.
- In the design
- Controller in the protected area, OSDP with secure channel and tamper detection on reader and enclosure, all verified during acceptance testing.
- Typical failure
- A magnetic lock on an escape door, never coordinated with the fire protection design: nobody has checked what happens on power failure or when the alarm sounds.
- In the design
- Exit hardware agreed with the fire protection designer, and release on fire alarm and on power failure included in the test protocol.
- Typical failure
- Strict anti-passback with no evacuation rule: after a drill, half the staff still show as inside and the door will not let them back in.
- In the design
- Anti-passback reset after an evacuation, defined in the design and tested at acceptance.
- Typical failure
- Credentials for visitors and for people who have left, still active months later, and an event log kept indefinitely.
- In the design
- Expiry by default, removals tied to a client procedure and a log retention period agreed with whoever handles data protection in the organisation.
What you receive
- Risk analysis and the grade assigned to each access point
- Door schedule: reader, credential, locking hardware, sensors and behaviour on power failure and on fire alarm
- Drawings showing readers, controllers and containment, plus a schematic
- Performance-based specification that several brands can meet
- Network flow matrix for the access control system
- Test protocol: opening, forced and held-open door, anti-passback, release on fire alarm and on power failure
- Designs S3
- Installs, connects and certifies the licensed security company you choose
- Operates your team
Reference standards
- EN 60839-11-1 Access control: system and component requirements, with a security grade per access point.
- EN 60839-11-2 Application guidelines: design, planning, installation, operation and maintenance.
- EN IEC 60839-11-5 OSDP: the communication protocol between the controller and the readers.
- EN 179 Emergency exit devices operated by a lever handle or push pad, for escape routes.
- EN 1125 Panic exit devices operated by a horizontal bar, for escape routes.
- EN 13637 Electrically controlled exit systems for use on escape routes.
- CTE DB SI 3 (Spain) Evacuation of occupants, including doors on escape routes.
- GDPR, Article 9 Special categories of data, including biometric data used to identify a person.
Questions
What access control grade do I need?
It depends on each door. EN 60839-11-1 defines four security grades and applies them per access point, not to the building as a whole. The risk analysis sets the grade of each door. If the building also has a Grade 3 intrusion system, the design aligns the two.
Can we use fingerprint or facial recognition?
Technically, yes, but it is not only a technical decision. In its November 2023 guide, the Spanish Data Protection Agency (AEPD) treats biometrics for attendance and access control as high-risk processing of special category data (Article 9 GDPR) and requires a prior data protection impact assessment. The decision rests with the data controller and their adviser; the design gives them the technical information and an alternative without biometrics.
Can we reuse the readers and cards we already have?
It depends on the technology. If they are 125 kHz proximity or wired over Wiegand, the audit flags it and proposes a phased migration: readers that read both technologies, card replacement group by group and a cut-off date for the old one. Whatever complies is kept.
Do you install access control?
No. S3 designs, specifies and supervises. You contract the supply and installation; if the system connects to an alarm receiving centre (ARC), that work falls to a licensed security company.
Before choosing the reader, let's define each door.
Tell us which access points you need designed or reviewed. The first conversation lasts 30 minutes, is with an engineer and is free of charge.