Key takeaways
- Give every bidder the same opening inventory and operational requirements.
- Expect a site walk that covers doors, frames, locks, exit hardware, power, wiring, users, and connected systems.
- Require each proposal to state what is new, reused, tested, excluded, optional, and owned by another party.
- Compare software, credentials, recurring charges, commissioning, training, documentation, and support—not hardware alone.
- Verify the business, license, insurance, permit, and trade requirements that apply to the scope and location.
- Treat egress, fire and life-safety, and accessibility as explicit coordination items with the authority having jurisdiction.
First test
Does the installer understand the complete opening?
An access-control proposal should describe how each door, gate, garage, or elevator connection will secure, release, report status, and return to normal operation.
- Door and frame condition
- Existing lock, latch, exit hardware, closer, strike, maglock, or electrified lock
- Credential and reader compatibility
- Controller capacity and equipment location
- Power supply, low-voltage cable, conduit, and network path
- Request-to-exit and door-position needs
- User groups, schedules, software, and administration
- Intercom, gate, elevator, camera, alarm, network, and automatic-operator connections
- Egress, fire and life-safety, accessibility, permit, and authority-review conditions
- Commissioning, handoff, documentation, warranty, and support
Before bids
Give every installer the same problem to solve.
Proposals become comparable when every bidder receives the same property context, opening schedule, and operating requirements.
Property summary
Provide the property type, operating pattern, project goals, current system, known problems, project phases, target openings, expected users, administrators, and affected property, facilities, IT, security, and management contacts.
Opening schedule
For each door or gate, record location, purpose, secure and egress sides, door and frame type, existing lock and release hardware, closer, reader, observed symptoms, known controller and cable connections, and visible conditions that require professional review.
Operational requirements
Describe credential preferences, user groups, schedules, visitor and vendor rules, staff overrides, lost-credential and offboarding processes, event needs, connected systems, training, and support expectations.
Field review
Expect the site walk to cover physical and digital conditions.
Physical openings
The installer should inspect doors, frames, locks, latches, exit devices, hinges, closers, strikes, maglocks, electrified hardware, and repeated closing behavior. A door that drags, sags, binds, or fails to latch belongs in the proposal.
Infrastructure
Readers, controllers, power supplies, cable paths, conduit, network connections, and equipment spaces should be located or traced. Existing infrastructure should be identified and tested before reuse is promised.
Access flow
The installer should ask who enters, where, and when, including staff, tenants, residents, vendors, maintenance teams, deliveries, visitors, and administrators.
Connected systems
Intercom release, gates, elevators, automatic operators, alarm interfaces, cameras, and networks should have clear interface and responsibility boundaries.
Code-sensitive conditions
Required egress doors, fire-rated openings, panic or fire exit hardware, delayed-egress systems, and other electrically locked egress arrangements should be flagged for appropriate design, permit, and authority review.
Qualification
Evaluate business records, relevant experience, and scope clarity.
Business and scope verification
Confirm that the legal business identity matches public records. Ask which license classifications, registrations, permits, insurance, and other-trade requirements apply to the proposed work, then verify those items through the appropriate state and local sources.
Commercial opening experience
Look for the ability to explain readers, credentials, controllers, power, wiring, software, doors, frames, locks, strikes, maglocks, closers, exit hardware, and egress as one connected scope.
Relevant proof
Ask for service-matched references or reviews and permission-cleared project photos that do not expose credentials, sensitive system details, security weaknesses, or private property information.
Accountability
Identify the project contact and the parties responsible for system design, doors, wiring, power, networks, gates, elevators, alarms, finish work, permits, inspections, commissioning, and support.
Technical comparison
Require the proposal to explain design, reuse, and lifecycle.
Opening-level design
Every controlled opening should have a defined credential, reader, controller connection, locking or release method, request-to-exit, door position, power, cable path, egress behavior, and system interface as applicable.
Reuse decisions
Ask which doors, locks, readers, controllers, power supplies, cables, and conduit will remain, how each will be verified, and what happens if a retained component does not pass inspection or testing.
Software and administration
Confirm account ownership, administrator access, user and credential management, schedules, event review, software, licenses, subscriptions, renewal decisions, offline behavior, updates, expansion, and support.
Migration and future direction
If old and new systems will coexist, require a credential, user, controller, wiring, opening, event-history, temporary-operation, testing, and legacy-retirement plan.
Apples-to-apples review
Normalize the scope before comparing totals.
| Category | What should match | Question when it does not |
|---|---|---|
| Controlled openings | Same doors, gates, garages, elevator connections, and phases | Did one bidder omit, combine, or assume an opening? |
| Credentials and readers | Same user groups and required credential capabilities | Are card, fob, mobile, keypad, and migration assumptions different? |
| Controllers and architecture | Equivalent capacity, management, resilience, and future direction | Does one proposal require more shared infrastructure or constrain expansion? |
| Locking hardware | A complete, compatible release method for every opening | Did one bidder include door hardware while another assume the current opening works? |
| Exit and monitoring | Same required request-to-exit, door-position, manual-release, alarm, and other functions | Are devices or emergency behaviors omitted? |
| Power and wiring | Equivalent supplies, cable, conduit, pathways, labeling, and testing | Is existing infrastructure assumed reusable without verification? |
| Door and frame work | Same preparation, repair, alignment, closer, patching, and finish responsibilities | Who handles an opening that cannot accept the proposed hardware? |
| Software and recurring costs | Same term, subscriptions, hosting, features, licenses, and administrator rights | Are renewal or recurring costs absent from the initial total? |
| Integrations | Same intercom, gate, elevator, network, camera, and alarm interfaces | Does the scope deliver a working integration or stop at an undefined connection? |
| Permits and review | Same design, permit, inspection, and AHJ responsibilities | Which items are included, allowances, exclusions, or owner responsibilities? |
| Commissioning and handoff | Same testing, acceptance, documentation, training, and account transfer | What will the property actually receive before closeout? |
| Support | Same warranty, service path, response process, and exclusions | Who handles a failure that crosses software, wiring, locking hardware, and the door? |
Contract clarity
Put the opening, responsibilities, acceptance, and commercial terms in writing.
Scope by opening
Describe existing conditions and proposed reader, credential, controller, locking hardware, request-to-exit, door-position, power, wiring, preparation, and connected-system work for each opening.
Shared system scope
List controllers, power supplies, software, licenses, networks, credentials, user setup, equipment locations, and shared infrastructure.
Responsibilities and exclusions
Assign door, frame, electrical, low-voltage, network, gate, elevator, fire-alarm, automatic-operator, permit, inspection, patching, painting, and occupied-building coordination as applicable.
Acceptance and handoff
Define testing, administrator access, training, documentation, device records, opening schedules, punch-list, and support conditions.
Commercial terms
Make hardware, labor, taxes, freight, subscriptions, recurring fees, alternates, allowances, exclusions, payment milestones, and change-order conditions visible and understandable.
Buyer protection
Red flags in an access-control proposal
- No site walk for a retrofit involving existing doors and hardware
- Reader quantities with no opening schedule
- No description of the lock, strike, maglock, exit device, closer, or door behavior
- Existing wiring assumed reusable without identification or testing
- No controller, power-supply, software, or credential-management detail
- Integration included without a named interface and responsibility boundary
- No plan for user migration, schedules, account ownership, or administrative handoff
- Fire-rated, egress, delayed-egress, or panic-hardware conditions treated as generic devices
- Recurring software, service, or renewal costs omitted from comparison
- Unclear permit, inspection, patching, finish, or other-trade responsibilities
- Support described without a contact path, scope, warranty, or exclusions
- Formal partner, dealer, certification, licensing, or performance claims that cannot be verified
Installer interview
Ask questions that reveal whether the proposal is property-specific.
- What did you observe at each opening that changed your recommendation?
- How does the access request travel from credential to reader to controller to lock?
- Why does the selected locking hardware fit this door and frame?
- Which components will be reused, and how will you verify them?
- What happens when lock power, utility power, network connectivity, or a connected system changes?
- How do people exit, and which release or monitoring devices are included?
- Which conditions require design, permit, inspection, or AHJ review?
- Who owns each interface with intercoms, gates, elevators, alarms, cameras, networks, and automatic operators?
- What does the property team receive at handoff?
- How are lost credentials, turnover, schedules, administrators, and future expansion handled?
- What recurring charges and renewal decisions apply?
- Who diagnoses a failure that involves both the access system and physical door?
Claims boundary
Expect an approval path, not a generic compliance promise.
Be cautious with a proposal that promises a code-compliant result without identifying the opening, occupancy, current California requirements, local amendments, design responsibility, and approval path. Electrified locking can involve egress, fire-alarm and sprinkler conditions, accessibility, panic or fire exit hardware, emergency lighting, signage, and other requirements.
Applicable requirements depend on the project and jurisdiction. Listed, compatible components should be used where required. The fire marshal or other authority having jurisdiction determines compliance.
Common questions
Installer and proposal questions
How many bids should a property compare?
Follow the property’s procurement process. Additional bids are useful only when each bidder receives the same requirements and the proposals can be normalized to the same scope. California CSLB guidance recommends comparing written bids against identical plans, specifications, and scope.
Should the lowest proposal win?
Not until the scopes match. One proposal may include door hardware, wiring, software, subscriptions, integrations, permits, testing, and support that another leaves out. Compare total responsibility and lifecycle conditions before comparing totals.
Does every door need inspection?
Every retrofit opening needs enough field verification to support the proposed hardware, wiring, and responsibility. Repeated opening types may share details, but assumptions should still be documented.
Who should own the access-control account?
The proposal should state who receives administrator access, what rights are included, how credentials and schedules are managed, and what happens if the property changes staff or service providers.

Sources and further reading
These references support the general technical guidance. The right answer for a specific opening still depends on the property and the authorities responsible for the project.
- California Contractors State License Board: Finding the Right Contractor
- California Contractors State License Board: Check a License
- U.S. General Services Administration: Guide to Physical Access Control Systems Ordering
- Security Industry Association: The Basics of Physical Access Control
- California Building Standards Commission: 2025 California Code Changes: Chapters 9 and 10
- California Building Standards Commission: Current California Building Standards Codes
