Replacing legacy access control without a day of open doors
What carries over, what goes, how to sequence the cutover, and how to move a whole building onto new credentials without locking anyone out.
We have been installing access control in Orange County since 1984, which means we are now regularly tearing out systems we put in ourselves twenty and thirty years ago. That is a strange kind of credential, but it is a useful one. We know what a system looks like at the end of its life because we have watched the whole life, and we know which parts of a 1998 install are still perfectly good in 2026, because we pulled the wire.
This guide is the conversation we have with facility managers who call us about a system that is limping. The vendor is gone, or the panel is discontinued, or the software only runs on a computer nobody is allowed to update. Here is how to think about the replacement, in the order we would think about it.
Signs it is actually time
Not every old system needs replacing, and we will get to when repair is the better call. But some symptoms are terminal, and it is worth being honest about which ones you have.
- The panel is end-of-life. The manufacturer has discontinued it, firmware updates stopped, and replacement boards come from eBay. The system works today, but the next failed component may have no fix.
- The head-end software runs on a museum piece. If your access control administers from a Windows XP or Windows 7 machine that cannot be patched, that computer is both a single point of failure and, if it touches your network, a security hole. We still walk into buildings where the access PC has a sticky note that says "DO NOT TURN OFF."
- You are locked out of your own system. The installing company folded or was bought, nobody has the admin password, and adding or removing an employee means calling around hoping someone can get in. At that point you do not control your access control; you just live with its last known configuration.
- Your credentials are 125 kHz prox. The classic beige clamshell cards, and most of the thin ones too. These broadcast an unencrypted number that a twenty-dollar handheld cloner can read and copy in seconds, and card-copying kiosks will duplicate them for anyone holding one. A building full of them is a building whose keys can be photocopied.
- Nobody can service it. The list of technicians who know the platform keeps shrinking, service calls take weeks to schedule, and each one starts with an hour of archaeology.
One of these alone might be manageable. Two or more, and you are spending money maintaining a liability. The buildings that plan the migration choose their schedule; the ones that wait get it chosen for them, usually at the worst possible time.
What carries over and what does not
The good news, and the reason migrations cost meaningfully less than fresh installs, is that the expensive, disruptive part of access control is the stuff in the walls and on the doors, and most of it does not care which brand of panel it is connected to.
| Component | Usually | Why |
|---|---|---|
| Door wiring | Stays | Copper is copper. If it was pulled competently and tests clean, it feeds the new system. |
| Electric strikes & maglocks | Stay | Locking hardware is platform agnostic. It gets replaced for wear, not for the migration. |
| Power supplies | Usually stay | Good ones outlive panels. We test them and replace only the tired or undersized ones. |
| Request-to-exit devices | Usually stay | Motion REX sensors and exit buttons wire into any controller. |
| Control panels | Go | The panel is the platform. Replacing the system means replacing this. |
| Readers | Go | Old readers speak old protocols and read cloneable cards. New OSDP readers are where the security upgrade actually lives. |
| Credentials | Go, eventually | Prox cards should be retired. Some platforms read old and new on one reader, so this can be gradual. |
That split is why the rough budget for a platform migration lands around 40 to 60 percent of a fresh install for the same door count. The variance inside that range is almost entirely about the condition of the existing wiring and hardware, which brings us to the audit.
Start with a door audit, not a quote
Before anyone talks numbers, someone needs to physically open every door and look. On a migration survey we walk each opening and record what lock hardware is on it, how it is powered, where the wire runs and what condition it is in, what the reader is, and whether the door has working exit and fire-release behavior. We also find the things the drawings do not show: the door someone added in 2011 with wire stapled through a ceiling tile, the maglock with no REX, the panel in a closet that now holds the janitor's supplies and a space heater.
The audit does three jobs. It tells you what actually carries over, so the quote is a real number instead of a guess with contingency stacked on it. It surfaces code problems that have to be fixed during the migration anyway. And it produces the door schedule that the whole cutover plan hangs on. An installer who quotes your migration without walking your doors is quoting somebody's building, just probably not yours. Our access control surveys are free, and so are most reputable integrators', so there is no reason to skip this step.
Three ways to cut over
Once the new platform is picked, and our PDK vs. Brivo vs. Verkada comparison covers how we make that call, the real planning question is sequencing. There are three basic strategies, and the right one depends on the building.
What we do not recommend is the accidental fourth strategy, where doors get migrated whenever someone has a free afternoon and the building spends two months half on each system with nobody sure which badge opens what. Pick a strategy, write the door schedule, and finish.
Re-badging a whole building
Credential re-issuance is the part of a migration that touches every single person in the building, so it deserves more planning than it usually gets. A few things we have learned doing this at scale:
- Clean the list first. Migration is the one natural moment to audit who should have access at all. Every legacy database we export has ghosts in it: former employees, a vendor from 2019, badges labeled "spare." Reconcile against a current HR roster before anyone prints new cards, and the new system starts life clean.
- Decide the credential mix up front. Mobile credentials on phones, smartcards, or both. Most offices land on mobile-first with a stack of cards for visitors, contractors, and the people who do not want a work app on a personal phone. Modern readers handle both at the same door.
- Use a dual-read bridge if you can. Platforms whose readers accept both the old 125 kHz cards and the new credentials let you enroll people over a couple of weeks instead of one chaotic Monday. The old cards keep working during the transition, then you shut them off on a published date. This is one of the reasons PDK shows up so often in our retrofits.
- Set a hard end date and honor it. The old credential format has to actually die, on a communicated date, or you will find cloneable prox cards still opening your server room two years later. The point of the migration was to stop that.
Fire and egress do not pause for your project
Every door has to remain legal every night of the migration, not just at final inspection. People must be able to exit without a credential, without special knowledge, and without power, on day one, day nine, and the last day. In practice that means exit hardware and REX devices stay live through every swap, maglocks keep their fire-alarm release at all times, and a door is never left overnight in a half-wired state where the lock works but the release does not.
A migration is also when inherited sins surface. Old systems accumulate them: the maglock someone added without tying it to the fire alarm, the storage room that became an office and changed the egress math. Those must be corrected during the swap, not migrated. In most Orange County cities this work needs a permit and, where fire-release wiring changes, fire marshal sign-off, which a licensed low-voltage contractor should be handling as part of the job. A bidder who does not bring up permits on a migration is telling you something.
Rescuing your data from the old system
The best case is an export. Most legacy platforms, even elderly ones, can produce a cardholder list as a CSV or a report that can be turned into one, and if the system is administrable at all, we pull names, card numbers, and access groups before anything is touched. Event history usually does not migrate; if you have retention obligations, archive the old logs as a report and keep them.
The worst case, no admin access, dead database, vendor long gone, is recoverable too. You rebuild from an HR roster, department by department, and treat it as the access review the building was overdue for anyway. We have rebuilt buildings both ways. The export saves hours; the rebuild produces the cleaner system.
When repair beats replacement
Sometimes the right answer is a service call, not a migration, and we would rather tell you that during the survey than sell you a system. Repair is usually the better call when the platform is still supported and parts are available, the failure is one component rather than the head-end, the credentials are already modern encrypted smartcards or mobile, and the building is not about to grow. A failed power supply or a water-damaged reader on a five-year-old supported system is a repair, full stop, and our commercial locksmith side handles plenty of door-hardware fixes that never justify touching the panel.
The line we use: repair buys time, and it is worth buying when the system has time left. It is not worth buying when every dollar of repair goes into a platform that is discontinued, unsupported, and secured with credentials a gift-shop kiosk can copy. Spending $2,000 fixing a system you will replace within two years is just paying for the replacement twice.
What the timeline really looks like
For a typical 10 to 30 door Orange County building, done door-by-door and occupied the whole time: about a week from survey to a written proposal; one to four weeks of hardware lead time depending on the platform and the moment's supply situation, during which the cutover schedule and re-badging plan get written; then one to three weeks of on-site work, head-end first, doors in scheduled groups, with the credential transition overlapping the door work when dual-read readers allow it. Call it four to eight weeks start to finish, with the building disruption concentrated into minutes per door rather than days per building. Small buildings on a flag-day plan compress the on-site work into a weekend. Larger or higher-security sites running parallel stretch it out deliberately.
For what the project should cost, start with the per-door numbers in our Orange County cost guide and apply the 40 to 60 percent migration discount discussed above. Then get a real number from a door audit, because your building's wiring, not a rule of thumb, decides which end of that range you are on.
Legacy migration questions
Retire the old system on your schedule.
Tell us what you are running and we will walk the building, price the migration door by door, and keep every door working while we do it.