Your access control system works fine. Then you order 2,000 replacement employee ID cards, they arrive on time, and half your doors reject them. Nothing looks wrong: the artwork is crisp, the photos are sharp, the plastic feels solid. The failure is invisible, and it is almost always the same one — the chip inside the card does not speak the same language as the readers on your walls.

This guide is written for facility security managers, IT teams, and procurement leads who buy employee ID cards in volume and cannot afford a failed rollout. It is deliberately ordered the way the decision should actually be made: reader compatibility first, card material second, visual security third, and only then artwork and price. Reverse that order and you will pay for the same batch twice.
By the end you will have a reader audit you can run this week, a chip-to-reader compatibility table, a realistic view of what different card materials cost over their service life, and the exact specification sheet your supplier needs before production starts. We have manufactured secure cards and credentials since 2005, and the errors below are the ones we intercept most often at the quotation stage.

Start With the Reader, Not the Card

The most costly error in employee badge procurement is treating the card as a print job. It is not. The card is one half of a radio protocol, and the reader is the other half. A 125 kHz proximity card will never work on a 13.56 MHz reader, regardless of how well it is printed, laminated, or personalised. Frequency and protocol both have to match, and “contactless” tells you almost nothing on its own.
Before you request a single quotation, run this audit:
- Read the label on the reader itself. Most units carry a manufacturer mark and model number on the housing or under the faceplate. HID, Suprema, ZKTeco, Idemia, and Nedap all print identifiable model codes.
- Ask your access control software for the card format. The head-end system knows the bit format it expects — for example 26-bit H10301 or a 37-bit corporate format. This is often easier to obtain than the reader spec.
- Request a card compatibility report from your integrator. If you have a service contract, this costs you nothing and creates a written record you can hold them to.
- Send your supplier a working sample card — not a photo of one. A physical sample lets a manufacturer read the chip type, UID structure, and encoded format directly, which removes guesswork entirely.
If your site has grown through acquisitions or phased fit-outs, expect to find more than one reader generation in the building. That is normal, and it changes your answer: you may need dual-technology cards rather than a single credential type. We return to that in the migration section.

Prox, MIFARE Classic, DESFire EV3, Seos: What Your Readers Actually Accept

Once you know what your readers accept, the next question is whether you should keep using it. These technologies are not interchangeable and they are not equally safe. Contactless cards at 13.56 MHz are governed by ISO/IEC 14443-1:2018, but conforming to the standard says nothing about cryptographic strength — that depends entirely on the chip.
| Credential technology | Frequency | Security model | Clone resistance | Sensible use in 2026 |
|---|---|---|---|---|
| HID Prox, EM4100, AWID, Indala | 125 kHz | Fixed number, no cryptography | Very low | Legacy doors pending replacement |
| MIFARE Classic 1K / 4K | 13.56 MHz | Proprietary Crypto1 | Low | Canteen, printing, non-critical |
| MIFARE Plus / DESFire EV2, EV3 | 13.56 MHz | AES-128, mutual authentication | High | Standard for new enterprise rollouts |
| HID iCLASS SE / Seos | 13.56 MHz | AES with secure object container | High | Sites already in the HID ecosystem |
| Dual-technology (125 kHz + 13.56 MHz) | Both | Inherits the weaker of the two | Mixed | Transition period only |
Two points deserve emphasis because they change budgets.
First, 125 kHz proximity credentials transmit a fixed number with no authentication and can be duplicated in seconds using handheld cloners that cost less than a single day of guard cover. They are convenience tokens, not security credentials. NIST reached the same conclusion for federal facilities and published a risk-based framework for choosing authentication strength in SP 800-116 Rev. 1, Guidelines for the Use of PIV Credentials in Facility Access. Even if you are not a federal agency, its graduated approach — match the authentication mechanism to the risk behind the door — is the cleanest way to justify budget to a finance committee.
Second, MIFARE Classic’s proprietary Crypto1 cipher has been publicly broken since 2008, and practical attack tooling has been in circulation ever since. If your canteen and your server room share one MIFARE Classic credential, your server room inherits the canteen’s security level.
There is also a trap in the word “compatible.” Many readers will happily accept a modern card by reading only its card serial number (CSN or UID) — the unencrypted identifier every ISO/IEC 14443 card broadcasts before authentication. A system configured this way gets none of the cryptographic protection it paid for, because the CSN can be read and replayed as easily as a Prox number. Ask your integrator explicitly whether the reader performs mutual authentication against a diversified key, or merely reads the CSN. For a deeper technical breakdown of the chip families themselves, see our MIFARE vs NTAG vs ICODE vs UCODE chip comparison, and for the HID-specific ecosystem our guide to HID smart cards and credentials for access control.
When a supplier claims a chip is certified, you can verify it yourself: security certifications for smart card ICs are published on the Common Criteria Portal certified products list. A certification claim that cannot be found on that list should be treated as marketing, not evidence.

Card Body Material: Why Cheap Cards Are Rarely the Cheapest

An employee badge lives a hard life. It gets clipped, flexed, dropped, wiped with alcohol, left on a dashboard in summer, and tapped against a reader ten or more times a day. The international methodology for predicting whether a card survives that life is ISO/IEC 24789-1:2024, Identification cards — Card service life, which derives a test plan from two inputs: expected service life in years and average uses per day. It includes a dedicated application profile for access cards, and it is the right language to use when you challenge a supplier’s durability claim.
| Card body | Typical daily-carry service life | Relative blank cost | Best fit | Main failure mode |
|---|---|---|---|---|
| Standard PVC | 1–3 years | 1.0× | Visitors, contractors, short campaigns | Warping, delamination, print wear |
| Composite PVC/PET | 3–5 years | 1.3–1.6× | Daily-carry employee badges | Edge wear over long service |
| Polycarbonate | 5–10+ years | 2.5–4× | High-security and laser-engraved IDs | Higher unit cost, longer lead time |
Run the arithmetic that matters. The number to optimise is not the price of a blank card — it is the fully loaded cost of an issued badge across the credential’s service life, which includes the chip, printing, the ribbon and laminate, the HR and security staff time to re-photograph and re-issue, and the access control record-keeping around each replacement. In most enterprise programmes that administrative load is several times the price of the card itself. A composite card at 1.4× the blank cost that survives twice as long is not a premium option; it is the cheaper option.
Polycarbonate earns its price where tamper evidence is a requirement rather than a preference: the layers fuse into a monolithic body, so the card cannot be split and re-assembled with a substituted photo, and personalisation is laser-engraved into the core rather than printed on the surface. If you are weighing that decision in detail, our comparison of polycarbonate vs PVC vs PETG for government ID covers the trade-offs, and our polycarbonate ID card page lists available constructions.
One practical note that saves reprints: contactless cards have a slightly uneven surface over the embedded chip and antenna, so direct-to-card printing can leave visible artefacts and white edges. Retransfer (reverse transfer) printing prints to a film that is then fused onto the card, giving true edge-to-edge coverage on chip cards. If your artwork carries a full-bleed corporate colour, specify retransfer.

Visual Security: What Stops a Forged Badge at the Door

Chip security protects the door. It does nothing at reception, in a lift lobby, or during a guard’s visual spot-check — and those are exactly the checkpoints an intruder targets. A badge that is cryptographically strong but visually generic still fails at the one checkpoint that has no reader: the person looking at it. A convincing counterfeit only has to survive two seconds of human attention.
Effective visual security is layered so that features are checkable at different levels of effort:
- Overt (verifiable by anyone, instantly): a custom holographic overlay or patch carrying your logo, a ghost image of the cardholder, colour-shifting ink, and tactile embossing. Custom holograms matter more than generic ones — a stock “genuine” hologram can be bought by anyone.
- Covert (verifiable by trained staff with simple tools): microtext that blurs when photocopied, UV-fluorescent inks, and fine guilloche line work that defeats scan-and-reprint attacks.
- Forensic (verifiable by the issuer): taggants, hidden registration marks, and a controlled substrate batch that lets you prove a card came from your production run.
Match the layer count to the risk behind the door rather than buying every feature available. A distribution centre and a pharmaceutical clean room do not need the same badge. Our breakdown of ID card security tiers maps feature sets to organisational risk levels, and custom holographic overlays can be produced to your own artwork rather than a stock design.
Whatever features you choose, train the people who check badges and give them a reference card. Security features that nobody has been shown how to verify are decoration.

The Specification Sheet Your Supplier Needs Before Production

Almost every badge reprint we see could have been prevented by a complete specification at the quotation stage. Send this with your enquiry and you remove the ambiguity that causes rework:
- Reader make, model, and firmware version, plus the access control platform.
- Chip part number, not just the family name. “DESFire” is a family; the orderable item is a specific part such as a DESFire EV3 8K. Memory size and EV generation both affect price and compatibility.
- Card data format and bit length (for example 26-bit H10301), the facility or site code, the card number range, and the start number.
- Key management: who holds the AES application keys, whether keys are diversified per card, and whether the factory pre-encodes or you encode in-house at issuance.
- Printed numbering: whether the human-readable number matches the encoded number, and where it sits on the card.
- Physical format: ID-1 per ISO/IEC 7810:2019 — 85.60 × 53.98 mm, 0.76 mm nominal thickness — plus slot punch position and orientation.
- Personalisation: photo specification, variable data fields, and whether printing is retransfer or direct-to-card.
- Packaging and sequencing: boxed in number order, or split by department or site.
One line on that list quietly causes more trouble than the rest combined. The widely used 26-bit H10301 Wiegand format encodes only an 8-bit facility code and a 16-bit card number — 255 facility codes and 65,535 card numbers in total. Large employers, high-turnover operations, and long-running programmes exhaust that space and end up with two live credentials carrying identical numbers, which the access control system cannot distinguish. If your organisation is anywhere near that scale, specify a larger custom format before you order, not after the collision appears in an audit.
If photo capture and issuance workflow is the part you are still designing, our walkthrough on how to make photo ID cards for employees covers image standards and the enrolment sequence.

Migrating Off Legacy Credentials Without Shutting the Door

Most organisations know their 125 kHz or MIFARE Classic estate should be retired. What stops them is the arithmetic of doing it all at once: replacing every reader and re-badging every employee in the same quarter is a capital request that rarely survives review. There are three realistic paths.
- Dual-technology cards. One card carries both a 125 kHz chip and a 13.56 MHz secure chip. Issue the new badge once; old readers keep working while you replace them at your own pace. This decouples the credential rollout from the reader rollout, which is what makes the budget approvable.
- Multi-technology readers. Replace readers first with units that accept both legacy and secure credentials, then re-badge population by population. Better if your reader estate is already at end of life.
- Zone-by-zone cutover. Convert the highest-risk areas — data centres, cash handling, R&D, controlled stock — to secure credentials first and leave perimeter doors for a later phase. This is the risk-based sequencing NIST recommends in SP 800-116 Rev. 1.
A caveat that suppliers rarely volunteer: a dual-technology card is only as strong as its weakest interface, and the 125 kHz side remains clonable for as long as any reader still honours it. Dual-tech is a bridge, not a destination. Write a sunset date for legacy acceptance into the project plan at the start — and confirm your access control platform can be configured to stop honouring the legacy format on that date, rather than assuming it can.
If you are also standardising RFID across asset tracking or logistics at the same time, the frequency trade-offs differ from access control; our LF vs HF vs UHF RFID frequency selection guide covers that decision separately so the two projects do not get conflated.

Frequently Asked Questions
Can you supply cards that work with our existing readers?
In most cases yes, provided we can identify the credential technology. The fastest route is to post us two or three working sample cards. We read the chip type, UID structure, and encoded format directly, then confirm in writing what we can match before you commit to an order.
What is the minimum order quantity for encoded employee ID cards?
MOQ depends on the chip and the personalisation involved rather than on the card body. Plain pre-encoded cards run at far lower volumes than fully personalised badges with custom holographic overlays, because overlay origination carries a one-off tooling step. Ask for MOQ and unit price at two or three volume breaks so you can see where the curve flattens.
Should the factory pre-encode our cards, or should we encode in-house?
Pre-encoding removes work from your issuance desk and guarantees clean sequential numbering. In-house encoding keeps your AES keys inside your own security boundary, which some policies require. Many organisations split the difference: the factory delivers cards with a known transport key, and the security team writes the operational keys at issuance.
How long should employee ID cards last?
Plan around your own usage rather than a marketing figure. Standard PVC typically gives one to three years of daily carry, composite three to five, and polycarbonate longer still. ISO/IEC 24789-1 exists precisely so that service life can be predicted from expected years and daily uses instead of estimated — ask your supplier which application profile they tested against.
Are dual-technology cards a security risk?
During a planned migration they are a sensible compromise. They become a risk when the migration has no end date, because the legacy interface stays clonable indefinitely. Treat dual-technology as a time-boxed transitional credential with a documented sunset date.
Our readers accept modern cards already. Do we still need to change anything?
Possibly. Confirm whether the reader performs mutual authentication or is simply reading the card serial number. CSN-only configurations are common, and they discard the cryptographic protection of the chip you paid for. This is a configuration question for your integrator, not a card question.
Your Next Step: Send a Sample Card, Not a Guess
Compatibility problems are cheap to prevent and expensive to discover after delivery. The single most useful thing you can do before ordering employee ID cards is to put two or three of your current badges in an envelope and let a manufacturer read them.
GENUINE has produced secure cards, RFID credentials, and holographic security features since 2005. Send us your current badge and your reader model, and we will confirm the matching chip, recommend a card body suited to your service life, and quote at two or three volume breaks so the cost curve is visible before you commit. If you prefer to start from the product side, our RFID smart card range lists the common chip and body combinations.
Request a compatibility check and a sample pack via our contact page — include your reader model and approximate annual volume, and we will come back with a specification sheet you can circulate internally.




