A card read is only one part of the decision
A contactless device detecting a card identifier is not the same as authenticating a PIV credential through the required mechanism. The agency’s policy and approved physical access control system determine how identity is verified and whether entry is permitted.
NIST FIPS 201-3 defines requirements for the PIV identity system. NIST SP 800-116 Rev. 1 addresses risk-based selection of PIV authentication mechanisms for facility access. Neither should be reduced to a claim that every door needs the same reader or that ordinary lock hardware is “FIPS certified.”
Draw the responsibility boundary
The reader obtains credential information. The approved validation and control system makes the access decision. The lock or release hardware operates the physical opening. Door-position and other monitoring devices report their particular states. Each role needs a defined interface and an owner responsible for configuration and support.
Before ordering, record the reader, controller, software, validation service, firmware requirements, and door hardware. Mobile-credential or proximity-card support is not proof of PIV or CAC compatibility. Likewise, an escort is a procedural control, not an additional electronic authentication factor.
Verify a configuration, not a brand
The GSA Approved Products List includes product and topology information. Check the exact configuration and agency requirements with the PACS integrator. Do not assume that all equipment from a listed manufacturer shares the same approval.
At the opening, inspect the frame, latch, closer, power transfer, available supply, and any label restrictions. A compatible reader does not resolve a door that binds or make an unsuitable electrified strike acceptable for the assembly.
Decide what happens during a fault
Loss of network connectivity, credential-validation availability, controller communication, and lock power are separate events. The agency should approve the response to each. Do not silently fall back to accepting a card number without the required validation.
“Fail-safe” and “fail-secure” describe particular locking-hardware behaviour on power loss; they do not independently establish compliance of the complete exit arrangement. The project team must assess required egress and the approved security operation together.
Test the design that was approved
Write acceptance criteria for authorized and denied access, revoked credentials, door-state monitoring, recovery after a fault, and required exit operation. Identify authorized test accounts and witnesses, and document responsibility for any access-right changes. Avoid using live credential details in general correspondence.
For the physical opening scope, review PIV reader and door integration. Contractor eligibility, specialist system work, and agency acceptance remain project-specific decisions.
