Planning guide

Access Control Wiring and Standards Reference: Wiegand vs OSDP

A technical reference covering reader-to-controller protocols (legacy Wiegand vs OSDP/SIA OSDP over RS-485 with AES-128 Secure Channel), door hardware (electric strike vs maglock, fail-safe vs fail-secure, REX, door position sensor), and composite access-control cabling with real distances, voltages, AWG resistance, and voltage-drop math.

5.0· 14 Google reviews

Updated 2026-07-24

EVOTECH technicians installing indoor and outdoor security cameras, with a monitoring wall and branded service van.
Illustrative brand image — security-camera and surveillance work.

The short answer

Wiegand and OSDP are the two ways a card reader talks to an access-control panel, and OSDP is the modern replacement. Wiegand is a one-way electrical signaling scheme from the 1980s: the reader pushes bits to the controller over two data lines, D0 and D1, plus a common ground. A pulse on D0 is a binary 0, a pulse on D1 is a binary 1, with pulse widths of roughly 20-100 microseconds and gaps of 200 microseconds to 20 milliseconds. It is unencrypted, unsupervised, point-to-point (one reader per home-run cable), and manufacturers publish a practical limit near 500 feet. The classic 26-bit format carries an 8-bit facility code and 16-bit card number wrapped in two parity bits, and those bits travel in the clear, which is why Wiegand can be sniffed or replayed with cheap hardware.

OSDP (Open Supervised Device Protocol), standardized as SIA OSDP and published internationally as IEC 60839-11-5:2020, runs over an RS-485 (TIA-485) serial bus. It is bidirectional and multi-drop: one panel polls many peripheral devices on a two-wire differential pair (A/B) plus ground, at distances up to about 4,000 feet (1,200 m). Its Secure Channel profile adds AES-128 encryption and mutual authentication, and the line is continuously supervised, so a cut wire or a swapped reader is detected. For any new install, or any run over 500 feet, OSDP with Secure Channel is the protocol to specify; Wiegand remains only for legacy panels that cannot accept RS-485. The door hardware side, electric strike versus maglock, fail-safe versus fail-secure, REX, and door-position monitoring, is independent of the reader protocol and is governed by life-safety codes.

Wiegand vs OSDP: choosing the reader protocol

The first decision at any door is how the reader reports credentials to the controller. Two schemes dominate. Wiegand is a one-way electrical signaling method: the reader transmits, the panel listens, and there is no return path, no encryption, and no supervision. OSDP is a full serial protocol over RS-485 that is bidirectional, supervised, and, in its Secure Channel profile, encrypted with AES-128. For a greenfield installation the choice is straightforward: specify OSDP readers and OSDP-capable controller inputs. The main reason to still see Wiegand is an existing panel whose reader ports are Wiegand-only, or a short retrofit where replacing the head-end is not yet budgeted.

Distance is often the deciding factor. Wiegand's usable reach is bounded near 500 feet because the unbuffered pulse train degrades over long copper. OSDP inherits RS-485's differential signaling and reaches roughly 4,000 feet (1,200 m) on a properly terminated bus, and one bus can multi-drop many readers instead of one home run per door. Security is the other driver: Wiegand card data travels in the clear and is trivially captured or replayed, while OSDP Secure Channel authenticates the reader and encrypts the link, defeating the common 'wire-tap the reader' attack.

  • Choose OSDP (SIA OSDP / IEC 60839-11-5) for any new install, any run over 500 ft, or wherever credential interception is a concern; it is bidirectional, supervised, and supports AES-128 Secure Channel.
  • Choose Wiegand only when the existing controller accepts Wiegand inputs exclusively and a head-end upgrade is out of scope; treat it as legacy.
  • Distance: Wiegand practical maximum around 500 ft; OSDP over RS-485 up to about 4,000 ft (1,200 m).
  • Topology: Wiegand is point-to-point (one reader per cable to the panel); OSDP is multi-drop (many peripheral devices on one two-wire bus).
  • Security: Wiegand is unencrypted and unauthenticated; OSDP Secure Channel adds AES-128 encryption plus mutual authentication and continuous line supervision.
  • Door-lock hardware selection (strike vs maglock, fail-safe vs fail-secure) is independent of this protocol choice and driven by life-safety code, not by the reader.

Reader-to-controller signaling: Wiegand and OSDP in detail

Wiegand uses three conductors for data: D0, D1, and a signal ground. Both data lines idle high (near the reader's supply voltage, commonly 5 V logic). To send a 0 the reader briefly pulls D0 low; to send a 1 it pulls D1 low. Published timing puts each pulse at roughly 20-100 microseconds with an inter-pulse interval of 200 microseconds to 20 milliseconds. The standard 26-bit frame is a leading even-parity bit, an 8-bit facility code, a 16-bit card number, and a trailing odd-parity bit, 26 bits total. There is no acknowledgment, no tamper reporting, and no encryption, so anything on those two wires can read or inject card data.

OSDP replaces that with a packetized master/peripheral protocol on RS-485. The panel (control panel, CP) polls each reader (peripheral device, PD) in turn over a differential A/B pair plus ground. Common baud rates are 9600, 19200, 38400, 57600, and 115200 bps, with the spec reaching 230400. Because it is a real bus, the panel knows instantly if a reader stops answering (supervision), can push LED, buzzer, and text back to the reader, and, with Secure Channel enabled, wraps every packet in AES-128 encryption keyed by a per-device secure channel base key.

  • Wiegand data wiring: D0, D1, and signal ground; lines idle high, pulsed low to signal bits; typical pulse 20-100 us, interval 200 us-20 ms.
  • Wiegand 26-bit standard format: 1 leading even-parity bit + 8-bit facility code + 16-bit card number + 1 trailing odd-parity bit = 26 bits, transmitted unencrypted.
  • OSDP physical layer: RS-485 (TIA-485) two-wire differential (A/B) plus ground; multi-drop bus rather than a home run per reader.
  • OSDP baud rates: 9600, 19200, 38400, 57600, 115200 bps (spec supports up to 230400 bps); half-duplex polled master/peripheral messaging.
  • OSDP Secure Channel: AES-128 encryption with mutual authentication; standardized as SIA OSDP v2.2 and IEC 60839-11-5:2020, with a SIA OSDP Verified interoperability program.
  • Supervision: OSDP continuously monitors device presence and reports offline/tamper conditions; Wiegand offers no return channel and cannot report a cut wire or a substituted reader.

Locking hardware: electric strike vs maglock, fail-safe vs fail-secure

The locking device is chosen separately from the reader. An electric strike replaces the fixed strike plate in the door frame; when energized (or de-energized, depending on model) it pivots to release the latch so the door can push open, while the door's own lever or panic hardware still allows mechanical exit. A magnetic lock (maglock) is an electromagnet on the frame that bonds to an armature plate on the door; common holding forces are 600 lbf and 1,200 lbf. A maglock has no mechanical latch, so it is always fail-safe by physics: cut the power and it releases. Both types commonly run on 12 V or 24 V DC.

Fail-safe versus fail-secure describes the state on power loss. Fail-safe means unlocked when de-energized, the correct behavior where a locked door would trap occupants, and the only behavior a maglock can have. Fail-secure means locked when de-energized, common on electric strikes for stairwell and exterior doors where mechanical egress from the inside still works. Because a maglock removes all mechanical egress, life-safety codes such as NFPA 101 and the IBC require independent release paths, for example a listed request-to-exit device and a hardwired egress button that drops power directly, plus fire-alarm release. Matching lock behavior to egress requirements is a code decision, not a preference.

  • Electric strike: mounts in the frame, releases the latch; available in fail-safe or fail-secure models; mechanical egress via the lever/panic hardware is always preserved.
  • Maglock: electromagnet plus armature; typical holding force 600 lbf or 1,200 lbf; inherently fail-safe (releases on power loss) because it has no mechanical latch.
  • Fail-safe = unlocked on power loss (all maglocks, some strikes); use where a trapped occupant is the hazard.
  • Fail-secure = locked on power loss (many strikes); use on stairwell/exterior doors where inside egress remains mechanical.
  • Operating voltage: 12 V or 24 V DC is standard for both strikes and maglocks; confirm the exact current draw from the device datasheet before sizing power and wire.
  • Maglocks require code-mandated egress: NFPA 101 / IBC generally call for a listed REX device plus a fail-safe egress button (and fire-alarm release) that removes power independent of the controller.

Request-to-exit and door monitoring

A controlled door needs to know two more things beyond 'valid card presented': that someone is legitimately leaving, and whether the door is actually open or closed. Request-to-exit (REX) covers egress. A REX device is either a passive-infrared motion sensor mounted over the inside of the door or a monitored switch inside the exit lever or panic bar. When it triggers, it tells the controller the exit is authorized, so the panel shunts (temporarily ignores) the door-position input and no forced-door alarm is generated as the person leaves. On a maglock, a REX often also drops lock power directly as one of the required egress paths.

Door position is monitored by a door position sensor (DPS), almost always a magnetic reed switch: a magnet on the door and a switch on the frame that closes when the door is shut. The controller uses the DPS for two alarms. A forced-door (door-forced-open) alarm fires when the DPS shows open without a valid unlock or REX. A door-held-open alarm fires when the door stays open past a set shunt time, commonly 30 seconds, after a valid access. Together, REX plus DPS turn a simple electric lock into a supervised, auditable opening.

  • REX (request-to-exit): a PIR motion sensor over the door or a switch in the exit device; signals the controller to authorize egress and shunt the door contact so leaving does not raise an alarm.
  • On maglocks, the REX and a separate egress button frequently cut lock power directly to satisfy free-egress code requirements.
  • DPS (door position sensor): a magnetic reed switch, magnet on the door leaf and contact on the frame, reporting open/closed state to the panel.
  • Forced-door alarm: DPS reads open with no valid credential or REX event; indicates the door was pried or pushed.
  • Door-held-open alarm: DPS stays open beyond the programmed shunt/relock timer (commonly around 30 seconds after a granted access).
  • A fully monitored opening therefore uses four low-voltage circuits at the door: reader data, lock power, REX, and DPS.

Composite access-control cable, AWG, and voltage-drop math

Because a monitored door needs four circuits, installers usually pull one composite access-control cable, a single jacket bundling several gauges. A typical composite carries an 18 AWG twisted pair for lock power (the highest-current run), a 22 AWG twisted pair (often shielded) for reader data, and one or two 22 AWG pairs for REX and DPS. For OSDP the reader pair should be shielded twisted pair to preserve the RS-485 differential signal; for Wiegand, keep the data run under 500 feet. The lock conductors get the heavier 18 AWG specifically to limit voltage drop, because a lock that browns out below its rated voltage may chatter or fail to release.

Voltage drop follows Ohm's law, V = I x R, over the round-trip conductor length. Solid copper resistance at room temperature is about 6.385 ohms per 1,000 ft for 18 AWG and 16.14 ohms per 1,000 ft for 22 AWG. Example: a 500 mA maglock 250 ft away sees 500 ft of conductor round-trip. On 18 AWG that is 0.500 A x 3.19 ohms = about 1.6 V drop, leaving ~22.4 V of a 24 V supply, acceptable. The same run on 22 AWG is 0.500 A x 8.07 ohms = about 4.0 V drop, and on a 12 V lock that 4 V loss is often enough to cause failure, which is exactly why lock power uses 18 AWG and, where possible, 24 V.

  • Composite access-control cable typically bundles: 18 AWG pair (lock power) + 22 AWG shielded pair (reader/OSDP data) + 22 AWG pair(s) for REX and DPS, under one jacket.
  • Use shielded twisted pair for the OSDP RS-485 run; ground the shield at one end only to avoid ground loops.
  • Copper resistance (solid, ~20 C / 68 F): 18 AWG about 6.385 ohms/1,000 ft; 20 AWG about 10.15; 22 AWG about 16.14; 24 AWG about 25.67 ohms/1,000 ft.
  • Voltage drop uses round-trip length: V_drop = I x R, where R = (2 x one-way feet / 1,000) x ohms-per-1,000-ft.
  • Worked example: 0.5 A maglock at 250 ft on 18 AWG drops about 1.6 V (fine on 24 V); on 22 AWG it drops about 4.0 V (risky on 12 V).
  • Prefer 24 V over 12 V on long lock runs: for the same wattage the current halves, and voltage drop scales with current, so 24 V tolerates far longer cable.

Standards, structured-cabling practice, and when a pro install helps

Access-control low-voltage work sits alongside the same structured-cabling discipline used for networks. Reader and door cabling should be installed to recognized practices, ANSI/TIA-568 governs the balanced twisted-pair and topology conventions many installers follow for data runs, and where readers connect to IP door controllers, standard Ethernet rules apply (100 m / 328 ft channel limit for copper, VLAN segmentation per IEEE 802.1Q to isolate the access-control network). The protocol and life-safety references are the load-bearing ones: SIA OSDP and IEC 60839-11-5 for the reader link, and NFPA 101 and the IBC for egress on any electrified locking hardware.

Much of this is approachable for a capable DIYer or in-house facilities team: pulling composite cable, terminating an electric strike, and mounting a reader are mechanical tasks. The parts that reward professional involvement are the ones with code and safety exposure, maglock egress schemes that must satisfy NFPA 101 and local fire-marshal review, fail-safe versus fail-secure decisions on egress-critical doors, fire-alarm interface for lock release, and OSDP Secure Channel key management across many doors. If a mistake could trap an occupant, fail an inspection, or leave credential data interceptable, that is the point where a professional design-and-install pass earns its cost.

  • Reader/OSDP link standards: SIA OSDP v2.2 and IEC 60839-11-5:2020; look for SIA OSDP Verified devices for interoperability.
  • Structured cabling: ANSI/TIA-568 for balanced twisted-pair practice; for IP door controllers, the 100 m (328 ft) Ethernet channel limit and IEEE 802.1Q VLAN segmentation apply.
  • Life-safety codes: NFPA 101 (Life Safety Code) and the IBC govern egress, especially any door where a maglock removes mechanical exit.
  • DIY-friendly tasks: pulling composite cable, mounting readers, wiring a fail-secure electric strike on a non-egress-critical door.
  • Bring in a professional for: maglock egress design and fire-marshal review, fire-alarm lock release, fail-safe/fail-secure calls on egress doors, and OSDP Secure Channel key rollout at scale.
  • A professional install most clearly helps where an error creates a code violation, a trapped-occupant hazard, or an interceptable credential path.

Frequently asked questions

Is OSDP always better than Wiegand for access control?

For new installations, OSDP is the stronger choice in nearly every case: it is bidirectional, continuously supervised, supports AES-128 Secure Channel encryption, multi-drops many readers on one RS-485 bus, and reaches about 4,000 ft versus Wiegand's roughly 500 ft. The main reason to keep Wiegand is an existing controller that only accepts Wiegand inputs, or a short legacy run where replacing the panel is not yet in scope. Wiegand still works electrically; it simply offers no encryption, no line supervision, and no return channel, so its card data can be intercepted or replayed.

What is the difference between fail-safe and fail-secure locks?

The terms describe what happens when power is lost. Fail-safe means the door unlocks on power loss, the required behavior where a locked door could trap occupants, and the only behavior a magnetic lock can have because it holds solely by electromagnet. Fail-secure means the door stays locked on power loss, common on electric strikes for stairwell and exterior doors where a lever or panic bar still allows mechanical exit from the inside. Because maglocks remove mechanical egress, codes such as NFPA 101 and the IBC require independent release paths (a listed REX plus a fail-safe egress button and fire-alarm release).

What cable and gauge do I need for an access-controlled door?

A monitored door has four low-voltage circuits: reader data, lock power, request-to-exit (REX), and door position sensor (DPS). Installers commonly pull one composite access-control cable that bundles an 18 AWG pair for lock power, a 22 AWG shielded pair for reader/OSDP data, and 22 AWG pairs for REX and DPS. Lock power uses the heavier 18 AWG to limit voltage drop; at about 6.385 ohms per 1,000 ft it drops roughly 1.6 V on a 500 mA lock at 250 ft, versus about 4.0 V on 22 AWG, which can cause a 12 V lock to fail. Use shielded twisted pair for OSDP runs.

How far can access-control reader cable run?

It depends on the protocol. Wiegand is practically limited to about 500 ft because its unbuffered pulse train degrades over long copper, and each reader needs its own home-run cable. OSDP runs over RS-485 and reaches roughly 4,000 ft (1,200 m) on a properly terminated, shielded bus, and a single bus can multi-drop multiple readers. Separately, IP door controllers connected over Ethernet follow the standard 100 m (328 ft) copper channel limit. Lock power distance is governed by voltage drop rather than the data protocol, so heavier gauge and 24 V supplies extend usable lock runs.

Our work

Clean installs across the Houston area

See all our work
Fiber network rack with single-mode cabling by Evotech IT, HoustonFiber distribution enclosure and splicing by Evotech IT LLC, Houston TXProfessional fiber optic installation by Evotech IT serving HoustonFiber optic cabling and patch panel installation by Evotech IT LLC, Houston TX
Call WhatsApp