Latest
Subscribe
Advertisement

Standards & regulations

The protocols, certifications and laws that govern physical access control — what each one actually requires, and who it binds.

CCPA / CPRA (CCPA)

California Attorney General

California's consumer privacy law (as amended by the CPRA), which treats biometric information as sensitive personal information subject to disclosure, deletion and limitation rights.

FICAM (FICAM)

US General Services Administration

The US government's Federal Identity, Credential, and Access Management framework, whose approved-products process governs which PACS components may be used in federal buildings.

FIPS 201 (FIPS 201)

NIST (National Institute of Standards and Technology)

The US federal standard for Personal Identity Verification (PIV) credentials, defining the interoperable smartcard identity used across federal facilities and systems.

GDPR (biometric data) (GDPR Art. 9)

European Union

Under the EU GDPR, biometric data used to identify a person is a special category requiring an explicit legal basis — a high bar for face or fingerprint access in Europe.

HSPD-12 (HSPD-12)

US Department of Homeland Security

The 2004 presidential directive mandating a common, interoperable identity credential for federal employees and contractors — the policy that produced FIPS 201 and the PIV card.

Illinois Biometric Information Privacy Act (BIPA)

Illinois General Assembly

The Illinois statute governing collection and storage of biometric identifiers. It requires informed written consent and provides a private right of action — the most litigated biometric-privacy law in the US.

ISO/IEC 27001 (ISO 27001)

ISO / IEC

The international standard for an information security management system (ISMS). Certification signals a systematic, audited approach to securing data — including a cloud vendor's customer data.

NDAA Section 889 (NDAA §889)

US Congress

A federal procurement ban prohibiting agencies from buying video surveillance and telecommunications equipment from named Chinese manufacturers — a key compliance filter for security hardware.

NIST SP 800-116 (SP 800-116)

NIST (National Institute of Standards and Technology)

NIST's guidance for using PIV credentials in physical access control systems, mapping authentication factors to facility security areas.

ONVIF (ONVIF)

ONVIF (Open Network Video Interface Forum)

An interoperability standard for IP-based physical security. ONVIF Profile A and Profile C cover access control — configuration and door control — so components from different vendors work together.

SOC 2 (SOC 2)

AICPA (American Institute of CPAs)

An independent audit report on a service provider's controls for security, availability, processing integrity, confidentiality and privacy — the baseline trust artefact for cloud access control vendors.

Texas CUBI (CUBI)

Texas Legislature

Texas's Capture or Use of Biometric Identifier law, requiring consent before capturing biometric data. Enforced by the state Attorney General rather than by private lawsuits.

UL 294 (UL 294)

UL Solutions

The US safety and performance standard for access control system units — the certification buyers look for on controllers, readers and power supplies.

UL 60839 (UL 60839)

UL Solutions

The North American adoption of the international IEC 60839 series for alarm and electronic security systems, including access control, aligning US practice with global standards.