125kHz vs 13.56MHz: Cost of Access Control Credentials

Jan 08, 2026

Leave a message

Ruby Chen
Ruby Chen
A product expert specializing in RFID solutions. Ruby focuses on customer service, matching suitable hardware to clients across various industries seeking RFID solutions, and has over 10 years of sales experience.

125kHz vs 13.56MHz: Cost of Access Control Credentials

 

Quick answer: 125kHz access control credentials are usually cheaper, easier to source, and highly compatible with legacy proximity readers, but many common LF chips only transmit a fixed ID. 13.56MHz credentials cost more when they use secure chips such as MIFARE Plus SL3 or DESFire EV2/EV3, but they can support memory, encrypted authentication, and stronger access control design. The real decision is not only 125kHz vs 13.56MHz; it is chip type, reader configuration, encoding method, and total ownership cost.

 

Fifteen seconds to clone a 125kHz keyfob. ICT's security team tested this in 2023 with a $30 Amazon device-unboxing to working duplicate, fifteen seconds. Their ICT card technology security comparison is worth reading if you want the methodology and the broader migration context.

 

We get asked about frequency selection constantly at Syntek. Procurement managers want a simple answer, and there isn't one. Frequency determines physics. Chip selection determines security. Manufacturing quality determines whether credentials last five years or fail after six months. These are separate decisions.

 

The Right Frequency For RFID Keyfobs

 

125kHz vs 13.56MHz access credentials: the practical difference

 

Decision Point 125kHz LF Credential 13.56MHz HF Credential
Typical access chips EM4100, TK4100, T5577, HID Prox-compatible formats MIFARE Classic, MIFARE Plus, DESFire EV2, DESFire EV3, NTAG for NFC use cases
Main advantage Low unit cost, stable read behavior, broad legacy compatibility More memory, two-way communication, stronger authentication options
Main risk Many fixed-ID chips have no encryption or challenge-response Security depends on chip family and reader setup; CSN-only reading is weak
Best fit Low-risk doors, pools, gyms, legacy maintenance, temporary credentials Corporate access, hotel systems, multi-application cards, higher-security zones
Buying mistake to avoid Using fixed-ID proximity credentials as the only control for sensitive entrances Buying secure chips but configuring readers to authenticate only the card serial number

 

For a deeper frequency selection guide across RFID keyfob projects, see our article on choosing the right frequency for RFID keyfobs. For a neutral technical overview of proximity, MIFARE, and DESFire card differences, the Proximity, MIFARE and DESFire technical explanation is also useful.

 

At 125kHz, electromagnetic waves couple inductively between the keyfob antenna and reader. Stable coupling. Water doesn't attenuate significantly. Metal surfaces don't create the interference patterns you see at higher frequencies-which is why early access control standardized on LF technology.

EM4100 and TK4100 chips broadcast a 64-bit identifier in the clear. No encryption, no challenge-response, no authentication. The reader asks "who are you?" and the chip answers with its ID, every time, to anyone asking. Clone devices record that answer and replay it.

We still sell EM4100 keyfobs. Lots of them. Pool access, internal zone separation, temporary contractor credentials. There are legitimate use cases where the security limitation is acceptable and the cost advantage matters-$0.15-0.30 per unit at volume versus $2.50+ for secure HF chips. If your project needs durable housings, logo printing, serial numbers, and multiple LF/HF chip options, start with custom ABS RFID keyfobs for access control.

 

We won't recommend them for primary building entry. The liability exposure isn't worth the savings.

 

Moving to 13.56MHz doesn't automatically solve security problems.

 

13.56MHz is a frequency band, not a security grade. MIFARE Classic, MIFARE Plus in Security Level 3, and DESFire EV2/EV3 all sit in the HF world, but they behave very differently in a door system. A low-cost 13.56MHz credential used only by UID or CSN is not comparable to a DESFire application using diversified keys and encrypted mutual authentication.

 

MIFARE Classic was the industry standard for years. ISO14443A compliant, 1KB or 4KB memory, widely supported. The Crypto1 encryption looked adequate. Researchers at Radboud University broke it in 2008-fundamental cryptographic weakness, no firmware fix possible. An Android phone with MIFARE Classic Tool can clone these credentials now.

 

We ship Classic-compatible keyfobs for legacy maintenance. If your building has 50 readers running MIFARE Classic and no upgrade budget, buying new Classic keyfobs makes sense. Replacing them with DESFire won't help if readers can't perform encrypted authentication anyway.

New deployments? Classic is a non-starter. The March 2024 Unsaflok disclosure-3 million hotel locks across 13,000 properties-should have ended that debate.

The secure HF options: MIFARE Plus in SL3 mode with AES enabled, DESFire EV2, DESFire EV3. All implement AES-128. DESFire EV2 and EV3 carry EAL5+ certification for compliance-sensitive deployments. NXP's MIFARE DESFire EV3 product data sheet also documents ISO/IEC 14443A compliance, hardware cryptographic support, flexible application management, and Common Criteria EAL5+ certification.

 

A DESFire keyfob on an improperly configured system provides no more security than EM4100. The Flipper Zero team documented this in their 2023 RFID protocol analysis: many access control systems authenticate using only the Card Serial Number, even with DESFire readers installed. CSN is unencrypted, readable by any NFC device. A $4 DESFire keyfob authenticating via CSN operates at $0.20 LF security levels.

 

We ask clients to confirm reader configuration before quoting. "Does your system authenticate using encrypted sector data, or just CSN?" If they don't know, we tell them to find out before spending money on premium credentials. Our guide to RFID data security for access credentials explains why fixed IDs, replayable responses, default keys, and weak backend validation can undermine an otherwise expensive credential.

Reader compatibility checklist before ordering DESFire or MIFARE Plus:

1. Does the reader support 13.56MHz ISO14443A, or only 125kHz LF?

2. Does the controller accept encrypted application data, or only Wiegand output from a card number?

3. Are keys diversified per site, per card, or shared as a default key?

4. Can your integrator encode credentials before deployment, or do you need supplier pre-encoding?

5. Can old lost credentials be revoked cleanly in the access software?

If your existing hardware cannot support the authentication method you plan to buy, the credential upgrade will fail at the door. In that case, review the RFID access control reader configuration before approving bulk production.

 

The cost structure of RFID credentials is violently non-linear with volume.

 

Unit price is only one part of access credential cost. The real budget includes chip grade, shell material, printing, UID or sector encoding, sample testing, data matching, packaging, defect handling, and future reissue volume. A buyer comparing only "125kHz price" and "13.56MHz price" may choose the cheapest item and still pay more later through failed reads, re-encoding work, reader replacement, or support tickets.

 

Chip Type 100 units 1,000 units 5,000+ units
EM4100/TK4100 (125kHz) $0.80-1.50 $0.25-0.40 $0.15-0.25
T5577 rewritable (125kHz) $1.20-2.00 $0.45-0.70 $0.30-0.50
MIFARE Classic 1K (13.56MHz) $1.00-2.00 $0.40-0.80 $0.30-0.60
DESFire EV2 (13.56MHz) $4.00-6.00 $2.50-3.50 $2.00-3.00
DESFire EV3 (13.56MHz) $5.00-8.00 $3.00-4.50 $2.50-3.50

 

A property manager ordering 200 keyfobs pays roughly 3x more per unit than one ordering 2,000. Multi-site operators aggregate procurement across properties. Organizations with predictable replacement cycles order annual volumes upfront.

 

T5577 occupies a unique position. Unlike fixed-UID chips, it's field-programmable with 330 bits of configurable memory-can emulate EM4100, HID Prox, Indala, several other protocols. Facilities managing legacy systems from multiple vendors, integrators needing on-site reconfiguration: T5577 provides flexibility that justifies the modest premium over EM4100. The 32-bit password protection isn't strong by modern standards, but it stops casual cloning.

 

Hidden costs buyers often miss

 

Cost Item Why It Matters How To Control It
Encoding and numbering Wrong facility code, wrong bit format, or wrong sector data can make cards readable but unusable. Confirm Wiegand format, card number range, site code, and encoding file before production.
Sample testing Reader models, door controllers, and software versions may behave differently with the same chip. Test 5-10 samples on real doors before bulk order approval.
Reader replacement Secure HF credentials may require new readers if old hardware only supports LF fixed IDs. Audit installed readers before deciding between single-frequency, dual-frequency, or multi-technology migration.
Failure rate A cheap batch with weak antenna tuning or poor housing can create more support cost than the saving. Ask for antenna testing, material specs, and environmental reliability records.
Future reissue Every lost card, new tenant, new employee, or contractor badge repeats the credential cost. Use annual volume planning and avoid permanent dual-frequency premiums unless needed.

 

Manufacturing quality is where cheap keyfobs fail.

125kHz key fob antenna

The antenna inside a 125kHz keyfob: copper wire wound around a ferrite core. Ferrite dramatically improves magnetic coupling-ResearchGate literature shows ferrite-core coils achieving approximately 125x the coupling efficiency of equivalent air-core designs.

The quality of that ferrite, winding precision, tuning capacitor consistency-these determine whether the keyfob reads reliably across different reader models.

 

At 13.56MHz, the antenna is typically etched copper on PCB substrate. Tighter manufacturing tolerances, but resonant frequency is more sensitive to environmental factors. Mount an HF keyfob against a metal keychain, the antenna detunes, read range drops 30-50%. Quality manufacturers compensate in antenna design and verify with VNA testing during production.

 

We've seen batches from low-cost suppliers with defect rates above 8%. At $0.10 less per unit, that's not savings-it's support cost transferred to the client.

 

The enclosure matters. ABS plastic is industry standard: impact resistance, chemical stability, RF transparency. Cheaper PP compounds crack in cold weather. We had clients in northern Europe discover this when December temperatures triggered warranty claims across their portfolio.

 

For outdoor installations: IP65 handles rain and dust, IP68 is rated for submersion. The cost difference is $0.15-0.25 per unit. Skipping that upgrade and replacing water-damaged credentials costs more.

 

When does upgrading from 125kHz to 13.56MHz pay off?

 

The business case for upgrading from legacy LF to secure HF depends heavily on context. The strongest case appears when credentials protect high-value areas, when audit trails matter, when cloned credentials would create legal exposure, or when the same card is expected to support multiple applications such as building access, parking, elevators, lockers, vending, or membership value.

 

These projects can fail too. We've seen upgrades that cost more than projected, took longer than planned, required reader replacements outside original scope. ROI depends on specific situation: existing infrastructure, threat environment, replacement rate, project management quality.

 

The cost differential between secure and insecure credentials has narrowed substantially. DESFire EV2 that cost $8-10 each in 2019 is now $2.50-3.50 at volume.

 

Dual-frequency keyfobs embed both 125kHz and 13.56MHz antennas. We manufacture them. We discourage clients from specifying them unless there's a clear transition plan.

 

Two antennas in close proximity couple with each other, detuning both. Physical separation requirements add bulk. Each antenna must be independently optimized, compromises in one affect the other. Manufacturing complexity increases defect rates. The 40-60% premium over single-frequency often delivers compromised performance on both frequencies.

Where dual-frequency makes sense:

Planned LF-to-HF migrations taking 12-24 months where credentials need to work on both systems during changeover.

Where it doesn't:

Permanent deployments paying the premium indefinitely for capability never used.

For multi-tenant buildings with different systems on different floors, separate credentials are usually more practical. Less elegant, works better, costs less over time.

 

A cleaner LF-to-HF migration plan is usually phased by risk. Upgrade server rooms, finance offices, warehouses, and main entrances first. Keep low-risk doors on legacy proximity until reader replacement is scheduled. During the transition, issue dual-technology credentials only to users who actually need both systems. Once the last LF reader is retired, stop buying dual-frequency credentials and move to a single secure HF credential.

 

Specification details that matter, based on deployment failures we've seen:

 

Frequency and protocol compatibility.

Verify existing readers support the chip you're ordering. "13.56MHz" isn't enough-specify ISO14443A, ISO15693, or proprietary protocols. Get samples, test on actual infrastructure before production orders.

Wiegand format.

Access control panels expect specific formats-26-bit, 34-bit, 37-bit. Wrong format means the keyfob reads but doesn't authenticate. Confirm with your integrator.

Memory and encoding.

DESFire comes in 2KB, 4KB, 8KB variants. Single-application access control: 2KB sufficient. Multi-application deployments combining building access with parking, elevators, vending: may require larger memory. Pre-encoding adds cost but eliminates field programming. Blank credentials require on-site capability.

Environmental specifications.

Operating temperature standard is -20°C to +60°C; high-temp variants exist for laundry and autoclave. IP rating appropriate to installation environment. ABS housing, avoid cheaper alternatives.

Quality documentation.

ISO/IEC 10373-6 compliance testing, Q-factor measurements, environmental test reports. Supplier can't produce documentation? Reconsider the supplier.

 

For new deployments where security matters: DESFire EV2 at 13.56MHz. EV3 adds marginal improvements at premium pricing-hard to justify outside government or high-value asset protection. Confirm encrypted sector authentication, not CSN-only. Budget $2.50-4.00 per keyfob at volume.

 

For legacy LF maintenance where upgrade isn't feasible: EM4100 or TK4100 for reliable compatibility at minimal cost. Accept the security limitation consciously. Need on-site reprogramming? Pay the modest premium for T5577.

 

For transitions: multi-technology readers rather than dual-frequency keyfobs. Reader premium is one-time; keyfob premium recurs with every credential issued.

 

Don't over-specify. We've quoted projects requesting DESFire EV3 with 8KB memory for gym membership systems-$4+ per keyfob for capabilities they'll never use. DESFire EV2 with 2KB at $2.50 delivers identical functionality for that application.

 

Don't under-specify either. Primary building entrance with EM4100 credentials is a security decision, whether consciously made or not. If someone clones a keyfob and gains access, the question "why were we using technology that's trivially cloned?" will come up.

 

Frequency selection isn't complicated once you separate the decisions: physics from security from manufacturing quality. Most confusion comes from marketing that conflates them, or procurement focused on unit cost without considering total ownership cost. If your team is still comparing IC and ID credentials at a basic level, this guide to IC card vs ID card selection for access control can help standardize the terminology before purchasing.

 

FAQ: 125kHz vs 13.56MHz access control credentials

Q: Is 13.56MHz Always More Secure Than 125kHz?

A: No. 13.56MHz can be much more secure when the system uses encrypted authentication with chips such as MIFARE Plus SL3 or DESFire EV2/EV3. But if the reader only checks an unencrypted card serial number, the system can still behave like a low-security ID token.

Q: Can I Replace 125kHz Keyfobs With DESFire Keyfobs Without Changing Readers?

A: Usually no. If existing readers only support 125kHz proximity IDs, they cannot read or authenticate DESFire credentials. You need 13.56MHz ISO14443A-capable readers and access software that can handle the required encrypted data.

Q: Why Are DESFire Credentials More Expensive?

A: DESFire credentials use more capable chips, support secure memory structures, and often require proper key management or pre-encoding. The higher price pays for security capability, but the system must be configured correctly for that capability to matter.

Q: When Is 125kHz Still Acceptable?

A: 125kHz can still be acceptable for low-risk doors, simple membership identification, legacy maintenance, temporary contractors, or internal areas where cloning risk does not create serious exposure. It should not be the only credential protecting sensitive entrances.

Q: Should I Choose Dual-Frequency Keyfobs?

A: Choose dual-frequency keyfobs only when users must access both old LF readers and new HF readers during a defined migration period. For permanent deployment, dual-frequency credentials usually add recurring cost and may compromise antenna performance.

 

Working through a deployment decision? We'd rather help you specify correctly upfront than debug a mismatched system later.

 

Pricing reflects January 2025 wholesale rates, varies by volume and encoding requirements. For project quotations, contact sales with volume requirements and infrastructure details.

Send Inquiry