The access control planning process typically comprises a detailed requirements analysis, the creation of a target concept, manufacturer-neutral technology selection, detailed planning of the system architecture, a transparent tender and award process, professional project support, and final acceptance and documentation. The goal is a legally compliant, integrated, future-proof solution that ensures the protection of people, property and data.

From requirements analysis to legally compliant implementation: a guide for decision-makers

Planning an access control system is complex and requires in-depth expertise. This article examines the detailed process step by step, to ensure a secure, efficient and future-proof solution for your company and to avoid costly wrong decisions.

Key Takeaways

  • A detailed requirements analysis and a clear target concept are decisive for the success of an access control system, to capture all protection objectives and legal requirements.
  • Manufacturer neutrality and compliance with standards (e.g. DIN EN 60839-11-1, VdS guidelines) are essential in technology selection and detailed planning, to ensure flexibility and future viability.
  • Professional project support, seamless documentation and comprehensive training ensure smooth operation and ongoing legal compliance of the access control system.

In a world where protecting company assets (whether sensitive data, valuable property or employee safety) is a top priority, well-thought-out access control is essential. Implementing such a system, however, is far more than installing readers and locks. It requires a structured, methodical process that takes account of all technical, organisational and legal aspects. Professional planning is the cornerstone of a system that not only meets current requirements but is also future-proof and can respond flexibly to change. Poor planning, by contrast, can lead to significant security gaps, high follow-on costs, and legal risk.

Article image: Zutrittskontrolle Planung Ablauf - hero

1. Sound requirements analysis: the cornerstone of every plan

Every successful access control planning process begins with a comprehensive, detailed requirements analysis. In this phase, the aim is to develop a deep understanding of your company's specific security requirements, existing infrastructure and operational processes. It is crucial not only to identify the obvious protection objectives but also to precisely assess potential vulnerabilities and risks. This includes analysing which areas are particularly worth protecting, from server rooms to research laboratories to sensitive production areas or the executive level. Equally important is clarifying which groups of people (employees, visitors, service providers) should have access, when and where, and which identification media might be used (e.g. RFID transponders, biometrics, mobile solutions).

Another central point is consideration of the legal framework, in particular the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). The processing of personal data, which inevitably arises with access control systems, requires particular care and transparent documentation. Under Article 32 GDPR, appropriate technical and organisational measures must be taken to protect this data. An independent requirements analysis, as PLANATEL® has offered for over 34 years, ensures that all relevant aspects are objectively assessed and that the course is set for a tailored, legally compliant solution. This not only avoids later rework but also creates a solid basis for user acceptance of the system.

2. Creating the target concept and manufacturer-neutral technology selection

Building on the requirements analysis, a detailed target concept is developed in the next step. This concept defines the functional requirements for the future access control system and sets out the technical specifications. The identified protection objectives are translated here into concrete system functions. These include, for example, defining security zones, setting access criteria and times, and integration with other security systems such as fire alarm systems (BMA), intrusion detection systems (EMA) or video surveillance.

A critical aspect at this stage is manufacturer-neutral technology selection. The market for access control systems is diverse and dynamic, with a broad range of technologies such as RFID systems, biometric solutions (fingerprint, facial recognition), mobile access systems via smartphone, or classic PIN codes. According to ASSA ABLOY's 2025 Wireless Access Control Report, wireless systems have overtaken wired solutions for the first time, underlining the growing relevance of digital and mobile solutions. The choice of the right technology depends heavily on the specific requirements and risk profile. Independent consulting from PLANATEL® ensures that the selection is objective and free of manufacturer dependency. This protects your company from unnecessary investment and ensures the solution is optimally tailored to your needs and remains flexible in the long term. Avoiding manufacturer dependency is a central concern, particularly in countries such as Germany, France and the United Kingdom, which prioritise open protocol systems.

3. Detailed planning and system architecture: integration and interfaces

Once the target concept has been defined, detailed planning of the system architecture follows. This phase is decisive for technical feasibility and the system's later performance. Here, the exact components, their placement, the cabling structure, and the necessary interfaces to other systems are defined. A modern access control system is rarely a standalone solution; rather, it is an integral part of a comprehensive security concept. Integration with fire alarm systems, for example, is essential to automatically release escape routes in the event of fire while simultaneously preventing unauthorised access. Connection to intrusion detection systems, video surveillance systems or time-recording systems is also often sensible, to exploit synergies and increase efficiency.

Detailed planning also takes account of compliance with relevant standards and guidelines. DIN EN 60839-11-1, for example, sets out the minimum requirements for functionality, performance characteristics and test procedures for electronic access control systems and defines various security grades. VdS guidelines, such as VdS 2358 and VdS 2367, are likewise significant for the planning and installation of access control systems. At this stage, PLANATEL® produces precise planning documentation covering all technical details, from selecting readers and control units to defining the network architecture and power supply. Careful planning of the power supply is of great importance here, to avoid failures and ensure operational reliability, as AZS System AG points out. This creates the basis for a smooth installation and reliable operation.

Article image: Zutrittskontrolle Planung Ablauf - mid

4. Tender and award: transparency and cost optimisation

With the detailed planning documentation in hand, the tender phase can begin. The aim is to find qualified installers who can implement the planned access control system professionally and cost-efficiently. A precise, complete tender is of the greatest importance here, in order to obtain comparable bids and avoid later amendments or misunderstandings. PLANATEL® produces comprehensive specifications of services for this purpose, clearly defining all technical requirements, the services to be delivered, and the standards to be observed. This covers not only the hardware and software components but also installation services, commissioning, documentation and training.

The award is made based on a transparent, objective evaluation of the bids received. Here, not only the pure acquisition costs are considered, but also factors such as the quality of the components offered, the installer's experience, references, maintenance concepts, and long-term operating costs (total cost of ownership). PLANATEL®'s independent position is invaluable at this stage, since we receive no commissions from manufacturers or installers. This guarantees an objective evaluation and the selection of the best solution for your company, free of manufacturer dependency. We support you in negotiations and ensure that the contractual agreements cover all aspects of planning and implementation, to guarantee maximum investment security and minimise the risk of errors. Careful selection of the installer is decisive for the success of the entire project.

5. Project support and quality assurance during implementation

The planning phase is complete, but the work of an independent consultant does not end there. During implementation of the access control system, professional project support and quality assurance are essential. PLANATEL® acts in this phase as your extended arm, monitoring the commissioned installer's compliance with the planned specifications and standards. This includes regular site visits, checking the installation of hardware components such as readers, controllers and cabling, and reviewing the software configuration and the interfaces to other systems. Our goal is to ensure that the system is built exactly according to the detailed planning documentation and the contractual agreements.

Quality assurance also includes checking the materials and components used for conformity with the tender requirements and relevant standards. For cost reasons, inferior components or faulty installation can often lead to later system failures or disruptions. Through our continuous monitoring, such risks are identified and remedied at an early stage. We ensure that documentation of the installation is complete and traceable, which is of great importance for later servicing, extensions or audits. Independent project support from PLANATEL® protects your interests and ensures your investment project is completed on time, on budget and to the desired quality, without you having to deal with every technical detail yourself.

6. Acceptance, documentation and training: secure operation from day one

Formal acceptance of the access control system is a decisive milestone in the project. In this phase, it is checked whether the installed system fulfils all contractually agreed functions and meets the technical specifications and applicable standards. PLANATEL® carries out detailed acceptance tests covering both the hardware and software functions. This includes checking the readers, door controls, alarm functions, logging, and the correct function of all interfaces to integrated systems. Any defects identified are documented and their remediation demanded from the installer before final acceptance takes place.

Alongside acceptance, comprehensive documentation of the system is of the greatest importance. This includes as-built records, wiring diagrams, configuration files, operating manuals and maintenance plans. Complete documentation is essential for smooth operation, troubleshooting and future extensions of the system. At the same time, administrators and key personnel at your company are thoroughly trained to operate, manage and service the system independently and securely. This covers the granting and revocation of access permissions, evaluating logs, and managing emergency scenarios. Thorough instruction of all users ensures smooth operation from the outset. PLANATEL® supports you in producing maintenance concepts and selecting certified service providers, to ensure the long-term functionality and legally compliant servicing of your access control system.

Legal compliance and data protection are not one-off tasks in planning and implementing access control, but an ongoing process requiring constant attention. In particular, the General Data Protection Regulation (GDPR) places high demands on the processing of personal data, which inevitably arises with access control systems. Under Article 9 GDPR, biometric data, which some systems use for authentication, is classed as particularly sensitive, and its processing is permitted only under strict conditions. Companies must ensure that the collection, storage and processing of this data complies with the principles of data minimisation and purpose limitation, and that the rights of the data subjects are upheld.

In addition, employment-law aspects must be observed. The introduction and use of technical systems to monitor employee behaviour or performance is subject to co-determination by the works council under Section 87(1) No. 6 of the Works Constitution Act (BetrVG) and requires a works agreement. This ensures that employees' interests are appropriately taken into account and that the monitoring is proportionate. PLANATEL® advises you comprehensively on this legal framework and helps you plan an access control system that is not only technically mature but also fully legally compliant. We support you in producing the necessary documentation and concepts, to avoid fines and legal disputes and to strengthen employee trust.

8. Common mistakes in planning and how PLANATEL® avoids them

Despite the best intentions, mistakes can occur when planning access control systems, with far-reaching consequences. One of the most common mistakes is an inadequate requirements analysis, leading to a system that is either over-dimensioned or not up to the actual requirements. Another critical point is a lack of integration with existing security and building-management systems, resulting in standalone solutions and increased administrative effort. Neglecting future viability and scalability is likewise a widespread problem; a system that fits today should also be extendable tomorrow.

An often underestimated risk is manufacturer dependency. If a system is tailored from the outset to a single manufacturer's products, this can lead in the long run to higher costs, limited flexibility and difficulties with servicing. Germany, France and the United Kingdom prioritise open protocol systems specifically to avoid this dependency. Disregarding data protection provisions and employment-law requirements can also carry significant legal and financial risk. PLANATEL® meets these challenges with a proven, manufacturer-neutral planning process based on over 34 years of experience. We place value on a thorough requirements analysis, integration into a holistic security concept, and strict compliance with all relevant standards and laws. Our independence guarantees that we always find the optimal solution for your specific requirements, without being tied to particular products or providers. This way you avoid costly mistakes and get a future-proof system.

Article image: Zutrittskontrolle Planung Ablauf - bottom

Next step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
E-Mail: info@planatel.de

Frequently asked questions

How can PLANATEL® help with planning an access control system?

PLANATEL® offers manufacturer-neutral, financially independent planning and consulting for access control systems. We accompany you through the entire process: from the detailed requirements analysis and the creation of a tailored target concept, through tendering and award, to project support and acceptance. Our expertise ensures your system is legally compliant, future-proof and optimally tailored to your needs, based on over 34 years of experience.

What advantages does independent planning offer over directly commissioning an installer?

Independent planning from PLANATEL® guarantees objectivity in technology selection and avoids manufacturer dependency. We optimise costs through transparent tendering and ensure the solution matches your requirements exactly, without being influenced by sales interests. This leads to higher quality, cost efficiency and long-term investment security for your company.

What are the biggest risks of inadequate access control planning?

Inadequate planning can lead to significant risks, including security gaps that allow unauthorised access, high follow-on costs from wrong decisions or rework, inadequate scalability for future requirements, and legal consequences from non-compliance with data protection or employment-law provisions. Professional planning minimises these dangers.

How are data protection and employment law taken into account in planning?

Data protection and employment law are integral parts of our planning. We ensure that the processing of personal data complies with the requirements of the GDPR (Art. 9, Art. 32) and the BDSG. We also advise on involving the works council under Section 87(1) No. 6 BetrVG, to ensure a legally compliant works agreement and promote employee acceptance of the system.

What role do maintenance concepts and training play after installation?

After installation, maintenance concepts and comprehensive training are decisive for long-term secure and efficient operation. PLANATEL® supports the creation of maintenance plans and the selection of certified service providers. Training enables your staff to manage the system independently, control permissions and respond to faults, which significantly increases operational reliability.

What is the first step in planning access control?

The first and most important step is a comprehensive requirements analysis. Here, the specific security requirements, the areas to be protected, potential risks, and the relevant groups of people are captured and assessed in detail. This forms the basis for all further planning steps.

Which standards are relevant to planning access control systems?

DIN EN 60839-11-1, which sets minimum requirements for systems and components, is highly relevant to planning access control systems, along with various VdS guidelines, such as VdS 2358 and VdS 2367. These standards and guidelines define technical and organisational requirements for different security grades.

Why is manufacturer neutrality important when planning access control?

It avoids dependency on individual providers, enables the use of open protocol systems, and secures the system's long-term flexibility and extendability, without being tied to proprietary solutions.

What role does the GDPR play in access control?

The GDPR plays a central role, since access control systems process personal data. Companies must ensure that the collection, storage and processing of this data is legally compliant, particularly for biometric data. Article 32 GDPR requires appropriate technical and organisational protective measures.

Sources and further information

  • concepture.de
  • lohrer.de
  • assaabloy.de
  • gfos.com
  • azs.de