As U.S. regulators look deeper into technology supply chains, access control manufacturers and buyers are placing greater emphasis on component sourcing, secure communication and vendor transparency.
The U.S. access control market is entering a new phase.
For years, organizations evaluating access control systems have focused primarily on functionality: credential technologies, scalability, integrations, mobile access, cybersecurity and total cost of ownership.
Today, particularly in government and critical-infrastructure environments, another question is becoming increasingly important:
Can the vendor demonstrate where its technology comes from and what is inside the device?
The Federal Communications Commission's latest supply-chain security actions reinforce this shift.
In July 2026, the FCC adopted its Third Report and Order in ET Docket No. 21-232, further strengthening the Equipment Authorization Program. One of its most significant changes addresses what the Commission described as a component-part loophole involving certain logic-bearing hardware supplied by entities appearing on the FCC Covered List.
Although these rules are not written specifically for physical access control systems, they point to a broader change that security manufacturers, integrators and buyers cannot ignore:
Compliance is moving beyond the finished product toward the technology supply chain behind it.
Why This Matters to Access Control
Modern access control systems are no longer isolated door-opening technologies.
Readers increasingly support RFID, NFC, Bluetooth and mobile credentials. Controllers connect to IP networks and cloud platforms. Biometric terminals process sensitive identity information. Access control, video surveillance, visitor management and intercom systems are increasingly part of the same connected security environment.
As these systems become more interconnected, processors, communications modules, firmware and other programmable components become more relevant to cybersecurity and procurement decisions.
The FCC's latest actions reflect this concern by extending regulatory attention deeper into the equipment supply chain, including certain logic-bearing hardware components.
For access control manufacturers, the message is increasingly clear.
In the future, saying that a product is secure may not be enough. Buyers may increasingly expect vendors to explain how the product is built, where critical components originate and how communication between devices is protected.
Public-Sector Procurement Will Feel the Shift First
The impact is likely to be strongest in government, defense-related projects and critical infrastructure.
NDAA Section 889 procurement restrictions and the FCC Covered List operate under different regulatory frameworks. However, together they have contributed to a U.S. security market that places greater emphasis on technology provenance, supplier risk and supply-chain transparency.
This is particularly relevant to environments such as government facilities, transportation systems, utilities, healthcare infrastructure, data centers and other security-sensitive sites.
Instead of evaluating only the brand shown on the enclosure, security and procurement teams may increasingly ask:
-
Who manufactures critical communications components?
-
What communication protocol is used between the reader and controller?
-
Is encrypted communication supported?
-
Can important upstream suppliers be identified?
-
Does the equipment have the required FCC authorization?
-
Does the manufacturer's sourcing strategy satisfy the project's procurement requirements?
Not every access control product is directly affected by the FCC's latest rules.
However, supply-chain transparency is increasingly becoming part of the purchasing conversation.
How Access Control Vendors Are Responding to a Changing Market
The U.S. access control market already shows several different strategies for responding to changing security, connectivity and procurement expectations.
HID Global remains one of the industry's best-known providers of credentials and reader technologies. Its strength lies in a broad credential ecosystem spanning smart cards, mobile credentials and readers, while its newer solutions also reflect the industry's move toward mobile access and more secure communication protocols.
Honeywell positions access control as part of a broader building and security ecosystem. Its solutions can integrate access management with video surveillance, intrusion detection and building automation, making this approach particularly relevant to large commercial and institutional environments.
Johnson Controls, including its Software House and C•CURE heritage, remains closely associated with enterprise security deployments where organizations need centralized management across complex facilities and multiple security systems.
Verkada represents the market's shift toward cloud-managed physical security. Its platform emphasizes centralized administration and integration between access control, video security, visitor management and other security applications.
ZKTeco USA takes a broader physical-security approach, with access control, biometric authentication, entrance control and related technologies serving organizations that require multiple credential and identity-verification options.
Alongside these larger vendors, specialized manufacturers may also gain attention as buyers place greater emphasis on sourcing flexibility, interoperability and deployment architecture.
Taiwan-based CHIYU Technology, for example, develops access controllers, readers, biometric terminals and management software. Its product portfolio includes OSDP-capable devices such as the SEMAC-CP202 controller, illustrating how smaller manufacturers are also adapting to demand for more secure reader-to-controller architectures.
For government and security-sensitive projects, alternative sourcing and standards-based design may become increasingly relevant. However, procurement eligibility should always be evaluated against the requirements of each individual project rather than inferred from manufacturing location, protocol support or vendor-issued compliance statements.
The larger trend is therefore not about one particular manufacturer. It is about how different vendors are adapting to a market where security architecture, supply-chain visibility and interoperability increasingly influence purchasing decisions alongside product functionality.
Why OSDP Is Becoming More Strategically Important
The changing regulatory environment is also likely to increase interest in the Open Supervised Device Protocol, or OSDP.
Traditional Wiegand communication remains widely deployed, but it was created long before modern cybersecurity requirements became part of physical-security system design.
OSDP offers bidirectional reader-to-controller communication and supports Secure Channel using AES-128 encryption.
For security teams, this creates advantages beyond interoperability.
Secure communication between readers and controllers can become part of a broader secure-by-design access control architecture, particularly for government facilities and other sensitive environments.
OSDP can also help manufacturers and integrators move away from completely proprietary reader-controller communication and toward more standardized architectures.
One distinction remains important: supporting OSDP does not automatically mean that a product is OSDP Verified. The Security Industry Association operates a separate verification program for products that have completed its testing requirements.
Compliance Claims Will Need More Evidence
Perhaps one of the biggest changes ahead is what buyers expect when they hear the word compliant.
Statements such as FCC compliant, NDAA compliant or cybersecure may no longer be sufficient for sophisticated government and enterprise buyers without supporting documentation.
The FCC is already considering additional measures involving hardware and software bills of materials, software and firmware associated with Covered List entities, white-label equipment and additional supply-chain disclosures.
These measures remain part of further proposed rulemaking and should therefore be distinguished from requirements that have already been adopted.
Nevertheless, the regulatory direction is significant.
Manufacturers capable of offering stronger component traceability, transparent OEM relationships, documented communications security and long-term firmware management could gain an advantage even when competing against products with similar functionality.
Supply-Chain Transparency Becomes a Competitive Advantage
These changes should not be viewed only as another compliance burden.
They may also create opportunities.
Historically, access control manufacturers differentiated themselves primarily through credentials, hardware capabilities, software integrations, user experience and price.
The next competitive layer may be trust.
Customers may increasingly consider whether a manufacturer can answer questions such as:
Where does the technology come from?
How is communication protected?
Who controls firmware development?
Can the supplier identify critical upstream components?
Can regulatory and procurement claims be documented?
Established manufacturers will continue to compete through large ecosystems, cloud platforms, enterprise integration and broad market presence.
At the same time, smaller and specialized manufacturers may compete through supply-chain flexibility, open protocols, focused product architectures and greater responsiveness to project-specific requirements.
This means the next stage of competition in access control may be shaped not only by company size or brand recognition, but also by the ability to demonstrate transparency and technical trust.
From Secure Products to Trusted Infrastructure
The larger trend extends beyond one FCC regulation.
Physical security devices are becoming connected infrastructure.
Connected infrastructure is becoming part of the cybersecurity perimeter.
And the cybersecurity perimeter increasingly extends into the technology supply chain.
For organizations evaluating access control systems in the United States, purchasing decisions are therefore likely to revolve around three questions:
Does it work?
Is it secure?
Can we trust where it comes from?
As FCC requirements and government procurement policies continue to evolve, the ability to demonstrate supply-chain trust could become nearly as important as the ability to control the door.
Frequently Asked Questions
Does the FCC's July 2026 rule ban access control systems?
No. The rule is not a blanket ban on access control products. It strengthens equipment-authorization restrictions involving certain entities and components. Its impact depends on the technology, components and FCC requirements applicable to a specific device.
Is NDAA compliance the same as FCC compliance?
No. NDAA procurement restrictions and FCC equipment requirements operate under different regulatory frameworks. Compliance with one should not automatically be interpreted as compliance with the other.
Why is OSDP important for access control security?
OSDP supports bidirectional communication and AES-128 Secure Channel between compatible readers and controllers, providing stronger security capabilities than traditional unencrypted reader communication.
What should access control buyers evaluate beyond product features?
Buyers should increasingly consider component sourcing, reader-to-controller security, firmware management, FCC authorization where applicable, manufacturer transparency and project-specific government procurement requirements.