OSDP vs Wiegand: Which Reader Protocol Should NZ Installers Use?
Essential Security Supplies
For a new commercial access control installation in New Zealand, specify OSDP with Secure Channel enabled wherever the selected controller and reader support it. Retain Wiegand where a documented legacy requirement makes it necessary, with a clear understanding of the security limitations and a practical migration plan.
The important distinction is not simply OSDP versus Wiegand. It is whether the complete reader-to-controller connection is compatible, correctly commissioned and protected. An OSDP label on a reader does not prove that encryption is active, and a secure smart card does not automatically protect the cable leaving that reader.
This guide helps NZ installers choose the interface, assess existing wiring and specify the checks needed before handing a working door over to the customer.
What do OSDP and Wiegand actually connect?
Both interfaces connect a reader to an access control unit. They are separate from the technology used between a credential and the reader. A card, mobile credential or keypad can provide an identity to the reader; the reader then passes information to the controller, which applies the site's access permissions.
Wiegand normally sends credential data using Data 0 and Data 1 conductors. Reader power and any separate LED, buzzer or tamper connections must also be allowed for. Credential data travels from reader to controller, without an equivalent protocol-level conversation back to the reader.
OSDP, the Open Supervised Device Protocol, supports two-way communication over an RS-485 data pair. Power still needs to be provided. The Security Industry Association's OSDP overview explains its purpose, supervision capabilities and recognition as IEC 60839-11-5:2020.
Keep the layers separate when writing a specification: credential security, reader communication, controller security and door hardware each need their own checks. Our single-door access control planning checklist helps turn those individual components into a complete door schedule.
OSDP vs Wiegand: installer comparison
| Installation question | Wiegand | OSDP |
|---|---|---|
| Reader data direction | Credential data normally travels from reader to controller. | Two-way reader and controller communication. |
| Protection of reader data | Standard Wiegand does not encrypt or authenticate the reader data link. | Secure Channel protects the link when supported, enabled and correctly keyed. |
| Communication supervision | No inherent polling-based reader supervision; separate tamper circuits may be fitted. | Controller can monitor reader responses and detect communication loss. |
| Cable assessment | Follow the exact reader and controller wiring limits. | Use suitable RS-485 twisted-pair cable and the manufacturer's topology requirements. |
| Reader addressing | Normally associated with its dedicated reader input. | Requires compatible addressing and communication settings. |
| Remote functions | Limited by separate wiring and product-specific facilities. | LED, buzzer, configuration and firmware functions depend on both devices' implementations. |
| Typical selection | Documented legacy repairs or constrained staged upgrades. | Preferred starting point for new projects when Secure Channel is available. |
These are interface differences, not a declaration that every OSDP product has every feature. Confirm the exact reader, controller, firmware and software combination before ordering. A useful procurement question is: “Can you demonstrate this pairing operating with Secure Channel and the functions listed in our door schedule?”
Why Secure Channel is the decisive security feature
OSDP can operate without encryption. Selecting OSDP mode alone therefore does not close the security gap in a reader cable. Secure Channel adds AES-128 encryption and authentication to the communication between the reader and controller.
For the installer, the acceptance evidence should be an explicit secure-session indication or another manufacturer-supported diagnostic, recorded for each reader. A successful card read is insufficient: the door might be functioning over an unsecured connection.
The SIA Corporate Credential Design Guide discusses reader-panel protection, credential authentication and key management as distinct controls. That distinction matters when a customer asks whether fitting DESFire readers makes the whole installation secure.
Encryption on the cable does not fix every weak point
A reader configured to accept an easily copied static identifier still has a credential problem, even if its controller link is encrypted. Equally, a strongly authenticated credential can leave an exposed communication path if its reader sends the result through standard Wiegand.
Review how credentials are read, which legacy technologies remain enabled, how administrators obtain access and where the controller is mounted. Place the decision-making equipment and lock switching arrangements inside an appropriately protected area. Do not treat protocol selection as a substitute for physical security.

When retaining Wiegand can be a practical choice
Existing buildings rarely offer a clean-sheet installation. A failed reader may need replacing before a planned controller upgrade, or several tenancies may depend on a shared platform that cannot be changed during normal operation.
In those situations, a compatible Wiegand replacement can be a practical interim measure. Record why it was chosen, the exposure of the reader cable, the area being protected and the conditions under which the site will migrate. Avoid presenting that repair as an encrypted reader-link upgrade.
The RBH NK86-DNB-D34 DESFire Wiegand keypad reader is a relevant catalogue option when assessing a Wiegand-based requirement. Its product description identifies the interface and credential features, but the installer must still confirm credential encoding, keypad behaviour and compatibility with the receiving controller.
A converter may help a staged transition, but it does not remove the limitations of a remaining Wiegand segment. Draw the complete communication path and identify where conversion occurs. If any exposed section remains unencrypted, explain that clearly in the handover record.

Can you reuse existing Wiegand wiring for OSDP?
Sometimes, but conductor count alone is not enough. Inspect cable construction, pair twisting, route, joints, shielding arrangements, run length and power delivery. A cable that worked for Wiegand is not automatically suitable for an RS-485 connection.
For new wiring, select cable meeting the equipment manufacturers' RS-485 requirements. For a retrofit, document the existing cable and test it with appropriate equipment before accepting reuse. Where the route cannot be assessed reliably, allow for replacement rather than promising an upgrade based on a quick continuity check.
Check the bus and the power separately
Follow the controller and reader instructions for topology, termination, biasing, reference connections and shielding. Do not copy a generic terminal diagram onto a different product. RS-485 A/B naming can differ between manufacturers, so verify the documented terminal relationship rather than relying on letters or colours alone.
Calculate voltage drop using the reader's specified demand and the actual supply arrangement. Measure voltage at the farthest reader under representative load, including any keypad or other enabled functions. Reliable data wiring does not compensate for an inadequate power supply.
OSDP can support multiple addressed devices on a bus, but the controller determines what is supported in the installed system. Confirm reader count, bus layout and door mapping. Do not assume an existing star arrangement can be reused unchanged or that a quoted RS-485 maximum distance is a guaranteed project limit.
Specify exact products and prove interoperability
Start with the door schedule and controller capability, then choose the reader. Consider indoor or outdoor placement, mounting width, credentials, keypad requirements and the customer's maintenance arrangements alongside the interface.
The RBH M45-DNB-D-O DESFire OSDP mullion reader provides a specific OSDP product to discuss with Essential Security Supplies. The catalogue identifies DESFire sector reading, NFC and BLE features. Those listings do not establish that every credential, mobile application or controller will work with it.
Use our access control reader collection to compare the required form factor and interface. Request written confirmation of the exact controller pairing, supported firmware, Secure Channel procedure and any required software configuration. Confirm supply availability separately from technical suitability.
Ask whether the exact device and firmware appear in the SIA OSDP Verified programme. Verification is useful evidence of tested conformance; it does not replace a bench test of the features required for your project.

Commissioning checklist for NZ installation teams
Bench-test the intended pairing before site deployment. The following is a practical project checklist to adapt to the manufacturer's instructions and the customer's acceptance requirements.
- Record the equipment: exact reader and controller models, serial numbers, firmware, software version and reader port assignment.
- Confirm communication settings: reader address, baud rate and any bus sharing arrangements. Every device sharing a bus must have the appropriate unique address.
- Establish Secure Channel: follow the authorised key-loading process, confirm the protected session and leave installation or default-key mode only as documented for commissioning.
- Protect key custody: keep secrets in an approved restricted system. The general door schedule should record their controlled location, not expose raw keys to every recipient.
- Test access decisions: valid and invalid credentials, restricted time schedules, PIN combinations where applicable, and the correct door association.
- Test feedback and supervision: LEDs, buzzer, communication loss and supported tamper reporting. Confirm events reach the people or systems expected to respond.
- Test recovery: controlled power cycling and reconnection, with approval for any disruptive test. Verify the secure session resumes as intended.
- Document maintenance: reader replacement, rekeying, firmware changes, backups and the process for confirming security after service work.
The SIA OSDP implementation checklist provides additional guidance on cable assessment, bench testing and supported device functions. Agree the site's expected fault responses before testing, especially where disconnecting a reader could affect occupied premises.
For New Zealand projects, treat the interface choice as one line in the wider specification. Confirm the client's security requirements and assess the complete door, including exit arrangements and emergency operation, through the appropriate project design process. OSDP does not by itself certify the door or determine its emergency release behaviour.
Frequently asked questions
Does an OSDP reader automatically use encryption?
No. Both the reader and controller must support Secure Channel, and the installer must configure and verify it. A functioning reader or an OSDP product label is not proof of an encrypted session.
Can an OSDP reader connect directly to a Wiegand-only controller?
Only if the reader offers a compatible Wiegand mode or a suitable converter is used. Confirm the exact implementation. A Wiegand section remains unencrypted by the standard interface, so this does not provide end-to-end OSDP protection.
Will OSDP stop access cards being cloned?
OSDP Secure Channel protects reader-to-controller communication. Credential cloning resistance depends separately on the card technology, authentication, keys and reader settings. Assess both links.
Do OSDP readers all support remote firmware updates?
No. OSDP provides file-transfer capabilities, but usable remote updating depends on the reader, controller and management software. Verify the supported procedure for the exact pairing.
Should every existing Wiegand door be replaced immediately?
Assess the site's risk, cable exposure, controller support and operational constraints. Prioritise sensitive or exposed doors and document a staged migration where immediate replacement is impractical.
Get help specifying the right reader interface
For new projects, make verified OSDP Secure Channel operation the starting point. For legacy sites, record the reason for retaining Wiegand and plan how the exposed communication path will be improved.
Contact Essential Security Supplies for reader and controller specification help. Send your controller model, firmware, credential type, door schedule and cable details so our team can help check suitable options and identify compatibility questions before you order.