The promise of mobile access—using smartphones and watches instead of traditional cards, keys, or fobs—is alluring. Our phones are nearly always with us, and similar use cases, like mobile payments, have become dominant in many markets.
So why isn’t mobile access growing faster in some places? Adoption takes time, and misconceptions persist. This eBook breaks down common myths about mobile access to help you separate truth from fiction and decide if it’s the right next step for your organisation.
Let’s take a look at 9 myths around mobile access.
1. Myth: Mobile access requires users to download yet another stand-alone app.
Truth: Mobile credentials can be integrated into popular digital wallets as well as your existing corporate app — driving usage and engagement.
Mobile access can be deployed in many ways, with smartphone apps being among the most common and convenient. Software development kits (SDKs) simplify integrating credentials into your company’s app, creating app “stickiness.”
Employees and tenants can use the app to enter the building, access secure floors, release printed documents, book meeting rooms, exit the parking garage, and more — enhancing engagement and the work experience.
Another option is to let users add their mobile credentials to their favourite digital wallet, tapping into a familiar experience.
2. Myth: Mobile credentials are less secure than physical credentials.
Truth: Mobile credentials are more secure than physical cards — when they have been certified to internationally recognised security standards.
To start, mobile credentials are safer than cards because people are much less likely to lose or lend their phone than a card. They also are more likely to quickly notice when they do lose them, and the mobile credential can be easily decommissioned remotely. For additional safety, mobile access credentials can be set to not function until a device’s screen is unlocked.
When evaluating potential mobile access providers, it is critical to look for internationally recognized third-party security certifications like ISO/IEC 27001 covering information security management, and SOC 2 Type 2, the gold standard for attesting that organizations store and process client data in a secure manner.
Best-in-class mobile access solutions utilize Advanced Encryption Standard (AES) encryption to keep data secure and unreadable to would-be hackers, the same standard used to protect the world’s most sensitive data. Additionally, storing encryption keys on a smartphone’s secure element — rather than inside of an application — makes them nearly impossible to extract in the first place.
3. Myth: Mobile credentials compromise your personal privacy.
Truth: Your personal data remains on your phone — encrypted and inaccessible by your mobile access provider.
When a mobile ID (credential) is issued, it comes with a unique number assigned to the user’s mobile device. Each time you present this mobile credential to a reader, your device is authenticated and its unique number is sent to the reader. The local access control system then grants you specific access rights, following local policies.
What’s even cooler? This whole authentication process works even without internet coverage, whether you’re in a basement or a remote area. Plus, no personal data is collected from your phone—no need, and no way to do so!
4. Myth: QR codes are easier to use than mobile credentials.
Truth: Mobile credentials are less error-prone than QR codes and provide more functionality.
QR codes have become ubiquitous for various functions, yet they come with their own set of hassles. Issues like phone brightness, screen conditions, ambient lighting, and reading angles can make scanning them frustratingly inconsistent. Plus, having to unlock your phone first slows down the process—a critical flaw in access control where every millisecond counts, especially in high-traffic scenarios.
Fraud prevention is another headache. QR codes can be easily copied or reused, raising the risk of multiple employees sharing the same credentials or granting unauthorized access to a friend. Even dynamic QR codes aren’t foolproof; they can be duplicated via video calls.
But there’s a better way. Top-tier mobile access credentials can function without the need to unlock your phone, even when your battery is low or completely dead. Take the iPhone’s Express Mode with Power Reserve, for instance—it works up to five hours after your device needs a recharge. With mobile access solutions using near-field communication (NFC) technology, all you need to do is hold your phone near the reader to be recognised and granted access. Simple, efficient, and frustration-free.
5. Myth: Mobile credentials are not reliable.
Truth: Improper phone settings are the biggest cause of lack of functionality — and easily remedied.
Transitioning from one technology, like card-based credentials, to a new format can feel like a leap. Many worry it won’t work as seamlessly as what they’re accustomed to.
In truth, functionality issues often stem from personal phone settings or sometimes the reader’s settings. For example, some mobile devices using Bluetooth® Low Energy tech need location services enabled for the app to run smoothly in the background. Update that setting, and voilà, problem solved!
6. Myth: Mobile credentials should be free because they are virtual.
Truth: Companies advertising “free” mobile credentials are simply moving the cost to another part of their solution — and can limit your options for future integrations and upgrades.
Access control is a fascinating interplay of systems and products, from readers and controllers to credentials and software. The true cost of managing credentials lies in the robust security and technology that keeps your information safe and operational, not just the physical card or key.
Unlike physical credentials, mobile credentials need ongoing software maintenance to stay compatible with the latest mobile devices and operating systems. Beware of mobile access providers that offer “free” credentials—this often means they’re shifting costs elsewhere and locking you into their entire ecosystem. This can limit flexibility and interoperability with other systems, and you might miss out on crucial updates, certifications, and support to combat the latest security threats.
Choose wisely to ensure your access control solution remains cutting-edge and secure!
7. Myth: Mobile access is overly complicated to implement.
Truth: Mobile access simplifies many aspects of access control, and drives operational efficiencies and cost savings.
All access control relies on collaboration with various business systems, and mobile access control is no exception. However, it brings some distinct advantages. Cloud-managed mobile access solutions enhance operational efficiency by seamlessly connecting to other back-end systems and offering centralized management across multiple locations.
From a provisioning perspective, everything can be handled remotely! Users can receive their credentials without the hassle of coordinating in-person meetings. Administrators simply email users a link to download their credentials — and they are good to go. Revoking credentials and upgrading software is just as straightforward.
Moreover, many readers can read both mobile devices and traditional cards, allowing for a smooth, phased implementation. This flexibility makes the transition to mobile access control not only easy but also highly efficient.
8. Myth: My employees are not going to like using their own phones for mobile access.
Truth: Bring Your Own Device (BYOD) policies are not new — and are predicted to keep rising as employees seek simplicity and connection.
BYOD policies have been around for decades, and their popularity is only set to soar. In fact, the global BYOD and Enterprise Mobility Market is forecast to skyrocket to US$296.4 billion by 2030! In Japan alone, this growth is projected at an impressive CAGR of 14% between 2023 and 2030.
What’s fueling this surge? Today’s employees crave connection and engagement, and they’re accustomed to doing everything on their mobile devices. Enter company engagement apps—these nifty tools, deployable on both personal and company-issued phones, often include mobile access, fostering efficient two-way communication between employees and companies. Plus, they have a positive influence on workplace culture.
9. Myth: Mobile access sounds too technical and hard to manage. I’m more comfortable with plastic cards; I can see them and know how to keep track of them.
Truth: Cloud-based ID management solutions, like HID Origo, make it easy and more efficient for administrators.
Despite the advanced technology behind mobile access, administrators will find the experience incredibly simple and easy to master. Managing digital credentials is almost identical to handling physical ones—minus the headaches of dealing with lost or damaged cards.
With the HID Origo Management Portal, adding mobile users is a breeze. You can do it one by one or save time by bulk uploading a CSV or Excel file. Once added, users receive an email to accept and install their mobile credential, and they’re ready to go!
The best part? Everything is tracked and displayed on a single dashboard. This makes it super easy to monitor usage patterns, change permissions, or revoke credentials—all with complete visibility and control. Say goodbye to administrative hassles and hello to seamless mobile management!




