What Is a Proximity Card?

Also called: Prox card

Related problems: Worried our old badges can be copied; Security assessment flagged our 125 kHz badges; Need to replace badges without disrupting everyone at once

A proximity card, or prox card, is a contactless access badge that works at 125 kHz (low frequency). When held near a compatible card reader, it powers up from the reader’s radio field and sends back a fixed ID number, which the access control system checks against its list of who may enter. Prox cards have been the default office badge for decades and are still widely installed, but because the number is typically unencrypted and unchanging, they are widely reported to be easy to copy.

At a glance

  • Prox cards work at 125 kHz and typically send the same number each time they are read.
  • They are cheap, durable and supported by a very large installed base of readers.
  • Inexpensive tools are widely reported to be able to read and copy many prox cards from a short distance.
  • Migration usually means multi-technology readers plus a phased move to smart cards or mobile credentials.
  • Key fobs and stickers can use the same technology, so the risk is not limited to badges.

What problem it solves

Prox cards solved the problems of keys and magnetic stripe cards: no physical key to cut, no stripe to wear out, and a quick tap (or near-tap) at the door. They let organizations issue, disable and audit access per person, which is why they spread so widely.

The problem buyers face today is the reverse: the same simplicity that made prox cards cheap makes them weak. Because a typical prox card answers a compatible reader with the same number each time, someone who briefly gets close to a badge, for example in a lobby, elevator or café, may be able to capture it and make a working copy. That makes prox a common finding in physical penetration tests and a reason auditors ask about badge technology. It is the physical cousin of social engineering: the attacker doesn’t break the door, they become an authorized badge.

How it works

The card. Inside is an antenna coil and a small chip with no battery. The reader’s field powers the chip, which transmits its stored data. That data typically includes a card number and a facility code, a site or customer number meant to reduce collisions between cards from different installations.

Card formats. The bits a prox card sends are arranged in a format that defines where the facility code and card number sit. Some formats are open and widely used; others are proprietary to a manufacturer or reserved for one customer. Proprietary or controlled formats can make it harder to order duplicate blank cards through normal channels, but they do not encrypt the data, so they do not by themselves stop a determined copier.

The read. The reader passes the number to the door controller, which looks it up and unlocks the door if that card is allowed at that time. Read range at a standard door reader is short, usually a few inches or less, but readers with longer range exist, which is part of the cloning concern.

Migration. Because so many readers and cards are in place, few organizations switch overnight. A common path is to install multi-technology readers that read prox and newer credentials, issue smart cards or mobile credentials in phases, sometimes on dual-technology cards that carry both, and then disable prox acceptance at the readers once migration is complete. Leaving prox enabled indefinitely keeps the weakness in place.

When it matters for buyers

  • When a penetration test or audit flags badges. Prox cloning is a common finding.
  • When replacing readers or controllers. It is the natural time to choose a stronger credential.
  • When moving to cloud access control. Some access control as a service (ACaaS) platforms support legacy prox for transition; check how long.
  • When protecting sensitive rooms. Server rooms, pharmacies and labs may need a stronger credential or a second factor such as a PIN even before a full migration.
  • When reordering cards. Ask whether you should keep buying a format you plan to retire.

Questions to ask vendors

  • What card technology and format do we use today, and who controls the format?
  • Can your readers read our existing prox cards and the replacement credential at the same time?
  • What is the recommended replacement, and why is it more resistant to copying?
  • How do we turn off prox acceptance once migration is done, site by site?
  • What does a phased migration cost in readers, cards and labor?
  • Can sensitive doors require a PIN or second factor during the transition?

How it differs from a smart card

A proximity card works at 125 kHz and typically sends a fixed, unencrypted number. A smart card works at 13.56 MHz and has a chip that can store data and perform cryptographic authentication with the reader, so a well-configured modern smart card is much harder to copy. Some older smart card formats also have publicly documented weaknesses, so “smart card” alone is not the goal; a current format with properly managed keys is. They often look identical, so check the technology, not the plastic. For help planning a migration, see our door access controls overview.

Frequently Asked Questions

Can proximity cards be cloned?
Legacy 125 kHz proximity cards are widely reported to be easy to copy. They typically send the same unencrypted number every time, and inexpensive tools sold online can read one from a short distance and write it to a blank card. How exposed you are depends on your readers, door layout and what else protects sensitive areas.
How do I know if our badges are prox cards?
Check the card markings or your access control records for the card type, ask your integrator, or look at the readers and their documentation. Cards described as 125 kHz or low frequency are proximity cards. Many older badges are, even when they look identical to newer smart cards.
What should we replace proximity cards with?
Most organizations move to 13.56 MHz smart cards that use cryptographic authentication, mobile credentials on phones, or both. Choose the format together with the readers and controllers, and confirm it is a current, well-supported format rather than an older one with known weaknesses.
Do we have to replace every card and reader at once?
No. A common approach is to install multi-technology readers that read both old and new cards, issue new credentials in phases, and then turn off acceptance of the old format once everyone has migrated.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.