Read any guide on generating access control leads and you will be told to run Google Ads, tidy your Google Business Profile, and post case studies. That advice is written for a plumber, with the nouns changed.
It misses what is actually happening in this market. The department buying access control is changing, and the reason to replace a system is no longer about features. Both of those are commercial openings, and neither appears in a single page currently ranking for this keyword.
The short answer
Stop advertising for people shopping for access control, and start identifying buildings whose access control is obsolete. The second group is far larger, is not in the market yet, and has a reason to move that you can demonstrate rather than argue.
The legacy base is the market
The core technology of electronic access control was released in the 1960s and, as Jon Polly writes in Security Info Watch, has remained remarkably unchanged since, with the main shift being from serial panel communication to IP connectivity. Panels are still a handful of reader ports, inputs and relays.
Two numbers from that piece matter more than anything in the marketing literature:
- Most consultants suggest refreshing an access control system every 8 to 10 years.
- Retrofits of 25 years and older are common enough to be discussed as a category.
By the numbers
That gap is your pipeline. Every commercial building in your radius that installed access control before roughly 2018 is overdue by the industry's own guidance, and a meaningful share of them are running equipment two and a half decades old. None of them are searching for you. All of them are prospects.
This is the same structure as the rest of the life-safety trades. Fire inspection has a code-set calendar. Commercial security has a grant calendar. Access control has a refresh cycle and an obsolescence argument. In all three, the buying date is set by something outside the customer's enthusiasm, which means it is knowable in advance. We map all four of those clocks in security integrator marketing.
Prox and Wiegand are the sales argument
Here is what makes the access control version unusually strong: the reason to replace is not "newer is nicer". It is that the installed technology is regarded within the industry as insecure.
Polly is blunt about it. Legacy protocols like Wiegand and Prox are described as outdated and insecure, and 125 kHz Prox as "the tech that just will not die, despite most respected security practitioners calling for its demise." He goes as far as proposing that anyone selling Prox should require an end-user licence agreement placing liability on the customer, and predicts Wiegand's lifespan would collapse if installers had to sign something similar.
You do not need to adopt that position to use it. You need to be the integrator who can explain, in a building running thick white proximity cards, what that credential technology actually is and what its known weaknesses mean for the organisation's risk. That is a conversation no competitor pitching cost per door is having.
Watch out
Do not turn this into fear selling. The credible version is an assessment: here is what is installed, here is the protocol it uses, here is what the industry's own standards bodies say about it, here is the migration path and what it costs. The document does the persuading. Overclaiming destroys the technical credibility that is the entire basis of the approach.
The sanctioned migration path is OSDP, the Open Supervised Device Protocol, a bidirectional secure RS-485 protocol between panel and peripherals. Critically for you: "many installers are still unaware or untrained on OSDP. So are manufacturers." The Security Industry Association runs OSDP bootcamps and publishes an OSDP Verified product list, and one validator noted that several manufacturers claiming compliance still have real work to do.
A capability most of your competitors lack, with a public verification list you can check and they cannot be bothered to, is the definition of a differentiator.
You are selling to IT now
This is the part most integrators are slowest to adjust to, and it changes who you market to entirely.
Brett Zelnio of Stratified Logic Group, quoted in the same piece, puts it directly: in the absence of a security manager, the IT manager often fills the gap, and on large capital projects within enterprise organisations it is not uncommon for the voice of the CIO to carry more influence than the voice of the CSO.
The article also names the driver plainly: the push for change is not coming from inside the security industry. IT departments have audited the technical debt they own and decided it is time to get rid of it.
That reframes the entire pitch. IT does not evaluate access control on doors per panel. It evaluates it on the list Polly rattles off as standard enterprise infosec expectations: 802.1x port authentication with certificate injection, TLS 1.3, TPM secure element, secure boot, signed firmware, SSO, ISO 27001 or SOC 2, AES-256, zero trust. Security systems get air-gapped from production networks precisely because they fail to meet those standards.
Tip
Two concrete implications. First, your website and proposals need this vocabulary present, because an IT director evaluating you will look for it and its absence is disqualifying. Second, organisations that have recently pursued SOC 2 or ISO 27001, or hired their first IT security lead, are actively auditing exactly this. That is a buying signal available from news, job postings and LinkedIn, and nobody in your trade is watching it.
Finding the buildings
No list exists for sale, which is the good news. The signals are observable:
- Your own installed base. You already know what is behind every door you have worked on, provided your records hold equipment at the site rather than in a technician's memory. This is the cheapest commercial work in the trade and it depends entirely on whether your system stores the installed system at a site.
- Visible credentials. Thick 125 kHz proximity cards and fobs clipped to staff are diagnostic, and visible from a lobby.
- Building age and last renovation. Public permit records date the likely install.
- Compliance events. SOC 2, ISO 27001, a first CISO hire, a cyber insurance renewal. Each one triggers an audit that finds the access control system.
- Tenant churn in multi-tenant buildings. A new tenant is a credential reissue, which is the cheapest possible entry into a building you do not yet own.
We build the assessment offer, the conversion page and the follow-up system behind an approach like this, so an enquiry arrives with the building, the credential technology and the timeline already attached. If your pipeline problem is really that nobody is working your own installed base, we will tell you that instead of selling you a campaign.
Two platforms, not nine
Practitioners in this trade are strikingly consistent about line card discipline, and it matters more when you are selling to technical buyers.
The advice given in r/accesscontrol to an integrator trying to grow commercial work: learn everything your licence allows, but limit your line card. Pick one on-premise and one cloud access control platform and train relentlessly on just those. Know the manufacturer reps and bring them into your opportunities. Do the same for CCTV. Then use that authority publicly, through webinars, workshops and open houses.
The same subreddit shows what that depth sounds like in practice. One integrator, comparing two cloud platforms, explained they use the cheaper option strictly for smaller, low site-count customers because it does not scale as well, has fewer integrations, and relies on proprietary hardware they consider mediocre, while the other is their default whenever budget allows.
That is not a brochure. That is someone who has installed both and can tell a customer which one is wrong for them, which is the single most persuasive thing an integrator can do. It also simplifies your own operations, which is half the answer to which systems your business should run on.
The channels, ranked
Your installed base and referrals. Highest close rate, lowest cost, and entirely dependent on records. Start here.
Legacy-technology outbound. The assessment offer against buildings running Prox. Slowest to build, most defensible once running, and nobody else is doing it.
IT-adjacent partnerships. MSPs are moving into this space and frequently need a hardware partner. They also already hold the relationship with the decision-maker you are trying to reach.
Video attach. The same buildings need cameras, and video has its own separate trigger in alarm verification, which we cover in CCTV installer lead generation. Quoting a combined scope wins work that single-discipline competitors never see.
Search. Worth doing for the minority actively shopping, on narrow commercial queries rather than broad ones. It will not carry a commercial pipeline on its own.
Lead marketplaces. Skip entirely. Built for homeowner emergencies, useless for capital projects.
What to do this quarter
- Audit your own installed base for Prox and Wiegand. That is a target list you already own and have never used.
- Get OSDP-trained and say so publicly. A scarce capability with a public verification list is free differentiation.
- Rewrite your commercial pages for an IT reader. If an IT director cannot find how you handle network segmentation, firmware signing and SSO, you are being filtered out before the call.
- Track the trigger on every opportunity — refresh cycle, compliance event, tenant change, incumbent failure — so in a year you know which signal actually pays.
The industry's own commentators describe access control as a segment where innovation can stall for decades without anyone being overtaken. The same inertia applies to how it is sold. That is the opening.