Cloud-based access control (ACaaS) trades a local server and IT maintenance for an internet-dependent, subscription-priced system managed from anywhere — the right call for multi-site portfolios and thin admin staff, but only after you've priced the recurring fee and confirmed offline behavior. This guide breaks down the real cost curve against on-prem, what happens at the door when connectivity drops, and the data-residency and NDAA Section 889 questions federal and healthcare buyers need answered before signing. We name platforms like Brivo, Verkada, and Avigilon Alta factually where relevant — not as an endorsement over buying direct.
Cloud-Based Access Control: Buyer's Guide (ACaaS)
Cloud-based access control (ACaaS) buying guide: cloud vs on-prem tradeoffs, subscription costs, offline failover, and NDAA compliance for direct buyers.
Cloud vs. On-Prem: What Actually Changes
The core trade in access-as-a-service (ACaaS) isn't "cloud good, panel bad" — it's where the database lives. On-prem keeps the credential database and event log on a local server; the door controllers phone home to a box in your IT closet. Cloud systems (Brivo, Verkada, Avigilon Alta, and similar platforms) push that database to the vendor's hosted environment, and your controllers reach it over the internet instead.
That shift buys real things: no server to patch, remote lock/unlock from a phone, faster multi-site rollout, and updates without a truck roll. It also changes your risk model — you now depend on the vendor's uptime, breach history, and data handling, not just your own IT team's. For a single building, on-prem often still wins on total control. For a portfolio of sites with rotating staff and no full-time badge administrator, cloud usually wins on labor cost.
The Subscription Math Nobody Puts on the Website
Cloud access control is priced as door-count × per-door annual fee, stacked on hardware you still buy once. That recurring line is what budget owners underestimate. Run the comparison before signing:
- Year one: hardware plus install is often comparable to on-prem, sometimes higher because the controllers carry a cloud-services premium.
- Year two onward: the subscription becomes the dominant cost. Multiply the per-door fee by door count by the years you plan to keep the system, and compare against an on-prem system's occasional software-maintenance renewal.
- Growth and shrink: adding doors is easy and priced per-door, but removing them rarely earns a refund — check the contract's true-down terms before you sign.
- What's included: video integration, mobile credentials, visitor management, and API access are frequently upsells on top of the base per-door price. Ask for the itemized quote, not the marketing tier name.
None of this makes cloud the wrong call — it just means the spec-sheet number is a floor, not the total. Request a multi-year total-cost-of-ownership breakdown, not a per-door teaser rate.
What Happens When the Internet Goes Down
This is the question buyers forget until it matters. Cloud-managed doesn't have to mean cloud-dependent for the unlock decision — but architectures differ:
- Better designs cache the credential list at the door controller, so badge reads keep working locally during an outage and queue events for sync once connectivity returns.
- Weaker designs phone the cloud for every read, so an ISP outage becomes a facility lockout (or a fail-safe door standing open, its own problem).
- Ask any vendor what a badge read does at a given door if the building's internet is down for hours. Get the answer in writing, and confirm it applies to every door type quoted — mag locks and electric strikes behave differently on power and network loss.
For federal, healthcare, and critical-infrastructure sites, offline behavior belongs in the RFQ as a pass/fail requirement, not a nice-to-have.
Data Residency, Hosting, and the Compliance Layer
A cloud access-control platform is a data-handling vendor as much as a hardware vendor — your badge database, video integrations, and access logs live on someone else's servers. Before you buy, get answers on:
- Where the data is hosted. US-based hosting matters for FedRAMP-adjacent and CJIS-adjacent buyers, and the vendor should commit to it in the contract, not just a sales deck.
- Who can see your access logs. Vendor support access, subcontractors, and retention periods should be documented, not assumed.
- Country of origin of the hardware. Cloud platform and door hardware are sometimes different supply chains entirely. A US-hosted dashboard doesn't clear a reader or controller made by a covered entity under NDAA Section 889 — separate questions that both need documented answers before a federal or DoD facility can accept the system.
This is where we differ from most integrators quoting this category: we screen every access-control component — controllers, readers, credentials — against Section 889 before it goes on a quote, and provide country-of-origin documentation on request. We are not a GSA Schedule holder (that application is in progress), so federal and SLED buyers work with us direct — GPC, simplified acquisition under FAR Part 13, or an open-market purchase order, with WAWF/PIEE invoicing on the DoD side.
Migrating Off a Legacy Panel
Swapping an aging on-prem panel for a cloud platform is rarely a full rip-and-replace. Most sites can reuse existing card readers and wiring if the new controllers support the same credential format, so confirm credential compatibility before assuming a wholesale hardware swap. What usually needs replacing is the panel itself and, if the badge population runs an outdated low-frequency format, the credentials. Plan the cutover door-by-door rather than building-wide, so the old system is never decommissioned before the new one is validated on every door.
Ready to compare cloud and on-prem access control for your facility with real numbers instead of teaser pricing — request a documented quote from Uniqcli.
Frequently asked questions
Is cloud-based access control more expensive than on-prem in the long run?
Often, yes, once you account for the recurring per-door subscription. Hardware and install costs are comparable in year one; from year two on, the subscription fee compounds while an on-prem system's cost is mostly a periodic software-maintenance renewal. Run the multi-year total before deciding.
What happens to door access if the internet goes down?
It depends on the controller design. Better systems cache credentials locally so badge reads keep working offline and just queue events for sync later. Weaker designs require a live cloud connection for every read. Get the vendor's answer in writing before you buy.
Can a cloud access control platform be NDAA Section 889 compliant?
The cloud dashboard being US-hosted doesn't automatically clear the door hardware — controllers, readers, and credentials are a separate supply chain and need their own country-of-origin documentation. Ask for both before a federal or DoD facility accepts the system.
Do I need to replace all my card readers to switch to a cloud system?
Usually not. Most sites can reuse existing readers and wiring if the new controllers support the same credential format. What typically gets replaced is the panel itself, and credentials only if the badge population is on an outdated low-frequency format.
Can Uniqcli sell cloud access control directly to a federal agency?
Yes. We sell direct — GPC, simplified acquisition under FAR Part 13, or an open-market purchase order, with WAWF/PIEE invoicing for DoD buyers. Our GSA MAS Schedule application is in progress; we are not yet a Schedule holder.
Need it sourced compliant and direct?
Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.
