What are the NEN standards for access control?
The most important NEN standards for access control are NEN-EN 60839-11-1 (system requirements for electronic access control systems) and NEN-EN 60839-11-2 (application guidelines). These standards describe how access control systems must be technically configured, classified, and installed. They apply to a wide range of environments, from office buildings to secure industrial sites. In this article, we answer the most frequently asked questions about NEN standards and access control. Do you have a question right away? Feel free to contact us with Sellox.
Which NEN standards apply to access control?
For access control, NEN-EN 60839-11-1 and NEN-EN 60839-11-2 are the most relevant standards. The first describes the technical and functional requirements for electronic access control systems. The second provides practical guidelines for their application in specific situations. Together, they form the standards framework against which professional systems in the Netherlands are assessed.
In addition to the NEN-EN 60839 series, other standards may also apply, depending on the context:
- NEN-EN 50133: an older standard for access control systems, which in many cases has been replaced by the 60839 series, but is sometimes still used as a reference.
- NEN 2575: relevant when access control is combined with fire alarm systems, because integration between systems imposes specific requirements.
- ISO/IEC 27001: Not technical in nature, but relevant for organizations that embed access control in a broader information security policy.
Exactly which standards apply depends on the type of object, the risk class, and the requirements of the client or insurer.
What do the NEN standards prescribe regarding access security?
The NEN standards for access security prescribe how a system must be classified into performance levels, which components must meet which requirements, and how installation and documentation must take place. They distinguish between four performance levels (grades 1 through 4), where a higher level represents greater resistance to attempts at manipulation or circumvention.
Specifically, the standards touch upon the following aspects:
- Identification means: From simple PIN codes to biometric verification, each method has a corresponding performance level.
- Access controllers and readers: The hardware must meet specific requirements for tamper resistance and communication security.
- Management and logging: The system must record and store access events so that reconstruction is possible afterwards.
- Power supply: Emergency power and failure protection are mandatory for higher performance levels.
- Documentation: Installers must demonstrate that the system is installed and configured in accordance with the standard.
How does NEN-EN 60839 differ from other security standards?
NEN-EN 60839 distinguishes itself from other security standards by specifically focusing on electronic access control systems and using a detailed classification into performance levels. Standards such as NEN 2575 (fire alarm) or NEN-EN 50131 (intrusion detection) focus on other security disciplines. NEN-EN 60839 is the only standard that describes the entire lifecycle of an access control system, from design to maintenance.
An important difference compared to the older NEN-EN 50133 is the broader scope. Whereas 50133 was limited to the basic functionality of access control, the 60839 series also includes requirements for system integration, cybersecurity of the communication layers, and management processes. This makes the standard better suited for modern, network-connected access control systems.
Compared to ISO/IEC 27001, NEN-EN 60839 is technical and product-oriented, whereas ISO/IEC 27001 is a management standard. Organizations that use both utilize 60839 for the technical implementation and 27001 for the surrounding policy framework.
When are you required to comply with NEN standards for access control?
In the Netherlands, there is no general statutory obligation for all organizations to comply with NEN standards for access control. The obligation arises in specific situations: when an insurer sets it as a condition, when a client or government agency requires it contractually, or when legislation and regulations for a particular sector prescribe it.
Situations in which compliance is mandatory or strongly recommended in practice:
- Business insurance: Many insurers require security systems to meet recognized standards before damage is reimbursed.
- Government buildings and vital infrastructure: The central government and municipalities apply security requirements that refer to NEN standards.
- Healthcare institutions and data centers: Sectors with strict privacy legislation (such as the GDPR) expect demonstrably secure access control.
- Tenders: In public tenders, conformity to standards is often included as a selection criterion.
Even without a formal obligation, compliance offers a demonstrable level of quality that inspires confidence in customers, partners, and regulators.
How do you demonstrate that an access control system complies with the NEN standard?
Demonstrating that an access control system complies with the NEN standard is done through a combination of product certification, installation documentation, and, where applicable, an independent inspection. The supplier or installer is responsible for providing evidence that the system has been designed, installed, and configured in accordance with the applicable standard and the required performance level.
The most commonly used methods to demonstrate conformity are:
- Product certificates: Components such as readers, controllers, and software are tested and certified by independent testing institutes based on the NEN-EN 60839 standard.
- Installation file: The installer records which components were used, how the system is configured, and which performance level was achieved.
- Delivery documentation: a completion certificate or declaration of conformity signed by the installer and handed over to the client.
- Periodic inspection: For higher performance levels and certain sectors, an annual inspection by a recognized party is customary or required.
It is wise to ask in advance, when purchasing an access control system, what performance level the system achieves and what documentation the installer provides. This prevents disputes with insurers or clients afterwards. Contact us Contact Sellox for advice on a compliant access control system that suits your situation.
Frequently Asked Questions
What is the difference between the performance levels (grades 1 through 4) and how do I choose the right level for my situation?
The four performance levels range from Grade 1 (low risk, such as a small office space) to Grade 4 (very high risk, such as data centers or critical infrastructure). The choice depends on factors such as the value of the objects to be protected, the risk profile of the location, and the requirements of your insurer. Based on a risk analysis, a recognized security consultant or installer can determine which performance level is appropriate and required for your situation.
What happens if my existing access control system no longer complies with the applicable NEN standards?
A non-compliant system can lead to problems with damage claims, where insurers may refuse coverage, or to rejection during tenders and contract renewals. In some cases, an upgrade of specific components or a reconfiguration is sufficient to still meet the standard. Have a recognized installer perform a compliance check to determine which adjustments are necessary and what the most cost-effective route to standard compliance is.
As an organization, do I need to have knowledge of the NEN standards myself, or is that entirely the responsibility of the installer?
The technical responsibility for standard-compliant installation lies with the installer, but as the client, you would be wise to have basic knowledge of the applicable standards and performance levels. This allows you to specifically ask about the performance level to be achieved and the associated documentation when requesting quotations, and prevents unpleasant surprises later on. Always explicitly request a Declaration of Conformity and a detailed installation file upon completion.
How does NEN-EN 60839 relate to the GDPR regarding the logging of access events?
NEN-EN 60839 requires that access events be recorded and retained, but the GDPR sets limits on how long personal data — including access logs — may be retained and who has access to it. Organizations must balance both frameworks: complying with the logging obligation under the standard while maintaining a retention policy that is in line with the GDPR. It is advisable to document this in your privacy policy and discuss it with both your security installer and your privacy or compliance officer.
Do the NEN standards for access control also apply to small businesses or self-employed professionals with business premises?
There is no statutory minimum size at which NEN standards become mandatory; even small businesses can be affected, for example through their business insurer or a landlord who sets compliance as a condition. For a low-risk environment, Grade 1 or 2 will generally suffice, which is relatively simple and affordable to achieve. It always pays to inquire about the security requirements set by the insurer when taking out business insurance, so that you do not face uncovered losses afterwards.
How often must a compliant access control system be maintained or inspected?
For higher performance levels (Grade 3 and 4), an annual inspection by an accredited party is customary and, in many cases, contractually or sector-specifically required. For lower performance levels, periodic maintenance is strongly recommended to ensure operation and conformity, even though a formal inspection is not always mandatory. Additionally, ensure that software and firmware updates for controllers and readers are implemented in a timely manner, as outdated software can undermine the cybersecurity of the system and thereby jeopardize compliance with standards.
Can I combine access control systems from different brands and still comply with the NEN standard?
That is possible, but requires extra attention: each individual component must be certified at the required performance level, and the combination of components must demonstrably function correctly as a whole. Not all brands and systems are mutually compatible in terms of security and communication protocols, which increases the risk of weak links. Have an installer create a system design in advance in which interoperability and combined compliance with standards are explicitly ensured and documented.