ONVIF Profile D: keep access decisions in the right place when integrating peripherals

Profile D standardizes communication between access peripherals and a securely located client. It does not certify the complete door, credential, or life-safety design.

Executive summary

What you need to know

Profile D standardizes communication between access peripherals and a securely located client. It does not certify the complete door, credential, or life-safety design.

Potentially affected

Organizations integrating readers, biometric devices, keypads, locks, sensors, displays, door phones, recognition cameras, access-control units, or management platforms.

DSE recommendation

Document where credentials, rules, and decisions reside, verify exact Profile D conformance, and separately test network, door, credential, and life-safety behavior.

What Profile D connects

Source fact: ONVIF Profile D addresses interfaces for access-control peripheral devices. The official scope includes token readers for cards, keys, mobile phones, or bar codes; biometric readers; keypads; sensors; locks; displays; LEDs; and cameras used for iris, facial, or license-plate recognition.

The profile separates capture from the access decision. A peripheral device captures a credential identifier and passes it to a securely located Profile D client, such as an access-control unit or management system. The client holds the access rules, schedules, and credentials, decides whether access should be granted, and can command the peripheral to grant or deny access, show a message, or request another input such as a PIN.

A conformant client can configure information such as the door or access point for which a device is responsible. It can also configure allowed or blocked credential identifiers when the device supports that capability. Profile D complements Profiles A and C and can be combined with Profiles M and T in an integrated video and access-control design.

Where the profile stops

Profile D defines an interface; it does not certify a complete opening. It does not establish lock suitability, egress behavior, fire-code compliance, power capacity, battery runtime, cable condition, credential cryptography, biometric accuracy, network segmentation, or the security of every stored record. A profile claim also belongs to an exact product and firmware or software version.

Conditional capability matters. A product type appearing in the Profile D scope does not mean every conformant device provides every recognition, local-list, display, or integrated-video function. Project requirements must be matched to the official feature documents and then tested with the intended client.

DSE integration checklist

DSE recommendation: This is DSE operational synthesis, not an ONVIF door-hardware or code-compliance procedure.

  1. Diagram each peripheral, securely located client, controller, server, door, network path, and stored-data location.
  2. Identify which component captures an identifier, stores rules, makes the decision, and operates the output.
  3. Verify exact Profile D records and feature documents for both client and device.
  4. Test valid, invalid, expired, blocked, and unknown credentials plus any PIN or second-input workflow.
  5. Test loss and restoration of the client or network, including documented offline behavior.
  6. Verify lock, sensor, message, audit, and video association functions required by the design.
  7. Validate power, wiring, egress, fire alarm, accessibility, and life-safety behavior through the appropriate qualified process.
  8. Retain the tested versions, results, exceptions, and recovery steps with commissioning records.

Official references

Primary reference

Review the official source

ONVIF — Profile D · Verified July 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE