# Control physical access credentials from issue through revocation

> A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and revocation operate as one controlled lifecycle.

- Canonical URL: https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-07-28T14:22:00+00:00
- Modified: 2026-07-28T14:22:00+00:00
- Last reviewed by DSE: 2026-07-28
- Resource type: Guide
- DSE priority: Advisory
- Topics: Access Control
- Reading time: 3 minutes

## What you need to know

A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and revocation operate as one controlled lifecycle.

## Potentially affected

Organizations that issue employee, contractor, visitor, temporary, card, fob, smart-card, emergency, test, or mobile credentials through a physical access control system.

## DSE recommendation

Map the credential lifecycle to named owners and measurable time limits, then reconcile people, credentials, access levels, lifecycle events, and physical inventory with defensible evidence.

## Article

## Source fact: authorization and credentials require continuing control

NIST [SP 800-53 Rev. 5 Update 1](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) provides a catalog of security and privacy controls that organizations tailor to their risks. Physical and Environmental Protection control PE-2 addresses authorizing physical access, maintaining an authorized-access list, issuing credentials, reviewing access, and removing people from the list when access is no longer required. PE-3 addresses enforcing physical access and maintaining relevant access records. The publication is mandatory in specified federal contexts, but it is not automatically a compliance requirement for every private organization.

The underlying principle applies broadly: a card’s technology cannot compensate for stale authorization. One person may hold several legitimate credentials, including a mobile instance, but each credential must remain traceable to a verified identity, sponsor, status, access approval, issue event, and expiration or review rule.

## Separate lifecycle responsibilities

The authoritative personnel or contractor owner confirms relationship status. A manager sponsors business need. The protected-area owner approves sensitive-space access. The credential administrator encodes, issues, suspends, replaces, and revokes credentials. Physical security defines policy, reconciles records, monitors exceptions, and tests performance. Avoid requester self-approval and shared badge-holder records.

Before issue, authenticate the request and recipient, check for duplicate or active credentials, approve the least access needed, and document special doors, schedules, anti-passback exceptions, and expiration. Record the unique credential identifier, technology, issuer, recipient, activation, sponsor, and acknowledgement. Test an intended door and a representative denial without recording reusable credential secrets in the ticket.

## DSE recommendation: make changes event-driven

- Connect joiner, mover, leave, contract-end, and termination events to the credential process with defined completion targets and acknowledgements.

- On a role or location change, remove access tied only to the prior assignment. Require fresh approval for restricted areas instead of copying the old profile wholesale.

- On reported loss, authenticate the reporter, disable the affected credential promptly, review relevant activity, issue a different identifier, and document investigation or notification decisions.

- At departure, coordinate timing with the authorized personnel process, revoke every card, fob, mobile instance, and associated permission, recover property, and verify completion. Property return does not replace electronic revocation.

- Review active credentials against authoritative people, sponsor, access-level, expiration, inventory, and activity records. Include contractors, visitors, emergency badges, guard credentials, test cards, and dormant mobile instances.

- Control blank stock, returned cards, printers, keys, mobile licenses, and destruction. Prevent a returned or replaced identifier from silently remaining active.

Measure median and maximum revocation time, credentials without current sponsors, overdue temporary access, dormant active credentials, lost-credential replacements, inventory differences, and unresolved privileged access. Set review frequency by risk: a data center, cash room, laboratory, executive area, or round-the-clock entrance may justify more frequent review than a public lobby. Every exception should have a reason, accountable owner, expiration, and closure evidence.

## Primary reference

- Name: NIST SP 800-53 Rev. 5 Update 1: Security and Privacy Controls
- Authority: National Institute of Standards and Technology
- URL: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- Source publication date: 2020-09-23

## Citation and use

Preferred citation: “Control physical access credentials from issue through revocation,” DSE Security, https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
