Ask any manufacturer and the Wiegand era ended years ago. Every current reader line speaks OSDP, every current panel supports it, and Secure Channel encryption has been in the spec long enough to buy a drink. Then walk a site commissioned in the last 24 months and count how many readers are still wired as Wiegand, transmitting card data in the clear over a protocol from the 1980s that can be defeated with a device that fits behind a faceplate.
The migration everyone agreed on is the migration nobody finished, and I find the reasons more interesting than the technology.
Why Wiegand won't die
The honest answers, collected from years of watching this play out on real projects:
- It works on day one. Wiegand is 5 wires and no configuration. OSDP needs addressing, baud settings, and a Secure Channel key ceremony, and someone on the crew has to understand all of it. Under schedule pressure, the protocol that commissions itself wins.
- The panel supports it, sort of. Plenty of installed controllers accept OSDP but treat it as a checkbox. Multi-drop behaviour, supervised reader status, tamper reporting, and key management vary enough between platforms that integrators default to what behaves identically everywhere, which is Wiegand.
- Nobody specified it. Consultants copy the reader schedule from the last job. If the spec doesn't say "OSDP with Secure Channel enabled and verified," the low bid decides the wiring, and the low bid picks the protocol with zero configuration hours in it.
- The retrofit math looks scary. Sometimes it is, but the fear is usually pointed at the wrong line item. The reader swap and panel config are the easy part. Whether the existing cable can carry RS-485 is the real question, and it deserves its own section below.
- Secure Channel gets skipped even where OSDP exists. This is the quiet scandal. OSDP without Secure Channel is still plaintext, and sites proudly running "OSDP" with encryption never enabled have upgraded their connector, not their security.
The cable behind the wall
Here's the failure I keep seeing on retrofits, and it's the source of half the "OSDP is flaky" complaints in the field: OSDP dropped onto legacy reader cable that was never built for it.
RS-485, the transport underneath OSDP, is differential signalling. Its noise immunity comes from the twist in the pair; the 2 conductors pick up interference together and the receiver subtracts it out. Take away the twist and you've taken away the physics. The installed base is full of exactly that: 22/8 station wire, unshielded, non-twisted, pulled in the Wiegand era when none of it mattered because Wiegand barely qualified as a data protocol.
Run OSDP over 300 feet of untwisted 22/8 and it'll often commission clean on a quiet afternoon. Then the site goes live, the VFDs and fluorescent ballasts do what they do, and the channel spends its life throwing retries: readers dropping offline overnight, LEDs lagging card presentations, tamper alarms ghosting, links renegotiating at random. The techs blame the protocol or the panel. The protocol is fine. Nobody consulted the physics.
What proper looks like: a genuine twisted pair for the data lines, shielded for anything beyond short runs or noisy environments, with the shield grounded at one end. Daisy-chain the multidrop rather than star-wiring it from a junction box, and terminate long runs correctly. When a long marginal run misbehaves, drop the baud rate before blaming the hardware. Plenty of composite door cable already contains a suitable twisted pair, which is why a cable audit belongs at the front of every migration quote: some sites re-terminate onto the pair they already own, and some genuinely need a re-pull. The expensive mistake is finding out which one you are after the readers are on the wall.
What it actually costs a site
The attack against Wiegand isn't theoretical and hasn't been for over a decade: a cheap interception device installed behind a reader in under a minute harvests every credential presented until someone finds it, and nobody finds it, because nothing supervises the line. Any facility that's spent money on smart credentials while running them over Wiegand has encrypted the card and broadcast the conversation.
Supervision cuts the other way too. OSDP tells the panel when a reader goes offline or gets tampered with. Wiegand tells the panel nothing, ever. Half the value of the migration is just knowing your readers are still yours.
Where the excuses stop
For new construction in 2026, there's no defensible reason to land a Wiegand reader. Full stop, and I'll argue with anyone's estimator about it. For existing sites, the pragmatic sequence I'd push: perimeter and high-security doors first, Secure Channel enabled and verified with keys actually rotated off default, then interior doors on the natural replacement cycle. Demand the commissioning report show Secure Channel status per reader, because "we ran OSDP" without that line means less than integrators want it to.
The spec sheet war ended long ago. The one on the wall is still being lost, one value-engineered door at a time.