Nedap Access Control Solutions (AEOS Technology)
Nedap AEOS is a web-based access control platform for organisations that need centralised control of doors, credentials, identities and audit trails across single or multiple sites.
AEOS is one of only three physical access control systems with Cyber Assurance of Physical Security Systems (CAPSS) accreditation and Automatic Access Control Systems (AACS) status from the National Protective Security Authority (NPSA).
That matters for UK buyers in government, critical infrastructure and other higher-assurance settings. But accreditation alone is not enough.
82% of medium and large UK businesses reported a cyber incident in the previous year, according to 2026 government research. So buyers need to look beyond basic door control and consider architecture, integrations, compliance, vulnerabilities, cost and long-term fit.
i2 Security & Fire Protection is a Nedap-approved installer with more than 35 years of UK security experience. This guide explains how Nedap access control works, where it fits best, and what to check before you buy a new system or upgrade an existing one.
- Design
- Installation
- Maintenance
- Consultancy
What is Nedap Access Control?
Nedap Access Control is a web-based physical access control and access management system, delivered through the AEOS platform. It manages identities, credentials, and permissions so you can control who goes where and when, and maintain a searchable audit trail of all access activity.
Nedap launched AEOS in 2000 and describes it as the world’s first fully web-based IP access control system. In the UK, AEOS holds CAPSS and AACS accreditation from the NPSA and is listed in the Catalogue of Security Equipment.
AEOS runs on a central server that holds the database, rules and configuration. The server communicates over a secure IP network with AEOS Blue controllers at each door or barrier. These controllers connect readers, locks and sensors to the platform and apply the access rules defined in AEOS.
The video below provides a brief visual overview of how Nedap AEOS access control adapts to changing security requirements, including scalability, integrations and centralised management.
AEOS is the core platform, but it becomes a complete access control system through the controllers, credentials, hardware and software modules connected to it.
What Are Nedap's Core Access Control Solutions?
Nedap’s core access control solutions are AEOS Access Control, AEOS Blue Controllers, Nedap Mobile Access, AEOS Locker Management, AEOS Intrusion, and Access AtWork.
AEOS Access Control
AEOS Access Control is the primary Nedap software application used by security teams day-to-day. It provides a browser-based interface to manage identities, issue and revoke cards or mobile credentials, and assign permissions across doors, zones, buildings and sites.
A rule engine sits at the heart of the AEOS Access Control platform. It allows access rights to change automatically based on time, location, role or data received from other systems. The University of Nottingham synchronises AEOS Access Control with its HR and student databases. Tens of thousands of access privileges are updated automatically as people join, move, or leave.
AEOS Access Control is designed as an open platform that fits into a wider security ecosystem. It offers certified integrations with video management, identity and time-and-attendance systems. AEOS links events directly to CCTV footage, HR records, and muster lists from a single interface.
AEOS Blue Controllers
AEOS Blue controllers connect each door to the platform. They link readers, locks, sensors and alarms to the AEOS server over IP and make access decisions locally based on the rules they receive.
Blue controllers cache card data and access rules, so they continue to grant or deny access during network or server outages. Doors continue to operate, and the controllers maintain event logs until connectivity is restored.
Blue controllers protect encryption keys in hardware using Secure Access Modules (SAMs). Each controller and reader gets its own digital certificate, so all communication between the server and the door hardware is encrypted and authenticated.
AEOS controllers support Power over Ethernet (PoE) and flexible Inputs/Outputs (I/O) and can drive turnstiles, secure holding areas and lifts in a scalable system design. Adding more controllers to the network scales the system as your needs grow.
Nedap Mobile Access
Nedap Mobile Access extends AEOS, enabling users to use phones and wearables as credentials. You can load corporate badges into Apple Wallet on iPhone and Apple Watch, and into Google Wallet on Android and Wear OS devices.
Users present their device to a Near Field Communication (NFC) compatible reader to open doors or barriers. With NVITE readers, Apple Wallet credentials work even when an iPhone is in power-reserve mode. No separate app needs to be opened.
Mobile credentials use a phone’s existing security (such as biometric unlock or PIN). You issue fewer physical cards, and have greater control because staff can’t lend their phone as easily as they can hand someone a plastic card. You can run mobile and physical cards together during rollout.
AEOS Locker and Asset Management
AEOS Locker Management uses the same identity and rule model as for doors. It suits workplaces with a hybrid workforce, hot-desking, and shared spaces that require secure storage for personal items, equipment, and documents.
AEOS treats lockers, cabinets and post boxes as managed asset objects. People use the same card or mobile credential they use on doors to open their lockers. This removes the need for separate keys or codes. All locker events are logged centrally alongside door events.
Administrators manage lockers from a web interface with real-time status visibility. You can allocate lockers permanently or dynamically, apply time schedules, define automatic release rules and monitor live status across large estates. Because locker management is part of AEOS, it uses the same security model, encryption and integration points as the core access control system.
AEOS Intrusion
AEOS Intrusion links intrusion detection panels with your access control system. Panels and keypads connect to the AEOS server so you can arm, disarm and handle alarms from the same interface you use for doors.
When intrusion and access are linked, AEOS only grants access if the relevant alarm zone is disarmed. This prevents accidental alarms when someone enters an armed area.
AEOS Intrusion hardware meets EN 50131 Grade 3 requirements, with supervised detector inputs, sounder and relay outputs and Transmission Control Protocol/Internet Protocol (TCP/IP) networking. Operators can see card events, door status, alarm states, and video in a single interface whilst delegating local control where needed.
Access AtWork
Access AtWork is Nedap’s cloud-native access control platform.
Unlike AEOS, which Nedap positions as its high-security on-premises security platform, Access AtWork suits organisations that want easier remote management and less infrastructure to maintain.
Access AtWork is accessible from anywhere and removes the need for customers to manage system updates on their own servers. It stores your data in certified EU data centres, complies with General Data Protection Regulation (GDPR), and works with existing hardware.
Choose Access AtWork if you want simpler administration, lower infrastructure overhead and a more straightforward route into cloud-based access control.
Long-Range Identification Systems
Nedap offers the following long-range identification systems for vehicle and perimeter access control.
- uPASS: Passive Ultra-High Frequency Radio Frequency Identification (UHF RFID) readers for long-range vehicle identification
- TRANSIT: Readers for secure vehicle and driver identification
- ANPR Lumo: Licence plate recognition for sites such as car parks, campuses, and logistics yards
Each of these products relies on the same AEOS architecture. The diagram in the next section shows how the platform, controllers, readers and integrations fit together.
What Does the Nedap AEOS System Architecture Look Like?
The diagram below shows the Nedap AEOS architecture.
The way Nedap built AEOS shapes many of its main benefits. It affects how securely the platform operates, how easily it integrates, and how well it scales over time.
What Are the Benefits and Key Features of Nedap AEOS?
The benefits and key features of Nedap AEOS include enhanced security, future-proofing, simplified audit/compliance, flexibility, improved emergency response, and reduced costs.
Enhanced Security for Critical Infrastructure
Nedap AEOS is a CAPSS- and AACS-assured access control system listed in the NPSA’s Catalogue of Security Equipment.
This independent evaluation against NPSA technical and cybersecurity requirements makes AEOS a strong option for the UK government, policing and other high-security sites.
Future-Proofed Technology Investment
Nedap has maintained backward compatibility for 15+ years, so older controllers can still work with the current AEOS software.
AEOS Upgrade Assurance gives you access to the latest AEOS software version. This helps keep your system current without hardware replacement.
Nedap supports each AEOS version for up to three years after release. Older versions can still run, but no longer receive bug fixes or patches.
Compliance and Audit Capabilities
AEOS records every access event so you know who used which credential, at which door, at what time. You can search these records to show who accessed specific areas during incidents or audits and gain clearer operational insight.
The system meets UK GDPR, NIS2 and ISO 27001 requirements through configurable retention policies and role-based administration. You can anonymise or delete personal data whilst keeping access event records for compliance reporting.
Flexibility Without Vendor Lock-In
AEOS integrates with over 100 third-party manufacturers.
Millennium Bridge House in London deployed AEOS alongside its existing Panasonic CCTV and alarm systems rather than replacing working equipment. This reduced project costs whilst creating a unified security management system.
You can add new technologies as they emerge (e.g., facial recognition, analytics, mobile access) rather than being limited to a single vendor’s development schedule.
Improved Emergency Response
AEOS helps improve emergency response by showing who’s in your building based on card reader activity.
The system can unlock doors automatically during fire alarms to support evacuation. You can also trigger instant lockdown across all sites when threat levels rise, whilst keeping access open for emergency responders.
Lower Total Cost of Ownership
AEOS eliminates rekeying costs. When employees leave or lose their cards, you revoke their electronic credentials instantly rather than paying hundreds of pounds to rekey doors.
Organisations with thousands of users integrate AEOS with HR databases so that access credentials are updated automatically when people join, change roles, or leave. This removes manual data entry, prevents access rights errors and frees staff for higher-value work.
AEOS controllers work with existing readers and locking hardware. You can adapt the system by replacing the controllers whilst keeping the readers, cabling, and door furniture. The software includes core functions such as the rule engine and Application Programming Interface (API), without per-feature licensing.
Those benefits matter, but they do not remove the need for secure design, deployment and maintenance. Like any networked access control system, AEOS still has vulnerabilities that need to be understood and managed.
What Are the Nedap Access Control System Security Vulnerabilities?
The main vulnerabilities in Nedap access control systems include network exposure, delayed software or firmware updates, poor credential management, and physical attacks on readers, locks, or cabling.
Network Exposure
Nedap AEOS, just like any IP-based access control system, depends on secure deployment and ongoing maintenance to run properly.
Attackers may target servers, controllers, or management interfaces on poorly secured networks through insecure remote access, poor segmentation, or weak administrative controls.
Delayed Software and Firmware Updates
Networked access control platforms rely on software, firmware, and connected devices that need regular updates.
Delayed patching can leave older components in service for longer than they should be. This will increase the risk of known security weaknesses being exploited or system performance falling behind current security standards.
Poor Credential Control
Lost cards, shared credentials, cloned tokens, or weak enrolment processes all pose a threat to the security of your access control system.
AEOS helps reduce this risk through encrypted communications and centralised credential management, but operators still need fast revocation, clear joiner-mover-leaver processes, and regular access reviews.
Physical Security
Physical tampering with access points is a concern for most security systems.
Secure controller design, encrypted communications, monitored inputs, and good installation all help reduce risk.
However, readers, locks, and cabling still need proper physical protection. This includes secure mounting, tamper protection, protected cable routes, and door hardware that resists forced entry or interference.
How to Reduce Risk
The vulnerabilities mentioned above are not unique to Nedap. They’re common to most networked access control systems. You can reduce them by following the steps below.
- Use AEOS’s built-in security features to strengthen your baseline protection
- Harden the network to reduce exposure and limit unauthorised access
- Restrict administrator permissions to the minimum each user needs
- Apply software and firmware updates promptly
- Monitor audit trails for unusual activity and potential security issues
- Revoke lost credentials quickly and investigate suspicious events without delay
Even when those risks are well managed, they still shape how a Nedap system is designed, supported and priced. That is why you need to look at cost and licensing alongside security.
How Much Does Nedap Access Control Cost and How Does Licensing Work?
Nedap does not publicly list prices because costs depend on the size and complexity of the system.
The main costs are the number of doors, controllers, readers, credentials and integrations. Server requirements, along with the level of installation, commissioning, training, and ongoing support, will also influence the price.
Nedap typically tailors licensing to the software functions and overall system design rather than selling it as a single off-the-shelf package. That means the final price reflects your site’s layout, operational needs, and integration requirements, not a fixed standard product.
For small and medium enterprises (SMEs), Nedap is usually cost-effective only when your site needs more than basic door control. Start with a focused deployment, keep the scope tight, and expand only where the added functionality is justified.
If your requirements are simple, it’s worth comparing Nedap with other access control systems that may be a better fit.
What are the best alternatives to Nedap access control?
The table below shows the best alternatives to Nedap access control for specific needs.
| Alternative | Best Fit |
|---|---|
| Paxton | Best for simpler commercial and SME-style deployments |
| TDSI | Best for UK enterprise, education, and the public sector |
| Vanderbilt | Best for larger integrated security needs |
| Brivo | Best if you want modern cloud-based access control |
| Grosvenor | Best if you want an established UK access control brand |
How does Nedap AEOS compare with LenelS2?
Nedap AEOS and LenelS2 (from Honeywell) are both enterprise access control platforms.
Nedap AEOS is best suited to UK buyers who value NPSA CAPSS, AACS assurance, and a security-led platform.
LenelS2 is better suited for organisations that need broader deployment options. These include on-premises, browser-based and cloud-based options through platforms such as OnGuard, NetBox, Elements and OnGuard Cloud.
How does Nedap AEOS compare with Paxton in terms of security features?
Nedap AEOS is usually the better fit for UK buyers who want high-security access control, as it holds NPSA CAPSS and AACS certifications.
Paxton is usually the better fit for buyers who want simpler access control. Its mainstream commercial features include centralised management, smartphone credentials, video integration, and multi-site support through Net2 and Paxton10.
How Does Nedap AEOS Compare with Genetec?
Nedap AEOS and Genetec are both enterprise access control platforms.
Nedap AEOS is usually the stronger choice for higher-assurance UK sites. Genetec is usually the better option where flexible deployment and a wider unified security platform matter more.
General comparisons between Nedap and other brands are useful, but the sector you operate in matters too. In healthcare, for example, access control must support complex permissions, sensitive areas, and rapid emergency response.
Is Nedap AEOS suitable for healthcare facilities?
Nedap AEOS is well-suited to healthcare facilities. It can handle flexible security levels, complex authorisations, vehicle access, centralised control, and integration with systems such as lifts, video, alarms, and fire detection.
This supports hospitals and clinics that need staff-only zoning, controlled access to sensitive rooms, shift-based permissions, locker management, and rapid emergency response.
Healthcare case studies from AZ Alma and AZ Zeno show that AEOS supports keyless access, patient QR code access, staff lockers, emergency settings, and vehicle entry.
Healthcare is one example of where AEOS is a good fit. But in any setting, security teams still need a clear process for handling reader faults, offline controllers and credential issues.
How Do You Troubleshoot Common Nedap AEOS Issues?
Most Nedap AEOS issues fall into a small number of common access control faults. These include reader faults, offline controllers, credential problems, sync failures and unclear event data.
Working through the following basic checks will help identify the cause of most common faults.
- Identify the fault by confirming whether the problem affects a reader, a controller, a credential, a sync process, or an event log
- Check the basics by reviewing power, network status, cabling, and reader or controller connectivity
- Verify the credential by confirming that the card or mobile credential is active, assigned correctly, and still valid in AEOS
- Review recent changes by checking for updates, configuration changes, or integration changes that may have affected the system
- Inspect the event log to see what happened, when it happened, and whether the issue is isolated or repeated
- Escalate the issue if it affects multiple doors, a controller stays offline, credentials keep failing without a clear cause, or the evidence points to deeper software, firmware, or integration faults
If anything is unclear at any stage, i2 Security & Fire Protection is here to support you from the first diagnosis through to resolution.
Why Choose i2 Security & Fire Protection for Your Nedap Installation?
i2 Security & Fire Protection is a Nedap-approved installer with 35 years of security system experience. Our Nedap-certified engineers are experts in the following.
- System Design: Site surveys, door scheduling, credential strategy, network architecture and integration planning tailored to your security requirements and operational workflows
- Installation: AEOS server deployment, Blue controller installation, reader and lock integration, network configuration and commissioning. We work with your existing infrastructure, where possible, to reduce costs
- Integration: Connection to your CCTV, intrusion panels, HR systems and time-and-attendance platforms. We handle API configuration and testing
- Training: Operator and administrator training on AEOS interface, credential management, rule engine configuration and reporting functions
- Maintenance: Preventive maintenance contracts, software updates, firmware upgrades, troubleshooting and technical support with emergency callout and remote diagnostics
- Consultancy: Security audits, system upgrades, multi-site rollout planning and compliance guidance for UK GDPR, NIS2 and ISO 27001 requirements.
As a Nedap-approved partner, we have direct access to technical support and receive priority updates on software releases, hardware updates, and security patches. This means your system gets prompt updates and expert troubleshooting when needed.
Frequently Asked Questions
Where can you find Nedap AEOS manuals and documentation?
Contact i2 Security & Fire Protection, and we’ll help you source the Nedap AEOS manuals and documentation you need.
Nedap provides a mix of public and partner-only documentation.
Public documents can include specification sheets, guides, and some integration manuals. You can typically access firmware and more technical documentation through the Nedap partner portal.
How much does AEOS Upgrade Assurance cost?
AEOS Upgrade Assurance does not have a fixed public price. Nedap calculates the cost each year based on your AEOS software licence.
Call the expert i2 Security team today, and we will check your current setup and explain the options available to you.
What is Open Supervised Device Protocol (OSDP)?
OSDP is an access control communications standard developed by the Security Industry Association (SIA).
It was approved as IEC 60839-11-5, and its Secure Channel mode encrypts data between readers and controllers.
Nedap AEOS Blue controllers support OSDP Secure Channel for reader-to-controller communication.
How do you add a new user in Nedap AEOS?
In AEOS, you add a new user by creating an identity, entering the user’s details, assigning permissions, and linking a credential.
For exact steps, check your AEOS version and documentation, or give us a call.
What are the different types of access control?
The main types of access control are credential-based, permission-based, physical and logical systems. For more details, read our access control installation guide.
Where is Nedap based?
Nedap is based in Groenlo, the Netherlands, with offices and subsidiaries worldwide, including the UK.
Where can you find Nedap's access control data privacy policy?
Nedap’s privacy policy is in the Privacy Statement on the main Nedap website.
AEOS also includes privacy-related features, such as anonymisation and audit controls, but these do not replace the company’s formal privacy policy.
Why Nedap AEOS Is a Strong Fit for High-Security UK Sites
Nedap AEOS is one of only three CAPSS-accredited physical access control systems in the UK. For government, critical infrastructure, and other higher-assurance environments, this provides buyers with an independently tested system that supports encrypted authentication, clear audit trails, and a wide range of integrations.
AEOS can connect with existing CCTV, intrusion and HR systems, so sites do not need to replace working infrastructure to upgrade access control. It also lets you upgrade in stages, using software and controller changes instead of replacing the whole system at once.
i2 Security & Fire Protection is a Nedap-approved installer. We design, install, and support AEOS systems across the UK, providing advice on fit, scope, integration, and long-term support.
Ready to discuss your access control requirements? Contact the team for a site survey and detailed proposal.