comparison

125kHz vs 13.56MHz: Choosing Access Cards and Readers

125 kHz cards are cheap but easy to clone; 13.56 MHz cards add memory and, on DESFire-class chips, AES security. Compare range, chips, security and migration.

Key takeaways

  • 125 kHz and 13.56 MHz both use near-field inductive coupling, so read range on a wall reader is similar: a few centimeters.
  • Most 125 kHz access cards (EM4100, prox-style) send a fixed ID with no cryptography and can be copied onto a rewritable T5577 blank.
  • 13.56 MHz is only more secure when the reader authenticates the card (for example AES-128 on MIFARE DESFire EV2/EV3), not when it reads the UID alone.
  • Dual-frequency readers and hybrid cards let a site move from 125 kHz to 13.56 MHz without re-issuing every card at once.
  • Specify cards and readers as a set: frequency, chip, output format and number convention must all match the controller.

125 kHz (LF) access cards are inexpensive and still widely installed, but most of them carry a fixed ID with no cryptography and can be copied in seconds. 13.56 MHz (HF) cards communicate faster, hold more data and, on chips such as MIFARE® DESFire® EV2/EV3, support AES-128 authentication, which is why new projects usually specify 13.56 MHz and use dual-frequency readers to migrate existing sites. Read range on a wall reader is similar for both, so the real decision is about security, compatibility and what your controller expects.

Quick comparison: range, security, memory and cost

125 kHz (LF) 13.56 MHz (HF)
Carrier frequency 125 kHz (LF band; animal ID uses 134.2 kHz) 13.56 MHz (HF ISM band)
Coupling Inductive, magnetic near field Inductive, magnetic near field
Common standards and formats EM4100 (de facto), HID Prox®-compatible FSK formats; ISO 11784/11785 for animal ID ISO/IEC 14443 Type A/B, ISO/IEC 15693, NFC Forum tag types
Typical wall-reader range About 3–10 cm About 2–6 cm (ISO/IEC 14443 cards)
Card-to-reader data rate About 2 kbit/s (EM4100 at RF/64) 106 kbit/s base rate, up to 848 kbit/s (ISO/IEC 14443)
Memory 64-bit read-only frame (EM4100); 512 bits (EM4305, rewritable) 144 bytes user memory (NTAG213) to 8 KB (DESFire EV3 8K)
Cryptography None on common access chips None or 32-bit password (NTAG21x); Crypto1 (MIFARE Classic, broken); AES-128 (DESFire EV2/EV3, NTAG 424 DNA)
Several cards in the field No anti-collision on EM4100 Anti-collision defined in ISO/IEC 14443-3
Readable by an NFC phone No Yes for most types (MIFARE Classic support varies by handset)
Relative card cost Lowest Low (NTAG, MIFARE Classic) to higher (DESFire, CPU cards)
Clone resistance Low Low when only the UID is read; high with AES authentication

Two things the table cannot show. First, “125 kHz” is a frequency band, not a protocol: an EM4100 reader decodes amplitude-modulated (ASK) Manchester data, while prox-style cards use frequency-shift keying (FSK). An EM-only reader will not read a prox card, and the reverse is also true. Second, a 13.56 MHz card is only as secure as the way the reader reads it, which the security section below covers.

How LF and HF coupling work

Both bands use passive cards powered by the reader’s magnetic field. The reader drives an antenna coil with alternating current, and the card’s coil sits in that field like the secondary winding of a loosely coupled transformer. The card rectifies the induced voltage to run its chip, then answers by switching a load across its coil (load modulation), which the reader detects as small changes in its own antenna current.

The wavelength is about 2,400 m at 125 kHz and about 22 m at 13.56 MHz. A read distance of a few centimeters is a tiny fraction of either, so neither band radiates a far-field wave the way UHF RFID does. In the near field, the magnetic field falls off roughly with the cube of distance, which is why antenna size and card orientation matter more than transmit power, and why doubling range takes far more than doubling power.

The higher carrier has three practical consequences:

  • Speed. ISO/IEC 14443 starts at 106 kbit/s (the carrier divided by 128), roughly 50 times the common EM4100 rate. That headroom is what makes challenge-response cryptography practical in the half-second a user holds up a card.
  • Anti-collision. ISO/IEC 14443-3 defines how a reader selects one card when a wallet holds several. EM4100 cards simply repeat their ID, so two in the field corrupt each other’s data.
  • Environment. LF passes through water and body tissue more easily, one reason the 134.2 kHz band is used for animal ID. Both bands detune when a card or reader sits directly on metal, so use spacers or on-metal designs.

125 kHz chips: EM4100, T5577 and prox formats

EM4100 and compatibles (such as TK4100) are read-only. Each chip holds a fixed, pre-programmed 64-bit frame: 9 header bits, 40 data bits arranged as 10 rows of 4 bits with a parity bit per row, 4 column-parity bits and a stop bit. The 40 data bits are usually written as 10 hex digits, an 8-bit version or customer field followed by a 32-bit ID. The card transmits this frame over and over whenever it is powered. There is no command set and nothing to authenticate.

T5577 is a rewritable LF chip with configurable modulation and data rate. It can be programmed to emulate EM4100 and several prox-style formats, which is useful for issuing cards that match an existing number range. It is also the standard blank for cloning.

EM4305 is a 512-bit read/write chip, widely used for ISO 11784/11785 (FDX-B) animal ID and in credentials that need a rewritable ID. For a side-by-side of these three chips, see EM4100 vs T5577 vs EM4305.

Prox-style formats (cards compatible with HID Prox®) use FSK modulation and carry a Wiegand-structured number, most often 26-bit but also longer formats. A reader has to support both the modulation and the format, so “125 kHz” on a datasheet tells you very little about compatibility on its own.

13.56 MHz chips: MIFARE Classic, DESFire, NTAG and CPU cards

  • MIFARE Classic 1K/4K: ISO/IEC 14443-3 Type A, with 1 KB or 4 KB of memory divided into sectors protected by 48-bit keys and the proprietary Crypto1 cipher. Crypto1 was publicly broken in 2008, and sector keys can now be recovered with low-cost tools. It remains very common in installed systems.
  • MIFARE DESFire EV2/EV3: ISO/IEC 14443-4 Type A, with a multi-application file system, AES-128 authentication and encrypted or MAC-protected communication. EV3 is offered in 2, 4 and 8 KB versions. It supports key diversification and an optional random UID.
  • NTAG213/215/216: NFC Forum Type 2 tags on ISO/IEC 14443A with 144, 504 or 888 bytes of user memory, a 7-byte UID and optional 32-bit password protection. They suit NFC links and low-security uses. NTAG 424 DNA adds AES-128 and a per-tap cryptographic message (SUN), so a backend can check that a tap is genuine.
  • CPU (smart) cards: microprocessor cards running an operating system, using ISO/IEC 14443-4 (Type A or B) with ISO/IEC 7816-4 commands. Security depends on the card application and how its keys are managed.
  • ISO/IEC 15693 vicinity cards: designed for longer range with larger antennas, common in libraries and industrial ID. A 14443-only reader will not read them.

Other 13.56 MHz families, such as iCLASS®, Seos®, LEGIC® and FeliCa®, use their own security layers. A reader must support that technology specifically; a generic reader may return only a card serial number, or nothing. Our MIFARE Classic vs DESFire guide covers the security and cost trade-offs between the two most common access-control chips.

How to tell if a card is 125 kHz or 13.56 MHz

  1. Phone test. Turn on NFC and hold the card to the back of the phone with an NFC tag-reading app open. Phones operate only at 13.56 MHz, so if the app detects the card it is HF, and it usually shows the chip type (for example MIFARE Classic 1K or NTAG215) and the UID. No response usually means LF, although a few HF technologies are not recognized by phone NFC stacks.
  2. Light test. Hold a thin PVC card in front of a bright light. An LF card shows a small, densely wound coil of fine wire with many turns, often round. An HF card shows a few turns of antenna running close to the card edge, usually rectangular.
  3. Markings. LF cards are often marked “EM”, “ID” or “TK4100”, or carry two printed numbers (a 10-digit number and one in the form “123,45678”). HF cards may be marked “IC”, “M1”, “1K”, “NFC” or “DESFire”. Treat markings as a hint, not proof.
  4. Reader test. A dual-frequency USB desktop reader shows which band responds and the number it reads, which also tells you what format your controller is likely receiving.

Some cards contain both an LF and an HF chip (hybrid cards). They respond to a phone and to an LF reader alike, so check each band separately with a reader that can be set to one band at a time.

Security: why 125 kHz and UID-only cards are easy to copy

An EM4100 or prox-style card sends its complete ID to any reader that powers it, with no authentication. A handheld copier, or a concealed reader near a queue, can capture the ID, and writing it to a T5577 blank produces a working duplicate. The controller has no way to tell the copy from the original.

Moving to 13.56 MHz does not fix this if the reader only reads the UID. The UID travels unencrypted during anti-collision, and UID-changeable “magic” cards and card emulators reproduce it. Reading MIFARE Classic sector data helps little, because Crypto1 keys can be recovered.

Clone resistance comes from the reader proving that the card holds a secret key it never reveals:

  • DESFire EV2/EV3 with AES-128 and diversified keys, where each card’s key is derived from a master key and the card’s UID, so one compromised card does not expose the rest. The reader reads the credential from an application file, and random UID can be enabled so the UID is useless to an attacker.
  • NTAG 424 DNA with SUN messages checked by a backend.
  • CPU cards running a managed card application.

Encrypted anti-clone readers perform this authentication and pass only the resulting credential number to the controller. Protect that link too: Wiegand sends the number in clear, while OSDP v2 with Secure Channel encrypts reader-to-controller traffic with AES-128.

Migrating with dual-frequency readers and cards

Most sites cannot replace every card on one day. A dual-frequency reader reads 125 kHz EM cards and 13.56 MHz ISO/IEC 14443A cards and reports both on the same Wiegand or RS485 output, so old and new cards work side by side. Multi-technology readers extend this to more credential types, and OEMs building their own terminals can use multi-technology reader modules.

Check these points before rollout:

  • Legacy numbers must not change. The new reader has to output existing LF cards in the same bit format and number convention as the old one, or every enrolled user fails. Test a sample of current cards against the controller first.
  • HF UIDs and Wiegand length. A 4-byte UID is 32 bits and fits a Wiegand 34 frame. Wiegand 26 carries only 24 data bits, so the reader drops a byte, which can produce duplicate numbers. 7-byte UIDs (NTAG and many DESFire cards) do not fit either format and are truncated or mapped in reader-specific ways.
  • Byte order. Readers differ on whether they send UID bytes most-significant or least-significant first. The same card can therefore appear as two different numbers on two brands of reader.
  • Hybrid cards. A card with both an LF chip and an HF chip (for example EM4100 plus MIFARE Classic 1K or DESFire) lets users carry one card during the transition. Confirm which chip the reader reports when both respond.

A typical sequence: audit the credentials in use, replace readers with dual-frequency units, issue HF or hybrid cards as people join or cards wear out, then switch off LF reading once the last LF card is retired (on readers that allow it). Where the controller supports it, move the reader link to OSDP Secure Channel at the same time.

Buying cards and readers as a matched set

When a card “doesn’t work”, the cause is usually a mismatch somewhere between card, reader and controller. Confirm each item before ordering:

  • Frequency and chip family of the existing cards: EM4100 vs prox-style FSK; MIFARE Classic vs DESFire vs NTAG
  • What the reader reads: UID only, sector or file data, or an authenticated credential
  • Output interface and format the controller expects: Wiegand 26 or 34, RS485, OSDP, or USB keyboard emulation
  • Number convention: decimal or hex, byte order, leading zeros, and the printed number format (10-digit or “123,45678”)
  • For secure cards: who generates and holds the keys, whether keys are diversified, and how keys are loaded into readers
  • Form factor: ISO/IEC 7810 ID-1 card (85.60 × 53.98 mm), clamshell card, key fob, wristband or sticker
  • Printing: thin PVC cards for direct-to-card printers; clamshell cards are too thick for most card printers
  • Numbering: sequential numbers or a specified range if you are adding to an existing system
  • Sample test: the reader and card tested together with your controller before the bulk order

Browse access control readers and cards, key fobs and wristbands with that list in hand, and order samples of both together.

Next steps

Send us a sample card or photos of both sides, your controller model and the reader output you use today. We will confirm the frequency, chip and format, recommend a matched reader and card set, and test them together before dispatch. Request a quote or samples and we will reply within 24 hours.

Frequently asked questions

Can phones read 125 kHz cards?

No. Phone NFC works only at 13.56 MHz, so a phone cannot read an EM4100 or prox-style 125 kHz card. Reading those needs a dedicated LF reader, for example one connected by USB or Bluetooth.

How can I tell if my access card is 125 kHz or 13.56 MHz?

Hold it to an NFC-enabled phone running a tag-reading app. If the phone detects it, the card is 13.56 MHz; if not, it is most likely 125 kHz, which a dual-frequency desktop reader or the coil shape seen against a bright light can confirm.

Is 13.56 MHz always more secure than 125 kHz?

No. If the reader only reads the card UID, a 13.56 MHz card can be copied almost as easily as a 125 kHz card. Security comes from cryptographic authentication, such as AES-128 on MIFARE DESFire EV2/EV3 with diversified keys.

Will any 125 kHz reader read any 125 kHz card?

No. EM4100-type cards use amplitude (ASK) modulation while prox-style cards use frequency-shift (FSK) modulation and different data formats, so the reader must support the specific technology. Check the chip or format, not just the frequency.

Can one reader read both 125 kHz and 13.56 MHz cards?

Yes. A dual-frequency reader contains both an LF and an HF front end and reports either card over the same output, such as Wiegand or RS485. That lets a site issue 13.56 MHz cards while existing 125 kHz cards keep working.

Which has the longer read range, 125 kHz or 13.56 MHz?

On standard wall readers they are similar, typically about 3–10 cm for 125 kHz cards and 2–6 cm for ISO/IEC 14443 cards. Much longer range calls for larger antennas or a different technology such as UHF.

Want a second opinion on your spec?

Send us your controller, credential type and environment — we'll recommend compatible hardware and quote within 24 hours.

Products mentioned

Hardware for this job

CR-180

Touch Keypad RFID Card Reader, Wiegand 26/34/66

Square 89.5 mm touch-keypad reader for card plus PIN, reading up to 9 cm, in EM, MIFARE, sector-read, FeliCa and dual-frequency versions with Wiegand output.

125 kHz, 13.56 MHz or dual (by version)Wiegand 26/34/66Up to 9 cm
Details →
CR-300

OSDP & Wiegand Metal Card Reader, 125 kHz + 13.56 MHz + BLE

Slim 86 × 86 mm metal reader with OSDP v2.2, RS485, Wiegand and Bluetooth LE 5.3. Reads 125 kHz EM plus MIFARE, DESFire EV1–EV3, ICODE and FeliCa; IP65.

125 kHz + 13.56 MHz + 2.4 GHz (BLE 5.3)OSDP v2.2, RS485, Wiegand0–3 cm
Details →
CR-190

Wiegand 26/34 RFID Card Reader, EM, MIFARE or Dual

Card-only 89.5 mm square reader with Wiegand 26/34 output (66 on upper tiers), in EM, MIFARE, sector-read, FeliCa and dual-frequency versions.

125 kHz, 13.56 MHz or dual (by version)Wiegand 26/34/6612 V DC ±5%, ≤ 200 mA
Details →
CR-130

Metal Keypad Wiegand Card Reader with Doorbell Button

Card-plus-PIN reader in a 120 × 80 mm metal housing with physical keys, a doorbell button and Wiegand 26/34/66 output to your controller.

125 kHz (-E) or 13.56 MHz (-M, -MS, -MS-FC)Wiegand 26/34; 66 on -MS tiersPhysical keys + doorbell button
Details →

Keep reading

Tell us what you are building

Send your card type, interface and quantity. You get a quote, lead time and compatibility notes within 24 hours — samples available for most items.

Email us
sales@valenid.com

Request a quote

Tell us what you need — an engineer replies within 24 hours with pricing, lead time and compatibility notes.

We reply within 24 hours on working days. Your details are used only to answer this inquiry — see our privacy policy.