Skip to content

Security System Integrator or Specialists? A Vendor Scorecard for Alarm, CCTV and Access Control

Security System Integrator or Specialists? A Vendor Scorecard for Alarm, CCTV and Access Control
Table of contents

Updated October 2026. If you are planning an upgrade that touches intrusion, cameras and doors at once, the first decision is structural: hire one security system integrator for all three, or a specialist for each. Most advice on this question comes from companies that sell one of the answers. We do not install, monitor or sell equipment, so we have no platform to protect, and our view is simpler than the sales pitches: the integrator-versus-specialist question matters less than who owns the system when the contract ends.

The short answer

Hire a single security system integrator for alarm, CCTV and access control only if it can show completed projects in all three disciplines at your building type and quotes an open, non-proprietary platform you could hand to another company. If it is strong in two and resells the third, or if its proposal rests on dealer-locked panels, proprietary readers or a cloud subscription you cannot leave, split the work between specialists. Whichever structure you pick, make it reversible: write equipment ownership, programming ownership, admin credentials and an as-built handover into the bid before anyone signs.

What a security system integrator is, and what you are actually buying

Choosing between alarm, camera and access control vendors is a scoring exercise on design quality, service capability, openness and five-year cost, not a bet on a brand. Start with what each vendor type actually is. A security system integrator designs, installs and programs multiple security systems so they work as one: the access control panel tells the cameras to bookmark video when a door is forced, the intrusion panel arms when the last badge leaves. An alarm company installs and monitors intrusion and fire panels; a camera installer mounts and configures video. Security integrators sit above both, and the good ones carry the licences, programming skills and service staff for every discipline they quote (our services overview lists what we screen for in each of the five system types). The bad ones carry one strong trade and subcontract the rest while presenting a single logo.

Being excellent at one of the three systems proves nothing about the other two.

SystemWhat the vendor must actually deliverWhat good looks like
Intrusion alarmCommercial-zone panel, detector placement, cellular and IP communication paths, a written response protocol, and signals received by a UL-listed central stationNon-proprietary panel with installer code released to you; monitoring contract with term, renewal and ownership stated
Video surveillance / CCTVCamera design by field of view and lighting, storage sized to a written retention window (roughly 1 TB per 1080p camera per month, 2 TB at 4K), network switching, remote-access licensingRetention stated in days, storage headroom of 20 to 50%, camera placement on a floor plan you keep
Access controlDoor hardware and strikes, request-to-exit and egress compliance, controllers, readers and credentials, cardholder database, software or cloud licensingOSDP readers, standard door hardware, your staff able to add and revoke badges without a service call

Access control is the discipline to check hardest, because door hardware, request-to-exit and egress rules are a different trade from alarm wiring, and an alarm company that is superb at monitoring can still deliver doors that fail inspection.

One security system integrator vs separate specialists

A single integrator makes sense when the firm has verifiable depth in all three systems, the building genuinely benefits from security system integration (doors triggering cameras, one credential for alarm and access), and the proposal uses hardware and software another integrator could service. Splitting the work is the safer choice when one bidder's strength is lopsided, when the integrated proposal relies on proprietary components, or when fire and intrusion monitoring need a local alarm company with a UL-listed station relationship that the video and access vendor does not have.


One integratorSeparate specialists
AdvantagesSingle point of accountability; one service contract; native integration between door events, video and arming; one set of drawingsBest-in-class depth per system; competitive pressure on every line; a failure or dispute with one vendor does not strand the others; lock-in limited to one system at a time
DisadvantagesWeakest discipline gets hidden under the strongest; single vendor can hold the whole building hostage at renewal; integration often achieved through one proprietary platformThree contracts and three service numbers; integration depends on open APIs and someone owning the interface; finger-pointing when a cross-system feature fails
Wins whenMulti-site or campus with a real operations team; integrator proves all three trades; open platform in writingSingle building; one bidder clearly stronger per system; compliance-heavy fire or cannabis monitoring; you want leverage at every renewal

The hybrid many buildings land on

In practice, many commercial buildings end up with two vendors, not one or three: a local alarm company handling intrusion and fire with signals routed to a UL-listed central station, and a security integrator handling video and access control. UL's description of its central station certification notes that NFPA 72 allows central station service to be delivered either by a single full-service company or by a contractual partnership between a local alarm company and a UL-listed monitoring station. Your installer does not need to own the monitoring station; it needs a documented contract with one that is listed. That gives you a specialist for the life-safety side and an integrator for the operational side, with the integration point (door-forced events to video) handled by the integrator alone.

The lock-in map: where it hides, item by item

Vendor lock-in in commercial security is any component that only the installing company can service, reprogram, license or export, so that leaving them means replacing hardware or losing data. It hides in proprietary or dealer-locked alarm panels, Wiegand reader wiring, the cardholder database, video management licences, cloud subscriptions, auto-renewing monitoring contracts and the admin passwords the installer never handed over.

Proprietary panels and dealer-locked programming

Some intrusion panels are sold only through one dealer network, and even open panels can be locked by withholding the installer code. Either way, as our commercial security system cost guide puts it, every future quote then has to come from the company that installed it. Ask for the panel make and model, confirm it is available through multiple dealers, and require the installer code in the handover.

Reader protocol: Wiegand vs OSDP

OSDP (Open Supervised Device Protocol) is the Security Industry Association's open standard for communication between access control panels and readers; its Secure Channel mode adds AES-128 encryption and two-way supervision, replacing the one-way, unencrypted Wiegand interface, and SIA notes it was published as international standard IEC 60839-11-5 in 2020. Two things follow for lock-in. Wiegand is a legacy interface that most reader and controller brands support, so it is not a lock-in risk by itself, but it is a security weakness because card data crosses the wire one-way, unencrypted and in plain text. OSDP is both more secure and, because it is an open standard, keeps readers interchangeable between controller brands. Specify OSDP Secure Channel and, where you can, readers and controllers on SIA's OSDP Verified list, which tests devices for conformance to the standard. Our access control page goes further on credential choices and the recurring cost of cloud-managed doors.

Cardholder and credential databases

Your employees, their badge numbers, schedules and door permissions live in a database. If it sits on the vendor's cloud tenant or in an encrypted on-premise application only they can open, you cannot migrate it. Require a documented export of the full cardholder database in a format another system can import, and confirm the credential technology itself is not vendor-specific, or a new system will mean reissuing every badge.

Video management licences and cloud recording

Recording and remote-access licences can be registered to the reseller rather than to you, and cloud recording is a per-camera subscription: stop paying and the archive may be gone unless the contract names an export path. Ask whether the cameras are ONVIF conformant (the open interface standard for IP video and access devices that lets products from different brands work together) so they can be re-pointed to another recorder, who holds the licence keys, and how a full archive export is performed.

Monitoring contract terms

Commercial monitoring agreements commonly run 36 to 60 months and renew automatically unless cancelled inside a notice window, often 30 to 60 days before the end date, according to our alarm monitoring guide. Subsidized installs attached to a monitoring agreement can mean the provider retains the equipment; some low-cost offers are effectively leasing the panel and the yard signs. Early termination fees and retained equipment together can turn a monitoring switch into a full panel replacement.

Admin passwords

The quietest form of lock-in. If the installer holds the only administrator login to the recorder, access control server, cloud dashboards and the alarm panel's programming level, you own hardware you cannot control. The contract should state that you hold admin credentials on every device from day one and that the integrator works from a separate, revocable account.

The vendor scorecard

Below is the weighting we recommend when scoring commercial security system companies against each other. Score each bidder 1 to 5 on each row, multiply by the weight, and compare totals. Openness and ownership gets 20% because it is the only line that determines what every future bid costs you; a vendor that scores low here makes all other scores a one-time event.

CriterionWeightWhat to score
Design quality25%Site walk performed; camera placement on a floor plan; retention and storage shown with calculations; detector placement justified; door-by-door hardware schedule; egress and fire code addressed
Service capability20%Technicians local to the building (not a national logo and a subcontractor); written response times; parts stock; after-hours coverage; references from your building type
Openness and ownership20%Non-proprietary panel; OSDP readers; ONVIF cameras; exportable databases; you hold admin credentials and licences; equipment owned outright at completion
Five-year total cost15%Installed price + (monitoring + cloud + software + licence renewals) × 60 months, plus any annual escalator and termination fee
Cybersecurity10%Default passwords changed and documented; firmware update process; network segmentation of cameras and controllers; encrypted reader and communicator paths
Credentials and track record10%State alarm or low-voltage licence verified; insurance certificate; UL-listed station relationship for monitoring; NICET or manufacturer certifications; complaint history

Adjust the weights if your situation demands it: a cannabis dispensary with a six-month retention mandate might lift design quality; a multi-site operator with lean facilities staff might lift service capability. Keep openness at or above 20% regardless.

Questions to put in writing before you sign

Ask every bidder these in writing and attach the answers to the contract. Verbal reassurances about "open systems" do not survive a dispute.

  1. "What parts of your solution lock me into you?" An honest vendor names at least one thing. A vendor who says "nothing" has not thought about it or is not telling you.
  2. "Can another integrator take over without replacing hardware?" The answer should identify the panel, controllers, readers and cameras by model and confirm each is available through other dealers.
  3. "Who owns the programming, database and video?" You should own all three, with export formats named.
  4. "Who holds the administrator credentials on each device, and when do I receive them?" At commissioning, before final payment.
  5. "What are the term, renewal notice window, annual escalator and early termination fee on every recurring charge?" Line by line, for monitoring, cloud, software and licences.
  6. "What happens to my footage and cardholder data if I stop paying the subscription?" Get the retention-after-cancellation period and export procedure in writing.
  7. "Which parts of this scope will be performed by subcontractors?" Then score the subcontractor's capability, not the prime's.

The as-built handover checklist

A complete as-built package is what makes your vendor choice reversible. It is also what lets a second integrator quote a takeover without a paid discovery visit. Require it as a deliverable tied to final payment, and ask to see a sample from a past job before you award the work.

  1. As-built drawings showing every device location, with revisions from the design drawings marked.
  2. Device schedule: make, model, serial number, IP address, MAC address and firmware version for every camera, controller, reader, panel and switch.
  3. Cable schedule: cable type, run, origin and termination points, labelled to match the field.
  4. Panel and controller wiring diagrams, zone lists and input/output assignments.
  5. Camera settings: resolution, frame rate, compression, motion zones and the retention calculation that sized the storage.
  6. Software licences and activation keys, registered in your company's name, with renewal dates.
  7. Administrator credentials for every device and application, delivered securely and changed from defaults.
  8. Configuration backups for the alarm panel, access control database and VMS, with instructions to restore them.
  9. Monitoring account details: central station name, account numbers, call list and the written response protocol.
  10. A documented transfer procedure: the steps a successor integrator would follow to assume service, including how the installer's own accounts are revoked.

Why identical scope matters: $35,000 vs $50,000

Take a hypothetical $35,000 bid and a $50,000 bid for the same building. On the surface the first saves $15,000. Read line by line, the cheaper bid may cover fewer controlled doors, a shorter retention window on local storage rather than cloud, legacy readers, a dealer-locked panel on a longer monitoring term, and no permits or training. Add what is missing and the gap closes or reverses, with a worse ownership position on the cheaper bid. The documented version of this is in our standardized scope checklist: a $19,400 bid for an 8,000-square-foot office covered 12 cameras with 14-day local retention and no access control; once the missing doors, cloud retention, software, switching, permits and training were added, it came to about $31,200 plus roughly $200 a month it had not shown, the same price as the most expensive bid but with a shorter warranty.

The fix is to compare the five-year figure, not the install figure: installed price plus every unavoidable monthly cost multiplied by 60. At $100 a month, monitoring alone adds $6,000 over five years, and cloud video at $10 to $30 per camera per month adds $600 to $1,800 per camera over the same 60 months before any hardware is counted. Our commercial security system cost guide sets out current installed ranges and monitoring bands, the scope checklist above walks through normalizing bids, so we will not repeat that worksheet here, and our guide to security integrators that install access control and CCTV together compares national and local firms on the same ownership terms. The point for the vendor-structure decision is that you cannot judge "one integrator vs three specialists" on price until the three specialist quotes and the one integrated quote describe the same doors, cameras, retention and ownership terms.

Building type changes the scope before price enters the picture. A dispensary in Ohio needs six times the video storage of one in Colorado; a clinic's recorder may hold protected health information; a school's classroom locks must release with one motion from inside. Our industry guides set out the rule that drives the spec for each building type, which is also the rule your bidders should already be working under.

How we standardize it

We are an independent quote service, not a security company. We do not install, monitor or sell equipment, and the licensed contractors in our network pay us for introductions, so the service costs the business nothing. You complete one building profile covering systems, industry, square footage and timeline, and we send that same scope to a small number of contractors we have screened for a verified state licence, a current insurance certificate, complaint history and experience with your building type. Because every bidder prices the same scope, the quotes come back comparable: installed cost, monitoring rate, contract term and who owns the equipment at the end, side by side. That is the information the scorecard above needs, and it is what the how it works page explains in detail. If you are deciding between a single security system integrator and separate specialists, you can request both structures on the same profile and let the comparable numbers settle it: get quotes for your building.

Frequently asked questions

Should I hire one security integrator for alarm, CCTV and access control, or separate specialists?

Hire one integrator only if it can prove completed work in all three disciplines at your building type and quotes open, non-proprietary hardware and software. If its strength is lopsided or the proposal depends on dealer-locked panels, proprietary readers or a cloud tenant you cannot export, split the work. Many buildings end up with a local alarm company for intrusion and fire and an integrator for video and access.

Who owns the equipment, programming, passwords and cardholder database when the contract ends?

Only what the contract says you own. Subsidized installs attached to monitoring agreements often leave the provider owning the panel. Programming, the access control database and admin credentials default to the installer unless the contract names you as owner and sets a handover date. Put all four in writing, with export formats, before signing.

Can another integrator take over my system without replacing the hardware?

Yes, if the panel is non-proprietary with the installer code released, readers use OSDP or standard wiring, cameras are ONVIF-compliant, the cardholder database is exportable, and you hold the admin logins. If any of those is missing, the takeover usually involves replacing that component. Ask each bidder to confirm takeover feasibility by component before you award the job.

What does a UL-listed central station mean, and does my installer need to own one?

A UL-listed central station has been evaluated against UL 827, the Standard for Central-Station Alarm Services, and is audited annually by UL to keep its listing. Your installer does not need to own the station. UL notes that NFPA 72 permits central station service through either a single full-service company or a contractual partnership between a local alarm company and a UL-listed monitoring station.

What is OSDP, and why should readers use it instead of Wiegand?

OSDP is SIA's open standard for communication between access control panels and readers, published internationally as IEC 60839-11-5. Its Secure Channel mode encrypts reader traffic with AES-128 and supervises the connection so a disconnected or tampered reader is reported. Wiegand is one-way and unencrypted, so card data can be intercepted and replayed. Specifying OSDP Secure Channel closes that weakness and keeps readers interchangeable across controller brands.

How should I weight a scorecard when comparing commercial security vendors?

A workable weighting is design quality 25%, service capability 20%, openness and ownership 20%, five-year total cost 15%, cybersecurity 10%, and credentials and track record 10%. Score each vendor 1 to 5 per criterion and multiply by the weight. Keep openness at 20% or more, because it decides whether every future bid, from the same security system integrator or a new one, is competitive or captive.

Ready to get started?

Talk to our team and see how we can help.