Keypad and Card Reader Installation Technique

Why this matters

A keypad or card reader is the part of the door the customer actually touches, and it is also the part most likely to get commissioned in a hurry because the mechanical work (the lockset or strike behind it) already ate the appointment. A reader mounted six inches off spec, an admin code never changed from the box default, or an enrollment step skipped because the tech ran out of time all look fine on the day and all come back as service calls. This is the technique for a standalone, single-door keypad or reader, either a self-contained mechanical pushbutton lock or a wired electronic keypad or prox reader paired with its own small controller, not a networked multi-door system, which is its own procedure. The device family was already chosen at the estimate; this article is the install and commissioning record filled in field by field, because a reader install that skips a field is the one that gets a callback inside the first month.

Field 1: opening ID and existing hardware baseline

Before anything is unboxed, record what the door already is: the existing lockset type and bore (cylindrical or mortise, standard 2-1/8 inch cross-bore or a mortise pocket), door material and thickness, and whether the opening is interior or exposed to weather. This field exists because the two form factors in scope for this article need different things from the same door. A self-contained mechanical pushbutton lock (a keyed-alike pushbutton combination lock body, the common back-door and gate hardware in this trade) drops into a standard cylindrical or mortise prep the same way a normal lockset does, needs no wiring, and has no controller. A wired electronic keypad or prox reader needs a mounting surface for the reader itself, usually beside the door rather than in it, plus a low-voltage wire path to a small standalone controller and to whatever lock or strike it drives. Confirm on-site which form factor the door actually supports; a masonry storefront wall with no accessible conduit path changes the wiring plan the estimate assumed, and that gets caught here, before a bit ever touches the wall.

Field 2: mounting location and height

For a self-contained pushbutton lock, mounting is the standard lockset bore, no separate decision needed beyond confirming backset match. For a wired reader or keypad, pick the mounting height with the same reach range used for any door-side control, roughly chest height on the latch side, clear of the door swing and of any obstruction that would force a user to reach across the opening. Confirm the wall or jamb surface can take the reader's mounting screws solidly; a reader screwed into hollow drywall with no backing will work on day one and loosen within months from repeated hand pressure. If the reader is exterior-exposed, confirm its housing is weather-rated before it goes on the wall, and gasket or seal the mounting screws and the wire entry point so water does not track down the conductor into the housing, a common cause of an exterior reader failing intermittently in wet weather long after a dry-season install passed every test.

Field 3: wire pull and termination record (wired units only)

Skip this field for a self-contained pushbutton lock. For a wired keypad or reader, record the run length from reader to controller and from controller to the lock or strike it drives, and size the conductor for that run rather than pulling whatever gauge is already on the spool. Data and power typically share a jacketed multi-conductor cable rated for the reader's format; do not substitute a smaller-gauge cable to save a pull just because the data conductors carry little current, because the same cable also often carries the lock-side power and that leg is the one that sags under an undersized run. De-energize the controller's power source before landing any conductor at the reader or the controller, verify de-energized with a meter, and cap conductor ends until they are ready to land, the same discipline any low-voltage termination needs regardless of how small the system is. Route the cable away from sharp door-frame edges and any pinch point in the door's own swing arc; a cable nicked at install shorts weeks later when someone leans the wrong way against the frame.

Field 4: power-up and first-signal test

Re-energize only after every termination at both ends is complete and visually checked. On first power-up, confirm the reader or keypad lights or beeps per its normal ready state before testing any credential; a unit with no ready indication has a power or termination fault that a credential test will only mask as "not working" without telling you which half failed. For a self-contained mechanical pushbutton lock, the equivalent first check is cycling the combination lever through its default or factory-set combination once, confirming the mechanism itself operates smoothly before any combination is set for the customer.

Field 5: clear the default code before you enroll the customer's own

Every keypad and reader in this class ships with a factory default admin code or a documented default combination, and that default is public information, printed in the installation manual and searchable online. The single most common security failure on a standalone keypad install is leaving that default live because the enrollment step ran out of time. Change the admin code or master combination first, before enrolling any user codes, and confirm the old default no longer works by testing it once it should be dead. This is not optional even on a rushed job; a unit installed and left on its factory default is, in practice, an unlocked door with an extra step.

Field 6: enroll the customer's codes or credentials and test each one

Enroll at minimum the codes or credentials the customer specifies at handoff, whether that is a single shared staff code, individual codes per employee, or a batch of prox cards. Test every enrolled code or credential individually rather than trusting the enrollment confirmation the unit gives; a code that enrolls without error can still fail to open the door if it collided with an existing entry or if the unit's enrollment limit was exceeded silently. On a wired unit, also confirm the relay drives the lock or strike correctly on a valid credential and does nothing on an invalid one, cycling both outcomes at least once.

Field 7: document the fallback and the lockout path

Every standalone unit needs a documented way in when the primary method fails: a mechanical key override on the pushbutton lock body or the reader's own housing, a backup battery-powered entry method, or, for some wired units, a request-to-exit or manual release the customer can reach without the credential system. Record which fallback this specific install has and confirm it works before leaving; a unit with a key override that was never test-cycled is a unit whose fallback is untested exactly when it will be needed most, which is the day the primary method fails.

Field 8: customer handoff and sign-off

Walk the customer through changing their own admin code (never leave that step to the tech alone, since a customer who cannot change their own admin code is dependent on a service call for a routine task), demonstrate the fallback method, and confirm in writing who received the admin credentials. This last field is the completed artifact: an opening ID with its hardware baseline, its mounting and wiring record, its confirmed default-code change, its tested enrollment, its documented fallback, and a named customer contact who received the admin access. A record missing any one field is not a finished install, it is an install someone will have to reconstruct from memory on the next service call.

Worked example: the completed record for a laundromat back door

Opening: back service door, laundromat, exterior, hollow-metal door with an existing mortise lockset. Field 1 baseline: mortise prep confirmed present and in good condition; owner wants staff entry without keys, so the estimate's electronic keypad-to-standalone-controller form factor is confirmed on-site rather than the mechanical pushbutton option, because the owner also wants a log of which staff code was used, which only the electronic unit provides.

Field 2: reader mounted on the exterior brick beside the door at chest height, clear of the door swing, screws set into masonry anchors rather than surface adhesive given the exterior exposure, weather gasket seated under the housing.

Field 3: an 18-foot run from reader to the controller mounted inside the back room, and a 6-foot run from controller to the mortise lock's electrified cylinder. Both runs are well inside the low end of the controller manufacturer's wire chart at this length, so the cable already on the truck's spool is adequate, confirmed rather than assumed given the exterior run's exposure to temperature swings. Power isolated at the controller before landing either run, verified de-energized, both ends capped until ready.

Field 4: first power-up, the reader's ready light comes on steady and the keypad accepts a keystroke with an audible tone; the mechanism has power. Field 5: factory default admin code changed immediately, then tested and confirmed dead.

Field 6: three staff codes enrolled, each tested individually; the third staff code fails to open the door on its first test because it was entered one digit short during enrollment, caught immediately by the individual test rather than assumed good because the unit's enrollment screen showed no error. Re-entered and re-tested, it passes.

Field 7: the mortise lock retains its original mechanical key override, tested and confirmed it still throws the bolt independent of the electronic system, giving the owner a fallback if the controller or power ever fails.

Field 8: the owner is walked through changing the admin code, the mechanical key override is demonstrated, and the owner signs for having received the new admin code and one physical override key. The completed record, all eight fields present, goes in the shop's file for this customer, and a copy stays with the owner.

References

  • BHMA / ANSI A156.25 - American National Standard for Electrified Locking Devices (applicable to standalone electrified keypad and reader-driven locks).
  • See related: Electronic Strike Installation Technique (the lock-side hardware a wired reader or keypad typically drives), Electronic Access Control Systems Reference (credential type and networked-system comparison, for when a job outgrows a standalone unit), Access Credential Issue and Revoke SOP (ongoing credential management after this install is complete).