No. Almost no battery-powered smart lock speaks BACnet, Modbus or KNX, and none of the ones we sell do. We’re not dodging the question. It’s how the hardware works, and once you see why, the spec line that sent you here usually turns out to be asking for something else.
We get this from MEP consultants, fit-out contractors and facilities managers in Dubai and Abu Dhabi, always in the same shape. The door hardware schedule says the lock “shall support BACnet/Modbus/KNX integration with the building management system.” Somebody has to answer it. So here’s the honest version. What those three things are, what a BMS can realistically do with a door, the three routes that exist, and the one case where the right answer is to leave the door alone.
If you’re building door access into your own software rather than a BMS, that’s a different job and we’ve written it up separately in our smart lock app integration guide.
What are BACnet, Modbus and KNX, and what is each one for?
All three are field bus protocols. They were designed so plant equipment on a wire could be read and controlled from one head-end. None of them was designed for a door lock running on four AA cells.
| Protocol | Standard | Runs on | Built for | Native on a battery lock? |
|---|---|---|---|---|
| BACnet | ANSI/ASHRAE 135, also ISO 16484-5 | RS-485 (MS/TP) or Ethernet (BACnet/IP) | HVAC, chillers, AHUs, lighting, and the head-end that watches them | No |
| Modbus | Modicon 1979, now Schneider Electric, open spec | RS-485 (RTU) or Ethernet (TCP) | Meters, VFDs, pumps, generators, anything with a register map | No |
| KNX | ISO/IEC 14543-3 and EN 50090 | Dedicated twisted-pair bus, also RF and IP | Lighting, blinds, HVAC zones, room control in villas and hotels | No |
A few things follow from that table.
BACnet is the one your building management head-end almost certainly already speaks. It’s the ISO standard for building automation and a national standard in more than thirty countries. If your consultant wrote one protocol into the schedule, it’ll be this one.
Modbus is older and simpler. It moves coils, which are single bits, and registers, which are 16-bit values. It has no built-in security at all. That’s fine on a segregated plant network behind a firewall. It’s a bad idea anywhere a door credential could be reached from.
KNX is the one we see most on UAE villa and hotel projects, because it’s usually already in the building doing lighting, curtains and room thermostats. KNX can drive a lock, but read that carefully. It drives a relay, and the relay drives an electric strike or a maglock. The KNX bus isn’t talking to a fingerprint lock. It’s switching power to a piece of door hardware.
Why can’t a battery smart lock speak any of them?
Because all three assume a permanent physical connection and mains power, and a battery lock has neither.
A lock running on AA cells is asleep most of its life. Its radio wakes up, does one short exchange and goes back down, because the radio is the biggest single draw on the battery. A BACnet MS/TP device on an RS-485 trunk works the opposite way. It sits on a polled bus and answers whenever the master asks, which means it’s awake and powered all the time. Put that duty cycle on a battery lock and you’d be changing cells every few weeks.
There’s a second reason, and it’s what decides the architecture. Those protocols want a wire to the door. On a UAE fit-out, running cable to every office and meeting room door leaf means containment, a door loop and a power supply per door. That’s most of the cost of a wired access control system, at which point you’re not buying smart locks any more. You’re buying a panel-based system with readers, controllers and strikes, and that’s a different tender.
So the realistic integration point for a battery lock is the cloud account the locks report to, not the door itself. Everything below follows from that.
What does the BMS need from a door?
This is the question we ask first, and it usually shortens the conversation. In our experience the spec line gets copied forward from the HVAC schedule and nobody has written down what the head-end is supposed to do with a door once it can see one.
There are four things people mean. They belong in different places.
| What you want | Where it belongs | Can a battery lock do it? |
|---|---|---|
| See whether a door is open or closed on the BMS graphic | BMS, via a separate door contact | Not from the lock. Fit a door contact and wire it to the BMS like any other input |
| Get an alarm when a door is forced or held open | Access control platform, optionally mirrored to the BMS | Yes, as an event in the lock’s own platform. Mirroring it to the BMS needs middleware |
| Release the door on a fire alarm | Fire alarm panel, hard-wired | No, and it must not. See the section below |
| Issue and revoke credentials, see who opened what | Access control platform | Yes. This is what the lock is for, and it isn’t a BMS job |
The door position row catches people out. A smart lock knows whether it’s locked. It doesn’t know whether the leaf is shut. A door can be unlatched and standing wide open while the lock reports “unlocked” and nothing else. If your BMS graphic needs a real open or closed state, that’s a magnetic door contact, and it costs very little next to the argument about protocols.
The fire row is non-negotiable and we’ll come back to it.
The credential row ends the discussion on most projects. A BMS is a plant system. It isn’t designed to hold a staff list, expire a contractor’s access at 5pm, or produce an audit trail somebody will read after an incident. Pushing credential management onto a BMS because the schedule said BACnet is how projects end up with a system nobody can operate.
Which integration route fits your project?
There are three, in the order we recommend them.
| Route | What happens | Effort | Who owns it in year two | Pick it when |
|---|---|---|---|---|
| 1. Two systems, no integration | BMS runs the plant. The access platform runs the doors. Facilities staff use two screens | None | Nobody, because there’s nothing to maintain | Under about 50 doors, one site, no contractual requirement for a single head-end |
| 2. Event feed into middleware | The lock platform’s cloud API pushes events to an integration layer, which presents them to the BMS as BACnet or Modbus points | Weeks. Needs a developer or a BMS integrator with API skills | Whoever built it, and they have to still exist | You have a real reporting or compliance need for one timeline across doors and plant |
| 3. Wired access control with a native BACnet interface | Drop the battery locks on the doors that matter. Use panels, readers and strikes from an access control brand that publishes a BACnet interface | Months, and it’s a separate tender | The security contractor under a maintenance contract | High-security doors, turnstiles, lifts, or a client who truly requires native protocol compliance |
Route 1 is right far more often than anyone expects, and we say so before we quote anything. A building with twenty office doors and a chiller plant doesn’t need those two things on one screen. It needs somebody to remember to revoke a credential when a staff member leaves.
Route 2 is where the interesting work sits. Your locks report through a gateway to their cloud platform, the platform exposes a cloud API, and an integration layer subscribes to those events and republishes them as BACnet objects or Modbus registers the head-end can read. On UAE projects that integration layer is very often a Niagara Framework station running on a JACE controller, because Niagara is already on site for the plant and it carries a driver per protocol. Tridium licence their drivers, so budget for that as a line item rather than an afterthought.
Route 3 deserves a mention even though it isn’t what we sell on most jobs. If the client’s requirement is truly native, stop trying to bend a residential lock into the shape of a plant controller. Two different systems on two different door types make a better building than one bad compromise everywhere. We’ve set out the wider decision in when to build a custom access control integration and when not to.
One more point on the wire, since it comes up whenever route 3 is on the table. If you’re specifying readers on a wired system, ask for OSDP rather than Wiegand. Wiegand sends the credential one way in plain text and has done since the 1980s. OSDP is the Security Industry Association’s replacement, runs bidirectionally over RS-485, and its Secure Channel uses AES-128 with message authentication. On a new UAE building there’s no good reason left to specify Wiegand.
A worked example: a 22-door office fit-out in Business Bay
This is the shape of job we see most. A tenant takes a floor, the fit-out contractor holds the door schedule, and the schedule says BACnet.
- Week 1. The contractor sends us the door schedule. Twenty internal doors, offices, meeting rooms and a store. Two main entrance doors on the lobby side, already on the landlord’s system.
- Week 1. We ask the question above. What does the BMS need to do with a door? The answer comes back from the facilities manager, not the consultant, and it’s “we want to know if the server room door is left open, and we want to kill a leaver’s access the same day.”
- Week 1. That splits into two jobs. Door held open on one door is a door contact, wired to a BMS input the plant contractor is already terminating. Killing a leaver’s access is the access platform, and no BMS is involved.
- Week 2. We survey the floor plate for gateway coverage. The locks talk Bluetooth, so gateway count depends on the slab, the partition build and where the power sockets sit. We don’t quote a coverage radius off a datasheet. We walk it.
- Week 2. We quote hardware, and we say plainly that BACnet integration is not in our scope and not in our price.
- Week 3. The consultant asks us to confirm BACnet compliance. We answer in writing that the locks have no native BACnet interface, that an event feed to the BMS is achievable through the cloud API plus an integration layer, and that the integration layer is the BMS integrator’s scope. Declared up front, in writing, before award.
- Week 4. Award. Twenty locks, two gateways, one card encoder, sixty cards.
- Week 6. Install. Twenty mortise doors on one visit, not twenty separate callouts.
- Week 6. Commissioning. We build the account structure before anyone touches a lock, because retro-fitting an account structure onto twenty live doors is miserable. Admin account held by the tenant, not by us and not by the fit-out contractor. Groups by floor zone. One manager per group.
- Week 6. Credentials issued. Sixty cards encoded, staff enrolled, contractor codes set to expire on the snagging date rather than “never.”
- Week 7. Handover. The FM gets two logins and a one-page sheet. The server room door contact shows on the BMS graphic. The door log lives in the access platform. Nobody built any middleware, and the building works.
Step 6 is what matters commercially. Saying “no native BACnet, here’s the route that does work” before award is the difference between a clean project and a variation argument at handover.
What does it cost?
Hardware and fitting for that twenty-door floor, priced at our listed rates on the day of writing:
| Item | Unit | Qty | Line total |
|---|---|---|---|
| Altix R9 smart door lock | AED 494.99 | 20 | AED 9,899.80 |
| Altix G2 wireless gateway | AED 179.99 | 2 | AED 359.98 |
| Card encoder | AED 349.99 | 1 | AED 349.99 |
| RFID access cards | AED 34.99 | 60 | AED 2,099.40 |
| Hardware subtotal | AED 12,709.17 | ||
| Mortise fitting, listed single-door rate | AED 450 | 20 | AED 9,000.00 |
| Total at listed fitting rate | AED 21,709.17 |
That’s AED 635.46 a door in hardware, or AED 1,085.46 a door if you pay a single-door callout rate twenty times over.
Nobody should pay a single-door callout rate twenty times over, and we don’t expect anyone to. There’s no published batch fitting price on our site, which is a gap on our side rather than a negotiating position. Send us the door count and we’ll price the visit.
While we’re being straight about our own numbers, our published figures don’t agree with each other. Our installation cost article says AED 150 to 350 for labour. The mortise fitting service sells at AED 450 and the cylinder fitting service at AED 350. We know about it and we’re fixing it. Until then, take the service page price as the one you’ll be invoiced.
We won’t put a number on the BMS side, because we’d be making it up. What you’re buying there is a driver licence, integrator days for mapping and commissioning, and an annual maintenance line. On a twenty-door floor that package regularly costs more than every lock on it. Get it quoted by your BMS integrator before anyone agrees a compliance line, not after.
What the UAE rules say, and what they don’t
Fire first, because it’s the only part of this article that can hurt somebody.
Under general life safety practice, and this is our position as installers rather than a code citation, an electrified lock that holds a door shut on an escape route has to release when the fire alarm operates, and stay released until the panel is reset. That release is a hard-wired circuit between the fire alarm panel and the door hardware. It doesn’t go through a cloud API, a Wi-Fi gateway, a BMS graphic or a battery. We could not retrieve the specific clause of the UAE Fire and Life Safety Code of Practice covering locking devices on means of escape, so we’re not going to quote one at you. Put it to your fire consultant and to Civil Defence for the emirate you’re building in, before the door schedule is frozen.
Most of that argument is about maglocks, not about the locks in this article. A battery mortise lock with a handle on the inside gives free egress mechanically. You pull the handle and the door opens whether the electronics are alive or dead. The same mechanism is what keeps you covered when the batteries die, which we’ve covered in what happens when a smart lock fails.
On Dubai’s green building side, Al Sa’fat is the Dubai Municipality green building system and it pushes buildings toward a BMS for intelligent control of lighting and air conditioning. Read that for what it says. It’s about energy, not doors. We’ve found nothing in it that requires a door lock to sit on a building automation bus, and we’d be glad to be sent a clause that says otherwise.
On SIRA, our reading is that the agency regulates security service providers and electronic security systems in Dubai, which is why CCTV work has to go through a SIRA-approved company and gets audited afterwards. A tenant fitting battery locks on their own internal office doors is a different thing from installing a building security system. Where the line falls on your specific project is SIRA’s call, not ours, so ask them. We’ve set out what we do and don’t know in our SIRA-approved smart locks guide.
And if Modbus is running anywhere near this, keep it off the internet. The protocol has no authentication and no encryption in the base spec. Segment it, firewall it, and don’t let a door event ride on it across an untrusted network.
What breaks, and what it looks like when it breaks
Middleware built in route 2 fails silently more often than it fails loudly. The BMS graphic keeps showing the last state it received, which looks exactly like a quiet building. Build a heartbeat into the integration on day one, so a stale feed raises an alarm instead of showing green.
Timestamps disagree. The lock stamps an event locally, the gateway forwards it, the cloud records it, and the BMS receives it. That’s four clocks. In an incident review, the gap between them is the thing that wastes the afternoon. Agree one source of truth up front and write it into the handover document.
When the gateway drops, the doors keep working. That surprises people, and it’s a design feature. Codes and cards are held on the lock, so the door opens with the gateway dead. What stops is remote issuing and the live event feed. Events queue and arrive late. If your integration assumes real time, it will misbehave for those hours.
Integrations outlive their authors. The fit-out contractor’s developer built it, invoiced and left the country. Nobody at the tenant knows how it was authenticated or where the credentials live. That’s the most common way integrations die in this market, and it’s why route 1 deserves more respect than it gets.
Account structure gets treated as an afterthought. Doors get commissioned into whichever account the technician was logged into that morning. Two years later the tenant can’t move the estate, because the admin account belongs to a company they no longer use. Set the account structure before the first lock goes on the door.
When you should not integrate at all
Four cases where we’ll tell you to stop.
Under fifty doors on one site, two screens isn’t a problem that needs middleware. It’s a training issue, and training costs nothing.
If you can’t name the person or the maintenance contract that keeps the integration alive in year two, don’t build it. It will break, and it will break quietly.
Some clients want one monthly report, not one live screen. A scheduled export out of the access platform costs a fraction of a BACnet feed and answers the same question.
And if the door is on an escape route, the real ask was probably fire release. That’s the fire alarm contractor’s scope, hard-wired, and no amount of protocol work substitutes for it.



















