Get ten smart lock suppliers to provide you with certifications, and you’ll likely get ten folders of CE reports, FCC documents, UL files, RoHS declarations, and test certificates. But that doesn’t necessarily indicate whether those documents are relevant to your project.

When there is a smart lock that will only be sold in the USA, collecting European compliance documents is not the top priority. Radio compliance does not indicate that the door hardware proposed is appropriate for the fire-rated door. The word “BHMA Grade 1” provides very little indication to the buyer if the supplier does not tell them either the applicable ANSI/BHMA standard or the models covered by the grade.

The better question is not: “How many certifications does this smart lock have?” It is: “Which requirements apply to my market, my door, and my project?” That distinction can avoid unneeded testing expenses, specification mismatches, and also late-in-the-job project issues.

This guide outlines the considerations B2B buyers should make when considering UL, ANSI/BHMA, FCC/RED, and the new Aliro standard, while making sure they don’t think of them as interchangeable badges.

Commercial Smart Lock Project Compliance Workflow

1. Start With the Project, Not the Certificate

Before asking a supplier for UL, FCC, or CE documents, define three things.

1) Where Will the Product Be Sold?

Market regulations come first.

A wireless smart lock placed on the U.S. market may be subject to FCC equipment-authorization requirements. Radio equipment placed on the EU market falls within the Radio Equipment Directive where applicable, together with other relevant EU legislation. UK-connected consumer products can also fall within the PSTI security regime when they meet its scope.

These requirements are jurisdiction-specific. One document does not automatically replace another.

2) Where and How Will the Lock Be Used?

A hotel guest-room lock, apartment lock, access-control locking device, and smart deadbolt may look similar from a buyer’s perspective, but they do not necessarily fall under the same hardware standards.

Door type matters too. A normal internal door, an exterior entrance, and a fire-rated opening create different compliance questions.

3) What Does the Project Specification Require?

This is where many sourcing discussions go wrong. A legal market requirement and a project specification are not the same thing.

Beyond the basic requirements of the market, an architect, consultant, developer, hotel group, or authority having jurisdiction can require a specific listing, performance, fire rating or hardware configuration of the systems and equipment.

A practical rule is:

  • The market determines regulatory requirements.
  • The application determines performance requirements.
  • The project specification determines what must be documented.

2. Not All Smart Lock Certifications Solve the Same Problem

A buyer can simplify smart lock compliance into four layers.

Compliance Layer

The Question It Answers

Typical Examples

Market regulatory compliance

Can this product be legally placed on the target market?

FCC, EU RED, RoHS

Lock and hardware performance

Does the hardware meet the relevant performance criteria?

ANSI/BHMA standards, selected UL standards

Application-specific requirements

Is it suitable for this particular door or environment?

Fire-door evidence, IP testing, hazardous-location requirements

Cybersecurity and interoperability

How does the connected product protect or exchange digital credentials?

RED cybersecurity requirements, UK PSTI where applicable, Aliro

The important point is simple:

  • Never use one layer to answer a question belonging to another.
  • FCC compliance does not prove mechanical durability.
  • A BHMA grade does not prove EU radio compliance.
  • A CE mark does not automatically prove suitability for a fire-rated opening.
  • Aliro interoperability does not replace market-access regulations.

4 Layers of Smart Lock Compliance

3. UL: First Ask What You Are Trying to Prove

When a supplier says: “This lock is UL certified.” Your next question should be: “Certified to which UL standard?” “UL” alone is not a product-performance category.

1) UL 294: Access Control System Units

UL 294 is for physical access-control equipment and systems that control entry, exit or access to protected areas or devices. It covers the requirements for access-control equipment when building, performing and operating.

Therefore UL 294 may apply to a commercial project with electronic access-control functions and it should be determined if it is required for the proposed product category, system architecture, project specification, or applicable code.

It should not simply be added to every hotel or apartment RFQ by default.

2) UL 1034: Burglary-Resistant Electric Locking Mechanisms

UL 1034 covers electric locking mechanisms for burglar resistance and has evaluated several factors such as static strength and dynamic strength and endurance. The current sixth edition specifies defined ratings for these characteristics. Importantly, its scope also states that it does not address the fire-retardant classification of a door assembly.

So UL 1034 and UL 294 answer different questions. Neither should be treated as a generic “higher” or “lower” certification.

3) Fire-Rated Openings Are Another Question Again

UL 10C is a test method for positive-pressure fire tests of door assemblies. The standard specifically notes that changes from tested construction or conditions can substantially affect performance.

That is why a statement such as: “This smart lock has a fire certificate.” is still not enough for a serious project. The buyer needs to understand what was tested, with which door assembly or hardware configuration, for which duration and under which conditions.

4. “BHMA Grade 1” Sounds Impressive. But Grade 1 of What?

This is one of the most valuable questions a savvy lock shopper can ask.

ANSI/BHMA does not offer one set of smart-lock grading system, with a set maximum cycle number for all types of locks.

Some of the products used by various builders are subject to separate ANSI/BHMA standards, and BHMA expressly acknowledges that grading requirements will vary by product. Grade 1 is typically the highest achieved in Grades 1, 2 and 3 depending on the particular product standard.

For instance, BHMA-A156.36 is for Auxiliary Locks, with operational, cycle, strength, security and finish testing. ANSI/BHMA A156.25-2023 covers Electrified Locking Devices and shall be used in conjunction with the applicable mechanical BHMA product standards.

Therefore, instead of asking: “Do you have BHMA Grade 1?”

ask: “Which ANSI/BHMA standard applies, which grade was achieved, which exact models are covered, and what supporting documentation can you provide?”

That question produces much more useful procurement information.

US‑Smart‑Lock‑Project_Flowchart_iLockey

5. FCC: A Certified Module Does Not Automatically Answer the Whole Product Question

Wireless compliance is another area where oversimplified statements create confusion. A supplier may tell you: “The Bluetooth module already has FCC certification.” That does not automatically mean the claim is useless—but it also does not finish the compliance review.

The FCC provides specific rules and guidance for certified transmitter modules and for host products that integrate those modules. A host manufacturer may be able to rely on an approved module when the applicable integration conditions are followed, while labeling, installation conditions and other host-product requirements still need to be addressed.

So the better procurement questions are:

  • Which module is being used?
  • What is its FCC ID?
  • What integration conditions apply?
  • Does the final lock configuration follow those conditions?
  • What additional host-product testing or labeling is required?
  • The important question is not simply: “Does the chip have FCC?”
  • It is: “Is the final product configuration compliant for the way we intend to sell and install it?”

6. CE Is Not a Sticker You Buy From a Test Lab

European buyers often ask suppliers: “Please send me your CE certificate.” But that language can obscure what should be checked?

The EU Radio Equipment Directive sets essential requirements and conformity-assessment procedures for radio equipment. The manufacturer prepares an EU Declaration of Conformity and is responsible for the conformity of the product. The products are then CE marked as per the relevant rules. Not all conformity routes require a Notified Body number.

When purchasing a wireless smart lock, therefore, the CE logo on a brochure should not be the only criterion considered.

Check: Product identification, applicable EU legislation, Declaration of Conformity, applicable standards, technical documentation and configuration provided.

Another EU standard requirement for electrical and electronic equipment is RoHS. The RoHS Directive is designed on EU Declaration of Conformity and CE-marking system. It’s important to note that a claim is a CE logo appearing on marketing. Traceable conformity documentation is evidence.

7. RED Cybersecurity: A Requirement Buyers Can No Longer Ignore

Cybersecurity has become a more direct part of EU radio-equipment compliance.

Since 1 August 2025, the RED cybersecurity essential requirements in Article 3(3)(d), (e) and (f) have applied to specified categories of radio equipment. Their main concerns are protecting the network, privacy and personal-data protection, and fraud protection.

In connected smart-lock projects, procurement teams must not only concern themselves with the compliance with RF performance and EMC but also with compliance aspects of the other components of the system.

Software architecture, connectivity and cybersecurity can now affect product conformity.

There is also an important future transition: the EU has adopted measures to repeal the RED cybersecurity delegated regulation from 11 December 2027, when the Cyber Resilience Act becomes fully applicable, in order to avoid regulatory duplication.

For buyers planning multi-year product programs, regulatory monitoring should therefore be part of supplier management—not a one-time certificate collection exercise.

8. Selling to the UK? First Check Whether PSTI Actually Applies

The UK PSTI product-security regime came into effect on 29 April 2024.

But it is specifically aimed at relevant consumer connectable products supplied to UK consumers. There are possible examples of products that are connected, for example door locks, and manufacturers and importers and distributors have obligations when products are connected.

This creates an important B2B distinction.

A connected lock sold as a consumer product can present a different PSTI scope question from equipment supplied exclusively as part of a professional commercial system. Do not simply add “PSTI certificate required” to every UK smart-lock RFQ. First determine whether the product and route to market fall within the legislation.

EU Market & UK Market

9. Aliro Is Not Another Certificate to Collect

Aliro belongs in this discussion—but for a completely different reason.

Aliro 1.0 is a standardized communication protocol and credential for digital access, and was released by the Connectivity Standards Alliance on 26 February 2026. It can be used in offices, hospitality, universities and residential access applications.

With the implementation, Aliro enables digital-access communication via NFC, Bluetooth Low Energy (BLE) and UWB. In April 2026, UL Solutions began to provide authorized certification and interoperability testing for Aliro.

Aliro is not a replacement for FCC, RED, UL or fire-door.

It addresses another question: Can digital credentials be used reliably on interoperable devices and access-control systems?

In a project planning scenario for mobile wallet credentials, wearables, or smartphones, or for long-term multi-vendor interoperability, that could prove to be strategically significant. When it comes to an easy RFID hotel lock replacement, it’s not necessarily a buying priority now.

A new standard should not be added to your specification because it is new. What business problem does it solve?

10. The Five Questions That Expose Weak Compliance Claims

When evaluating a smart lock supplier, five questions reveal far more than a folder full of logos.

1) Which exact standard does this document refer to?

“UL certified” and “BHMA certified” are not precise enough.

Ask for the standard number.

2) Which exact product models are covered?

Do not assume every product from the same manufacturer shares the same compliance status.

Where certification programs permit product families, confirm that the proposed model and configuration are actually included.

3) What type of document is this?

A certificate, test report, Declaration of Conformity and laboratory test summary do not mean the same thing.

Know what you are reviewing.

4) Can it be independently verified?

Where an official certification database or file number exists, use it.

FCC provides equipment-authorization records; UL and BHMA also maintain searchable certification resources for relevant programs.

5) Does it cover the configuration you are actually buying?

Changes to radio modules, lock bodies, electronic boards, materials or other critical components may affect the relevance of previous testing or certification.

Do not compare paperwork with a brochure.

Compare paperwork with the sample and purchase specification.

5 Questions to Verify Smart Lock Compliance

11. Build Your Compliance List Before You Ask for a Quotation

Before comparing smart lock prices, complete a project compliance table.

Project Question

Buyer Input

Target market

U.S. / EU / UK / Other

Application

Hotel / Apartment / Office / Residential / Other

Door type

Standard / Fire-rated / Exterior / Other

Wireless technology

BLE / Wi-Fi / NFC / Other

Project-specified standards


Exact lock model


Required compliance documents


Third-party or AHJ approval required?

Yes / No

Sample or pilot verification required?

Yes / No

This changes the supplier conversation. Instead of asking five factories for a price on “a certified hotel lock,” you are asking them to quote against the same technical and compliance conditions. That makes price comparison more meaningful. It also identifies expensive compliance gaps before tooling, sampling or installation.

12. Smart Lock Certification  FAQs

The following are some common questions about smart lock certification for your reference.

1) All commercial smart locks should be UL 294?

There isn’t a universal requirement that makes UL 294 a requirement for all commercial smart locks. Access-control system units are covered by UL 294, but the requirement for this depends on the product, system design, project specification, and applicable code or approval requirements.

2) Is a new FCC ID required for a smart lock with an FCC-certified Bluetooth module?

Not automatically. Certified transmitter modules are allowed under certain conditions to be integrated into host products as permitted by FCC rules. The manufacturer has to verify module-integration conditions, appropriate host product responsibilities, etc.

3) Are CE’s a certification?

CE should be considered as a conformance marking in the context of the existing EU regulation. The manufacturer will carry out the necessary conformity assessment procedure, prepare the EU Declaration of Conformity, and take responsibility for compliance for radio equipment.

4) Is the same cycle requirement always given for BHMA Grade 1?

No. BHMA says that grading criteria vary depending on the product and is set forth in the relevant ANSI/BHMA standard. Always ask which grade is in reference to which standard.

5) Does every commercial connected smart lock support UK PSTI?

Not automatically. The current regime for relevant consumer connectable products supplied to consumers in the UK applies to such products. PSTI should not be considered a project requirement until it has been analyzed with regard to product scope and/or route to market.

6) Will a fire-tested smart lock perform on all fire-rated doors?

No. Fire performance relates to the tested door assembly and configuration. UL 10C specifically notes that variations from the tested construction or conditions can substantially change performance.

7) Is Aliro required for smart locks?

Aliro is an interoperability standard for digital credentials, not a general legal market-entry requirement. Whether it matters depends on the project’s mobile-access and ecosystem strategy.

13. Before You Ask iLockey for a “Certified Lock,” Tell Us What the Project Requires

If you are sourcing smart locks for a hotel, apartment project, commercial building, distribution program or OEM/ODM product line, send iLockey the following project information:

  • Target market.
  • Door type.
  • Application.
  • Required standards or project specification.
  • Expected quantity.

We are then able to discuss appropriate product selections and ensure that appropriate compliance documents exist for the models being considered. If a required standard is not being met by the proposed model, that should be determined prior to sampling and quotation, and not after installation. It all begins with good compliance work, before the order is placed, not on arrival at project site.

MATCH THE LOCK TO THE PROJECT

14. Conclusion

The longer the list of certifications, the more one might think that a particular smart lock is more suitable than another. The actual work is to match the product to four things: The market, the door, the application, and the project specification. Once those conditions are clear, one can decide on which regulations, product standards, test reports, declarations or certification listings are applicable.

And when a supplier says: “We have UL, BHMA, FCC and CE,” that should not end the discussion. It should start it. Ask which standard. Ask which model. Ask which configuration. Ask for the document. Verify it.