{"id":74175,"date":"2026-09-03T08:09:55","date_gmt":"2026-09-03T11:09:55","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=74175"},"modified":"2026-09-03T08:09:55","modified_gmt":"2026-09-03T11:09:55","slug":"electronic-security-public-buildings-procurement-integration-inspection","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/electronic-security-public-buildings-procurement-integration-inspection\/","title":{"rendered":"Electronic Security in Public Buildings: How to Procure, Integrate, Inspect, and Accept Systems under Law 14.133"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Procuring electronic security for public buildings should not be treated as an isolated purchase of cameras, biometric readers, controllers, or software. The real object is an <strong>integrated physical security system<\/strong> comprising sensors, field devices, network infrastructure, servers, storage, management platforms, access rules, integrations, electrical infrastructure, cybersecurity, personal-data processing, operating procedures, and acceptance criteria.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When this systems view is absent from the Preliminary Technical Study, Terms of Reference, design, bidding documents, and inspection plan, the Public Administration transfers to the integrator decisions that should have been made before procurement. The consequences usually emerge during implementation: technically good equipment that does not interoperate, undersized licenses, insufficient storage, doors without local autonomy, limited integrations, analytics that do not achieve the operational purpose, network failures, cybersecurity gaps, conflicts with the LGPD, and disputes about what exactly must be accepted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In public buildings, complexity increases because the system must simultaneously support asset protection, personal safety, service continuity, traceability, auditing, operation by internal or outsourced teams, administrative rules, data protection, and public-procurement requirements. Therefore, the best result does not begin with a brand or catalog: it begins with the <strong>technical definition of the problem, architecture, performance requirements, interfaces, and acceptance evidence<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why is public electronic security an engineering system rather than an equipment list?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A public building may combine visitor reception, administrative areas, technical rooms, archives, a data center or server room, parking, perimeter areas, loading docks, service areas, restricted-circulation spaces, and sectors with different criticality levels. Each zone imposes different requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A camera that adequately serves a circulation area may be unsuitable for facial identification at an entrance. A biometric reader may identify a person, but the decision to release a door may depend on rules stored in controllers, schedules, groups, anti-passback, alarm status, interlocks, network contingency, and integration with other platforms. A VMS may record video, but operations may require event correlation, maps, investigation, forensic export, audit trails, and integration with access control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, procurement must address at least five layers:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Layer<\/td><td>Examples<\/td><td>Engineering question<\/td><\/tr><tr><td>Field<\/td><td>cameras, readers, sensors, locks, contacts, request-to-exit devices<\/td><td>does the device sense or actuate with adequate performance?<\/td><\/tr><tr><td>Control<\/td><td>controllers, I\/O, gateways, edge devices<\/td><td>does the system continue operating when the server or network fails?<\/td><\/tr><tr><td>Communication<\/td><td>Ethernet, PoE, VLAN, fiber, Wi-Fi when applicable<\/td><td>is there sufficient capacity, redundancy, segmentation, and security?<\/td><\/tr><tr><td>Platform<\/td><td>VMS, ACS, PSIM, analytics, database<\/td><td>how are events, rules, users, and evidence managed?<\/td><\/tr><tr><td>Operation<\/td><td>procedures, profiles, response, maintenance, auditing<\/td><td>can the agency operate, investigate, and maintain the system?<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If any of these layers is absent from the scope, the procurement is incomplete. Equipment may be installed, powered, and visible in software without the solution being ready to fulfill the public purpose that justified the investment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The article on <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/seguranca-eletronica-fundamentos-arquitetura-padroes-integracao-2\/\">electronic security fundamentals, architecture, and integration<\/a> explores the technological elements in greater depth. Here, the focus is public procurement and the technical governance required to turn those elements into an object that can be tendered, inspected, and accepted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Law 14.133 requires technical planning before procurement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Law 14.133 structures the preparatory phase as a planning stage. Article 18 requires consideration of technical, market, and management dimensions capable of affecting the procurement. For electronic security, this means that the Public Administration must understand the need before writing specifications or requesting prices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The initial question should not be \u201chow many cameras will be purchased?\u201d It should be: <strong>which risks and operational needs must the system address, in which areas, with what performance, availability, retention, integration, and evidence?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A consistent ETP should address topics such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the security problem motivating the procurement;<\/li><li>current condition of existing systems;<\/li><li>possibility of reusing, integrating, or migrating the installed base;<\/li><li>criticality of areas and assets;<\/li><li>availability and continuity requirements;<\/li><li>need for CFTV, access control, intrusion detection, intercom, LPR, analytics, or PSIM;<\/li><li>impacts on network, servers, storage, power, and cooling;<\/li><li>cybersecurity requirements;<\/li><li>processing of personal and biometric data;<\/li><li>implementation and operating model;<\/li><li>software licensing;<\/li><li>maintenance, updates, and support;<\/li><li>test and acceptance criteria;<\/li><li>vendor lock-in risks;<\/li><li>capacity of the public-sector team to operate and inspect the solution.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The maturity of this stage directly affects the bidding documents. If the ETP merely reproduces an equipment list, the Terms of Reference tend to inherit the same weakness, and procurement begins comparing products without a sufficiently defined architecture.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The most common mistake: specifying a product before defining the operational requirement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In physical security systems, specifications often originate from datasheets. The Public Administration selects a reference camera, server, reader, or platform and turns that product\u2019s characteristics into requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This reverses the logic. First there must be an <strong>operational requirement<\/strong>; then, a technical solution capable of meeting it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider an institutional entrance. The purpose may be to identify people entering, associate the event with a credential, record an image with sufficient quality, keep the door secure during communication failure, allow emergency release according to the security strategy, and record every administrative intervention.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This need must be broken down into verifiable requirements. Selection of the sensor, resolution, lens, WDR, illuminator, biometrics, controller, lock, protocol, or server comes afterward.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IEC 62676-4:2025, applicable to video surveillance systems for security applications, reinforces this approach by addressing VSS planning, design, installation, testing, commissioning, and maintenance. The value of such a reference is not to turn bidding documents into a transcription of the standard, but to require the system to be conceived from its purpose and to have objectively verifiable performance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can security needs be converted into verifiable requirements?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A useful requirement must make three things possible: specify, compare, and test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cHigh-resolution camera\u201d is weak because it does not define a result. \u201c4 MP camera\u201d is more objective, but it still does not demonstrate that the system will fulfill its purpose. Resolution is only one component of the image chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A more mature structure connects:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>risk \u2192 operational objective \u2192 scenario \u2192 functional requirement \u2192 performance requirement \u2192 test evidence \u2192 acceptance criterion.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Element<\/td><td>Definition<\/td><\/tr><tr><td>Risk<\/td><td>unauthorized access to a technical area<\/td><\/tr><tr><td>Objective<\/td><td>prevent entry by a person without valid authorization<\/td><\/tr><tr><td>Scenario<\/td><td>user presents a facial credential or card at the door<\/td><\/tr><tr><td>Function<\/td><td>identify, validate the rule, and grant or deny access<\/td><\/tr><tr><td>Performance<\/td><td>decision within the established time and local continuity according to requirements<\/td><\/tr><tr><td>Evidence<\/td><td>logs, system event, physical door actuation, and contingency test<\/td><\/tr><tr><td>Acceptance<\/td><td>all scenarios approved according to a documented procedure<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This chain is decisive during inspection. If the Public Administration contracts only product characteristics, the inspector can verify whether the installed model matches the proposal but may be unable to demonstrate whether the security objective was achieved.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How should the architecture be defined before procurement?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The architecture should describe relationships among subsystems, zones, networks, platforms, and responsibilities. It need not freeze every manufacturer-specific detail when the contracting model allows later development, but it must establish the boundaries that cannot remain open.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For IP CFTV, the architecture should normally define:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>network topology and segmentation;<\/li><li>recording location;<\/li><li>physical or virtual servers, or appliances;<\/li><li>storage and retention policy;<\/li><li>continuous, event-based, or hybrid recording;<\/li><li>permitted codecs;<\/li><li>analytics and metadata handling;<\/li><li>operator workstations;<\/li><li>user profiles;<\/li><li>evidence export and preservation;<\/li><li>time synchronization;<\/li><li>integration with access control and other systems;<\/li><li>required redundancy;<\/li><li>configuration backup;<\/li><li>update and firmware policy.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For access control, consideration should be given to:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>server-controller-reader architecture;<\/li><li>where access rules are actually executed;<\/li><li>behavior during loss of communication;<\/li><li>controller capacity and memory;<\/li><li>protocols between reader and controller;<\/li><li>credential types;<\/li><li>anti-passback and occupancy rules;<\/li><li>interlocks;<\/li><li>integration with alarms and video;<\/li><li>emergency commands;<\/li><li>power supply and autonomy;<\/li><li>event recording;<\/li><li>identity administration;<\/li><li>migration of existing records.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This care avoids a recurring problem: confusing the identification device with the component that makes the access decision. In robust architectures, readers, biometric terminals, controllers, and servers may divide functions. The bidding documents must establish the responsibility of each layer and the expected behavior in normal, degraded, and contingency modes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The article on <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/arquitetura-controle-de-acesso-corporativo\/\">corporate access-control architecture<\/a> helps explain this separation between identity, decision, door control, and central management.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Interoperability must be specified by function, not by the word \u201cONVIF\u201d<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Interoperability is one of the highest-risk issues in electronic-security procurement. The phrase \u201cONVIF-compatible equipment\u201d is insufficient because ONVIF does not represent a single universal function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organization maintains distinct profiles for specific feature sets. For video, Profile T covers advanced streaming and functions such as H.264\/H.265, image configuration, events, metadata, and, where supported, additional capabilities. For access control, Profiles A, C, and D support different sets of configuration, door control, events, and peripheral functions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ONVIF itself warns that only products officially registered as conformant with a profile should be treated as ONVIF conformant. This must be reflected in technical due diligence: a commercial statement in a datasheet is not enough.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also an important current point. In October 2025, ONVIF announced the end of support for Profile S and recommended Profile T as its successor for video applications. A public specification that simply repeats \u201cONVIF Profile S\u201d from older bidding documents may freeze an outdated technological reference, including authentication mechanisms that the organization itself considers incompatible with current cybersecurity recommendations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To avoid this, the bidding documents should define:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>which function must interoperate;<\/li><li>which profile or interface supports that function;<\/li><li>which versions or minimum conditions are accepted;<\/li><li>how product conformity will be verified;<\/li><li>which test will demonstrate actual integration;<\/li><li>which features may remain proprietary;<\/li><li>which integrations are mandatory for acceptance.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This method reduces the risk of \u201cpartial compatibility,\u201d where video appears in the VMS but events, analytics, PTZ, audio, I\/O, edge recording, metadata, or administration features do not work as expected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Integration among CFTV, access control, and PSIM requires use cases<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An integrated system is not one that merely displays several interfaces on the same monitor. Useful integration must produce operational behavior.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples of use cases:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>an access-denied event automatically opens the corresponding camera;<\/li><li>a forced door generates an alarm, video, and correlated record;<\/li><li>an operator retrieves video associated with a credential event;<\/li><li>a perimeter alarm presents a map, video, and response procedure;<\/li><li>an analytics event creates an operational incident;<\/li><li>license-plate recognition is associated with vehicle access authorization;<\/li><li>loss of controller communication generates a system-health alarm;<\/li><li>recording or storage failure triggers a technical alert;<\/li><li>critical events are forwarded to the PSIM with priority and workflow.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Each case must identify the event source, destination, exchanged fields, acceptable latency, failure behavior, records, responsibility, and test criterion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/a3aengenharia.com.br\/solucoes\/plataformas-de-gerenciamento-de-informacoes-de-seguranca-fisica-psim\/\">PSIM \u2014 Physical Security Information Management<\/a> solution is especially relevant when the Public Administration needs to coordinate multiple subsystems and procedures. But not every building requires PSIM. The requirement should derive from operational complexity, not from the desire to add another software layer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Bidding documents should avoid vendor lock-in without sacrificing performance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Public procurement of electronic security must balance two concerns: interoperability and technical accountability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An excessively proprietary specification may restrict competition and create manufacturer dependence. On the other hand, requiring generic interfaces without defining performance can produce a solution that is formally \u201copen\u201d but functionally limited.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The appropriate strategy is to separate:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>performance requirements;<\/li><li>mandatory open interfaces;<\/li><li>functions that may remain proprietary;<\/li><li>integrations that must be certified or approved;<\/li><li>data that must be exportable;<\/li><li>backup and recovery formats;<\/li><li>license use and continuity rights;<\/li><li>API documentation when applicable;<\/li><li>conditions for future component replacement.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is particularly important for VMS, access-control systems, and analytics platforms because selecting a platform creates life-cycle effects far greater than acquiring an individual camera.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can CFTV be sized without turning megapixels into a design criterion?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Resolution cannot be analyzed in isolation. The design must relate scene, distance, lens, field of view, lighting, motion, compression, image quality, identification purpose, and storage capacity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At an entrance, the purpose may require identification. In a parking area, operations may require license-plate recognition. In a corridor, detection and tracking may be sufficient. At a perimeter, the priority may be reliable detection and intrusion alarms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An <a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-cftv-ip-e-videomonitoramento\/\">IP CFTV and Video Surveillance Design<\/a> should convert those purposes into coverage, positioning, specifications, VMS, storage, network, integration, and tests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The bidding documents should also require design evidence: coverage drawings, calculation reports, bitrate and retention assumptions, camera schedules, network architecture, integration matrix, and acceptance criteria.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Storage must be calculated using explicit assumptions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Storage is one of the items most subject to differences among manufacturer calculators. The result depends on resolution, frame rate, codec, GOP, scene complexity, lighting, motion, VBR\/CBR, event-based recording, retention, and proprietary compression features.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, estimates and proposals must make the assumptions explicit. It is not technically appropriate to compare two storage solutions only by raw capacity in TB.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sizing must distinguish:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>raw and usable capacity;<\/li><li>RAID overhead or equivalent protection;<\/li><li>target retention;<\/li><li>operating margin;<\/li><li>design bitrate;<\/li><li>continuous and event-based recording;<\/li><li>primary and secondary streams;<\/li><li>analytics and metadata;<\/li><li>exported evidence;<\/li><li>future expansion;<\/li><li>disk-replacement policy.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">During inspection, these assumptions must be verified against the configuration actually implemented. A system delivered with a bitrate far below that used in the sizing calculation may achieve contractual retention by sacrificing image quality.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Access control must be tested in degraded mode<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A system may work perfectly while servers, controllers, network, and power are available. That does not demonstrate resilience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The test plan should include loss of communication between controller and server, restart, power failure, battery operation, behavior of critical doors, event preservation, later synchronization, operation of emergency devices, and recovery after failure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Business scenarios should also be tested:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Scenario<\/td><td>Expected result<\/td><\/tr><tr><td>valid credential<\/td><td>access granted according to rule<\/td><\/tr><tr><td>invalid credential<\/td><td>access denied and event recorded<\/td><\/tr><tr><td>access outside allowed hours<\/td><td>rule applied correctly<\/td><\/tr><tr><td>door held open<\/td><td>alarm generated<\/td><\/tr><tr><td>forced door<\/td><td>alarm and video correlation<\/td><\/tr><tr><td>server loss<\/td><td>local behavior according to requirement<\/td><\/tr><tr><td>communication restored<\/td><td>events synchronized and system normalized<\/td><\/tr><tr><td>emergency<\/td><td>doors operate according to the security strategy and applicable legislation<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The existence of a facial terminal does not eliminate the need to understand where credentials, rules, and decisions reside. Depending on the architecture, validation may occur at the device, controller, or central layer, and this design affects performance, availability, and security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Biometrics requires specific LGPD treatment and governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The LGPD classifies biometric data linked to an individual as sensitive personal data. This makes the procurement of facial recognition, fingerprints, iris recognition, or other biometrics different from a simple hardware purchase.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The agency must define purpose, legal basis, necessity, proportionality, retention, security, access, sharing, record of processing activities, and responsibilities between controller and processors. The design should avoid excessive collection and clearly separate biometric templates, images, credentials, and logs when the architecture permits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ANPD has been treating biometrics as a highly relevant regulatory topic. Recent technical documents highlight the potential impact of facial recognition and other biometric technologies on fundamental rights and the need to comply with LGPD principles and legal bases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For bidding documents, this translates into practical questions:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>where are biometric templates stored?<\/li><li>will the manufacturer or integrator have remote access?<\/li><li>will data be sent to the cloud?<\/li><li>is processing performed outside Brazil?<\/li><li>what is the retention policy?<\/li><li>how is a user deleted?<\/li><li>how are backups protected?<\/li><li>which logs record queries and changes?<\/li><li>is there segregation of administrative profiles?<\/li><li>how are software updates performed without unnecessary data exposure?<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The assessment should be proportional to context. Biometrics in a mission-critical area is not necessarily inappropriate; however, its adoption must be technically justified and governed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cybersecurity has become a physical-system requirement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cameras, controllers, intercom devices, servers, and appliances are IP assets. A connected physical-security architecture without proper hardening creates a new attack surface.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design should address:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>network segmentation;<\/li><li>VLANs and ACLs;<\/li><li>authentication and credential management;<\/li><li>disabling default accounts;<\/li><li>HTTPS\/TLS when supported;<\/li><li>certificates;<\/li><li>SNMP and monitoring;<\/li><li>secure NTP and time synchronization;<\/li><li>firmware updates;<\/li><li>version inventory;<\/li><li>configuration backup;<\/li><li>remote access;<\/li><li>logs and auditing;<\/li><li>unnecessary ports and services;<\/li><li>vulnerability management;<\/li><li>life cycle and end of support.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is another reason not to copy old specifications. ONVIF\u2019s 2025 Profile S announcement is an objective example of how interoperability criteria also evolve for cybersecurity reasons.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How should technical qualification be structured without steering procurement?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Qualification should demonstrate capacity compatible with the complexity of the object without turning a technological preference into an undue barrier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In integrated electronic security, the Public Administration may need to verify experience in relevant portions such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>design or implementation of IP CFTV;<\/li><li>VMS at a compatible scale;<\/li><li>access control;<\/li><li>integration among subsystems;<\/li><li>associated networks and storage;<\/li><li>systems in critical operating environments;<\/li><li>commissioning and integrated testing.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The relevance of each portion depends on the specific object. A procurement focused primarily on access control should not require disproportionate experience with video walls, for example.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Team qualification must also reflect actual responsibilities. Multidisciplinary projects may require engineering coordination and specialists in electronic security, networks, electrical systems, cybersecurity, and commissioning.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How should technical proposals be compared beyond price?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two proposals may present the same quantities and similar prices while assuming profoundly different architectures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technical analysis should compare:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Dimension<\/td><td>What to verify<\/td><\/tr><tr><td>Architecture<\/td><td>compliance with the design and interfaces<\/td><\/tr><tr><td>Equipment<\/td><td>full compliance with requirements<\/td><\/tr><tr><td>Licenses<\/td><td>quantity, model, validity, and features<\/td><\/tr><tr><td>Integrations<\/td><td>native, protocol-based, API-based, or custom development<\/td><\/tr><tr><td>Storage<\/td><td>assumptions, usable capacity, and retention<\/td><\/tr><tr><td>Network<\/td><td>ports, PoE, uplinks, redundancy, and segmentation<\/td><\/tr><tr><td>Servers<\/td><td>processing, memory, GPU when required, and expansion<\/td><\/tr><tr><td>Cybersecurity<\/td><td>hardening, updates, and vulnerability management<\/td><\/tr><tr><td>Migration<\/td><td>preservation of records, configurations, and history when applicable<\/td><\/tr><tr><td>Tests<\/td><td>procedures, instruments, evidence, and acceptance<\/td><\/tr><tr><td>Support<\/td><td>SLA, escalation, manufacturer, and integrator<\/td><\/tr><tr><td>Life cycle<\/td><td>discontinuation, compatibility, and future expansion<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This analysis reduces the risk of contracting the apparently lowest-priced proposal and later discovering that essential items were treated as options, extras, or outside the scope.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A3A also provides <a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/apoio-tecnico-licitacao-analise-propostas-engenharia\/\">Technical Support for Procurement and Engineering Proposal Analysis<\/a>, which is especially useful when the evaluation committee needs specialized support to verify architecture, technical compliance, and differences among proposals.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why is reviewing the bidding documents before publication cheaper than correcting implementation?<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Most electronic-security problems that appear during implementation were already latent in the bidding documents: integration without a use case, storage without assumptions, ONVIF without a profile, undefined licenses, and acceptance without a test procedure. An independent technical review before publication allows these gaps to be corrected while they are still inexpensive to resolve.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-tecnica-edital-anexos-licitacoes-engenharia\/\">Learn about Technical Review of Bidding Documents and Attachments for Engineering Procurement<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A large share of execution conflicts originates in ambiguities that predate the contract.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the bidding documents require integration but do not list events and commands;<\/li><li>retention is stated in days without recording assumptions;<\/li><li>the specification requires biometrics but does not define architecture and data processing;<\/li><li>VMS is required without quantifying licenses;<\/li><li>storage is defined only in TB;<\/li><li>the server is described without a workload;<\/li><li>ONVIF is mentioned without profile or function;<\/li><li>the system must be \u201credundant,\u201d but the supported failure is not defined;<\/li><li>acceptance is conditioned on \u201coperation\u201d without a test procedure;<\/li><li>migration of the installed base has no defined responsibility.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-tecnica-edital-anexos-licitacoes-engenharia\/\">Technical Review of Bidding Documents and Attachments<\/a> should verify consistency among the ETP, Terms of Reference, design, quantities, estimate, qualification, evaluation, risk matrix, measurement, inspection, and acceptance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In electronic security, the review must also identify cross-discipline incompatibilities. It is not enough for each discipline to be correct in isolation. A camera may meet its datasheet but exceed the PoE capacity of the specified switch. A set of readers may work but exceed controller capacity or topology. Storage may meet calculated volume while the network cannot support aggregate traffic.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How should electronic-security implementation be inspected?<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Inspecting electronic security requires more than checking installed quantities. Configurations, integrations, licenses, events, logs, storage, contingencies, and performance must be converted into technical evidence that supports the inspector formally designated by the Public Administration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/apoio-tecnico-fiscalizacao-obras-contratos-engenharia\/\">See how Technical Support for Inspection of Engineering Works and Contracts operates<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Article 117 of Law 14.133 establishes monitoring and inspection of contract execution and requires occurrences to be recorded. For electronic systems, inspection should combine physical inspection, document verification, configuration testing, and digital evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/fiscalizacao-por-evidencias-obras-publicas-rastreabilidade-tecnica\/\">Evidence-based inspection<\/a> is especially suitable because many requirements cannot be demonstrated by a photograph.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An installed camera may require evidence of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>model and serial number;<\/li><li>firmware;<\/li><li>stream configuration;<\/li><li>codec and bitrate;<\/li><li>NTP;<\/li><li>resolution and frame rate;<\/li><li>VLAN and address;<\/li><li>VMS integration;<\/li><li>recording;<\/li><li>analytics;<\/li><li>coverage and image quality;<\/li><li>tamper alarms when applicable.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An access-control door may require:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>reader and credential method;<\/li><li>associated controller;<\/li><li>logical address;<\/li><li>power supply;<\/li><li>battery;<\/li><li>lock;<\/li><li>door sensor;<\/li><li>request-to-exit device;<\/li><li>access rule;<\/li><li>events;<\/li><li>communication-failure test;<\/li><li>video integration;<\/li><li>emergency behavior.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/como-fiscalizar-obra-publica-lei-14133-metodo-evidencias\/\">public-works inspection method<\/a> can be applied to electronic systems through baseline control, inspection, nonconformity records, measurement, and progressive acceptance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Inspection must follow detailed design and submittals<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In many contracts, the procurement design does not contain every installation detail. The contractor develops detailed design, shop drawings, diagrams, point lists, final architecture, calculations, and manufacturer documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These documents should not be treated as mere paperwork. They are the opportunity to verify the solution before errors become physical installation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The workflow should define:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>required documents;<\/li><li>responsible authors;<\/li><li>submission deadlines;<\/li><li>review criteria;<\/li><li>status codes;<\/li><li>comment process;<\/li><li>condition for releasing installation;<\/li><li>revision control;<\/li><li>As-Built updating.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Installing before critical documents are approved transfers the agency\u2019s technical control to the field and increases the probability of rework.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Measurement should pay for verifiable delivery, not merely delivered equipment<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Electronic security is particularly vulnerable to early measurement because much of the value is concentrated in equipment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the contract recognizes almost all value upon physical delivery, the Public Administration loses leverage to require integration, configuration, documentation, training, testing, and corrections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A measurement structure can separate milestones such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>approval of detailed design;<\/li><li>supply and inspection;<\/li><li>physical installation;<\/li><li>configuration;<\/li><li>integration;<\/li><li>functional tests;<\/li><li>contingency tests;<\/li><li>As-Built documentation;<\/li><li>training;<\/li><li>commissioning;<\/li><li>provisional acceptance;<\/li><li>correction of open items;<\/li><li>final acceptance.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/boletim-medicao-obras-servicos-engenharia-evidencias-pagamento\/\">Construction Measurement Report<\/a> presents the logic of linking payment to evidence and measurement criteria.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What should be included in the testing and commissioning plan?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The test plan should be developed before implementation is complete. Testing only at the end creates a queue of defects when schedule and budget are already under pressure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IEC 62676-4:2025 includes testing and commissioning in the video-surveillance system life cycle. For an integrated solution, the plan should extend this logic to all subsystems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A mature strategy combines verification levels:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Document verification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Checks models, licenses, designs, point lists, firmware, versions, certificates, backups, network documentation, and manuals.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Physical inspection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verifies installation, mounting, orientation, identification, finish, infrastructure, power supply, protection, grounding when applicable, and conformity with drawings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Functional test<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Demonstrates each individual function: video, recording, access, alarm, relay, sensor, audio, analytics, LPR, or another contracted function.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Integration test<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Demonstrates exchange of events and commands among platforms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failure test<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Simulates loss of server, network, power, storage, controller, link, or another critical component according to the architecture.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Performance test<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verifies retention, image quality, latency, throughput, search capacity, number of streams, analytics response, or other defined indicators.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Operational test<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Validates real procedures with operators, user profiles, investigation, evidence export, alarms, and response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/webstore.iec.ch\/en\/publication\/66755\">IEC 62676-2-11:2024<\/a> is particularly relevant to government environments because it defines minimum interoperability profiles between VMS and cloud systems, including authority-access scenarios. It shows how video interoperability can be specified at functional levels rather than only as generic compatibility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Acceptance must be based on a requirements-and-evidence matrix<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Acceptance should not begin with an equipment list. It should begin with the requirements matrix.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A traceability matrix may contain:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>ID<\/td><td>Requirement<\/td><td>Source document<\/td><td>Verification method<\/td><td>Evidence<\/td><td>Result<\/td><\/tr><tr><td>SEC-001<\/td><td>minimum video retention<\/td><td>TR<\/td><td>analysis + test<\/td><td>storage report<\/td><td>pass\/fail<\/td><\/tr><tr><td>SEC-002<\/td><td>forced-door event correlated with video<\/td><td>design<\/td><td>integrated test<\/td><td>log + capture<\/td><td>pass\/fail<\/td><\/tr><tr><td>SEC-003<\/td><td>local operation during server loss<\/td><td>design<\/td><td>failure test<\/td><td>test record<\/td><td>pass\/fail<\/td><\/tr><tr><td>SEC-004<\/td><td>evidence export with audit trail<\/td><td>TR<\/td><td>functional test<\/td><td>file + log<\/td><td>pass\/fail<\/td><\/tr><tr><td>SEC-005<\/td><td>segregation of administrative profiles<\/td><td>security policy<\/td><td>configuration inspection<\/td><td>user matrix<\/td><td>pass\/fail<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This model reduces subjectivity. Instead of asking \u201cis it working?\u201d, the inspector verifies whether each contracted requirement has sufficient evidence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Commissioning is different from the integrator\u2019s configuration work<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The company that installs the system naturally performs configuration and internal tests. That does not replace a structured verification from the owner\u2019s perspective.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Commissioning should verify whether the system as a whole meets the requirements and is ready for operation. This involves technical independence, test planning, result records, open-item control, retesting, and acceptance documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In complex systems, commissioning can identify failures that do not appear during physical inspection:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>events that do not reach the VMS;<\/li><li>different time zones or NTP settings;<\/li><li>an access rule not replicated to the controller;<\/li><li>failover that does not occur;<\/li><li>a camera that loses analytics when using a particular codec;<\/li><li>storage that cannot sustain the real load;<\/li><li>a temporary or incomplete license;<\/li><li>integration that works only in a specific scenario;<\/li><li>a user with excessive privileges;<\/li><li>a backup that exists but cannot be restored;<\/li><li>a contingency procedure that cannot actually be executed.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning<\/a> structures verification, testing, readiness, and handover with a focus on a deliverable that the owner can actually use.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How should migration of existing systems be handled?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Modernization in public buildings rarely starts from zero. There may be an installed base of cameras, readers, controllers, credentials, servers, cables, switches, racks, and licenses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ETP should decide what will be:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>retained;<\/li><li>integrated;<\/li><li>updated;<\/li><li>migrated;<\/li><li>replaced;<\/li><li>decommissioned.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Migration must have inventory, compatibility, responsibility, and an operating window. In access control, it is essential to define how users, groups, credentials, history, biometric templates, and rules will be handled. In VMS, existing recordings, servers, storage, licenses, and continuity of monitoring during the transition must be assessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An inadequate strategy can create two parallel systems for months, duplicate operations, or create a security window during cutover.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can discontinuation and technology-dependence risks be reduced?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The life cycle of electronic security is longer than the commercial life cycle of many products. Cameras, servers, and software may be discontinued while the building continues to operate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The contract should address:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>manufacturer support period;<\/li><li>update policy;<\/li><li>spare-parts availability;<\/li><li>minimum supported version;<\/li><li>operating-system compatibility;<\/li><li>software update rights;<\/li><li>license transfer;<\/li><li>replacement by successor models;<\/li><li>data export;<\/li><li>documentation and administrative passwords;<\/li><li>termination of the integrator\u2019s remote access.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The Public Administration should not receive a solution that is technically closed, works on day one, and is impossible to maintain in year three.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What evidence should be included in the As Built?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The electronic-security As Built must represent the actual system, not merely update drawings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on scope, the final package should include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>drawings showing device locations and identifiers;<\/li><li>network diagrams;<\/li><li>access-control diagrams;<\/li><li>IP address table;<\/li><li>VLANs and ports;<\/li><li>camera list;<\/li><li>door list;<\/li><li>serial numbers;<\/li><li>models and firmware;<\/li><li>servers and storage;<\/li><li>licenses;<\/li><li>electrical diagrams;<\/li><li>cable and termination list;<\/li><li>integration matrix;<\/li><li>user and profile matrix in a secure format;<\/li><li>configuration backups;<\/li><li>restoration procedures;<\/li><li>test reports;<\/li><li>closed open items;<\/li><li>manuals and warranties;<\/li><li>training records.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The documentation must be sufficient for another qualified professional to understand, maintain, and evolve the system without depending exclusively on informal knowledge held by the original integrator.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who should participate in inspection?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Law 14.133 allows the Public Administration to contract third parties to assist and support inspectors with technical information without transferring the public agent\u2019s own responsibility. Decree 11.246\/2022, within the federal scope to which it applies, details the roles of managers and inspectors and recognizes inspection complexity as an element to consider in appointment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In an integrated security system, the public-sector team may not internally possess all the competencies needed to review VMS, networks, access control, storage, cybersecurity, licensing, and commissioning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/apoio-tecnico-fiscalizacao-obras-contratos-engenharia\/\">Technical Support for Inspection of Engineering Works and Contracts<\/a> can provide inspections, document analysis, tests, records, and technical opinions that support the formally designated inspector.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This separation is important: technical consulting does not replace the inspector\u2019s legal role. It improves the quality of the information available for the inspector\u2019s decision.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can procurement be structured in stages?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A large procurement can be organized into technical gates.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Gate<\/td><td>Condition to advance<\/td><\/tr><tr><td>G0 \u2014 diagnosis<\/td><td>inventory and risks known<\/td><\/tr><tr><td>G1 \u2014 requirements<\/td><td>objectives, architecture, and criteria approved<\/td><\/tr><tr><td>G2 \u2014 procurement<\/td><td>bidding documents and attachments technically consistent<\/td><\/tr><tr><td>G3 \u2014 detailed design<\/td><td>submittals and drawings approved<\/td><\/tr><tr><td>G4 \u2014 installation<\/td><td>infrastructure and devices verified<\/td><\/tr><tr><td>G5 \u2014 configuration<\/td><td>platform and rules configured<\/td><\/tr><tr><td>G6 \u2014 integration<\/td><td>integrated use cases approved<\/td><\/tr><tr><td>G7 \u2014 commissioning<\/td><td>functional, failure, and performance tests approved<\/td><\/tr><tr><td>G8 \u2014 handover<\/td><td>documentation, training, and backups complete<\/td><\/tr><tr><td>G9 \u2014 acceptance<\/td><td>open items closed and formal acceptance completed<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This model prevents the schedule from being treated as a purely physical sequence. Installation advances when the engineering required for that stage is mature.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Technical checklist for electronic-security bidding documents<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before publication, it is worth checking whether the documents clearly answer the following questions:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Need and scope<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>which risks and objectives justify the procurement?<\/li><li>which buildings, areas, and systems are included?<\/li><li>is there an installed base to preserve?<\/li><li>which interfaces are outside the scope?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Architecture<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>where are servers, controllers, and storage located?<\/li><li>is there redundancy? of what, and against which failure?<\/li><li>how do subsystems communicate?<\/li><li>what is the network topology?<\/li><li>how does the system operate during communication loss?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">CFTV<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>what is the purpose of each camera?<\/li><li>is there a coverage study?<\/li><li>how was storage calculated?<\/li><li>which codecs and streams will be used?<\/li><li>which analytics are mandatory?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Access control<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>where is the access decision made?<\/li><li>which credentials are accepted?<\/li><li>what is the offline behavior?<\/li><li>how are emergency doors handled?<\/li><li>which integrations are required?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Software and licensing<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>which modules and license quantities are required?<\/li><li>are they perpetual, subscription-based, or term licenses?<\/li><li>is there recurring cost?<\/li><li>which updates are included?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Interoperability<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>which functions must be interoperable?<\/li><li>which ONVIF profile applies?<\/li><li>how will conformity be demonstrated?<\/li><li>which APIs or SDKs are required?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Cybersecurity and LGPD<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>how will credentials and access be managed?<\/li><li>are there hardening requirements?<\/li><li>how will biometric data be handled?<\/li><li>is there supplier remote access?<\/li><li>which logs and audit trails are mandatory?<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Inspection and acceptance<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>which documents must be submitted?<\/li><li>which tests will be performed?<\/li><li>which evidence will be required?<\/li><li>how will nonconformities be handled?<\/li><li>what defines provisional and final acceptance?<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If several answers depend on future decisions by the integrator, the object is not yet sufficiently mature for competitive and technically controlled procurement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When does it make sense to contract Consulting Engineering before procurement?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Specialized support is especially relevant when the agency:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>has legacy systems from different manufacturers;<\/li><li>plans to migrate VMS or access control;<\/li><li>will use biometrics or facial recognition;<\/li><li>has multiple buildings;<\/li><li>needs to integrate CFTV, access, intrusion detection, and PSIM;<\/li><li>has high-availability requirements;<\/li><li>needs to preserve operations during implementation;<\/li><li>does not have an internal team able to review the architecture;<\/li><li>plans significant investment with a long life cycle;<\/li><li>needs to prepare an ETP, Terms of Reference, design, or bidding documents;<\/li><li>will receive technically heterogeneous proposals;<\/li><li>requires independent inspection, commissioning, or acceptance.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In this scenario, Consulting Engineering acts before the purchase, during selection, and throughout execution. Its role is not to choose a brand for the agency, but to <strong>organize requirements, reduce technical information asymmetry, make proposals comparable, and create evidence for decision-making and acceptance<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Electronic security in a public building is an engineering and technology procurement with a strong operational component. The risk of failure increases when the Public Administration attempts to simplify it into a list of cameras, readers, servers, and licenses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The quality of the result depends on a coherent sequence: diagnosis, requirements, architecture, design, bidding documents, proposal analysis, inspection, testing, commissioning, and acceptance. Each phase must preserve traceability between the problem that motivated the investment and the evidence that will demonstrate compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Interoperability must be verified by function; ONVIF needs to be specified by profile and actual conformity; storage must be sized with explicit assumptions; access control must be tested under failure; biometrics requires data governance; cybersecurity must be part of the architecture; and acceptance must verify the integrated system under operational scenarios, not merely the physical installation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the Public Administration structures these elements before procurement, it increases competition on technically comparable grounds, reduces change orders and interpretation disputes, and preserves its ability to inspect and evolve the solution throughout the life cycle.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">An installed system is not the same as a ready system. Commissioning organizes functional tests, integrations, failures, performance, documentation, open items, and retesting so that acceptance is based on demonstrated requirements \u2014 not merely on the perception that the equipment is powered on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Learn about Engineering Commissioning<\/a><\/p>\n<\/div>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Technical references<\/summary>\n<p class=\"wp-block-paragraph\">[1] BRASIL. Lei n\u00ba 14.133, de 1\u00ba de abril de 2021 \u2014 Lei de Licita\u00e7\u00f5es e Contratos Administrativos. 2021. Available at: <a href=\"https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2019-2022\/2021\/lei\/l14133.htm\">https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2019-2022\/2021\/lei\/l14133.htm<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] BRASIL. Decreto n\u00ba 11.246, de 27 de outubro de 2022 \u2014 atua\u00e7\u00e3o dos gestores e fiscais de contratos. 2022. Available at: <a href=\"https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2019-2022\/2022\/decreto\/d11246.htm\">https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2019-2022\/2022\/decreto\/d11246.htm<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] BRASIL. Lei n\u00ba 13.709, de 14 de agosto de 2018 \u2014 Lei Geral de Prote\u00e7\u00e3o de Dados Pessoais (LGPD). 2018. Available at: <a href=\"https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/l13709compilado.htm\">https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/l13709compilado.htm<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] AUTORIDADE NACIONAL DE PROTE\u00c7\u00c3O DE DADOS. Documentos T\u00e9cnicos e Orientativos \u2014 tratamento de dados pessoais e biom\u00e9tricos. 2026. Available at: <a href=\"https:\/\/www.gov.br\/anpd\/pt-br\/centrais-de-conteudo\/documentos-tecnicos-orientativos\">https:\/\/www.gov.br\/anpd\/pt-br\/centrais-de-conteudo\/documentos-tecnicos-orientativos<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[5] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 62676-4:2025 \u2014 Video surveillance systems for use in security applications \u2014 Part 4: Application guidelines. 2025. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/110108\">https:\/\/webstore.iec.ch\/en\/publication\/110108<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[6] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 62676-2-11:2024 \u2014 Interop profiles for VMS and cloud VSaaS systems for safe cities and law enforcement. 2024. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/66755\">https:\/\/webstore.iec.ch\/en\/publication\/66755<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[7] ONVIF. ONVIF Profiles \u2014 video and access control interoperability profiles. 2026. Available at: <a href=\"https:\/\/www.onvif.org\/profiles\/\">https:\/\/www.onvif.org\/profiles\/<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[8] ONVIF. Profile T \u2014 advanced video streaming. 2026. Available at: <a href=\"https:\/\/www.onvif.org\/profiles\/profile-t\/\">https:\/\/www.onvif.org\/profiles\/profile-t\/<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[9] ONVIF. ONVIF to End Support for Profile S; Recommends Profile T as Replacement. 2025. Available at: <a href=\"https:\/\/www.onvif.org\/pressrelease\/onvif-to-end-support-for-profile-s\/\">https:\/\/www.onvif.org\/pressrelease\/onvif-to-end-support-for-profile-s\/<\/a>.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Frequently asked questions<\/summary>\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-seguran-a-eletr-nica-em-pr-dio-p-blico-deve-ser--78014013\"><strong class=\"schema-faq-question\">Should electronic security in a public building be procured as an equipment purchase?<\/strong> <p class=\"schema-faq-answer\">Not necessarily. In integrated solutions, the object includes architecture, network, software, licensing, storage, access control, integrations, cybersecurity, testing, and documentation. Procurement should reflect the system\u2019s real complexity and the outcomes that must be delivered.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-deve-ser-definido-antes-da-licita-o-de-cft-170bcbd4\"><strong class=\"schema-faq-question\">What should be defined before procuring CFTV and access control?<\/strong> <p class=\"schema-faq-answer\">Risks, operational objectives, areas, architecture, functional and performance requirements, integrations, licensing, infrastructure, cybersecurity, data processing, measurement criteria, testing, and acceptance should be defined.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-basta-exigir-que-c-meras-sejam-onvif-0833001a\"><strong class=\"schema-faq-question\">Is it enough to require cameras to be ONVIF?<\/strong> <p class=\"schema-faq-answer\">No. ONVIF has different profiles, each covering specific functions. The bidding documents should identify the required interoperability function, the applicable profile, and how conformity and integration will be tested.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-profile-s-ainda-deve-ser-usado-como-principal-re-275d91d1\"><strong class=\"schema-faq-question\">Should Profile S still be used as the main video requirement?<\/strong> <p class=\"schema-faq-answer\">ONVIF announced in 2025 that support for Profile S would end and recommends Profile T as its successor for video applications. New bidding documents should review old references and specify current profiles compatible with the required functions.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-a-lgpd-afeta-sistemas-de-reconhecimento-fac-870b43c3\"><strong class=\"schema-faq-question\">How does the LGPD affect facial-recognition and biometric systems?<\/strong> <p class=\"schema-faq-answer\">Biometric data linked to an individual is sensitive personal data. The agency must define purpose, legal basis, security, retention, access, responsibilities, and other controls applicable to processing this data.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-fiscalizar-uma-instala-o-de-seguran-a-eletr-ab5ad66a\"><strong class=\"schema-faq-question\">How should an electronic-security installation be inspected?<\/strong> <p class=\"schema-faq-answer\">Inspection should combine physical inspections, analysis of designs and submittals, equipment verification, configuration validation, functional and integration tests, nonconformity records, evidence-based measurements, and document control.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-que-deve-ser-testado-no-controle-de-acesso-e082951c\"><strong class=\"schema-faq-question\">What should be tested in access control?<\/strong> <p class=\"schema-faq-answer\">In addition to valid and invalid credentials, schedules, door events, rules, video integration, loss of communication, power failure, autonomy, event synchronization, and emergency behavior according to the design should be evaluated.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-qual-a-fun-o-do-comissionamento-em-seguran-a-ele-8b1c7659\"><strong class=\"schema-faq-question\">What is the role of commissioning in electronic security?<\/strong> <p class=\"schema-faq-answer\">Commissioning systematically verifies that the integrated system meets requirements and is ready to operate. It includes functional, integration, failure, and performance tests, documentation, open-item control, retesting, and support for handover and acceptance.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-a-administra-o-pode-contratar-apoio-t-cnico-para-43b6c625\"><strong class=\"schema-faq-question\">Can the Public Administration contract technical support to assist the inspector?<\/strong> <p class=\"schema-faq-answer\">Yes. Article 117 of Law 14.133 allows third parties to be contracted to assist and support inspectors with technical information. The inspector\u2019s legal role remains with the representative formally designated by the Public Administration.<\/p><\/div><\/div>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Supplementary technical materials<\/summary>\n<h4 class=\"wp-block-heading\">Related solutions<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/solucoes\/videomonitoramento\/\">Video Surveillance: IP CFTV, VMS, analytics, and operations<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/solucoes\/plataformas-de-gerenciamento-de-informacoes-de-seguranca-fisica-psim\/\">Physical Security Information Management (PSIM): security integration and command<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/solucoes\/video-analytics\/\">Video Analytics: detection, classification, and automation of video events<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/solucoes\/protecao-perimetral\/\">Perimeter Protection: detection, video surveillance, and integrated response<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Related services<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-cftv-ip-e-videomonitoramento\/\">IP CFTV and Video Surveillance Design<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-tecnica-edital-anexos-licitacoes-engenharia\/\">Technical Review of Bidding Documents and Attachments for Engineering Procurement<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/apoio-tecnico-licitacao-analise-propostas-engenharia\/\">Technical Support for Procurement and Engineering Proposal Analysis<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/apoio-tecnico-fiscalizacao-obras-contratos-engenharia\/\">Technical Support for Inspection of Engineering Works and Contracts<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Main content on this topic<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/como-fiscalizar-obra-publica-lei-14133-metodo-evidencias\/\">How to Inspect a Public Work: method, responsibilities, and evidence under Law 14.133<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/fiscalizacao-por-evidencias-obras-publicas-rastreabilidade-tecnica\/\">Evidence-based inspection in public works<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/gestor-fiscal-contrato-lei-14133-diferencas-atribuicoes\/\">Contract manager vs. inspector under Law 14.133<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-licitacoes-e-contratos-de-engenharia\/\">Complete Guide to Procurement and Contracts for Engineering Works and Services<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Related technical content<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/arquitetura-controle-de-acesso-corporativo\/\">Corporate Access-Control Architecture<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-analiticos-de-video\/\">Complete Guide to Video Analytics<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/seguranca-eletronica-fundamentos-arquitetura-padroes-integracao-2\/\">Understanding Electronic Security: fundamentals, architectures, standards, and integration<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/boletim-medicao-obras-servicos-engenharia-evidencias-pagamento\/\">Construction Measurement Report<\/a><\/li><\/ul>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>How to procure electronic security for public buildings: CFTV, access control, integration, ONVIF, LGPD, inspection, commissioning, and acceptance under Law 14.133.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"1ca45088-4aac-43f3-8f21-1e9698aae17d","_a3a_i18n_canonical_slug":"electronic-security-public-buildings-procurement-integration-inspection"},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-74175","articles","type-articles","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74175\/revisions"}],"predecessor-version":[{"id":74183,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74175\/revisions\/74183"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=74175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=74175"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=74175"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=74175"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=74175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}