Drag
LEARN
MORE

The SAFETY Act Buyer’s Guide: How to Spot Proven Security Technology 

Thomas Standley
Thomas Standley
Access control Accreditation Credentialing Events Executives & Senior leaders IT & Technology professionals Operations leaders SAFETY Act Security leaders Sports Stadiums & arenas Technology Venue leaders

Security technology is easy to claim. It is harder to prove. 

Leading industry insights from the SAFETY Act webinar, Inside the SAFETY Act: What It Means for Vendors, Venues and Security Leaders. 

Introduction 

When you are responsible for a venue, stadium, major event or public-facing organization, the security technology you select becomes part of your risk posture. 

It influences who gets access, how decisions are made, what your team can see in real time, and how confidently you can respond under pressure. 

That is why choosing security technology can no longer be based on claims alone. 

You need to know whether the technology has been tested, evidenced and validated in the environments where it will actually be used. 

“The SAFETY Act is not just liability protection. It is about resilience, collaboration and building a stronger national security framework.” Lt. Luis Moncayo, NYPD SHIELD / NYPD Intelligence & Counterterrorism Bureau

That was one of the clearest takeaways from the recent SAFETY Act webinar, Inside the SAFETY Act: What It Means for Vendors, Venues and Security Leaders. The discussion brought together security leaders, venue operators, risk specialists and technology providers to explore how the SAFETY Act is shaping the way organizations think about anti-terrorism technologies, operational resilience and vendor selection. 

For buyers, the message was direct: 

“The market is crowded and buyers are increasingly faced with competing claims around security, resilience and operational effectiveness.” 

In that environment, strong language is not enough. 

Many platforms describe themselves as secure, resilient, enterprise-ready or counter-terrorism aligned but those words only matter if they can be backed up. 

One of the most powerful warnings from the webinar was around “security washing” — where security terminology is used to position a product as credible, even when it has not been properly stress-tested or independently validated. 

“The security market is heavily saturated with what we call security washing.” Peder Berg, CEO, Accredit Solutions  

A platform may look polished in a demo and may claim to strengthen security, improve resilience or support compliance but if those claims have not been tested in real operational environments, buyers are still being asked to take a leap of faith.  

Many of the considerations in this guide are drawn directly from the webinar and from Accredit Solutions’ own experience of successfully achieving both DHS SAFETY Act Designation and Certification. Having completed that rigorous independent evaluation, we have first-hand insight into the standards, evidence and operational maturity required of recognized anti-terrorism technologies. 

Your evaluation criteria need to change 

Traditionally, technology procurement has focused on features, pricing, implementation, user experience and service support. But when you are evaluating security technology, especially technology that will operate in a high-risk venue or major event environment, you need to go further. 

The question is not only “What does this platform do?”, but also “How do you know it works?” And that means you need evidence of operational maturity. 

When evaluating security technology, ask whether it has been deployed in comparable environments, tested under operational pressure, and whether the vendor can demonstrate real-world performance, auditability and integration into live security workflows. 

You need to know whether the system can help your team make access decisions consistently and whether those decisions can be evidenced later. 

So, it’s important to know whether current clients are willing to provide a reference. 

The SAFETY Act raises the standard because it forces vendors and operators to move from assertion to evidence and helps venues and organizers strengthen their wider risk posture. 

If you can demonstrate that the technologies you rely on have been independently evaluated, you strengthen your defensibility, support governance obligations and gain additional confidence under scrutiny. 

Accredit Solutions recently became one of the first access-control-enabled credentialing technology providers to achieve both U.S. Department of Homeland Security SAFETY Act Designation and Certification. Through that process, Accredit Solutions underwent extensive independent evaluation of its technology, operational effectiveness and supporting evidence. 

SAFETY Act validation goes beyond standard compliance 

The webinar made clear that the SAFETY Act process is different from many compliance frameworks you may already recognize. Frameworks such as ISO 27001 or SOC 2 remain important as they address areas such as information security, governance, policies, controls and data handling. 

But the SAFETY Act asks a more operational question, “Does the technology or security program deliver the anti-terrorism outcome it claims?” 

“The SAFETY Act goes further and deeper into validating whether your operational claims and security outcomes actually hold up in real-world environments.” Thomas Standley, President, Accredit Solutions USA

The SAFETY Act process looks at the specific claims being made, it examines deployment evidence, reliability, workflows, auditability, operational use and how the technology supports the security outcome in practice. 

Just because a vendor has strong internal controls, may meet recognized information security standards doesn’t automatically prove the technology can support live operational security in a complex venue environment. 

“We couldn’t just say our technology improves venue security or strengthens operational resilience. We had to demonstrate it operationally and evidence it.” Thomas Standley, President, Accredit Solutions USA

The most credible vendors are prepared to have their claims examined. 

Why should you care that a vendor has SAFETY Act Designation and Certification? 

For buyers, SAFETY Act Designation and Certification provides independent evidence that a technology has been assessed beyond a traditional procurement process and a signal of operational maturity, evidential rigour and real-world validation. 

It means the technology has undergone independent evaluation, and the vendor has submitted its technology, processes, documentation, deployment history, operational workflows, performance evidence and proof of how the technology contributes to the claimed security outcome and been assessed against real-world operational outcomes. 

It gives you added confidence that the product has been examined beyond a normal sales or procurement process and looks beyond whether a product has attractive features – it examines how the technology supports operational security in practice. 

A SAFETY Act award signals that the vendor has engaged seriously with anti-terrorism risk, operational resilience and the evidence required to support high-stakes security environments. 

For you, that’s critical to know because your procurement decisions may one day need to be explained. 

For example:  

  • Why did you choose this vendor? 
  • Why did you select this technology? 
  • What evidence supported the decision? 
  • How did it strengthen your security posture? 
  • How did it help you demonstrate responsible decision-making? 

Selecting a SAFETY Act designated and certified technology can help show that your security procurement decision was made carefully, responsibly and with evidence in mind. 

It doesn’t replace the need to assess fit, functionality, integration or service quality but it should form part of your risk-based procurement process. 

Confidence under scrutiny 

The value of SAFETY Act Designation and Certification is not only that a vendor has gone through a rigorous process but the true value is what that process gives you in return. 

Liability awareness 

  • Your security leaders, legal teams and executives need to know that the technologies you select are not creating unnecessary exposure. 
  • Outcome: SAFETY Act designated and certified technologies can help support a more informed liability strategy because the vendor’s claims have been independently reviewed. 

Defensibility 

  • After an incident, your organization may be asked to explain why certain technologies were selected, what controls were in place and whether reasonable steps were taken. 
  • Outcome: Using independently evaluated technology can help strengthen the defensibility of those decisions. 

Risk posture 

  • Technology selection is part of your venue’s wider risk posture. 
  • Outcome: A proven system can help reduce reliance on manual judgment, improve visibility, strengthen audit trails and support more consistent security outcomes. 

Insurance confidence 

  • Insurers and risk advisors want evidence. 
  • They want to understand what controls exist, how decisions are made and whether your organization can prove that its systems support risk reduction. 
  • Outcome: SAFETY Act status can provide useful additional confidence in those conversations. 

This is why suppliers go through the SAFETY Act process, not just to gain recognition but to prove that their technology can support serious security outcomes. 

And it is why you should pay attention when selecting technologies that form part of your security operation. 

Proven security technology should be operationally specific 

When you are evaluating security technology, be cautious of vague claims. One of the strongest takeaways from the industry lead webinar was that vague security claims should raise concern. 

The product should be specific about the risk it helps address, the operational problem it solves and the evidence that supports its role. 

For credentialing and accreditation, this is especially important. 

Historically, accreditation has often been seen as an administrative process: collect data, approve applications, print passes and manage badge distribution. 

That assumption is increasingly outdated in major venues and events where identity, access permissions and movement control form part of the wider security architecture. Credentialing helps determine who is authorized, what they are allowed to access and whether that permission should still be valid. 

“We’re at the identity layer, the credentialing layer, the operational access decision layer.” Thomas Standley, President, Accredit Solutions USA

Your credentialing platform should support live operational trust and help your team understand who a person is, why they are there, whether they have been approved, what access they should have and whether that access can be changed or revoked when circumstances change. 

“That’s very different to simply printing badges or issuing passes.” Thomas Standley, President, Accredit Solutions USA

This changes the evaluation criteria. 

A proven accreditation platform should produce credentials AND should support identity assurance, access governance, operational visibility, audit trailsand real-time control. 

If your venue relies on visual checks today, consider the risk 

The webinar highlighted a practical risk that many venues still face; over-reliance on manual processes and visual checks. 

A badge may look valid, a pass may appear familiar, a guard may recognize someone but in high-pressure environments, visual judgement alone is not a robust access control model. 

“Many of those decisions can’t rely on visual checks or manual processes anymore.” Thomas Standley, President, Accredit Solutions USA

In real-world environments, people make mistakes, processes vary by gate, shift or contractor, temporary staff may not understand every access rule, or someone may still be carrying a credential that should have been revoked. 

If your venue relies on visual checks today, consider what happens when access rights change quickly.

  • Can your team revoke access instantly? 
  • Can a gate team see that change in real time? 
  • Can the system prevent entry if a credential is invalid? 
  • Can permissions be changed without reprinting passes? 
  • Can security teams see the decision and the reason behind it? 
  • Can access events be audited after the fact? 

Your security team should be able to make access decisions based on live, reliable and enforceable information, not interpretation at the gate. 

And a proven platform should give your team control before a mistake becomes a risk. 

Evidence should include real-world deployment 

The SAFETY Act discussion repeatedly returned to evidence. Real-world evidence. 

You should be cautious of technology that has only been demonstrated in controlled environments rather than deployed at scale. 

When you’re evaluating a vendor, you need to understand where and how the technology has been deployed, and whether the system has operated in environments with comparable scale, risk and complexity. 

For major venues and events, that complexity may include: 

  • Multiple stakeholder groups 
  • Temporary and rotating workforces 
  • Contractors and suppliers 
  • Media and broadcast teams 
  • VIPs and guests 
  • Operational staff 
  • Back-of-house areas 
  • Restricted zones 
  • Multiple approval workflows 
  • Changing access rights 
  • High-pressure event-day conditions 

If a vendor can’t explain how its technology performs in these conditions, it may not be ready for them. 

A proven security technology should be able to show how it supports the full operational picture. 

Documentation is part of the product’s value 

Another major webinar takeaway was that documentation is central to security maturity. If a system is making access decisions, validating credentials or supporting a security workflow, those actions need to be recorded. 

When you are evaluating technology, you need to know what the platform documents. 

  • Can your team audit access decisions? 
  • Can reports be produced quickly? 
  • Can your organization show who had access, when, why and under what approval? 
  • Can changes be traced? 
  • Can revoked credentials be evidenced? 
  • Can the technology support post-event review, investigation or insurance discussions? 
  • Can your organization demonstrate not only what decision was made, but why it was made? 

In the SAFETY Act context, documentation is critical because it helps prove that processes aren’t only defined but followed. 

For venues and events, this is equally important outside the SAFETY Act process. After an incident, your leaders may need to show what was known, what was decided and what action was taken. 

Technology that can’t provide evidence leaves your organization exposed. 

Red-team testing: your technology should support improvement, not just operation 

Another important lesson from the webinar was that security technology should not be static, the strongest systems help your organization learn and improve. 

Red-team testing was a major part of the discussion.  

What is red-team testing? 

Red teaming is the process of safely and deliberately testing whether people, processes and technologies can be bypassed. It helps organizations identifyand fix security weaknesses before they become real incidents. 

In a venue or event environment, red teaming may involve authorized personnel posing as spectators, contractors, media, staff or credential holders to test whether they can gain access to restricted areas without proper authorization. For example, they may test: 

  • Whether a badge is checked properly
  • Try to enter through a staff route
  • Attempt to access back-of-house areas, loading docks, broadcast compounds, command areas or restricted zones
  • Whether a revoked credential still works
  • Whether a gate team relies only on visual recognition.

The purpose is to expose weaknesses safely, so they can be corrected before a real threat actor finds them.

“You’ve got to make corrections, whether you pass or fail.” Brian Maguire, USTA / US Open

When you are evaluating security technology, consider whether it can support this test-and-improve culture. 

If a red-team exercise exposes a problem with credential checking, access control, revoked permissions or movement into restricted spaces, can the technology help correct the issue? 

  • Can rules be updated quickly? 
  • Can access be restricted immediately? 
  • Can workflows be improved? 
  • Can reports show what changed? 
  • Can your organization prove the correction was made? 
  • Can your team retest the process and evidence the improvement? 

Red-team findings are only valuable if they lead to action. A mature security platform should help your leaders identify gaps, act quickly, document the change and strengthen the system over time. 

Vendor selection is now part of risk management 

One of the strongest commercial takeaways from the webinar was that vendor selection itself is becoming a security decision. 

The technologies you select for credentialing, access control, screening, surveillance, incident response and workforce management are part of your organization’s risk posture. 

They influence who gets access, how decisions are made, what can be seen in real time and how confidently your leaders can respond under pressure. 

That means your vendor evaluation needs a security lens. You need to know: 

  • Whether the vendor understands your threat environment. 
  • What operational risk they help reduce
  • Whether they have been independently reviewed
  • Can they show deployment evidence
  • Can they support your wider security program
  • Can they integrate with public safety, command, access control or operational workflows
  • Can they prove maturity

This is why SAFETY Act Designation and Certification matters. They give you an additional layer of confidence that a technology has gone through a rigorous assessment process and has been evaluated against specific security claims. 

In practical terms, this can help you answer internal questions from legal, risk, insurance, procurement and executive teams: 

  • Why this vendor? 
  • Why this technology? 
  • What evidence supports the decision? 
  • How does this strengthen our security posture? 
  • How does this help us demonstrate responsible decision-making? 

This gives you confidence in knowing you’ve selected a technology that has been independently evaluated against its security claims. 

What this means for credentialing and accreditation 

For Accredit Solutions, the SAFETY Act discussion reinforces a clear market shift. 

Accreditation is no longer simply about pass production, it’s about trust, access and control. 

In simple terms, you need: 

  • Visibility 
  • Control 
  • Evidence 
  • Confidence that decisions are not being made manually, inconsistently or too late 

Modern accreditation supports that by connecting identity, permissions and operational access in one live system and helps reduce blind spots, improve accountability and strengthen the security architecture around people movement. 

That’s why credentialing belongs in the same conversation as counter-terrorism preparedness, access control and operational resilience. 

Final takeaway: buy proof, not promises 

The SAFETY Act webinar made one thing clear for buyers: security technology must be proven. 

  • Not just described
  • Not just demonstrated
  • Proven

The technology you select today may be scrutinized tomorrow by executives, insurers, legal teams, regulators, public safety partners or investigators. 

You need confidence that your decisions are defensible. 

SAFETY Act Designation and Certification gives you that additional layer of independent validation showing that a vendor has been required to evidencewhat its technology does, how it works and how it supports real-world security outcomes. 

That should shape every procurement conversation. 

Do not buy the loudest promise. Buy the strongest proof. 

About Accredit Solutions 

Accredit Solutions is a global leader in accreditation, credentialing and access management technology for high-stakes live environments. 

Trusted by major sports organizations, venues, events and public-sector clients around the world, Accredit Solutions helps operations and security leaders manage identity, approvals, permissions and access with confidence. 

The Accredit Solutions platform provides a single source of truth for accreditation, helping teams replace manual processes with real-time visibility, controlled workflows and auditable decision-making. From major events and stadium operations to complex multi-stakeholder environments, Accredit Solutions enables leaders to know who is authorized, where they can go and whether that access should still be valid. 

Accredit Solutions has achieved both SAFETY Act Designation and Certification from the U.S. Department of Homeland Security, recognizing the platform’s role as a qualified anti-terrorism technology. This reflects the company’s commitment to evidence-led security, operational resilience and technology that performs in real-world environments. 

With Accredit Solutions, accreditation becomes more than a credential. It becomes a live trust layer for safer, smarter and more controlled operations. 

To find out more or to speak to us, get in touch.

 

Want the latest news straight to your inbox?