// C-CURE 9000 HEALTH CHECK · HANS STUDY · ONTARIO, CANADA
C-CURE 9000 Health Check
Access control fails differently from video. When a recorder struggles you lose footage you might never have needed. When C-CURE struggles, a door does not open for somebody standing in front of it, or it opens for somebody who should not be there. The system carries on reporting itself healthy either way.
What the Health Check covers
C-CURE 9000 problems rarely stay in one layer either. A door that behaves oddly can be a controller firmware mismatch, a CrossFire service under memory pressure, a SQL bottleneck, a journal that has never been maintained, or a third-party integration doing something the integrator did not document. Reviewing one layer in isolation is how these systems stay half-broken for years.
Application server and services
CrossFire service health, memory behaviour under sustained load, service dependencies and start order, and the faults that surface as intermittent client disconnects rather than as an obvious failure.
SQL Server
C-CURE lives on its database more than most platforms. Memory configuration, maintenance plans, index and journal growth, backup and restore that has actually been tested, and version support against the C-CURE release.
iSTAR controller estate
Firmware consistency across controllers, cluster and encryption configuration, memory and cardholder capacity against the population actually loaded, and offline behaviour when the server is unreachable.
Redundancy and failover
Whether the design has real redundancy or a single instance carrying an entire estate. Failover behaviour tested rather than assumed, and what happens to in-flight events during a switch.
Personnel and credentials
Data hygiene at scale, clearance and access level structure, stale cardholders, credential technology and migration exposure, and whether the permission model can still be explained by anyone.
Integrations
Elevator control, video, intrusion, visitor management and directory sync. The highest-risk surface in most C-CURE deployments and the first thing blamed when something else is wrong.
Doors and field hardware
Supervision configuration, held and forced door handling, request to exit behaviour, lock power and battery calculations, and whether alarms mean anything or are routinely cleared unread.
Security and lifecycle
Operator privilege model, audit trail and journal retention against policy, certificate and encryption posture, patch discipline, and version currency against support.
Common issues identified
The pattern in C-CURE estates is different from video platforms. One application server quietly carrying access control for buildings that were never meant to share a single point of failure. Controller firmware that drifted apart over successive service visits. A database nobody has maintained since commissioning, with a journal that has grown for years. Access levels that accumulated until nobody can say who can go where. Lock power calculated once, at handover, before half the doors were added.
The one worth calling out specifically: elevator integration takes the blame for a great many faults that are not the elevator interface at all. On a multi-tower estate I worked through, the failures traced to software faults and configuration inside C-CURE, not to the interface everyone had been arguing about. That distinction matters, because one of those is a support case and the other is a re-architecture.
The full engagement: access control stabilisation and a core network rebuild across a multi-tower complex.
Who this is for
Organisations where C-CURE 9000 controls access to something that matters, and where nobody can currently say with confidence how it would behave under failure. Commercial real estate, healthcare, education, government, and enterprise campuses.
It is most useful when the system has grown past its original design, when it changed hands between integrators, when an upgrade or expansion is coming, or when doors have started behaving in ways nobody can explain.
What you receive
The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.
- A findings report organized by severity and by system layer, readable by both the security team and the IT team.
- Specific, configuration-level recommendations tied to published guidance and real operational practice.
- A prioritized action list separating what to fix now, what to schedule, and what to design around.
- A working session to walk through the findings and answer what the report raises.
Recommendations do not change based on who is selling. There is no product being steered toward at the end of this.
Scope and pricing
Fixed price, agreed in writing before the work starts. No hourly meter, no scope creep, and no invoice larger than the conversation suggested. Nothing is sold at the end of it either, which is the independence policy.
// Start here
Starter health check
$500
One system, any size
Remote, 90 minutes, live
- Version position against end of life and end of support
- The upgrade path in order, with the traps on it
- Obvious risks visible without a full review
- A straight answer on whether a full health check is worth your money
Credited in full against a full health check booked within 30 days.
// Most common
Health check, single site
$4,500
One site, up to 150 doors
Remote. Remote unit or on site available
- Full review across every layer listed on this page
- Findings report by severity and by system layer
- Configuration-level recommendations tied to published guidance
- Prioritized action list separating now, scheduled, and design-around
- A 90-minute working session to walk it through
// Multi-site
Health check, multi-site
$9,500
Up to 3 sites, up to 500 doors
Remote. Remote unit or on site available
- Everything in the single-site review, across the estate
- Redundancy, failover and database availability reviewed as one system
- Cross-site behaviour checked against what the design assumed
- A 90-minute working session to walk it through
// Larger estates
Enterprise
From $18,000
Beyond 3 sites or 500 doors
Scoped per engagement
- Scoped and priced in writing before anything starts
- Unusual integration, compliance or jurisdictional requirements accommodated
Extend a tier instead of jumping to the next one
Estates rarely land neatly on a boundary. If yours sits just past one, add to the tier below rather than paying for the one above. The rates follow the same slope as the tiers, so extending is never a worse deal than upgrading.
Cameras, doors, readers or controllers beyond the tier allowance. Counted as configured, not as licensed. (per 100)
A further site beyond the tier allowance, reviewed to the same depth and included in the same report. (per site)
Pre-configured appliance shipped to site and returned. See delivery below. (per deployment)
Where physical inspection is required. Travel agreed in writing before it is incurred. (per day, plus travel at cost)
A further 90-minute session, usually for a different audience such as IT, operations or a vendor. (per session)
The findings translated into a short document for a board, council or executive, written to be read by somebody non-technical. (one-off)
Findings inside five business days rather than the standard window. Subject to availability.
How the work is delivered
Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.
A pre-configured unit ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.
Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.
Where the work genuinely requires being in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Day rate plus travel at cost, agreed in writing up front and never added afterwards.
What a health check does not include
Listed because an unstated exclusion is what turns a fixed price into an argument at invoice time, and that is the exact failure this practice exists to review other people for.
- Remediation. The report says what to fix; fixing it is a separate engagement or your own team.
- Configuration changes. Nothing is altered on a live system during a review.
- Licence, hardware or software costs, which are yours and are bought direct.
- Vendor support cases, escalations, or dealings with your integrator on your behalf.
- On-site attendance, unless added explicitly.
- Ongoing monitoring or a retainer. A health check is a point-in-time assessment.
Prices are for a C-CURE 9000 environment and are held for 30 days from quotation. Travel, where an on-site day is added, is charged at cost and agreed in writing before it is incurred.
Related advisory areas
Access Control Design →
Door schedules, hardware selection, panel layout, power calculations, egress and code.
Security Network Design →
The network under the controllers. A surprising share of access control faults live there.
Expert Opinion →
When the system has already failed and there is a disagreement about why.
Health checks for other platforms
Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.
Genetec Security Center →
Architecture, roles and sizing under real load.
Milestone XProtect →
Edition, Device Pack currency and support entitlement.
Avigilon Unity and Alta →
Which product family you are in, and what that decides.
AXIS Camera Station →
Edge analytics, and the device estate that limits them.
Lenel OnGuard →
Version position, database age, and access level sprawl.
Kantech EntraPass →
Edition ceiling, gateway topology, and controller firmware.
Find out how it behaves before it has to
Access control is judged on the day it fails. Everything that decides that outcome was configured, sized or skipped long beforehand.
Independent of Software House, Johnson Controls, and every integrator involved. See the independence policy.