Three technologies, one job description: show that an officer was somewhere. They are not interchangeable, they fail in different ways, and — the part that gets skipped — they do not prove the same thing. The gap only shows up months later, when a client disputes a tour and the evidence has to hold up in a meeting.
Here is the comparison without the vendor deck: what each one does physically, what someone can fake, and which post each one belongs at.
The physical difference
QR is printed. Ink on a substrate, no electronics. The officer’s camera reads it from a comfortable distance, it costs almost nothing per point, and a replacement is a PDF, a printer and two minutes with double-sided tape.
NFC is a passive tag: a chip and an antenna, no battery. It works at 13.56 MHz on proximity standards such as ISO/IEC 14443, specified for operation up to about 10 cm; with a phone in a guard’s hand, that means bringing the device within a few centimetres of the tag. The phone’s field powers the chip for the length of the read. That forced proximity is the real advantage over QR, and it is worth stating plainly: NFC cannot be read from across the yard or through a truck window. QR can.
BLE is a Bluetooth Low Energy beacon. Unlike an NFC tag, it runs on a battery, it transmits on its own schedule, and a phone picks it up from several metres away — tens of metres in the open. Distance is inferred from signal strength, and that inference is noisy: a hand or a body between beacon and phone can collapse the reading even when the beacon is right there.
What each one actually proves
This is the question that matters when there is a complaint on the table.
QR proves that a camera saw an image. That is the whole claim. A printed code can be photographed and scanned later from a screen, from the break room, from the other end of the route. This is not a hypothetical attack — it is the first idea anyone has when the alternative is walking to the far corner of a dark lot at 3 a.m.
NFC proves that a phone came within centimetres of a specific tag. Much harder to fake from a distance. But the tag is still an object, and an object can be pried off a wall and carried in a pocket. That is where the guarantee ends.
BLE proves that a phone was somewhere near a beacon — where “near” is anything from one to thirty metres depending on walls, bodies and interference. It is a reasonable signal of presence in an area. It is not evidence that anyone stood at a specific point. If the checkpoint is “the substation door” and the beacon reads from the corridor across the way, the record cannot tell those apart, and neither can you six weeks later.
Which is why the checkpoint can never be the whole record
All three share the same underlying weakness: a checkpoint is a token, and tokens move. What turns a scan into evidence is not the paper or the chip — it is what the server keeps around it: which identified user scanned, from what GPS position, and at what time the record was sealed. A scan of “north gate” arriving from a coordinate eight miles away is a very short conversation.
One detail worth stating out loud, because it changes how a report should be read: a checkpoint scan does not carry a timestamp from the phone. The server stamps the time when the record arrives. If an officer walked a basement with no coverage and the data uploaded on the way out, the recorded time is the upload, not the walk-by. That does not invalidate the tour, but you want to know it before you argue minutes with a client, and the supervisor reviewing the report wants to know it too.
The offline queue does cover other things — incidents, visitor entries, and the start and end of a tour — and for those the app keeps the time the event actually happened. Attendance is the exception: a clock-in needs a live connection at the moment it happens, and the app does not keep it on the device for later. Worth designing around when a route runs through underground levels.

Compatibility, where deployments quietly break
QR has no compatibility question. Any phone with a camera reads it.
NFC has one, and it needs answering with your actual device inventory rather than an assumption:
- Android. Most mid-range and flagship handsets have NFC hardware. Plenty of budget models do not. If officers use their own phones, this is a survey, not a guess.
- iPhone. Reading tags from inside an app has been possible since the iPhone 7 through Core NFC, with the app open and a read session the user starts. Background tag reading — tap the phone with nothing open — only arrived with the iPhone XS. For a guard tour this is rarely the blocker, because the officer already has the app open at the point. It becomes a blocker when somebody sold the site on “just tap the phone.”
And one piece of physics that has ruined entire installs: an NFC tag stuck directly onto metal — a door frame, an electrical cabinet, a shipping container — will not read. On-metal tags with a ferrite layer exist for exactly this. Finding that out after mounting forty tags on a loading dock is an expensive afternoon.
Choosing per point, not per site
Outdoors and exposed. Sun and rain kill a printed code gradually: three seconds to read, then ten, then the officer gives up. A rugged NFC tag survives it. If the site is an hour away, NFC pays for itself in avoided trips. If the site is ten minutes away and you own a printer, QR is cheaper even reprinting twice a year.
Basements and dead zones. All three read fine without a network — none of them needs a signal to be scanned. What changes is the recorded time, as above. If underground timing matters to the contract, put a checkpoint at the entry and another at the exit of the dead zone so the report can bracket the gap.
Hazardous or explosive atmospheres. A BLE beacon is powered electronics and lands squarely in the certification conversation for equipment in explosive atmospheres. A passive NFC tag and a printed code carry no energy source of their own. That said, the officer’s phone is powered electronics too — in these areas the site’s safety authority sets the rule, not the software vendor. Ask before mounting anything.
Public areas where people touch things. Lobbies, malls, buildings with tenants: codes get peeled off because they look untidy, tags get picked at out of curiosity. Fast replacement wins here, and fast replacement is QR. A new code is an email. A new NFC tag is an order, a programming step and a site visit.
High turnover. The more the roster churns, the less you can rely on a veteran knowing where the tag is hidden. Large, obvious, well-signed checkpoints with a reference photo in the post orders cause fewer training incidents than a discreet disc somebody has to be told about.
When not to use BLE at all. If the contract requires proof of presence at a specific point, a beacon whose range is measured in metres is the wrong tool — it cannot separate “at the door” from “walked past the corridor.” Add battery maintenance, which is a recurring task nobody budgets and which fails silently: a dead beacon does not raise its hand, it just stops appearing.
What CGuardPro supports
CGuardPro works with QR and NFC checkpoints. We do not push BLE for the reason above: a beacon that reads from metres away does not prove what a client wants proven, and it adds a battery-powered consumable to an operation that already has enough of them.
The QR guard tour system ties each point to an identified officer and a position; GPS guard tracking fills in the route between points; and what the officer finds along the way belongs in the daily activity report, which is the document that actually gets read during a dispute. The full picture sits in patrol software and on the features page, and the durability-and-cost side of the QR-versus-NFC argument is covered in more depth in NFC vs QR checkpoints.
The short version
- QR — near-zero cost, instant replacement, universal support. Photographable, so the server has to validate position and time.
- NFC — forces physical proximity, survives weather, costs per tag. Check your handset fleet and buy on-metal tags where the mounting surface is steel.
- BLE — approximate presence in an area, with batteries to maintain. Do not use it as proof of passage through a specific point.
Starting from zero, the sensible order is QR everywhere, NFC at the points that get destroyed or that demand provable proximity, and no beacons until someone can name a problem the other two do not already solve. If you want a second opinion on a specific site, talk to us.