
Most Johnson Controls migrations start the same way: a C•CURE 9000 server needs a hardware refresh, exacqVision recorders are approaching end of life, or a maintenance renewal has you questioning whether the same setup is worth reinvesting in. Whatever brought you here, the question underneath all three is the same: what does moving off Johnson Controls actually involve?
The honest answer is that some of your deployment carries over and some of it doesn't, and the split isn't where most vendor pages suggest. Your cameras, cabling, readers, locks and credentials usually survive. Your recorders and your door controllers don't. This guide covers what stays, what gets replaced, what it costs you in hardware, and how to time the transition around your existing contracts.
If you've already confirmed your cameras are ONVIF-compliant, skip to the migration steps. If you're still deciding whether it's the right time, jump to the final section.
A Johnson Controls deployment typically spans access control, video management, and intrusion detection. The migration comes down to what can stay and what needs to be replaced, and video and access control answer that question differently.
Your ONVIF-compliant IP cameras, cabling, and PoE switches stay. Coram Point works with any ONVIF-compliant or RTSP camera streaming H.264 or H.265, which is usually where the bulk of the sunk cost sits. That codec requirement is worth checking during the audit rather than after: older cameras in a long-lived exacqVision estate are the ones most likely to fail it.
What gets phased out is the exacqVision or victor recorder layer, along with the associated client licensing. Note that this is a hardware swap rather than a hardware elimination: Coram records to a local Coram Point appliance at each site, which handles video storage and edge AI processing while the cloud handles management, alerting, search and viewing. You're replacing a recorder you patch and refresh yourself with one the vendor manages, not removing on-site hardware from the design.
Coram Point is required for video — there's no direct-to-cloud deployment where cameras record without it. Cameras stream to the local appliance, which handles recording and edge detection, while the cloud handles alerting, metadata and on-demand access.
You also can't substitute your own server hardware. Coram Point ships as tested GPU configurations and running on untested hardware isn't supported, so if part of your business case was repurposing existing C•CURE or exacqVision server capacity, take that off the table now rather than at design review.
The requirement is scoped to video, which matters if you're phasing: a doors-first cutover that leaves video on exacqVision for the time being doesn't need a Coram Point. The appliance comes into scope when the cameras do.
This is where migrations get underestimated. The controller has to be replaced. Coram Access Control runs on Coram's own DC-41 or DC-11 controller, and there's no supported path for running Coram Access Control through a third-party controller. If you're on C•CURE, that means your Software House iSTAR panels come out.
The peripheral hardware around those panels usually survives, provided it's protocol-compatible:
So a typical retrofit rewires existing readers, locks, credentials and sensors into new Coram controllers. Budget for the controller boxes and the labour to swap them; don't budget for re-pulling door hardware.
One credential caveat worth raising before you scope: if your existing cards use advanced encryption such as EV3 DESFire and you want new Coram credentials to work on the old readers, you'd need to supply the reader's encryption keys. That information is rarely available, which can force a reader decision you weren't planning on.
Camera compatibility. Start with a complete camera inventory and confirm ONVIF support for each model.
Door controller inventory. Count panels and doors per panel across the iSTAR family — Ultra, Ultra SE, Ultra LT, Edge, eX — plus any older apC controllers still in service. Coram's DC-41 handles four doors per unit and the DC-11 handles one, so this maps directly to hardware spend.
Reader and credential audit. Confirm reader protocol (Wiegand or OSDP) and card frequency, and flag any encrypted credential formats early.
Network readiness. Review bandwidth, uplink capacity, and network design, especially across multiple sites.
Existing hardware lifecycle. Remaining useful life per asset tells you what belongs in phase one and what can wait.
Identity integrations. If your access environment relies on an identity provider or SSO, verify how users and permissions carry over before you begin.
Contract timing. Map your JCI maintenance and license renewal dates now. Timing the migration around them avoids paying for overlapping systems or absorbing early termination costs.
1. Audit the existing deployment. Document camera inventory, recorder count and location, iSTAR panel count and doors per panel, reader protocols and card formats, current license counts, and contract end dates across your JCI agreements. This becomes the reference point for every decision that follows.
2. Separate what's reusable from what's replaced. Cross-reference cameras against ONVIF compatibility. Separately, confirm which readers, locks and credentials are protocol-compatible with Coram controllers. Expect two different answers: the camera replacement list is usually smaller than IT directors assume, while the controller list is a straight one-for-one swap.
3. Run Coram and JCI in parallel first. Bring Coram online alongside your existing system on a subset of cameras or a single site. A parallel run validates camera onboarding, AI analytics, and door behaviour against real conditions before you commit further.
4. Move to a phased cutover. Once the pilot validates, move site by site. Retire recorders and panels as each site cuts over rather than running two full systems longer than necessary. This is where the contract end dates from step one earn their keep.
5. Decommission and wind down contracts. As each site completes cutover, decommission retired JCI hardware and formally close out the associated maintenance and license agreements. Doing this against your original contract calendar, rather than reactively, keeps the migration from costing more than it needs to.
Timeline: A single-site migration with a straightforward ONVIF camera fleet and few doors moves faster than a multi-site deployment with mixed hardware and staggered renewals. Treat any specific week or month estimate with skepticism until your audit is done.
Coram is a physical security platform that unifies video, access control, and AI analytics in one console, running a hybrid architecture: local appliances at each site, cloud for everything else.
In a Johnson Controls migration, Coram Point ingests your existing camera fleet and replaces the exacqVision or victor recorder layer. Your cameras stay where they are. Recording and edge processing move to Coram Point, and management, search, alerting and viewing move to the cloud. There's no server for your team to patch, and no recorder to refresh on its own hardware cycle — Coram Point is fully managed and updates automatically.
Coram is SOC 2 Type II audited, with the report available on request through Coram's Trust Center, which also holds a completed HIPAA gap assessment. If you're in a regulated environment, request both during evaluation rather than working from a summary line on a vendor page — including this one.
From there, Coram extends past video. AI analytics like search and alerting are built in natively rather than licensed as a separate add-on the way JCI typically treats them. Access control lives on the same platform, so you're not running Software House for doors and a separate VMS for cameras with two consoles, two vendors and two support paths. That consolidation does require Coram controllers at the door, as covered above — the console unifies, but the panel changes.
Best for: IT directors consolidating a fragmented on-prem JCI stack into a single platform, who are already facing a recorder or panel refresh and would rather redirect that spend than repeat it.
Less good fit: Sites with a recently refreshed iSTAR estate and years of useful life left in the panels, where the controller swap is pure new cost rather than a redirected refresh.
Timing matters more than most IT directors initially assume. These are the signals that indicate it's the right moment.
Hardware refresh is already due. If exacqVision recorders, C•CURE servers, or iSTAR panels are coming up for replacement anyway, that's the natural cutover point. You aren't creating a project, you're redirecting one.
exacqVision or C•CURE is hitting end-of-life or a forced upgrade. A mandatory upgrade cycle is a good moment to ask whether you want to reinvest in the same architecture.
Johnson Controls is reassessing its security portfolio. In April 2026, Bloomberg reported that JCI is working with financial advisers to solicit interest in its Access Control and Intrusion Detection units, in a deal potentially worth up to $4.5 billion. The company is seeking to sell them separately but may sell to a single buyer. Worth weighing carefully rather than reacting to: discussions were reported as early stage with no decision made, JCI may retain one or both units, and the company declined to comment. The reported scope also covers access control and intrusion only — exacqVision and victor video weren't described as part of it. Separately, on its Q2 2026 earnings call, JCI management characterised its security offering as less differentiated than its HVAC service portfolio and signalled a reassessment of how it's priced and sold. If you're weighing a multi-year reinvestment in C•CURE or iSTAR, roadmap ownership is a fair question to put to your account team.
Multi-site remote management has become a real pain point. If your team is juggling separate consoles or VPN connections per site, that overhead is worth pricing against a single cloud console.
Maintenance costs keep creeping up. Per-appliance and per-seat licensing compounds as you add cameras, doors, or sites. If your maintenance renewal has grown faster than your deployment has, that's a signal.
You're consolidating identity and SSO. If there's already an initiative to centralise identity management, migrating access control at the same time avoids doing the integration work twice.
If none of these apply and you're mid-contract with two or more years remaining, migrating now typically means absorbing unnecessary early-termination costs. The better move is to run the audit and evaluation now, then sequence the cutover to land when your current contract ends.
Start with three inventories: cameras and their ONVIF support, iSTAR panels and doors per panel, and your JCI contract end dates. That combination tells you what carries over, what needs replacing, and what a realistic cutover schedule looks like. If you'd rather see how Coram handles your specific camera fleet first, book a demo.
Yes, if they're ONVIF-compliant or support RTSP, and if they stream H.264 or H.265. Coram Point is camera-agnostic and adopts existing cameras without a full hardware swap — brands already verified include Axis, Hanwha, Avigilon, Wisenet, Vivotek, Panasonic, Sony, Uniview, Hikvision, Lorex, Reolink, Amcrest and GW Security, and Coram publishes a compatibility check procedure for models not on that list.
Only cameras locked into a proprietary protocol, or too old to stream a supported codec, need replacing. That's typically a smaller portion of the fleet than IT directors expect. Cabling and PoE switches carry over regardless.
The controller, yes. Coram Access Control runs on Coram's own DC-41 or DC-11 controller, and there's no supported configuration that keeps a third-party panel and adds Coram software on top. Your iSTAR panels come out.
Most of the hardware around them stays. Wiegand and OSDP readers connect to the Coram controller, most standard 12V DC electronic locks are supported with external power, standard door position sensors and request-to-exit buttons are supported per door slot, and third-party RFID cards work at standard 13.56 MHz or 125 kHz formats — you enter the card ID manually rather than using the auto-scan flow.
One exception to check early: encrypted credential formats such as EV3 DESFire require the reader's encryption keys if you want new Coram cards working on old readers, and those keys are rarely obtainable.
You also don't have to move video and access control at the same time. Some teams migrate video first and leave C•CURE running until the panels are due for replacement anyway.
Hybrid, permanently, not just during migration. A local Coram Point appliance at each site handles video recording and edge AI. The cloud handles management, search, alerting and viewing.
The appliance is a video requirement. Access control runs on Coram's door controllers instead, so a doors-only migration doesn't need one. Coram can also run alongside your existing JCI system during cutover, which is the recommended path.
Footage on existing JCI recorders stays accessible until those sites are decommissioned. New footage records to the Coram Point at that site, so primary retention depends on appliance storage, the same relationship you have with exacqVision today.
Cloud retention has two tiers:
Scope the second one carefully. Backed-up footage isn't directly viewable or searchable in the app, and retrieval runs through Coram support. Treat it as disaster recovery, not a second live archive. Size the appliance for the retention your investigations need, and use cloud backup for the loss scenario.
Johnson Controls typically licenses per appliance or per seat, so cost scales with both hardware and user count. Coram uses a per-camera subscription that includes AI and cloud management, so forecasting tracks camera count instead.
Model the hardware on both sides: a Coram Point per site and Coram controllers per door group, against your recorder, server and panel refresh cycle.

