The short answer
Yes, in most cases you can keep a large share of what is installed. Run a pre-tender technical audit before writing the specification: inventory every camera (model, firmware, ONVIF profile, codec), confirm the target VMS or recorder speaks ONVIF Profile S/T/G, and check support status, night quality, and network path. Most IP cameras shipped since roughly 2010 stream via RTSP and can be kept; end-of-life or closed-protocol devices usually must be replaced or isolated.
Key takeaways
- The audit output is an inventory table that becomes part of the tender file, so every bidder prices against the same camera reality and you avoid paying for cameras you already own.
- Most IP cameras manufactured since about 2010 expose RTSP or ONVIF and can connect to a new platform without being replaced.
- Interoperability is profile-specific: Profile S/T cover streaming, Profile G covers edge recording and retrieval, Profile M covers analytics metadata.
- End-of-life cameras with no firmware path are a security risk (legacy Hikvision and D-Link models are actively targeted) and should be replaced or isolated on a private network.
- Resolution alone does not decide reuse: a correctly placed 1080p camera often outperforms a high-megapixel camera with the wrong lens or mounting angle.
- Cameras that work on paper may fail at night, under traffic light, or because of missing credentials and a saturated uplink — test the real frame before keeping.
- Analytics added over existing ONVIF cameras do not require ripping out hardware; what matters is a tested, supported integration, not a generic 'compatible with everything' claim.
Why audit before you write the tender
Modernization and expansion tenders are usually written as a shopping list of new cameras, while the hardware already on the wall is ignored. That is where money is spent twice: you pay a contractor to install new devices in positions an existing camera could still cover, and you inherit two fleets with different firmware, protocols, and passwords. A pre-tender technical audit converts the decision 'which cameras are reusable' from an opinion into documented evidence that becomes part of the procurement file.
The audit answers one question per camera — keep as installed, keep after refurbishment or remounting, or replace. In practice this changes the outcome for only a minority of devices: integrators report that on a typical estate of several dozen cameras most connect and stream as they are, with a handful needing remounting and one or two needing replacement because of age or damage. You cannot know which handful that is until each position has been inspected, because the devices that actually fail are frequently not the oldest ones on paper.
Once finished, the audit table feeds directly into the tender: which camera models must be connected by the winner, which positions need refurbishment or relocation works, what bitrate and storage the network must carry, and what security acceptance criteria apply. Without this table, suppliers add contingency for the unknown and disagreements about 'who owns which device' surface after the contract is signed.
- Keep-as-is: streams and covers its intended task today.
- Refurbish or remount: usable but needs a new lens angle, cleaning, or relocation.
- Replace: end-of-life, damaged, or no longer able to meet the coverage task.
What to inventory on every camera
Start with a physical and logical inventory that records each camera's manufacturer and exact model, serial number, firmware version, mounting height and angle, and the coverage purpose it serves. A camera with no attached decision — what event should this feed detect — is only a storage cost, not a sensor. Assigning one job per camera during the audit prevents the most common design mistake: asking a single camera to watch a fence line and read plates at the same time, tasks that usually require different placement and lens characteristics.
For every device also record how to reach the stream: the RTSP URL, the ONVIF service credentials, and the codec. H.264 and H.265 both work for modern platforms, and H.265 roughly halves bandwidth, which matters when you later estimate storage and switch capacity. Old estates are frequently blocked by missing credentials — the installer left and took the passwords with them — so budget for password recovery on systems older than five years and note the issue in the audit before integration time is billed to the project.
- Manufacturer, model, serial and firmware version.
- ONVIF service endpoint, credentials and whether a dedicated ONVIF user exists.
- Codec and typical bitrate, plus the switch port, VLAN and uplink path.
- One defined coverage task and the mounting geometry needed for it.
- A night frame taken at the hour the camera actually must work.
Protocol and platform compatibility
Compatibility is not binary; it depends on matching ONVIF profiles between the camera and the receiving software. Profile S covers basic video streaming and remains the most widely implemented; Profile T adds advanced streaming with H.264/H.265 and modern events; Profile G standardizes edge recording and retrieval from on-board storage; Profile M standardizes analytics metadata and events. A new camera can join an existing VMS when both camera and client are Profile S or T conformant, and older recorders can be swapped for new models when both sides support Profile G.
Profile conformance also has nuance: some features are mandatory for the client and device, others conditional. Motion-event support in Profile T, for example, is mandatory for both; PTZ control is mandatory only for the client because not every conformant device is a PTZ camera. The only authoritative place to confirm that a product truly conforms is the manufacturer-independent ONVIF conformance database, not the marketing claims on the box.
ONVIF does not replace a vendor's SDK. On-board analytics such as face or license-plate recognition frequently stay proprietary and are not exposed through ONVIF, so a decision to reuse cameras for an analytics project must separate 'the stream works' from 'the feature works.' Standards bodies also retire profiles over time and recommend successors — treat a camera's conformance as something to re-verify, not as a permanent fact, whenever a platform change is planned.
- Profile S / T: video streaming between camera and VMS or recorder.
- Profile G: edge storage, search and playback on SD or on-board media.
- Profile M: metadata and analytics event handling.
- Vendor SDK: still required for proprietary on-board analytics features.
Supportability and cybersecurity decide more than picture quality
A camera that still produces a good image can still be the wrong one to keep. Manufacturers stop issuing firmware when a product reaches end-of-life, and unpatched cameras become attractive targets. Attackers repeatedly exploit legacy devices: a Hikvision authentication flaw first patched in 2017 was still being used against unpatched cameras in 2025, and end-of-life D-Link models have been documented as permanently unpatched with no corrective firmware ever released.
The practical consequence for an audit is that every camera must be classified by supportability. If the vendor offers current firmware and the device can be kept off the public internet, reuse is defensible. If the device is end-of-life and internet-reachable, the safe route is replacement, or isolation on a private VLAN behind a firewall with remote administration disabled. Network isolation reduces but does not eliminate risk, because a compromised host on the same LAN can still reach the camera — so for genuinely unsupported hardware the definitive remedy remains a supported replacement.
- Check whether the manufacturer still publishes firmware for the exact model.
- Confirm the camera is not directly exposed to the internet.
- Record whether it can be placed on a private VLAN with remote admin disabled.
- Replace or accept residual risk for permanently unpatched end-of-life units.
Optical quality and the real coverage task
Resolution is the least reliable single predictor of reuse value. Many detection tasks run comfortably at 1080p, and the tasks that genuinely need more — reading a plate at distance or verifying a face beyond a few meters — usually fail because of placement, not pixel count. A high-megapixel camera with the wrong lens and mounting angle delivers less usable evidence than a modest 1080p camera aimed correctly. When a reuse question is really a placement question, the cheaper and faster fix is remounting, not replacement.
The decisive test is a frame from the actual operating hour. Infrared washout and headlight bloom are the two most common surprises at night, so the audit should sample a frame at the hour the position is expected to matter rather than in daylight. A camera that looks sharp in the afternoon but blooms at 02:00 may need a remount, an exposure setting change, or replacement depending on whether the fault is optical or in the sensor.
- 1080p is sufficient for person and zone detection and many PPE rules.
- Plate reading and face verification depend on placement and reach, not only megapixels.
- Sample a real night frame before classifying a camera as keep or replace.
- One camera cannot reliably serve two incompatible coverage jobs.
Turning the audit into the tender file
The audit only earns its cost if it lands in the tender documentation. A typical 1080p H.264 stream runs at roughly two to four megabits per second, so a fleet of fifty cameras means a hundred to two hundred megabits of continuous traffic; confirming that the existing switches and uplink can carry the retained cameras, plus whatever is added, is part of the audit, not an afterthought. Where an existing recorder is being replaced, Profile G conformance on both sides lets you keep on-board and edge media rather than rewriting the archive.
Include in the specification a section stating that the customer retains ownership of listed cameras, that the contractor must connect, configure and test them, and that any device not listed may be assumed to be removed. Attach the per-camera table with its keep, refurbish or replace verdict, the responsible party, and an indicative cost so bidders can price the works instead of padding for uncertainty. This structure reduces tender disputes and makes the winning scope auditable after handover.
Put it into practice
Camera Reuse Decision Matrix for the Tender File
Use this routing matrix during the audit to classify every camera into keep, refurbish or replace, then export the result as a table attached to the tender. Work top to bottom per camera; the first rule that applies sets the verdict.
- Identify the manufacturer, model and firmware; an unidentifiable camera is a replace candidate until proven otherwise.
- Look the camera up in the independent ONVIF conformance database and record which profiles (S/T/G/M) it actually reports.
- If the camera and the target VMS or recorder are both Profile S/T conformant, keep for live streaming.
- If reuse depends on retrieving media from the camera's own storage, keep only when both sides are Profile G conformant.
- If analytics metadata must reach the platform, require Profile M; otherwise confirm the analytics feature over the vendor SDK.
- If firmware has no vendor update path and the camera is reachable from outside the LAN, classify as replace unless it can be isolated on a private VLAN with remote administration off.
- Test a night frame at the real operating hour; if IR washout, blur or headlight bloom blocks the coverage task, move the camera to remount or replace.
- Confirm the codec and bitrate fit the existing switch port and uplink headroom before keeping a camera.
- Assign exactly one coverage decision per camera; split positions where a camera is asked to do two incompatible jobs.
- Verify credentials are recoverable; on estates older than five years budget for password recovery and record the effort.
- Record the verdict (keep / refurbish / replace), the responsible party and an indicative cost per camera in a table that is annexed to the tender.
Questions people ask
What is the difference between ONVIF Profile S and Profile T when deciding which cameras to keep?
Profile S is the long-standing baseline for basic IP video streaming between a camera and a recording or management client. Profile T is the advanced streaming profile: it covers the same streaming role but adds modern encoding such as H.264 and H.265, imaging settings, and events like motion and tamper detection. For a reuse decision, what matters is that both the camera and the software or recorder you plan to keep or buy are conformant to the same profile, so that all the features you rely on are supported. Note that conformance programmes evolve — standards bodies sometimes retire older profiles in favour of successors — so verify the current conformance status of both devices rather than assuming it is permanent.
My cameras use a closed proprietary protocol. Can they still be reused?
Only if the platform you are moving to has an official, tested driver for that proprietary protocol, or the camera also exposes a standard interface such as ONVIF or RTSP. Closed-protocol devices often connect quickly inside their own brand ecosystem but are opaque to third-party software. Before committing, validate the specific model against the target VMS rather than trusting a generic 'compatible with everything' claim. If neither a standard stream nor a supported driver exists, the camera is effectively replace-only regardless of how well it still images.
How do I check whether a camera is end-of-life, and why does it matter for reuse?
Check the manufacturer's support pages for the exact model to see whether current firmware is still published and when end-of-sale and end-of-life were announced. It matters because vendors stop issuing security patches for legacy devices, and unpatched cameras are regularly targeted — documented cases include a Hikvision authentication flaw patched in 2017 still exploited in 2025 and permanently unpatched end-of-life D-Link models. An end-of-life camera can still be reused if it has a current, safe firmware and is kept off the public internet, but the fully unpatched end-of-life unit is best replaced, or at minimum isolated on a private VLAN with remote administration disabled.
We are switching to a new VMS vendor. Do we have to change the cameras as well?
Usually not. If your cameras are IP-based and expose ONVIF or RTSP, the VMS layer can be replaced while the cameras, cabling and network stay in place. Video analytics can also be added as an intelligence layer on top of the existing platform without swapping cameras, provided there is a tested, documented integration with your specific VMS. Before signing, validate that the specific camera models are supported and that any proprietary on-board features you need are exposed. If the estate is very old or closed-protocol, run a compatibility check first because those cameras are the ones most likely to force replacement.
Can old analog cameras be reused after an upgrade?
Yes, within limits. An analog camera produces its signal through a DVR or video encoder; if that recorder or encoder exposes a standard RTSP or ONVIF stream to the network, the upstream platform can ingest the camera exactly as it would an IP camera. What you lose is the digital control and analytics granularity of a native IP device, so an analog camera is most suitable for simple observation or recording positions where no event-level intelligence is required. The recorder itself must be supported and secure, because reusing an end-of-life DVR can reintroduce the very firmware risk the audit is meant to remove.
What resolution does a kept camera need to keep it for identification tasks such as reading a plate?
There is no fixed megapixel answer, because identification depends on the sensor, lens, distance, lighting and angle, not on the sensor resolution alone. A well-placed 1080p camera frequently outperforms a higher-megapixel unit with the wrong lens or mounting. General person and zone detection runs comfortably at 1080p; plate reading at distance and face verification beyond a few meters need better reach and usually fail because of placement rather than pixel count, so the fix is often a remount or a dedicated camera position. In an audit, judge each candidate against its defined coverage task and a real night frame instead of a resolution spec sheet.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Future proofing: ONVIF Profiles can ensure a successful retrofitONVIF
- Do you know your ONVIF profiles?ONVIF
- Что такое ONVIF в видеонаблюдении: протокол, профили и совместимость камерskudov.net
- Deploying vision AI on the cameras you already ownExamin
- AI in your cameras without changing your infrastructuresDAVANTIS
- Legacy Hikvision camera vulnerability resurfaces in active exploitsField Effect
- CVE-2026-12174 (D-Link DCS-935L end-of-life IP camera)Armis