Resources / Technical Standards / Industry Guidance

EN 50518:2019 Explained: The Alarm Receiving Centre Standard.

The European standard governing monitoring centre construction, staffing and response. What it is, what Category I means in practice, and why it matters to enterprise security buyers in Ireland.

Manguard Plus operates the first EN 50518:2019 Category I certified Alarm Receiving Centre in Ireland. 8 min read – updated June 2026 – technical reference.

What is EN 50518?

EN 50518:2019 is the European standard that defines requirements for an Alarm Receiving Centre, or ARC: the facility that receives, verifies and acts on alarm signals transmitted from monitored sites. It was published by CENELEC in 2019 as a consolidated single-document revision of the earlier three-part EN 50518 series, which had separately covered location and construction, technical requirements, and procedures.

The standard sets out, in one document, what an ARC must be: how its building is constructed, how its power and communications are made redundant, how its operators are organised, how alarm signals are processed, and how the whole facility is audited. It is technology-neutral in the sense that it covers any monitored signal an ARC might handle – intruder, fire, panic, lone worker, hold-up, CCTV verification, environmental – rather than only one alarm type.

It does not govern the alarm system at the protected site (those systems sit under their own EN series, including EN 50131 for intruder systems). EN 50518 governs the facility on the receiving end of the wire.

The three categories explained

EN 50518:2019 grades ARCs in categories that reflect the resilience, redundancy and operational depth of the facility. The table below summarises the practical differences across the dimensions that matter most for an enterprise security buyer:

Requirement Category I
Highest tier
Category II
Mid tier
Category III
Entry tier
Physical construction Hardened building shell engineered to the highest attack-resistance grade in the standard Reduced attack-resistance grade; standard commercial construction with hardened access points Baseline commercial construction with controlled access
Power redundancy Dual independent feeds plus on-site generation and battery, sized for extended autonomy UPS plus generator, shorter required autonomy UPS sized for short-term continuity
Communications redundancy Multiple diversely routed communication paths across independent carriers At least two communication paths Two communication paths, may share carrier
Staffing Continuous 24/7 operator presence with minimum operator counts scaled to signal volume Continuous staffing at reduced minimums Continuous staffing, baseline minimums
Geographic redundancy Dual-site failover to an independent secondary ARC Recovery procedure rather than live secondary site Documented business continuity arrangement

In practice, Category I represents the strictest end of the standard: an ARC that is built, powered, connected, staffed and replicated such that it can continue handling alarm traffic, without degradation, through events that would put a lower-category ARC into recovery mode. Construction is engineered to absorb sustained physical attack. Power is engineered to survive extended grid outage on a single site. Communications are engineered to survive carrier failure. Staffing is engineered to absorb signal-volume spikes without exceeding response targets. And a secondary ARC takes the traffic live if the primary site is taken offline.

Physical and security requirements for an ARC

The standard treats the ARC building as a security-critical facility in its own right. Specific physical requirements include:

  • Hardened building shell. External walls, roof and floor specified to resist forced entry, vandalism and standoff attack to the grade required for the chosen category.
  • Attack-resistant doors and glazing. Main access doors and any external glazing specified to a burglary-resistance class consistent with the chosen category.
  • Controlled perimeter and access. Multi-stage access control on entry, with separation between public, administrative and operations zones inside the building.
  • Intrusion detection on the ARC itself. The ARC must monitor its own facility for unauthorised entry, with alarms routed independently of the signals it receives from clients.
  • Fire detection and suppression. Detection and, where category requires, suppression sized for the operations floor and the equipment rooms.
  • Environmental controls. Climate and humidity control for the equipment areas, with monitoring tied into the building management system.

The intent of these provisions is straightforward: a single attacker, a single equipment failure, or a single environmental incident cannot be allowed to take the ARC offline. The standard hardens the building because the building is part of the response chain.

Related European standards referenced in ARC design
  • EN 1627Resistance to burglary classification (RC ratings)
  • EN 13501-2Fire resistance classification of construction products
  • EN 50131Intrusion and hold-up systems at the protected site
  • EN 50136Alarm transmission systems and equipment

Operational requirements

Physical hardening is only half of the standard. EN 50518 also defines how the ARC is run on the day:

  • Staffing minimums. Continuous 24/7 operator presence, with category-specific minimum operator counts at any given moment and scaling rules tied to signal volume.
  • Operator training and authority. Documented training programme, recorded competence, defined authority to initiate response actions including emergency-services escalation.
  • Redundant communications. Multiple diversely routed inbound paths from monitored sites, plus diversely routed outbound paths to keyholders, response teams and emergency services.
  • Dual-site failover. For Category I, a secondary ARC capable of taking over alarm traffic if the primary site becomes unavailable, with failover tested on a defined cycle.
  • Response time targets. Defined targets for signal acknowledgement and handling, measured per signal type and audited against the standard.
  • Audit logging and recording. Complete audit trail of every signal received, every action taken and every communication made, with retention periods specified per signal type.
  • Recording retention. Voice and data records of operator actions retained for the period defined in the operating procedures and aligned with national data-protection law.

The operational provisions exist for the same reason as the physical ones: a single operator absence, a single carrier failure, or a single site outage cannot be permitted to silence an alarm in transit.

Why this matters for Irish enterprise buyers

For most small commercial sites in Ireland, “monitored” simply means “connected to a monitoring centre” and the category of that centre is rarely interrogated. For enterprise sites, the picture changes:

  • Insurance schedules. Higher-value and higher-risk sites now routinely have monitoring requirements written into the insurance schedule by name. EN 50518 is the standard those schedules cite. Categories are increasingly distinguished, with premium loadings reflecting the gap.
  • Sector compliance. Data centres, regulated pharma, banking and critical national infrastructure typically operate to internal security baselines that name EN 50518-certified monitoring as a control. Procurement teams in these sectors are now asking the category question on tender.
  • RFP language. Public-sector and large private-sector tenders increasingly specify Category I monitoring, not generic “PSA-licensed monitoring”. The wording matters: a PSA licence is the legal floor; EN 50518 is the technical benchmark; the category is the resilience grade.
  • Continuity exposure. Relying on a Category II provider for a Tier-1 site means accepting that, during the events that put a Cat II ARC into recovery mode, your alarms are the ones being deprioritised. Whether that is an acceptable risk is a procurement decision, not a technical one.
Position as of June 2026
Manguard Plus operates the first EN 50518:2019 Category I certified Alarm Receiving Centre in Ireland. The Manguard Command and Control Centre is the receiving end for alarm, fire, panic, lone worker and CCTV verification signals from enterprise sites across the country, monitored to the highest tier of the European standard.

How to verify a provider's claim

“EN 50518 monitored” is one of the most loosely used phrases in Irish security procurement. The standard has three categories, two operational regimes (single site vs dual site) and a defined certification process – and any of those can be quietly absent behind the phrase. If you are specifying a monitoring partner, the following questions separate the claim from the certification:

  • Which certification body issued the certificate? A real certificate names an accredited body. “Self-certified” or “compliant with” is not certification.
  • What is the certificate number, issue date and expiry date? All three should be on a single sheet, available on request, and current.
  • Which specific category is certified? Many providers say “EN 50518” without naming a category. The category is the answer that matters.
  • Does the certification cover a single ARC site or a primary plus secondary? For Category I, the answer should describe a working dual-site configuration, not a paper failover.
  • What is the audit cycle and when was the last surveillance audit? A genuine certification operates on a defined cycle; a provider that cannot quote it likely is not on one.
  • What is the PSA licence number? Independent of EN 50518, the monitoring centre must hold a current PSA monitoring-centre licence under PSA 33:2014. The number is public and verifiable.

If the answers come quickly and in writing, the certification is real. If they arrive vaguely or via the marketing team, the certification almost certainly is not what it is being represented to be.

FAQs

Frequently Asked Questions.

The questions enterprise security and procurement teams ask most often about EN 50518:2019 and Category I monitoring.

EN 50518:2019 consolidates and replaces the earlier three-part EN 50518 series (Parts 1, 2 and 3, published 2010 to 2014) which separately covered location and construction, technical requirements, and procedures and requirements for operation. The 2019 revision merges those into a single standard and aligns categorisation of Alarm Receiving Centres with current operating practice, including the way modern ARCs use redundant communications and dual-site failover.

EN 50518 is not, by itself, a piece of Irish primary legislation. It is referenced as the benchmark standard for Alarm Receiving Centres by insurers, by procurement specifications in regulated sectors, and by the PSA licensing framework where monitoring centres are licensed under PSA 33:2014 and operate to EN 50518. In practice, for enterprise sites in pharma, data centres, banking and critical infrastructure, an EN 50518-certified ARC is now a baseline procurement requirement rather than an option.

Category I is the highest tier of EN 50518:2019 and requires the strictest physical construction, the most robust redundancy in power and communications, and continuous staffing levels matched to alarm signal volume. Category II permits a reduced specification on some of those elements – typically physical hardening and redundancy depth. The practical effect is that a Category I ARC can continue operating, without degradation, through events that a Category II ARC is not engineered to absorb, including extended power loss, primary site failure or sustained physical attack.

Insurance schedules for higher-value or higher-risk sites increasingly name EN 50518 explicitly, and may distinguish between categories when setting premium loadings, excess levels or claim conditions. For Tier 1 enterprise sites, presenting evidence of Category I monitoring is often the difference between standard terms and a loaded premium. The exact treatment is insurer- and policy-specific and should be confirmed with your broker before specifying or changing a monitoring provider.

Ask for the certification body’s name, the certificate number, the issue and expiry dates, the specific category certified, and whether the certification covers a single ARC site or a primary-plus-secondary configuration. A genuine Cat I provider will produce all of this on request. A provider that uses phrasing such as ‘EN 50518 monitored’ or ‘compliant with EN 50518’ without naming a category or a certifying body is almost always not Category I.

EN 50518 governs the Alarm Receiving Centre itself – the facility, its construction, staffing and operating procedures. Any monitored signal handled by that ARC therefore benefits from its EN 50518 category, whether the signal originates from an intruder alarm, a fire system, a panic device, a lone worker device or a CCTV verification platform. The standard is signal-type agnostic at the receiving end.

Certification is granted by an accredited third-party certification body and is subject to a defined audit cycle, typically combining an initial full assessment with periodic surveillance audits and a full recertification on a multi-year cadence. Any material change to the ARC – relocation, expansion, new failover site, change of operating procedures – normally triggers a focused reassessment outside the standard cycle.

Certification is issued by accredited certification bodies operating against the standard, not by the Irish state directly. In parallel, the Private Security Authority (PSA) licenses monitoring centres under PSA 33:2014. The two regimes operate alongside each other: the PSA licence is the legal requirement to operate as a monitoring centre in Ireland; EN 50518 certification is the technical benchmark for how that centre is built and run.

Need Monitoring Backed by the Only Cat I ARC in Ireland?

If your insurance schedule, your sector baseline or your own continuity policy now references EN 50518:2019 Category I, the Manguard Plus alarm-monitoring service is built around exactly that standard. Talk to our team about specifying, switching or upgrading your monitoring.