Federal agencies are restricted from procuring systems or services that use covered equipment as a substantial or essential component or critical technology, subject to exceptions and waivers.
Know what “NDAA compliant” means—and what it does not.
Section 889 addresses covered telecommunications and video-surveillance equipment and services in federal procurement and contracting. It is an important supply-chain requirement, but it is not a universal cybersecurity certificate, country-of-origin label, or blanket ban on every camera made in China.
Federal agencies are restricted from contracting with entities that use covered equipment or services in the described manner, even outside the federal contract, subject to the rule.
The FAR definition includes Huawei, ZTE, and—within stated surveillance and national-security purposes—Hytera, Hikvision, and Dahua, plus subsidiaries or affiliates.
A camera badge alone does not decide the status of an entire recorder, network, service, contract, or installation.
Section 889 is about covered technology in federal acquisition.
FAR 52.204-25 implements prohibitions from Section 889 of the FY 2019 National Defense Authorization Act. The clause defines covered telecommunications equipment and services and applies two related federal contracting restrictions.
- Section 889(a)(1)(A): restricts federal procurement or obtaining of equipment, systems, or services that use covered technology as a substantial or essential component or critical technology.
- Section 889(a)(1)(B): restricts federal agencies from entering, extending, or renewing a contract with an entity that uses covered technology in the defined way, even when that use is not in performance of the federal contract.
- Exceptions and waivers exist: the FAR text—not a marketing badge—controls whether an exception or approved waiver applies.
The rule’s definition currently identifies Huawei and ZTE telecommunications equipment, and certain Hytera, Hikvision, and Dahua video-surveillance or telecommunications equipment for specified public-safety, government-facility, critical-infrastructure, and national-security purposes, including subsidiaries and affiliates. It also allows additional connected entities to be identified through the statutory process.
Supply-chain decisions can affect eligibility, risk, and future projects.
Government agencies, federal contractors, schools, critical-infrastructure operators, grant recipients, and private organizations with procurement policies may require NDAA-aligned equipment. Even when a private purchase is not legally subject to Section 889, buyers may prefer a documented supply chain to support customer requirements or avoid replacing a system later.
The concern is not that every product from one country behaves the same. The federal framework identifies specified covered entities and technology because of national-security and supply-chain risk determinations. Accurate procurement depends on legal identity, producer, subsidiaries, affiliates, components, services, and the intended use—not a broad assumption based only on marketplace language or country of origin.
Related federal programs are not interchangeable.
The FCC maintains a Covered List under the Secure and Trusted Communications Networks Act. Congress also enacted the Secure Equipment Act, and the FCC adopted equipment-authorization rules addressing covered equipment. These actions relate to national-security risk and equipment authorization, but an FCC identifier, emissions compliance, and NDAA procurement status answer different questions.
Federal procurement and contracting restrictions involving covered telecommunications and video-surveillance equipment or services.
A federal list of communications equipment and services determined to pose an unacceptable risk under the governing law.
Rules governing authorization of radio-frequency equipment. An FCC marking is not a broad product endorsement.
Credentials, firmware, access control, encryption, network design, monitoring, and vulnerability response remain separate operational responsibilities.
Avoid six common NDAA misunderstandings.
NDAA alignment is not a domestic-content claim.
It does not replace cybersecurity controls or maintenance.
Procurement restrictions and RF authorization are different.
One compliant camera does not automatically qualify every component or service.
The legal analysis is based on covered entities, equipment, services, use, and current rules.
Lists, ownership, models, firmware, and contract requirements can change; verify current records.
Use a documented, system-level review.
- Identify every camera, recorder, switch, radio, encoder, software platform, and material service by manufacturer and model.
- Obtain the manufacturer’s current Section 889 or NDAA declaration and model datasheets.
- Check the current FAR clause, definitions, FCC Covered List, and any agency-specific or grant-specific terms.
- Review subsidiaries, affiliates, private-label/OEM relationships, and substantial or essential components where applicable.
- Keep the bill of materials, declarations, datasheets, invoices, and serial records with the project file.
- For a federal contract, grant, or regulated project, obtain a determination from the contracting officer, authority, or qualified counsel rather than relying only on a retailer page.
Our Compliance Center links the manufacturer declaration and indexes model-level datasheets and credentials. That evidence helps procurement review, but the buyer remains responsible for the complete project and its governing requirements.
Manufacturer documentation supports informed selection.
Luminys publishes a company compliance statement covering its branded product line. Elite Security Direct also displays model identifiers, manufacturer records, datasheets when published, and extracted credential tags in the product evidence index. Specifications and legal status can change, so the current manufacturer record and applicable government source remain controlling.
Security camera compliance FAQ
Is NDAA compliance required for every private security-camera purchase?
No. Section 889 is principally a federal procurement and contracting restriction. A private buyer may still choose NDAA-aligned equipment for supply-chain policy, customer requirements, grant conditions, future eligibility, or risk management.
Does NDAA compliant mean made in the USA?
No. NDAA alignment addresses covered equipment and services; it is not a country-of-origin label.
Does NDAA compliant mean a camera cannot be hacked?
No. NDAA status is not a cybersecurity certification. Secure deployment still requires supported firmware, strong credentials, restricted access, protected networking, and ongoing maintenance.
Does an NDAA camera make the whole system compliant?
Not automatically. The applicable rule or contract may require review of the recorder, switches, radios, services, software, and other substantial or essential components. Verify the complete bill of materials and the current contract language.
Are all cameras manufactured in China prohibited?
No. The federal rules identify covered entities, equipment, and services under defined conditions; country of manufacture alone is not the complete legal test. Verify the producer, subsidiaries and affiliates, components, services, current federal sources, and the applicable procurement requirement.
Verify against current federal records.
This page is educational and not legal advice. Consult the exact contract, grant, agency requirement, current federal sources, and qualified counsel when a formal compliance decision is required.