What NDAA Section 889 Actually Says
Section 889 is part of the National Defense Authorization Act—specifically the 2019 NDAA. It establishes a prohibition on the procurement and use of telecommunications equipment and services produced by five named Chinese companies: Huawei, ZTE, Hytera, Hikvision, and Dahua, along with any of their subsidiaries or affiliates.
The prohibition rolled out in two phases:
- Phase 1 (August 13, 2019): Federal agencies cannot purchase or obtain the covered equipment or services.
- Phase 2 (August 13, 2020): Federal contractors and subcontractors cannot use covered equipment anywhere in their operations—not just on government sites—if they want to remain eligible for federal contracts.
That second phase is where most compliance failures happen. The prohibition is on use, not just new purchases. An organization that bought Hikvision cameras in 2017, installed them in a corporate office, and has been renewing federal contracts ever since is in violation—regardless of when the cameras were purchased.
The implementing regulation is FAR Subpart 4.21, which requires contractors to represent their compliance status in every covered contract action. That representation carries legal weight.
Who This Applies To
The short answer: any organization with a financial or contractual relationship with the federal government. That includes:
- Federal agencies and their direct vendors
- Defense contractors and subcontractors at every tier
- GSA Schedule holders
- Critical infrastructure operators receiving federal grants
- Law enforcement agencies participating in federal task force agreements or receiving federal equipment grants
- Municipalities and public-sector organizations that accept federal funding for infrastructure, public safety, or emergency management programs
If any portion of your budget touches federal dollars, the equipment that supports those programs—including surveillance systems—needs to be clean.
Which Brands Are Prohibited—and Why Rebranding Doesn't Help
The five covered manufacturers are Hikvision, Dahua, Hytera, Huawei, and ZTE. But the prohibition extends to subsidiaries and companies that are "substantially" the same entity. This is where buyers get caught.
A significant portion of the mid-market camera industry runs on Hikvision or Dahua hardware rebranded under different names. The housing and badge may say something unfamiliar, but the image sensor, chipset, and firmware inside are from a covered manufacturer. Under Section 889, the brand name on the box is irrelevant—what matters is the actual supply chain.
This means procurement teams cannot rely on unfamiliar brand names as safe alternatives. You need documentation, not assumptions.
What NDAA-Compliant Actually Means
A camera is NDAA-compliant when it is manufactured by a company that is not one of the five covered entities, contains no covered components at the chip or firmware level, and can produce documentation to prove both of those things.
Brands that are generally considered compliant for 2026 include Axis, Hanwha, Vivotek, Bosch, and Pelco (under current ownership). But "generally considered" is not a compliance standard. For any covered deployment, you need a written Letter of NDAA Compliance for each specific hardware model—not a verbal assurance from a sales representative, and not a marketing claim on a product page.
For government facility deployments, license plate recognition cameras are a common component at entry and exit chokepoints, and they carry the same compliance requirements as any other camera in the system. LPR is not a carve-out.
What Managed Surveillance Providers Must Be Able to Prove
If you are contracting with a managed surveillance provider—a company that deploys cameras and operates remote video monitoring on your behalf—you are still responsible for the compliance status of the hardware on your site. The provider's equipment, operating under your federal contract, is your exposure.
This is a gap many organizations miss. They assume the vendor handles compliance. The vendor may assume the client has reviewed it. Neither assumption is documentation.
What you should require from any provider operating on a covered site:
- A Letter of NDAA Compliance for each hardware model they deploy
- Country of manufacture declaration for cameras and recording equipment
- Supply chain documentation at the component level, if your risk profile requires it
- Written certification embedded in the service contract—not a side email, not a verbal confirmation
- A defined process for hardware refresh notifications: if a provider swaps a camera model mid-contract, you need to know the replacement's compliance status before it goes on your wall
For temporary or mobile deployments—law enforcement operations, emergency management, construction phases on government-adjacent sites—the same requirements apply. A mobile surveillance unit brought onto a federal facility or deployed in support of a federally funded program needs to carry the same compliance documentation as any fixed installation.
The Buyer's Checklist: Five Questions for Every Provider
Before any contract is signed, put these questions in writing and require written answers:
- Are all cameras, NVRs, and network components in your systems free of Hikvision, Dahua, Huawei, ZTE, and Hytera components at the hardware and firmware level?
- Can you provide a Letter of NDAA Compliance for each hardware model you plan to deploy on our site?
- Do you have documented visibility into your supply chain for chip-level and firmware-level components?
- Will you certify NDAA compliance in writing as a term of our service agreement?
- How do you handle hardware refreshes during a contract term—will you proactively notify us if a replacement model changes the compliance status of our deployment?
A provider that hesitates on any of these questions, or offers verbal reassurance instead of written documentation, is not a compliant partner for a covered deployment.
How VDS Handles NDAA Compliance
Vision Detection Systems operates only NDAA-compliant hardware across all deployments. For government agencies, law enforcement, and federal contractors, we provide written compliance certification as part of the service agreement—not as an add-on, and not after the fact.
Our full NDAA compliance documentation covers hardware models, Letters of NDAA Compliance, and the supply chain standards we hold our hardware partners to. If your procurement office or legal team needs to review documentation before contract execution, that process is built in—not something we have to scramble to produce.
We also maintain hardware refresh protocols so that if a camera model in our fleet changes compliance status—whether due to an acquisition, a supply chain change, or a regulatory update—affected clients are notified before any replacement is deployed.
If your organization is operating under federal contracts, receiving federal grants, or supporting law enforcement and critical infrastructure programs subject to NDAA Section 889, the compliance status of your surveillance systems is not something to resolve after a procurement decision is made. Contact Vision Detection Systems to review your deployment requirements and receive written NDAA compliance documentation before your next contract action.
