Vision Detection Systems
NDAA Compliant Security Cameras: A Buyer's Compliance Guide for 2026
BLOG | PROCUREMENT & COMPLIANCE

NDAA Compliant Security Cameras: A Buyer's Compliance Guide for 2026

Understand NDAA Section 889, which camera brands are prohibited, and what to ask any surveillance provider before signing a contract.

BYVDS Editorial
PUBLISHEDAugust 2026
READ5 min
COMPLIANCE
SUMMARY

If your organization holds a federal contract or receives federal funding, the security cameras on your property are not just an operational decision—they are a compliance obligation. A single non-compliant camera, purchased years ago and still running on a corner of your facility, can jeopardize contract eligibility. Most procurement teams don't find out until an audit is already underway. This guide gives you the plain-language breakdown of what NDAA Section 889 actually requires, which products are affected, and the specific questions you need to put to any surveillance provider before you sign anything.

What NDAA Section 889 Actually Says

Section 889 is part of the National Defense Authorization Act—specifically the 2019 NDAA. It establishes a prohibition on the procurement and use of telecommunications equipment and services produced by five named Chinese companies: Huawei, ZTE, Hytera, Hikvision, and Dahua, along with any of their subsidiaries or affiliates.

The prohibition rolled out in two phases:

  • Phase 1 (August 13, 2019): Federal agencies cannot purchase or obtain the covered equipment or services.
  • Phase 2 (August 13, 2020): Federal contractors and subcontractors cannot use covered equipment anywhere in their operations—not just on government sites—if they want to remain eligible for federal contracts.

That second phase is where most compliance failures happen. The prohibition is on use, not just new purchases. An organization that bought Hikvision cameras in 2017, installed them in a corporate office, and has been renewing federal contracts ever since is in violation—regardless of when the cameras were purchased.

The implementing regulation is FAR Subpart 4.21, which requires contractors to represent their compliance status in every covered contract action. That representation carries legal weight.

Who This Applies To

The short answer: any organization with a financial or contractual relationship with the federal government. That includes:

  • Federal agencies and their direct vendors
  • Defense contractors and subcontractors at every tier
  • GSA Schedule holders
  • Critical infrastructure operators receiving federal grants
  • Law enforcement agencies participating in federal task force agreements or receiving federal equipment grants
  • Municipalities and public-sector organizations that accept federal funding for infrastructure, public safety, or emergency management programs

If any portion of your budget touches federal dollars, the equipment that supports those programs—including surveillance systems—needs to be clean.

Which Brands Are Prohibited—and Why Rebranding Doesn't Help

The five covered manufacturers are Hikvision, Dahua, Hytera, Huawei, and ZTE. But the prohibition extends to subsidiaries and companies that are "substantially" the same entity. This is where buyers get caught.

A significant portion of the mid-market camera industry runs on Hikvision or Dahua hardware rebranded under different names. The housing and badge may say something unfamiliar, but the image sensor, chipset, and firmware inside are from a covered manufacturer. Under Section 889, the brand name on the box is irrelevant—what matters is the actual supply chain.

This means procurement teams cannot rely on unfamiliar brand names as safe alternatives. You need documentation, not assumptions.

What NDAA-Compliant Actually Means

A camera is NDAA-compliant when it is manufactured by a company that is not one of the five covered entities, contains no covered components at the chip or firmware level, and can produce documentation to prove both of those things.

Brands that are generally considered compliant for 2026 include Axis, Hanwha, Vivotek, Bosch, and Pelco (under current ownership). But "generally considered" is not a compliance standard. For any covered deployment, you need a written Letter of NDAA Compliance for each specific hardware model—not a verbal assurance from a sales representative, and not a marketing claim on a product page.

For government facility deployments, license plate recognition cameras are a common component at entry and exit chokepoints, and they carry the same compliance requirements as any other camera in the system. LPR is not a carve-out.

What Managed Surveillance Providers Must Be Able to Prove

If you are contracting with a managed surveillance provider—a company that deploys cameras and operates remote video monitoring on your behalf—you are still responsible for the compliance status of the hardware on your site. The provider's equipment, operating under your federal contract, is your exposure.

This is a gap many organizations miss. They assume the vendor handles compliance. The vendor may assume the client has reviewed it. Neither assumption is documentation.

What you should require from any provider operating on a covered site:

  • A Letter of NDAA Compliance for each hardware model they deploy
  • Country of manufacture declaration for cameras and recording equipment
  • Supply chain documentation at the component level, if your risk profile requires it
  • Written certification embedded in the service contract—not a side email, not a verbal confirmation
  • A defined process for hardware refresh notifications: if a provider swaps a camera model mid-contract, you need to know the replacement's compliance status before it goes on your wall

For temporary or mobile deployments—law enforcement operations, emergency management, construction phases on government-adjacent sites—the same requirements apply. A mobile surveillance unit brought onto a federal facility or deployed in support of a federally funded program needs to carry the same compliance documentation as any fixed installation.

The Buyer's Checklist: Five Questions for Every Provider

Before any contract is signed, put these questions in writing and require written answers:

  1. Are all cameras, NVRs, and network components in your systems free of Hikvision, Dahua, Huawei, ZTE, and Hytera components at the hardware and firmware level?
  2. Can you provide a Letter of NDAA Compliance for each hardware model you plan to deploy on our site?
  3. Do you have documented visibility into your supply chain for chip-level and firmware-level components?
  4. Will you certify NDAA compliance in writing as a term of our service agreement?
  5. How do you handle hardware refreshes during a contract term—will you proactively notify us if a replacement model changes the compliance status of our deployment?

A provider that hesitates on any of these questions, or offers verbal reassurance instead of written documentation, is not a compliant partner for a covered deployment.

How VDS Handles NDAA Compliance

Vision Detection Systems operates only NDAA-compliant hardware across all deployments. For government agencies, law enforcement, and federal contractors, we provide written compliance certification as part of the service agreement—not as an add-on, and not after the fact.

Our full NDAA compliance documentation covers hardware models, Letters of NDAA Compliance, and the supply chain standards we hold our hardware partners to. If your procurement office or legal team needs to review documentation before contract execution, that process is built in—not something we have to scramble to produce.

We also maintain hardware refresh protocols so that if a camera model in our fleet changes compliance status—whether due to an acquisition, a supply chain change, or a regulatory update—affected clients are notified before any replacement is deployed.

If your organization is operating under federal contracts, receiving federal grants, or supporting law enforcement and critical infrastructure programs subject to NDAA Section 889, the compliance status of your surveillance systems is not something to resolve after a procurement decision is made. Contact Vision Detection Systems to review your deployment requirements and receive written NDAA compliance documentation before your next contract action.

Frequently asked questions

Does NDAA Section 889 apply to state and local governments?

Section 889 is a federal law that directly binds federal agencies and their contractors. State and local governments are not automatically subject to it—but if a municipality accepts federal grants, participates in federal task force agreements, or contracts with federal agencies, those specific programs and the equipment supporting them fall under the prohibition. Many states have also begun adopting parallel legislation, so the practical reach is expanding year over year.

If we bought Hikvision or Dahua cameras before 2019, do we have to remove them?

Yes, if you are seeking or holding federal contracts. Phase 1 of Section 889 (August 2019) prohibited federal agencies from purchasing covered equipment. Phase 2 (August 2020) went further: federal contractors cannot use covered equipment anywhere in their operations as a condition of contract eligibility. Purchase date does not provide an exemption—the prohibition is on current use, not just new procurement.

How do I know if a camera is truly NDAA compliant and not just rebranded?

OEM rebranding is a real and documented problem. A camera sold under a lesser-known brand name may still contain Hikvision or Dahua chipsets or firmware, which makes it a covered product regardless of the label on the housing. The only reliable method is to request a Letter of NDAA Compliance from the manufacturer—not the reseller—along with country of manufacture documentation and, for higher-stakes deployments, supply chain attestation at the component level. Marketing language on a product page is not a substitute for written documentation.

What happens if a compliance violation is discovered during a contract audit?

The consequences range from contract termination to debarment from future federal contracting opportunities. Under FAR Subpart 4.21, contractors are required to represent that they do not use covered telecommunications equipment. A false representation—even an accidental one due to inadequate vendor vetting—can trigger significant legal and financial exposure. Proactive documentation and written compliance certification from your surveillance provider is the practical safeguard against that outcome.