Industry
NDAA Section 889 Compliance in 2026: The Import Ban Just Changed the Math for Federal and Municipal Buyers
On June 26, 2026, the FCC prohibited the continued importation and marketing of previously authorized "legacy" surveillance equipment from Hikvision, Dahua, Huawei, ZTE, and Hytera. The rule took effect on July 16, 2026, ten days after Federal Register publication on July 6, so it is in force now. Two limits matter before you act on it. The prohibition reaches only equipment used for public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes, so ordinary commercial use of this equipment sits outside it. And of those four purposes, the FCC has expressly suspended the one closest to most camera buyers: the prohibition does not currently apply to physical security surveillance of critical infrastructure, because the Commission has no definition of that term and has said the suspension holds until it adopts one. For nearly four years, gear that received FCC authorization before the 2022 rules could keep entering the US legally under a grandfather loophole. That loophole is closed. New units and spare parts for covered equipment are now being stopped at the border (FCC Public Notice, June 26, 2026, fcc.gov/supplychain/coveredlist, retrieved 2026-07-14).
Corrected August 6, 2026. This post originally described the June 2026 import and marketing prohibition without its scope limits, and its timeline stated that FCC Covered List membership was unchanged after the March 12, 2021 listing. Both have been corrected against FCC Public Notice DA 26-635 and the FCC Covered List. A claim about a competitor's country of manufacture has also been removed for want of a primary source. Regulatory status last verified August 6, 2026. This proceeding is live: the critical-infrastructure suspension lifts when the FCC adopts a definition of that term, and this page will need revisiting on that day.
That single change turns Section 889 from a paperwork problem into a supply problem, and it reaches a much larger group of buyers than the phrase "federal procurement" suggests.
The Scenario That Catches Buyers
A city council approves a $400,000 camera upgrade for a public parking structure. The bid comes in under budget, the spec sheet reads clean, and the brand on the housing is one nobody in the room has heard flagged. Eighteen months later, a routine federal grant audit turns up the same cameras built on a chipset tied to Hikvision. The grant is federal, the cameras are not compliant, and the city is now negotiating a rip-and-replace on a budget that already spent its camera line item once.
That is the mechanism behind Section 889 of the 2019 National Defense Authorization Act.
What Section 889 Actually Says
Section 889 of the 2019 NDAA bars the use of video surveillance and telecommunications equipment from five named manufacturers, Hikvision, Dahua, Huawei, ZTE, and Hytera, along with their subsidiaries and affiliates, in two situations: direct federal procurement, and any system where that equipment is a substantial or essential component tied to federal work, per Section 889(a)(1)(B).
The FCC Covered List, maintained under the Secure Networks Act, is the enforcement layer underneath the statute. The sequence is where most published content gets it wrong, so here is the actual timeline:
| Date | Action | Status |
|---|---|---|
| Mar 12, 2021 | Five entities placed on the FCC Covered List. Those five Section 889 entries are unchanged, but the Covered List itself has grown four times since: Kaspersky (2024), drones and UAS components (Dec 2025), foreign-produced routers (Mar 2026), and power inverters and robots (Jul 2026). The June 2026 import ban below covers entries added in 2024 or earlier, so it reaches the Kaspersky listing but not the 2025 or 2026 additions. | In force |
| Nov 2022 (eff. Feb 6, 2023) | R&O (FCC 22-84) blocks new FCC authorizations for Covered List gear, so it cannot be sold as new in the US. | In force |
| Adopted Oct 2025 (FCC 25-71); published Dec 2025 (FR Doc 2025-21928) | R&O half sets the import/marketing-prohibition procedure and a covered-component-part rule (eff. Dec 26, 2025). FNPRM half re-proposes a "critical infrastructure" definition. | R&O final; FNPRM open |
| Jun 26, 2026 (eff. early Jul 2026) | Import and marketing of previously authorized legacy covered gear prohibited. Executes the Dec 2025 procedure. | In force now |
| ~Jul 3, 2026 (Jul 22 vote) | Third R&O/FNPRM proposes going further. | Not yet adopted |
Two framing points the table compresses. The Dec 2025 document is two things at once: its Report and Order half is final adopted law, while its Further Notice half only seeks comment on a "critical infrastructure" definition, reopened after the DC Circuit vacated the FCC's prior one in Hikvision USA v. FCC, 97 F.4th 938 (D.C. Cir. 2024). So the import-and-marketing mechanism is settled; that definition is not. And nothing on the Covered List changed in 2026 by way of new entities, what changed is enforcement: the June 26 ban closed the legacy loophole for gear these five had already gotten authorized before 2022. We do not treat the July 2026 third proceeding as current law until it is adopted.
Who It Actually Applies To
The statute reaches any contractor, grantee, or loan recipient using covered equipment as a substantial or essential component of a system tied to federal work. None of the buyers below is "the federal government," yet all can trip Section 889:
| Buyer type | How 889 reaches them |
|---|---|
| University | Runs federal research grants |
| Hospital system | Bills Medicare |
| Municipality | Took a federal infrastructure loan |
| Private contractor | Performs federal work at its own facility |
Anyone assuming the rule only touches Department of Defense installations is reading half the statute. State law adds a layer: Florida and Indiana restrict covered surveillance equipment for their own agencies. We build in Holly Hill, Florida, so for buyers working with Florida agencies this is a local-authority question too.
Three Rules, Not One
Buyers regularly conflate three separate requirements that each ask a different question:
| Requirement | Question it answers | Enforcement mechanism |
|---|---|---|
| NDAA Section 889 | Is the manufacturer on the banned list (Hikvision, Dahua, Huawei, ZTE, Hytera, or an affiliate)? | Procurement prohibition for federal buyers, contractors, grantees, loan recipients |
| TAA (Trade Agreements Act) | Where was the product manufactured or substantially transformed? | Separate country-of-origin procurement rule |
| FCC Covered List | Is the equipment authorized for sale in the US at all? | New authorizations blocked since the Nov 2022 R&O (eff. Feb 2023); legacy import/marketing banned June 2026 |
Satisfying one does not satisfy the others. A camera manufactured in a TAA-compliant country can still ship a banned manufacturer's chipset inside it. A camera that clears Section 889 by brand name can still fail a TAA audit if final assembly happens somewhere that does not qualify. Buyers who ask their vendor "are you NDAA compliant" and stop there are asking one-third of the question.
The OEM Rebrand Trap, and How to See Through It
The brand printed on a camera housing is not proof of who made it. Public reporting identifies several familiar brands as historically built on covered manufacturers:
| Brand | Historically built on |
|---|---|
| Lorex, Amcrest | Dahua |
| HiLook, HiWatch, EZVIZ | Hikvision |
We frame these as historically built on those manufacturers, not as claims about any specific unit's sourcing today, because sourcing can change and the SKU in front of you is what matters.
Here is the concrete way to check, and it costs nothing. Every camera and recorder carries an FCC ID on its label. The leading characters of that ID, the grantee code, identify the actual manufacturer, and the full ID is searchable in the FCC's public database (fcc.gov/oet/ea/fccid). A procurement officer can take the FCC ID off a sample unit or a spec sheet, look it up, and see who really made the hardware, regardless of the brand on the box. That turns the abstract rebrand warning into a five-minute action any buyer can run before signing.
The New Problem: Covered Gear Is Becoming a Stranded Asset
The June 2026 import ban created a procurement question that did not exist before, and it reaches buyers who believe 889 does not apply to them. Because new units and spare parts for covered equipment can no longer clear the border, a system built on covered cameras now has a shrinking parts supply. Nothing gets shut off and installed equipment keeps operating. But when a covered camera fails, a matching replacement is increasingly hard to source legally, which pushes the owner toward replacement on the failed vendor's timeline rather than their own.
That reframes the decision. It is no longer only a compliance question, it is an asset-lifecycle one. A buyer standing up a new system on covered hardware in 2026 is buying into a supply chain that is closing.
What Buyers Should Actually Ask For
Documentation, not a verbal claim: a bill of materials, a country-of-manufacture statement, and a plain answer to "who makes this hardware, not who sells it." If a vendor cannot answer that in writing, the compliance claim is unverified.
We are not the only NDAA- and TAA-compliant option, and any honest treatment should say so. Axis, Hanwha Vision, Pelco, Avigilon, and Verkada all offer compliant product lines. One caution, using Verkada because buyers ask about it most: its compliance is model-specific, not brand-wide. Per Verkada's own compliance documentation, the TAA, NDAA, and FIPS 140 designations attach to the government-grade line, not the whole catalog. A brand-level badge tells a buyer nothing about the specific SKU in front of them, and country of manufacture is a separate question you should ask the vendor in writing rather than infer from a compliance badge. Verify at the model level.
What matters underneath compliance is where the hardware is built, who controls the firmware, and what total cost of ownership looks like once equipment is in the ground. Several NDAA-compliant vendors price around mandatory per-camera subscriptions rather than a one-time purchase, a related cost question for any multi-year contract.
Every Iron Gate system is designed, engineered, assembled, and tested at our Holly Hill, Florida facility, with domestic supply chain documentation available for procurement review. That is where accountability sits when a vulnerability is disclosed, a part fails, or an audit asks for the paper trail.
A Compliance Checklist Before You Sign
- Does the vendor name the actual manufacturer, not just the brand, in writing?
- Can the vendor produce a bill of materials showing chipset origin?
- Have you pulled the FCC ID off a sample unit and looked up the real grantee?
- Is the product NDAA Section 889 compliant, TAA compliant, or both, documented separately?
- Is the specific model covered by, or built on a chipset from, a Covered List entity?
- Has this been re-verified against the current FCC Covered List and Federal Register record, not a snapshot from a prior budget cycle?
Section 889 enforcement moved fast through 2025 and into 2026, and Hikvision is actively contesting it: it opposed the March 2026 proceeding, argues the FCC lacks authority to revoke compliant authorizations, and filed a DC Circuit challenge in December 2025. A court could shift some of this. Any compliance answer should be dated and re-checked against the current FCC record before a purchase order goes out, not assumed from a vendor's marketing page.
Request Compliance Documentation
To request current compliance documentation for a specific procurement, call 904-896-5618 or book a security assessment. For buyers evaluating government contracts specifically, see our government security solutions.
Common Questions
Can I still buy Hikvision or Dahua cameras in 2026? As new equipment, effectively no. Covered-list gear has been blocked from new FCC authorization since the November 2022 rules took effect in February 2023, and on June 26, 2026 the FCC also prohibited the import and marketing of previously authorized legacy units, effective July 16, 2026. That legacy prohibition is narrower than it first looks: it applies only to the four covered purposes, and the FCC has suspended it for physical security surveillance of critical infrastructure until it adopts a definition of that term. Installed equipment can keep operating either way, and for public safety, government facility, and other national security use, sourcing new covered units or spare parts through legal US channels is now closed.
Do I have to remove my existing Hikvision cameras? No. The 2026 import ban does not require rip-out and there is no kill switch. The practical pressure is different: replacement units and spare parts for covered gear are being cut off at the border, so a failed camera becomes harder to replace like-for-like over time.
How do I check if my camera is NDAA compliant? Start with the FCC ID on the device label. The grantee code (the leading characters) identifies the actual manufacturer, and you can look up the full ID in the FCC public database at fcc.gov/oet/ea/fccid. That tells you who really built the hardware regardless of the brand name. Then ask the vendor for a bill of materials and a country-of-manufacture statement in writing.
Is Verkada NDAA compliant? It depends on the model, not the brand. Per Verkada's own compliance documentation, TAA, NDAA, and FIPS designations apply to specific government-grade SKUs rather than the entire catalog. Verify compliance at the individual model level, not from a brand-wide claim, and ask for a country-of-manufacture statement in writing for whichever camera you are actually buying.
Are Hikvision cameras banned by the government? Hikvision, along with Dahua, Huawei, ZTE, and Hytera and their subsidiaries and affiliates, is barred from federal procurement under NDAA Section 889 and has been on the FCC Covered List since March 2021. New equipment authorization has been blocked since February 2023, and legacy import and marketing were prohibited by an order adopted June 26, 2026 and effective July 16, 2026, for covered purposes only, with the critical-infrastructure purpose currently suspended.
Is TAA compliance the same as NDAA compliance? No. TAA governs where a product is manufactured or substantially transformed. NDAA Section 889 governs whether the manufacturer is one of five named, banned entities. A product can pass one and fail the other.
Which security camera brands are NDAA compliant? Several brands offer NDAA- and TAA-compliant product lines, including Axis, Hanwha Vision, Pelco, Avigilon, Verkada, and Iron Gate Technologies. Because compliance and sourcing can be model-specific and can change, verify current status and country of manufacture at the individual model level with each vendor.
Ready to Talk Security?
Our engineering team can walk you through the right solution for your environment.
Book a Security Assessment