Industry
Is Your Camera Footage Admissible? What Chain of Custody Actually Requires
A claim arrives eleven months after the incident. Counsel asks for the footage. Whether you can produce something a court will accept was decided by choices made at install time, most of them by people who were not thinking about a courtroom.
That is the argument of this piece. Admissibility is engineered at install and merely discovered at subpoena. By the time anyone asks, every decision that matters has already been made.
This covers the Federal Rules of Evidence. State rules vary, sometimes substantially, and none of what follows is legal advice. It is a description of what the federal rules ask of a recording system so that you can make engineering decisions with the legal consequence visible.
Two Doors: Rule 901 and Rule 902
Video gets into evidence one of two ways.
The first is authentication under Rule 901, which requires producing evidence sufficient to support a finding that the item is what its proponent claims. The rule lists examples. Rule 901(b)(1) accepts "Testimony that an item is what it is claimed to be." Rule 901(b)(4) accepts "The appearance, contents, substance, internal patterns, or other distinctive characteristics of the item, taken together with all the circumstances" (law.cornell.edu/rules/fre/rule_901, retrieved 2026-08-13).
The second is self-authentication under Rule 902, where a certification substitutes for a live witness. That door opened wider on December 1, 2017, when subsections (13) and (14) were added.
What Rule 901(b)(9) Is Actually Asking
Buried in the list of examples is the subsection that should change how you specify a recording system. Rule 901(b)(9), Evidence About a Process or System, authenticates by "Evidence describing a process or system and showing that it produces an accurate result" (law.cornell.edu/rules/fre/rule_901, retrieved 2026-08-13).
Read it again with your NVR in mind. The subject of that sentence is not the video. It is the system.
Under 901(b)(9), what gets examined is whether your recorder, your clock, your storage, and your export process produce an accurate result. That is a documentation question about infrastructure, and it means the following stop being IT preferences and start being evidentiary facts:
Where your system clock gets its time. An NVR with a drifting internal clock and no external time source produces timestamps that nobody can vouch for. If the recorder syncs to NTP, which server, and is the sync logged?
Whether your retention behaves the way you say it does. A policy document claiming 90 days is worth nothing if the array actually rolls over at 47 because it was sized on an optimistic bitrate assumption. Sizing a retention window from a real per-camera bitrate, rather than trusting a calculator's hidden defaults, is an exercise worth running before you make the claim, and this is one of the places that gap becomes expensive.
Whether the export is the recording or a re-encode. Some systems export by transcoding to a convenient format, which changes the file. Whether that matters depends on the challenge you face, but you should know which one your system does before you find out in a deposition.
Whether the system logs its own gaps. A recorder that silently stops for six hours and resumes without noting it has produced a record with a hole and no explanation for the hole.
What Changed on December 1, 2017
Rule 902(13) makes self-authenticating "A record generated by an electronic process or system that produces an accurate result, as shown by a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12). The proponent must also meet the notice requirements of Rule 902(11)."
Rule 902(14) makes self-authenticating "Data copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification, as shown by a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12). The proponent also must meet the notice requirements of Rule 902(11)" (law.cornell.edu/rules/fre/rule_902, retrieved 2026-08-13, amendment effective December 1, 2017).
Do not skip that closing sentence in either subsection. Self-authentication does not follow from producing a certification. Rule 902(11) requires the proponent, before the trial or hearing, to give the adverse party reasonable written notice of the intent to offer the record and to make the record and the certification available for inspection, so that the party has a fair opportunity to challenge them. That is a step counsel takes rather than an engineering one, but it governs whether the self-authentication route is available at all, so it is worth knowing that the certification on its own does not finish the job.
The practical change is that a written certification from a qualified person can substitute for producing a live custodian witness. For a facility with no dedicated video custodian, and with turnover in whoever happens to administer the system, that route is worth understanding in advance rather than discovering under deadline.
Note the phrase in 902(14): "a process of digital identification." That is the language hash verification speaks to directly. If your export procedure produces a cryptographic hash of the file at the moment of export, and that hash is recorded and can be recomputed later to show the file is unchanged, you have a process of digital identification rather than an assertion that nobody tampered with it.
Chain of Custody in Practice
Chain of custody is not a form. It is the ability to answer, later and under challenge, who had the file and what happened to it. What follows is the operational checklist that produces those answers.
| What the rule reaches | The operational artifact that speaks to it | Decided when |
|---|---|---|
| Rule 901(b)(9), system produces an accurate result | Documented time source and sync logs, recorder configuration record, gap and health logging, written retention policy that matches measured behavior | At design and install |
| Rule 901(b)(1), testimony that the item is what it is claimed to be | A named person who can describe the system and the export, and who is still reachable | At staffing, and again at turnover |
| Rule 901(b)(4), distinctive characteristics taken with the circumstances | Embedded timestamps, camera identifiers, and continuous surrounding footage rather than an isolated clip | At configuration and at export |
| Rule 902(13), record generated by an electronic process, with certification | A qualified person available to certify, plus system documentation good enough for them to certify against | Before the request arrives |
| Rule 902(14), data copied, authenticated by a process of digital identification | Hash computed at export, recorded, and reproducible on the delivered file | At export, and it cannot be added afterward |
| Any of the above, if the footage no longer exists | Retention window that outlasts your realistic claim horizon, plus a working legal hold procedure | At procurement, before anything else on this list matters |
The bottom row governs every row above it. If the footage rolled over, the rest of the table is academic.
Retention Is the Upstream Decision
Most claims do not arrive the week of the incident. A slip and fall, an employment dispute, a cargo loss, a contract disagreement about what was delivered and when: these surface on the timeline of a lawyer and an insurer, not on the timeline of your storage array.
So the question at procurement is not "how many days does the vendor's calculator say we get." It is "how long is our realistic claim horizon, and does the retention window clear it with margin." Then, separately, do you have a legal hold procedure that actually stops the overwrite once someone knows a claim is coming? A hold that requires a specific administrator to remember to click something, in a system that deletes on a schedule, is not a hold.
Cloud-Only Versus On-Premise Changes the Custodian Question
Where the footage lives changes who can certify it and how quickly you can get it.
With on-premise recording under your control, the system is yours, the export is yours, and the qualified person under Rule 902(13) can be someone on your side who knows the configuration. You control the export format and can compute a hash at the moment of export.
With cloud-only storage, the record was generated and held by a third party. Producing it means going through that vendor's process on that vendor's schedule, and the person best positioned to certify how the system produces an accurate result may work for the vendor rather than for you. That is workable, and plenty of organizations do it. It is also a dependency you should price before you sign, alongside the data sovereignty questions cloud-only architecture raises and the contractual picture on subscription platforms.
We are not claiming cloud footage is inadmissible. It is not. The point is narrower: the custodian, the export process, and the response timeline sit outside your organization, and you should know that before a subpoena rather than after.
Iron Gate's Position
We build on-premise recording under customer control, and the evidentiary case is one of the reasons. The system is documented at install, the time source is specified rather than left to a default, retention is sized against a stated policy rather than a marketing figure, and the customer holds the export.
We are not lawyers and we do not certify that a system satisfies a rule of evidence. What we do is design so the answers exist. When counsel asks where the timestamps come from and whether the file is unchanged, the difference between a good afternoon and a bad one is whether somebody decided those questions two years earlier.
Common Questions
Is security camera footage admissible in court?
It can be, through authentication under Rule 901 or self-authentication under Rule 902(13) and (14). Admissibility turns on whether you can show the system produces an accurate result and that the file is what you say it is, which depends on decisions made long before the request. These are the federal rules and state rules differ.
What is chain of custody for video evidence?
The ability to account for the file from recording through export to delivery: who had it, what was done to it, and evidence that it is unchanged. In practice that means a documented export process, a recorded hash, timestamps traceable to a known time source, and a named person who can describe all of it.
Do I need a witness to authenticate surveillance video?
Not necessarily since December 1, 2017. Rules 902(13) and 902(14) allow a certification from a qualified person to substitute for live testimony, provided the certification requirements of Rule 902(11) or (12) are met. Both subsections also require the proponent to meet the notice requirements of Rule 902(11), which means advance written notice to the adverse party and an opportunity to inspect the record and the certification (retrieved 2026-08-13). The certification on its own does not complete the route. Whether it fits your situation is a question for counsel.
What is FRE 902(14) and how does it apply to a video export?
It makes data copied from an electronic device or storage medium self-authenticating when authenticated "by a process of digital identification," with a qualifying certification. Computing and recording a cryptographic hash at the moment of export is the practice that speaks most directly to that language.
How long should a business keep surveillance footage for a legal claim?
Long enough to clear your realistic claim horizon with margin, which is a question about your exposure and your industry rather than a universal number. Whatever you choose, verify the array actually delivers it rather than trusting the policy document, and make sure a legal hold can stop the overwrite.
What makes video evidence get thrown out?
Common failure modes are footage that no longer exists because retention rolled over, timestamps nobody can trace to a time source, an export process nobody can describe, gaps in the recording with no explanation, and no available person who can speak to how the system works. Every one of those is an infrastructure decision rather than a legal one.
Sources
- Federal Rule of Evidence 901, Authenticating or Identifying Evidence, law.cornell.edu/rules/fre/rule_901, retrieved 2026-08-13
- Federal Rule of Evidence 902, Evidence That Is Self-Authenticating, law.cornell.edu/rules/fre/rule_902, retrieved 2026-08-13. Subsections (13) and (14) added by amendment effective December 1, 2017.
Ready to Talk Security?
Our engineering team can walk you through the right solution for your environment.
Book a Security Assessment