Back to Blog

Industry

NDAA Section 889 Compliance: What Federal and Municipal Buyers Must Verify

Iron Gate Technologies | | 10 min

A city council approves a $400,000 camera upgrade for a public parking structure. The bid comes in under budget, the spec sheet reads clean, and the brand on the housing is one nobody in the room has heard flagged. Eighteen months later, a routine federal grant audit turns up the same cameras built on a chipset tied to Hikvision. The grant is federal, the cameras are not compliant, and the city is now negotiating a rip-and-replace on a budget that already spent its camera line item once.

That is the mechanism behind Section 889 of the 2019 National Defense Authorization Act. For most of its life it was a paperwork problem. As of mid-2026 it is a supply problem, and it reaches a much larger group of buyers than the phrase "federal procurement" suggests.

On June 26, 2026, the FCC prohibited the continued importation and marketing of previously authorized "legacy" surveillance equipment from Hikvision, Dahua, Huawei, ZTE, and Hytera. The rule took effect in early July 2026, so it is in force now. For nearly four years, gear that received FCC authorization before the 2022 rules could keep entering the US legally under a grandfather loophole. That loophole is closed. New units and spare parts for covered equipment are now being stopped at the border (FCC Public Notice, June 26, 2026, fcc.gov/supplychain/coveredlist, retrieved 2026-07-14).

What Section 889 Actually Says

Section 889 of the 2019 NDAA bars the use of video surveillance and telecommunications equipment from five named manufacturers, Hikvision, Dahua, Huawei, ZTE, and Hytera, along with their subsidiaries and affiliates, in two situations: direct federal procurement, and any system where that equipment is a substantial or essential component tied to federal work, per Section 889(a)(1)(B).

The FCC Covered List, maintained under the Secure Networks Act, is the enforcement layer underneath the statute. The sequence is where most published content gets it wrong, so here is the actual timeline.

Date Action Status
Mar 12, 2021 Five entities placed on the FCC Covered List. Membership unchanged since. In force
Nov 2022 (eff. Feb 6, 2023) R&O (FCC 22-84) blocks new FCC authorizations for Covered List gear, so it cannot be sold as new in the US. In force
Dec 2025 (FR Doc 2025-21928, FCC 25-71) R&O half sets the import/marketing-prohibition procedure and a covered-component-part rule (eff. Dec 26, 2025). FNPRM half re-proposes a "critical infrastructure" definition. R&O final; FNPRM open
Jun 26, 2026 (eff. early Jul 2026) Import and marketing of previously authorized legacy covered gear prohibited. Executes the Dec 2025 procedure. In force now
~Jul 3, 2026 (Jul 22 vote) Third R&O/FNPRM proposes going further. Not yet adopted

Two framing points the table compresses. The Dec 2025 document is two things at once: its Report and Order half is final adopted law, while its Further Notice half only seeks comment on a "critical infrastructure" definition, reopened after the DC Circuit vacated the FCC's prior one in Hikvision USA v. FCC, 97 F.4th 938 (D.C. Cir. 2024). So the import-and-marketing mechanism is settled; that definition is not. And nothing on the Covered List changed in 2026 by way of new entities, what changed is enforcement: the June 26 ban closed the legacy loophole for gear these five had already gotten authorized before 2022. We do not treat the July 2026 third proceeding as current law until it is adopted.

Who the Rule Actually Reaches

The statute reaches any contractor, grantee, or loan recipient using covered equipment as a substantial or essential component of a system tied to federal work. None of the buyers below is "the federal government," yet all can trip Section 889.

Buyer type How 889 reaches them
University Runs federal research grants
Hospital system Bills Medicare
Municipality Took a federal infrastructure loan
Private contractor Performs federal work at its own facility

Anyone assuming the rule only touches Department of Defense installations is reading half the statute. State law adds a layer: Florida and Indiana restrict covered surveillance equipment for their own agencies. We build in Holly Hill, Florida, so for buyers working with Florida agencies this is a local-authority question too.

Three Rules, Not One

Buyers regularly conflate three separate requirements that each ask a different question.

Requirement Question it answers Enforcement mechanism
NDAA Section 889 Is the manufacturer on the banned list (Hikvision, Dahua, Huawei, ZTE, Hytera, or an affiliate)? Procurement prohibition for federal buyers, contractors, grantees, loan recipients
TAA (Trade Agreements Act) Where was the product manufactured or substantially transformed? Separate country-of-origin procurement rule
FCC Covered List Is the equipment authorized for sale in the US at all? New authorizations blocked since the Nov 2022 R&O (eff. Feb 2023); legacy import/marketing banned June 2026

Satisfying one does not satisfy the others. A camera manufactured in a TAA-compliant country can still ship a banned manufacturer's chipset inside it. A camera that clears Section 889 by brand name can still fail a TAA audit if final assembly happens somewhere that does not qualify. Buyers who ask their vendor "are you NDAA compliant" and stop there are asking one-third of the question.

The OEM Rebrand Trap, and How to See Through It

The brand printed on a camera housing is not proof of who made it. Public reporting identifies several familiar brands as historically built on covered manufacturers.

Brand Historically built on
Lorex, Amcrest Dahua
HiLook, HiWatch, EZVIZ Hikvision

We frame these as historically built on those manufacturers, not as claims about any specific unit's sourcing today, because sourcing can change and the SKU in front of you is what matters.

Here is the concrete way to check, and it costs nothing. Every camera and recorder carries an FCC ID on its label. The leading characters of that ID, the grantee code, identify the actual manufacturer, and the full ID is searchable in the FCC's public database (fcc.gov/oet/ea/fccid). A procurement officer can take the FCC ID off a sample unit or a spec sheet, look it up, and see who really made the hardware, regardless of the brand on the box. That turns the abstract rebrand warning into a five-minute action any buyer can run before signing.

Covered Gear Is Becoming a Stranded Asset

The June 2026 import ban created a procurement question that did not exist before, and it reaches buyers who believe 889 does not apply to them. Because new units and spare parts for covered equipment can no longer clear the border, a system built on covered cameras now has a shrinking parts supply. Nothing gets shut off and installed equipment keeps operating. But when a covered camera fails, a matching replacement is increasingly hard to source legally, which pushes the owner toward replacement on the failed vendor's timeline rather than their own.

That reframes the decision. It is no longer only a compliance question, it is an asset-lifecycle one. A buyer standing up a new system on covered hardware in 2026 is buying into a supply chain that is closing.

What Buyers Should Actually Ask For

Documentation, not a verbal claim: a bill of materials, a country-of-manufacture statement, and a plain answer to "who makes this hardware, not who sells it." If a vendor cannot answer that in writing, the compliance claim is unverified.

We are not the only NDAA- and TAA-compliant option, and any honest treatment should say so. Axis, Hanwha Vision, Pelco, Avigilon, and Verkada all offer compliant product lines. One caution, using Verkada because buyers ask about it most: its compliance is model-specific, not brand-wide. Per Verkada's own compliance documentation, the TAA, NDAA, and FIPS 140 designations attach to the government-grade line, not the whole catalog, and its hardware is built primarily in Taiwan, a TAA-designated country, so no TAA problem but not US-made. A brand-level badge tells a buyer nothing about the specific SKU in front of them. Verify at the model level.

What matters underneath compliance is where the hardware is built, who controls the firmware, and what total cost of ownership looks like once equipment is in the ground. Several NDAA-compliant vendors price around mandatory per-camera subscriptions rather than a one-time purchase, a related cost question for any multi-year contract. The security camera buyer's guide covers how that math plays out over a five-year horizon.

A Compliance Checklist Before You Sign

  1. Does the vendor name the actual manufacturer, not just the brand, in writing? A brand name on a housing is a marketing decision. The manufacturer is the compliance question.
  2. Can the vendor produce a bill of materials showing chipset origin? The chipset is where a covered manufacturer most often survives inside an otherwise clean-looking product.
  3. Have you pulled the FCC ID off a sample unit and looked up the real grantee? Five minutes in the FCC database settles what a spec sheet cannot.
  4. Is the product NDAA Section 889 compliant, TAA compliant, or both, documented separately? They are different rules with different answers. Ask for each one on its own.
  5. Is the specific model covered by, or built on a chipset from, a Covered List entity? Compliance attaches to the SKU, not the catalog.
  6. Has this been re-verified against the current FCC Covered List and Federal Register record, not a snapshot from a prior budget cycle? The record moved twice in the last eight months.

Section 889 enforcement moved fast through 2025 and into 2026, and Hikvision is actively contesting it: it opposed the March 2026 proceeding, argues the FCC lacks authority to revoke compliant authorizations, and filed a DC Circuit challenge in December 2025. A court could shift some of this. Any compliance answer should be dated and re-checked against the current FCC record before a purchase order goes out, not assumed from a vendor's marketing page.

Iron Gate's Position

Every Iron Gate system is designed, engineered, assembled, and tested at our Holly Hill, Florida facility, with domestic supply chain documentation available for procurement review. That is where accountability sits when a vulnerability is disclosed, a part fails, or an audit asks for the paper trail.

American-made hardware is not a marketing angle on this rule, it is the reason the question does not arise. A system built in Holly Hill has no Covered List manufacturer in it to find, no grantee code that resolves to a banned entity, and no exposure to the June 2026 import ban when a unit needs replacing in year four.

To request current compliance documentation for a specific procurement, call 904-896-5618 or book a security assessment. For buyers evaluating government contracts specifically, see our government security solutions. The Iron Gate technology overview covers how the hardware is built.

Common Questions

Can I still buy Hikvision or Dahua cameras in 2026?
As new equipment, effectively no. Covered-list gear has been blocked from new FCC authorization since the November 2022 rules took effect in February 2023, and as of June 26, 2026 the FCC also prohibited the import and marketing of previously authorized legacy units. Installed equipment can keep operating, but sourcing new covered units or spare parts through legal US channels is now closed.

Do I have to remove my existing Hikvision cameras?
No. The 2026 import ban does not require rip-out and there is no kill switch. The practical pressure is different: replacement units and spare parts for covered gear are being cut off at the border, so a failed camera becomes harder to replace like-for-like over time.

How do I check if my camera is NDAA compliant?
Start with the FCC ID on the device label. The grantee code (the leading characters) identifies the actual manufacturer, and you can look up the full ID in the FCC public database at fcc.gov/oet/ea/fccid. That tells you who really built the hardware regardless of the brand name. Then ask the vendor for a bill of materials and a country-of-manufacture statement in writing.

Is Verkada NDAA compliant?
It depends on the model, not the brand. Per Verkada's own compliance documentation, TAA, NDAA, and FIPS designations apply to specific government-grade SKUs rather than the entire catalog, and the hardware is built primarily in Taiwan. Verify compliance at the individual model level, not from a brand-wide claim, for whichever camera you are actually buying.

Are Hikvision cameras banned by the government?
Hikvision, along with Dahua, Huawei, ZTE, and Hytera and their subsidiaries and affiliates, is barred from federal procurement under NDAA Section 889 and has been on the FCC Covered List since March 2021. New equipment authorization has been blocked since February 2023, and legacy import and marketing were prohibited as of June 26, 2026.

Is TAA compliance the same as NDAA compliance?
No. TAA governs where a product is manufactured or substantially transformed. NDAA Section 889 governs whether the manufacturer is one of five named, banned entities. A product can pass one and fail the other.

Which security camera brands are NDAA compliant?
Several brands offer NDAA- and TAA-compliant product lines, including Axis, Hanwha Vision, Pelco, Avigilon, Verkada, and Iron Gate Technologies. Because compliance and sourcing can be model-specific and can change, verify current status and country of manufacture at the individual model level with each vendor.

Ready to Talk Security?

Our engineering team can walk you through the right solution for your environment.

Book a Security Assessment