NDAA-compliant cameras are surveillance devices and supporting hardware free of components from manufacturers named in NDAA Section 889, primarily Chinese state-linked firms flagged as national security risks. Federal agencies, contractors, and grant recipients are legally required to use them; many private businesses adopt the same standard voluntarily. The single move that protects you either way is to demand model-level written attestations and bill-of-materials disclosures before you sign a purchase order, not after.
TL;DR:
- Vendors must provide detailed, model-specific attestations and disclose component suppliers to verify NDAA compliance before purchase.
- Replacing noncompliant cameras entirely is the most straightforward option, but upgrading recording systems or adding analytics software are cost-effective alternatives.
- A thorough inventory, model-level verification, and documented responses from vendors form the basis of an effective compliance audit.
- Noncompliance can result in contract termination, fines, and legal exposure; therefore, legal review of representations is essential before signing.
- Brand name alone is unreliable, as covered components may be hidden in OEM arrangements or relabeled; component supplier disclosures are crucial.
Table of Contents
- What Is NDAA Section 889 and How Does It Apply to Video Surveillance?
- Who Has to Comply, and What Happens If They Don’t?
- Which Manufacturers Get Flagged, and Why the Brand Name Isn’t Enough
- How to Verify NDAA Compliance Before You Buy
- Rip-and-Replace, System Upgrade, or a Camera-Agnostic Analytics Layer?
- Step-by-Step: Auditing Your Existing System and Planning Upgrades
- What a Professional Installer Actually Delivers on a Compliance Project
- How Should Organizations Prioritize the Move to Compliant Cameras?
- Get a Compliance Audit From Central Jersey Security Cameras
- Sources
What Is NDAA Section 889 and How Does It Apply to Video Surveillance?
Section 889 of the National Defense Authorization Act splits into two operative parts. Section 889(a)(1)(A) bars federal agencies from buying “covered telecommunications equipment or services” as a substantial part of any system. Section 889(a)(1)(B) goes further, prohibiting agencies from contracting with any entity that uses covered equipment at all, even in systems unrelated to the government contract itself. That second clause is what pulls whole companies, not just federal buyers, into the compliance conversation.
The Federal Acquisition Regulation clause FAR 52.204-25 is the mechanism that actually enforces this. Contracting officers write it into solicitations, and it requires vendors to represent, in writing, whether they provide or use covered equipment. The original statutory language, including the specific findings that led Congress to name particular manufacturers, lives in the Congress.
For video surveillance specifically, “covered” doesn’t just mean cameras with a certain logo. It covers:
- Video surveillance and telecommunications equipment produced by the named manufacturers or their subsidiaries and affiliates
- Systems where that equipment is “a substantial or essential component” of the overall product, even under a different brand
- Cloud and software services that route through or depend on covered hardware, an area platforms like Microsoft Azure’s NDAA compliance guidance address directly for cloud-connected systems
That last point trips up a lot of buyers. A camera can carry an unfamiliar brand name and still fail compliance if the video management software behind it depends on a covered component somewhere in the chain.
Who Has to Comply, and What Happens If They Don’t?
Federal agencies must comply outright. Federal contractors and subcontractors inherit the obligation through flow-down clauses, meaning a prime contractor’s compliance duty passes to every vendor and subcontractor touching that contract, security camera installers included. Grant recipients using federal funds typically face the same requirement, often written directly into award terms.
Private businesses with no federal contract in sight still have real reasons to comply:
- Future eligibility: a company that installs non-compliant cameras today may find itself locked out of bidding on government or grant-funded work later
- Insurer and customer pressure: some commercial insurers and enterprise customers now ask for NDAA attestations as part of vendor due diligence
- Supply-chain hygiene: removing unvetted foreign hardware from a network reduces exposure regardless of who’s watching
The consequences for getting this wrong are not abstract. Noncompliant contractors risk contract termination, suspension, or outright debarment from future federal work. Misrepresenting compliance status in a written attestation, even unintentionally, can trigger False Claims Act exposure, which carries treble damages and per-violation penalties. Security industry analysis has flagged compliance as something that needs to be managed as a documented procurement project, not a checkbox on a sales brochure. Anyone signing a federal or grant-funded contract with camera provisions should have legal counsel review the representations clause before signing, not after an audit flags a problem.
Which Manufacturers Get Flagged, and Why the Brand Name Isn’t Enough
Section 889 names specific companies whose equipment federal buyers and covered contractors cannot use: Hangzhou Hikvision, Dahua Technology, Hytera Communications, Huawei, and ZTE, along with their subsidiaries and affiliates. That affiliate language matters. A camera sold under a smaller, unfamiliar brand can still be manufactured by one of these companies under an OEM arrangement, meaning the box says one thing and the circuit board says another.
This is where brand-only assurances fall apart. A vendor can honestly believe their product is compliant because the label on the box doesn’t match any name on the list, while the actual system-on-chip, image sensor, or network module inside was sourced from a covered manufacturer and simply relabeled downstream. Component-level inquiry into the SoC, sensor, and network module is often the only way to catch this, because the outward branding tells you nothing about what’s soldered inside.
Three things worth checking before you assume a product is clean:
- Whether the manufacturer discloses its component suppliers by name, not just by category
- Whether the same factory produces cameras for multiple brands you’ve seen marketed as “compliant”
- Whether the vendor will put the attestation in writing tied to a specific model number, not a general company statement
How to Verify NDAA Compliance Before You Buy
Treat this like a due diligence exercise, not a sales conversation. Marketing pages rarely disclose the details that actually matter, and vendors are not required to volunteer component sourcing unless you ask directly and in writing.
- Request a written Section 889 attestation tied to specific model numbers. A blanket “our company is NDAA-compliant” letter is close to worthless. You want a document that names the exact model, firmware version, and date of the representation.
- Request a component-level bill of materials. Ask for disclosure of the system-on-chip manufacturer, image sensor origin, and network module supplier. If a vendor resists this request, treat it as a signal, not a formality.
- Build representations and warranties into the contract itself. Include clauses requiring the vendor to notify you if a component supplier changes, plus reporting obligations if a future model revision introduces a covered part.
- Add flow-down language if you’re a contractor or subcontractor. Your compliance obligation likely needs to pass to your own vendors and installers, and the contract should say so explicitly.
- Escalate ambiguous answers to procurement, legal, and IT together. No single department should sign off alone. IT can assess technical claims, legal can assess contract exposure, and procurement can hold the vendor relationship accountable over time.
Pro Tip: Ask for the bill of materials before you ask for pricing. Vendors who are genuinely compliant will have this documentation ready; vendors who are stalling usually reveal it in how long the response takes.
Some vendors won’t disclose sourcing details in standard marketing collateral at all, not because they’re hiding something malicious, but because most buyers never ask. Asking in writing, and making the answer a contract condition rather than a verbal assurance, is what actually protects you.
Rip-and-Replace, System Upgrade, or a Camera-Agnostic Analytics Layer?
Once you know which parts of your system are noncompliant, you have three realistic paths forward, and they carry very different costs and timelines.
Full replacement. Buying new NDAA-compliant cameras end to end gives you the cleanest compliance story and the newest hardware. The tradeoff is cost and disruption: replacing every camera, cable run, and mount in a facility is expensive and takes time, especially for larger sites with legacy wiring.
VMS or NVR-level upgrade. Sometimes the noncompliant piece isn’t the camera at all. It’s the recorder or the video management software processing the feed. Upgrading or isolating that layer while keeping compliant cameras in place can resolve the issue at a fraction of the cost of full replacement, provided the cameras themselves check out clean at the component level.
Camera-agnostic Video AI. A growing option for facilities with large fleets of already-compliant cameras is layering analytics software on top of existing ONVIF or RTSP camera streams, without replacing hardware, as long as the analytics platform itself contains no covered components. This tends to be the most cost-effective route for industrial sites that already invested in compliant cameras but need better detection, counting, or alerting capability.
- Budget: full replacement costs the most upfront; a VMS/NVR upgrade or analytics layer usually costs less
- Disruption: replacement means downtime during installation; software-layer upgrades often run with minimal interruption
- Contractual obligations: if a contract specifically mandates compliant hardware (not just compliant analytics), a software fix alone may not satisfy the clause
Pro Tip: Read your contract’s exact wording before choosing a path. Some clauses require compliant equipment specifically, which rules out a software-only fix even if it solves the practical problem.
Step-by-Step: Auditing Your Existing System and Planning Upgrades
A proper audit follows a sequence, not a scramble. Skipping steps is how organizations end up replacing cameras that were already fine while missing the recorder that actually failed.
- Build a full inventory. List every camera, NVR, encoder, cloud service, and third-party plugin touching your video system, including model numbers and firmware versions.
- Run model-level verification against each item. Cross-check manufacturer names, then push further into affiliate and OEM relationships where the brand is unfamiliar or the origin is unclear.
- Escalate ambiguous cases immediately. If a vendor can’t answer sourcing questions in writing within a reasonable window, treat that model as unverified rather than assuming compliance.
- Triage by risk, not by convenience. Replace the highest-risk nodes first, typically anything touching government-contracted areas or handling sensitive facility zones, before addressing lower-stakes cameras.
- Document every step. Keep dated records of attestations requested, responses received, and decisions made. This paper trail is what protects you if a contract auditor or grant reviewer asks questions later.
- Set a realistic budget and timeline. Phased remediation over several quarters is often more practical than an all-at-once swap, particularly for larger commercial or industrial sites.
Contract language worth adding during this process includes a vendor notification clause for future component changes and a reporting requirement if a model is later found noncompliant after installation. Replacement urgency is often driven by contract or grant terms directly. Regulators generally don’t retroactively deauthorize equipment you already own unless a specific clause requires it, which is exactly why the contract language matters more than general anxiety about the news.
What a Professional Installer Actually Delivers on a Compliance Project
A professional security camera installation company approaches NDAA compliance work as a documented project, not a product swap. A site survey comes first: walking the property, cataloging every camera, recorder, and network device already in place, and flagging anything with an unclear manufacturer origin.
From there, the work moves into model-level inventory and bill-of-materials coordination, contacting manufacturers directly when a component’s origin isn’t obvious from spec sheets alone. For organizations with active or upcoming federal, state, or grant-funded contracts, this often means coordinating directly with a client’s procurement and legal teams to make sure the attestations we help gather actually satisfy the contract language, not just general reassurance. Our government security systems work follows this same documented process.

Installation itself includes secure configuration from day one, meaning network segmentation and access controls set up correctly the first time rather than patched in later. Ongoing service and maintenance keep that documentation current as firmware updates or component changes occur, which matters because a system compliant at installation can drift out of compliance if nobody’s tracking supplier changes down the road.
How Should Organizations Prioritize the Move to Compliant Cameras?
If your organization holds or wants federal contracts, immediate replacement of anything flagged during an audit is the right call. The False Claims Act exposure alone makes delay a bad bet. For everyone else, phased remediation, tackling the highest-risk cameras first while budgeting the rest over a few quarters, is usually the more sensible path.
What I’d push back on is the instinct to trust a vendor’s marketing page over a written attestation. Ask for the documentation before you ask for a quote. If a vendor hesitates on model-level paperwork, that hesitation tells you more than anything on their spec sheet. Schedule an audit with a professional installer before you assume your current system is fine.
— Tom
Get a Compliance Audit From Central Jersey Security Cameras
You’ve got three paths forward on compliance, replace everything, upgrade the recording layer, or add an analytics layer, and figuring out which one fits your building, budget, and contract obligations is exactly the kind of decision that benefits from a second set of eyes on-site rather than a guess from a spec sheet. Such companies handle that groundwork directly: a site survey, model-level camera inventory, bill-of-materials coordination with manufacturers, and installation with secure configuration built in from the start, serving homes and businesses throughout their service areas.
What you walk away with is a compliance report, a remediation plan prioritized by risk, and documentation formatted for your procurement file, whether that’s for a federal contract, a grant requirement, or simply your own peace of mind. If your facility handles government-adjacent contracts, our government security systems page covers that work in more detail, and readers navigating contract risk more broadly may find this GSA contract holder compliance overview useful as background. For homeowners and business owners ready to move forward, request a quote for professional camera installation and get a system built right the first time.
Sources
- FAR 52.204-25 — Prohibition on certain telecommunications and video surveillance services or equipment
- John S. McCain National Defense Authorization Act for Fiscal Year 2019 — full text
- SIA analysis of acquisition rules related to NDAA prohibition


