NDAA Compliance for Video and Security Equipment

NDAA compliance for video and security equipment means avoiding the procurement or use of covered telecommunications and video surveillance products under Section 889 of the National Defense Authorization Act, a rule that reaches beyond what a federal buyer purchases and into what it uses anywhere in its operation.

Section 889 sits inside the John S. McCain National Defense Authorization Act for Fiscal Year 2019, a public law available in full on congress.gov, and it is one of the few federal acquisition rules that names specific manufacturers directly rather than describing a category of risk in the abstract. Homeland security agencies, utilities, and other critical infrastructure operators increasingly treat an NDAA compliance review as a routine part of any camera or security software purchase, not just a step reserved for direct federal contracts.

What Section 889 Actually Prohibits

Section 889 contains two separate prohibitions, and confusing them is the most common mistake buyers make during an NDAA compliance review.

The Procurement Prohibition, Part (a)(1)(A)

This part bars federal agencies from procuring or obtaining covered telecommunications or video surveillance equipment and services as a substantial or essential component of any system, or as critical technology of any system. It governs what an agency itself buys.

The Use Prohibition, Part (a)(1)(B)

This part is broader. It bars a federal agency from entering into, renewing, or extending a contract with any entity that uses covered equipment or services as a substantial or essential component of any system, regardless of whether that use touches the federal contract at all. A contractor can lose federal business over equipment installed somewhere else in its operation entirely.

Provision What It Restricts Who It Reaches
Section 889(a)(1)(A) Federal procurement of covered equipment as a system component Federal agency purchasing decisions
Section 889(a)(1)(B) Use of covered equipment anywhere in a contractor’s operation Any entity holding or seeking a covered federal contract

The Named Covered Manufacturers

Section 889 does not describe covered equipment in the abstract. It names the manufacturers directly, along with their subsidiaries and affiliates.

  • Video surveillance products: Hangzhou Hikvision Digital Technology Company and Dahua Technology Company.
  • Telecommunications equipment: Huawei Technologies Company, ZTE Corporation, and Hytera Communications Corporation.

The OEM and Rebranding Trap

These manufacturers sell components and complete devices through original equipment manufacturer agreements with many other brands, so a camera, DVR, or NVR sold under an unrelated name can still contain a restricted sensor or chipset. Checking the label on the housing is not enough. A proper NDAA compliance check verifies the chipset and sensor origin of each device, not just the brand printed on the box.

Who Is Bound by NDAA Compliance

NDAA compliance binds federal agencies directly, and it reaches contractors, subcontractors, and many recipients of federal grant funding indirectly through the terms attached to that funding.

The FAR Clauses That Enforce Section 889

Two clauses in the Federal Acquisition Regulation put Section 889 into practice. FAR 52.204-25 is the prohibition clause itself, written into applicable federal contracts to bar the contractor from providing or using covered equipment. Separately, FAR 52.204-24 is the representation clause, under which a contractor states, typically through its annual representations and certifications, whether it does or does not use covered telecommunications or video surveillance equipment or services. A false representation under either clause is a serious matter, not a formality.

Practical Compliance Steps If You Already Own Cameras

An operator that already has cameras installed can work through an NDAA compliance review in a defined sequence rather than starting from scratch.

  • Inventory every camera, NVR, DVR, and recorder by manufacturer and model, not just by the installer or reseller brand.
  • Check whether any device was manufactured or supplied under an OEM agreement with a covered manufacturer, since the retail brand name is not proof of origin.
  • Request a written compliance statement from each hardware vendor confirming the chipset and sensor origin.
  • Flag any confirmed covered equipment for replacement before it becomes a component of a federal contract or grant funded system.
  • Keep the compliance statements on file, since a contracting officer or grant administrator can request them during a review.

Where Software Fits Into an NDAA Compliance Plan

Software that runs on cameras an operator already owns, and that are already compliant with Section 889, does not introduce new covered hardware into the security estate.

An operations platform that layers on top of existing compliant cameras, rather than replacing them with new hardware, keeps the compliance boundary where it already sits, at the camera and sensor level, not at the software layer running on top of it. Utility operators and other regulated buyers evaluating a security upgrade tend to look at this distinction closely before signing anything. The same review applies to port operators weighing new camera hardware against software that runs on what they already have installed.

Frequently Asked Questions

What is NDAA compliance and where does it come from?

NDAA compliance refers to Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019, which restricts federal purchase and use of certain named manufacturers’ telecommunications and video surveillance equipment. It applies through FAR clauses written into applicable federal contracts.

Does NDAA compliance apply to state and local government purchases?

Section 889 binds federal agencies and their contractors directly. State and local agencies are pulled in indirectly when federal grant funding carries the same restriction into the funded purchase, so a grant funded buyer should treat the equipment list as if Section 889 applied directly.

Can a camera be NDAA compliant if it carries a different brand name than the restricted manufacturers?

A different brand name is not proof of compliance by itself. OEM and private label arrangements mean a restricted chipset or sensor can sit inside hardware sold under an unrelated name, so the origin of the components needs to be verified directly with the manufacturer.

Does installing new security software introduce NDAA compliance risk on cameras I already own?

Not by itself. Software installed on hardware you already own, and that hardware is already compliant, does not introduce new covered equipment into your security estate. The compliance boundary set by Section 889 sits at the camera and sensor level, not at the software layer running on top of it.

What should I do if I find a restricted camera already installed on a federal contract site?

Flag it, obtain a written compliance statement from the vendor or plan for replacement, and follow the contracting officer’s guidance for that specific contract. Waiting until an audit surfaces the issue removes the ability to manage the timeline on your own terms.

Argu’s vision agent software installs on top of the cameras an operator already has in place, rather than requiring new camera hardware, so an NDAA compliance review can stay focused on the existing camera and sensor inventory rather than expanding to include Argu itself as new equipment. Homeland security and utility teams planning a security upgrade often start there. If your team needs a second set of eyes on an NDAA compliance review, talk to Argu about your camera inventory.

Last updated: September 2026

Sharing the post:

Monitor & Secure your perimeter today!

Schedule a demo to see the AI agent run on your own footage.

Get a Custom Demo

See how the agent performs on your specific environment.

Join world-class security teams

By submitting this form, you agree to our Privacy Policy. Your data is encrypted.

Seamless Integration With

Related Posts

Critical Infrastructure Security: Definition and Scope

Critical infrastructure security protects power, water, ports, and communications systems designated vital by CISA....

Video Redaction: What It Is and Why It Is Required

Video redaction blurs or masks identifiable people and plates before footage is shared, often a...

False Alarm Rate: Why It Matters More Than Detection

False alarm rate is the share of security alerts that are not real events. See...

Occupancy Analytics: What It Measures and Why

Occupancy analytics counts people in a space or zone in real time using existing cameras,...

What Is ANPR? Automatic Number Plate Recognition

ANPR reads vehicle license plates from live video in real time. See how it works,...

Best AI Video Analytics Companies in 2026

Ten AI video analytics and video surveillance companies compared on sourced facts: founding, HQ, core...