The short answer
NDAA Section 889 bars federal agencies from procuring video surveillance and telecommunications equipment produced by Huawei, ZTE, Hytera, Hikvision, Dahua and their affiliates, and bars agencies from contracting with entities that use that equipment anywhere in their operations. 2 CFR 200.216 applies the same prohibition to federal grant and loan funds, which is how it reaches HUD-assisted housing and other federally funded California projects. An NDAA compliant camera is one whose actual manufacturer, not the brand on the label, is outside the covered list, confirmed by a written manufacturer statement that names the model numbers.
| Statute | NDAA FY2019 Section 889 (Pub. L. 115-232) |
|---|---|
| Grants and loans | 2 CFR 200.216, Uniform Guidance |
| Covered makers | Huawei, ZTE, Hytera, Hikvision, Dahua and affiliates |
| FCC action | New equipment authorizations barred, Nov 2022 |
| Commonly specified | Axis, Hanwha Vision, Avigilon, Meraki MV, UniFi |
| License | CSLB #472017, C-7 Low Voltage Systems |
What Section 889 prohibits, and the two parts that matter#
Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Public Law 115-232) is the federal rule behind nearly every “NDAA compliant” line item you see in a camera spec. It has two operative parts.
Part A, effective August 13, 2019, bars federal agencies from procuring or obtaining telecommunications and video surveillance equipment or services from the covered companies, or any system that uses that equipment as a substantial or essential component or as critical technology.
Part B, effective August 13, 2020, bars federal agencies from entering into, extending or renewing a contract with any entity that uses covered equipment or services, whether or not that equipment has anything to do with the federal contract. This is the part that reaches a company’s own facilities, not only the products it sells to the government. A contractor with Hikvision cameras on its warehouse is, on its face, an entity that uses covered equipment.
Both parts are implemented in the Federal Acquisition Regulation (FAR 52.204-24, 52.204-25 and 52.204-26), which is where the representations, the reasonable inquiry standard and the reporting obligations live. The statute covers telecommunications equipment and video surveillance equipment, so cameras, recorders, video management servers and the network gear that carries them are all in scope.
Who has to comply in California#
Section 889 is federal law, but it reaches a large share of California commercial and institutional construction because federal money moves through it.
| Buyer | How Section 889 reaches them | What it means for the camera spec |
|---|---|---|
| Federal agencies and federal buildings | Part A directly | Covered equipment cannot be purchased or installed |
| Federal prime and subcontractors | Part B, via FAR 52.204-25 | The company itself must not use covered equipment at any site |
| Recipients of federal grants and loans | 2 CFR 200.216 | Grant or loan funds cannot pay for covered equipment or systems that use it |
| Public housing authorities and HUD-assisted owners | 2 CFR 200.216 through HUD program funds | Cameras bought with those funds must be compliant; owners commonly apply it property-wide |
| LIHTC rehabs with federal gap funding | 2 CFR 200.216 where HOME, CDBG or similar funds are in the stack | Compliance follows the funding source, so check the capital stack |
| Cities, counties, school districts, transit and water agencies | 2 CFR 200.216 on federally funded projects; many adopt it as policy | Increasingly written into the agency standard for all sites |
| Private owners with no federal money | Not required by statute | Often specified anyway to preserve federal eligibility and for cybersecurity reasons |
The regulation that extends the prohibition to grants and loans is 2 CFR 200.216, part of the Uniform Guidance that governs federal financial assistance. It was added in 2020 and states that recipients and subrecipients may not obligate or expend loan or grant funds to procure or obtain covered telecommunications or video surveillance equipment or services, or to extend or renew contracts for them. This is how the rule reaches HUD-funded housing: a public housing authority or a rehab funded in part with HUD grant programs is a recipient or subrecipient, and the cameras are an expenditure. Our multifamily and affordable housing page describes how we handle this on occupied rehabs, and our government and public works page covers agency work.
The covered manufacturers and the FCC Covered List#
The statute names five companies and their subsidiaries and affiliates:
- Huawei Technologies Company
- ZTE Corporation
- Hytera Communications Corporation
- Hangzhou Hikvision Digital Technology Company
- Dahua Technology Company
For cameras, the two that matter are Hikvision and Dahua, which supply cameras and recorders to many other brands under OEM agreements, so the equipment is often sold under other names.
A separate federal action reinforces the list. The Federal Communications Commission maintains a Covered List under the Secure and Trusted Communications Networks Act of 2019. Huawei, ZTE, Hytera, Hikvision and Dahua were placed on that list in March 2021, and other entities (including Kaspersky and several Chinese telecommunications carriers) have been added since. In an order adopted in November 2022, the FCC barred new equipment authorizations for equipment produced by the Covered List companies, which means new Hikvision and Dahua camera models cannot receive the FCC authorization required to be legally imported and marketed in the United States. Equipment authorized before that order was not revoked by it, and the FCC has continued rulemaking since on modular components and on the treatment of previously authorized equipment. The practical effect for a California buyer is that the covered manufacturers are restricted on both the procurement side (Section 889 and 2 CFR 200.216) and the import side (FCC equipment authorization).
The white-label problem: how covered cameras reach your submittal#
The hard part of NDAA compliance is not avoiding a box that says Hikvision. It is that Hikvision and Dahua have supplied cameras and recorders as original equipment manufacturers to dozens of brands that sell under their own names. A submittal can show a brand you have never heard of, a distributor house brand, or a brand with an American address, and the camera inside can be a covered product with a different label and a reskinned firmware.
The statute covers equipment produced by the named companies and their subsidiaries and affiliates. A relabeled Hikvision camera is produced by Hikvision. The brand on the box does not change that, and a distributor’s assurance that “it is our brand, not Hikvision” does not survive a compliance review or a discovery request.
Warning signs on a submittal include: a brand with no published manufacturing information, a spec sheet whose layout and part numbering match a Hikvision or Dahua data sheet, a web interface that matches the covered maker’s, and pricing well below the compliant brands. The fix is the one the rest of this article covers: specify by actual manufacturer, require the manufacturer’s attestation, and verify the model.
How to specify NDAA compliant cameras in Division 28#
The spec section should do four things.
Name the requirement. State that all video surveillance equipment, including cameras, recorders, video management software and associated network components, shall comply with Section 889 of the FY2019 NDAA and, where applicable, 2 CFR 200.216, and shall not be produced by Huawei, ZTE, Hytera, Hikvision, Dahua, or any subsidiary or affiliate, including equipment manufactured by those companies and sold under another brand.
Name the basis of design and acceptable manufacturers. Commonly specified NDAA compliant camera lines include Axis, Hanwha Vision, Avigilon, Cisco Meraki MV and Ubiquiti UniFi Protect. Each publishes an NDAA statement, and each should be verified per model, because product lines change. We install and configure Meraki MV and install the others to spec.
Require documentation as a submittal condition. The spec should say that no camera product will be approved without a manufacturer’s written NDAA compliance statement covering the specific model numbers, and that substitutions must carry the same documentation.
Address the whole system. A compliant camera on a non-compliant recorder is a non-compliant system. Include recorders, NVR and VMS servers, PoE switches used for the camera network, and any cellular or wireless bridge, since the statute’s “substantial or essential component” language reaches all of them. Our security camera systems page explains how we build the system end to end, and the Division 27 and 28 spec checklist covers the rest of the section.
How to document compliance#
Documentation is what an auditor, a HUD monitor or a GC compliance desk will actually ask for, usually a year after the project closed. We build the file during submittal and deliver it at closeout.
| Document | Source | What it should contain |
|---|---|---|
| Manufacturer NDAA compliance statement | Camera, recorder and VMS manufacturer | Statement referencing Section 889, listing model numbers or product families, on letterhead |
| Model verification | Installer, from manufacturer data | Cross-reference of every model on the submittal to the manufacturer statement |
| Ownership note | Manufacturer or public record | Confirms the manufacturer is not a subsidiary or affiliate of a covered company |
| Installer certification | Telelink | Statement that installed equipment matches the approved submittal with no substitutions |
| Closeout equipment schedule | Telelink | Camera by camera list with make, model, serial number, location and firmware version |
| FCC ID (where relevant) | Device label or manufacturer | Supports the import-side check on newer equipment |
Submittal language that works in practice: “Contractor certifies that all video surveillance equipment furnished under this section, including cameras, recording appliances, video management software and network switches dedicated to the surveillance network, complies with Section 889 of the National Defense Authorization Act for Fiscal Year 2019 and 2 CFR 200.216, and is not produced by Huawei Technologies Company, ZTE Corporation, Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, Dahua Technology Company, or any subsidiary or affiliate thereof, including products manufactured by those entities and sold under other brand names. Manufacturer compliance statements for each model are attached.”
What to do with existing non-compliant cameras#
Occupied buildings frequently have some covered equipment already installed. There are three practical paths.
Replace the system. Where federal funds are in the project, this is the cleanest answer and it is often required, since grant funds also cannot be used to extend or renew contracts for covered equipment or services. Existing coax or Cat5e pathways can often be reused, which keeps cost down.
Replace in phases. Where the owner has no current federal contract obligation but wants to preserve eligibility, replace the recorder and the exterior and entry cameras first, then interior cameras as budget allows. Document the phasing plan so a future compliance review has a dated replacement schedule on file.
Isolate and disclose. Where a federal contractor cannot replace immediately, network isolation (a separate VLAN with no internet access) reduces cybersecurity risk but does not cure the Section 889 problem. Part B requires a representation and, if covered equipment is found, a report to the contracting officer. A waiver process exists but is narrow. This path is a question for the owner’s counsel, not an installation question.
In every case we survey, photograph and record the make and model of every existing camera and recorder before quoting replacement, because the label often does not name the manufacturer. On an occupied building, the replacement is phased the same way as any other low voltage rehab work, which our occupied buildings guide covers.
NDAA compliance checklist for owners and general contractors#
- Identify whether federal funds, federal contracts or federal grant pass-throughs touch the project or the owner
- Write Section 889 and 2 CFR 200.216 into Division 28, naming the five covered companies, their affiliates and OEM products
- Name compliant basis of design manufacturers and require per-model manufacturer statements
- Extend the requirement to recorders, VMS, camera network switches and wireless bridges
- Reject submittals without manufacturer documentation; do not accept distributor or brand assurances alone
- Survey existing cameras and recorders and record actual manufacturer, not label
- Require a closeout equipment schedule with serial numbers and firmware versions
- Keep the compliance file with the project record for the life of the system
Next step#
Send us the camera schedule and the funding sources on the project and we will return a compliant basis of design, a submittal package with manufacturer statements, and a survey of any existing equipment that needs to come out. Start at request a bid. GCs can find our Division 28 submittal process on the for general contractors page.
This article is general information for planning and specification, not a bid, engineering advice or legal advice. Codes and standards change; confirm the current edition with the authority having jurisdiction. Scope and price for a specific building come only in a written proposal.