Uniqcli Security

Is eufy (Anker) NDAA Compliant?

Is eufy NDAA compliant? No. eufy is a China-based Anker consumer brand with a documented cloud-privacy history — not a fit for federal or SLED sites.

No — eufy is not an appropriate camera line for a federal, SLED, or any Section 889-sensitive facility. eufy is a consumer smart-home brand owned by Anker Innovations, a Chinese consumer-electronics company (publicly listed on the Shenzhen Stock Exchange). It is not one of the five entities named in NDAA Section 889 (Hikvision, Dahua, Huawei, ZTE, Hytera), so it is not "banned by name" the way those brands are — but that narrow fact tells you almost nothing about whether it belongs on a government contract. eufy also has a well-documented, publicly reported history of cloud and encryption problems that a federal buyer cannot wave away.

Below is what actually governs the purchase decision — country of origin, per-SKU documentation, and the vendor's own track record — plus where to buy compliant cameras direct instead.

The short answer, expanded

NDAA Section 889 — enacted in the 2019 National Defense Authorization Act and implemented through FAR 52.204-25 — prohibits federal agencies and their contractors from procuring or using covered telecommunications and video-surveillance equipment from five named entities: Hikvision, Dahua, Huawei, ZTE, and Hytera, along with their affiliates and OEM rebrands. eufy is not on that list, so it is not "banned by name" the way Hikvision or Dahua is.

That is the extent of the good news, and it is not enough to clear a real procurement. eufy is the smart-home camera and security brand of Anker Innovations, a Chinese consumer-electronics company (publicly listed on the Shenzhen Stock Exchange). Two separate rules govern whether a camera can go on a federal contract, and eufy falls short on both:

eufy's documented cloud and encryption history

Beyond the country-of-origin issue, eufy carries a publicly reported track record any federal, healthcare, or critical-infrastructure buyer should weigh. In late 2022, independent security researchers demonstrated that eufy camera and doorbell streams — marketed as stored locally and end-to-end encrypted — could be pulled and viewed unencrypted using standard open-source tools. Researchers also reported that facial-recognition thumbnails and user data were being uploaded to a cloud server (reported to be AWS) without encryption, contradicting the brand's "local only" claims.

Anker publicly acknowledged the gap in February 2023, conceded its cameras had not been end-to-end encrypted, and said it had corrected the issues raised and engaged third-party auditors. We're stating what was reported and acknowledged, not speculating about current practices — but for a government or regulated-industry buyer, a documented history of a vendor's marketing claims not matching its actual data handling is itself a compliance-relevant fact. Procurement should never rest on a manufacturer's own privacy claims; it should rest on independently verifiable documentation, and that standard applies to every vendor we recommend, not just the ones with a public incident on record.

Why a consumer smart-home brand isn't a federal system

Separate from the origin and privacy questions, eufy is built and sold as a consumer smart-home product: app-controlled cameras and doorbells aimed at residential buyers. A federal, SLED, healthcare, or critical-infrastructure deployment is a different category of purchase. It requires a documented supply chain, enterprise VMS integration, cybersecurity hardening standards, and a manufacturer willing to sign compliance attestations that go in the contract file. Consumer smart-home brands — eufy included — are not engineered or supported for that environment.

What to buy instead

Several manufacturers build genuinely compliant, federal-grade lines, none of them a Section 889 covered entity, each with documented TAA-eligible models:

Compliance is verified per SKU and per bill of materials — a manufacturer can offer both compliant and non-compliant models, and NDAA status is not the same as TAA status. Confirm the specific model and its documented origin before it goes on a contract.

Get it specified compliant and direct

Uniqcli Security is a TAA and NDAA Section 889-compliant physical-security integrator. We design, install, and support camera, access-control, intrusion, and monitoring systems for federal agencies, the Army, Navy, Air Force, Marines and broader DoD, SLED, healthcare and VA, and critical infrastructure — and we sell direct, through the Government Purchase Card, Simplified Acquisition (FAR Part 13), and open-market purchase orders, with WAWF/PIEE invoicing for DoD. We're vendor-neutral, so we match the right compliant line to your mission and hand your contracting and audit teams the SKU-level documentation they need. If eufy or another consumer camera is already installed at a sensitive site, request a quote and we'll map a compliant replacement path.

Frequently asked questions

Is eufy banned under NDAA Section 889?

No. Section 889 names five covered entities by statute: Hikvision, Dahua, Huawei, ZTE, and Hytera (plus their affiliates and OEM rebrands). eufy/Anker is not one of them, so it is not banned by name. But absence from that list does not equal compliance — eufy is not marketed or documented as an NDAA-verified surveillance product, and it is a China-based consumer brand that most federal and SLED buyers will not accept for a security system.

Is eufy TAA-compliant?

No. TAA (the Trade Agreements Act) requires a product be made or substantially transformed in the US or a TAA-designated country, and China does not qualify. eufy is a brand of Anker Innovations, a China-based company, and its cameras are not manufactured or documented to meet TAA country-of-origin rules. That rules eufy out of GSA and most federal procurements independent of the NDAA question.

Didn't eufy have a security or privacy scandal?

Yes, and it's public record. In late 2022 and early 2023, security researchers demonstrated that eufy camera streams marketed as local-only and end-to-end encrypted could be viewed unencrypted, and reported that facial-recognition thumbnails were uploaded to a cloud server (reported to be AWS) without encryption. Anker publicly acknowledged the gap in February 2023 and said it had corrected the specific issues raised. For a federal or healthcare buyer, a documented history like that is itself a reason to require independent, verifiable compliance attestations rather than take a vendor's marketing claims at face value — regardless of brand.

Can we keep eufy cameras already installed at a government or SLED site?

Treat them the same as any other non-compliant consumer camera: evaluate for removal as part of a documented compliance posture, especially anywhere covered by Section 889, a TAA-flow-down clause, or an agency cybersecurity policy. Uniqcli can inventory an existing deployment, flag which devices fail NDAA or TAA, and design a compliant replacement without disrupting coverage.

What should we buy instead of eufy for a federal or commercial security system?

Choose a documented, TAA-eligible line from a manufacturer that isn't a Section 889 covered entity — Axis, Bosch, Hanwha Vision (Wisenet), i-PRO, Avigilon, Pelco, Digital Watchdog, VIVOTEK, Speco, or MOBOTIX are common federal-grade choices, paired with a compliant VMS such as Genetec or Milestone. Compliance is confirmed per SKU, so verify the specific model before it goes on a contract.

Ready when you are

Need it sourced compliant and direct?

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.