No — eufy is not an appropriate camera line for a federal, SLED, or any Section 889-sensitive facility. eufy is a consumer smart-home brand owned by Anker Innovations, a Chinese consumer-electronics company (publicly listed on the Shenzhen Stock Exchange). It is not one of the five entities named in NDAA Section 889 (Hikvision, Dahua, Huawei, ZTE, Hytera), so it is not "banned by name" the way those brands are — but that narrow fact tells you almost nothing about whether it belongs on a government contract. eufy also has a well-documented, publicly reported history of cloud and encryption problems that a federal buyer cannot wave away.
Below is what actually governs the purchase decision — country of origin, per-SKU documentation, and the vendor's own track record — plus where to buy compliant cameras direct instead.
The short answer, expanded
NDAA Section 889 — enacted in the 2019 National Defense Authorization Act and implemented through FAR 52.204-25 — prohibits federal agencies and their contractors from procuring or using covered telecommunications and video-surveillance equipment from five named entities: Hikvision, Dahua, Huawei, ZTE, and Hytera, along with their affiliates and OEM rebrands. eufy is not on that list, so it is not "banned by name" the way Hikvision or Dahua is.
That is the extent of the good news, and it is not enough to clear a real procurement. eufy is the smart-home camera and security brand of Anker Innovations, a Chinese consumer-electronics company (publicly listed on the Shenzhen Stock Exchange). Two separate rules govern whether a camera can go on a federal contract, and eufy falls short on both:
- NDAA Section 889 (per-SKU verification): Even brands outside the five named entities must be verified so they don't embed covered components — a Huawei/HiSilicon chipset, for example — somewhere in the bill of materials. Compliance under 889 is established per SKU with manufacturer documentation, not by brand reputation or absence from a list. eufy does not market or document its consumer camera line as NDAA-verified for federal use.
- TAA (Trade Agreements Act, 19 U.S.C. 2501): TAA is a country-of-origin rule that governs GSA and much federal acquisition. A product must be made or substantially transformed in the US or a TAA-designated country, and China is not on that list. As a China-based brand, eufy does not clear this test, which independently disqualifies it from most federal and many SLED procurements regardless of the NDAA question.
eufy's documented cloud and encryption history
Beyond the country-of-origin issue, eufy carries a publicly reported track record any federal, healthcare, or critical-infrastructure buyer should weigh. In late 2022, independent security researchers demonstrated that eufy camera and doorbell streams — marketed as stored locally and end-to-end encrypted — could be pulled and viewed unencrypted using standard open-source tools. Researchers also reported that facial-recognition thumbnails and user data were being uploaded to a cloud server (reported to be AWS) without encryption, contradicting the brand's "local only" claims.
Anker publicly acknowledged the gap in February 2023, conceded its cameras had not been end-to-end encrypted, and said it had corrected the issues raised and engaged third-party auditors. We're stating what was reported and acknowledged, not speculating about current practices — but for a government or regulated-industry buyer, a documented history of a vendor's marketing claims not matching its actual data handling is itself a compliance-relevant fact. Procurement should never rest on a manufacturer's own privacy claims; it should rest on independently verifiable documentation, and that standard applies to every vendor we recommend, not just the ones with a public incident on record.
Why a consumer smart-home brand isn't a federal system
Separate from the origin and privacy questions, eufy is built and sold as a consumer smart-home product: app-controlled cameras and doorbells aimed at residential buyers. A federal, SLED, healthcare, or critical-infrastructure deployment is a different category of purchase. It requires a documented supply chain, enterprise VMS integration, cybersecurity hardening standards, and a manufacturer willing to sign compliance attestations that go in the contract file. Consumer smart-home brands — eufy included — are not engineered or supported for that environment.
What to buy instead
Several manufacturers build genuinely compliant, federal-grade lines, none of them a Section 889 covered entity, each with documented TAA-eligible models:
- Axis Communications (Sweden) and Bosch (Germany) for established enterprise IP camera lines.
- Hanwha Vision / Wisenet (South Korea, with US-assembled lines) and i-PRO (Japan/US) for broad mission coverage.
- Avigilon and Pelco (Motorola Solutions), plus Digital Watchdog (US), for integrated camera-and-recorder deployments.
- Genetec and Milestone XProtect for the video management layer.
- VIVOTEK (Taiwan), Speco Technologies (US), and MOBOTIX (Germany) for specialized and edge use cases.
Compliance is verified per SKU and per bill of materials — a manufacturer can offer both compliant and non-compliant models, and NDAA status is not the same as TAA status. Confirm the specific model and its documented origin before it goes on a contract.
Get it specified compliant and direct
Uniqcli Security is a TAA and NDAA Section 889-compliant physical-security integrator. We design, install, and support camera, access-control, intrusion, and monitoring systems for federal agencies, the Army, Navy, Air Force, Marines and broader DoD, SLED, healthcare and VA, and critical infrastructure — and we sell direct, through the Government Purchase Card, Simplified Acquisition (FAR Part 13), and open-market purchase orders, with WAWF/PIEE invoicing for DoD. We're vendor-neutral, so we match the right compliant line to your mission and hand your contracting and audit teams the SKU-level documentation they need. If eufy or another consumer camera is already installed at a sensitive site, request a quote and we'll map a compliant replacement path.