Wyze is not one of the five NDAA-named manufacturers, but its China-manufactured hardware and consumer-cloud architecture still fail federal Section 889 screening and have no place in a compliant government or critical-infrastructure deployment. Wyze markets itself as a Seattle-area startup, and it is headquartered in Washington state — but the cameras themselves are built through a Chinese manufacturing partnership, and the company has never published the country-of-origin documentation a contracting officer needs to clear a device for federal use. For any facility that has to pass a Section 889 review, that's a disqualifying gap, not a gray area.
Is Wyze NDAA Compliant?
Wyze isn't on the NDAA's named-brand ban list, but its China-manufactured, consumer-cloud design still fails federal Section 889 screening. Here's why.
The short answer
Wyze is not one of the five manufacturers Congress named in NDAA Section 889 — Hikvision, Dahua, Huawei, ZTE, and Hytera. So strictly speaking, Wyze isn't "banned" the way those brands are. But that's the wrong question for a federal buyer to ask. The real question is whether Wyze can pass the country-of-origin, supply-chain, and security-architecture screening that Section 889 was written to enforce — and on every count that matters to a contracting officer or facility security manager, it can't.
Wyze is headquartered in the Seattle area, in Washington state, and markets itself as an American company. Its hardware, per public reporting and manufacturing records, is produced in China through a manufacturing partnership (commonly cited as Tianjin Hualai Technology Co.). That split — US brand, Chinese factory floor, cloud-dependent firmware — is exactly the pattern federal security reviews are built to catch, whether or not the specific vendor shows up on the named-entity list.
Why "not on the list" isn't the same as "compliant"
Section 889 Part A bans five named Chinese manufacturers and their subsidiaries/affiliates by name. Part B goes further: it bars any "covered telecommunications equipment or services" used as a substantial or essential component of a system, or as critical technology, regardless of brand label. Agencies and primes are expected to run country-of-origin and component-level due diligence on every camera, not just check a brand name against a list.
Wyze has never published the kind of documentation a federal buyer needs to clear that bar — no formal NDAA 889 self-certification letter, no component-level bill of materials disclosure, no country-of-origin attestation suitable for a contract file. Without that paperwork, a contracting officer has no way to certify the device clean, and an auditor has no way to verify it later. That paperwork gap is disqualifying on its own, independent of whether Wyze ends up on a future named-entity list.
The consumer-cloud architecture problem
Even setting country of origin aside, Wyze cameras are built as consumer smart-home devices, not federal-grade security infrastructure. They depend on a consumer cloud backend for viewing, storage, and remote access rather than an on-premises VMS or NVR a facility fully controls. That model has a track record: Wyze has publicly acknowledged more than one incident where a caching or account-mapping failure let users briefly view other customers' camera feeds and thumbnails — not a targeted hack, but a basic failure of access segmentation in the cloud pipeline. For a home user, that's an embarrassing bug. For a facility protecting federal records, PII, or CUI, it's a data-handling failure that no compliance office can sign off on.
Federal buildings, SLED facilities, and healthcare sites also need role-based access control, audit logging, on-prem or FedRAMP-eligible storage options, and warranty/support backed by a company set up to sell to government — none of which is part of Wyze's product line or business model. Wyze sells through consumer retail and its own app store; it isn't structured for GPC, FAR Part 13, or WAWF invoicing, and it has no federal sales or compliance function to speak of.
What "rip and replace" looks like here
If Wyze cameras are already installed at a facility that's now subject to Section 889 — a new federal lease, a grant condition, a CMMC requirement flowing down from a prime — the fix is the same rip-and-replace process used for named-brand equipment: inventory every device down to the make and model, pull anything without a clean chain of custody, and re-cable to a compliant platform rather than trying to "patch" compliance onto consumer gear after the fact.
What actually clears the bar
TAA-compliant, NDAA-889-screened manufacturers — Axis, Bosch, Hanwha Vision, i-PRO, Pelco, Digital Watchdog, Speco, and similar lines — build to federal procurement standards from the start: documented country-of-origin, on-prem or hybrid VMS architecture, role-based access control, and long-cycle firmware support. These are the platforms that pass a compliance review the first time, not the ones you have to defend after the fact.
Uniqcli sells these compliant lines direct to federal, SLED, healthcare, and commercial buyers through the paths federal buyers actually use — Government Purchase Card, Simplified Acquisition under FAR Part 13, and open-market purchase orders with WAWF invoicing for DoD — with no reseller layer and a paper trail that holds up in an audit. If you've got Wyze or other consumer-grade cameras in a facility that now needs to pass Section 889 screening, request a documented quote and we'll scope the replacement.
Frequently asked questions
Is Wyze on the NDAA Section 889 banned list?
No. Section 889 names five manufacturers by brand — Hikvision, Dahua, Huawei, ZTE, and Hytera — and Wyze isn't one of them. But Part B of Section 889 also bars covered telecommunications equipment more broadly, and Wyze's undocumented China-based manufacturing and consumer-cloud architecture keep it from passing a federal compliance review regardless of the named-brand list.
Where are Wyze cameras actually made?
Wyze is headquartered in the Seattle area of Washington state, but per public reporting and manufacturing records, its camera hardware is produced in China through a manufacturing partnership commonly cited as Tianjin Hualai Technology Co. Wyze has not published the country-of-origin or component-level documentation a federal contract file typically requires.
Can Wyze cameras be installed in a federal or SLED building?
They shouldn't be, and most facility security offices will flag them during a Section 889 screening. Beyond the sourcing question, Wyze's consumer-cloud architecture and lack of federal-grade access controls make it unsuitable for facilities handling CUI, PII, or federal records, independent of the NDAA named-brand issue.
What should a facility do if Wyze cameras are already installed?
Treat it as a rip-and-replace project: inventory every camera by make and model, remove any device without a documented chain of custody, and re-cable to a TAA-compliant, NDAA-screened platform such as Axis, Bosch, Hanwha Vision, i-PRO, or Pelco.
Is Wyze TAA compliant?
No. TAA compliance requires the finished product be substantially transformed in the US or a designated country. Wyze's China-manufactured hardware doesn't meet that standard, and the company has not published TAA compliance documentation for federal buyers.
Need it sourced compliant and direct?
Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.
