Uniqcli Security

NDAA vs TAA Compliance for Security Cameras: What's the Difference?

NDAA vs TAA compliance for security cameras explained: NDAA Section 889 bans covered vendors; TAA is a country-of-origin rule. Both must be verified per model

NDAA and TAA are two separate federal compliance rules, and most government camera purchases must satisfy both. NDAA Section 889 (via FAR 52.204-25) is an ownership and security rule that bars equipment from five covered entities — Hikvision, Dahua, Huawei, ZTE, and Hytera — along with their affiliates and rebrands. TAA (the Trade Agreements Act) is a separate country-of-origin rule requiring manufacture in the US or a TAA-designated country.

The key difference: NDAA cares who made the device and what is inside it, while TAA cares where it was made. A product can pass one rule and fail the other, so both must be verified for the exact model on your order.

NDAA Section 889 and TAA are different laws

NDAA Section 889 (from the 2019 National Defense Authorization Act, implemented through FAR 52.204-25) is a security and ownership rule. It prohibits federal agencies, and the contractors that support them, from procuring or using covered telecommunications and video-surveillance equipment made by five named entities — Hikvision, Dahua, Huawei, ZTE, and Hytera — along with their subsidiaries, affiliates, and OEM rebrands. The concern is who built the product and what is inside it, not where it was assembled.

A camera is "NDAA-compliant" when it is not made by a covered entity and does not contain covered components, such as a Huawei/HiSilicon system-on-chip. Because a single manufacturer can ship both compliant and non-compliant models, Section 889 status is determined per SKU and per bill of materials — the specific model must be verified, not just the brand.

TAA is a country-of-origin rule

TAA (the Trade Agreements Act, 19 U.S.C. 2501) governs where a product is made. For TAA-covered federal contracts, an item must be manufactured or "substantially transformed" in the United States or in a TAA-designated country. Many allied nations qualify, but several major manufacturing countries — including China, Russia, and India — are not designated. TAA compliance is established per model, based on the country of final manufacture or substantial transformation.

Why a product can pass one and fail the other

The two rules are independent, which is where buyers get caught:

Most federal procurements require both: Section 889 keeps covered entities out of the supply chain, and TAA satisfies the trade-origin requirement on the contract. Treat them as two separate boxes that each must be checked for the exact model on the quote.

Brands that offer compliant lines

None of the leading professional brands are Section 889 covered entities, and each offers compliant lines: Axis Communications (Sweden), Bosch (Germany), Hanwha Vision/Wisenet (South Korea, with US-assembled lines), i-PRO (Japan/US), Avigilon and Pelco (Motorola Solutions, US/Canada), Genetec (Canada), Milestone XProtect (Denmark), Digital Watchdog and Speco (US), VIVOTEK and ACTi (Taiwan), MOBOTIX (Germany), and Verkada (US). On the access-control side, HID Global, Mercury Security, LenelS2, Software House (C-CURE 9000), and Brivo offer compliant platforms. NDAA status here is clean, but TAA still depends on the specific model's manufacturing origin — so the SKU must be confirmed against the destination contract.

By contrast, equipment from Hikvision, Dahua, Huawei, ZTE, and Hytera — and Chinese-origin or rebranded lines such as Uniview, Lorex, EZVIZ, Annke, LTS, and TP-Link Tapo — must not be purchased for federal use and, if already installed, may need to be removed and replaced. Ubiquiti is US-based and not a covered entity, but its UniFi Protect line is a prosumer/IT product rather than a federally marketed surveillance line, so it is not a default compliant choice and any model must be verified.

Get the documentation right the first time

Because both rules turn on the specific model, the safest path is to confirm Section 889 and TAA posture before the purchase order — and to keep the manufacturer attestations on file for contracting and audit teams. Uniqcli Security is a TAA- and NDAA Section 889-compliant integrator that designs, installs, and manages surveillance and access-control systems and sells direct. We are vendor-neutral, so we match the right compliant line to your mission and provide the origin and 889 documentation your reviewers will ask for. Request a quote or schedule a compliance assessment, and we will confirm both compliance dimensions on every line of your system.

Frequently asked questions

Is NDAA the same as TAA compliance?

No. NDAA Section 889 is a security and ownership rule that bans equipment from covered entities (Hikvision, Dahua, Huawei, ZTE, Hytera) and their affiliates and rebrands, implemented through FAR 52.204-25. TAA (the Trade Agreements Act) is a separate country-of-origin rule requiring manufacture or substantial transformation in the US or a TAA-designated country. They are different laws, and many federal contracts require both.

Can a camera be NDAA-compliant but not TAA-compliant?

Yes. A camera from a non-covered brand can satisfy Section 889 yet still fail TAA if its specific model is assembled in a country that is not TAA-designated — China, Russia, and India are not designated. The reverse can also happen. Because the two rules are independent, the exact model must be checked against both.

Does an NDAA-compliant brand mean every model is TAA-compliant?

No. Brands like Axis, Bosch, Hanwha, i-PRO, Avigilon, Genetec, and Milestone are not covered entities and offer compliant lines, but TAA status depends on where each individual model is manufactured. Compliance is confirmed per SKU and per bill of materials, not by brand name alone.

Which camera brands are banned under NDAA Section 889?

Equipment from Hikvision, Dahua, Huawei, ZTE, and Hytera — plus their subsidiaries, affiliates, and OEM rebrands — is prohibited for federal use. Chinese-origin or rebranded lines such as Uniview, Lorex, EZVIZ, Annke, LTS, and TP-Link Tapo are also not federally acceptable and should not be purchased for government projects.

How do I prove a camera is both NDAA and TAA compliant?

Obtain manufacturer attestations for the specific model: a Section 889 statement confirming it is not a covered product or component, and a TAA country-of-origin declaration. Uniqcli Security verifies both for each line of a system and provides the documentation contracting and audit teams require.

Ready when you are

Need it sourced compliant and direct?

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.