Yes — covered cameras already installed in a federal facility must be ripped out and replaced, not just left in place. Section 889 prohibits federal agencies and their contractors from using equipment from Hikvision, Dahua, Huawei, ZTE, and Hytera (and their affiliates and rebrands), so simply halting new purchases does not satisfy the rule. Any covered device still operating has to be removed and swapped for an NDAA-compliant alternative.
This guide explains how to scope a rip-and-replace, which brands and rebrands are covered, the difference between NDAA and TAA in a removal project, and what compliant lines to standardize on.
What "rip-and-replace" actually means under Section 889
Section 889(a)(1)(B) of the 2019 NDAA — implemented through FAR 52.204-25 — bars federal agencies and their contractors from using covered equipment, not just from buying it new. That "use" prohibition is what forces removal. It is not enough to stop purchasing Hikvision or Dahua; any covered camera, recorder, or radio already operating in a federal facility (or in a contractor's own systems supporting federal work) must be identified and physically taken out of service. Leaving covered gear connected — even on a separate VLAN — does not cure a use violation.
The covered entities are statutory: Hikvision, Dahua, Huawei, ZTE, and Hytera, including their subsidiaries, affiliates, and OEM rebrands. The rebrand point is what trips up most inventories. Chinese-origin or rebranded lines such as Uniview (UNV), Lorex, EZVIZ, Annke, LTS, Alibi, LaView, W Box, ICRealtime, Q-See, Reolink, and TP-Link Tapo can carry covered hardware and SoCs under a different label and are not acceptable for federal use. A camera that looks fine on its faceplate can still be covered at the bill-of-materials level, so each model must be verified.
How to scope the removal
Start with a full asset inventory by make, model, and firmware — including devices behind an NVR that the network discovery tool may not surface individually. For each device, confirm two things: the manufacturer is not a covered entity, and the unit does not contain covered components (for example, Huawei/HiSilicon SoCs). Because compliance is determined per-SKU and per bill-of-materials, a single brand can ship both compliant and non-compliant models, so document the specific model and BOM rather than ruling on the brand alone. Anything that fails either test goes on the replace list; everything else can stay, subject to TAA review when a covered federal-acquisition contract applies.
Keep in mind that TAA (Trade Agreements Act) is a separate test from NDAA. A camera can be free of covered entities yet still fail TAA because it was assembled in a non-designated country (China, Russia, and India are not TAA-designated). For covered contracts, both tests have to pass, and each is evaluated against the specific model.
What to replace covered cameras with
Removal is also the moment to standardize on a clean, compliant fleet. Established compliant lines come from Axis Communications (Sweden), Hanwha Vision / Wisenet (South Korea, with US-assembled lines), i-PRO (Japan/US), Bosch (Germany), Avigilon and Pelco (Motorola Solutions), Digital Watchdog, Speco Technologies, and VIVOTEK and ACTi (Taiwan), among others. None are 889 covered entities, and all offer compliant lines — though TAA status still depends on the specific model's manufacturing origin. On the management side, Genetec, Milestone (XProtect), exacqVision, and Salient Systems provide compliant VMS platforms, and access control commonly standardizes on HID Global, Mercury Security, LenelS2 (OnGuard), Software House (C-CURE 9000), or Brivo. The right line depends on the mission, the existing infrastructure, and whether TAA applies, and Uniqcli sources the correct compliant line per site rather than defaulting to a single brand.
A note on edge cases: Ubiquiti is US-based and is not a 889 covered party, but its UniFi Protect line is a prosumer/IT product, not a federal-grade, NDAA-marketed surveillance line — verify the specific model rather than treating it as a default compliant choice.
Documenting the replacement for audit
A rip-and-replace project is only complete when the paperwork supports it. Contracting and audit teams will want a before/after asset register, certificates of NDAA 889 and TAA posture for every new device, disposal records for the removed gear, and an attestation that no covered equipment remains in use. Building that documentation as you go — not after the fact — is what keeps the agency clean against FAR 52.204-25 representations.
Uniqcli is a direct, NDAA Section 889- and TAA-compliant integrator. We assess the existing fleet, identify covered and rebranded devices, design the compliant replacement system end to end, sell direct, and hand over the documentation your contracting and audit teams need. To plan a removal, request a quote or schedule a compliance assessment at /get-a-quote — no payment up front.