Uniqcli Security

Section 889 Rip-and-Replace: Removing Banned Cameras

Section 889 rip-and-replace guide for federal buyers: how to identify and remove banned Hikvision/Dahua cameras and replace them with NDAA/TAA-compliant syste

Yes — covered cameras already installed in a federal facility must be ripped out and replaced, not just left in place. Section 889 prohibits federal agencies and their contractors from using equipment from Hikvision, Dahua, Huawei, ZTE, and Hytera (and their affiliates and rebrands), so simply halting new purchases does not satisfy the rule. Any covered device still operating has to be removed and swapped for an NDAA-compliant alternative.

This guide explains how to scope a rip-and-replace, which brands and rebrands are covered, the difference between NDAA and TAA in a removal project, and what compliant lines to standardize on.

What "rip-and-replace" actually means under Section 889

Section 889(a)(1)(B) of the 2019 NDAA — implemented through FAR 52.204-25 — bars federal agencies and their contractors from using covered equipment, not just from buying it new. That "use" prohibition is what forces removal. It is not enough to stop purchasing Hikvision or Dahua; any covered camera, recorder, or radio already operating in a federal facility (or in a contractor's own systems supporting federal work) must be identified and physically taken out of service. Leaving covered gear connected — even on a separate VLAN — does not cure a use violation.

The covered entities are statutory: Hikvision, Dahua, Huawei, ZTE, and Hytera, including their subsidiaries, affiliates, and OEM rebrands. The rebrand point is what trips up most inventories. Chinese-origin or rebranded lines such as Uniview (UNV), Lorex, EZVIZ, Annke, LTS, Alibi, LaView, W Box, ICRealtime, Q-See, Reolink, and TP-Link Tapo can carry covered hardware and SoCs under a different label and are not acceptable for federal use. A camera that looks fine on its faceplate can still be covered at the bill-of-materials level, so each model must be verified.

How to scope the removal

Start with a full asset inventory by make, model, and firmware — including devices behind an NVR that the network discovery tool may not surface individually. For each device, confirm two things: the manufacturer is not a covered entity, and the unit does not contain covered components (for example, Huawei/HiSilicon SoCs). Because compliance is determined per-SKU and per bill-of-materials, a single brand can ship both compliant and non-compliant models, so document the specific model and BOM rather than ruling on the brand alone. Anything that fails either test goes on the replace list; everything else can stay, subject to TAA review when a covered federal-acquisition contract applies.

Keep in mind that TAA (Trade Agreements Act) is a separate test from NDAA. A camera can be free of covered entities yet still fail TAA because it was assembled in a non-designated country (China, Russia, and India are not TAA-designated). For covered contracts, both tests have to pass, and each is evaluated against the specific model.

What to replace covered cameras with

Removal is also the moment to standardize on a clean, compliant fleet. Established compliant lines come from Axis Communications (Sweden), Hanwha Vision / Wisenet (South Korea, with US-assembled lines), i-PRO (Japan/US), Bosch (Germany), Avigilon and Pelco (Motorola Solutions), Digital Watchdog, Speco Technologies, and VIVOTEK and ACTi (Taiwan), among others. None are 889 covered entities, and all offer compliant lines — though TAA status still depends on the specific model's manufacturing origin. On the management side, Genetec, Milestone (XProtect), exacqVision, and Salient Systems provide compliant VMS platforms, and access control commonly standardizes on HID Global, Mercury Security, LenelS2 (OnGuard), Software House (C-CURE 9000), or Brivo. The right line depends on the mission, the existing infrastructure, and whether TAA applies, and Uniqcli sources the correct compliant line per site rather than defaulting to a single brand.

A note on edge cases: Ubiquiti is US-based and is not a 889 covered party, but its UniFi Protect line is a prosumer/IT product, not a federal-grade, NDAA-marketed surveillance line — verify the specific model rather than treating it as a default compliant choice.

Documenting the replacement for audit

A rip-and-replace project is only complete when the paperwork supports it. Contracting and audit teams will want a before/after asset register, certificates of NDAA 889 and TAA posture for every new device, disposal records for the removed gear, and an attestation that no covered equipment remains in use. Building that documentation as you go — not after the fact — is what keeps the agency clean against FAR 52.204-25 representations.

Uniqcli is a direct, NDAA Section 889- and TAA-compliant integrator. We assess the existing fleet, identify covered and rebranded devices, design the compliant replacement system end to end, sell direct, and hand over the documentation your contracting and audit teams need. To plan a removal, request a quote or schedule a compliance assessment at /get-a-quote — no payment up front.

Frequently asked questions

Does Section 889 require removing cameras that are already installed, or only block new purchases?

Both. Section 889(a)(1)(B) prohibits the use of covered equipment, which means covered cameras already installed in a federal facility — or in a contractor's systems supporting federal work — must be removed, not just left disconnected. Halting new purchases addresses procurement but does not cure an ongoing use violation.

How do I know if my existing cameras are covered under Section 889?

Inventory every device by make, model, and firmware, then check two things: the manufacturer is not a covered entity (Hikvision, Dahua, Huawei, ZTE, Hytera, or their affiliates and rebrands), and the unit contains no covered components such as Huawei/HiSilicon SoCs. Compliance is verified per-SKU, so watch for rebranded lines like Uniview, Lorex, EZVIZ, Annke, LTS, and others that may carry covered hardware under a different label. Uniqcli verifies status per device during an assessment.

Can I just move covered cameras to a separate network instead of replacing them?

No. Network segmentation, air-gapping, or VLAN isolation does not satisfy Section 889, which prohibits the use of covered equipment regardless of how it is connected. The device must be physically removed from service to be compliant.

What should I replace covered cameras with?

Standardize on established NDAA-compliant lines such as Axis, Hanwha Vision (Wisenet), i-PRO, Bosch, Avigilon, Pelco, Digital Watchdog, Speco, or VIVOTEK, managed by a compliant VMS like Genetec or Milestone. The right line depends on the mission and whether TAA applies, since TAA status varies by the specific model's manufacturing origin. Uniqcli is vendor-neutral, sells direct, and sources the correct compliant line per site.

Do I need to satisfy TAA as well as NDAA when replacing cameras?

If the replacement is procured under a covered federal-acquisition contract, yes — TAA is a separate country-of-origin test from NDAA. A camera can be free of covered entities yet still fail TAA if it was assembled in a non-designated country such as China, Russia, or India. Both tests have to pass for covered contracts, and Uniqcli confirms each device against both, then sells the compliant system direct.

Ready when you are

Need it sourced compliant and direct?

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.