Uniqcli Security

What Is NDAA Section 889? A Camera & Access-Control Buyer’s Guide

What NDAA Section 889 is, how it applies to cameras and access control, how it differs from TAA, and which compliant vendors federal buyers can specify.

NDAA Section 889 is a 2019 federal law that prohibits agencies, contractors, and grant recipients from buying or using "covered" telecommunications and video-surveillance equipment from five named entities — Hikvision, Dahua, Huawei, ZTE, and Hytera — along with their affiliates and OEM rebrands. It is implemented in federal contracts through FAR clause 52.204-25.

For camera and access-control buyers, the practical takeaway is this: a device is compliant only if it is not made by a covered entity and contains no covered components, and that has to be confirmed per model — not assumed from the brand name. This guide explains how Section 889 works, how it differs from TAA, and which vendors are safe to specify.

Section 889 in plain terms

Section 889 has two parts. Part A bars federal agencies from buying covered equipment. Part B — the one that affects contractors and grant recipients most — prohibits the government from contracting with any entity that uses covered equipment anywhere in its operations, even on commercial systems unrelated to the contract. For video surveillance and access control, that means a single covered camera on a network can jeopardize a contract.

The prohibition is implemented in the FAR through clause 52.204-25, which flows the restriction down through prime contracts and subcontracts. It is not optional, and there is no general waiver for routine commercial purchases.

What makes a camera or access-control system "non-compliant"

A device is covered (prohibited) if it is made by a covered entity — Hikvision, Dahua, Huawei, ZTE, or Hytera — including their subsidiaries, affiliates, and OEM rebrands. It is also covered if it contains covered components, such as a Huawei/HiSilicon system-on-chip, even when sold under a different brand name.

This is why compliance is decided per SKU, not per brand. A single manufacturer can ship both compliant and non-compliant lines, so the specific model and its bill of materials must be verified before purchase. Treating a brand as universally "safe" or "banned" is how non-compliant hardware slips into a federal deployment.

Brands that should never be specified for federal use include the five covered entities above, plus Chinese-origin and rebrand lines such as Uniview (UNV), Lorex, EZVIZ, Annke, LTS, Alibi, LaView, ICRealtime, Q-See, and Reolink. If any of these are already installed, they typically must be removed and replaced rather than reused.

NDAA 889 is not the same as TAA

Buyers frequently conflate two separate rules:

A product can be NDAA-compliant yet not TAA-compliant (for example, built by a non-covered manufacturer but assembled in a non-designated country), and the reverse is also possible. For most federal procurements you need to satisfy both, which is why documentation for each device should state its 889 posture and its country of manufacture.

Which camera and access-control lines are safe to buy

For video surveillance, established compliant manufacturers include Axis Communications (Sweden), Hanwha Vision / Wisenet (South Korea, with US-assembled lines), i-PRO (Japan/US), Bosch (Germany), Avigilon and Pelco (Motorola Solutions), Digital Watchdog, Speco Technologies, VIVOTEK, ACTi, MOBOTIX, and Verkada. None are covered entities, and each offers compliant lines — though TAA status still depends on the specific model.

On the software and access-control side, compliant choices include video management platforms from Genetec, Milestone (XProtect), exacqVision, and Salient Systems, and access control from HID Global, Mercury Security, LenelS2 (OnGuard), Software House (C-CURE 9000 / iSTAR), Brivo, STid, and Honeywell Commercial Security (NDAA-marketed SKUs only). For intrusion and alarm, Bosch, Honeywell, and Napco offer compliant lines.

Because compliance is confirmed per model, the right answer is rarely a single brand — it is the specific line whose 889 posture and country of origin both check out for your mission. That verification is the work, and it is what should sit behind any "approved" list before an order goes out.

How Uniqcli handles compliance

Uniqcli Security is a TAA / NDAA Section 889-compliant physical-security integrator. We design, integrate, and manage camera, access-control, intrusion, and monitoring systems, and we sell direct — no payment up front. Because we are vendor-neutral, we specify the right compliant line for each mission rather than pushing a single brand, and we verify 889 and TAA posture at the SKU level before anything is ordered. For every project we provide the manufacturer attestations and country-of-origin documentation that contracting officers and audit teams need on file.

If you are scoping a new system, planning a rip-and-replace of legacy hardware, or simply need to confirm that an existing deployment is defensible, request a quote or schedule a compliance assessment with our team and we will map the right compliant path for your facility.

Frequently asked questions

Does Section 889 apply to me if I'm a contractor, not a federal agency?

Yes. Part B of Section 889 prohibits the government from contracting with any entity that uses covered equipment in its operations — not just equipment used on the federal contract itself. That means a covered camera anywhere in your business can affect your eligibility. The restriction flows down through FAR 52.204-25 to subcontractors as well.

Is a brand either fully compliant or fully banned?

Neither, for most brands. The five covered entities (Hikvision, Dahua, Huawei, ZTE, Hytera) and their rebrands are prohibited outright. Among non-covered manufacturers, compliance is determined per SKU: a single brand can offer both compliant and non-compliant models, so the specific model and its components must be verified before purchase. Uniqcli confirms this at the SKU level.

What is the difference between NDAA 889 and TAA compliance?

NDAA 889 is a manufacturer-and-component rule (who built it, what chips are inside). TAA is a country-of-origin rule requiring the product to be made or substantially transformed in the US or a TAA-designated country — China, Russia, and India are not designated. A product can satisfy one and not the other, so federal buyers usually need to confirm both.

We already have Hikvision or Dahua cameras installed. What now?

Covered equipment generally cannot be reused for federal purposes and typically must be removed and replaced — a process often called rip-and-replace. The replacements should be verified as both NDAA 889 and TAA compliant. Uniqcli can assess the existing system, document what must come out, and design a compliant replacement.

Which camera brands can I safely specify for a federal facility?

Compliant manufacturers include Axis, Hanwha Vision (Wisenet), i-PRO, Bosch, Avigilon, Pelco, Digital Watchdog, Speco, VIVOTEK, ACTi, MOBOTIX, and Verkada, with access control from HID, LenelS2, Software House, Brivo, and Mercury. None are covered entities. TAA status still depends on the specific model's manufacturing origin, which should be confirmed before order — Uniqcli verifies this per SKU.

Ready when you are

Need it sourced compliant and direct?

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.