R-03Resource / Compliance Guide

NDAA Section 889, in plain English.

Which brands are banned, who has to care, and what to do if non-compliant cameras are already on your walls. Written for buyers, not contracts officers.

DC · Maryland · Virginia·Updated quarterly·~8 min read
01 / The law

What Section 889 actually says.

Two sentences of context, then the part that matters for buying cameras.

Part A · Aug 2019

Federal agencies can't buy covered equipment.

As of August 2019, federal agencies are prohibited from procuring telecommunications or video surveillance equipment from named companies — or any system that uses covered equipment as a "substantial or essential component."

Part B · Aug 2020

Federal contractors can't use it. Anywhere.

As of August 2020, federal agencies cannot contract with any entity that uses covered equipment — even on private projects, even purchased before the rule existed. Compliance is a representation made under FAR 52.204-25.

The covered list is named explicitly in the statute and codified in FAR 4.21 / DFARS. It applies to the equipment and any service that routes user data through it.

02 / Covered companies

The named brands. And their rebrands.

Five companies are named in the statute. Their subsidiaries, affiliates, and OEM relationships are covered too — which is where most buyers get tripped up.

01
Hikvision
Video surveillance — cameras, NVRs, VMS
Most-deployed banned brand in commercial buildings.
02
Dahua
Video surveillance — cameras, NVRs, intercoms
Second-most-common; OEMs under many private labels.
03
Hytera
Two-way radio + push-to-talk infrastructure
Less common in commercial AV; still covered.
04
Huawei
Networking, telecom, mobile
Switches and SFP modules are the typical exposure.
05
ZTE
Networking, telecom
Same exposure pattern as Huawei.
Watch list

Common rebrands and OEM labels

If a camera ships with Hikvision or Dahua firmware under a different label, it is still covered. These are the labels we encounter most often in DMV buildings — not exhaustive, and not all SKUs from each label are covered:

  • Annke
  • Lorex (legacy SKUs)
  • LTS Security
  • EZVIZ
  • Honeywell Performance Series (legacy)
  • Swann (select)
  • ezTalks
  • Kogan
  • Anpviz
  • LaView (select)

When in doubt, check the device's UI for Hikvision's "iVMS" or Dahua's "DMSS / SmartPSS" — that's the firmware tell.

03 / Beyond federal

You're not federal. Why does this still matter?

Section 889 was written for federal procurement, but its gravity now extends well past the federal contracts office. Four reasons we see in DMV deals every week.

01

Cyber-insurance underwriters

Carriers increasingly include NDAA-compliance language in commercial cyber policies. Non-compliant gear can trigger exclusions, premium loadings, or — at renewal — refusal to bind.

02

Prime-contractor flow-down

If you sub to anyone who touches federal work, FAR 52.204-25 flows down to you. Property managers, construction GCs, AV integrators, IT MSPs — covered equipment in your stack puts the prime out of compliance.

03

Future federal opportunity

GSA leases, federal-tenant build-outs, defense-adjacent industries (cleared facilities, data centers, biotech with federal grants) all assume an NDAA baseline. Banned cameras are a deal-killer late in diligence.

04

Tenant + acquirer scrutiny

When a building changes hands, or a federally-affiliated tenant tours, the security stack is part of the package. A non-compliant DVR in the IT closet has killed leases and reduced sale prices.

04 / What we install instead

Compliant alternatives that aren't a downgrade.

The good news: NDAA-compliant doesn't mean expensive or worse. Three lines we install, chosen by use-case, not by margin.

Primary

Turing

Wizer's default for federally-adjacent and government-adjacent projects

  • Designed and certified for NDAA Section 889 + TAA compliance
  • Strong AI analytics (object/face/LPR) at competitive pricing
  • Cloud + on-prem options without per-camera licensing surprises
Enterprise

Axis Communications

Spec'd when the design calls for Axis explicitly or specialty optics

  • Swedish manufacturer, long compliance track record
  • Best-in-class image quality + extreme-environment hardware
  • Higher hardware cost; deep VMS/ACS interoperability
Cloud-first

Avigilon Alta / Verkada

Spec'd when the customer wants cloud-managed VMS as the primary system

  • NDAA-compliant hardware paired with native cloud VMS
  • Recurring license fees, but zero on-prem NVR footprint
  • Strong fit for multi-site enterprises with thin IT staff
05 / If you already have non-compliant gear

Six steps to audit what you have.

Before you replace anything, you need a clear picture. This is the sequence we run on every site we inherit — yours or a tenant's.

  1. 01

    Pull a device inventory

    List every camera, NVR, switch, and intercom by make + model. The label on the side is the source of truth — not what the install paperwork says.

  2. 02

    Cross-reference firmware

    Check each device's web UI / settings page. Hikvision firmware shows "iVMS"; Dahua shows "DMSS" or "SmartPSS". Either is a covered-equipment tell, regardless of label.

  3. 03

    Identify rebrands

    OEM relationships are the trap. Annke, LTS, EZVIZ, Lorex (legacy), and Honeywell Performance Series (legacy) are common labels we find covering Hikvision/Dahua hardware.

  4. 04

    Document the network path

    Section 889 covers any system that uses covered equipment as a "substantial or essential component." If a banned NVR records to a compliant cloud, the system is still covered.

  5. 05

    Map federal exposure

    Tag each site by federal-adjacency: federal tenant, prime contract flow-down, GSA lease, cyber-insurance language. This determines replacement priority.

  6. 06

    Build a phased replacement plan

    High-exposure sites first; reuse cabling and mounting hardware where possible to lower per-site cost. Most replacements complete in a single after-hours window per site.

06 / Replacement reality

"Rip and replace" isn't always rip-and-replace.

The phrase makes replacement sound catastrophic. In practice, most commercial sites can be brought into compliance without re-cabling, without down-time, and without losing a single recorded event from the old system.

Cabling stays

Cat6 / Cat6A drops are reused 90%+ of the time. The new cameras land on the same PoE ports.

Mounts often stay

Standard junction boxes and arm mounts carry forward. Only the camera head and the patch get swapped.

Recordings migrate

We export and archive the old NVR's footage to cold storage before decommission. Chain of custody intact.

Phased by zone

Lobbies + perimeter + data closets first. Lower-risk interior cameras can run on a 60–90 day tail.

Audit / Quote

Find out where you stand.

We'll walk the site, document every covered device by make and model, and hand back a phased replacement plan with line-item pricing. No surprise findings, no scare tactics — just the actual list and the actual cost.

After we hand over the keys

The system is only as good as the team supporting it.

When the install is done, the system has to keep working — through firmware drift, staff changes, ISP outages and the day someone unplugs the wrong thing. Wizer Managed Site Operations keeps it that way.

  • 24/7 monitoring on cameras, doors, AV gear and network.
  • One number to call. We answer it.
  • Lifecycle planning so nothing surprises your budget.