Serving Springfield · Joplin · Branson & all of Missouri Support@VTC-USA.com
(417) 831-0097
VictoryTechnology Co.
Expert Review Evan Allen, founder, Victory Technology Company. 14 years in land mobile radio and physical security; supplier of Blue Shield–eligible, MOSWIN-approved equipment to Missouri agencies.

An NDAA-compliant security camera is one that contains no equipment from the manufacturers banned under Section 889 of the 2019 National Defense Authorization Act: Hikvision, Dahua, Hytera, Huawei, and ZTE, plus their subsidiaries and the OEM partners selling their hardware under other names. That last clause is where buyers get hurt. The banned camera giants move enormous volume under labels that sound nothing like Hikvision or Dahua, so a camera can be non-compliant while wearing a perfectly American-sounding brand. Compliance is about who built the hardware and firmware, not whose sticker is on the box.

Quick Facts

Section 889 Part A bars federal agencies from buying covered equipment. Part B (effective August 13, 2020) bars them from contracting with entities that even use it as a substantial component. 2 CFR 200.216 extends the ban to federal grant and loan recipients, which pulls in schools, universities, cities, and counties. The FCC put these makers on its Covered List and stopped authorizing new equipment from them in November 2022, and it has since tightened the rules twice, adopting orders on October 28, 2025 and July 22, 2026 that reach covered components and previously authorized devices. The restrictions remain fully in force as of August 2026.

What does Section 889 actually ban?

Two things, in two phases. Part A is the one people have heard of: federal agencies cannot buy video surveillance or telecommunications equipment from the covered makers, their subsidiaries, or their affiliates. Part B, effective August 13, 2020, is the one with reach: agencies cannot contract with any entity that uses covered equipment as a substantial component of any system, even systems that never touch government work. A contractor with Dahua cameras watching its own parking lot has a Part B problem the day it certifies compliance on a federal bid.

Then the rule left the contracting world entirely. 2 CFR 200.216 applies the same prohibition to recipients of federal grants and loans, and the FCC closed the front door in November 2022 by refusing to authorize new equipment from the covered makers at all. The FCC has kept moving in one direction since: an October 28, 2025 order reaches previously authorized covered devices, and a July 22, 2026 order extends the ban to new devices built on covered makers' chips.

Who actually has to comply?

  1. Federal agencies and their contractors: strictly. Part A governs what agencies buy; Part B governs who they may do business with. The certification is signed under penalty, not skimmed.
  2. Grant-funded public buyers: strictly. Through 2 CFR 200.216, the ban follows federal money into K-12 districts, universities, city halls, and county commissions. If a school camera project or a public safety grant purchase touches federal funds, covered equipment is off the table, full stop.
  3. Private businesses: technically free. No statute forces a purely private buyer to comply. The honest argument for doing it anyway is practical: insurers increasingly ask what is on the network, future federal contracts or grants would inherit the problem, and the FCC authorization halt means the banned lines are aging out of the US market regardless. Compliance today is cheaper than a rip-and-replace later.

What is the white-label trap?

Both banned camera giants built much of their business as OEMs, manufacturing cameras and recorders that other companies sell under their own brands. The label changes; the covered hardware and firmware inside do not. This is how an organization that would never knowingly buy Hikvision ends up running it anyway, purchased in good faith from a brand with a flag in its logo.

It goes a layer deeper than the camera maker. Plenty of devices from otherwise independent brands carry HiSilicon chipsets, and HiSilicon is Huawei's silicon arm, which drags the device into covered territory no matter who assembled it. The reseller at the end of the listing frequently does not know what is inside the housing, and some prefer not to find out. "I didn't know" is not a defense that survives a grant audit.

How do you verify a camera before you buy it?

  1. Check the FCC ID on the device. Every camera with WiFi or Bluetooth must carry one, and looking it up shows who actually sought the authorization. Wired-only cameras are often authorized under a Supplier's Declaration of Conformity instead, with no FCC ID at all, so for those the OEM letter in the next step does the work. A famous brand on the box with someone else's FCC ID on the label is the trap announcing itself.
  2. Get an OEM disclosure letter in writing. Ask the vendor to state, on paper, who manufactures the hardware and who writes the firmware. A vendor that will not put it in writing has answered your question.
  3. Prefer manufacturers that build their own hardware. A company that designs and manufactures its own cameras has nothing to disclose because there is no one hiding upstream. Axis builds its own, which is a large part of why VTC carries Axis.

What about the cameras already on your wall?

Inventory what you have before an auditor does. Pull the model and FCC ID off every camera and recorder, identify the true OEM, and flag covered devices, starting with anything bought using federal money. From there, replacement is a plan, not a panic: covered equipment tied to compliance obligations goes first, the rest is scheduled against its natural lifecycle, and existing cabling usually stays, which keeps the cost closer to a head swap than a rebuild. VTC does this as a system evaluation, and site assessments are free. The decision framework for what replaces the old gear is in our Missouri business camera buyer's guide.

Frequently Asked Questions

Two moves: look up the FCC ID if the device has one (wireless cameras must carry one; wired-only cameras often do not), and ask the vendor for a written OEM disclosure letter naming who manufactures the hardware and firmware. If the two answers disagree, or the letter never arrives, treat the camera as covered.

No. Section 889 and 2 CFR 200.216 bind federal agencies, contractors, and recipients of federal grants and loans, not purely private buyers. But the FCC stopped authorizing new equipment from these makers in November 2022, insurers are asking questions, and any future federal contract or grant inherits your camera closet. Legal is not the same as wise.

When federal money is involved, yes. 2 CFR 200.216 attaches the Section 889 prohibition to federal grant and loan funds, so a district spending them on cameras is barred from covered equipment, including white-labeled versions. State-funded purchases are safest specified the same way.

Think in OEMs, not brand names, because names are exactly what the white-label trade launders. The reliable pattern is manufacturers that design and build their own hardware; Axis does, and it is the camera line VTC installs. For anything else, verify the FCC ID where present and demand OEM disclosure in writing before purchase.

Not Sure Who Really Built Your Cameras?

VTC inventories existing systems, verifies OEMs against the covered list, and designs NDAA-clean replacements on Axis hardware, with free site assessments across Missouri.

Call VTC(417) 831-0097

← All Resources