Uniqcli

InsightsProcurement Guidance

Blue UAS and NDAA-Compliant Drones: A Buyer’s Check

Blue UAS status and “NDAA compliant” are not interchangeable. The Blue List is a current government record of vetted unmanned systems and components; federal and Defense purchases can also implicate the American Security Drone Act, FAR prohibitions, Defense-specific statutes, the FCC Covered List, agency policy, grant terms, and the exact solicitation. Verify the complete configuration and evidence on the award date.

By Uniqcli Team · · 10 min read · Updated

Gray unmanned aircraft resting on gravel with no people nearby.
Gray unmanned aircraft resting on gravel with no people nearby.

Key takeaways

  • DCMA took over management of the Blue List from the Defense Innovation Unit in December 2025. Use the current DCMA record, not an old reseller screenshot.
  • A platform’s appearance on the Blue UAS Cleared List is strong evidence for its listed configuration and program status. It is not a permanent approval for every payload, radio, controller, software version, cloud service, or substitute component.
  • “NDAA compliant” should identify the specific statutory section, product scope, date, and evidence. The term by itself is too broad for acceptance.
  • FAR Subpart 40.2 implements American Security Drone Act restrictions on procurement and operation of UAS manufactured or assembled by covered foreign entities, with defined exceptions and waivers.
  • The FCC Covered List and conditional approvals are dynamic and answer a communications-equipment authorization question distinct from Blue status.
  • Contracting, aviation safety, cybersecurity, privacy, radio, data, training, maintenance, and records requirements all remain after the supply-chain screen passes.
On this page

Procurement Guidance

Start with the current Blue List owner

The Defense Innovation Unit created and operated Blue UAS as a way to vet commercial unmanned aircraft systems and components for government use. On December 3, 2025, DIU formally transferred the Blue UAS Cleared List to the Defense Contract Management Agency. DCMA’s Unmanned Systems–Experimental organization now manages and expands the Blue List.

That transition matters to buyers. A 2024 DIU PDF, manufacturer press release, or distributor page may describe a prior configuration or status. The current list is the authoritative starting point. Save the listing, retrieval date, platform name, manufacturer, configuration detail, and any associated components or software evidence with the procurement file.

List status can change as products, supply chains, software, and policy change. Treat verification as an award and acceptance activity, not a one-time market-research task. If delivery occurs months after award, recheck the received configuration before operational approval.

What Blue status tells you—and what it does not

DIU describes the Blue UAS Cleared List as containing commercial drones that underwent security and performance assessments for government use. Its Blue UAS Framework has addressed interoperable components and software. DCMA is scaling that model under the transferred Blue List.

Blue status is meaningful because it links a named system or component to a government vetting process. But the scope is defined. A listed aircraft may be paired on a quote with a different controller, payload, radio, battery, ground station, mapping application, cloud tenant, or third-party integration. Those changes can alter supply-chain, cybersecurity, interoperability, export, radio, safety, and mission conclusions.

Ask four questions:

  • What exact configuration is listed today?
  • Does every quoted material component match that configuration or an explicitly listed framework component?
  • What additions sit outside the listed scope, and which authority evaluated them?
  • What process controls substitutions and post-award changes?

Do not turn “Blue” into a brand-wide adjective. Write “the listed configuration was verified on [date]” and attach the evidence.

Why “NDAA compliant” is incomplete

The National Defense Authorization Act is enacted every year and contains many provisions. Several UAS and supply-chain restrictions have appeared across different years, scopes, agencies, products, and dates. A seller saying “NDAA compliant drone” may mean a Blue-listed platform, a representation about certain foreign components, a Defense purchasing rule, Section 889 screening, or the American Security Drone Act. Those are not identical.

Require the seller to identify:

  • the statute, section, regulation, clause, or agency policy addressed;
  • the exact platform and bill of materials covered;
  • whether software, radios, payloads, controllers, cloud services, and critical components are included;
  • the evidence source and responsible signer;
  • the effective date and any expiration;
  • the change-notification and substitution process.

The buyer should independently compare that evidence with the solicitation. A manufacturer representation can support responsibility; it does not replace the contracting officer’s assessment or the government list.

American Security Drone Act and FAR Subpart 40.2

The American Security Drone Act of 2023 created government-wide restrictions involving UAS manufactured or assembled by covered foreign entities. FAR Subpart 40.2 implements the procurement and operation rules. It defines a FASC-prohibited UAS and points to the covered-foreign-entity list maintained through SAM.

The FAR says contracting officers, working with the program office or requiring activity, must review proposals for prohibited delivery and, on or after December 22, 2025, prohibited operation, unless an exemption, exception, or waiver applies. FAR 52.240-1 is prescribed for solicitations and contracts. The rule includes documentation duties for exemptions, exceptions, and waivers.

This is not the same as “must be Blue.” A solicitation can require Blue status, and the Blue List can provide an efficient approved path for Defense use, but the FAR prohibition is framed around covered foreign entities and defined UAS. Read the actual clause and agency requirement.

The FAR also defines the UAS broadly to include the aircraft and associated elements such as communication links and control components needed for safe and efficient operation. That argues against screening only the airframe logo.

Section 889 is a separate screen

Section 889 of the FY2019 NDAA addresses covered telecommunications equipment and services. Part A restricts federal procurement of systems that use covered equipment or services as a substantial or essential component or critical technology. Part B restricts contracting with entities that use covered equipment or services under the statute and implementing FAR provisions, subject to exceptions and waivers.

A drone system can contain cameras, radios, networking equipment, cloud connectivity, or video services that create Section 889 questions. Passing a UAS-specific list does not eliminate the need to review the contract’s Section 889 representations and the complete system. Conversely, a Section 889 representation alone does not establish Blue status or satisfy every UAS restriction.

For component-level review, Section 889 surveillance BOM checklist should be used alongside the UAS procurement file.

FCC Covered List and conditional approvals

The FCC Covered List concerns communications equipment and services deemed to pose an unacceptable national-security risk under the Secure and Trusted Communications Networks Act framework. In late 2025 and 2026, the FCC issued UAS-related updates and established a conditional-approval mechanism reflected in the current list.

The FCC’s public notices emphasize that the Covered List changes and that regulated parties must monitor current notices. Some conditional approvals are device-specific and time-limited. A July 2026 FCC notice explicitly describes the “Blue UAS list” used for its determination as the combination of the Blue UAS Cleared List and the compliant components and software list.

Do not infer that FCC treatment, Blue status, and procurement eligibility are one universal list. They interact, but each authority has its own scope. Check the current FCC record for communications-equipment consequences and retain any conditional approval with its termination date.

State, local, education, and grant-funded buyers

Nonfederal buyers can face federal conditions when a grant or cooperative agreement funds the purchase, when they support a federal mission, or when a state law adopts its own UAS restrictions. State requirements vary widely and can name manufacturers, countries, lists, agencies, or use cases.

Start with the funding instrument and state procurement authority. Ask whether restrictions apply to purchase, operation, maintenance, software, or data; whether existing fleets are grandfathered; whether public safety has an exception; and who can issue a waiver. Do not market a Blue-listed platform as automatically satisfying every state statute.

For mixed funding, identify which dollars pay for the aircraft, payload, software, support, and operation. Preserve the grant terms and approval. A platform purchased with local funds can still be operated under a federal award that imposes conditions.

Build a component-level UAS bill of materials

A useful bill of materials extends beyond the aircraft SKU. Record:

  • airframe and serial;
  • flight controller and firmware;
  • propulsion controller where relevant;
  • navigation, GNSS, and positioning components;
  • radios, modems, antennas, and data links;
  • remote controller, display, and mobile device;
  • ground-control-station hardware and software;
  • payloads, cameras, sensors, gimbals, and storage media;
  • batteries, chargers, docking stations, and power accessories;
  • remote ID module and broadcast configuration;
  • mapping, fleet, media, and analytics software;
  • cloud hosting, regions, accounts, APIs, support tools, and subprocessors;
  • update service, signing, release channel, and support lifecycle.

Identify manufacturer, model, version, country of origin when required, supplier, approval record, and substitution status for each material item. The depth should match risk and the contract; it does not require disassembling every system without authority. It does require enough traceability to know whether the delivered configuration matches the approved one.

Cybersecurity review beyond the list

A cleared supply chain does not automatically produce a securely operated fleet. Build a threat model around aircraft loss, account takeover, malicious updates, command-link interception, cloud exposure, sensor-data leakage, insider misuse, compromised support access, and unsafe geospatial information.

Review:

  • account provisioning, MFA, roles, and privileged access;
  • device identity and fleet enrollment;
  • firmware and application signing, update source, rollback, and vulnerability response;
  • encryption and key management for command links, storage, upload, and cloud services;
  • default credentials and local maintenance ports;
  • logs for flights, users, updates, exports, administrative changes, and failures;
  • data location, retention, sharing, deletion, and legal hold;
  • offline operation and behavior when cloud services are unavailable;
  • remote vendor support and subcontractor access;
  • incident reporting, preservation, and revocation.

Test the actual configuration. A strong airframe can be undermined by a shared tablet account or public media link. Restrict personal devices and consumer cloud accounts if the mission requires managed custody.

Privacy, records, and data ownership

UAS can capture identifiable people, license plates, facilities, radio metadata, thermal imagery, and precise location. Before deployment, define lawful purpose, notice, collection limits, retention, sharing, public-records treatment, evidentiary handling, and deletion.

The contract should state who owns raw and processed data, metadata, models, and derived products; where they are stored; who can use them for product improvement; and how they are returned or deleted at termination. Review whether technical-support personnel can see flight data or imagery.

For public safety and inspection, chain of custody may matter. Record operator, aircraft, sensor, timestamps, location, file hash or integrity method, transfer, access, editing, export, and retention. Security and records teams should agree on the workflow before the first mission.

Aviation and radio requirements remain

Supply-chain approval does not grant flight authority. The operator must comply with applicable FAA rules, airspace authorization, remote identification, registration, pilot requirements, operational limitations, waivers, and agency flight policy. Specialized government or public-safety operations can have distinct authorities; involve the aviation program and counsel.

Radio links and payloads can implicate spectrum licensing, authorization, interference, and local coordination. Confirm that the quoted radio configuration is legal and supported for the operating location. An imported or alternate radio can change both compliance and Blue configuration.

Build safety acceptance around mission conditions: weather, night operations, people, vehicles, structures, electromagnetic environment, lost link, return-to-home behavior, geofencing, emergency landing, battery failure, and maintenance. The procurement team should not promise an operational capability the aviation authority has not approved.

Evaluate the complete offer

Create mandatory gates before performance scoring:

  • Exact platform and component status verified against current official records.
  • Contract-specific statutory and regulatory representations complete.
  • No prohibited configuration or operation under applicable FAR, DFARS, FCC, state, or grant rules.
  • Cybersecurity and data architecture accepted.
  • FAA, spectrum, safety, and operator path feasible.
  • Support, parts, training, maintenance, and evidence meet the mission timeline.

Then evaluate mission performance: payload quality, endurance, environmental limits, link range, navigation, obstacle handling, portability, launch and recovery, repair, training, workflow, data processing, and total cost.

Require a demonstration with the proposed configuration. A different payload or controller can make the demonstration irrelevant. Use representative terrain, connectivity, data workflow, and operator tasks.

Contract language and substitution control

The line item should identify exact manufacturer, model, configuration, software, required components, Blue or other official status as of a defined checkpoint, and evidence deliverables. State whether substitutions require contracting-officer and security approval. Require notice of changes that affect supply chain, list status, firmware, cloud, support, ownership, or critical components.

Acceptance should include serial capture, physical inspection, component reconciliation, firmware and application versions, account enrollment, approved configuration, list and FCC recheck, cybersecurity test, data export, maintenance records, and operator documentation.

Avoid broad supplier promises such as “all future upgrades remain compliant.” Require version-specific evidence and a change process. Preserve the original approved configuration so a field repair does not quietly introduce an unreviewed radio or camera.

Sustainment and fleet monitoring

Plan batteries, propellers, motors, controllers, payloads, cables, cases, chargers, firmware, software subscriptions, training, calibration, and repair. Determine which repairs can be done locally and which require return to the manufacturer. Record chain of custody and data handling during repair.

Monitor official list status, FCC notices, vulnerability advisories, recalls, ownership changes, component substitutions, software release notes, and end-of-support dates. Assign a fleet configuration owner with authority to approve updates. A pilot applying an unreviewed mobile-app update before a mission can change risk.

Maintain a grounded-status process for aircraft affected by a critical vulnerability, expired conditional approval, unsafe component, or missing maintenance. The asset system should identify every affected serial and location quickly.

Run an annual configuration reconciliation even when the fleet has not changed intentionally. Compare every active serial, controller, payload, critical component, firmware, application, cloud tenant, and radio against the approved baseline and current official records. Investigate undocumented field repairs and loaner equipment before the next mission.

Frequently asked questions

Is every NDAA-compliant drone on the Blue List?

No. “NDAA compliant” can refer to different provisions and evidence, while the Blue List is a specific government-managed record. A solicitation can require Blue status even if a seller makes a separate statutory representation.

Does Blue UAS status cover every accessory?

Only components and configurations within the applicable listed scope. Verify payloads, radios, controllers, software, cloud services, and substitutions separately.

Who manages the Blue UAS list now?

DCMA took over from DIU in December 2025. DIU’s old portal redirects buyers to the current DCMA Blue List environment.

Does Blue status satisfy the American Security Drone Act?

It is relevant government evidence, but the contracting officer must apply FAR Subpart 40.2, the covered-entity list, the solicitation, and any exception or waiver. Do not treat the terms as legally identical.

How often should status be checked?

At market research, proposal evaluation, award, receiving or operational acceptance, and after material component or software change. High-risk fleets should also monitor current notices continuously.

Ask AI about Uniqcli

Why buyers use Uniqcli

Related reading

InsightsProcurement Guidance

How to Buy GPU Infrastructure Through Federal Contract Vehicles

Federal contract vehicles can shorten acquisition lead time, but a vehicle does not turn an incomplete GPU requirement into a deployable system. The buyer still needs a complete scope, competition strategy, exact contract-holder path, configuration-specific products and services, funding, delivery plan and acceptance criteria.

· 6 min read

InsightsProcurement Guidance

How to Write a GPU Server RFQ Without Creating an Unusable Quote

A good GPU server request for quotation makes responsive offers comparable and the delivered system testable. It describes the workload, buying unit, salient performance and interfaces, site constraints, software/support, delivery and acceptance. A weak RFQ says “NVIDIA B300 server or equivalent” and leaves sources to guess whether the government needs a GPU, an eight-GPU server, a liquid-cooled rack or a cluster.

· 6 min read

InsightsProcurement Guidance

How to Evaluate an AI Infrastructure Integrator for Government

An AI infrastructure integrator should deliver a working, documented and supportable system—not a collection of individually valid boxes. The evaluation should test how the integrator turns a workload into compute, fabric, storage, power, cooling, security, supply-chain evidence, factory acceptance and site operations. The strongest answer is an artifact and a method: sizing worksheet, rack elevation, cable matrix, as-built BOM, test report and escalation map.

· 6 min read

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team

Ready to scope your program?

Talk to a Uniqcli engineer, or send a bill of materials for a TAA-verified quote — no payment up front.