Uniqcli

Supply-Chain Compliance · Free Guide

NDAA §889 Covered-Equipment Screening Checklist for Federal IT & Physical-Security Buyers

Screen cameras, NVRs, radios, and network gear for banned makers — and the rebadged OEM modules that hide them — before you buy.

By Uniqcli Team ·

8 min read · Free PDF download · Print-friendly

What's inside

Key takeaways from this guide

  • Five named makers anchor the ban — Huawei, ZTE, Hikvision, Dahua, and Hytera, plus their subsidiaries and affiliates — and it follows the chipset and module, not just the logo, so a rebadged OEM camera is covered too
  • §889 bars two different things: Part A stops the government from buying covered gear (effective 8/13/2019); Part B stops a contractor from using it anywhere in its own business (effective 8/13/2020) — a camera on a private loading dock can disqualify a federal award
  • There is no dollar threshold and no grandfathering — the prohibition reaches even the lowest-dollar buys, regardless of where the item was assembled or when it was purchased
  • You represent compliance through three FAR clauses — 52.204-24, -25, and -26 — so know which is a per-offer representation, which is the substantive prohibition and flowdown, and which is the annual SAM.gov representation
  • Two equipment buckets are covered — video surveillance and telecommunications — so screen IP cameras, NVRs, video-management software, two-way radios, and network switches
  • §889 is its own regime, separate from the FCC Covered List and from FASCSA — clearing one does not clear the others

Section 889 is mature — the pressure now is proving you screened

Section 889 is not a new rule, and there is no looming deadline to race. It is a mature prohibition that has been in force for years, and that maturity is exactly why it deserves a second look: enforcement has moved from paperwork to scrutiny, and the failures that surface in an audit are almost never the obvious ones. Nobody knowingly buys a banned camera. They buy a camera from a brand they have never heard of, at a good price, with a spec sheet that says "Made in Taiwan" — and the sensor, the NVR chipset, or the video-management firmware inside it traces straight back to a covered maker.

That is the trap this guide is built around. The five named makers are easy to screen for by logo. The rebadged OEM modules that carry their silicon under a different label are not — and §889 follows the module, not the badge. This checklist walks the buckets §889 actually covers, the representations you will sign, the family of sub-brands to watch, and a repeatable pre-purchase workflow that produces the written evidence an audit will ask for.

Because §889 is mature rather than new, the pressure has shifted from "is there a rule?" to "can you prove you screened?" The representations you make in a federal acquisition are serious statements, and a representation that turns out to be wrong is not a clerical slip — it is a compliance failure that can put an award and a contractor's standing at risk. The defensible position is simple to state and harder to live: for every covered-bucket item, hold a dated, written screen in the file that shows you looked past the badge to the maker and the module.

What §889 actually prohibits

Section 889 of the NDAA for Fiscal Year 2019 is two prohibitions wearing one number, and buyers get into trouble by conflating them.

Part A — §889(a)(1)(A) — bars a federal agency from procuring or obtaining covered telecommunications or video-surveillance equipment or services, or from entering a contract with an entity that provides such equipment as a substantial or essential component of any system. It took effect August 13, 2019. This is the half most buyers picture: the government cannot buy the banned gear.

Part B — §889(a)(1)(B) — goes further. It bars the government from contracting with any entity that uses covered equipment or services anywhere in that entity's operations, not just on the federal contract. It took effect August 13, 2020. This is the half that surprises people: a contractor's own internal, private-side surveillance system can make it ineligible for a federal award even if none of that gear ever touches the government's work.

The statutory test that ties both halves together is whether the covered equipment is a "substantial or essential component" of any system, or "critical technology" as part of any system. That phrasing is the reason a rebadge does not escape the rule. It is not asking whose name is on the bezel; it is asking whose technology is doing the work inside. A no-name NVR built on a covered maker's system-on-chip, or a third-party camera running a covered maker's video-management firmware, is squarely in scope.

The reach also extends beyond the five parent companies to their subsidiaries and affiliates. The precise, current roster of affiliated entities is not fixed and does change over time, so screen against the live FAR sources rather than a static list, and keep your own file generic to "subsidiaries and affiliates" where you cannot confirm a specific entity.

Two more properties make §889 unusually blunt. First, there is no dollar threshold: the prohibition is not gated by acquisition size the way some clauses are, and it reaches down to the smallest buys — the prohibition in FAR 52.204-25 applies at or below the micro-purchase level with no exemption (FAR 13.201(j)). One nuance, addressed in the representations section below: the substantive prohibition reaches those low-dollar buys even though the separate offeror representation is generally not collected on them.

Second, there is no grandfathering by assembly location or purchase date. "Assembled in the USA," "Made in Taiwan," or "bought before the rule" do not clear it. Country of assembly answers a TAA question, not a §889 question, and §889 has no legacy carve-out for gear already on the shelf.

The covered-entity family tree

ParentCommon sub-brands / OEM labels to watchProduct types
HikvisionLTS and other Hikvision-OEM rebadgesIP cameras, NVRs, video surveillance
DahuaNumerous white-label NVR / camera brandsIP cameras, NVRs, video surveillance
HyteraRebranded land-mobile-radio (LMR) two-way radiosTwo-way radios, land-mobile comms
HuaweiSwitches, telecom equipment, handsets
ZTETelecom / networking equipment

Why the family tree matters more than the logo

The five names above are the anchor of every §889 screen, but their value is that they force you past the parent brand to the sub-brands and OEM labels that carry the same silicon — the layer where audits actually fail. Two cautions come with the tree. Verify current OEM relationships before you rely on any name: rebadging arrangements shift, and a brand that was clean last year may not be this year, or vice versa.

The specific white-label brands are the trap, and most are not household names. When a camera, NVR, or radio comes from a brand you do not recognize, treat the unknown brand as a prompt to demand a written maker-and-module attestation — not as a reason to assume it is fine.

Physical-security buyers carry the heaviest exposure here, and it is worth saying why. Video surveillance is one of the two buckets §889 names outright, and the surveillance market is exactly where white-label rebadging is most common — a large share of budget-tier IP cameras and NVRs are built on a handful of upstream platforms, then sold under many downstream names. A buyer sizing a camera count and a storage plan can do everything else right and still seat a covered sensor or a covered NVR chipset in the middle of the design. The same logic applies to two-way radios on the land-mobile side, where rebranded units are common. Build the maker-and-module screen into the design decision, not after it.

Pre-purchase §889 screening workflow

  • Identify the bucket — confirm whether the item is video-surveillance or telecommunications equipment (IP cameras, NVRs, video-management software, two-way radios, network switches). If it is, §889 screening applies.
  • Obtain a written maker-and-module attestation — ask the vendor to state, in writing, the actual maker and to confirm that no covered chipset, module, or firmware from a covered entity is inside. A verbal "it's fine" is not evidence.
  • Check the maker against the five entities and their known rebadgers — screen the parent, its subsidiaries and affiliates, and the OEM/white-label labels, not just the brand on the box.
  • Confirm the firmware and video-management software are not from a covered entity — the badge on the hardware can be clean while the VMS or firmware traces to a covered maker.
  • Get a written country-of-origin statement — capture where the item and its critical components originate. Origin answers TAA, not §889, but you want both on file, and the same request captures both.
  • Put it in the buy file and retain it for audit — the screen only counts if you can produce it later, so date it and tie it to the specific item and order.
  • Reconcile with the other screens — run the FCC Covered List and FASCSA screens separately; §889 clearance does not clear them.

The FAR representations you'll sign

ClauseWhat it doesWho acts
FAR 52.204-24Offeror representation regarding covered telecommunications equipment or services — the per-offer attestation about what the offeror will provide.The offeror / vendor competing for the award.
FAR 52.204-25The substantive prohibition on providing, and on the government procuring, covered equipment — with flowdown to subcontractors.Government (may not procure); contractor (may not provide or use); flows down to subs.
FAR 52.204-26Annual representation, made in SAM.gov (Reps & Certs), about the entity's status.The contractor / entity, annually in SAM.gov.

A nuance that trips people up on small buys

The substantive prohibition in 52.204-25 applies even at or below the micro-purchase level (FAR 13.201(j)) — there is no low-dollar exemption from the ban itself. But the separate offeror representation in 52.204-24 is generally not collected on those very low-dollar transactions. In other words: the absence of a signed representation on a small buy does not mean §889 does not apply. The prohibition is always live; the paperwork step is what varies.

Common mistakes that fail an audit

Assuming "Made in USA" or "Made in Taiwan" clears it. Country of assembly is a TAA question. §889 is about the maker and the module, not where the box was screwed together — a camera assembled in a designated country can still contain a covered maker's sensor or system-on-chip.

Missing the rebadged OEM cameras. This is the single most common failure: the brand is unfamiliar and cheap, the silicon or firmware inside is covered, and screening only for the five logos misses it entirely.

Forgetting that Part B reaches your own internal systems. Part B is about what the contractor uses anywhere in its business — a private-side camera or radio you never invoiced to the government can still disqualify a federal award.

Treating a low-dollar buy as exempt. There is no micro-purchase carve-out from the prohibition; small does not mean out of scope.

How §889 sits next to the other screens

A single covered-bucket buy can trip more than one regime, and each is independent. §889 clears the five named makers and their affiliates through the FAR representations. The FCC Covered List is a broader, separately maintained list used for different purposes — and it keeps growing; a December 2025 action extended it to cover foreign-produced drones and their critical components, with DJI and Autel among the makers named. FASCSA exclusion orders are yet another regime, checked on SAM.gov — the first such order, naming Acronis AG and related parties, took effect July 11, 2025.

The point is not to master all three here; it is to remember that a clean §889 screen does not close the others. Run each check that applies, and file the evidence for each separately. A dedicated FCC Covered List and FASCSA walkthrough belongs in its own screen — this guide stops at the §889 boundary on purpose.

How Uniqcli helps

Uniqcli is a sourcing partner, not a compliance authority — we do not certify equipment as "§889 compliant," and nothing here is a claim that we hold any status of our own. What we can do is help you get the evidence your buy file needs: written maker-and-module attestations, country-of-origin statements, and firmware/VMS provenance from the supply chain, packaged so your screening is documented rather than assumed. When your requirement involves cameras, NVRs, radios, or network gear where the rebadge risk is real, bring it to us as a quote or RFQ and we will help you source it with the paperwork attached.

Frequently asked questions

Does §889 have a dollar threshold?

No. The prohibition applies regardless of purchase size — it reaches down to and below the micro-purchase level with no exemption. Note the nuance: the substantive ban is always in force, even though the formal offeror representation form is generally not collected on the very smallest transactions. Small-dollar does not mean out of scope.

Is a Hikvision- or Dahua-chipset camera sold under another brand covered?

Yes. §889 follows the substantial or essential component — the chipset, module, or firmware — not the brand on the label. A rebadged OEM camera carrying a covered maker's silicon is covered even if the outside says something else entirely. This is the classic §889 trap.

Does using gear I already own count, or only new purchases?

Both, in effect. Part A restricts what the government can buy; Part B restricts what a contractor can use anywhere in its business, including equipment already installed on your own private-side systems. There is no grandfathering by purchase date.

How is §889 different from the FCC Covered List?

They are separate regimes with different lists and different purposes. §889 centers on the five named makers and their affiliates and is carried through the FAR representations; the FCC Covered List is broader and separately maintained, and it has continued to grow to include additional makers and categories such as foreign-produced drones. Clearing one does not clear the other — screen each that applies.

Who signs the representation — the reseller or the buyer's contractor?

The offeror competing for the award makes the 52.204-24 offeror representation, and the entity makes the annual 52.204-26 representation in SAM.gov. The substantive 52.204-25 prohibition binds the government (may not procure) and the contractor (may not provide or use), and flows down to subcontractors. A reseller can and should provide written maker/module and country-of-origin attestations to support your file — but the FAR representation itself is made by the offeror/contractor in the acquisition, not by the reseller.

Ask AI about Uniqcli

TAA + 889 together

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team

Ready to put this into practice?

Talk to a Uniqcli specialist, or send a bill of materials for a TAA-verified quote — no payment up front.