NDAA Compliance Guide for Security Contractors and Integrators
Losing a bid over paperwork is worse than losing it on price.
Every year, integrators walk into school district, municipal, federal, and utility projects with a camera package that works perfectly — and gets thrown out because nobody could prove the equipment was NDAA compliant. Sometimes the gear was genuinely compliant and the submittal was just thin. Sometimes the gear was a white-labeled camera with a restricted chipset inside.
This guide covers what the rule actually says, when it reaches you, and how to build a submittal that clears review the first time.
Every camera and NVR recorder NorthStar stocks is NDAA compliant, and we back cameras and recorders with a 3-year warranty.
What Section 889 actually bans
Section 889 of the 2019 National Defense Authorization Act (NDAA) is the provision everyone means when they say "NDAA compliant." It has two parts, and the second one is the one integrators underestimate.
Part (a)(1)(A) prohibits federal agencies from procuring covered telecommunications and video surveillance equipment or services.
Part (a)(1)(B) prohibits federal agencies from contracting with any entity that uses covered equipment or services — anywhere in that entity's operations, not just on the government's project.
The named companies in the statute include Huawei, ZTE, Hytera, Hangzhou Hikvision, and Dahua, along with their subsidiaries and affiliates. For video surveillance specifically, Hikvision and Dahua are the two that dominate the conversation.
Part (B) is why a contractor can be disqualified for cameras on its own warehouse wall, even when every camera quoted for the job is clean.
Who this applies to — it is wider than "federal"
Most integrators assume NDAA rules only touch direct federal work. In practice the requirement flows downhill through several channels:
- Federal contracts and subcontracts. Prime and sub tiers both inherit the restriction.
- Federal grant and loan funding. State, municipal, K-12, higher education, transit, and utility projects funded even partly by federal dollars routinely carry NDAA language.
- State-level bans. Several states have adopted their own restrictions on the same vendor list for state-funded procurement.
- Owner-specified requirements. Hospitals, data centers, defense-adjacent manufacturers, and national retail chains often write NDAA compliance into their security standards voluntarily, because their own customers demand it.
- Cyber-insurance and audit requirements. Increasingly common in renewal questionnaires.
If you bid public work at all, assume the requirement is coming and standardize your catalog around it rather than checking project by project.
The OEM trap: why "not a Hikvision camera" is not the same as compliant
The restriction follows the manufacturer, not the label on the housing. A large share of budget cameras sold under dozens of brand names are OEM or ODM builds from restricted manufacturers with a different logo and firmware skin. The badge changes. The origin does not.
Signs a camera deserves a second look before you quote it:
- No traceable manufacturer, only a seller or brand name
- No published compliance statement or letter of conformity
- Firmware, web UI, or mobile app that is visually identical to a restricted vendor's platform
- Model numbering that maps one-to-one onto a restricted vendor's catalog
- Pricing far below every traceable equivalent in the same class
- A distributor who cannot tell you where the unit is manufactured
The safe test is documentary, not visual: can the supplier put the compliance claim in writing, on letterhead, tied to the model number you are buying?
How to verify a product before you quote it
Run this sequence on any camera, recorder, encoder, intercom, or video device entering a controlled project:
- Identify the actual manufacturer — not the reseller, not the brand. Ask directly.
- Get a written NDAA Section 889 compliance statement referencing the specific model or series.
- Confirm the statement covers the whole device — chipset, firmware, and any bundled software or cloud service.
- Check the associated services, since 889 covers services as well as hardware: cloud video, remote management, and P2P platforms count.
- Record the model, serial range, and purchase date so you can reproduce the chain of custody at audit time.
- Re-verify on refresh cycles. Manufacturers change contract suppliers. A compliant model in 2024 is not automatically the same build in 2027.
Building a submittal package that clears review
Most rejections are documentation failures, not product failures. A complete package for a controlled project generally includes:
| Document | What it proves |
|---|---|
| Manufacturer compliance letter | The device is not covered equipment under Section 889 |
| Product specification sheets | Model numbers match exactly what was quoted and installed |
| Bill of materials with model numbers | No substitutions slipped in during procurement |
| Supplier statement / invoice trail | Chain of custody from manufacturer to job site |
| Warranty documentation | Service life and support obligations are backed |
| Firmware and software listing | Bundled services are also clean |
| Company-level 889 representation | Part (B): your own operations are compliant |
Keep these as a reusable template. The integrators who win repeat public work are the ones whose submittal takes twenty minutes to assemble, not two weeks.
Don't forget Part (B): your own house
Part (a)(1)(B) applies to your company as an entity. Before certifying compliance on a federal contract, audit:
- Cameras on your own office, warehouse, yard, and vehicles
- Demo and training gear in your showroom
- Loaner and spare stock on the shelf
- Routers, switches, and radios used in your own network
- Any cloud video service used internally
- Equipment inherited through acquisitions
Remediate before you certify, not after a question comes in.
Where NorthStar fits
NorthStar exists for exactly this problem: an integrator-focused catalog where compliance is the default rather than something to chase per product.
- Cameras — every camera we stock is NDAA compliant, including AI bullets, vandal domes, PTZ, fisheye, multi-sensor, and license plate recognition.
- NVR recorders — our 8-channel and 16-channel 4K PoE NVRs are NDAA compliant.
- Custom VMS servers — purpose-built recording appliances pre-configured for your camera list.
- Warranty — 3 years on cameras and recorders, 1 year on everything else. Full terms on our warranty page.
- Returns — free returns within 30 days on unused product in manufacturer packaging. See shipping and returns.
Need a compliance statement for a submittal? Contact us with the model numbers and we will send documentation with the quote.
Frequently asked questions
What does NDAA compliant mean for security cameras?
An NDAA compliant camera is one that is not covered equipment under Section 889 of the 2019 National Defense Authorization Act. Section 889 names Huawei, ZTE, Hytera, Hangzhou Hikvision, and Dahua, along with their subsidiaries and affiliates. A compliant camera is manufactured outside those supply chains, including its chipset, firmware, and any bundled cloud or remote management service.
Does Section 889 apply to private companies or only federal agencies?
Both. Part (a)(1)(A) stops federal agencies from buying covered equipment. Part (a)(1)(B) stops federal agencies from contracting with any entity that uses covered equipment anywhere in its own operations. That second part reaches private integrators, and the requirement also flows into state, municipal, K-12, transit, and utility projects that use federal grant or loan funding.
How do I verify a camera is actually NDAA compliant before quoting it?
Identify the real manufacturer rather than the reseller or brand, request a written Section 889 compliance statement that references the specific model or series, confirm it covers chipset, firmware, and bundled services, and keep the model numbers, serial ranges, and purchase records for audit. Re-verify at every refresh cycle, since manufacturers can change contract suppliers between production runs.
Can a rebranded camera still be non-compliant?
Yes. The restriction follows the manufacturer, not the label. Many budget cameras sold under unfamiliar brand names are OEM or ODM builds from restricted manufacturers with different branding and a firmware skin. Warning signs include no traceable manufacturer, no written compliance statement, a web interface identical to a restricted vendor's platform, and pricing far below every traceable equivalent.
What documents should an NDAA submittal package include?
A manufacturer compliance letter tied to the model, product specification sheets, a bill of materials with exact model numbers, a supplier statement or invoice trail showing chain of custody, warranty documentation, a list of bundled firmware and software services, and a company-level Section 889 representation covering your own operations.
Are NorthStar cameras and recorders NDAA compliant?
Yes. Every camera and NVR recorder in the NorthStar catalog is NDAA compliant, including AI bullet, vandal dome, PTZ, fisheye, multi-sensor, and license plate recognition models. Cameras and recorders carry a 3-year warranty, and we can supply compliance documentation with the quote for submittal packages.