resources

NDAA camera checker

Section 889 names five companies: Huawei, ZTE, Hytera, Hikvision, and Dahua. It does not name a single retail brand. The statute covers equipment produced by those companies, so a label you have never heard of can still be covered equipment, and that is the part that catches people. Search a brand below, then verify the specific model by its FCC ID.

What Section 889 actually says

Section 889 of the fiscal 2019 National Defense Authorization Act creates two separate prohibitions, and conflating them is the most common mistake in a procurement thread.

Part A bars federal agencies from procuring or obtaining covered equipment or services. It took effect in August 2019. Part B bars federal agencies from entering into, extending, or renewing a contract with any entity that uses covered equipment or services, anywhere in that entity's operations, whether or not the equipment touches the federal contract. It took effect in August 2020 and is the reason the question reaches so far down the supply chain. Both are implemented through FAR 52.204-25.

The definition of covered equipment names Huawei and ZTE for telecommunications, then separately names Hytera, Hangzhou Hikvision, and Dahua, or any subsidiary or affiliate of those companies, for video surveillance and telecommunications equipment used for public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes. Two details in that sentence do most of the work in practice. The first is produced by, which follows the manufacturer rather than the brand on the box. The second is subsidiary or affiliate, which is why consumer sub-brands are not a way around it.

Who is actually bound

  • Federal agencies, directly.
  • Prime contractors and subcontractors, through the FAR clause in their contracts.
  • Many grant and loan recipients, through the funding terms rather than the statute.
  • Private organizations with no federal money, not by the statute, though the same requirement often arrives through a customer contract, an insurer, a parent company, or a framework such as CMMC that a client is being held to.

Verify it yourself with the FCC ID

The most reliable check available to anyone standing in front of a camera is the FCC ID on the device label, because it identifies the company that obtained the equipment authorization rather than the company that printed the box.

  1. Read the FCC ID from the device label, the packaging, or the web interface.
  2. Take the grantee code, which is the first three characters if it starts with a letter, or the first five if it starts with a digit.
  3. Look the code up in the FCC equipment authorization database. The grantee name is the manufacturer of record.
  4. Compare it against the covered manufacturers. A match is a produced-by answer, not a guess.
Grantee codeGrantee of record
2ADTDHangzhou Hikvision Digital Technology Co., Ltd.
ZTSZhejiang Dahua Technology Co., Ltd.
SVNZhejiang Dahua Vision Technology Co., Ltd.

Treat those three as a starting point rather than a complete set. Manufacturers hold multiple grantee codes over time, and the authoritative answer is whatever the FCC database returns for the code in front of you. Two caveats: a camera with no radio may carry no FCC ID at all, and a grantee code tells you who obtained the authorization, which is strong evidence of production but is not the same as a signed attestation. Ask for both.

What changed in 2026

The FCC stopped authorizing new covered equipment in 2022, but models authorized before that cutoff kept flowing into the country legally for nearly four years. That window is closed. A rule published July 6, 2026 and effective July 16, 2026 prohibits the importation and marketing of previously authorized covered equipment as well (91 FR 41023).

For a fleet operator the practical effects are supply and replacement, not enforcement against installed hardware. Cameras already on the wall keep working, and nobody is coming to remove them. What changes is that the legitimate replacement stream for covered models is ending, which turns a slow refresh conversation into a scheduled one, and makes the gray-market channel that fills the gap a genuine sourcing risk.

How this list is maintained

Every entry carries its source and the whole dataset carries a verification date, currently August 3, 2026. Entries fall into four buckets, ordered by how strong the evidence is.

  • Named in Section 889. The statute names the company. Primary source, no interpretation required.
  • Owned by a named entity. A brand or controlled company of a named manufacturer, covered by the subsidiary and affiliate language.
  • Reported rebrand. Independent reporting, principally IPVM's public OEM directories, places the brand as a reseller of equipment produced by a named manufacturer. This is a sourcing report, not a legal finding, and it can go stale when a brand changes manufacturer.
  • Not named. The company is not in the statute and not on the FCC Covered List. It is a statement about those two documents and nothing more.

Two limits worth stating plainly. Rebrand relationships are deliberately obscured, so any public list is a floor rather than a ceiling, and the brands documented are the ones somebody took the trouble to test or trace. And brand-level status never settles model-level truth: catalogs mix manufacturers, sourcing changes between generations, and the same brand can carry covered and uncovered lines at once. Where the answer matters, the pair that holds up is an FCC ID lookup plus a written attestation naming the model.

Answering the question across a whole fleet

Checking one camera is a five minute job. The version that actually gets asked is different: an auditor, a prime, or a new client wants to know whether anything covered is installed anywhere across every site you support, and the honest answer for most operators is that nobody is certain. Records were accurate at commissioning. Then a camera failed on a Friday, a tech swapped in whatever was on the van, and the spreadsheet did not move.

MentatNOC keeps that inventory current on its own: what model is actually at each address, what firmware it runs, and when that changed, with the history recorded as it happens rather than reconstructed the week the question lands. It never stores or watches your video. See compliance and proof for how the evidence side works, or walk a live fleet in the interactive demo.

know what is actually installed

The inventory an auditor asks for, current on its own.

Model, firmware, and change history for every camera across every site you support.