NDAA Section 889, FAR 52.204-25, and AI Physical Security: The 2026 Camera Supply-Chain Compliance Briefing for Federal Agencies, Critical Infrastructure Operators, and DoD Contractors
FAR 52.204-25, the FCC Covered List, Section 1260H, NIST SP 800-82r3, and CMMC 2.0 PE controls form a layered regulatory stack. This compliance briefing walks federal procurement officers, critical infrastructure security directors, and DoD primes through what an NDAA-compliant AI physical security stack actually looks like.
NDAA Section 889 camera compliance has stopped being a niche federal-contracting concern and started being a generalized procurement risk for any AI physical security buyer that touches federal funding, critical infrastructure, or defense supply chains. The statute dates to 2019. The enforcement environment around it does not. Between mid-2024 and mid-2026, the FCC has updated the Covered List twice, DoD has begun layering Section 1260H "Chinese Military Companies" restrictions on top of Section 889, and the FAR Council has tightened representation requirements across DoD, DHS, GSA, and the VA.
This compliance briefing is for federal procurement officers, critical infrastructure security directors, DoD prime and subcontractors, state and local agencies receiving federal pass-through funding, and AI physical security vendors selling into those buyers. It covers what FAR 52.204-25 prohibits, what the FCC Covered List adds, how DFARS, NIST SP 800-82r3, and CMMC 2.0 Level 2 layer additional obligations, and what an NDAA-compliant AI physical security stack looks like in practice.
Why the Section 889 enforcement posture changed in 2025 and 2026
Section 889 became binding federal acquisition policy on August 13, 2019. For most of the five years that followed, the compliance burden landed primarily on prime contractors and grantees. Enforcement was uneven, the FCC Covered List moved slowly, and many state and local agencies receiving federal pass-through funding never read the flow-down clauses closely enough to know they were affected.
That posture has changed. Four enforcement vectors converged in late 2025 and early 2026, and any procurement officer responsible for surveillance or AI security purchases needs to understand all four.
First: the FCC Covered List expanded twice in 14 months. The original Covered List, published under the Secure and Trusted Communications Networks Act of 2019, named Huawei, ZTE, Hytera, Hikvision, and Dahua as covered telecommunications equipment producers. In December 2025 the FCC's Public Safety and Homeland Security Bureau issued DA 25-1086, which added all foreign-produced uncrewed aircraft systems and UAS critical components to the Covered List by operation of Section 1709 of the FY2025 NDAA. The Section 1709 expansion specifically names Shenzhen Da-Jiang Innovations (DJI) and Autel Robotics, along with any subsidiary, affiliate, partner, joint-venture participant, or licensee. This matters for physical security because UAS-mounted cameras, perimeter drone patrols, and tethered surveillance UAS are increasingly bundled with AI analytics platforms.
Second: Section 1260H is now layering on top of Section 889. The "Chinese Military Companies" list maintained by the Department of Defense under Section 1260H of the FY2021 NDAA overlaps with but is broader than the Section 889 list. Hikvision and Dahua appear on both lists. Starting in June 2026, DoD prime contractors face additional compliance obligations regarding entities on the 1260H list, with full-flow restrictions expected to take effect in June 2027. For DoD primes and subs, this means the FAR 52.204-25 representation is no longer sufficient on its own, a parallel due-diligence pass against the 1260H list is now required.
Third: CMMC 2.0 made physical-protection assessment a contracting requirement. The Cybersecurity Maturity Model Certification 2.0 Acquisition Rule (48 CFR), which took effect November 10, 2025, requires DoD contractors handling Controlled Unclassified Information to demonstrate compliance with the Physical Protection (PE) family of controls in NIST SP 800-171, including PE.L2-3.10.2. The DoD CMMC Assessment Guide for Level 2 identifies video surveillance, sensors, alarms, and human guards as the mechanisms that satisfy the monitoring obligation. A surveillance system built on covered equipment is not, by itself, an automatic CMMC failure, but a CMMC Level 2 assessor will look at the camera supply chain during physical testing, and a fleet that includes covered telecommunications equipment becomes an avoidable risk factor in the assessment.
Fourth: false-statements exposure on SAM.gov representations is now being treated as enforceable. Federal contractors complete the FAR 52.204-26 representation annually through SAM.gov. Misrepresenting compliance, even unintentionally, exposes contractors to bid protests and, in serious cases, False Claims Act liability. The asymmetric risk profile (a single covered camera in a closet can void a representation covering thousands of contracts) has shifted procurement officer behavior toward whole-fleet inventory audits.
What FAR 52.204-25 actually prohibits, and what it does not
FAR 52.204-25 prohibits the executive branch from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The covered telecommunications equipment list expressly includes video surveillance and telecommunications equipment produced by Hangzhou Hikvision Digital Technology Company, Zhejiang Dahua Technology Company, Hytera Communications Corporation, Huawei Technologies Company, and ZTE Corporation, along with any subsidiary or affiliate of those entities.
The scope is broader than most procurement officers initially read it to be. Three points are worth pulling out.
Section 889 Part B applies whether or not the covered equipment is on the federal contract. Part A of Section 889 prohibits the federal government from buying covered equipment. Part B prohibits the federal government from contracting with any entity that uses covered equipment in any system, anywhere in its operations, regardless of whether that equipment touches federal work. A defense contractor with a Hikvision camera covering its own parking lot in a commercial building is non-compliant for Section 889 Part B purposes, even if no Hikvision camera ever sees a piece of CUI.
The flow-down reaches every subcontractor. Section 889 applies to subcontracts, subawards, grants, and cooperative agreements. A municipal transit authority that receives federal pass-through funding for a transit security project is subject to Section 889 on that project, and the AI vendor selling into it must represent compliance through its own supply chain.
Brand white-labeling does not provide an escape. Hikvision and Dahua own or are the original equipment manufacturer for a long list of secondary brands. A camera sold under a U.S. or European-sounding brand may still be Hikvision or Dahua at the hardware layer. The Section 889 prohibition extends to "covered telecommunications equipment produced by" the named entities, "or any subsidiary or affiliate of such entities", not just to equipment that bears their brand mark. White-label inventory audits are the most common source of Section 889 non-compliance findings in 2025 and 2026.
White-label Hikvision and Dahua cameras hide inside fleets that look NDAA-compliant on paper
The most common Section 889 compliance failure in 2025 and 2026 was not deliberate purchase of Hikvision or Dahua cameras. It was inherited inventory: cameras installed before 2019, cameras inherited through acquisitions, and cameras sold under U.S. or European-sounding brand names that were manufactured by Hikvision or Dahua as the original equipment manufacturer. A complete Section 889 inventory audit requires firmware fingerprinting, MAC OUI lookups, and supply-chain disclosure from every camera vendor, not just brand-name review. Procurement officers running compliance for the first time should plan for a multi-week inventory effort, not a same-week certification.
The layered regulatory stack that camera buyers must read together
FAR 52.204-25 is the most-cited regulation in this space, but it sits inside a stack of overlapping authorities. Buyers and vendors need to read the stack together, because a system can be FAR-compliant and still fail one of the other layers.
Six authorities that govern federal AI physical security camera procurement
A camera fleet that satisfies one layer can still fail another. Compliance is multi-axis, not single-axis.
Hikvision, Dahua, Hytera, Huawei, ZTE, and their subsidiaries and affiliates. Effective August 13, 2019. Applies Part A to federal purchases and Part B to entities that use covered equipment anywhere in their operations.
DoD prime contractors and subs must report any discovery of covered defense telecommunications equipment or services used as a substantial or essential component during contract performance. Discovery during the contract is not a get-out-of-jail card; it is a reporting trigger.
Covered equipment is prohibited from receiving new FCC equipment authorizations. The FCC's December 2025 update added DJI and Autel Robotics drone and UAS critical components under Section 1709 of the FY2025 NDAA, affecting AI security buyers using UAS-mounted cameras.
The Chinese Military Companies list maintained by DoD overlaps with but is broader than the Section 889 list. Hikvision and Dahua appear on both. Restrictions on contracting with entities that lobby for or do business with 1260H entities take effect June 2026 and June 2027.
NIST SP 800-82 Revision 3 (September 2023) covers physical and environmental protection and supply chain security for operational technology, which includes physical access control systems, environmental monitoring, and video surveillance feeding industrial control environments. Revision 4 is in pre-draft and will further align with NIST CSF 2.0.
Defense contractors handling CUI must protect and monitor the physical facility. Video surveillance, sensors, alarms, and human guards are the identified mechanisms. Recording alone is not monitoring; active surveillance is required, and the camera supply chain is now in scope of the third-party C3PAO assessment.
Two implications follow from reading the stack together. The FAR clause is necessary but not sufficient: a DoD prime can certify FAR 52.204-25 compliance, deploy a clean camera fleet, and still fail CMMC 2.0 Level 2 PE controls if monitoring is inadequate or the supply chain is not documented. The universe of "covered" equipment is also expanding. The 2025 FCC drone additions are a signal: as AI physical security extends into UAS, edge compute, and emerging modalities, the regulatory perimeter will keep moving.
Why AI physical security buyers face a sharper compliance problem than legacy CCTV buyers
A legacy CCTV buyer running an analog DVR can answer Section 889 questions at the camera level alone. An AI physical security buyer cannot, because the AI layer is increasingly tightly coupled to the camera. Three architectural patterns sit in the market today, and each has different Section 889 exposure.
AI Physical Security Architectures and Their Section 889 Exposure Profiles
| Architecture | How AI Couples to Camera | Section 889 Exposure | Buyer Diligence Required |
|---|---|---|---|
| Bundled "AI Camera" | AI model runs on camera silicon (on-camera inference) | High, camera and AI are inseparable; covered-hardware finding voids both | Hardware OEM disclosure, firmware fingerprinting, supply-chain audit |
| Vendor Appliance + Vendor Cameras | AI runs on vendor-supplied appliance; vendor also sells the cameras | Medium-High, vendor controls both camera and analytics supply chain | End-to-end OEM disclosure across cameras and appliances |
| Camera-Agnostic AI Layer | AI runs on a dedicated on-premises appliance against any IP camera | Low, AI layer is decoupled; buyer chooses NDAA-compliant cameras independently | Standard camera-level Section 889 audit; appliance OEM disclosure |
| Cloud-Hosted AI | Frames or streams uploaded to vendor cloud for inference | Variable, depends on cloud provider supply chain and data residency | Cloud provider supply-chain due diligence, FedRAMP authorization review, data residency analysis |
For federal buyers and federally-funded buyers, the camera-agnostic AI layer pattern is the architecturally cleanest path. It separates two independent procurement decisions, what camera fleet do we operate, and what AI detection layer do we operate on it, and lets each decision be audited on its own terms. Bundled "AI camera" architectures create a single point of failure: a single covered-hardware finding voids both the camera and the AI investment.
For deeper context on how those architectures compare technically, see the Intelligence report on AI Video Analytics vs. Traditional CCTV, which covers the technical shift from passive recording to real-time detection. The complementary report on AI Physical Security Procurement Compliance covers the broader federal and state regulatory framework that NDAA Section 889 sits inside.
How Section 889 reaches into critical infrastructure even without a federal contract
Critical infrastructure operators, electric utilities, water and wastewater systems, transit and rail, ports, communications networks, and pipeline operators, face Section 889 exposure even when they are not direct federal contractors. Three pathways reach them.
Federal pass-through funding. Department of Energy grid security grants, EPA water utility cybersecurity grants, FTA transit security grants, and DHS critical infrastructure protection grants all carry Section 889 flow-down representations. An electric cooperative that receives any DOE-funded resilience or security grant has to represent Section 889 compliance for the funded project, and in some grant programs, for the entity as a whole.
Federal facility colocation and shared-tenancy contracts. Utilities and transit authorities frequently operate equipment colocated with federal facilities. Section 889 representations on the federal side cascade into the colocation and shared-services contracts, which means the utility's camera supply chain becomes part of the federal facility's compliance audit.
CISA voluntary frameworks and emerging mandates. The Cybersecurity and Infrastructure Security Agency's Secure-by-Design initiative, released in joint guidance with NSA and 19 international partners in 2025, urges software manufacturers to ship secure-by-design and secure-by-default products. CISA also released updated Software Bill of Materials (SBOM) Minimum Elements guidance in 2025, which sets the documentation expectation for software components in critical-infrastructure-adjacent products. While neither is mandatory in the same sense as FAR 52.204-25, both are increasingly being referenced in procurement specifications, and both implicate the camera and AI supply chain.
For sector-specific deployment intelligence, the Critical Infrastructure and Electric Utilities Sector Playbook and Transit, Rail, and Aviation Sector Playbook cover the operational implications in detail.
The economic reality of rip-and-replace for an existing fleet
The single largest installed-base estimate comes from the FCC's Secure and Trusted Communications Networks Reimbursement Program, which was created to fund the removal and replacement of Huawei and ZTE telecommunications equipment from U.S. networks under the Secure Networks Act. When FCC participants completed their initial cost filings, the estimated rip-and-replace cost for telecommunications equipment alone reached approximately $4.98 billion, well above Congress's initial $1.9 billion appropriation. The video surveillance side of the covered equipment list adds an additional, separately tracked replacement burden that has not been comprehensively quantified at the federal level.
For an individual organization, the economic reality is sharper. The four cost categories that drive total rip-and-replace cost are:
Hardware Replacement
Per-camera replacement runs from approximately $400 for a basic compliant IP camera to $1,800+ for a higher-resolution, low-light, or pan-tilt-zoom unit. A 250-camera fleet replacement is a six- to seven-figure hardware procurement event before installation labor is added.
Installation and Cabling
If existing cabling, PoE infrastructure, and mounting hardware can be retained, labor cost is modest. If covered equipment was deployed with proprietary cabling or PoE specifications that do not match NDAA-compliant replacements, the project becomes a partial network re-architecture.
VMS and Integration Re-Work
Some legacy VMS deployments are tightly coupled to specific covered-equipment camera models. The VMS may continue to function with replacement cameras, but advanced features such as PTZ control, on-camera analytics passthrough, and edge motion detection may need re-integration. Budget 10 to 25 percent of hardware cost for integration re-work.
Compliance Audit and Documentation
A defensible Section 889 compliance posture requires written inventory documentation, supplier OEM disclosure letters, and an annual representation refresh. Many organizations also retain external counsel or a specialty compliance firm for the initial inventory pass. This line item is small relative to hardware, but it is real and recurring.
A buyer planning a rip-and-replace project should consider deploying the camera-agnostic AI detection layer at the same time. The marginal cost of adding an AI appliance during a fleet replacement is lower than running it as a separate project later, because cabling, PoE planning, and VMS integration are already in motion. The economic case for converging both efforts is covered in the Intelligence report on AI Physical Security Total Cost of Ownership.
What an NDAA-compliant AI physical security stack actually looks like
A compliant stack pairs three independent decisions: an NDAA-compliant camera fleet, a camera-agnostic AI detection layer running on a dedicated on-premises appliance, and a video management system that is itself either compliant or replaceable without affecting the AI layer.
Cameras. Axis Communications, Bosch Security, Hanwha Vision, Avigilon (Motorola Solutions), i-PRO, Pelco, FLIR (Teledyne FLIR), and Verkada are the most commonly procured NDAA-compliant camera lines for federal and federally-funded buyers in 2025 and 2026. Each maintains an NDAA compliance statement at the model-line level; buyers should request the statement for the specific SKU being procured, not just the brand. Cameras manufactured before the brand was known to be NDAA-clean may still be in inventory as legacy stock.
VMS. Milestone XProtect, Genetec Security Center, Avigilon Control Center, and several smaller VMS platforms are widely deployed with NDAA-compliant cameras. The VMS itself rarely raises Section 889 concerns directly, but VMS-vendor supply-chain documentation is increasingly requested during CMMC and federal audits.
AI detection layer. A dedicated on-premises appliance running computer vision detection against the VMS's existing camera feed is the architecturally cleanest option for federal and critical-infrastructure buyers. The appliance is independent of the camera supply chain, which means a future camera-fleet replacement does not require an AI-layer reprocurement. The detection layer should perform object-, posture-, and motion-pattern detection without performing facial recognition, without storing video, and without sending frames to the cloud for inference, the privacy and supply-chain posture that aligns most cleanly with federal and critical-infrastructure compliance frameworks.
For a broader treatment of how the detection layer fits inside a security operations center, see the Intelligence report on the Agentic Security Operations Center Architecture Reference. For the technical reference on how the detection itself works, see How AI Gun Detection Works.
Why architecture choices made for Section 889 also satisfy biometric privacy regimes
The same architectural choices that simplify NDAA Section 889 compliance, on-premises detection, no cloud roundtrip, no facial recognition, no biometric template, no stored video, also align with the patchwork of state biometric privacy laws covered in the Intelligence report on Biometric Privacy Compliance for AI Physical Security. Buyers planning a federal-facing deployment can specify a single architectural posture that satisfies BIPA (Illinois), CUBI (Texas), MHMDA (Washington), and emerging state biometric statutes alongside the federal supply-chain framework, rather than designing two parallel privacy and security architectures.
The Section 889 vendor due-diligence checklist
An AI physical security vendor selling into federal or federally-funded buyers should be able to answer the following questions in writing. Procurement officers running their first NDAA-compliant deployment can use this list as the spine of a vendor RFI.
Section 889 and Camera Supply-Chain Vendor Due-Diligence Checklist
| Question | Why It Matters | Acceptable Answer Form |
|---|---|---|
| Does any hardware in your AI physical security stack, including cameras, appliances, edge compute, and accessories, include components produced by Hikvision, Dahua, Hytera, Huawei, ZTE, or any subsidiary or affiliate? | Direct FAR 52.204-25 covered-equipment question | Written "No" with OEM disclosure documentation |
| Are any of the entities in your camera supply chain on the DoD Section 1260H Chinese Military Companies list? | 2026/2027 DoD restrictions take effect on top of Section 889 | Documented supply-chain mapping against current 1260H list |
| Does your AI detection layer perform on-premises inference, or are video frames or streams sent to a cloud service for processing? | Data residency, FedRAMP, and CISA Secure-by-Design alignment | Architecture diagram and data-flow disclosure |
| Does your platform perform facial recognition or compute biometric templates? | Biometric privacy regime exposure and PE-family CMMC considerations | Written architectural statement and DPIA-style data-element inventory |
| Do you provide a Software Bill of Materials for the AI detection software, and is it maintained according to the 2025 CISA SBOM Minimum Elements? | Critical-infrastructure procurement and DoD CMMC supply-chain expectations | Current SBOM in CycloneDX or SPDX format, updated per release |
| Does your platform hold DHS SAFETY Act Designation or Certification under the Safety Act of 2002, and at what tier? | Counter-terrorism liability protection alongside FAR compliance | Written designation letter and SAFETY Act office reference number |
The DHS SAFETY Act question is worth treating as a separate compliance axis rather than as a marketing badge. The Intelligence report on The DHS SAFETY Act in AI Security walks through what Designation and Certification each mean and why the distinction matters for federal-facing buyers.
Frequently asked questions about NDAA Section 889 camera compliance
Does NDAA Section 889 apply to my organization if we are not a federal contractor?
It can apply indirectly. Section 889 Part B prohibits the federal government from contracting with entities that use covered equipment anywhere in their operations, which means many subcontractors, grant recipients, and sub-recipients fall in scope even without a direct federal contract. Critical infrastructure operators receiving federal pass-through funding through DOE, EPA, FTA, or DHS programs typically inherit Section 889 representations on those funded projects, and in some grant programs the representation extends to the entity as a whole.
Are there any exceptions or waivers under Section 889 for covered video surveillance equipment?
FAR 52.204-25 includes a narrow waiver pathway, but the practical waiver yield rate has been low. The Director of National Intelligence may grant waivers in limited national security circumstances, and individual agency heads have limited waiver authority for specific contracts. For most federal buyers, planning for compliance without relying on a waiver is the operational default. The Section 889 Policies page on Acquisition.gov tracks the current waiver state.
Does Section 889 require us to remove existing Hikvision or Dahua cameras that were installed before 2019?
Section 889 is forward-looking on procurement, but Part B's prohibition on contracting with entities that use covered equipment means existing inventory becomes a contracting risk over time. Most federal contractors, grant recipients, and critical-infrastructure operators have either replaced their existing covered cameras or are in the process of doing so. The FCC's $4.98 billion estimate for telecommunications rip-and-replace illustrates the scale of the equivalent burden on the broader covered-equipment universe.
How does the FCC Covered List relate to FAR 52.204-25?
They are independent authorities that often overlap on the same equipment. FAR 52.204-25 governs federal procurement. The FCC Covered List governs FCC equipment authorization for new devices entering the U.S. market. A camera can be on the Covered List but not on the FAR 52.204-25 covered list, or vice versa. The two lists have moved more closely in lockstep since 2024, but buyers should not assume that compliance with one automatically implies compliance with the other.
Do CMMC 2.0 PE controls require AI-powered video surveillance specifically?
No. PE.L2-3.10.2 requires that the physical facility and support infrastructure for organizational systems be protected and monitored. Video surveillance, sensors, alarms, and human guards are the mechanisms the CMMC model identifies as acceptable. AI-powered detection is not required, but recording-without-monitoring does not satisfy the control. A facility that records video but has no operational monitoring layer fails the practice. AI detection provides one defensible path to the monitoring obligation, and is increasingly attractive given the assessment expectations on staffing and continuous oversight.
How does an AI physical security vendor demonstrate Section 889 compliance to a federal buyer?
The defensible compliance package includes a written representation, OEM disclosure for every hardware component in the offered solution, a current SBOM aligned to the 2025 CISA SBOM Minimum Elements, and an architectural statement covering data flow, inference location, and any cloud dependencies. Increasingly, federal buyers also request supply-chain mapping against the Section 1260H Chinese Military Companies list and disclosure of any subsidiary or affiliate relationships with covered entities. The vendor RFI checklist in this report covers the questions buyers should expect to ask.
Does a camera-agnostic AI detection layer create any Section 889 exposure of its own?
Only at the appliance level. A dedicated on-premises detection appliance has its own hardware bill of materials, and that bill of materials needs Section 889 review like any other federal procurement. A clean appliance running against an NDAA-compliant camera fleet provides the cleanest architectural compliance posture: two independent procurement decisions, two independent supply-chain audits, and no entanglement between the camera replacement cycle and the AI detection investment.
Continue the research
NDAA Section 889 compliance sits inside a broader federal regulatory framework that AI physical security buyers should read together rather than piece by piece. The following Intelligence reports cover adjacent pieces of that framework in depth.
- AI Physical Security Procurement Compliance, the broader federal and state regulatory framework, including GAO findings on federal AI acquisitions and emerging state procurement statutes.
- The DHS SAFETY Act in AI Security, the distinction between Designation and Certification under the Safety Act of 2002, and why the tier matters for federal-facing buyers.
- Biometric Privacy Compliance for AI Physical Security, how state biometric privacy laws interact with federal supply-chain requirements, and the architectural choices that satisfy both.
- Critical Infrastructure and Electric Utilities Sector Playbook, the operational implications of Section 889 and CISA frameworks for grid operators.
- Government and Public Buildings Sector Playbook, federal facility, ISC, and municipal compliance considerations end-to-end.
Federal procurement officers, critical infrastructure security directors, and DoD primes evaluating their NDAA-compliant AI physical security stack can request a structured compliance assessment covering supply chain, architectural posture, and SAFETY Act alignment for their specific operating environment.
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Section 889 Compliance Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment