NDAA Compliance

A Guide to NDAA
Compliance: What is
NDAA Compliance?

 

In this blog, we will be providing some guidance to

NDAA Compliance and its impact on the surveillance industry.

 

You have probably heard about the NDAA ban, or blacklist. The US Government has implemented a fairly wide-ranging act that prohibits using, buying or selling surveillance products that are manufactured by, or use components made by specific companies. We will discuss and list these companies below for you. Due to the language in the NDAA Section 889, OEM companies that purchase from the banned manufacturers would also be non-compliant. Therefore, it is important to understand which products are using components or relabeling surveillance equipment, from a banned manufacturer.

What is NDAA Compliance?

 

In short, the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year 2019 was signed into law in August of 2018 and subsequently NDAA 2020 for this year.

 

The law, specifically Section 889, prohibits federal agencies, their contractors and grant or loan recipients from procuring or using “telecommunications and video surveillance equipment or services” from specific Chinese companies as a “substantial or essential component of any system, or as critical technology as part of any system.” The NDAA ban includes telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation, as well as video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company. Therefore, for equipment to be NDAA Compliant, products must be free of any hardware, chipsets, SoC, or other materials from any of the companies listed on the Banned List.

There are 3 Essential Parts to Section 889:

 

1. Procurement: This bans federal agencies from purchasing or procuring covered equipment or services

2. Blacklist Clause: This bans federal agencies from doing business with companies that use covered equipment or services

3. Funding: This prohibits Federal money or ‘funding’ to be used to purchase covered equipment or services

 

In essence, the law was motivated by concerns over cyber attacks exploiting potential ‘backdoor’ issues in specific Chinese made components and equipment. However, that is a simplified version of the wide-ranging issues the law attempts to address.

What does that mean for Security Installers and Integrators?

 

If you have ever installed surveillance equipment for government facilities, then you know there is always an extra amount of planning.

 

With the new NDAA Requirements, there is an extra bit of care involved, specifically in choosing the right Security Cameras and Recorders that are NDAA Compliant. In short, if you are installing Security Cameras in a Federal Facility, or a job that is Federally Funded, you cannot use any of the banned equipment. This includes anything from entire manufacturers to components used in specific devices. In order for you to be compliant with section 889 of the NDAA law, you may not use equipment, or equipment that uses the components manufactured by any of the following companies:

Huawei Technologies
ZTE Corporation
Hanzhou Hikvision Digital Technology
Dahua Technology Company
Hytera Communication Corporation

What is immediately obvious from this?

 

You cannot install any Hikvision or Dahua security products in government facilities.

 

For any company on the banned list, this means that everything in their product line is non-compliant. However, it also means the following: If a company is not on the banned list, but uses a component in their device, that comes from a banned company, it is also NOT Compliant. You should keep in mind that it may be difficult to determine whether specific products from other brands are compliant. The most common example of this in surveillance applications is the use of the HiSilicon Chipset (manufactured by Huawei). Numerous manufacturers or ‘brands’ of surveillance equipment, have been using Huawei HiSilicon SOC Chipsets in their IP Cameras and NVRs. The SOC or ‘System on a Chip’ is the intelligent portion of your security device. It is important to make sure that any device you plan to install is not using HiSilicon chipsets. In addition, many of our Dealers and Integrators also install telecommunications equipment. The law specifically bans the use of any telecommunication equipment manufactured by Huawei and ZTE.

How do I make sure my Security Cameras
are NDAA Compliant?

 

Check our inventory for NDAA Compliant systems

Indications of common manufacture:

 

Have you ever wondered how two different manufacturers wind up using the same phone app? That can be an indication that they are both manufactured by the same company. A supplier or distributor should be transparent, as well as being able to tell you the origin of the products they are selling. However, not all of them are, or will.

 

 

OEM Companies

 

For a pretty extensive reference, you can view the IPVM list of companies that sell rebranded Hikvision product here: Hikvision OEMs In addition, you can view the IPVM list of rebranded Dahua products here: Dahua OEMs In summary, here are the 3 things you should look out for when bidding a government job:

 

1. Do not use any product from the specifically banned companies

2. Do not use any product that uses components from the banned companies

3. Ask for a List of NDAA Compliance before bidding a particular manufacturer

An Important to Note regarding NDAA and State Government Projects

 

You should keep in mind that the law affects only Federal Projects currently.

 

However, some states have considered extending the ban to state government purchases. Individual states may ban companies included in the NDAA on a state level. In fact, Vermont has already decided to adopt the tenets of the NDAA act. The state has instituted a government wide ban on equipment or technology from the banned companies. It seems likely that other states may follow suit. Therefore, it is important for you to check all applicable state laws when installing in a government facility. It may also be wise, if you are unsure, to just use NDAA Compliant Cameras regardless. Using NDAA Compliant products will future proof your installation.

Real Life Example on the importance of NDAA

 

We have seen a scenario where a government organization would not complete a purchase order with a construction materials supplier without confirming that their NVR was NDAA Compliant. Thankfully, this client had installed Uniview NDAA compliant Cameras and NVRs. We feel that a scenario such as this really drives home the nature of how this law will affect US companies. In other words, if you own a business that wants to do business with the Federal Government, you may need NDAA compliant surveillance in your facility.

Are all products from certain countries banned?

 

Some in the industry have expressed confusion as to the scope of the NDAA ban.

 

The ban is related to named companies, not the country of origin (manufacturing location) of video surveillance products or components. Although all of the companies on the ban list are based in China, and this may be the reason for the confusion. Country of Origin is not a determination of NDAA Compliance, just as it is not a determination of the opposite.

Which Security Cameras are NDAA Compliant? Which Cameras can you install in Federal Government Facilities?

 

There are currently several options available for NDAA Compliant Surveillance equipment.

 

At ROVR Technology, we realized early on that keeping NDAA compliant Cameras in stock would be essential to our Dealers. We made the decision to bring in a wide variety of IP Cameras and NVRs that can be installed in Federal Facilities. In addition, we have been adding new NDAA models regularly, and will continue to do so. Uniview NDAA Compliant IP Cameras and NVRs: Uniview was also quick to realize the importance of having NDAA compliant options available early on. While we still have many of the previous models in stock, we currently offer a large selection of IP Cameras and NVRs that are compliant.

ROVR Technology policy and strategy on NDAA

 

ROVR Technology’s policy for NDAA compliance as it relates to our clients:

 

As congress continues to mull over the details of NDAA compliance and specifically section 889, it is likely that changes will be forthcoming. We know that you are engaged in running your business. As your equipment supplier, we will do everything possible to keep up with changes or expansions in NDAA policy and how it affects you, our client. In addition, we will continue to expand our line of NDAA compliant surveillance equipment, so you have plenty of options. It is our ultimate goal, to be much more than a box mover. At ROVR Technology, we know that you expect more, and we continually strive to exceed your expectations.

 

If you would like more information on our NDAA Compliant Products, or just want to chat:

Call :903-340-6574

CONTACT US HERE