Trusted technology connects government, education, critical infrastructure, public safety, and private enterprise. |
Organizations evaluating video surveillance technology frequently encounter the term “NDAA compliant.” But what does it mean, and why should it matter when selecting cameras, recorders, software, or a complete security system? The answer has become more complex as federal requirements have evolved. Understanding the differences among NDAA procurement restrictions, the FCC Covered List, and equipment-authorization rules can help organizations make better-informed decisions about procurement, cybersecurity, supply-chain risk, and long-term system planning. What Is the NDAA?The National Defense Authorization Act, or NDAA, is annual federal legislation that establishes policies and funding priorities for the U.S. Department of Defense. Section 889 of the FY 2019 NDAA restricts federal agencies from procuring, obtaining, or using certain telecommunications and video surveillance equipment and services from designated companies. These restrictions can also affect organizations that contract with the federal government. The provisions were introduced in response to national-security, cybersecurity, and supply-chain concerns. How Have the Requirements Evolved?The current compliance landscape developed through several related federal actions. 2018–2019: Federal procurement restrictionsSection 889 of the FY 2019 NDAA established restrictions on federal procurement and use of covered telecommunications and video surveillance equipment and services. The restrictions identify equipment and services associated with designated manufacturers and can extend to certain subsidiaries, affiliates, and components. For federal contractors, the rules may affect more than equipment used directly on a government project. Depending on the applicable contract requirements, an organization’s use of covered technology elsewhere in its operations may also be relevant. 2021–2022: The FCC Covered List and new authorization rulesThe FCC published its initial Covered List in 2021 under the Secure and Trusted Communications Networks Act. The list identifies communications equipment and services determined to pose an unacceptable risk to U.S. national security or to the security and safety of U.S. persons. In November 2022, the FCC adopted new equipment-authorization rules implementing the Secure Equipment Act of 2021. These rules prevent the FCC from approving new equipment authorizations for products on its Covered List. This expanded the practical impact beyond direct federal purchasing. Many devices that emit radio-frequency energy require FCC authorization before they can legally be imported or marketed in the United States. The 2022 order did not automatically revoke every previously issued equipment authorization or impose a blanket prohibition on possessing previously purchased equipment. However, NDAA restrictions, contract terms, funding conditions, or organizational policies may still prohibit the purchase or use of those products. Read the FCC’s 2022 equipment-authorization order. 2025: Additional drone and surveillance provisionsSection 1709 of the FY 2025 NDAA required a national-security evaluation of communications and video surveillance equipment and services associated with DJI Technologies and Autel Robotics. The provision also addresses specified subsidiaries, affiliates, partners, joint ventures, technology-sharing relationships, and services—including software—provided by those entities or using their equipment. Following the required national-security determination, the FCC added the equipment and services identified under Section 1709 to its Covered List in December 2025. The FCC action also addressed foreign-produced uncrewed aircraft systems and critical drone components, subject to subsequent exemptions and updates. This development is especially relevant to drones and aerial-surveillance technology. It also reinforces an important point for every security-system buyer: compliance requirements can change. Organizations should verify current product-level information and consult the latest FCC Covered List rather than rely solely on an older compliance statement. Read Section 1709 in the enacted FY 2025 NDAA. Read the FCC’s December 2025 public notice. What Does “NDAA Compliant” Mean?In the security industry, “NDAA compliant” generally describes equipment that does not use prohibited telecommunications or video surveillance products or components identified under Section 889. Non-compliant equipment may include technology from a prohibited manufacturer or incorporate restricted components. This can make it ineligible for certain federal uses, federally funded projects, or government contracts. However, NDAA compliance and FCC authorization are not interchangeable.
A product may therefore require evaluation under more than one regulatory framework. Why Compliance Matters Government procurement requirementsFederal agencies and organizations working under certain federal contracts may be required to use compliant equipment. Choosing an ineligible product could cause procurement delays, contract issues, lost project opportunities, or costly system replacements. Broader market implicationsFollowing the FCC’s 2022 action, the issue extends beyond federal purchasing. Covered equipment may be unable to receive the FCC authorization normally required for new products to be imported or marketed in the United States. Supply-chain visibilityCompliance encourages buyers to examine who manufactures a product, where it is produced, and where its critical components originate. This visibility can support a more deliberate approach to supply-chain and technology risk. Cybersecurity considerationsNDAA compliance does not guarantee that a product is cybersecure. However, evaluating compliance can complement a broader cybersecurity program that includes product vetting, vulnerability management, network segmentation, and controlled access. Future procurement flexibilityAn organization may not require compliant equipment today, but its needs can change. Selecting compliant technology may make it easier to pursue future government contracts, participate in federally funded projects, enter regulated markets, or expand into more security-sensitive environments. Who May Need NDAA-Compliant Equipment?Organizations that commonly require or prioritize compliant solutions include:
Requirements vary by organization, contract, funding source, equipment type, and intended application. Buyers should review the rules applicable to their project rather than assume every organization within an industry has identical obligations. Common Misconceptions “NDAA compliant” means “cybersecure”Compliance addresses specific procurement and supply-chain restrictions. It is not a cybersecurity certification or a guarantee that equipment is protected against every threat. A secure surveillance deployment still requires:
Section 889 focuses heavily on federal procurement and contracting. However, the FCC’s equipment-authorization rules have broader market implications because they affect whether covered products can receive new authorizations. Private organizations may also select compliant systems voluntarily to strengthen procurement standards, reassure stakeholders, or preserve eligibility for future projects. Compliance applies only to camerasA surveillance system includes more than its cameras. Organizations may also need to evaluate:
Compliance should be confirmed for the exact model under consideration—not simply the manufacturer or product family. Compliance status may differ across products within the same portfolio. Buyers should request current written documentation and determine whether the exact equipment or manufacturer is affected by the FCC Covered List or other applicable restrictions. Every component must be made in the United StatesNDAA compliance does not necessarily mean that every product or component must be manufactured in the United States. The analysis generally focuses on whether prohibited equipment, services, manufacturers, or components are involved. Separate requirements, including the Trade Agreements Act, Buy American rules, contract terms, or agency-specific standards, may impose additional country-of-origin obligations. Previously authorized equipment was automatically banned in 2022The FCC’s 2022 order prohibited new authorizations for covered equipment. It did not automatically revoke all previously granted equipment authorizations. That distinction does not make previously authorized equipment acceptable for federal procurement. NDAA restrictions, contract terms, funding conditions, and organizational policies may still prohibit its purchase or use. Questions to Ask Before Purchasing EquipmentWhen evaluating a surveillance solution, ask:
Clear, documented answers can help prevent procurement complications later. Compliance and Long-Term PlanningMany organizations treat compliance as part of a broader technology and risk-management strategy. Potential benefits include:
Compliance should be considered early in the system-design process, particularly for technology expected to remain in service for many years. Organizations should also establish a process for reviewing compliance throughout the system’s lifecycle. A product that met applicable requirements when purchased may be affected by later legislative, regulatory, or Covered List changes. Looking Beyond ComplianceNDAA compliance is important, but it should not be the only selection criterion. Organizations should also evaluate:
The strongest surveillance solution balances compliance with security, performance, usability, reliability, and long-term operational needs. How Digital Watchdog Can HelpDigital Watchdog offers a portfolio of NDAA-compliant cameras, recorders, servers, accessories, and surveillance solutions for government agencies, critical infrastructure operators, educational institutions, and private businesses. Organizations should confirm compliance for each proposed model using current product documentation. Digital Watchdog maintains a model-level compliance list and product-selection filter to support this process. View Digital Watchdog’s NDAA compliance information. Combined with recording solutions, myDW Health Monitoring Service and DW Spectrum IPVMS, these products can help organizations build modern video surveillance systems while addressing applicable procurement and compliance considerations. NDAA compliance is more than a checkbox. When evaluated alongside FCC requirements, cybersecurity, operational performance, and long-term planning, it can contribute to a more secure, scalable, and future-ready surveillance strategy. This article provides general information and is not legal or procurement advice. Requirements, Covered List entries, and exemptions can change. Organizations should confirm the rules applicable to their contracts, funding sources, products, and intended uses. |