VideoCybersecurity

A reference for securing video infrastructure

Procurement rules that now govern surveillance equipment

The exact scope and effective dates of the rules that decide which cameras a buyer may lawfully install, and the points where the record runs out.

Published 5 September 2026Sources 18

The video-surveillance limb of Section 889 carries a purpose clause on its face. Covered equipment includes, at 889(f)(3)(B), "For the purpose of public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities)". Huawei and ZTE sit one subparagraph earlier at (f)(3)(A), with no purpose limitation at all. It has been in Pub. L. 115-232 since enactment on 13 August 2018, and every rule built on the statute inherits it.

The two prohibitions, and who each one binds#

Subsection (a)(1)(A) stops an executive agency procuring covered equipment; (a)(1)(B) stops the government contracting with an entity that uses it. Section 889(c) set the first at one year after enactment and the second at two, which FAR 52.204-25 recites as "on or after August 13, 2019" and "on or after August 13, 2020".

The off-contract reach belongs to one paragraph of that clause. Paragraph (b)(2), implementing 889(a)(1)(B), says the prohibition "applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract." Paragraph (b)(1) is the narrower one: a contractor may not supply the Government anything using covered equipment as a substantial or essential component — "any component necessary for the proper function or performance of a piece of equipment, system, or service".

2 CFR 200.216 carries the same bar into federal grants and loans, reaching school districts, transit agencies and hospitals that hold no federal contract. The one carve-out, at 889(a)(2)(B), turns on traffic handling rather than video: equipment "that cannot route or redirect user data traffic or permit visibility into any user data or packets that such equipment transmits or otherwise handles".

What the FCC can and cannot authorise#

The Public Safety and Homeland Security Bureau published the first Covered List on 12 March 2021 (DA 21-309), naming Huawei, ZTE, Hytera, Hikvision and Dahua; the Hikvision and Dahua entries reproduce the purpose limitation and extend to subsidiaries, affiliates and services "provided by such entities or using such equipment." Report and Order FCC 22-84 (88 FR 7592, effective 6 February 2023) barred authorisation, marketing and importation of listed equipment, holding that for those three the Commission "cannot and will not approve any application for equipment authorization that would allow the marketing and selling of such equipment for those specified uses" until each had a compliance plan approved.

The Commission's definition of critical infrastructure did not survive review. In Hikvision USA, Inc. v. FCC, 97 F.4th 938 (D.C. Cir., 2 April 2024), the court upheld the order so far as it prohibits authorisation for physical security surveillance of critical infrastructure, but vacated the portions defining "critical infrastructure" — a definition reaching anything "connected to" sixteen PPD-21 sectors and fifty-five national critical functions, which the panel called "overbroad, unexplained, and arbitrary". The listing itself stood, ratified by the Secure Equipment Act.

No compliance plan has been approved since, which is a stall rather than a refusal. In the Commission's words on 26 June 2026, that is "because the Commission's definition of critical infrastructure was the subject of litigation," and 2021-listed equipment "has not received authorization since November 11, 2022." A Second Further Notice (90 FR 55826, 4 December 2025) proposed a replacement drawn from 42 U.S.C. 5195c(e), calling its adoption "a precondition to the review and approval of any compliance plans".

The same June notice (DA 26-635; 91 FR 41023, 6 July 2026) closed the back door on old stock: from 16 July 2026 the importation and marketing of previously authorised covered equipment listed in 2024 or earlier is prohibited, including units authorised before the 2022 rules. For the 2021 entries it runs to public safety, government facilities and "other national security purposes"; the critical-infrastructure prong is suspended pending a definition. It reaches neither equipment in end users' hands nor anything listed after 2024.

FCC 25-71 (adopted 28 October 2025; 90 FR 53227, effective 26 December 2025) tightened what counts as covered. It read "produced by" as reaching past manufacture and assembly, held that "re-branding or 'white labeling' of any covered equipment does not change the status of whether the equipment is covered equipment", and added a new 47 CFR 2.903(b) barring authorisation of "All equipment that incorporates equipment meeting the descriptions in paragraph (a)(1) or (2)". The prohibitions now also cover modular transmitters, SDoC devices and equipment exempt from authorisation. Anyone buying rebadged hardware should ask which legal entity is the SDoC responsible party or certification applicant, since the Commission ordinarily treats that party as among the producers.

Two enforcement actions on the record#

On 20 April 2026 the FCC's Enforcement Bureau issued a Notice of Violation to Hangzhou Hikvision and Hikvision USA (DA 26-382), finding that 10 test reports "did not validly support the authorization under which Hikvision marketed the associated model" — emissions above the 47 CFR 15.107/15.109 limits, or tests run under the wrong parameters. That is an authorisation-integrity finding, but note the route: the equipment was authorised by self-declaration under SDoC, which is what FCC 25-71 pulled inside 2.903. We could not establish the model numbers or whether a forfeiture proceeding followed.

Two months earlier the Commission had adopted a Notice of Apparent Liability (FCC 26-7, 12 February 2026) proposing a $188,491 penalty against Zhejiang Dahua for missing the 8 March 2023 deadline to file contact information for its Covered-List subsidiaries and affiliates, in apparent violation of 47 CFR 2.903(d). An NAL proposes a penalty rather than imposing one, and we could not confirm whether this one became a final forfeiture order.

Still only a proposal#

A Third Further Notice (FCC 26-50, 91 FR 51139, published 7 August 2026) asks about SBOM and HBOM disclosure, term limits on equipment authorisations, SDoC registration, a US-based liable party for certified equipment, and prohibitions or presumptions against authorising equipment containing Covered List components or software. Comments were due 8 September 2026, replies 21 September. Nothing in it is law yet.

What the Entity List actually restricts#

BIS added both companies at 84 FR 54002, effective 9 October 2019, and 15 CFR Part 744, Supplement No. 4 still requires a licence for all items subject to the EAR — presumption of denial for Dahua throughout, and for Hikvision outside a short list of case-by-case ECCNs.

That is an export control: the licence requirement bites on shipping items subject to the EAR to those entities, and says nothing about a US organisation buying or installing their cameras, which is the work Section 889 and the FCC rules do. Tender documents conflate the two routinely. The Department of Defense's own contracting bars are tabulated on physical security and cybersecurity.

Britain's test is the jurisdiction of the maker#

In a written ministerial statement on 24 November 2022 (HCWS386), the Chancellor of the Duchy of Lancaster, Oliver Dowden, said that following a Government Security Group review, "Departments have therefore been instructed to cease deployment of such equipment on to sensitive sites, where it is produced by companies subject to the national intelligence law of the People's Republic of China." The criterion is the manufacturer's legal jurisdiction rather than a named-company list, and it binds the Government estate's sensitive sites.

The UK's product rule is vendor-neutral. S.I. 2023/1007, in force since 29 April 2024 UK-wide, excepted five categories in Schedule 3 as made; S.I. 2025/211 added three vehicle categories from 25 February 2025 in Great Britain only. Network cameras, NVRs and DVRs appear in no version of that schedule, and an IP camera is an internet-connectable product under PSTI Act 2022 s.5(1)-(2), so Schedule 1 binds it: passwords unique per product or user-defined, which a shared non-default password fails, plus a published vulnerability-reporting contact and minimum security-update period. We found no enforcement action against a camera manufacturer under it.

The dates the CRA and RED set#

There is no EU equivalent of Section 889: the Cyber Resilience Act and the RED delegated act carry no country-of-origin or named-company provision at all, and we found no primary source for any member-state ban, so we assert none.

Article 71 of Regulation (EU) 2024/2847 stages the CRA: it applies from 11 December 2027, Chapter IV from 11 June 2026, and Article 14 — reporting actively exploited vulnerabilities and severe incidents to ENISA and the relevant CSIRT — from 11 September 2026. Annex III Class I item 17 then covers "Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems", which on its face does not name professional IP cameras, NVRs or VMS; those fall to the default category unless another line catches them, such as item 6, network management systems.

Radio equipment is on a different clock. Delegated Regulation (EU) 2022/30 made RED Article 3(3)(d), (e) and (f) applicable to internet-connectable radio equipment; (EU) 2023/2444 moved the application date from 1 August 2024 to 1 August 2025; (EU) 2026/339 repeals 2022/30 with effect from 11 December 2027. Between 1 August 2025 and 11 December 2027 a camera with a Wi-Fi or cellular radio sits under RED. A camera whose only connection is PoE has no radio, so RED never reaches it.

Where the record stops#

Two things a buyer may want to assert cannot be verified as of 5 September 2026. The FCC's Covered List page refused automated retrieval (HTTP 403), so every quotation here comes from DA 21-309 and from Federal Register texts quoting it; entries added after 2021 sit outside what we confirmed. Whether a final critical-infrastructure definition has been adopted since the April 2024 remand is likewise unresolved: as of the 6 July 2026 notice it did not exist, so anyone saying that prong of the ban is live is ahead of the record. None of this is legal advice.

Assurance also has to come from the right document: CISA's Secure by Design Pledge is voluntary, and its stated scope is enterprise software, cloud services and SaaS — IoT hardware and consumer products sit outside it. None of these instruments says whether the firmware on a device is still maintained: see end-of-life cameras and camera vulnerability management. Per-model vulnerability history sits at camerarisk.com.

Sources

  1. Public Law 115-232, Sec. 889 — Prohibition on Certain Telecommunications and Video Surveillance Services or Equipment. U.S. Congress (congress.gov), 2018-08-13
  2. 48 CFR 52.204-25 — Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (NOV 2021). eCFR, 2021-11
  3. 2 CFR 200.216 — Prohibition on certain telecommunications and video surveillance equipment or services. eCFR, undated
  4. FCC Public Notice DA 21-309 — Publication of the List of Equipment and Services Covered by Section 2 of the Secure Networks Act. Federal Communications Commission, 2021-03-12
  5. 88 FR 7592 — Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program (FCC 22-84, Final Rule). Federal Register, 2023-02-06
  6. Hikvision USA, Inc. v. FCC, No. 23-1032 (D.C. Cir.), 97 F.4th 938. U.S. Court of Appeals for the D.C. Circuit, 2024-04-02
  7. 90 FR 53227 — FCC 25-71, Second Report and Order, ET Docket No. 21-232. Federal Register, 2025-11-25
  8. 90 FR 55826 — FCC 25-71 Second Further Notice of Proposed Rulemaking, ET Docket No. 21-232. Federal Register, 2025-12-04
  9. 91 FR 41023 — Prohibiting Importation and Marketing of Previously Authorized Covered Communications Equipment Added to the Covered List in 2024 or Earlier (DA 26-635). Federal Register, 2026-07-06
  10. 91 FR 51139 — Third Further Notice of Proposed Rulemaking (FCC 26-50), ET Docket No. 21-232. Federal Register, 2026-08-07
  11. FCC 26-7 — Notice of Apparent Liability for Forfeiture, Zhejiang Dahua Technology Co., Ltd.. Federal Communications Commission, 2026-02-19
  12. DA 26-382 — Notice of Violation to Hangzhou Hikvision Digital Technology Co., Ltd and Hikvision USA, Inc.. FCC Enforcement Bureau, Spectrum Enforcement Division, 2026-04-20
  13. 15 CFR Part 744, Supplement No. 4 — Entity List. eCFR, current
  14. Hansard Written Statement HCWS386 — Security Update on Surveillance Equipment. UK Parliament (Hansard API), 2022-11-24
  15. The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, Schedule 3. legislation.gov.uk, 2023
  16. Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71 and Annex III. EUR-Lex, 2024-11-20
  17. Commission Delegated Regulation (EU) 2026/339 repealing Delegated Regulation (EU) 2022/30. EUR-Lex, 2026-04-29
  18. Secure by Design Pledge. CISA, undated