[Home](/)/[Resources](/resources)/Section 889 Banned Components

USFederalRegulation guide

# Section 889 NDAA — Banned Telecom and Surveillance Components

Section 889 of the National Defense Authorization Act for Fiscal Year 2019 prohibits federal agencies from procuring — and contractors from using — telecommunications and video surveillance equipment from five named Chinese manufacturers and their subsidiaries and affiliates. For hardware companies supplying the US federal market or their contractors, Section 889 compliance requires component-level due diligence that goes far beyond tier-1 supplier declarations.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fsection-889-banned-components)

At a glance

Legislation

NDAA FY2019, Section 889

Part A effective

August 2019

Part B effective

August 2020

FAR clause

52.204-25

Prohibited entities

5 named + subsidiaries/affiliates

## The five prohibited manufacturers

The five named entities and all their subsidiaries and affiliates are covered. OFAC SDN list entities are separately prohibited under sanctions law. Understanding the corporate structure of these companies — especially their semiconductor and component operations — is essential for thorough BOM screening.

### Huawei Technologies

Prohibited for telecommunications equipment. Covers Huawei's networking infrastructure, routers, switches, base stations, and chipsets. Subsidiaries and affiliates are also covered — including HiSilicon semiconductor products, which appear as chips in third-party products not obviously associated with Huawei.

### ZTE Corporation

Prohibited for telecommunications equipment. ZTE produces networking equipment, handsets, and telecommunications systems. Like Huawei, ZTE's prohibition extends to subsidiaries and affiliates. ZTE's semiconductor and component operations can result in covered parts appearing in multi-tier supply chains.

### Hytera Communications

Prohibited for radio communications equipment. Hytera produces land mobile radio systems, digital mobile radio (DMR) equipment, and public safety communications devices. Procurement of two-way radios and related infrastructure for federal use requires screening against Hytera and its affiliates.

### Hangzhou Hikvision Digital Technology

Prohibited for video surveillance equipment. Hikvision is the world's largest manufacturer of IP cameras and video surveillance systems. Its products — including OEM-branded versions sold under third-party labels — appear throughout security camera markets. OEM white-labelled Hikvision hardware is a significant compliance risk in procurement.

### Dahua Technology

Prohibited for video surveillance equipment. Dahua is the second-largest video surveillance manufacturer globally. Like Hikvision, Dahua products are widely re-branded by other vendors. Buyers must look beyond the label on the box to the actual hardware and firmware provenance to determine if equipment contains Dahua components.

## Two-part prohibition explained

### Part A — Agency Procurement Prohibition (Effective August 2019)

Federal agencies cannot procure or obtain — directly or through a contractor — any telecommunications equipment or services produced or provided by a covered entity. This is the straightforward ban: if a covered manufacturer made it, a federal agency cannot buy it. Agencies must include screening requirements in their procurement processes.

### Part B — Contractor Use Prohibition (Effective August 2020)

The broader and more commercially impactful prohibition. Agencies cannot enter into, extend, or renew a contract with any entity that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. This catches hardware suppliers who use covered components in their own products.

### Waivers: Available but Rare

An agency head may grant a one-time waiver for up to two years if no alternative technology is available and the waiver is in the national security interest. The waiver process requires detailed justification, publication in the Federal Register, and notification to Congress. Waivers are not a practical compliance strategy for commercial hardware suppliers.

## Component-level compliance due diligence

Section 889 compliance cannot be achieved through a single supplier questionnaire. Hardware products contain dozens of components from multi-tier supply chains, and covered components frequently appear under third-party or OEM branding. Systematic BOM-level traceability is the only defensible approach.

01

Identify all subcomponents in the bill of materials — not just tier-1 components but processors, wireless chipsets, cameras, microphones, and networking chips at every level.

02

Trace wireless chipsets, cameras, microphones, and processors to the actual manufacturer — not the module vendor or distributor, but the entity that designed and fabricated the silicon or assembly.

03

Check the CISA Section 889 resource page for current covered entity guidance — the list of subsidiaries and affiliates is not exhaustive in the statute and requires ongoing monitoring.

04

Obtain supplier declarations at each tier of the supply chain — tier-1 declarations are necessary but insufficient; tier-2 and tier-3 declarations are required for components with complex multi-level supply chains.

05

Document the due diligence process in writing — the FAR requires that contractors be able to demonstrate the diligence they performed, not merely assert that no covered equipment is present.

06

Maintain records for contracting officer audit — Section 889 compliance documentation should be retained throughout the contract period of performance and for the post-award audit period.

## Practical compliance for hardware manufacturers

### FAR Clause 52.204-25 Attestation

When bidding on federal contracts, offerors must complete the FAR clause 52.204-25 representation confirming that they do not use covered telecommunications equipment or services. A false attestation exposes contractors to False Claims Act liability. The attestation covers the contractor's own use of covered equipment, not just the products being supplied.

### Supply Chain Mapping Tools

Commercial software tools exist to map component provenance against prohibited entity lists. These tools ingest BOM data, cross-reference component manufacturers against OFAC SDN lists and known Section 889 affiliates, and flag potential risks for human review. Automated tools supplement — but do not replace — human due diligence and supplier declarations.

### Component Substitution Strategy

For hardware manufacturers who discover covered components in their designs, the compliance path is component substitution — replacing the covered part with an equivalent from a non-covered manufacturer. This requires design re-work, re-qualification testing, and updated supply chain documentation. Early BOM screening during product development is far less costly than redesign during a contract bid cycle.

### CMMC Interaction

For DoD contractors, Section 889 compliance documentation supports CMMC (Cybersecurity Maturity Model Certification) Level 1 and above. CMMC assessors review supply chain risk management practices. Demonstrated Section 889 due diligence — BOM screening records, supplier declarations, component traceability — is evidence of supply chain risk management capability that assessors look for.

## Frequently asked questions

### Does Section 889 apply if we sell to a federal contractor rather than directly to an agency?

Yes. Part B of Section 889 prohibits agencies from contracting with any entity that uses covered equipment. This means prime contractors must flow the Section 889 requirement down to subcontractors and suppliers. If you supply hardware to a prime contractor who sells to a federal agency, you will typically be required to provide a Section 889 attestation as part of the subcontract. The obligation reaches through the supply chain, not just to direct agency suppliers.

### How do we identify if a component manufacturer is a subsidiary of a named entity?

The statute names the five companies and covers their subsidiaries and affiliates, but does not provide a definitive list of covered subsidiaries. CISA publishes guidance, but the determination requires research. For complex cases — particularly with Chinese conglomerates where ownership structures are opaque — you may need to consult legal counsel and use commercial risk intelligence services. Documented good-faith due diligence, even if incomplete, is better than no diligence at all in demonstrating compliance intent.

### Are there waivers available for Section 889 if no alternative components exist?

Waivers are technically available under Section 889 but are extremely difficult to obtain. An agency head must grant the waiver, it requires a national security justification, public notice in the Federal Register, and Congressional notification. No waiver has been granted for a commercial supplier's component sourcing issue. Hardware manufacturers should treat waiver availability as effectively zero for planning purposes and invest in component substitution instead.

### How does Section 889 interact with CMMC for DoD suppliers?

CMMC Level 1 through Level 3 all include supply chain risk management expectations. Section 889 compliance evidence — BOM screening documentation, supplier declarations, component traceability records — directly supports the supply chain practices assessors evaluate. Conversely, a DoD contractor who cannot demonstrate Section 889 due diligence is likely to face findings in a CMMC assessment. Running both programs together, using shared documentation, reduces compliance burden across the DoD supply chain requirements.

**Disclaimer:** This page is an educational resource only and does not constitute legal advice. Section 889 interpretation, subsidiary and affiliate determinations, and FAR clause requirements involve complex legal questions. Consult qualified government contracting counsel for product-specific compliance decisions.

🇺🇸 US roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇺🇸 US compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Related guides

*   [Export Control and Dual-UseExport control regulations — including the EU Dual-Use Regulation, US EAR (Export Administration Regulations), and US ITAR — re…](/guides/export-control-dual-use)
*   [US Supply Chain SecurityComplete guide to US supply chain security.](/guides/us-supply-chain-security)
*   [Conflict Minerals (3TG) ComplianceGuide to conflict minerals (3TG) compliance for electronics manufacturers — SEC Rule 13p-1, OECD due diligence framework, RMAP …](/guides/conflict-minerals-3tg-compliance)
*   [US State-Specific ComplianceComplete guide to US state-specific compliance.](/guides/us-state-specific-compliance)
*   [FAR and DFARS Compliance for HardwareSelling hardware to the US federal government and DoD: FAR Part 25 Trade Agreements Act, DFARS Section 889 prohibitions, CMMC cybersecurity levels, SAM.gov registration, and Buy American Act content thresholds.](/guides/us-government-procurement-far-dfars)