[Home](/)/[Resources](/resources)/FAR and DFARS

United StatesGovernment ProcurementFAR

# FAR and DFARS Compliance for Hardware Companies Selling to the US Government

The US federal market is one of the largest hardware buyers in the world — but accessing it requires navigating the Federal Acquisition Regulation (FAR, 48 CFR) and, for DoD contracts, the Defense Federal Acquisition Regulation Supplement (DFARS). Trade Agreements Act country-of-origin rules, Section 889's ban on Huawei and ZTE equipment in contractor supply chains, CMMC cybersecurity certifications, and SAM.gov registration are non-negotiable prerequisites. This guide explains each requirement with the specific CFR citations, dollar thresholds, and compliance actions that apply to hardware companies.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fus-government-procurement-far-dfars)

At a glance

TAA threshold (2023)

$182,000

Section 889 banned vendors

5 named + affiliates

CMMC levels

3 (1, 2, 3)

SAM.gov renewal cycle

Annual

## Core FAR and DFARS requirements for hardware

### FAR Part 25 — Trade Agreements Act (TAA) and designated country compliance

The Trade Agreements Act (19 USC § 2501 et seq.) prohibits procurement of products from non-designated countries for federal contracts above the TAA threshold — $182,000 for supplies in 2023 (adjusted periodically by USTR). TAA-compliant countries include all WTO GPA signatories, FTA partners, and least-developed countries, but explicitly exclude China, Russia, India, Malaysia, and several others. TAA compliance is determined by 'substantial transformation' — the country where the article was last substantially transformed into a new article of commerce. A product assembled in China from US components is Chinese-origin for TAA purposes. Representations are made in FAR 52.225-5 and 52.225-6.

### Buy American Act (BAA) vs Trade Agreements Act (TAA)

These are two distinct regimes. The Buy American Act (41 USC §§ 8301–8305) applies to contracts below the TAA threshold and requires domestic end products (manufactured in the US with US components comprising more than 55% of cost as of 2022 rule updates). The TAA applies above the threshold and opens procurement to designated countries. Most hardware companies target contracts above the TAA threshold, making TAA compliance the operative concern. FAR 25.401 lists TAA-exempt contracts. The 'component test' for BAA was tightened under Executive Order 14005 — the 55% domestic content threshold rises to 60% in 2024 and 65% in 2029.

### DFARS § 252.204-7012 — Safeguarding Covered Defense Information and CMMC

For DoD contracts, DFARS § 252.204-7012 requires contractors to implement NIST SP 800-171 controls for systems that process Covered Defense Information (CDI). This clause flows down to subcontractors. The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework formalizes this: Level 1 (17 basic practices, annual self-assessment) for Federal Contract Information; Level 2 (110 NIST 800-171 practices, triennial third-party assessment by a C3PAO for most contracts) for CDI; Level 3 (NIST 800-172, government-led assessment) for highest-sensitivity programs. CMMC Level 2 third-party assessment becomes a contract requirement under DFARS rulemaking expected to finalize in 2025.

### Section 889 of the NDAA 2019 — banned telecommunications equipment

Section 889 (Part A) prohibits federal agencies from procuring covered telecommunications equipment from Huawei Technologies, ZTE Corporation, Hikvision, Dahua Technology, Hytera Communications, and their subsidiaries and affiliates. Part B (effective August 2020) extends the prohibition to contractors whose supply chains contain covered equipment, even if the federal agency itself doesn't use it. Hardware companies must certify compliance with 889(b) in every federal contract via FAR 52.204-26 and DFARS 252.204-7019/7020. This requires active supply chain due diligence — not just first-tier supplier review but scrutiny of networking, surveillance, and communications components throughout the BOM.

### SAM.gov registration — UEI, CAGE code, and annual renewal

Any company receiving federal contract or grant funds must be registered in SAM.gov (System for Award Management) at time of offer and at time of award. Registration requires a Unique Entity Identifier (UEI), issued by SAM.gov since April 2022 (replacing DUNS numbers). Defense contractors also need a CAGE (Commercial and Government Entity) code, assigned by DLA. SAM.gov registration must be renewed annually — lapsed registration is a common reason awards are delayed. Active registration can be verified via the SAM.gov public search. State and local government contracts do not require SAM.gov registration.

### GSA Multiple Award Schedule (MAS) as a procurement vehicle

The GSA Schedule (also called Multiple Award Schedule or Federal Supply Schedule) is a long-term government-wide contract vehicle that pre-negotiates pricing, terms, and TAA compliance with vendors. Agencies can purchase directly from GSA Schedule holders without a full competitive acquisition — streamlining procurement significantly. Electronics and technology products fall under GSA Schedule Large Category IT (Schedule 70 legacy). Getting on GSA Schedule requires an offer submission, negotiation, and GSA contracting officer approval — typically 6–12 months. MAS contracts run 5 years with three 5-year option periods (20 years maximum). Products on MAS must maintain TAA and Section 889 compliance.

## Federal market entry process

01

Determine if the federal market is commercially viable for the product — identify target agencies and whether the product category is actively procured. Review USASpending.gov and FPDS-NG for historical award data on comparable products. Confirm the product can be manufactured in a TAA-designated country.

02

Assess country of origin for TAA compliance. Trace the 'substantial transformation' chain — where was the product last substantially transformed into a new article of commerce? If manufacturing is in China or another non-designated country, evaluate reshoring or third-country manufacturing before pursuing federal contracts.

03

Register in SAM.gov. Obtain a UEI (Unique Entity Identifier) directly from SAM.gov — no third-party intermediary is required. Apply for a CAGE code through DLA if pursuing DoD work. Plan 2–4 weeks for initial registration to activate. Set a calendar reminder for annual renewal.

04

Conduct a Section 889 supply chain audit. Map all telecommunications and video surveillance components in the product BOM — including Wi-Fi modules, cellular modems, IP cameras, and networking chips — against the list of covered companies and their known subsidiaries. Document the audit findings. Engage suppliers for written representations where needed.

05

Evaluate CMMC level required for target DoD contracts. If the contract involves Controlled Unclassified Information (CUI) or Covered Defense Information, Level 2 (NIST SP 800-171, 110 practices) is likely required. Engage a Registered Practitioner Organization (RPO) for gap assessment. If a C3PAO assessment is required, budget 12–18 months for preparation and assessment.

06

Apply for GSA Schedule if the product is appropriate for broad civilian agency procurement. Prepare the offer package including price list, TAA compliance documentation, Section 889 representation, and product specifications. Engage a GSA Schedule consultant for first-time offers — the process has specific formatting and negotiation requirements.

07

Respond to RFPs with accurate FAR/DFARS representations. Every solicitation will include a representations and certifications section (now largely completed in SAM.gov annually). Review Section K of each solicitation for specific certifications required. False statements in federal representations are subject to 18 USC § 1001 (false statements to federal agencies) in addition to civil False Claims Act liability.

08

Maintain ongoing compliance. Renew SAM.gov annually. Monitor Section 889 subsidiary lists — the government has continued to designate new covered entities and affiliates since 2019. Track CMMC rulemaking for updated assessment requirements. Update GSA Schedule pricing and TAA compliance status when supply chain changes occur.

## Frequently asked questions

### What does TAA compliance mean and which countries qualify?

TAA compliance means the end product was manufactured in, or substantially transformed in, a country designated under the Trade Agreements Act — not in a prohibited country like China or Russia. Designated countries include all WTO GPA signatories (EU member states, Canada, Japan, South Korea, Singapore, etc.), US FTA partners (Mexico, Chile, Australia, etc.), and least-developed countries. The USTR publishes the current designated country list. Substantial transformation is the key test: a product assembled in Taiwan from components sourced globally, where the assembly creates a new and different article of commerce, is Taiwanese-origin for TAA purposes. Origin is not determined by brand ownership or where the company is headquartered.

### How does Section 889 affect electronics supply chains?

Section 889 Part B prohibits federal contractors from using covered telecommunications equipment or services anywhere in their operations — not just in the contract deliverables. This means a company selling servers to a federal agency must ensure its internal office network, building security cameras, and any operational IT infrastructure doesn't include Huawei, ZTE, Hikvision, Dahua, or Hytera equipment. For hardware products, it means the product's BOM must be free of components made by covered companies or their subsidiaries. Identifying subsidiaries is the hard part — the FCC has an ongoing proceeding to maintain a public list, but supply chain due diligence remains the contractor's responsibility.

### What CMMC level do I need to sell hardware to DoD?

CMMC Level 1 (17 basic cybersecurity practices, annual self-assessment) applies to contracts involving only Federal Contract Information (FCI) — information provided by the government for contract performance, not for public release. Most hardware supply contracts fall into this category. CMMC Level 2 (110 NIST SP 800-171 practices, triennial C3PAO assessment for most contracts) applies to contracts involving Controlled Unclassified Information (CUI) — which includes technical specifications, engineering drawings, and design data marked as CUI on DoD contracts. If your hardware is integrated into a defense system and technical data is exchanged, Level 2 is likely required. Level 3 (NIST 800-172, government-led assessment) applies only to the most sensitive programs.

### Does selling to state governments require FAR compliance?

No — FAR and DFARS apply exclusively to federal government procurement by executive branch agencies. State and local government procurement is governed by each state's procurement code, not the Federal Acquisition Regulation. State contracts do not require SAM.gov registration, TAA compliance, Section 889 certifications, or CMMC. Some states have adopted analogous requirements — for example, several states have enacted their own bans on Huawei/ZTE equipment in government networks — but these are state-law obligations, not FAR-based. If a state contract is federally funded (e.g., through a federal grant), federal terms including TAA and Section 889 may flow down through the grant conditions.

**Disclaimer:** Educational resource only. Regulatory requirements change frequently. Consult a licensed US customs broker, trade attorney, or compliance specialist before making decisions.

[

Map your product, free

Every standard, document, and test that applies — free, no account required.

Start mapping](/platform/start)

Related guides

*   [Section 889 Banned ComponentsComplete guide to Section 889 NDAA compliance — the five prohibited manufacturers, Part A and Part B prohibitions, component-le…](/guides/section-889-banned-components)
*   [US Supply Chain SecurityComplete guide to US supply chain security.](/guides/us-supply-chain-security)
*   [US CHIPS Act Manufacturing IncentivesUS CHIPS and Science Act manufacturing incentives: $52.7B CHIPS for America Fund, 25% Advanced Manufacturing Investment Credit (Sec 48D), 10-year China guardrail restrictions, and how electronics manufacturers access CHIPS incentives.](/guides/us-chips-act-manufacturing-incentives)
*   [US FTC Made in USA LabelingUS FTC Made in USA labeling for electronics: the 'all or virtually all' standard, qualified claim safe harbours, state-level California requirements, $50,120 civil penalty per violation, and how electronics companies with offshore manufacturing manage origin claims.](/guides/us-ftc-made-in-usa-labeling)
*   [US ADA and Section 508 Accessible DesignADA Title III and Section 508 accessibility requirements for hardware: kiosks, ATMs and interactive displays, federal ICT procurement rules, VPAT preparation, and the litigation risk electronics manufacturers actually face.](/guides/us-accessible-design-ada-section-508)