Can you purchase any security camera you want when it comes time to upgrade or replace your business’s surveillance system? Well, it depends. If you plan to work with any federal agency or just want to be extra careful of the brands you choose to integrate into your system, then you need to read this article.
Contrary to popular belief, not all security products are created equal. Due to heavy regulation, many video surveillance cameras and security systems are currently banned for government use. These banned products include components from Chinese manufacturers listed in the 2019 National Defense Authorization Act (NDAA).
In this article, we will give you an overview of NDAA-compliant security cameras and how you can ensure that your surveillance system is compliant.
- How does NDAA impact security cameras?
- Who does the ban apply to?
- How to make sure your cameras are NDAA compliant?
- List of NDAA compliant brands
- How to Find a Security Installer that knows the NDAA regulations?
The National Defense Authorization Act (NDAA) restricts the use, procurement, or sale of certain brands of surveillance equipment for federal agencies. Federal agencies are prohibited from purchasing equipment from these brands, but they can’t do business with contractors that use surveillance technology from backlisted products.
The NDAA specifically bans security camera brands, including Dahua, Hikvision, and Huawei. The ban also includes any brands that may function under or as part of these companies, including brands affiliated with these companies.
The NDAA affects all federal agencies in the United States. The FBI, national park services, and the military are just a few examples of these entities. Additionally, security integrators can’t sell surveillance equipment to government agencies or their contractors under these brands.
According to the regulation, federal agencies are prohibited from working with contractors who use or offer unlawful surveillance equipment. The regulation is far-ranging and encompasses both new contracts and renewing or extending an existing ones.
It also applies regardless of whether the contractors utilize the cameras for government contact work. While the act focuses on prime contractors, subcontractors also have to comply.
Also learn more about NERC CIP Compliance
NDAA impacts companies like Dahua and Hikvision.
The best way to know if your surveillance technology is in compliance with the NDAA is to get a comprehensive audit with a security integrator that’s experienced in identifying equipment with both approved and banned components. Additionally, you find out your security camera’s OEM (original equipment manufacturer) and verify if they are on the NDAA compliant list.
Video surveillance regulation
Video surveillance regulation is a vast and often complicated world covering everything from privacy and data protection issues to health and state-specific laws. In addition to NDAA compliance, if your business or organization operates security cameras, there are additional video surveillance regulations to be aware of, such as:
- General Data Protection Regulation (GDPR)
- HIPAA compliance to protect Personal Health Information (PHI) while using a video security solution.
- Video surveillance state laws.
Even government agencies find it difficult to assure NDAA compliance since many brands employ products or components from other manufacturers. On the other hand, some manufacturers have gone above and beyond to ensure that their surveillance systems are NDAA-compliant cameras.
NDAA compliant manufacturers include:
- Axis Communications
- BCD International
- Digital Watchdog
- Seek Thermal
- 360 Vision Technology
This is not a comprehensive list. There are always new updates and changes in the video surveillance world, so it’s best to review your system and keep up with the latest updates.
NDAA impact on cybersecurity
There’s no doubt that cybersecurity is an important consideration for a video surveillance system. NDAA regulation has many cybersecurity provisions on topics from ransomware to incident response. In addition, the Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review their security cameras and apply the latest firmware updates.
Specifically, CISA has warned organizations that some cameras made by Chinese video surveillance vendor Hikvision are affected by a critical vulnerability. Securing your video surveillance system is the most crucial step to mitigating risk and yields substantial benefits for protecting your data. Therefore it is best not to install non-NDAA-approved security cameras.
Secure Equipment Act
In addition to NDAA, another reason why you should reconsider purchasing security cameras that are not NDAA approved is the Secure Equipment Act. This legislation requires the Federal Communications Commission (FCC) to prohibit the agency from reviewing or issuing new equipment authorizations for companies placed on its so-called “Covered List” of organizations whose equipment and services are considered a threat to national security.
What if my cameras aren’t NDAA compliant?
If you’re not a government-funded agency or have contracts with government agencies, you’re under no obligation to purchase NDAA-compliant hardware. It is, however, strongly advised that you use NDAA-compliant hardware. In addition, if you’re working with a vendor, they should be able to confirm that they exclusively employ components from whitelisted sources for cameras, sensors, and other devices.
All the major security camera manufacturers have published information regarding their compliance with NDAA. In addition, some of the most popular security camera manufacturers have statements on their websites. Examples include:
- Axis Communication: “We are pleased to affirm that our entire product portfolio, which includes solutions marketed to the US government, Department of Defense (DoD) and associated contractors and affiliates, is fully NDAA-compliant.”
- Avigilon (Motorola Solutions): “We will be manufacturing critical, NDAA-compliant safety and security video solutions on the doorstep of American public safety agencies and businesses”.
- Flir: “Backed by proven cybersecurity improvements, NDAA compliance, and technology features that optimize performance in harsh weather and environmental conditions, these FLIR security cameras are ideal for cyber-hardened security systems for critical infrastructure and government applications.”
Lastly, always keep in mind that reputable security companies and integrators are forthcoming with compliance information, so don’t hesitate to ask specific questions related to NDAA regulations.
Security professionals at Safe and Sound are ready to help you and are well-versed in the NDAA rules.
NDAA regulation not only prevents federal agencies from installing cameras made by companies on the black list, but also prohibits them from doing business with any organization that uses them. This means that as a security leader, integrator, or facility manager you don’t want to take the risk of installing non-NDAA compliant security systems for both compliance and cybersecurity reasons.
If you plan to work with government agencies or install security cameras on government property, you need to make sure that your video surveillance products are NDAA compliant. Additionally, it is strongly recommended that organizations use NDAA-compliant hardware as a general best practice and in an abundance of caution.
The best way to make sure that your security cameras are NDAA compliant is to get a comprehensive audit with an experienced security integrator. Along with NDAA, there are other security compliance issues and video surveillance challenges that one of our certified security consultants can assist you with moving forward.