Over the past decade, I have had countless conversations with law enforcement agencies, procurement officials, drone manufacturers, surveillance-industry colleagues and technology partners about one increasingly common subject: compliance.
Is this camera NDAA compliant? Does a drone have to be Blue UAS? What does TAA actually mean? Does an FCC ID mean a product is approved? Can an agency buy something with local funds that it cannot buy with a federal grant? And if a system is assembled in the United States, does that automatically make it compliant?
These are good questions. Unfortunately, they are often answered with acronyms, sales pitches, or oversimplified statements that make a complicated subject even more confusing.
This guide is intended to provide a practical, plain-English resource for state and local government buyers, law enforcement leadership, grant managers, procurement professionals, drone program managers, manufacturers, integrators and others involved in buying public safety technology.
The good news is that the maze becomes considerably easier to navigate once you recognize that NDAA, TAA, FCC, Blue UAS and “Made in USA” are answering different questions.
Quick Navigation
- The Big Picture: What Are These Rules Trying to Accomplish?
- NDAA, TAA, FCC and Blue UAS: Four Different Questions
- NDAA Section 889 Explained
- Federal Grants and 2 CFR § 200.216
- The FCC Covered List
- TAA Compliance
- Made in USA vs. Assembled in USA
- Blue UAS Explained
- The American Security Drone Act
- Compliance Scenarios
- Why the Source of Funding Matters
- The White-Label and Component Problem
- A Practical Buyer Checklist
- How This Applies to Surveillance and Drone Purchases
- Additional Public Safety Resources
- Frequently Asked Questions
- Official Government Resources
The Big Picture: What Are These Rules Trying to Accomplish?
Before getting buried in acronyms, it helps to understand the objectives behind many of these policies.
At a high level, much of the current federal activity falls into two overlapping categories: supply-chain and cybersecurity risk, and strengthening domestic or allied manufacturing capacity.
Those objectives often overlap, but they are not interchangeable. A product can avoid a prohibited manufacturer and therefore satisfy one requirement while still being manufactured in a country that makes it ineligible under another procurement rule.
That is why a statement such as “this product is NDAA compliant” does not automatically mean that it is TAA compliant, Blue UAS cleared, made in America, acceptable under a particular state law, or eligible for every federal grant.
NDAA, TAA, FCC and Blue UAS: Four Different Questions
| Term | The Basic Question | What It Is Not |
|---|---|---|
| NDAA Section 889 | Does covered telecommunications or video-surveillance technology from prohibited entities appear in the product, system or contractor environment? | It is not a universal “Made in America” requirement. |
| TAA | For a procurement where the Trade Agreements Act applies, is the end product from the United States or an eligible designated country? | It is not the same as NDAA compliance. |
| FCC Covered List | Has the FCC identified this equipment, service or category as presenting an unacceptable national-security risk, affecting equipment authorization and related market access? | An FCC ID is not an NDAA, TAA or Blue UAS certification. |
| Blue UAS | Has the UAS or component passed the federal defense community's prescribed security and compliance vetting process? | Blue UAS is not synonymous with basic NDAA compliance. |
Never treat “NDAA compliant,” “TAA compliant,” “FCC authorized,” “Blue UAS,” “Made in USA” and “Assembled in USA” as interchangeable labels.
NDAA Section 889 Explained
When surveillance-industry buyers use the phrase “NDAA compliant”, they are usually referring to Section 889 of the National Defense Authorization Act for Fiscal Year 2019 and its implementation through the Federal Acquisition Regulation.
Section 889 identifies covered telecommunications and video-surveillance equipment and services associated with several companies and their subsidiaries or affiliates. The best-known names are:
- Huawei Technologies Company
- ZTE Corporation
- Hytera Communications Corporation
- Hangzhou Hikvision Digital Technology Company
- Dahua Technology Company
Huawei and ZTE are addressed broadly as telecommunications-equipment producers. Hytera, Hikvision and Dahua are specifically addressed in connection with public safety, government facilities, critical-infrastructure surveillance and other national-security purposes.
There are two especially important pieces of Section 889 for federal contracting.
Section 889 Part A
Federal agencies generally cannot procure an equipment, system or service that uses covered telecommunications equipment or services as a substantial or essential component or as critical technology, unless an exception or waiver applies.
Section 889 Part B
Part B goes beyond the product being sold to the government. Federal agencies generally cannot contract with an entity that itself uses covered telecommunications equipment or services as a substantial or essential component of a system or as critical technology, subject to the applicable exceptions and waiver process.
This is why Section 889 compliance became an issue not only for camera manufacturers, but also for contractors, integrators, technology companies and other organizations doing business with the federal government.
For the current regulation, see FAR Subpart 4.21 and FAR 52.204-25 .
Does NDAA Compliance Reach Internal Components?
Potentially, yes.
The regulation is not limited to reading the brand name printed on the outside of a camera, radio or recorder. FAR terminology reaches covered equipment used as a substantial or essential component of a system and defines that phrase around components necessary to the proper function or performance of the equipment, system or service.
That makes component-level diligence important. A U.S.-branded enclosure does not magically make a system compliant if restricted technology remains inside it.
At the same time, buyers should be careful with blanket statements such as “any chip from company X automatically makes the entire product illegal.” The actual regulatory test, product architecture and procurement context matter.
Federal Grants and 2 CFR § 200.216
Section 889 is particularly important to state and local public safety agencies because federal financial assistance can bring federal restrictions into a procurement that otherwise appears purely local.
Under 2 CFR § 200.216, recipients and subrecipients generally may not obligate or expend federal loan or grant funds to procure or obtain covered telecommunications equipment or services, extend or renew a contract for them, or enter into such a contract.
The definition tracks the covered telecommunications and video-surveillance equipment identified under Section 889, including the manufacturers discussed above.
This is one reason MAXSUR created our Public Safety Grant Resource Center . Finding a grant is only the first step. Buyers also need to understand the conditions that come with the money.
Review the current federal rule at 2 CFR § 200.216 .
The FCC Covered List: A Different Kind of Rule
The FCC Covered List is frequently discussed in the same breath as NDAA, but it serves a different regulatory function.
The FCC maintains the Covered List under the Secure and Trusted Communications Networks framework. Equipment and services placed on the list have been determined to pose an unacceptable risk to U.S. national security or the security and safety of U.S. persons.
Covered equipment generally cannot obtain a new FCC equipment authorization. That is significant because many radio-frequency devices require FCC authorization before they may be marketed or imported into the United States.
This is more precise than simply describing the Covered List as a universal “total market ban.” Previously authorized equipment raises additional questions, and the FCC has established procedures through which existing authorizations for covered equipment can be limited or otherwise addressed.
The Major 2025-2026 Change for Drones
On December 22, 2025, the FCC added foreign-produced uncrewed aircraft systems and UAS critical components to the Covered List, subject to subsequent exceptions and updates.
As of this article's September 2026 update, the Covered List includes exceptions that, among other things, cover:
- Certain UAS and critical components included on the Blue UAS Cleared List through January 1, 2028;
- Certain UAS and critical components qualifying as domestic end products under the Buy American standard through January 1, 2028;
- Devices that have received applicable Conditional Approval; and
- Certain defined toy-drone categories.
This is a rapidly changing area. Do not rely on a blog article—even this one—as your permanent list.
Bookmark the official FCC Covered List and check it when developing a specification or evaluating a new product.
Does an FCC ID Mean a Product Is NDAA Compliant?
No.
An FCC ID can provide important information about equipment authorization and the entity responsible for that authorization, but an FCC ID is not a certificate of NDAA compliance, TAA compliance, Blue UAS status or U.S. origin.
Procurement personnel should think of FCC authorization and federal procurement compliance as separate checks.
TAA Compliance: Where Was the Product Made?
The Trade Agreements Act, or TAA, is another term that routinely gets mixed together with NDAA.
A useful shorthand is:
NDAA often asks whether prohibited covered technology is involved.
TAA asks whether an end product is from the United States or an eligible designated country when the Trade Agreements Act applies.
That shorthand is not the full law, but it demonstrates why the two concepts are different.
Under applicable TAA procurements, the government generally acquires U.S.-made or designated-country end products. A product may qualify because it is wholly the product of an eligible country or because it was substantially transformed there into a new and different article of commerce.
China is not a TAA-designated country.
Therefore, a product manufactured in China could conceivably contain no Section 889-covered technology and still be ineligible for a procurement requiring a TAA-compliant end product.
Conversely, a product's country of origin does not by itself answer whether the product contains covered technology under Section 889.
Another important nuance: TAA does not apply to every government purchase. Applicability depends on the procurement vehicle, agency, acquisition value, solicitation and other factors. GSA Schedule contracts, for example, generally incorporate TAA requirements unless otherwise stated.
Useful references include GSA's TAA Compliance guidance and FAR Subpart 25.4 .
“Made in USA” vs. “Assembled in USA”
Yet another source of confusion is American-origin labeling.
Saying a company is headquartered in the United States is not the same as saying its products are made in the United States.
The Federal Trade Commission generally requires an unqualified “Made in USA” claim to meet an “all or virtually all” standard. Final assembly or processing must occur in the United States, significant processing must be domestic, and foreign content generally must be negligible.
“Assembled in USA” is a different and more qualified representation. According to FTC guidance, the product's principal assembly should take place in the United States, the assembly must be substantial, and the product's last substantial transformation should occur in the United States.
Merely performing a simple final “screwdriver assembly” on imported major components does not necessarily support an unqualified “Assembled in USA” claim.
See the FTC's Made in USA guidance for the current standard.
Blue UAS Explained: More Than “NDAA Compliant”
Few terms create more confusion in the public safety drone market than Blue UAS.
The most important concept is simple:
A drone can potentially meet an NDAA requirement without automatically being Blue UAS cleared.
Blue UAS was created as a federal defense vetting ecosystem for secure commercial drone platforms and components. Platforms entering the Blue UAS environment undergo prescribed security, supply-chain and compliance evaluation.
The program has evolved considerably. In 2025, management of the Blue UAS Cleared List transitioned from the Defense Innovation Unit to the Defense Contract Management Agency, while the broader vetting ecosystem continued to expand.
For a state or local police department, that distinction matters.
A solicitation might require:
- NDAA compliance;
- ASDA compliance;
- Blue UAS Cleared status;
- A state-approved drone list;
- Specific domestic-content requirements; or
- Some combination of these.
Do not assume that one automatically substitutes for another.
Current information on the federal Blue UAS program and approved platforms should always be checked against the government's current Blue UAS resources.
The American Security Drone Act: Another Layer for UAS Procurement
Drone buyers also need to understand the American Security Drone Act of 2023 (ASDA).
ASDA created government-wide restrictions involving unmanned aircraft systems manufactured or assembled by covered foreign entities.
Federal Acquisition Regulation provisions prohibit covered UAS from being delivered under federal contracts and, since December 22, 2025, restrict operating covered UAS in the performance of federal contracts and using federal funds to procure or operate covered UAS, subject to statutory exemptions, exceptions and waivers.
Importantly, ASDA uses a specific list of covered foreign entities maintained through the Federal Acquisition Security Council and published through SAM.gov. Buyers should check the current list rather than relying entirely on brand-name shorthand.
Review FAR 52.240-1 and the American Security Drone Act Covered Foreign Entity information on SAM.gov .
State and local agencies using federal grants should also examine the terms of the specific award and the issuing agency's UAS guidance. Do not assume that “federal grant” automatically translates into a generic requirement to buy from the Blue UAS list; the actual funding authority, award conditions and governing rules control.
Common Compliance Scenarios
The following simplified examples illustrate why one compliance label cannot substitute for another.
| Scenario | NDAA §889 | TAA | Blue UAS | Why |
|---|---|---|---|---|
| Product made in China with no Section 889-covered telecom or surveillance technology | Potentially compliant | Generally not a designated-country end product | Not automatically | NDAA and TAA answer different questions. |
| U.S.-branded camera containing prohibited covered surveillance technology as an essential component | Problematic | Requires separate origin analysis | Not applicable | Brand name or U.S. headquarters does not override the component test. |
| Drone is NDAA compliant but has not completed Blue UAS clearance | May be compliant | Separate question | No | Blue UAS clearance is a separate vetting status. |
| Product assembled in the United States from substantial imported components | Depends on components | Depends on substantial transformation | Separate question | “Assembled in USA” alone resolves none of the other tests. |
Why the Source of Funding Matters
For state and local public safety agencies, one of the most important questions may be: What money are we using to buy this?
| Funding / Procurement | What to Check |
|---|---|
| Local municipal funds | State law, local policy, FCC restrictions, network-security requirements and procurement specifications. Federal grant rules do not automatically attach simply because the buyer is a government agency. |
| State funds | Determine whether the state has its own prohibited-technology law, approved-drone list, country-of-concern rule, cybersecurity policy or domestic-content requirement. |
| Federal grant funds | 2 CFR Part 200, award-specific terms, Section 889 restrictions and any UAS-specific requirements imposed by the federal awarding agency. |
| Federal contract | FAR clauses, Section 889 representations, ASDA provisions, solicitation requirements and agency-specific supplements. |
| GSA Schedule / TAA-covered acquisition | Country of origin, substantial transformation and applicable TAA requirements in addition to any security restrictions. |
And Then There Are State Laws
Federal rules are only part of the story.
States have increasingly adopted their own procurement restrictions, approved-drone lists, cybersecurity requirements, country-of-concern rules, operational limitations and replacement programs.
A procurement that may be permissible using local dollars in one state may be prohibited for a local government in another.
That makes state-specific research essential, particularly for agencies purchasing drones, networked surveillance systems or equipment intended for critical-infrastructure missions.
MAXSUR maintains state-oriented funding and public safety resources through our Public Safety Grant Resource Center .
The White-Label and Component Problem
One of the most difficult procurement problems is the product that looks American on the outside but is something entirely different underneath the label.
Rebranding is common throughout electronics manufacturing. In itself, private labeling is neither unusual nor improper. The compliance problem arises when the underlying manufacturer or a substantial or essential component is restricted and the buyer does not know it.
An American-sounding model name, domestic reseller or U.S. corporate headquarters should never substitute for supply-chain diligence.
Questions Worth Asking the Vendor
- Who is the actual original equipment manufacturer?
- Where is the finished product manufactured?
- Where does final assembly occur?
- What company manufactures the principal processor or system-on-chip?
- Who manufactures network, communications and radio modules?
- Does the product contain equipment from a Section 889-covered entity?
- What is the product's FCC ID, where applicable?
- Can the vendor provide a written NDAA compliance statement?
- If TAA is required, what is the asserted country of origin and basis for that determination?
- For drones, what is the aircraft's ASDA, Blue UAS or other applicable status?
Put Compliance in Writing
Procurement personnel should consider requiring meaningful representations in the quotation, bid response or contract rather than relying solely on a salesperson's verbal statement.
Depending upon the procurement and advice of agency counsel, this could include manufacturer identification, country of origin, compliance certifications, component disclosures, replacement obligations for falsely represented equipment and appropriate contractual remedies.
The objective is not to create paperwork for the sake of paperwork. It is to create a documented compliance trail showing that the agency asked reasonable questions before spending public money.
A Practical Technology Procurement Checklist
- Identify the source of funding. Local, state, federal grant, federal contract and cooperative-purchasing dollars can carry different requirements.
- Read the actual solicitation and grant terms. Never substitute a vendor's generic compliance statement for the requirement written into your award.
- Identify the actual manufacturer. Do not stop at the reseller or private-label brand.
- Review significant internal components. Especially processors, communications modules, flight controllers, cameras and network interfaces.
- Check the current FCC Covered List. Rules and exceptions can change.
- Determine whether TAA applies. If it does, document country of origin and substantial-transformation analysis as appropriate.
- For UAS, check ASDA and Blue UAS requirements separately.
- Check state law and state IT policy. State requirements can be more restrictive than federal procurement rules.
- Document the vendor's representations. Keep compliance records with the procurement file.
- Recheck before future purchases. Compliance status can change as manufacturers, components, federal lists and state laws evolve.
How These Rules Apply to Real Public Safety Technology Purchases
These rules are not academic. They increasingly shape how agencies purchase everyday operational technology—from a covert camera used by a narcotics unit to a large mobile surveillance trailer protecting a special event.
More Public Safety Technology Resources
Compliance is only one part of building an effective public safety technology program. Funding, procurement, training, deployment, maintenance and operating policy are equally important.
Public Safety Grant Resource Center
Search for funding resources and state-specific public safety grant information for law enforcement, fire, emergency management, drones, surveillance, communications and other mission technology.
Law Enforcement Technology Articles
MAXSUR publishes practical articles on drones, covert surveillance, investigations, public safety technology, deployment lessons and emerging technology.
How Drones Really Crash — And How Professionals Avoid It
Procurement compliance helps determine which aircraft an agency can buy. Good program management helps determine whether that aircraft survives the mission.
Frequently Asked Questions
Is NDAA compliant the same thing as Made in USA?
No. NDAA Section 889 addresses specified covered telecommunications and video-surveillance equipment and services. “Made in USA” is a U.S.-origin marketing claim governed principally by FTC standards. A product can potentially satisfy one test without satisfying the other.
Is NDAA compliant the same as TAA compliant?
No. TAA addresses eligible countries of origin for procurements where the Trade Agreements Act applies. NDAA Section 889 addresses covered telecommunications and surveillance technology. They are separate analyses.
Does a drone have to be Blue UAS to be NDAA compliant?
Not necessarily. Blue UAS clearance involves a specific federal vetting process. A procurement requirement may call only for applicable NDAA or ASDA compliance, while another solicitation may specifically require Blue UAS status or an approved state list.
Does an FCC ID prove a product is NDAA compliant?
No. An FCC ID relates to equipment authorization. It is not a certification of Section 889, TAA, ASDA or Blue UAS compliance.
Can an agency buy Chinese-made equipment with local funds?
The answer depends on the product, current FCC rules, applicable state and local law, cybersecurity policy and the intended deployment. Federal procurement or grant restrictions do not automatically govern every purchase made solely with local funds, but many states impose additional restrictions of their own.
If a federal grant pays for only part of a project, does the whole network become subject to NDAA?
Not automatically. Federal award rules prohibit covered expenditures and the award may contain additional conditions. The funded portion, contracts, system architecture and integration with existing equipment should be reviewed carefully rather than assuming that one federal dollar either taints the entire network or has no effect beyond a single invoice.
Can an American company sell a non-NDAA-compliant product?
Yes. The location of a company's headquarters does not establish Section 889 compliance. Buyers should identify the original manufacturer and relevant internal components.
Is “Assembled in USA” the same as “Made in USA”?
No. The FTC applies different standards. An unqualified Made in USA claim generally requires that the product be all or virtually all made domestically. An Assembled in USA claim can involve imported components but still requires meaningful domestic assembly and other conditions described in FTC guidance.
The Bottom Line
Procurement officers do not need to become supply-chain attorneys or electrical engineers to buy technology intelligently.
They do, however, need to ask the right questions.
Start with the funding source. Identify the actual manufacturer. Understand the major components. Distinguish NDAA from TAA, FCC authorization, ASDA and Blue UAS. Check the current state requirements. Put vendor representations in writing. And recheck the rules whenever a new procurement is initiated.
Most importantly, avoid making procurement decisions based on a single buzzword printed on a specification sheet.
The public safety technology market is moving too quickly for that.
Official Government Resources
- FAR Subpart 4.21 — Section 889
- FAR 52.204-25 — Covered Telecommunications and Video Surveillance
- 2 CFR § 200.216 — Federal Financial Assistance
- FCC Covered List
- FAR Subpart 25.4 — Trade Agreements
- GSA Trade Agreements Act Compliance Guidance
- FTC Made in USA Guidance
- FAR 52.240-1 — American Security Drone Act
- SAM.gov — American Security Drone Act Covered Foreign Entity List
Need Help Sorting Through a Technology Requirement?
MAXSUR works with public safety agencies across surveillance, drones, geospatial systems, rapid response and mission-specific technology. If your agency is trying to understand a procurement requirement, evaluate compliant technology or identify potential funding sources, our team is happy to help.
This article provides general educational information and should not be considered legal, contracting or grant-compliance advice. Requirements may differ by agency, funding source, state, solicitation and deployment. Consult the applicable contracting officer, grant manager, legal counsel or regulatory authority when determining compliance for a specific procurement.