What Section 889 actually requires, who it applies to, and the part most vendors gloss over: a compliant VMS does not by itself make your deployment compliant. Here is the real picture, and where Visylix fits in it.
Part of the US National Defense Authorization Act. It restricts covered Chinese-manufactured telecom and video surveillance equipment across the federal supply chain.
Federal agencies cannot buy covered telecommunications or video surveillance equipment. Straightforward, and the part most people know.
Effective August 2020, the government cannot contract with any entity that uses covered equipment anywhere in its operations. Not just on the contract. Anywhere. Including systems the government never pays for.
Covered manufacturers rebadge units under other brand names. The label on the housing does not settle the question. Diligence means tracing the actual manufacturer, not the brand.
Plus their subsidiaries and affiliates, which is where most of the risk actually sits.
A camera sold under an unfamiliar brand may still be a rebadged unit from one of these manufacturers. Verifying the brand on the housing is not diligence.
Section 889 is primarily about equipment. Your cameras, recorders, encoders, and network gear are all in scope. A compliant VMS is a necessary component, not a sufficient one. No software product can make a deployment compliant on its own, and any vendor implying otherwise is overselling.
What a VMS can legitimately do is avoid adding new exposure, stay neutral so you can pick compliant hardware on merit, and let you migrate in stages instead of replacing an entire estate at once.
Visylix is software. Here is exactly what that does and does not cover.
Visylix is video management software. It contains no components from any Section 889 covered entity.
Ships as a Docker image onto your servers. Fully on-premise and air-gap capable, so no video or metadata leaves your network.
ONVIF plus 13 streaming protocols means you choose compliant cameras on merit rather than being locked to one manufacturer.
Onboard compliant cameras alongside existing units. NVR forensic access across 15+ brands including OEMs keeps historical footage reachable during transition.
Work through these before you sign anything, VMS included.
Visylix is vendor-neutral, fully on-premise, and air-gap capable. Talk to our team about staging a migration without replacing your entire estate at once.
This page is general information, not legal advice. NDAA Section 889 obligations depend on your contracts and your equipment inventory. Confirm your position with your own counsel and contracting officer.
Section 889 of the US National Defense Authorization Act restricts federal agencies, and anyone contracting with them, from procuring or using certain Chinese-manufactured telecommunications and video surveillance equipment. Part A bans the federal government from buying it. Part B, effective August 2020, is the far-reaching one: it bars the government from contracting with any entity that uses that equipment anywhere in its operations, even on unrelated systems and even when the government is not paying for it.
The statute names Huawei, ZTE, Hytera, Hangzhou Hikvision, and Dahua Technology, along with their subsidiaries and affiliates. The affiliate and OEM dimension is what catches most buyers: a camera sold under a different brand may still be a rebadged unit from a covered manufacturer. Checking the brand on the housing is not sufficient diligence.
Visylix is video management software, not camera hardware, and it contains no components from any entity covered by Section 889. It ships as a Docker image onto infrastructure you own and can run fully on-premise or air-gapped, so no video or metadata leaves your network. Compliance for a deployment as a whole also depends on the cameras, recorders, and network equipment you attach to it, which is a hardware procurement question rather than a VMS one.
No, and any vendor implying otherwise is overselling. Section 889 is primarily about equipment. A compliant VMS is a necessary component but not sufficient on its own. Your cameras, NVRs, encoders, and network gear all sit in scope. What a VMS can do is avoid adding new exposure, support you in operating compliant hardware, and let you keep using existing non-covered cameras rather than forcing a rip-and-replace.
Yes. Because Visylix is vendor-neutral and speaks ONVIF plus 13 streaming protocols, you can stage a migration rather than replace an entire estate at once. Compliant cameras can be onboarded alongside existing units, and NVR forensic access across 15+ brands including OEMs lets you keep reaching historical footage on legacy recorders during the transition.
Federal agencies, federal contractors and subcontractors at any tier, grant recipients using federal funds, and a growing number of state governments, universities, healthcare systems, and critical-infrastructure operators that have adopted the standard voluntarily or through their own procurement rules. Many enterprises now apply it as a general supply-chain security baseline regardless of whether they hold a federal contract.