Unlock the full potential of Wavestore v6.48 -view our launch presentation today and explore the latest innovations in video management.
For Security Leaders, IT Directors, and Compliance Officers
Physical security systems — access control panels, IP cameras, video management software, cloud platforms — are no longer just locks and lenses. They are networked IT infrastructure, processing biometric data, streaming video to cloud servers, and authenticating identities in real time. And in 2026, the regulatory environment surrounding them has become genuinely consequential.
The FY2026 NDAA was signed by President Trump on 18 December 2025, passing with wide bipartisan margins (Holland & Knight) — and it carries real weight for the physical security industry. Cyber Essentials in the United Kingdom, meanwhile, enters its most rigorous update cycle to date. SOC 2 has evolved from a nice-to-have vendor credential into a baseline procurement requirement across both public and private sectors globally.
For security leaders and compliance officers, the convergence of these frameworks is not a bureaucratic headache — it is an opportunity. Organisations that understand and operationalise these requirements will protect their infrastructure, win more contracts, and build resilient systems that endure.
Those that ignore them face contract loss, legal exposure, and the real risk of deploying compromised hardware inside their own perimeters.
In physical security, NDAA compliance usually refers to the procurement restrictions tied to Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019. For security buyers, the issue is practical: certain telecommunications and video surveillance equipment can create procurement, supplier, and replacement risk in government, critical infrastructure, public safety, and other security-sensitive environments.
Section 889(a)(1)(A) took effect on August 13, 2019 and prohibits executive agencies from procuring covered telecommunications equipment or services. Section 889(a)(1)(B) took effect on August 13, 2020 and prohibits agencies from entering into, extending, or renewing contracts with entities that use covered telecommunications equipment or services in the relevant way.
For physical security procurement, the named manufacturers that matter most are Huawei and ZTE, and for public safety, government facility security, physical security surveillance of critical infrastructure, and other national security purposes, Hytera, Hikvision, and Dahua, including subsidiaries and affiliates. The rule also extends beyond hardware to video surveillance or telecommunications services provided by those entities or using such equipment.
The practical implication is simple: NDAA compliance is no longer a niche legal issue. It is now a sourcing, risk, and procurement standard for organisations that need trusted surveillance infrastructure.
For most physical security teams, the question is not whether NDAA is important in theory. It is whether a camera, platform, service, or supplier creates covered-equipment exposure in practice.
That means buyers should check:
This is why NDAA compliance should be treated as a procurement workflow, not just a policy reference.
Hardware from banned vendors often carries risks that extend well beyond brand politics. Devices manufactured by state-linked companies may contain backdoors, undisclosed remote access capabilities, or firmware vulnerabilities that have never been independently audited. When such devices are deployed inside a corporate or government network, they represent a persistent, low-visibility threat.
Your CCTV infrastructure streams data to servers, receives firmware updates, and in many cases connects directly to cloud management platforms. These are not just cameras — they are networked IT systems that process sensitive data, and they historically have been managed with far less cybersecurity rigour than other enterprise IT infrastructure.
Experience shows that supply chain and compliance requirements are bound to become high-priority issues in M&A diligence and prime targets for False Claims Act enforcement. For any organisation operating in a federally funded environment — whether directly or as a downstream subcontractor — deploying Section 889-banned equipment can result in contract termination and ineligibility for future awards.
One of the trickiest aspects of NDAA compliance is that it covers both direct and indirect use. Direct use means an agency purchases or installs a banned product. Indirect use occurs when a non-compliant component, such as a chipset or camera module, is embedded within an otherwise approved system.
One of the hardest parts of NDAA compliance is identifying hidden exposure inside the supply chain. A camera may not carry the name of a covered manufacturer on the box, but that does not automatically remove risk if the firmware lineage, OEM relationship, or underlying components still trace back to a covered entity.
This is not just a theoretical problem. In its May 19, 2026 report, the U.S. Government Accountability Office said some agencies faced difficulty identifying covered equipment because visibility into product supply chains was limited. GAO also noted that manufacturers were sometimes reluctant to share proprietary supply-chain information, making it harder to determine whether existing devices contained components produced by covered entities.
For buyers, the lesson is clear: surface branding is not enough. Due diligence should include written supplier confirmation, review of OEM and affiliate relationships, and a procurement process designed to uncover hidden exposure before deployment.
The FCC’s Covered List adds an important layer of clarity for buyers. The FCC states that covered equipment and services on the list have been determined to pose an unacceptable risk to the national security of the United States or the security and safety of U.S. persons.
That matters because it frames the issue as more than a contract technicality. For procurement and compliance teams, it reinforces that surveillance sourcing is now part of a wider trust, resilience, and national-security conversation.
Beyond the legal and financial impact, NDAA compliance represents a commitment to responsible technology sourcing and network security. Enterprise clients, insurers, and major institutional buyers are increasingly requiring compliance documentation as a condition of supplier qualification.
A common mistake is to assume NDAA is only relevant to U.S. federal agencies. In reality, the effects travel much further across global procurement and supply chains.
If your organisation supplies into U.S. government work, supports prime contractors, serves critical infrastructure, or wants to stay eligible for future regulated programmes, NDAA compliance becomes commercially relevant even outside the United States. It is also increasingly a market trust signal for multinational buyers that want stronger sourcing assurance from security vendors.
For UK and European organisations, the practical takeaway is this: NDAA compliance should be treated as an early warning indicator of where security procurement is heading. Buyers that build trusted sourcing into their platform decisions now are less likely to face expensive remediation later.
Physical security has moved to the cloud. Access control systems now run on SaaS platforms, and video footage is processed and stored in cloud infrastructure. This architectural shift has made two certification frameworks essential: Cyber Essentials and SOC 2.
The v3.3 update to Cyber Essentials Plus places sharper emphasis on technical assurance over narrative responses — forcing organisations to prove controls are working, not just documented.
Key changes directly relevant to physical security:
Cyber Essentials has become more than a compliance checkbox — it is increasingly tied to procurement requirements, supply chain expectations, and customer confidence.
SOC 2 is an auditing standard that evaluates cloud service providers against five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
For security leaders, SOC 2 Type II is the relevant credential. It covers not just the existence of controls at a point in time, but their consistent operational effectiveness over six to twelve months. A vendor without a current SOC 2 Type II report has a security posture that has not been independently verified — an unacceptable standard in 2026.
A genuinely secure physical security platform must protect sensitive data across its entire lifecycle.
Sensitive data held within a physical security platform includes access event logs, badge credentials, biometric templates, recorded video footage, and visitor records. The minimum standard for this data in 2026 is AES-256 encryption at rest, applied to both primary storage and backups.
Storage security also encompasses access controls: only authenticated, authorised services and personnel should be able to read or modify stored records. Role-based access control (RBAC) with least privilege principles should govern who can export, delete, or modify historical data.
All communication between physical security devices, on-premise servers, and cloud management platforms must be encrypted using TLS 1.2 or higher. Legacy unencrypted protocols represent exploitable attack surfaces and should be considered disqualifying.
Zero Trust Architecture (ZTA) assumes no user, device, application, or network segment should be trusted by default. For physical security systems, this means cameras and access readers are treated as untrusted endpoints until verified, and administrative access requires MFA and continuous logging.
A UK-based facilities management company installs access control for a US defence contractor's UK offices, using a camera brand not on the banned list. What they do not check is that the camera uses a Hikvision-derived chipset. Eighteen months later, an audit fails the cameras. The integrator faces contract termination and a rip-and-replace. **Lesson:** Demand firmware lineage before procurement.
A European corporate headquarters deploys a well-priced cloud-based access control system. When the CISO requests a SOC 2 Type II report for insurance, the vendor cannot produce one. A penetration test reveals access event logs are stored unencrypted. The result is forced migration and unexpected spend. **Lesson:** Ask for SOC 2 Type II reports upfront.
A UK-based financial institution selects a physical security platform that publicly documents NDAA compliance, holds SOC 2 Type II, and is Cyber Essentials Plus certified. When the institution tenders for a US programme, their security posture is documented and requires no remediation. Compliance becomes a competitive advantage.
Before approving a new surveillance deployment, buyers should:
FAR 52.204-25 defines a “reasonable inquiry” as an inquiry designed to uncover information in the entity’s possession about the identity of the producer or provider of covered telecommunications equipment or services, without requiring an internal or third-party audit. That makes it a practical standard for procurement teams, not just a legal concept.
What does NDAA compliance mean in physical security?
In practical terms, NDAA compliance means assessing whether a camera, VMS, service, or supplier creates exposure under the covered-equipment framework and then making procurement decisions accordingly.
Which manufacturers are commonly associated with NDAA risk?
The core names most relevant to physical security procurement are Huawei, ZTE, Hytera, Hikvision, and Dahua, including subsidiaries and affiliates where applicable.
Can rebranded cameras still create NDAA risk?
Yes. Supply-chain visibility can be limited, and branding alone does not guarantee that the underlying hardware, firmware, or component lineage is free from covered-entity exposure.
The convergence of NDAA, Cyber Essentials, and SOC 2 in 2026 is a response to a demonstrable threat: the exploitation of physical security infrastructure for cyber attacks. The attacks of 2025 made one thing undeniably clear: physical security is IT security. The physical security perimeter and the cybersecurity perimeter are the same perimeter.
Companies that build compliance into their security architecture will win contracts and operate infrastructure they can genuinely trust. The frameworks to protect both have never been clearer.
Will your organisation act before a compliance failure makes the decision for you? Book a Migration Consultation today to learn how Wavestore's NDAA-certified, SOC 2 Type II compliant WaveFusion platform secures your perimeter and your data.

Solutions for a world we can't yet see. Discover v6.48 features helping people and businesses.
