NDAA Compliance Checklist: Government Contractor Guide

Table of Contents

Last Updated: September 13, 2026

Quick NDAA Compliance Checklist Reference

An NDAA compliance checklist for government contractors is a structured set of verification steps covering prohibited equipment, FAR and DFARS flow-downs, cybersecurity standards, and audit documentation. Systems Integrations helps contractors across the Delaware Valley and Florida build these controls into daily operations rather than treating them as a pre-award scramble.

The checklist below summarizes what the rest of this guide explains in detail. Use it as a working reference, not a one-time exercise.

Requirement What It Covers Where It Applies Typical Owner
Section 889 Part A Prohibited telecom and video surveillance equipment All contracts and subcontracts Procurement, IT
Section 889 Part B Covered equipment and services from named entities All contracts and subcontracts Procurement, security
FAR 52.204-25 Flow-down to subcontractors at every tier Prime and sub contracts Contracts, supply chain
NIST 800-171 Protection of controlled unclassified information Systems handling CUI IT, security
CMMC 2.0 Certification of cybersecurity practices Defense contracts Compliance lead
Incurred Cost Submission Adequacy of cost documentation Cost-reimbursement contracts Finance, DCAA liaison
FOCI Disclosure Foreign ownership, control, or influence reporting Entities with foreign ties Legal, security
Pro Tip
Most contractors fail their first internal review on the same two items: unverified subcontractor representations and physical security devices that were never checked against the prohibited list. Both are cheap to fix early and expensive to fix during an audit.

Section 889: Prohibited Telecommunications and Video Surveillance Equipment

Section 889 compliance is the single most common gap we see when reviewing contractor facilities. It prohibits federal agencies and their contractors from using certain telecommunications and video surveillance equipment, and it applies to your physical security infrastructure, not just your IT stack.

A security integrator and a government contractor reviewing a laptop with a checklist of prohibited equipment in a modern office, with a whiteboard showing compliance notes in the background

The practical implication is that every camera, access control panel, and network device on a covered site needs a documented origin check. Many contractors audit their servers and ignore the cameras mounted above them.

Part A vs. Part B: What Each Prohibits

Part A prohibits agencies from procuring, obtaining, extending, or renewing contracts for covered equipment and services from specific named entities. Part B goes further: it prohibits using that equipment or those services as a substantial or essential component of any system, even if the contract itself doesn’t mention them.

The distinction matters because Part B catches equipment you already own and operate. A camera installed years ago on a facility network can create a compliance problem today.

Covered Equipment and Services List

The covered list includes video surveillance and telecommunications equipment produced by named entities, along with related services such as installation, maintenance, and managed support. Because the list changes, contractors should verify against the current federal source rather than a saved PDF from a previous year.

The FAR 52.204-25 text on acquisition.gov is the authoritative reference for the clause language itself.

FAR 52.204-25 Compliance: Flow-Down Clauses and Subcontractor Management

FAR 52.204-25 compliance requires prime contractors to flow the prohibition down to every subcontractor and to verify that those subcontractors are not supplying covered equipment. This is the clause that turns Section 889 from a purchasing rule into a supply chain obligation.

Subcontractor management is where most primes lose control. You can vet your own vendors thoroughly and still inherit a problem from a tier-two supplier that nobody asked.

A workable flow-down process includes three elements:

  • A written representation from each subcontractor at every tier
  • A documented review of the equipment and services they provide
  • A record of when that verification happened and who signed off
Watch Out
Accepting a verbal assurance from a subcontractor is not a flow-down. If an auditor asks for the written representation and you don’t have it, the prime carries the liability, not the sub.

NDAA Compliance Certification Process: Representation, Disclosure, and Documentation

The NDAA compliance certification process is the documentation trail that proves your organization checked, verified, and disclosed as required. “Certification” here means the representations you make in SAM.gov and in contract performance, not a single certificate you hang on a wall.

The Representations You Actually Sign

Three federal representations do most of the work, and each has a different trigger:

  • FAR 52.204-26 (Covered Telecommunications Equipment or Services, Representation). Completed annually in SAM.gov as part of your entity registration. It asks whether your organization uses any covered equipment or services. If you answer “does not use,” you have certified that across your entire enterprise, not just the contract at hand.
  • FAR 52.204-25 (Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment). Flowed into contracts and subcontracts. The clause itself contains a representation that the offeror will not provide covered equipment as a substantial or essential component of any system.
  • FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems). Applies when your systems process, store, or transmit federal contract information. It is the on-ramp to NIST SP 800-171 when CUI is involved.

A common pattern is for contractors to update SAM.gov once a year and assume that satisfies every downstream obligation. It does not. The SAM.gov representation is a snapshot; the contract-level representation is a continuing obligation.

Mandatory Disclosure Under FAR 52.203-13

If your contract exceeds the simplified acquisition threshold and has a performance period of 120 days or more, FAR 52.203-13 requires you to disclose, in writing, credible evidence of a violation of federal criminal law involving fraud, conflict of interest, bribery, or gratuity, or a violation of the civil False Claims Act. A Section 889 violation that involves a false representation can fall inside that boundary.

Disclosure goes to the agency Office of Inspector General and the contracting officer. Voluntary disclosure is almost always the better path. Concealment converts a fixable problem into a procurement integrity issue, and suspension or debarment exposure follows.

Documentation That Survives an Audit

A compliance log that an auditor can follow should capture, at minimum:

  • Who performed each verification and on what date
  • What equipment or service was reviewed and against which version of the covered list
  • Which contract or subcontract the review supported
  • How any exception or finding was resolved, and by whom
  • When and to whom any disclosure was made

Maintain the log continuously. A binder assembled the week before an audit tends to have gaps precisely where the auditor looks first, the dates and the sign-offs.

Watch Out
A SAM.gov representation that says “does not use covered equipment” is a certification. If a later audit finds a prohibited camera on a covered site, the representation itself becomes the exposure, separate from the underlying equipment issue.
Key Takeaway
Treat the certification process as three layers, annual SAM.gov representation, contract-level clause compliance, and event-driven disclosure, and keep one log that ties all three together.

Integrating NDAA with CMMC 2.0 and NIST 800-171

Integrating NDAA requirements with CMMC 2.0 and NIST 800-171 is where physical and cyber compliance converge. The same device that fails a Section 889 check may also be an unmanaged endpoint on a network handling controlled unclassified information.

NIST 800-171 sets the requirements for protecting CUI. CMMC 2.0 adds an assessment mechanism, and for many defense contracts it makes the previously self-attested practices verifiable. Contractors that treat these as separate workstreams end up duplicating effort and missing overlaps.

The overlap is real. Asset inventory, access control, and network segmentation serve both frameworks. A camera system running on a segmented network with documented device provenance satisfies physical security needs and reduces CMMC scope at the same time.

NIST SP 800-171 guidance remains the reference point for how CUI protection requirements are structured.

FREE CONSULTATION →

Key Takeaway
Treat NDAA, NIST 800-171, and CMMC 2.0 as one compliance program with three reporting lenses. Contractors who do this cut audit preparation time substantially because the evidence is the same evidence.

Audit Readiness, Internal Controls, and Post-Audit Remediation

Audit readiness comes down to whether your internal controls produce evidence on demand. DCAA and contracting officers don’t want to hear that a control exists; they want to see the artifact.

DCAA Accounting System Adequacy

For cost-reimbursement, time-and-materials, and certain fixed-price incentive contracts, the contracting officer relies on a DCAA pre-award survey of your accounting system. The survey tests whether the system meets the criteria in FAR 16.301-3 and the DFARS business system rules. In practice, DCAA looks for six things:

  • A system that segregates direct and indirect costs
  • A timekeeping system that captures labor by contract and by employee
  • A general ledger that ties to the job cost ledger
  • A chart of accounts that supports cost accumulation by contract
  • Interim (at least monthly) financial statements and job cost reports
  • A documented, consistently applied indirect rate structure

A system that fails any one of these typically produces a disapproved accounting system finding, which can hold up award on cost-type work until it is corrected.

Incurred Cost Submission Adequacy

If you hold cost-reimbursement contracts, you generally must submit an incurred cost submission (ICS) within six months after your fiscal year end. DCAA reviews it for adequacy before it audits the claimed rates. Common adequacy failures include:

  • Missing or unsigned schedules
  • Indirect rates that don’t reconcile to the general ledger
  • Unallowable costs that were not screened out
  • No supporting detail for the claimed base and pool amounts

A submission that DCAA deems inadequate is returned, and the clock restarts. Contractors that build the ICS from the same job cost data they use monthly tend to pass adequacy review on the first pass.

Internal Controls That Produce Evidence

Internal controls for NDAA compliance typically include segregation of duties between purchasing and verification, a documented approval path for new equipment, and periodic reconciliation of the asset inventory against the covered list. The control that most often fails is the reconciliation, because it is the one nobody owns.

A workable cadence is quarterly: pull the asset inventory, compare it to the current covered list, document any matches or near-matches, and route exceptions to a named owner with a due date.

Post-Audit Remediation: What to Do When a Finding Lands

Post-audit remediation is the step most guides skip. When a finding is issued, the response needs four elements:

  • Root cause. Not “the camera was missed,” but “the receiving process never checked device origin against the covered list.”
  • Corrective action. A specific change to the process, with an owner and a completion date.
  • Verification. Evidence that the fix holds, a sample re-test, a second reconciliation, a spot audit.
  • Systemic check. A scan of other sites or contracts for the same condition, so the finding doesn’t reappear under a different contract number.

Repeating the same finding in the next audit cycle signals a control that was never really implemented. DCAA tracks repeat findings, and they weigh heavily in business system disapproval decisions.

Pro Tip
Build a one-page corrective action template now, before you need it. Root cause, corrective action, owner, due date, verification method. When a finding lands, you fill in the blanks instead of drafting from scratch under deadline.
Key Takeaway
Audit readiness is not a binder. It is a set of controls that generate artifacts on a schedule, plus a remediation process that closes findings with evidence the fix actually holds.

Automated Compliance Monitoring and FOCI Disclosure for Contractors

Automated compliance monitoring tools reduce the manual burden of tracking equipment lists, subcontractor representations, and certificate expirations. For contractors with multiple sites, spreadsheets stop working once the portfolio grows past a handful of locations.

FOCI disclosure requirements apply to entities with foreign ownership, control, or influence. Contractors with international operations or foreign investors need to assess whether those relationships trigger reporting, and physical security vendors with foreign ties can themselves become part of the analysis.

This is where a cybercentric approach to physical security pays off. Systems Integrations designs NDAA-compliant video surveillance, card access, and intrusion systems with documented device provenance and centralized management across multi-site portfolios, which gives contractors a single point of contact and a cleaner evidence trail. You can review the video surveillance and card access capabilities directly.

Best For
Contractors running multiple facilities that need one compliance-ready security platform instead of site-by-site vendors.

Conclusion: Your Next Steps to NDAA Compliance

The hard part of NDAA compliance isn’t understanding the rules. It’s maintaining evidence across every site, subcontractor, and device while the covered list keeps changing.

Systems Integrations builds NDAA-compliant physical security systems with documented provenance, centralized cloud management, and a single point of contact for distributed organizations. Systems Integrations brings over 25 years of experience, certified installation coordination, and ongoing lifecycle support so your compliance evidence stays current.

Get started with Systems Integrations and turn your physical security infrastructure into an audit-ready asset rather than a liability.

Frequently Asked Questions

What is Section 889 of the NDAA?

Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 prohibits federal agencies and their contractors from procuring or using certain telecommunications and video surveillance equipment from specified Chinese companies. It has two parts: Part A bans products from five named companies, and Part B bans any equipment or services from those companies used as a substantial or essential component of any system. Compliance is required for all federal contracts and flows down to subcontractors.

Which video surveillance equipment is prohibited under the NDAA?

The NDAA prohibits video surveillance and telecommunications equipment from Huawei, ZTE, Hikvision, Dahua, and Hytera, including their subsidiaries and affiliates. This covers cameras, recorders, network switches, and management software. Contractors must remove or replace any such equipment from their systems and certify that they do not use it. Using prohibited equipment can lead to contract termination and debarment.

How do government contractors verify NDAA compliance?

Contractors verify compliance by conducting supply chain risk assessments, auditing their equipment inventories against the prohibited list, and obtaining written certifications from subcontractors. They must also maintain documentation for audits. The NDAA compliance certification process involves signing a representation in the contract (FAR 52.204-25) and keeping records. Many use automated compliance monitoring tools to continuously scan for prohibited components.

What are the penalties for non-compliance with NDAA regulations?

Penalties for NDAA non-compliance include contract termination, suspension or debarment from federal contracting, financial penalties under the False Claims Act, and reputational damage. The government may also require remediation at the contractor’s expense. Since compliance is a condition of contract award, failure to meet Section 889 requirements can result in losing current and future contracts.

Does NDAA compliance apply to all government contractors?

NDAA compliance applies to all prime contractors and subcontractors that provide products or services to federal agencies, regardless of size. The requirements flow down through FAR 52.204-25, so even small businesses must comply. However, the specific obligations depend on the contract type and whether equipment is involved. Contractors with no federal contracts are not directly subject to Section 889, but may face similar requirements from commercial clients.

How does NDAA compliance integrate with CMMC 2.0?

NDAA compliance and CMMC 2.0 both aim to protect the defense supply chain. Section 889 focuses on prohibited equipment, while CMMC 2.0 requires cybersecurity maturity based on NIST 800-171. Contractors can integrate the two by including NDAA checks in their CMMC assessment scope. Automated compliance monitoring tools can track both NDAA and CMMC requirements, reducing duplication and ensuring audit readiness.

Contact Us

Systems Integrations 2025 | All Rights Reserved