NDAA Compliance for UK Companies Working in the US Federal Market (2026)

UK Ltd companies tendering for US federal contracts, subcontracts, or working with the US defense industrial base must comply with NDAA Section 889 — the same prohibition that applies to American prime contractors. This guide covers what that means in practice, which products are compliant, and how to procure them from UK and European channels.

Why NDAA Applies to UK Companies

NDAA Section 889(a)(1)(B) prohibits any entity — including foreign companies — from using covered Chinese telecommunications equipment when operating under a US federal contract or subcontract. The taint rule extends this: if any component in your supply chain originates from a covered entity (Huawei, ZTE, Hikvision, Dahua, Hytera), the entire system is non-compliant.

UK companies encounter NDAA in three scenarios:

  • Subcontracting to a US prime contractor — NDAA compliance flows down through the contract.
  • Supplying security or AV systems to a US federal facility or base — including UK-based US military installations (e.g. RAF Mildenhall, RAF Lakenheath).
  • Tendering on NATO or Five Eyes interoperability contracts — where US procurement standards apply.

Dual Compliance: NDAA + UK Procurement Act 2023

UK companies working cross-border face a complementary framework at home. The UK Procurement Act 2023 enforced its April 2025 deadline requiring removal of Chinese CCTV (Hikvision and Dahua) from all sensitive government sites. The banned entity lists overlap almost exactly.

EntityNDAA Sec 889 (US)UK Procurement Act 2023FCC Covered List
HikvisionBannedBannedListed
DahuaBannedBannedListed
HuaweiBannedBannedListed
ZTEBannedRestrictedListed
HyteraBannedRestrictedListed
DJIFCC ListedRestrictedListed (Dec 2025)

A single compliant procurement policy covers both jurisdictions. UK companies should not maintain separate lists — the overlap is near-total.

NDAA-Compliant Hardware Available Through UK and European Channels

Video Surveillance

BrandNDAATAAUK Distributor
Axis Communications (Swedish)YesYesSeadan, ADI Global
Hanwha Vision (South Korean)YesYesADI Global, Videcon
Bosch Security (German)YesYesBosch direct, Norbain
Avigilon (Motorola Solutions)YesYesMotorola Solutions UK
Vivotek (Taiwanese)YesNoTri-Ed, specialist AV

TAA compliance is required for GSA Schedule contracts. For non-GSA US federal work, NDAA compliance alone is sufficient.

Networking

BrandNDAATAAUK Availability
Cisco MerakiYesYesWide — all major IT distributors
Aruba Networks (HPE)YesYesWide — HPE partner network
Ubiquiti UniFi (networking)YesNoWide — Amazon UK, specialist resellers

Note on TP-Link: TP-Link is under active US government security review as of 2026. Do not specify TP-Link on any contract where NDAA or FCC Covered List compliance is required.

Procurement Route for UK Ltd Companies

UK companies must register in SAM.gov (System for Award Management) before receiving US federal contract payments. NDAA compliance declarations are typically required at contract award and may be audited during performance.

  • Obtain a CAGE Code — register at SAM.gov. UK companies use a NATO CAGE (NCAGE) code issued by the UK National CAGE Office (part of the Defence and Security Accelerator).
  • Obtain a UEI (Unique Entity Identifier) — replaces the legacy DUNS number. Issued through SAM.gov registration.
  • Prepare a NDAA Sec 889 compliance attestation — a written declaration that no covered equipment is used in your performance of the contract. Retain manufacturer compliance letters for all hardware specified.
  • Flow-down requirements — if subcontracting, pass the NDAA compliance obligation to your own supply chain in writing.

Common Compliance Errors by UK Companies

ErrorRisk
Specifying Hikvision or Dahua on a US federal subcontractContract termination, debarment risk
Using TP-Link networking on a US government siteNon-compliance with FCC Covered List (March 2026)
Assuming UK Procurement Act compliance = NDAA compliancePartial overlap only — TAA adds a third layer for GSA work
Purchasing Axis or Hanwha from grey-market sourcesFirmware integrity unverifiable; warranty void
No written compliance attestation in the contract fileAudit exposure; potential False Claims Act liability

Verify Hardware Before Specifying

Use the NDAAz.com MAC Lookup Tool to verify any installed hardware by OUI prefix before specifying it on a US federal contract. The Compliant List contains verified manufacturers organised by category.