UK Ltd companies tendering for US federal contracts, subcontracts, or working with the US defense industrial base must comply with NDAA Section 889 — the same prohibition that applies to American prime contractors. This guide covers what that means in practice, which products are compliant, and how to procure them from UK and European channels.
Why NDAA Applies to UK Companies
NDAA Section 889(a)(1)(B) prohibits any entity — including foreign companies — from using covered Chinese telecommunications equipment when operating under a US federal contract or subcontract. The taint rule extends this: if any component in your supply chain originates from a covered entity (Huawei, ZTE, Hikvision, Dahua, Hytera), the entire system is non-compliant.
UK companies encounter NDAA in three scenarios:
- Subcontracting to a US prime contractor — NDAA compliance flows down through the contract.
- Supplying security or AV systems to a US federal facility or base — including UK-based US military installations (e.g. RAF Mildenhall, RAF Lakenheath).
- Tendering on NATO or Five Eyes interoperability contracts — where US procurement standards apply.
Dual Compliance: NDAA + UK Procurement Act 2023
UK companies working cross-border face a complementary framework at home. The UK Procurement Act 2023 enforced its April 2025 deadline requiring removal of Chinese CCTV (Hikvision and Dahua) from all sensitive government sites. The banned entity lists overlap almost exactly.
| Entity | NDAA Sec 889 (US) | UK Procurement Act 2023 | FCC Covered List |
|---|---|---|---|
| Hikvision | Banned | Banned | Listed |
| Dahua | Banned | Banned | Listed |
| Huawei | Banned | Banned | Listed |
| ZTE | Banned | Restricted | Listed |
| Hytera | Banned | Restricted | Listed |
| DJI | FCC Listed | Restricted | Listed (Dec 2025) |
A single compliant procurement policy covers both jurisdictions. UK companies should not maintain separate lists — the overlap is near-total.
NDAA-Compliant Hardware Available Through UK and European Channels
Video Surveillance
| Brand | NDAA | TAA | UK Distributor |
|---|---|---|---|
| Axis Communications (Swedish) | Yes | Yes | Seadan, ADI Global |
| Hanwha Vision (South Korean) | Yes | Yes | ADI Global, Videcon |
| Bosch Security (German) | Yes | Yes | Bosch direct, Norbain |
| Avigilon (Motorola Solutions) | Yes | Yes | Motorola Solutions UK |
| Vivotek (Taiwanese) | Yes | No | Tri-Ed, specialist AV |
TAA compliance is required for GSA Schedule contracts. For non-GSA US federal work, NDAA compliance alone is sufficient.
Networking
| Brand | NDAA | TAA | UK Availability |
|---|---|---|---|
| Cisco Meraki | Yes | Yes | Wide — all major IT distributors |
| Aruba Networks (HPE) | Yes | Yes | Wide — HPE partner network |
| Ubiquiti UniFi (networking) | Yes | No | Wide — Amazon UK, specialist resellers |
Note on TP-Link: TP-Link is under active US government security review as of 2026. Do not specify TP-Link on any contract where NDAA or FCC Covered List compliance is required.
Procurement Route for UK Ltd Companies
UK companies must register in SAM.gov (System for Award Management) before receiving US federal contract payments. NDAA compliance declarations are typically required at contract award and may be audited during performance.
- Obtain a CAGE Code — register at SAM.gov. UK companies use a NATO CAGE (NCAGE) code issued by the UK National CAGE Office (part of the Defence and Security Accelerator).
- Obtain a UEI (Unique Entity Identifier) — replaces the legacy DUNS number. Issued through SAM.gov registration.
- Prepare a NDAA Sec 889 compliance attestation — a written declaration that no covered equipment is used in your performance of the contract. Retain manufacturer compliance letters for all hardware specified.
- Flow-down requirements — if subcontracting, pass the NDAA compliance obligation to your own supply chain in writing.
Common Compliance Errors by UK Companies
| Error | Risk |
|---|---|
| Specifying Hikvision or Dahua on a US federal subcontract | Contract termination, debarment risk |
| Using TP-Link networking on a US government site | Non-compliance with FCC Covered List (March 2026) |
| Assuming UK Procurement Act compliance = NDAA compliance | Partial overlap only — TAA adds a third layer for GSA work |
| Purchasing Axis or Hanwha from grey-market sources | Firmware integrity unverifiable; warranty void |
| No written compliance attestation in the contract file | Audit exposure; potential False Claims Act liability |
Verify Hardware Before Specifying
Use the NDAAz.com MAC Lookup Tool to verify any installed hardware by OUI prefix before specifying it on a US federal contract. The Compliant List contains verified manufacturers organised by category.