Full Report
Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 prohibits federal agencies from procuring covered telecommunications and surveillance equipment and services from five specific Chinese companies (and their affiliates or subsidiaries) or awarding contracts to companies that use such equipment and services. Following implementation in fiscal year 2019, agencies…
Analysis Summary
# Regulation/Compliance: Section 889 of the NDAA FY 2019
## Overview
Section 889 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year 2019 is a supply chain integrity mandate. It prohibits the U.S. federal government from procuring or using telecommunications and video surveillance equipment or services from specific Chinese entities and their affiliates. Crucially, it also prohibits agencies from entering into contracts with entities that use such equipment, even if that equipment is not used in performance of a federal contract.
## Key Details
- **Issuing Authority:** U.S. Federal Government / Congress
- **Effective Date:** Phased implementation began in August 2019 (Part A) and August 2020 (Part B).
- **Jurisdiction:** U.S. Federal Agencies and all companies contracting with the U.S. Government.
- **Status:** In Effect (with ongoing GAO oversight and upcoming expansions).
## Requirements
### Mandatory Requirements
1. **Direct Procurement Prohibition (Part A):** Federal agencies may not procure or obtain any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component.
2. **Contractor Use Prohibition (Part B):** Federal agencies may not enter into, extend, or renew a contract with an entity that *uses* any covered equipment or services, regardless of whether that usage is related to federal work.
3. **Representation:** Contractors must publicly represent their compliance (or non-compliance) within the System for Award Management (SAM).
4. **Reporting:** Mandatory reporting by contractors if prohibited equipment is identified during contract performance.
### Recommended Practices
1. **Supply Chain Mapping:** Identifying the origin of components down to the sub-tier supplier level.
2. **Customs Data Analysis:** Utilizing customs and trade data to verify the origin of goods.
3. **Cross-Agency Information Sharing:** Agencies (specifically GSA and DOD) are encouraged to share insights regarding subsidiaries and affiliates of prohibited entities.
## Affected Organizations
- **Industries:** All sectors selling to the U.S. Federal Government (Defense, IT, Construction, Logistics, etc.).
- **Organization Size:** All sizes (no de minimis exception for small businesses).
- **Geographic Scope:** Global (applies to any entity worldwide seeking to contract with the U.S. Government).
## Compliance Timeline
- **August 13, 2019:** Part A Effective (Prohibition on government direct purchase).
- **August 13, 2020:** Part B Effective (Prohibition on contracting with entities that use covered equipment).
- **FY 2025-2026:** GAO reporting indicates near 90% compliance representation among active contractors.
- **Future:** Anticipated statutory prohibitions to expand into other sectors, such as semiconductors.
## Implementation Guidance
### Assessment Phase
- **Inventory Audit:** Conduct a comprehensive audit of internal telecommunications and video surveillance equipment (e.g., routers, switches, security cameras).
- **Vendor Inquiry:** Issue certifications to all suppliers to confirm they do not provide or use equipment from the five prohibited companies.
### Implementation Phase
- **Removal/Replacement:** Decommission and replace any identified "covered" equipment.
- **Policy Update:** Update procurement policies to explicitly forbid the purchase of prohibited Chinese telecommunications brands.
- **SAM Registration:** Ensure the "Representation" section in SAM.gov is accurately updated to reflect non-use.
### Validation Phase
- **SAM Search Tools:** Contracting officers use DOD/GSA search tools to verify contractor representations.
- **Automated Scrubbing:** GSA utilizes automated processes to remove prohibited items from Multiple Award Schedules.
## Technical Requirements
- **Prohibited Entities:** Equipment or services from **Huawei, ZTE, Hikvision, Dahua, and Hytera** (including subsidiaries and affiliates).
- **Scope of Tech:** Telecommunications equipment, video surveillance equipment, and specific components (e.g., chips or subsystems) from these entities.
## Penalties & Enforcement
- **Fines:** Potential for False Claims Act (FCA) litigation if a contractor misrepresents compliance.
- **Other Consequences:** Contract termination, debarment, or suspension from future federal bidding.
- **Enforcement:** Enforced by agency contracting officers and audited by the GAO; GSA utilizes automated "removal" processes for contract schedules.
## Related Standards
- **NIST SP 800-161:** Supply Chain Risk Management Practices for Federal Information Systems.
- **FASCSA (Federal Acquisition Security Council):** Works in tandem to identify and exclude high-risk vendors.
## Resources
- **Official Documentation:** [https://www.acquisition.gov/far/part-4#FAR_4_21] (Defanged)
- **Guidance Documents:** GAO Report 26-108630.
- **Tools:** System for Award Management (SAM.gov).
## Practical Recommendations
- **Identify Affiliates:** Organizations must look beyond the "Big 5" names, as the prohibition extends to hundreds of subsidiaries.
- **Prepare for Expansion:** Use current Section 889 frameworks to prepare for upcoming restrictions on foreign-sourced semiconductors.
- **Continuous Monitoring:** Supply chains change; annual certifications from sub-vendors are necessary to maintain compliance.