If your building runs Hikvision or Dahua cameras, the rules changed again this summer — and the coverage around it has been more alarming than accurate. Here’s what actually applies to a private California business, what doesn’t, and what’s worth doing about it.
The short version: your existing cameras are not illegal and nobody is making you take them down. What has closed is the supply line — new units, replacement parts, and matching hardware — along with the support window behind them.
What actually happened, in order
This wasn’t a single ban. It arrived in stages, which is why so many business owners think they missed a deadline.
2019 — NDAA Section 889. Congress barred federal agencies, federal contractors, and recipients of federal grants or loans from buying or using video surveillance equipment from five named manufacturers, Hikvision and Dahua among them. This is a statutory requirement, and it reaches contractor facilities where federal work is performed.
November 2022 — the FCC stops new authorizations. Acting under the Secure Equipment Act of 2021, the FCC prohibited new equipment authorizations for Covered List manufacturers. Most electronic equipment requires an FCC authorization to be legally imported, marketed, or sold, so this closed the front door on new models.
April 2024 — the courts weigh in. The D.C. Circuit upheld the FCC’s core authority but vacated the Commission’s definition of “critical infrastructure” as unjustifiably broad, sending that piece back for a rewrite. The ban survived; the boundaries of one key term did not.
June–July 2026 — the legacy loophole closes. The 2022 rule only applied to new models, so equipment authorized before the cutoff kept flowing into the country. On June 26, 2026 the FCC moved to restrict continued import and marketing of that previously authorized equipment as well, with the restriction taking effect in July. That’s the action behind this summer’s headlines.
What the ban does not do
Three things get consistently overstated, so it’s worth being precise:
It doesn’t require private businesses to remove installed equipment. Existing, legally installed systems can keep operating. There is no rip-and-replace mandate for a private California business with no federal contracts or grant funding.
It doesn’t cover every use equally. For Hikvision and Dahua specifically, the restrictions attach to covered purposes — public safety, government facilities, national security, and physical security surveillance of critical infrastructure — rather than to the manufacturer in every possible context. That’s a meaningful distinction, and it’s also why the critical-infrastructure definition has been litigated for two years.
It isn’t retroactive enforcement. No agency is inspecting private retail stores or warehouses to find cameras.
Who does have to act
The obligation is real and immediate for a specific set of organizations. If your facility takes federal dollars — federal contracts, federal grants, or federally backed funding — Section 889 compliance is a condition of that money, not a recommendation. That reaches further than most people assume: schools and community colleges, municipal buildings, public housing, transit facilities, water and utility infrastructure, and healthcare facilities with federal funding.
For those organizations, covered equipment generally needs to come out and be replaced, and the documentation matters as much as the hardware. If your business bids on federal contracts, or hopes to, the same logic applies before you bid rather than after.
The problem you probably don’t know you have
Here’s the part that catches even careful buyers: Hikvision and Dahua manufacture for dozens of other brands. A significant share of budget and mid-tier cameras sold under other names — including plenty on major retail platforms — are rebadged units from these manufacturers, with no mention of it on the box.
Which means the logo on your camera doesn’t answer the question. If compliance actually matters for your organization, you need documentation at the model and SKU level, not brand-level assurances.
Even without a mandate, the clock is running
For a private business with no federal exposure, the practical pressure isn’t legal. It’s operational, and it comes from three directions.
Parts and expansion. With imports restricted, replacing a failed camera with a matching unit gets harder and more expensive over time. Adding four cameras to an existing system is no longer a routine order.
Firmware and support. A manufacturer effectively shut out of the U.S. market has diminishing reason to invest in supporting U.S. installations. Security cameras that stop receiving firmware updates become network devices with unpatched vulnerabilities sitting on your business network.
Insurance and contracts. Cyber insurance underwriting has grown noticeably more interested in what’s on the network, and commercial contracts increasingly carry supply-chain provisions that didn’t exist five years ago.
None of that forces action this quarter. All of it argues for replacing on a planned schedule rather than during an outage.
How to plan a replacement without wasting the install
Start with an audit. Identify what’s actually installed — manufacturer, model, and firmware, including anything rebadged. This is the step most organizations skip, and it’s the one that determines the size of the job.
Keep the infrastructure. Most replacements don’t require new cabling. Conduit, cable runs, and mounting points usually survive a camera swap, which is the difference between a manageable project and a construction job.
Get compliance documentation at the SKU level. Written confirmation for the specific cameras and recorders you’re buying, not a general brand claim.
Run parallel, then cut over. Stand up the replacement system, confirm recording and retention are working, then decommission the old units — location by location if you’re covering multiple sites. Never decommission first.
A camera swap is a good moment to ask a harder question
If you’re already replacing hardware, it’s worth asking what the cameras are actually accomplishing. Most commercial systems record faithfully and are reviewed only after something has happened — which is useful for an insurance claim and rarely useful for preventing the loss.
Guardian Integrated Security works the other side of that problem. Our monitoring agents watch cameras live, so an intruder is challenged over on-site speakers while they’re still in the parking lot, Guardian’s own patrol is dispatched, and local police are alerted and coordinated with using a verified account of a crime in progress. In cities like Los Angeles, the municipal alarm ordinance explicitly accepts remote video as a form of verification — that distinction also determines whether police respond at all.
We install compliant camera systems across California and can work with most existing infrastructure. Every property starts with a free on-site assessment — including an honest read on whether your current system needs replacing yet. Call (800) 400-3167.
Sources
Section 889 of the National Defense Authorization Act for Fiscal Year 2019 · Secure Equipment Act of 2021 and the FCC’s November 2022 Report and Order on equipment authorizations · FCC Covered List, Public Safety and Homeland Security Bureau · Hikvision USA, Inc. v. FCC, D.C. Circuit decision of April 2, 2024 · FCC action of June 26, 2026 restricting import and marketing of previously authorized covered equipment, published in the Federal Register in July 2026.