If you sell to the federal government or hold a GSA Schedule contract, Section 889 likely applies to you right now. The law splits into two parts: Part A bans agencies from buying covered telecommunications and video surveillance equipment, and Part B bans the government from contracting with any company that uses that equipment in its own operations, anywhere in the business. Do three things this week: run a GSA 889 Representations Search and check your SAM.gov status, pull together a small cross-functional team, and start documenting your “reasonable inquiry” process.
Three FAR clauses drive the paperwork trail:
- FAR 52.204-26 — your annual representation inside SAM.gov
- FAR 52.204-24 — a solicitation-level representation on individual bids
- FAR 52.204-25 — the reporting clause, with a one-business-day initial notice and a ten-business-day follow-up if you find covered equipment
Key Takeaways
Section 889 compliance depends on running a documented reasonable inquiry across your entire enterprise, not just checking a box on a SAM.gov form once a year.
| Point | Details |
|---|---|
| Know Part A vs. Part B | Part A bans government procurement of covered equipment; Part B bans contracting with firms that use it anywhere in their operations. |
| Watch the five named manufacturers | Huawei, ZTE, Hytera, Hikvision, and Dahua are the covered manufacturers cited in official guidance, with possible DoD additions. |
| Track the reporting clock | FAR 52.204-25 requires notice within one business day and full details within ten business days of finding covered equipment. |
| Document, don’t just check | A reasonable inquiry should rely on records you already hold, but the process must be written down and repeatable. |
| Get help with the paperwork | Gsascheduleservices offers a discovery assessment to help contractors document reasonable inquiry and align it with GSA Schedule compliance. |
Table of Contents
- What Does Section 889 Compliance Actually Require?
- What Do the FAR Representation Clauses Require?
- How Do You Run a Reasonable Inquiry?
- How Do You Check GSA and SAM.gov for Section 889 Compliance?
- What Happens If You Find Covered Equipment?
- What Are the Legal Risks of Getting This Wrong?
- What Should Your 30/60/90-Day Compliance Plan Look Like?
- Where Contractors Actually Get Tripped Up
- How Gsascheduleservices Can Help With Section 889 Documentation
- Sources
- FAQ
What Does Section 889 Compliance Actually Require?
Section 889 compliance means proving, with documentation, that neither your company nor its affiliates use banned telecom or video surveillance gear, and that you haven’t sold that gear to the government. Part A took effect August 13, 2019, and stopped federal agencies from procuring the equipment outright. Part B followed a year later, on August 13, 2020, and it’s the one that trips people up. It bars the government from contracting with any company that uses covered equipment “as a substantial or essential component of any system, or as critical technology,” regardless of whether that use touches the federal contract at all.
Five manufacturers get named repeatedly in official guidance: Huawei, ZTE, Hytera, Hikvision, and Dahua, along with their subsidiaries and affiliates. The Department of Defense has authority to expand this list, so don’t treat it as permanently fixed.
By the numbers: Part B applies enterprise-wide. A security camera from Hikvision running your warehouse loading dock counts, even if that warehouse has nothing to do with your federal contract.
“Substantial or essential component” and “critical technology” sound vague on purpose. In practice, contracting officers interpret them broadly. A camera, a router, or a phone system running in the background of daily operations is exactly the kind of thing this rule targets.
What Do the FAR Representation Clauses Require?
The three FAR clauses work at different points in the contracting lifecycle, and mixing them up is one of the more common compliance gaps.
- FAR 52.204-26 requires an annual representation inside SAM.gov, confirming whether your company has or hasn’t conducted a reasonable inquiry and whether you use covered equipment.
- FAR 52.204-24 kicks in at the solicitation level. If you represent that you do use covered equipment, you have to lay out where, what it is, and how it’s used.
- FAR 52.204-25 governs what happens after award, if covered equipment turns up. You must notify the contracting officer within one business day, then follow up within ten business days with specifics.
The reporting clock: FAR 52.204-25 requires an initial notice within 1 business day and a detailed follow-up within 10 business days, including contract and order numbers, supplier and CAGE code, model number, item description, and the mitigation steps already taken.
How Do You Run a Reasonable Inquiry?
“Reasonable inquiry” is the legal standard the whole compliance program hangs on, and GSA guidance is clear that it relies primarily on information your company already has. You don’t automatically need a third-party audit, but you do need a documented, repeatable process. Here’s how to build one:
- Define the scope enterprise-wide. Include affiliates, subsidiaries, remote sites, and employee-owned equipment used for work, not just your headquarters network.
- Assemble the team. Procurement owns vendor records, IT owns network and asset inventories, facilities owns physical hardware like cameras and access control, legal owns documentation standards.
- Pull the data sources. Purchase orders, invoices, asset management exports, vendor questionnaires, maintenance and warranty records, and network device lists all matter here.
- Sample and verify. Spot-check invoices against vendor questionnaires rather than trying to physically inspect every device in every location.
- Document everything, including the negative findings. A file showing you checked and found nothing is worth more than no file at all if you’re ever audited.
Pro Tip: Don’t stop at core IT systems. Commonly missed exposures include video surveillance systems, access-control hardware, networking switches at remote or leased sites, and personal devices employees use for federal work.
Building this into your existing procurement guidelines rather than treating it as a one-off project keeps the inquiry current as vendors and equipment change.

How Do You Check GSA and SAM.gov for Section 889 Compliance?
Two government tools give you a starting point, though neither one is a complete answer on its own.
- GSA’s 889 Representations Search lets you check whether a business has an active Section 889 representation on file in SAM, searchable by business name, website, CAGE code, or Unique Entity ID. It only reflects what’s actually in SAM, so a vendor with no SAM record won’t show up.
- SAM.gov annual representations are where your own company’s certification lives under FAR 52.204-26. Check this yourself before a contracting officer does.
- Internal inventory scans — exports from asset management systems, automated network scripts that fingerprint connected devices, and manual audits of physical security hardware — fill the gaps the government tools can’t reach.
The limitation worth remembering: micro-purchase vendors often aren’t in SAM at all, and every representation is self-reported. The tools tell you what’s on paper. Your own inquiry has to confirm what’s actually installed.
What Happens If You Find Covered Equipment?
Finding a banned camera or router isn’t the disaster it might feel like in the moment, but the clock starts immediately.
- Report within one business day. Notify the contracting officer with whatever you know at that point.
- Follow up within ten business days. Provide the contract and order numbers, supplier name and CAGE code, brand and model, item description, and the mitigation steps you’ve already started.
- Choose a mitigation path. Replace the equipment, physically isolate it from any network touching federal work, or pursue a waiver if replacement isn’t immediately feasible.
- Consider the waiver route only for genuine constraints. The Office of the Director of National Intelligence holds waiver authority on national security grounds, and agency-level waivers require a complete laydown of the equipment plus a phase-out plan and timeline.
Pro Tip: Price out replacement before you assume a waiver is faster. Waiver packages require FASC and ODNI coordination and a documented phase-out plan, which often takes longer than swapping out a single switch or camera.
What Are the Legal Risks of Getting This Wrong?

Certifying compliance without actually doing the inquiry is the riskiest move a contractor can make. A false representation under FAR 52.204-26 or 52.204-24 can trigger False Claims Act liability, and separately, 18 U.S.C. §1001 covers false statements to the federal government.
What’s at stake: False Claims Act cases carry treble damages exposure plus per-claim penalties, on top of contract-level consequences like termination, suspension, or debarment from future federal work.
The fix isn’t complicated: build recurring audits into your procurement calendar, gate new purchases through a Section 889 check before they’re approved, and train procurement staff so accidental buys of prohibited micro-purchase items don’t slip through.
What Should Your 30/60/90-Day Compliance Plan Look Like?
Spreading the work over three phases keeps it from becoming a fire drill.
First 30 days:
- Run the GSA 889 Representations Search and confirm your SAM.gov status.
- Form the cross-functional compliance team.
- Pull a sample of asset inventories from IT and facilities to gauge exposure.
Next 30 days (through day 60):
- Complete the reasonable inquiry for critical systems and high-risk categories like surveillance and networking hardware.
- Update your SAM and solicitation-level representations to reflect what you found.
- Document every finding, including systems you cleared.
Final 30 days (through day 90):
- Draft remediation and phase-out plans for anything flagged.
- Train procurement and materials staff on what to watch for at purchase time.
- Set a recurring audit cadence, quarterly or semiannual, so this doesn’t become a one-time exercise.
Where Contractors Actually Get Tripped Up
Most compliance failures I see aren’t about ignorance of the law. They’re about scope. Companies check their servers and laptops, feel satisfied, and miss the security camera at a leased warehouse or the router an employee bought for a home office three years ago. Those are exactly the items that end up in a contracting officer’s follow-up questions.
The fix is boring but effective: gate every purchase order over a small dollar threshold through a Section 889 check, automate your asset inventory rather than relying on someone’s memory, and revisit the list every quarter. Reasonable inquiry isn’t a project you finish. It’s a habit you maintain, the same way you’d maintain any other federal contractor requirement.
— Josh
How Gsascheduleservices Can Help With Section 889 Documentation
Section 889 compliance and GSA Schedule maintenance run on the same muscle: paperwork that has to be accurate, current, and ready for review on short notice. Gsascheduleservices already handles that kind of documentation work for small and mid-sized federal contractors, and the same team can help you build a defensible reasonable-inquiry record instead of guessing at what a contracting officer will ask for.
A discovery call gets you a readiness assessment, a gap list specific to your current contracts, and a documentation plan you can hand to procurement and legal without rewriting it three times. If you’re maintaining or applying for a GSA Schedule and want Section 889 built into that process instead of bolted on afterward, start with a discovery session and get a straight answer on where you stand.
Sources
FAQ
Is Walmart Section 889 Compliant?
Large retailers that hold federal contracts or sell through GSA channels must submit the same SAM.gov representations as any other contractor, but specific compliance status for individual companies isn’t public beyond what appears in their SAM filings. Check any specific vendor through the GSA 889 Representations Search rather than relying on assumptions.
What Are the Two Exceptions to Section 889?
FAR 52.204-25© lists two narrow exceptions: services that merely connect to a third party’s facilities, such as backhaul or roaming arrangements, and equipment that can’t route or redirect user data or allow visibility into data packets. Both exceptions are interpreted narrowly, so don’t assume a gray-area product qualifies without confirming it.
How Do I Find a Company’s Section 889 Status?
Search the company by name, website, CAGE code, or Unique Entity ID in GSA’s 889 Representations Search, which pulls directly from SAM.gov records. Keep in mind the tool only shows what’s been self-reported, so micro-purchase vendors without a SAM presence won’t appear.
Who Needs to Be NDAA Compliant Under Section 889?
Any business holding or pursuing a federal contract, including GSA Schedule holders, subcontractors above certain thresholds, and their affiliates enterprise-wide, falls under Section 889’s requirements. If your company touches federal procurement in any capacity, assume the representation and reporting obligations apply and confirm your status through SAM.gov.
What Should I Do First If I’m Not Sure My Company Is Covered?
Start with the GSA 889 Representations Search and a SAM.gov review of your own annual representation, then begin a documented reasonable inquiry across procurement, IT, and facilities. Firms working on GSA Schedule applications can fold this directly into their government contracts documentation instead of treating it as a separate project.
Recommended
- Understanding Federal Contractor Requirements: A Guide
- 3 Important Points of TAA Compliance and GSA Policies
- How and Why to assure TAA Compliance with your GSA Contract
- An Essential Checklist to Maintain Your GSA Schedule Contract