compliancefar-section-889far-889-prohibitioncovered-telecommunicationsfederal-supply-chain-securityprohibited-vendors

FAR section 889 compliance: what federal contractors miss in Part B and why it costs them contracts

Julian ThorneJulian ThorneApril 29, 2026
Share:
FAR section 889 compliance: what federal contractors miss in Part B and why it costs them contracts

Key takeaways

  • FAR 889 Part B prohibits using any system with covered telecommunications equipment as a substantial or essential component, capturing violations that Part A procurement screens miss entirely.

  • Rebranded Chinese-manufactured video surveillance components from Hikvision and Dahua subsidiaries appear in products sold under non-Chinese brand names, creating violations in supply chains that passed standard vendor screening.

  • Reasonable inquiry under FAR 889 requires component-level documentation review, not vendor attestation forms alone. Accepting self-certification without examining product bills of materials does not satisfy the standard.

  • Prime contractors bear full compliance responsibility for subcontractor violations, including False Claims Act exposure if the prime accepted subcontractor certifications without adequate verification.

  • FAR 889 audit findings concentrate in systems that were compliant at procurement and became non-compliant through product refresh cycles that introduced covered components without re-screening.

  • A cure notice following a FAR 889 violation typically gives 30 days to demonstrate remediation progress. Most contractors discover at that point that their replacement timeline is measured in months, not weeks.

TL;DR

FAR section 889 compliance has two layers and most contractors have only built one of them. Part A screens for named vendors at the point of purchase. Part B catches covered equipment that enters through subcontractors, embedded components, and rebranded products. The audits that produce contract terminations are almost always finding Part B violations in supply chains where procurement-level screening passed cleanly. The attack surface for non-compliance is not in what you knowingly bought. It is in what you did not look inside.

What a FAR 889 audit actually looks like from the outside

A federal systems integrator supporting a civilian agency contract had been FAR 889 compliant since the regulation took effect. Their procurement team screened every purchase order against the covered entities list. Their SAM.gov representations were current. Subcontractor certifications were on file for all first-tier relationships. The compliance officer had reviewed the process with outside counsel. When the contracting officer's representative initiated a routine supply chain review in the second year of the contract, the focus was not on procurement records. It was on the network video recorders installed at two field office locations as part of the integrator's managed services scope. The units had been sourced from a domestic reseller, purchased under a non-Chinese brand, and were not on any covered entities list. The firmware signature identified them as running Hikvision software. The underlying hardware was manufactured by a Hikvision subsidiary.

Turning point:

The procurement screen had passed cleanly because the purchase order named a US reseller selling under its own brand. The component analysis, which nobody had run because the product category was not flagged for deeper review, showed covered equipment as a substantial component of the system. The integrator received a cure notice. The replacement timeline for deployed hardware at two federal facilities was estimated at four months. The contract had eight months remaining.

Why Part B creates exposure that Part A processes cannot catch

Part A of FAR 889 operates at the procurement transaction level. If a contractor is buying covered telecommunications equipment or services directly from a prohibited vendor, Part A catches it. The control is straightforward: screen the vendor, screen the product category, certify compliance.

Part B operates at the system level. It prohibits entering into a contract with the federal government if the contractor uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The word 'uses' is doing significant work. It applies to systems the contractor operates in performing the contract, not just systems it sold.

The practical consequence is that a contractor can purchase a product from a US-domiciled vendor, under a US brand name, on a purchase order that shows no prohibited vendor anywhere in the transaction record, and still be in violation of Part B if the product contains covered components. The violation is invisible to a procurement-level compliance process.

The market condition that makes this endemic is OEM and white-label manufacturing. Chinese manufacturers, including covered entities and their subsidiaries, produce hardware that is sold under dozens of non-Chinese brand names in the US market. Video surveillance equipment is the highest-risk category. A camera unit sold by a US distributor under a US brand may contain an imaging module, compression chipset, or firmware stack from a covered entity or its subsidiary. The distributor's product data sheet will not say so.

Example

Dahua Technology's subsidiary structure includes entities that supply components to manufacturers who sell finished products under their own names in North American markets. A contractor who purchases a video management system from a mid-tier US vendor, validates that the vendor is not on the covered entities list, and files the certification has not conducted reasonable inquiry into whether the product's underlying hardware includes Dahua-sourced components. The SAM.gov representation is a certification about what the contractor knows. It is not a certificate of what the product contains.

The substantial or essential component test requires a technical judgment about how dependent the system is on the covered equipment. A video recorder that uses a Hikvision chipset for all video processing is not a system that happens to contain a covered component. It is a system whose core function depends on covered technology. That is the analytical question, and it requires someone who knows the product architecture to answer it.

What supply chain assessments surface that procurement screens do not

Assessment base: Pattern observations from Vulnox supply chain and compliance assessments of federal contractors and defense industrial base organizations, 2023-2024.

Covered components in rebranded video surveillance infrastructure

In supply chain assessments of federal contractor environments, video surveillance and physical security systems consistently produce the highest rate of undetected covered equipment. Products purchased through domestic resellers and carrying non-Chinese brand names routinely contain Hikvision or Dahua hardware at the component level. The pattern is consistent enough that any federal contractor operating managed services or physical security infrastructure under a government contract should treat video systems as a high-probability risk category requiring component-level documentation, not just vendor screening.

Implication:

Contractors who have completed Part A compliance processes and believe their video infrastructure is clean are relying on a screen that was not designed to catch this exposure. The question is not who the product was purchased from. It is what is inside it.

Subcontractor systems that perform contract work without prime contractor visibility

Prime contractors typically screen their own technology environments. Subcontractors performing portions of the contract scope use their own systems, and those systems are often not examined at the prime level. In assessments of prime-subcontractor compliance relationships, it is common to find subcontractor environments using networking or collaboration equipment from covered entity subsidiaries. The subcontractor certification certifies their own procurement process. It does not certify that their operational systems contain no covered components.

Implication:

A prime contractor's False Claims Act exposure does not end at its own environment. If a subcontractor's systems used in contract performance contain covered equipment and the prime accepted certification without verification, the prime certification may be false. The standard for what a prime should have known is not zero.

Product refresh cycles that re-introduce covered equipment after initial compliance

Federal contracts run three to five years. Hardware refresh cycles run 18 to 36 months. A contractor who screened their environment at contract award and found no violations can accumulate violations during the contract period as equipment is refreshed through standard procurement processes. The refresh procurement is screened against the covered entities list. The component content of the new equipment is not re-examined because the system was already documented as compliant. The compliance documentation refers to the original equipment. The refreshed equipment may contain different components.

Implication:

FAR 889 compliance is not a point-in-time certification. It is a continuous obligation. The gap between initial assessment and ongoing monitoring is where contracts that started clean develop violations midstream.

The SAM.gov certification that increases audit risk

Common belief

A current, accurate SAM.gov FAR 52.204-26 representation demonstrates compliance and reduces the likelihood of focused audit scrutiny.

What we found

In pre-contract compliance assessments, Vulnox has identified covered equipment in contractor environments where the SAM.gov representation was current and accurate at the time of the previous certification. The equipment had entered through a hardware refresh cycle between certification dates. The contractor believed it was compliant. The representation said it was compliant. The environment was not. The gap between certification date and assessment date was 14 months.

A current SAM.gov representation certifies that the contractor has conducted a reasonable inquiry and, to its knowledge, does not use covered telecommunications equipment. If that representation is on file and the contractor has not in fact conducted a component-level inquiry into its supply chain, the representation may be false. A false certification is not neutral. It is the trigger for False Claims Act liability.

Contracting officers who initiate supply chain reviews are not looking for contractors with outdated representations. They are looking for contractors whose representations are current but whose supply chains contain covered equipment. A current false certification is more actionable than an expired one. The representation is the evidentiary starting point, and 'we certified that we had conducted reasonable inquiry' is not a defense when the inquiry was a vendor attestation checklist.

The counterintuitive implication is that a contractor who maintains current SAM.gov representations without having actually conducted reasonable inquiry is in a worse legal position than a contractor who has not yet made the representation.

What contractors say when the audit notice arrives

  • 'We screened every vendor against the covered entities list. None of our purchase orders show a prohibited vendor.'

    Root cause:

    Vendor screening at the purchase order level catches direct procurement from named entities. It does not catch covered components inside products sold by unnamed vendors, and it does not catch systems operated by subcontractors. The covered entities list names the parent companies. Subsidiaries and affiliates are included in the prohibition but are not all named on the list. A contractor whose compliance process screens purchase orders against the six named parent companies has not conducted reasonable inquiry into their supply chain.

  • 'Our subcontractors all signed FAR 889 certifications. We have them on file.'

    Root cause:

    A subcontractor certification certifies the subcontractor's own procurement process, not the component content of their operational systems. A subcontractor who purchased its networking equipment from a US reseller and has no covered entity on its purchase orders can truthfully certify that it conducted reasonable inquiry as it understood the requirement. If that equipment contains covered components and the prime accepted the certification as sufficient, the prime has not verified the supply chain. It has collected a piece of paper.

  • 'This system was compliant when we installed it. Nothing changed.'

    Root cause:

    The system was screened at installation. The compliance documentation reflects the equipment that was installed. If hardware components within that system were refreshed, if firmware was updated by the vendor to a version that includes covered software, or if a subcomponent was replaced with a different manufacturer's part during a maintenance cycle, the system may contain covered equipment that the original documentation does not account for. Compliance documentation ages. The equipment it describes does not stay static.

The supply chain exposure categories that standard FAR 889 processes do not reach

Cloud infrastructure used in contract performance

A contractor using a cloud service provider to process or store data related to federal contract performance is subject to FAR 889 to the extent that the cloud provider's backend infrastructure uses covered equipment. Major US cloud providers have largely addressed this at the infrastructure level, but smaller managed service providers and specialized platform vendors may not have mapped their own infrastructure against FAR 889 requirements. A contractor who has validated their own environment but relies on a third-party platform for contract-related processing has an exposure that is not visible in their own compliance documentation.

Unified communications and collaboration equipment

Video conferencing endpoints, IP phones, and collaboration room systems used to conduct federal contract work are systems used in performance of the contract. Networking components in these endpoints are frequently manufactured by covered entity subsidiaries. A contractor whose FAR 889 process focused on IT infrastructure and physical security equipment may not have examined their conference room technology inventory.

Firmware and software supply chain

FAR 889 covers telecommunications services as well as equipment. Software and firmware developed by covered entities or their subsidiaries, when used as a component of a system deployed in federal contract performance, is within scope. A networking device running firmware with a component sourced from a covered entity's software division presents the same compliance question as the hardware. Firmware provenance is rarely examined in standard supply chain assessments because most contractors treat FAR 889 as a hardware problem.

Where FAR 889 enforcement is heading in the next 24 months

  1. Contracting agencies will begin requiring component-level bills of materials for networked hardware as a contract deliverable, formalizing what is currently treated as a reasonable inquiry best practice.

    The current reasonable inquiry standard is self-assessed. Agencies have no standardized mechanism to verify component content at award. As enforcement actions accumulate and the rebranding problem becomes better documented in contracting officer guidance, the pressure to formalize component disclosure will increase. The signal is whether any major agency issues a deviation or class deviation requiring hardware BOMs as a contract requirement in 2025 or 2026.

    Confidence: mediumA published FAR deviation or agency-specific procurement requirement mandating hardware component disclosure for covered equipment categories by end of 2026.
  2. False Claims Act litigation involving FAR 889 will produce at least two settlement agreements in the $10M-plus range within 18 months, reshaping how contractors understand the certification risk.

    The qui tam mechanism under the False Claims Act enables competitors and former employees to bring claims based on false certifications. The volume of contractors who maintain SAM.gov representations without having conducted component-level reasonable inquiry is large. As plaintiff attorneys develop expertise in the technical analysis required to support these claims, the litigation rate will increase. A settlement in the disclosed range will produce immediate compliance investment across the federal contractor base.

    Confidence: mediumA publicly reported False Claims Act settlement involving FAR 889 certifications above $10M by mid-2027.

The compliance process that actually reduces FAR 889 risk is not the one most contractors have built

Most federal contractors have built a FAR 889 compliance process that satisfies the certification requirement and does not actually address the exposure. The process screens vendors at the procurement transaction level, collects subcontractor attestations, and files the SAM.gov representation. It is designed to produce defensible documentation, not to find covered equipment. Those are different objectives, and they produce different results.

A process designed to find covered equipment starts with the systems deployed in contract performance, maps backward to component origins, and treats vendor attestations as a starting point for inquiry rather than a conclusion. It is slower, more expensive, and requires technical input that compliance teams do not always have. It also actually identifies the violations before the contracting officer does.

The contractors who are most exposed right now are not the ones who ignored FAR 889. They are the ones who built a compliance process that looks thorough and produces clean certifications and has never run a component-level analysis on a single product in their environment. They have documentation of a process that did not find what an audit will find. That documentation makes the False Claims Act exposure worse, not better.

Counterargument

The counterargument is that component-level analysis is impractical at scale. A systems integrator managing hundreds of products across dozens of contracts cannot run hardware forensics on every piece of equipment. At some point, the reasonable inquiry standard must allow reliance on vendor certifications and industry norms. That is a legitimate argument, and it will win some of the time in enforcement proceedings. It is less persuasive when the product category is video surveillance and the compliance team had no documented reason to believe component-level screening was unnecessary.

The one action that changes your FAR 889 exposure profile this week

Pull the list of networked hardware used in performance of your active federal contracts, filter for any video surveillance, physical access control, or unified communications equipment, and request the firmware version and chipset origin documentation from the current vendors. Not the reseller. The manufacturer. If the manufacturer cannot provide component origin documentation, that is itself a finding. You do not need a full supply chain assessment to identify whether your highest-risk category has an exposure. The video infrastructure question can be answered in days. Most contractors have never asked it.

Further Reading

Frequently Asked Questions

What is the difference between FAR 889 Part A and Part B, and which creates more compliance risk?

Part A prohibits direct procurement of covered telecommunications equipment or services from named vendors including Huawei, ZTE, Hytera, Hikvision, and Dahua. Part B goes further: it prohibits using any system that uses covered equipment as a substantial or essential component, even if the contractor did not directly procure it. Part B creates significantly more risk because it captures indirect exposure through subcontractors and embedded components that standard procurement screening does not surface. Most contractors have Part A processes. Part B gaps are what generate audit findings.

What does reasonable inquiry mean under FAR 889 and what does it actually require?

Reasonable inquiry under FAR 889 requires an active, documented effort to determine whether covered telecommunications equipment exists in your supply chain. It is not satisfied by a vendor attestation form or a single self-certification. It requires reviewing component-level documentation, requesting supplier bills of materials for systems that include networking or video components, and applying greater scrutiny to lower-tier subcontractors. The standard shifts based on what the contractor knew or should have known. A contractor who accepted a supplier attestation without examining the product documentation for a system known to include Chinese-manufactured networking components has not conducted reasonable inquiry.

Which vendor categories most frequently produce FAR 889 violations in federal contractor supply chains?

The named entities are Huawei, ZTE, Hytera Communications, Hikvision, and Dahua Technology, plus their subsidiaries and affiliates. In practice, the highest violation frequency comes from video surveillance infrastructure (Hikvision and Dahua components are embedded in rebranded products sold under non-Chinese brand names) and networking equipment (Huawei chipsets appear in third-party products). The rebranding problem is the core challenge: a contractor can purchase equipment from a US-branded vendor and still be in violation if that equipment contains covered components.

How does FAR 889 compliance interact with subcontractor relationships?

Prime contractors are responsible for flowing FAR 889 compliance requirements down through their subcontractor relationships. The prime contract holder bears the compliance obligation regardless of where in the supply chain the prohibited equipment originates. Subcontractor certifications are required but are not sufficient on their own. A prime contractor whose subcontractor falsely certifies compliance and whose own oversight processes accepted that certification without verification faces contract termination and potential debarment. The practical implication is that reasonable inquiry cannot stop at the first-tier subcontractor.

What does a FAR 889 gap analysis actually examine that standard compliance reviews miss?

A FAR 889 gap analysis should examine the component origin of finished products, not just vendor names on purchase orders. Standard compliance reviews screen for named vendors at the procurement level. Gap analysis looks at what is inside the products: networking cards, camera modules, firmware origins, chipset manufacturers. It also maps subcontractor systems used in performance of the federal contract, cloud infrastructure components, and any third-party hardware used in system integration work. The gap between a procurement-level screen and a component-level analysis is where most undetected violations live.

What are the consequences of FAR 889 non-compliance and how quickly do they materialize?

Consequences range from contract termination for cause to suspension and debarment proceedings. False certification under FAR 52.204-26 also creates False Claims Act exposure, which adds treble damages and civil penalties to the equation. The timeline depends on how violations surface: an agency-initiated audit can result in a cure notice within 30 days and contract termination within 60. Self-disclosure of violations, while uncomfortable, typically results in better outcomes than audit discovery and is treated differently in debarment proceedings.

Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard

GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong

GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard

GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.

Ready to Secure Your Digital Assets?

Get a comprehensive vulnerability assessment for your website today.