Prove your cameras are §889 clean.
An expert-led security assessment of your camera estate that ends in asigned, audit-ready §889 attestation — the document your contracting officer actually asks for. A hands-on engagement led by our security team, not a self-serve scan.
Why this matters now
Under NDAA §889 and 2025–26 FCC enforcement, U.S. federal agencies, contractors, and a widening set of regulated buyers can no longer use cameras from the dominant vendors — Hikvision, Dahua, and their affiliate brands. §889 non-compliance can cost a federal contract worth millions. Many organizations don't actually know what's on their network, because covered hardware is often rebranded and hidden in plain sight.
You're not buying a scanner. You're buying contract protection— a defensible, signed answer to "is your camera estate free of covered equipment?"
Free self-check vs. the full assessment
Every OpenNVR install ships a free, instant §889 self-check. It's a genuine head start — but it is not an attestation. Here's the difference.
Instant self-check
Built into OpenNVR · free · runs locally
- ✓ Flags covered-vendor cameras you already manage
- ✓ Surfaces the obvious exposure & config risks
- ✓ Private — nothing leaves your box
- — A snapshot, not an official §889 attestation
The full OpenNVR §889 Assessment
Expert-led · signed attestation · paid engagement
- ✓ Every device assessed — active testing, not a snapshot
- ✓ Forensic rebrand detection + live CVE/CISA-KEV intel
- ✓ A dedicated SPOC and live expert working sessions
- ✓ A signed, audit-ready §889 attestation auditors accept
- ✓ Continuous monitoring, drift alerts & re-attestation
- …and much more — a defensible compliance package, not just a scan.
What's inside the assessment
One named point of contact from kickoff to attestation — you're not filing a ticket, you're working with a person.
We walk your team through the findings, the remediation plan, and the §889 determination — and answer your auditor's questions.
40+ checks across 12 categories, run against every device on your network — not a spot sample.
Unmasks Hikvision / Dahua hardware hidden behind affiliate and white-label brands that a name check would miss.
Each device is checked against current vulnerability and known-exploited-vulnerability feeds, not a static list.
Encryption, stream authentication, credential hygiene, and network exposure — probed, not assumed.
An audit-ready PDF your contracting officer accepts — the deliverable procurement actually asks for.
Drift alerts when a new camera appears, firmware regresses, or a device lands on an updated covered-vendor list — and a fresh attestation each cycle.
A prioritized path from where you are to a compliant, sovereign estate — what to fix first, and why.
What you receive
A Camera Security Posture Report (PDF + machine-readable JSON), containing:
- ✦An organization posture grade (A–F) and the three numbers a regulator cares about: critical findings, covered-vendor devices, internet-exposed cameras.
- ✦A per-camera inventory — vendor, model, firmware, exposure, and score for every device.
- ✦Findings by risk class, each with severity, evidence, and the concrete fix.
- ✦A compliance mapping — NDAA §889, CISA Secure-by-Design, NIST CSF, ETSI EN 303 645, ISO 27001.
- ✦A before / after — your current posture vs. a sovereign, offline-first architecture — with a prioritized remediation roadmap.
- ✦A signed, audit-ready §889 attestation (PDF).
How it works
We confirm the networks in scope and your written authorization to assess them. Read-only, agreed boundaries.
We run the assessment within the authorized scope — discovery, fingerprinting, and posture checks. No exploitation, no disruption to live systems.
Findings are reviewed and the report is hand-finished by our security team — not an auto-generated dump.
We walk you through the grade, the top risks, the §889 determination, and the roadmap. Turnaround is typically 1–2 weeks.
Authorization & safety: the assessment is read-only and runs only against networks you own or have authorized. It does not exploit, brute-force, or disrupt devices. Engagement terms include a mutual authorization + scope agreement and a confidentiality clause; your data stays yours.
Who it's for
Questions
Is a clean in-product self-check the same as an attestation?
No — and we're explicit about that. OpenNVR ships a free, instant §889 self-check that flags the obvious covered-vendor and configuration risks. It's a useful snapshot, but it is not an official §889 attestation. The full assessment is what produces the signed, audit-ready document.
Do we need to send you our footage or connect to a cloud?
No. OpenNVR is offline-first and the assessment is read-only. Nothing about your estate leaves your control, and the covered-vendor logic runs against your inventory — not a vendor cloud.
We're mid rip-and-replace of Hikvision / Dahua cameras. Can you help?
That's the core case. We identify covered and affiliate-brand devices (including rebrands), map the §889 exposure, and give you a prioritized remediation roadmap toward a compliant, sovereign estate — then attest to it.
Can integrators and MSSPs deliver this for their own clients?
Yes. There's a white-label path for authorized partners who run assessments for their client base. Ask us about the partner program.
Get your §889 assessment
Tell us about your estate and we'll scope a pilot. Signed attestation, expert-led, offline-first.
contact@opennvr.org →Or start with the free self-check inside OpenNVR — it flags covered-vendor cameras the moment you add them.