NDAA §889 · Camera Security Assessment

Prove your cameras are §889 clean.

An expert-led security assessment of your camera estate that ends in asigned, audit-ready §889 attestation — the document your contracting officer actually asks for. A hands-on engagement led by our security team, not a self-serve scan.

Why this matters now

Under NDAA §889 and 2025–26 FCC enforcement, U.S. federal agencies, contractors, and a widening set of regulated buyers can no longer use cameras from the dominant vendors — Hikvision, Dahua, and their affiliate brands. §889 non-compliance can cost a federal contract worth millions. Many organizations don't actually know what's on their network, because covered hardware is often rebranded and hidden in plain sight.

You're not buying a scanner. You're buying contract protection— a defensible, signed answer to "is your camera estate free of covered equipment?"

Free self-check vs. the full assessment

Every OpenNVR install ships a free, instant §889 self-check. It's a genuine head start — but it is not an attestation. Here's the difference.

Instant self-check

Built into OpenNVR · free · runs locally

  • ✓ Flags covered-vendor cameras you already manage
  • ✓ Surfaces the obvious exposure & config risks
  • ✓ Private — nothing leaves your box
  • — A snapshot, not an official §889 attestation

The full OpenNVR §889 Assessment

Expert-led · signed attestation · paid engagement

  • ✓ Every device assessed — active testing, not a snapshot
  • ✓ Forensic rebrand detection + live CVE/CISA-KEV intel
  • ✓ A dedicated SPOC and live expert working sessions
  • ✓ A signed, audit-ready §889 attestation auditors accept
  • ✓ Continuous monitoring, drift alerts & re-attestation
  • …and much more — a defensible compliance package, not just a scan.

What's inside the assessment

A dedicated security SPOC

One named point of contact from kickoff to attestation — you're not filing a ticket, you're working with a person.

Live expert working sessions

We walk your team through the findings, the remediation plan, and the §889 determination — and answer your auditor's questions.

Deep automated scan

40+ checks across 12 categories, run against every device on your network — not a spot sample.

Forensic OEM-rebrand detection

Unmasks Hikvision / Dahua hardware hidden behind affiliate and white-label brands that a name check would miss.

Live CVE & CISA-KEV intelligence

Each device is checked against current vulnerability and known-exploited-vulnerability feeds, not a static list.

Active security testing

Encryption, stream authentication, credential hygiene, and network exposure — probed, not assumed.

A signed §889 attestation

An audit-ready PDF your contracting officer accepts — the deliverable procurement actually asks for.

Continuous monitoring & re-attestation

Drift alerts when a new camera appears, firmware regresses, or a device lands on an updated covered-vendor list — and a fresh attestation each cycle.

An expert remediation roadmap

A prioritized path from where you are to a compliant, sovereign estate — what to fix first, and why.

What you receive

A Camera Security Posture Report (PDF + machine-readable JSON), containing:

  • An organization posture grade (A–F) and the three numbers a regulator cares about: critical findings, covered-vendor devices, internet-exposed cameras.
  • A per-camera inventory — vendor, model, firmware, exposure, and score for every device.
  • Findings by risk class, each with severity, evidence, and the concrete fix.
  • A compliance mapping — NDAA §889, CISA Secure-by-Design, NIST CSF, ETSI EN 303 645, ISO 27001.
  • A before / after — your current posture vs. a sovereign, offline-first architecture — with a prioritized remediation roadmap.
  • A signed, audit-ready §889 attestation (PDF).

How it works

1
Scoping call (30 min)

We confirm the networks in scope and your written authorization to assess them. Read-only, agreed boundaries.

2
Assessment

We run the assessment within the authorized scope — discovery, fingerprinting, and posture checks. No exploitation, no disruption to live systems.

3
Analysis

Findings are reviewed and the report is hand-finished by our security team — not an auto-generated dump.

4
Readout (45 min)

We walk you through the grade, the top risks, the §889 determination, and the roadmap. Turnaround is typically 1–2 weeks.

Authorization & safety: the assessment is read-only and runs only against networks you own or have authorized. It does not exploit, brute-force, or disrupt devices. Engagement terms include a mutual authorization + scope agreement and a confidentiality clause; your data stays yours.

Who it's for

Federal & state contractors and grant recipients facing §889 / FCC rip-and-replace
Government, defence-adjacent, and critical-infrastructure operators
Healthcare, K-12, and finance — regulated environments where cloud surveillance was never an option
Security integrators & MSSPs who want to run camera assessments for their own clients (white-label)

Questions

Is a clean in-product self-check the same as an attestation?

No — and we're explicit about that. OpenNVR ships a free, instant §889 self-check that flags the obvious covered-vendor and configuration risks. It's a useful snapshot, but it is not an official §889 attestation. The full assessment is what produces the signed, audit-ready document.

Do we need to send you our footage or connect to a cloud?

No. OpenNVR is offline-first and the assessment is read-only. Nothing about your estate leaves your control, and the covered-vendor logic runs against your inventory — not a vendor cloud.

We're mid rip-and-replace of Hikvision / Dahua cameras. Can you help?

That's the core case. We identify covered and affiliate-brand devices (including rebrands), map the §889 exposure, and give you a prioritized remediation roadmap toward a compliant, sovereign estate — then attest to it.

Can integrators and MSSPs deliver this for their own clients?

Yes. There's a white-label path for authorized partners who run assessments for their client base. Ask us about the partner program.

Get your §889 assessment

Tell us about your estate and we'll scope a pilot. Signed attestation, expert-led, offline-first.

contact@opennvr.org →

Or start with the free self-check inside OpenNVR — it flags covered-vendor cameras the moment you add them.