An NDAA representation can look like a checkbox at the end of a federal solicitation. The work behind that answer begins much earlier, usually with an equipment inventory that was built for IT support or insurance rather than government contracting.
The central question is not whether a product carries an “NDAA compliant” label. It is whether the company provides or uses covered telecommunications equipment or services as defined in FAR 52.204-25. That definition identifies named manufacturers and extends to subsidiaries, affiliates, associated services, and other entities designated through the statutory process. It also turns on the role of the equipment: a covered item used as a substantial or essential component, or as critical technology, falls within the prohibition.
“Reasonable inquiry” has a specific limit
FAR 52.204-24 asks an offeror to make representations about both providing and using covered equipment. The clause defines reasonable inquiry as a search for information already in the entity’s possession about the producer or provider. It expressly says that the inquiry does not require an internal or third-party audit.
That limit does not make an incomplete asset list reliable. A practical inquiry still has to reach the records where manufacturer identity may be hiding: purchasing data, maintenance contracts, managed network services, security-system inventories, and equipment acquired by individual sites. Distributor names alone are weak evidence because the required question concerns the producer or service provider.
The result should be reproducible. If the same inventory is reviewed during a renewal six months later, another employee should be able to see which locations were checked, which records were consulted, and how ambiguous devices were resolved.
Part B reaches beyond the federal project
The procurement restriction in Section 889(a)(1)(A) addresses equipment, systems, or services supplied to the Government. Section 889(a)(1)(B) examines the contractor’s own use. FAR 52.204-25 states that this second prohibition applies regardless of whether the covered equipment is used in performing the federal contract.
A camera at a warehouse, a telecommunications service used by a regional office, or equipment bundled into a managed service can therefore matter even when none of it will be delivered to the agency. This company-wide scope is why the review cannot stop at the bill of materials for the proposed solution.
Exceptions exist for specified third-party connection arrangements and for equipment that cannot route, redirect, or provide visibility into user data. Waivers follow a separate process. Neither should be assumed from a product description; the contract file needs the facts that support the exception or waiver.
A discovery starts a reporting clock
Compliance work continues after award. If covered equipment or services are identified during contract performance, FAR 52.204-25 requires an initial report within one business day. The report includes details such as the contract or order number, supplier, brand, model, item description, and available mitigation information. A follow-up is due within ten business days with further mitigation details and the steps taken to prevent recurrence.
The clause also flows into subcontracts and other contractual instruments, subject to the scope stated in the provision. Supplier declarations, model lists, and purchasing records are therefore operational records, not attachments collected once and forgotten.
Section 889 answers a sourcing and contracting question. Password policy, signed firmware, vulnerability handling, certificate management, and network segmentation belong to a separate security review. A clean representation cannot substitute for those controls, and strong security features cannot cure a prohibited source.