The FCC's Legacy Hikvision and Dahua Ban: What It Means for the Cameras Already on Your Walls

On June 26, 2026, the FCC's Public Safety and Homeland Security Bureau and Office of Engineering and Technology released Public Notice DA 26-635 in PS Docket No. 26-72, and it quietly ended a loophole the surveillance industry had been living with since 2022. The original Secure Equipment Act rules only stopped the FCC from authorizing new Hikvision, Dahua, Huawei, ZTE, and Hytera models; anything authorized before November 2022 could keep being imported and sold. DA 26-635 prohibits the continued importation and marketing of that previously authorized covered equipment when it's sold for public safety, security of government facilities, physical security surveillance of critical infrastructure, or other national security purposes. It was published in the Federal Register on July 6 and took effect July 16, 2026.

The second shoe drops on October 13, 2026. That's the effective date of the FCC's separate equipment-authorization order, FCC 26-50, published in the Federal Register on September 11, 2026 -- and it's the rule that replaces the 'critical infrastructure' definition the D.C. Circuit sent back to the agency in 2024. Under the new definition, critical infrastructure means systems and assets used to provide services or functions in the 16 federal critical infrastructure sectors that deliver any of the 55 National Critical Functions. Once that definition is in force, the critical-infrastructure leg of the legacy-equipment prohibition has a defined target, and integrators who have been quietly selling remaining Hikvision and Dahua inventory into utilities, healthcare, water, transportation, and certain commercial facilities lose that channel.

FCC 26-50 also goes further than any prior action by reaching inside other manufacturers' products. Starting October 13, the FCC will refuse to authorize new devices that incorporate logic-bearing components -- chips, modules, and other processing parts -- produced by a Covered List entity, if the device would have been prohibited had that entity built it outright. Covered List manufacturers must also go through full recertification for any modification rather than the faster permissive-change process. And online marketplaces will have to display a valid FCC ID at the point of sale, with compliance dates of March 1, 2027 for marketplaces with device access and June 1, 2027 for third-party seller listings. Taken together, the path for covered hardware into the U.S. professional market is close to closed.

Here's what the rules do not do, and it matters for every California property manager reading a scary headline: they don't make your existing cameras illegal. The FCC has been explicit that these prohibitions don't affect the continued use or operation of equipment you lawfully bought, and nothing requires a private business to rip out an installed system. The component prohibition in FCC 26-50 is prospective only and doesn't touch previously authorized equipment. If you own a 32-camera Hikvision NVR system in an office park or apartment community, it's still legal to run it tomorrow.

Network technician connecting patch cables in a server cabinet where surveillance recorders and switches are racked

Legal to run, though, is not the same as supportable. No new Hikvision or Dahua model has received FCC authorization since November 2022, and with legacy imports for covered uses now blocked, matching replacement cameras and spare parts get harder to source every quarter. That turns a routine failure -- a dead PTZ, a fried NVR power supply, a camera lost to a lightning strike -- into a mixed-vendor patch or a forced partial replacement on the failure's schedule, not yours. Industry replacement guides currently put a like-for-like swap at roughly $300-$800 per camera installed, which is why a planned, phased replacement almost always costs less than an emergency one.

The bigger exposure is cybersecurity. CVE-2021-36260, a Hikvision command-injection flaw with a CVSS score of 9.8 that lets an unauthenticated attacker take over a camera with a single crafted request, sits on CISA's Known Exploited Vulnerabilities catalog and is still being exploited in 2026. A 2022 CYFIRMA study found more than 80,000 internet-exposed Hikvision cameras still vulnerable, spread across roughly 2,300 organizations in 100 countries, and the 2025 release of an automated 'HikvisionExploiter' toolkit lowered the bar to novice-level mass exploitation. A camera running unpatched firmware on your production network isn't a camera problem -- it's an unmanaged Linux box with a path into everything else on the same VLAN.

Many owners don't know they have covered hardware at all. Hikvision and Dahua have built cameras and recorders for dozens of OEM labels, and a large share of budget and mid-tier cameras sold through distributors and online marketplaces are rebadged units that never mention the original manufacturer on the box. The reliable way to check is the FCC ID on the device label or in the NVR's system information, cross-referenced against the FCC's equipment authorization database and the Covered List at fcc.gov/supplychain/coveredlist. Brands like Hanwha Vision, Axis, i-PRO, and Avigilon are not on the Covered List and are the usual landing spots for replacement projects.

For California owners, the practical question is which bucket you're in. Facilities that are clearly in critical infrastructure sectors -- hospitals and clinics, water and wastewater, utilities, transportation, and certain government-adjacent sites -- should treat October 13 as the date their integrator's ability to sell or replace covered legacy gear in kind effectively ends. Properties using federal grants, loans, or contracts are already under NDAA Section 889 and 2 CFR 200.216 restrictions. And everyone else, including most multifamily, retail, and office owners, faces the slower squeeze of a shrinking parts supply, no new firmware-validated models, and a known-exploited vulnerability history that cyber insurers are increasingly asking about at renewal.

A sensible response isn't a panic rip-and-replace; it's an inventory and a plan. Start by pulling every camera and recorder's FCC ID and firmware version. Move any covered devices off the corporate network onto an isolated surveillance VLAN with no direct internet exposure and remote access only through a VPN or a managed cloud gateway. Patch what can still be patched. Then build a phased replacement schedule that prioritizes internet-facing recorders, cameras covering entrances and high-liability areas, and any device that can no longer receive firmware -- and budget it over two or three fiscal years rather than absorbing it after a failure.

One more reason to start now rather than later: pricing on compliant hardware is already moving. Integrators were told in 2025 to expect 10-25% camera price increases tied to tariffs on Chinese-origin hardware, and the October component rule adds compliance friction for manufacturers whose supply chains touch Covered List silicon. Owners who scope replacements now get to choose their platform -- including a move to a unified VMS that also handles access control -- instead of taking whatever is in stock the week the old NVR dies.

Mytek Pros inventories, secures, and replaces legacy surveillance systems as a licensed California low-voltage contractor (License #1116987) with DIR public-works registration (PW-LR-1001158430), BICSI certification, and DBE/DVBE/MBE certification, based in Carlsbad and serving San Diego County and businesses throughout California. We'll audit your existing cameras and recorders for Covered List hardware and known-exploited firmware, segment what has to stay in service, and design a phased NDAA-compliant replacement on a budget you control -- with our managed IT team keeping the surveillance network patched and monitored afterward. This is a technical assessment, not legal advice on whether your site qualifies as critical infrastructure. To get ahead of the October 13 deadline, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com.

Questions about design/build? Get in touch or explore our Design/Build services.