
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The Government Accountability Office takes a look into government efforts to implement a ban on federal use of equipment and services from Huawei and ZTE, in a new report reviewing efforts at the General Services Administration and the Defense Department to fulfill requirements from the fiscal 2019 National Defense Authorization Act.
Summary
“Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 prohibits federal agencies from procuring covered telecommunications and surveillance equipment and services from five specific Chinese companies (and their affiliates or subsidiaries) or awarding contracts to companies that use such equipment and services,” GAO says in a Sept. 22 report .
The five companies are Huawei, ZTE, Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company and Dahua Technology Company. The Federal Acquisition Regulatory Council issued two rulemakings to enforce the government ban, one in 2019 focused on federal agencies and a second in 2020 focused on federal contractors. GAO said, “As of March 2026, GAO found that nearly 90 percent of companies with active government contracts in fiscal year 2025 represented publicly that they do not use equipment from these companies.” GAO reviews public comments to the two interim rules and also highlights the Trump administration’s overhaul of the Federal Acquisition Regulation.
The FAR Council published a proposed rule for public comment in June 2026 to begin implementing the Revolutionary FAR Overhaul in regulations for multiple parts of the FAR, including those pertaining to the Section 889 prohibitions. “While largely similar to the model [class] deviation language for Section 889 prohibitions, the proposed rule includes updated definitions for telecommunications and video surveillance equipment and services. It also includes guidance on what activities are not considered use of covered equipment or services to help clarify implementation,” GAO found.
GAO also reviews challenges at GSA and DOD to implement Section 889, specifically highlighting: “(1) incomplete supply chain visibility, (2) difficulty complying with prohibitions when operating in foreign countries, and (3) difficulty obtaining representation information for micro-purchases.” “The agencies have taken steps to address some of these problems, but officials acknowledge that more needs to be done,” according to GAO. The report asks GSA and DOD to periodically share information on subsidiaries and affiliates collected “with relevant federal agencies, including leveraging the Cybersecurity and Infrastructure Security Agency’s existing mechanisms as appropriate.” The GSA Administrator and the Secretary of Defense should also coordinate with other federal agencies to “share insights from its Section 889 implementation experience that could be used to inform agencies’ approaches for implementing Section 889 or future prohibition efforts,” according to the GAO report.
KazaSec's take
Source code — and the third-party packages it depends on — is one of the most overlooked parts of an organization's real attack surface. A secure code review catches exactly this class of issue before it ships, not after it's already public.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.