5 FOUNDING CUSTOMER SPOTS AVAILABLE | Lock in 50% off forever
USE CASE · NDAA COMPLIANCE

Track NDAA compliance across your entire BOM

One covered-entity part can block a contract authorization. GriffinIQ screens your Bill of Materials for NDAA Section 889 covered entities, flags counterfeit and provenance risk under Section 818, and keeps you aligned with the FCC Covered List — so exposure surfaces at sourcing time, not at audit time.

What NDAA compliance requires of your supply chain

NDAA supply-chain compliance comes down to three overlapping obligations. GriffinIQ tracks all three from a single BOM.

Section 889

Covered-entity screening

NDAA Section 889 prohibits covered telecommunications and video-surveillance equipment from named entities — Huawei, ZTE, Hytera, Hikvision, Dahua, and their affiliates. Every component in your BOM has to be clear of them.

Section 818

Counterfeit-part avoidance

NDAA Section 818 requires defense contractors to detect and avoid counterfeit electronic parts and to source from trusted, authorized suppliers. Provenance has to be documented, not assumed.

FCC Covered List

Prohibited-source alignment

The FCC Covered List operationalizes these national-security determinations and keeps expanding. A supplier added to the list can turn a compliant BOM into an exposed one overnight.

The exposure surfaces at audit time — when it's too late

Most contractors don't discover a covered-entity part until a prime or government audit catches it. By then the program delay has already started, and remediation means re-sourcing under pressure. NDAA exposure is cheapest to fix at the moment a part enters the BOM — which is exactly where GriffinIQ puts the check.

How GriffinIQ tracks NDAA compliance

Screen every part against covered entities

Match manufacturers and suppliers in your BOM against Section 889 covered entities and the FCC Covered List, so flagged parts surface before they reach a contract.

Flag counterfeit and provenance risk

Identify components tied to counterfeit incidents, unauthorized sources, or unclear country-of-origin — the exposure Section 818 is designed to catch.

Catch list changes the moment they happen

Proactive alerts when a supplier is added to a covered list or a covered-entity match appears in a BOM you already submitted.

Keep audit-ready records

Centralized documentation and an audit trail of compliance checks, ready for prime-contractor and government review.

GriffinIQ is pre-launch. Our BOM analytics engine is in beta and compliance validation is in active development, shaped directly with our founding customers. We're transparent about where each capability stands.

NDAA compliance FAQ

What does "NDAA compliance" mean for a Bill of Materials?

In practice it means two things: no part or supplier in your BOM is tied to an NDAA Section 889 covered entity, and your electronic parts meet Section 818 counterfeit-avoidance and trusted-source requirements. GriffinIQ brings both checks into one view across your whole BOM.

What is NDAA Section 889?

Section 889 of the FY2019 NDAA prohibits federal agencies from procuring covered telecommunications and video-surveillance equipment or services from named entities — including Huawei, ZTE, Hytera, Hikvision, and Dahua — and from contracting with organizations that use them.

How does NDAA compliance relate to the FCC Covered List?

The FCC Covered List identifies communications equipment and entities deemed national-security risks, overlapping heavily with the NDAA covered entities. GriffinIQ screens your components against the Covered List so changes — like the recent expansion to additional UAS components — surface immediately.

Can GriffinIQ flag counterfeit-part risk?

Yes — counterfeit and provenance risk is core to what we surface, which is exactly the exposure NDAA Section 818 is designed to address. We flag parts tied to counterfeit incidents, unauthorized distributors, and unclear country-of-origin.

Where is our BOM data stored?

All data is processed and stored on US-based infrastructure with no foreign national access. We do not use offshore processing or third-party AI providers for your BOM data. Data submitted for a free scan is deleted after analysis.

How fast can we see our NDAA exposure?

Send us one BOM and we will run a complimentary scan, returning a report of covered-entity matches, counterfeit and obsolescence risks, and FCC Covered List flags — typically within 48 hours, no commitment required.

See your NDAA exposure on a real BOM

Send us one BOM and we'll return a complimentary scan of covered-entity matches, counterfeit and obsolescence risk, and FCC Covered List flags — within 48 hours, no commitment.

Request a Free NDAA BOM Scan