Back to blog
7 min readFlybyOps Team

Drone NDAA compliance: what it means and how to document it

Drone NDAA compliance turns on where components come from, not where the drone is assembled. Here is what the rules cover and how to document it.


Drone NDAA compliance is a supply-chain question wearing a procurement label. The National Defense Authorization Act restricts which drones federal agencies can buy and operate, and the test is not where an aircraft was assembled but where its critical parts and its corporate control come from. A drone built in a compliant country can still fail the test if a covered component sits inside it, which is why compliance is documented rather than assumed.

This article covers what NDAA compliance means, which components the rules reach, how the restrictions grew from a defense procurement bar into a government-wide rule, and how a program documents compliance so it holds up when someone asks. If your work touches federal contracts, federal grant money, or public agencies that spend either, this is a requirement rather than a preference.

What NDAA compliance means

The core restriction comes from Section 848 of the fiscal year 2020 National Defense Authorization Act. It bars federal defense procurement and operation of unmanned aircraft systems that are manufactured in, or that contain critical components sourced from, a set of covered countries: China, Russia, Iran, and North Korea. The concern is that hardware and software tied to those countries can expose sensitive data or operations, so the law draws a line at the source rather than at the label.

Compliance, then, is a statement about origin and control. A drone is compliant when neither the aircraft nor its covered components trace back to a covered country and when the manufacturer is not owned or controlled by an entity in one. Because that is a factual claim about a supply chain, it is something a buyer verifies with documentation, not something a marketing sheet settles on its own. The burden sits with the buyer, which is why programs that expect to sell into government work fold the compliance question into procurement from the first purchase order.

Which components are covered

The rules do not stop at the airframe. The covered components include flight controllers, radios and data links, cameras, gimbals, ground control systems, operating software, and data storage, the parts that gather, move, or hold information. The Defense Innovation Unit's Section 848 component guidance sets out how those components are defined, which is the reference a buyer checks a bill of materials against.

This is why assembly location tells you little. A drone put together in a compliant country with a flight controller or camera sourced from a covered country is not compliant, because the covered component disqualifies the whole system. A review that stops at the country of final assembly misses the point of the rule, which reaches into the parts and the software rather than the box they ship in. Operating software and data storage are the components buyers most often overlook, because they do not show up on a spec sheet, yet they are precisely where the rule's data-exposure concern lives. A firmware image or a storage module sourced from a covered country carries the same disqualifying weight as a foreign-made airframe.

How the rules reach beyond the Pentagon

The restrictions have widened over successive years. Section 817 of the fiscal year 2023 act extended the reach to contracting with entities that operate covered drones, not just to the drones themselves. The American Security Drone Act, enacted at the end of 2023 as part of that year's authorization, took the prohibition government-wide: federal agencies may not procure covered drones, and beginning December 22, 2025, they may not operate them, while contractors and grant recipients may not use federal funds to buy or operate them.

A separate development sharpened the edge in late 2025, when newly manufactured foreign-made drones and critical components were added to a federal covered list that blocks new equipment authorizations, with carve-outs for vetted and domestic products into 2027. Those rules are prospective, aimed at new equipment rather than grounding aircraft already in service, but the direction is clear. State and local agencies feel this even when they never contract with the federal government directly, because public-safety and infrastructure grants often carry the same sourcing conditions down to the recipient. A program spending federal money, directly or through a grant, needs to treat compliance as a buying criterion and not an afterthought.

How to document compliance

Documentation is what turns a compliance claim into something defensible. For each aircraft, that generally means a bill of materials, a compliance letter or certification from the manufacturer, and supplier disclosures that trace the critical components to non-covered sources. Reputable manufacturers now provide these on request, and a buyer that collects them at purchase is far better placed than one that goes looking after a contract is questioned. A compliance letter is most useful when it names the specific model and configuration, states which covered-country sourcing it rules out, and carries a date, so it can be matched to the aircraft on the ramp rather than read as a loose assurance.

The catch is that compliance is not permanent. Manufacturers change suppliers, firmware updates introduce new code, and ownership can shift, any of which can move an aircraft from compliant to not without a visible change on the outside. A program that treats compliance as a one-time checkbox drifts out of it quietly. The safer posture is a per-airframe record that holds the documentation, notes when it was last confirmed, and can be produced when an auditor asks, rather than a folder someone hopes is still accurate.

Common mistakes in drone NDAA compliance

Reading a Made in USA label as compliance. NDAA compliance turns on component sourcing and corporate control, not final assembly. A domestically assembled drone with a covered flight controller or camera still fails the test.

Assuming a Blue UAS listing is the only proof. A drone can be compliant without appearing on that list, and the list is one form of assurance rather than the legal definition. Absence from it does not by itself mean non-compliance.

Treating compliance as permanent. Suppliers change, firmware updates ship, and ownership shifts. An aircraft can leave compliance without any outward sign, so a purchase-day check is not a standing guarantee.

Ignoring federal-funds pathways. Restrictions reach contractors and grantees spending federal money, not just direct federal buyers. A program funded through a grant can be bound by the same rules it assumed did not apply to it.

Keeping no per-airframe record. Compliance is a claim about a specific aircraft's supply chain. Without documentation tied to each airframe, a program cannot answer a compliance question without a scramble it may not win.

FAQ

Does NDAA compliance depend on where a drone is assembled?

No. It turns on where the critical components are sourced and who owns or controls the manufacturer. A drone assembled in a compliant country can still be non-compliant if a covered component, such as the flight controller or camera, comes from a covered country.

Which countries are covered by the restrictions?

The covered countries are China, Russia, Iran, and North Korea. A drone manufactured in one of them, or containing critical components sourced from one, does not meet the compliance standard for federal procurement or operation.

Do the rules apply to my company if we only take federal grant money?

They can. The American Security Drone Act reaches contractors and grant recipients, restricting the use of federal funds to buy or operate covered drones. Spending federal money through a grant can bind you to the same requirements as a direct federal buyer.

What documents should I keep to show compliance?

A bill of materials, a manufacturer compliance letter or certification, and supplier disclosures tracing critical components to non-covered sources. Keeping these per aircraft, with a note on when compliance was last confirmed, is what lets you answer a question without a scramble.

Closing thought

NDAA compliance is not a badge a drone wears; it is a claim about its supply chain that has to be shown. The rules reach into the components and the software, they now bind anyone spending federal money, and they can lapse quietly when a supplier or a firmware version changes. A program that buys with compliance in mind and documents it per aircraft is the one that stays ready.

If you operate where NDAA compliance is a buying criterion, FlybyOps was built for the operational record problem at the center of regulated drone work. An equipment registry with per-airframe hour rollups, a document vault that flags expirations, and an append-only audit log are all part of how the platform keeps each airframe's compliance status recorded where an auditor can find it.

See it in action

Bring your drone program onto one record

FlybyOps gives enterprise drone teams a single audit-grade record for projects, flights, equipment, risks and incidents. Start free — 14-day trial, no credit card.

Start free trial