allison

The OEM Relabel Audit: Finding Hikvision and Dahua Hiding in Your Camera Fleet

The OEM Relabel Audit: Finding Hikvision and Dahua Hiding in Your Camera Fleet

The OEM Relabel Audit: Finding Hikvision and Dahua Hiding in Your Camera Fleet

The most uncomfortable conversation I have with facility owners starts the same way: they show me a camera fleet with no Hikvision or Dahua logos anywhere, and I show them why that means very little. The surveillance industry runs on OEM manufacturing at a scale most buyers never see — for years, a large fraction of the "brands" sold through distribution and big-box channels were relabeled hardware from a handful of factories, and Hikvision and Dahua were two of the largest OEM engines in the world. If your compliance posture is "we checked the logos," you have audited the paint. This is the process I use to audit what is actually inside the housings, built for integrators who have to sign their name to an NDAA compliance statement or answer an insurer's supply-chain questionnaire.

Why Brand Labels Lie

OEM relabeling is not fraud; it is how the electronics industry works. A regional brand wants a 40-camera product line without building cameras, so it buys hardware from an ODM/OEM factory, loads a skinned firmware, and prints its own box. The economics made Hikvision and Dahua dominant suppliers in that market for years — their platforms were cheap, capable, and easy to reskin. The result is a long tail of house brands, security-shop labels, and even respected mid-market names whose products were, at the silicon and firmware level, Hikvision or Dahua devices. The buyer two steps downstream sees only the relabel. Research groups that track this space have documented OEM relationships spanning dozens of brand names for each factory, and the practical consequence is simple: brand identity and manufacturing origin are independent variables, and only one of them is printed on the box.

The Named-Entity List vs the OEM Reality

The regulatory hook is Section 889 of the 2019 NDAA, which prohibits federal agencies — and, under 889(b), entities contracting with them — from procuring or using covered video surveillance equipment from named manufacturers including Hikvision and Dahua. Two properties of that rule matter for auditing. First, it names manufacturers, not brands: equipment "produced by" a covered entity is covered regardless of whose label ships on it, which is precisely why relabels are the compliance trap. Second, exposure extends beyond the federal buyer itself — contractors certify about the equipment they use, which is how a logistics company with a federal contract ends up caring intensely about the parking-lot cameras a landlord installed in 2019. Even for organizations with zero federal nexus, the same audit increasingly gets driven by insurers, enterprise tenants, and cybersecurity frameworks that ask the manufacturing-origin question directly. The audit below is the same regardless of who is asking.

FCC ID Lookup: The Five-Minute Truth Test

Every intentional radio emitter sold in the US carries an FCC ID, and wired-only devices still typically carry FCC compliance labeling with a grantee code where certified. That ID is the closest thing to a birth certificate the hardware has: the grantee code — the first segment of the ID — identifies the company that holds the equipment authorization, and it survives relabeling because certification belongs to the manufacturer, not the marketing brand. The workflow: pull the FCC ID off the device label (housing base, rear plate, or inside the dome cover), run it through the FCC's public equipment-authorization database, and read who the grant was issued to and what test reports are attached. A "SecureView Pro" camera whose FCC ID resolves to a grantee in Hangzhou has answered your question. Photograph every label as you go — the photo set becomes your audit evidence.

Three caveats from doing this at scale. Not every device carries a usable ID — some relabels are certified under the relabeler's own grantee code, some labels are worn or painted over, and PoE-only devices are inconsistent about labeling. Treat the FCC lookup as the fast first-pass filter that clears or flags the bulk of a fleet, not as the sole oracle. Second, do the lookup on the device label, not the datasheet — spec sheets get copied between OEM variants. Third, log the full ID string verbatim; grantee codes are the sortable key when you compile results across 300 cameras.

Firmware UI Fingerprints

The second diagnostic layer costs nothing but a browser. OEM platforms carry their lineage in software: web-interface layouts, menu trees, default credentials behavior, RTSP URL structures, and ONVIF device-information strings are expensive to change, so relabelers usually don't. The tells I check, in order: the device's ONVIF GetDeviceInformation response (manufacturer, model, firmware fields frequently reveal the platform under the skin), the firmware version string format, the web UI's structure and boilerplate (activation flows, menu layout, error messages), and the RTSP path convention the device answers on — the major platforms use distinct, well-known URL patterns for their stream paths. Network behavior adds a fourth: default port combinations and the proprietary discovery protocols the device responds to are platform signatures. String several of these together and you can identify the manufacturing platform with high confidence even when the label and the FCC trail are both silent. Document what you observed per device; "web UI and RTSP path structure consistent with Platform X, firmware string format matches" is defensible audit language.

The Usual Suspects: Lorex, Amcrest, House Brands

Certain names should raise the audit priority automatically, not as an accusation but as a base-rate statement. Lorex spent years as Dahua-manufactured hardware — including a period under Dahua ownership — and Amcrest's product lines have been extensively documented as Dahua OEM platforms. Beyond the well-known names, the highest-hit-rate category in my audits is the anonymous tier: house brands from regional distributors, "professional" lines sold by alarm dealers, NVR kits from big-box and e-commerce channels, and anything installed 2015-2020 at an aggressive price point. In multi-tenant and acquired-property portfolios, that era's value-engineered installs are exactly where covered OEM hardware concentrates. One pattern worth flagging from field experience: the fleet is rarely uniform. A typical positive finding is 15-30% of a mixed estate — the main building got name-brand hardware on the original spec, and the annex, the parking structure, and the retrofit floors got whatever the incumbent installer had on the truck.

Don't Forget the Recorders

Cameras get all the audit attention, but the recorder side of the rack carries the same OEM problem with higher stakes. NVR platforms were relabeled at least as aggressively as cameras during the value-engineering era, and plenty of house-brand recorders are covered-entity hardware under a different bezel. The recorder is also the worse place to have the problem: it holds the archive, it typically has the fleet's broadest network access — every camera VLAN plus, in careless designs, a path to the corporate network and outbound internet for remote apps — and its remote-access features are exactly the attack surface the cybersecurity findings against these platforms have centered on. Audit recorders with the same three layers: label and FCC ID where present, then the software fingerprints, which are usually more revealing on recorders than on cameras — the web interface, the mobile app it directs you to, the P2P/cloud relay service it registers with, and the client software family it requires are all platform signatures that survive relabeling almost untouched.

The same logic extends down the accessory chain in one specific place: cameras bundled in kits. A kit's cameras and recorder come from the same factory by definition, so one positive identification on either half determines the other. And when you replace a covered recorder, verify the replacement platform's origin as rigorously as the cameras' — the recorder is one line on the budget and most of the risk concentration in the system. For sizing and platform options on the compliant side, the recorder selection question is its own exercise, but it starts from the same origin-verified shortlist logic as the cameras.

Documenting the Audit for Insurers and Tenants

An audit that lives in your head is worth nothing at questionnaire time. The deliverable is a device-level register:

FieldExample content
Device / locationCam 214, parking structure L2 NE
Label brand and modelHouse-brand dome, model string from label
FCC ID and grantee resultFull ID; grantee name per FCC database
Firmware/ONVIF fingerprintManufacturer string, RTSP pattern, UI platform match
DeterminationCleared / Covered-entity OEM / Indeterminate
EvidenceLabel photo, lookup screenshot, response capture
DispositionRetain / replace by date / isolate pending replacement

Three determinations, deliberately: cleared, covered, and indeterminate. Resist the urge to force indeterminate devices into a bucket — an honest "could not establish origin; scheduled for replacement on lifecycle" reads far better to an insurer than a confident claim you cannot evidence. Date the register, name the auditor, and keep the photo evidence with it. When the questionnaire or the tenant's security addendum arrives, you answer it with an attachment instead of a scramble.

Prioritizing Replacement After a Positive Finding

A positive finding is a budgeting problem, and it should be sequenced, not panicked over. My triage: first, anything in scope of an actual federal contract or certification — that is a hard requirement with signature liability. Second, devices that are both covered-OEM and internet-reachable or unpatched, because the cybersecurity exposure is independent of the compliance question and older OEM firmware lines have carried serious, widely exploited vulnerabilities. Third, cameras covering sensitive areas — data centers, cash rooms, R&D floors. Fourth, everything else on a lifecycle schedule: fold replacements into the normal refresh budget over 12-24 months rather than a forklift event. In the interim, network mitigation is honest and cheap — isolate flagged devices on a VLAN with no outbound internet, drop their firmware update exposure, and log their traffic. Interim mitigation is not compliance for a covered device under a federal contract, but it is responsible risk management for everything in the third and fourth buckets while the budget cycle runs. For the replacement spec itself, start from the curated NDAA-compliant lists — Hikvision Alternatives (NDAA) and Dahua Alternatives (NDAA) — which map the covered platforms' common form factors and price tiers to compliant equivalents, and verify the replacement's own origin story the same way you audited the incumbents. Consistency is the credibility of the whole exercise.

Deployment takeaway: Brand labels are marketing; FCC grantee codes and firmware fingerprints are evidence. This Monday: pick your ten oldest or cheapest-era cameras, photograph their labels, run each FCC ID through the FCC equipment-authorization database, and check each device's ONVIF manufacturer string and RTSP path convention against the label brand. Log every device as cleared, covered, or indeterminate in a dated register with photo evidence. If any come back covered or indeterminate, isolate them from outbound internet the same week, then sequence replacement by contract exposure, reachability, and area sensitivity — a documented 18-month remediation plan beats both denial and panic, and it is what the insurer's questionnaire actually wants to see.

Where This Fits in a Deployment Program

The OEM audit belongs in three standing places: due diligence on every acquired or newly managed property, the annual review on any account with federal, insurer, or enterprise-tenant compliance exposure, and the intake process when you inherit a site from a previous integrator — which is where the surprises live. It also belongs in your procurement discipline going forward: every camera you spec should have a manufacturing origin you can state and evidence, because the audit you make easy today is the one you will pass in three years. Compliant replacement candidates across form factors are curated on the Hikvision Alternatives (NDAA) and Dahua Alternatives (NDAA) guides, with the full range browsable in the IP Cameras catalog. If you have a fleet with unknown-origin hardware in it — or a compliance questionnaire on your desk with a deadline — send over the device list, label photos, and the contract language driving the requirement, and we can help you scope the audit and spec origin-verified replacements that fit the existing mounts, cabling, and VMS.

Have questions about anything in this article?

Free pre-sales support from a Senior Specialist — BOM quotes, compatibility checks, price confirmation — within one business day. Need a full system design? $175/hour, hardware buyers get up to one hour credited back.