Hikvision and Dahua, the two largest Chinese makers of security cameras, are now restricted by governments in the US, UK, Australia and Canada, mainly over national security concerns and links to surveillance in Xinjiang. In the US, new covered models can no longer be authorized for sale, and federal agencies may not buy them. Yet both companies remain among the world’s biggest camera suppliers, and millions of their devices are still in use worldwide.
Revenue and market share
Hikvision reported total revenue of RMB 92.5 billion for 2024, up 3.5% year on year. International markets brought in about RMB 26 billion, or 28.1% of revenue, and the company said developing markets accounted for more than 70% of that overseas income (International Security Journal, 2025).
Precise global market shares are sold through paid analyst databases. In a published estimate, Memoori ranks Hikvision first and Dahua second by revenue and puts the two together at roughly a third of global video surveillance revenue (Memoori, 2026). That share is an unaudited industry estimate.
Their reach is especially visible in price-sensitive markets. In India, according to Reuters, Hikvision and Dahua together hold about 30% of the CCTV market, behind domestic brand CP Plus (Reuters, 2025).
Why governments are restricting them
Two separate concerns drive most of the government actions. The first is national security and data access. The UK’s 2022 decision explicitly targeted equipment from companies subject to China’s 2017 National Intelligence Law, which obliges organizations to support state intelligence work (UK Parliament, 2022). Officials worry that networked cameras on sensitive sites could be accessed or manipulated.
The second concern is human rights. The US Commerce Department added Hikvision and Dahua to the Entity List in October 2019 alongside Xinjiang public security bodies, stating they were implicated in human rights violations in China’s campaign against Uyghurs and other mostly Muslim minorities (Federal Register, 2019).
Hikvision rejects the security allegations. After a Canadian court setback in 2025, a Hikvision spokesperson told Reuters its products “do not pose a national security threat” (Reuters, 2025).
Government actions by country
| Date | Country | Action | Source |
|---|---|---|---|
| Aug 2018 | United States | NDAA FY2019 Section 889 bars federal agencies from procuring Hikvision, Dahua and Hytera video surveillance equipment | D.C. Circuit, 2024 |
| Oct 9, 2019 | United States | Hikvision and Dahua added to the Commerce Entity List (export restrictions) over Xinjiang | Federal Register, 2019 |
| Jun 3, 2021 | United States | Executive Order 14032 lists Hikvision; US persons barred from buying its publicly traded securities | Federal Register, 2021 |
| Nov 2021 | United States | Secure Equipment Act directs FCC to stop authorizing equipment on its Covered List | D.C. Circuit, 2024 |
| Nov 24, 2022 | United Kingdom | Departments told to stop deploying such equipment on sensitive sites and keep it off core networks | UK Parliament, 2022 |
| Nov 25, 2022 | United States | FCC bans new authorizations of covered Hikvision/Dahua equipment used for public safety, government facility security, critical infrastructure or national security | FCC, 2022 |
| Feb 2023 | Australia | Defence removes Hikvision/Dahua cameras after an audit found 900+ units across 250+ government sites | The Register, 2023 |
| Apr 2, 2024 | United States | D.C. Circuit upholds the FCC ban but finds its “critical infrastructure” definition too broad | D.C. Circuit, 2024 |
| Apr 9, 2025 | India | Mandatory lab testing (potentially including source code) for all internet-connected CCTV models; applies to all vendors, not only Chinese | Reuters, 2025 |
| Jun 27, 2025 | Canada | Hikvision Canada ordered to wind up and cease all operations | ISED Canada, 2025 |
| Oct 2025 | United States | FCC Second Report and Order covers modular transmitters and blocks further import and marketing of previously authorized covered equipment | FCC, 2026 |
| Jul 22, 2026 | United States | FCC Third Report and Order closes the “component” loophole for logic-bearing hardware parts | FCC, 2026 |
Scope of the US FCC ban
The FCC rules do not make it illegal for a consumer to keep or use a camera they already own. The 2022 order stopped new equipment authorizations, which are required to market or import radio-frequency devices in the US (FCC, 2022). For Hikvision, Dahua and Hytera, the ban applies to equipment used for public safety, government facility security, critical infrastructure surveillance or other national security purposes.
Hikvision USA and Dahua USA challenged the order. In April 2024, the D.C. Circuit ruled that Congress had effectively ratified the Covered List, so the companies could not contest their inclusion, but it sent the FCC’s broad definition of “critical infrastructure” back for revision (D.C. Circuit, 2024).
The FCC has since tightened the rules twice. According to its July 2026 order, the October 2025 rules blocked further importation and marketing of already-authorized covered equipment while allowing continued use, and the 2026 rules bar authorization of devices that incorporate covered logic-bearing components (FCC, 2026).
Canada’s shutdown order
Canada went further than any other Western government by ordering Hikvision’s Canadian subsidiary to close (ISED Canada, 2025). In September 2025, the Federal Court declined Hikvision’s request to set the order aside, and the company said it would pursue arbitration under the 2014 Canada-China investment treaty (Reuters, 2025).
Documented security vulnerabilities
Political concerns are separate from technical security, but both brands have had serious, publicly documented flaws.
| Vulnerability | Vendor | Severity | What it allowed | Source |
|---|---|---|---|---|
| CVE-2021-36260 | Hikvision | CVSS 9.8 | Command injection in the web server; a remote attacker could take control of the device | CISA, 2021 |
| CVE-2021-33044 | Dahua | CVSS 9.8 | Authentication bypass at login on older firmware | SecurityWeek, 2024 |
| CVE-2021-33045 | Dahua | CVSS 9.8 | Authentication bypass by spoofing loopback traffic | SecurityWeek, 2024 |
All three were patched by the vendors in 2021, but CISA later added them to its catalog of vulnerabilities exploited in the wild, Dahua’s two flaws in August 2024 (SecurityWeek, 2024). Internet-exposed cameras with old firmware are attractive targets regardless of brand, so for these flaws patching matters more than country of origin.
Practical steps for owners and buyers
- Owning one is not illegal for private individuals in the US, UK or Canada. The restrictions target government use, sales authorizations and corporate operations.
- Cameras are sometimes sold under a different brand from the actual manufacturer (“white labeling”), an issue the FCC sought comment on in its 2026 order. The FCC ID on the device or the firmware details can help identify the original maker.
- Update firmware or replace end-of-life devices, since unpatched cameras are the bigger everyday risk.
- Never expose cameras directly to the internet. Disable port forwarding and UPnP, change default passwords, and put cameras on a separate network segment or guest VLAN.
- Prefer local storage or vendors with clear data policies, and know where your footage is stored and who can access it.
- Businesses and public bodies should check procurement rules: US federal contractors face Section 889 obligations, and UK public bodies follow the 2022 guidance for sensitive sites.
Methodology
The government-action table rests on primary documents: the Federal Register, FCC orders, the D.C. Circuit opinion, a UK Parliament written statement and the Canadian government’s Investment Canada Act register. Where no official text was accessible (Australia, India, the Canadian court ruling), entries rely on Reuters and The Register. Vulnerability data comes from CISA and SecurityWeek. Company financials come from Hikvision’s reported results as summarized by International Security Journal.
Market share figures are estimates from industry analysts and differ between firms; the one cited here is published and rounded. The table covers the most significant national actions that could be verified and is not exhaustive; local and agency-level bans are omitted. Legal situations, especially in Canada and at the FCC, continue to evolve.