If you are a defense contractor, subcontractor, or federal supplier — even if you never touch classified data — you have two overlapping compliance regimes that shape which VPN you can legally deploy.
One is Section 889 of the National Defense Authorization Act, which prohibits your organization from using specifically named Chinese telecommunications and surveillance equipment or services, whether or not it touches your federal contract work. The other is the Cybersecurity Maturity Model Certification (CMMC), which sets the technical bar you must clear to be eligible for Department of Defense contracts that involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
The two regimes interact. And most commercial VPN marketing sidesteps both.
What Section 889 Actually Prohibits
Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Public Law 115-232) was enacted in August 2018 and implemented through the Federal Acquisition Regulation. It has two operative parts:
- Part A (effective August 2019) prohibits federal agencies from procuring or using "covered telecommunications equipment or services."
- Part B (effective August 2020) is the one that matters for contractors: it prohibits federal agencies from awarding contracts to entities that "use" covered telecommunications equipment or services as a substantial or essential component of any system — regardless of whether the equipment relates to the federal contract itself.
The named entities include Huawei Technologies, ZTE Corporation, Hytera Communications, Hangzhou Hikvision Digital Technology, and Dahua Technology — plus any subsidiary or affiliate of these companies. The FAR 52.204-25 clause operationalizes the prohibition and appears in essentially every federal contract awarded since 2020.
⚠️ Common misread: Contractors often think Section 889 only applies to equipment used on the federal contract. Part B is broader — it applies to your organization's use of covered equipment anywhere, even in a totally unrelated commercial line of business. Discovery of covered equipment in a subsidiary or a subcontractor's environment has been enough to trigger contract disputes.
How Section 889 Reaches a VPN Decision
A VPN is telecommunications infrastructure. Section 889 talks about "telecommunications equipment or services." So the question a diligent contractor has to answer is: does my VPN provider expose me to covered technology or services from a named entity?
Concretely, that means asking:
- Where is the VPN provider headquartered and legally domiciled? A US-based provider is not automatically compliant, but it is inside US legal jurisdiction. A provider headquartered in a country with limited transparency, or with ownership ties to entities of concern, is a harder due-diligence exercise.
- Where are the VPN's data centers physically located, and who owns them? A US provider that runs infrastructure in a country of concern is a supply chain concern even if the customer-facing brand is US.
- What is the VPN provider's upstream network transit — do they rely on carriers or hardware from a named entity? This is deeper due diligence and harder to verify, but it is exactly the type of question your C3PAO assessor may ask if CUI is in scope.
- Can the provider produce a written supply-chain risk statement or attestation? Not every provider will. The ones that can are demonstrating a level of operational maturity that maps well to CMMC requirements.
A US-headquartered, US-operated VPN with US-only server infrastructure — one that can attest to its supply chain in writing — is the easiest posture for a Section 889-aware contractor. That is not a marketing preference; it is a documentation problem.
CMMC 2.0 — What It Requires From Remote Access
CMMC 2.0, finalized by the DoD in its 2024 rulemaking and being phased into contracts through 2026 and beyond, has three levels:
- Level 1 — 17 basic safeguarding practices, self-assessed, for contractors handling FCI only.
- Level 2 — 110 practices from NIST SP 800-171, required for most contractors handling CUI, third-party assessed by a C3PAO for critical programs.
- Level 3 — Enhanced controls layered on top of Level 2, government-assessed, for the most sensitive contracts.
Most contractors are focused on Level 2. Level 2 is essentially SP 800-171 with formal certification. Several controls in SP 800-171 directly govern how you use a VPN:
AC-17: Remote Access
Remote access must be authorized, monitored, and controlled. In practical terms this means: a defined list of who is allowed to connect, session monitoring, and centralized termination capability. Your VPN needs to support role-based access, session logging, and administrative kill capability.
IA-2: Identification and Authentication
Multi-factor authentication is required for both privileged and non-privileged accounts. A VPN that only supports a shared password is not compliant. MFA must be enforced organization-wide, not opt-in.
SC-8 and SC-13: Transmission Confidentiality and Cryptographic Protection
Cryptography must be FIPS-validated when protecting CUI in transit. AES-256 is the industry standard and satisfies SC-13 as long as the implementation is validated. A VPN's cryptographic module choice — WireGuard, OpenVPN, IKEv2/IPsec — matters, and so does the implementation. Contractors handling CUI at Level 2 typically require documentation of the crypto module and mode of operation.
AU-2 and AU-3: Audit Events and Content of Audit Records
Connection logs, authentication events, and session terminations must be captured with enough detail to reconstruct events. Your VPN needs to produce administrator-accessible logs that meet these content requirements — a "we log nothing" consumer privacy stance is incompatible with CMMC Level 2 unless the administrator-side logging is available for compliance.
💡 The apparent contradiction: Consumer VPNs market "no logs." CMMC requires audit logs. Both can be true — the vendor can retain no logs on their infrastructure while the customer-administrator can collect access logs on their own side. What matters is that the deployment as a whole produces the audit trail SP 800-171 requires.
What This Means for Contractor VPN Selection
Combining Section 889 and CMMC, the VPN posture that actually clears both is:
- US-headquartered, US-operated, with US-based infrastructure
- Willing to attest in writing to supply-chain sourcing (no covered equipment from named entities)
- Enforces MFA organization-wide (not optional)
- Uses FIPS-validated or FIPS-compatible cryptography for transit
- Supports administrator-accessible connection and authentication logs
- Supports role-based access and centralized session termination
- Can produce documentation your C3PAO assessor can accept as evidence for AC-17, IA-2, SC-8, SC-13, and AU-2 controls
Most consumer VPN brands cannot check most of those boxes because their product is designed for individual privacy, not enterprise compliance documentation. The subset that can is small — and CyberFence is deliberately built to sit inside it. CyberFence is US-headquartered, US-operated, US-jurisdictioned, and structured to support the documentation defense contractors and their subcontractors need. For a broader walkthrough of the compliance-oriented posture, see our American-Owned VPN and HIPAA-Compliant VPN Guide pieces.
The Subcontractor Trap
Section 889 flows down through subcontracts. CMMC 2.0's rulemaking makes clear that subcontractors handling CUI must meet the same level of certification as the prime. That means if you are a defense subcontractor — even three tiers deep — you are not exempt from either regime. If you use non-compliant technology internally, and a prime contractor asks for FAR 52.204-25 representation, you may need to answer honestly that you cannot make the representation.
The consequence of misrepresenting compliance is not merely reputational. It is a False Claims Act exposure. The Department of Justice has prosecuted contractors for cybersecurity misrepresentation under the Civil Cyber-Fraud Initiative, and settlements have run into the millions. Getting the VPN decision right is not a nice-to-have; it is a legal exposure question.
Practical Next Steps
If you are a contractor evaluating VPNs, request the following from any vendor on your shortlist:
- Written statement of headquarters and infrastructure location
- Written attestation regarding Section 889 covered telecommunications
- Documentation of FIPS-validated cryptography (module identifier, mode of operation)
- Sample administrator audit log or specification of what the log includes
- Statement of MFA enforcement capability (organization-wide, not opt-in)
- Written confirmation that a Business Associate Agreement, Data Processing Agreement, or equivalent supply-chain agreement is available if your contract requires one
Any vendor that hesitates on those requests is not a serious candidate for a compliance-sensitive contract. Any vendor that provides them in writing has already done more than most competitors are willing to do.
If CyberFence is on your shortlist, visit the Teams page for compliance documentation or contact us directly. We publish an example client story from a defense subcontractor deployment for context on what the process looks like in practice.