Phoenix LiDAR Systems President Rob Dannenberg’s experience with Blue UAS verification shows why a statutory claim, a vetted product and the Drone Dominance supply chain roadmap are three different things—and why the trust boundary extends well beyond the aircraft.

When Phoenix LiDAR Systems submitted its miniRANGER-3 Lite for Blue UAS review, the company did not get the system back in working order. The equipment had been taken apart too thoroughly to be economically rebuilt.
Rob Dannenberg, Phoenix’s president, did not view that as a complaint about the process. He viewed it as evidence that the review had gone beyond paperwork. The reviewer was not simply asking who Phoenix said made the system. It was examining what was actually inside it.
That distinction sits at the center of an increasingly urgent debate over one of the unmanned systems market’s most widely used phrases: “NDAA compliant.”
For years, the phrase has functioned as shorthand. It signals that a manufacturer believes its product avoids the countries, entities and components prohibited under the applicable National Defense Authorization Act provisions. But it is not, by itself, an independent product certification. A company can make the representation without submitting the complete system to a government-recognized teardown, ownership review or cybersecurity assessment.
Dannenberg sees the issue from an unusually broad position. He is a retired Army veteran who later worked in engineering, surveying and geospatial technology before becoming president of a dual-use LiDAR manufacturer and integrator. His perspective connects operational risk with commercial integration, component auditing, payload security, software control and the integrity of the resulting data.
“Turning NDAA into a check-the-box is, I think, the biggest problem,” he said.
THREE DIFFERENT QUESTIONS
Inside Unmanned Systems’ June/July “Component by Component” feature separated the current procurement environment into three overlapping frameworks. Each answers a different question.
The NDAA establishes the statutory floor: who and what are prohibited? The provisions governing UAS procurement address covered countries, named entities and certain classes of components. They tell a buyer what cannot be purchased or operated. They do not create one universal process through which every product is affirmatively certified as secure.
Blue UAS asks a different question: has this specific system or component been independently reviewed and cleared? The Blue List, administered by the Defense Contract Management Agency’s Unmanned Systems X organization since it took over from the Defense Innovation Unit in December 2025, goes beyond a supplier’s representation. The process can include review of foreign ownership, control and influence, physical hardware teardown and cybersecurity. That is why a product can be NDAA compliant and still fail Blue UAS review.
The Drone Dominance Program Supply Chain Framework goes deeper still. It asks where individual components were made, assembled and controlled; where firmware repositories are hosted; whether source code can be audited; and whether the origin of sensitive materials can be documented. Its phased schedule covers 13 component areas and raises requirements through 2027. What is preferred in one phase is generally positioned to become the minimum in the next.
NDAA compliance is, therefore, a legal eligibility claim. Blue UAS adds independent evidence about a defined product. The Drone Dominance framework is turning that evidence into a continuing component-level and production-level discipline.
Dannenberg believes buyers confuse them largely because education has not kept pace. The rules have changed quickly, the terminology is imprecise, and many organizations are trying to satisfy contract language by obtaining a letter and checking a box. Some manufacturers may benefit from the ambiguity, but he does not assume every questionable claim is deliberate. Many, he said, do not fully understand what the rules require or how quickly they have moved.

WHAT THE PAPERWORK CAN MISS
Phoenix’s own experience illustrates why good intentions are not enough.
During its compliance work, the company learned that documentation supplied for one module did not fully account for the origin of a smaller embedded component. The larger module had come through an allied-country supply channel, but the deeper review identified a Chinese-origin part within it. The finding did not disqualify the Phoenix product, and Dannenberg did not believe the supplier had acted intentionally. Phoenix nevertheless replaced the component and strengthened how it monitors bills of materials and later changes.
The lesson was not that the part itself was necessarily capable of compromising a mission. It was that the paper trail did not completely describe the physical product.
That risk grows as supply chains become layered. A U.S. integrator may purchase a board from an allied supplier that purchases a module from a larger electronics house sourcing parts globally. Product revisions and emergency substitutions can alter the answer after an initial review.
DCMA’s teardown work has exposed the same structural problem at a wider scale. Inside Unmanned Systems reported that assessors have encountered wiped chips of unknown origin, counterfeit parts, Chinese-sourced ground-control elements and recurring cyber vulnerabilities. Some systems could satisfy a narrow line-item check while still failing the purpose of the deeper standard.
Dannenberg described that difference through the military concept of commander’s intent. A manufacturer may read a rule literally and conclude that a Chinese component is acceptable because its producer is not one of the specifically covered entities. That may satisfy the narrowest interpretation. It may still run against the larger objective: reducing reliance on adversarial supply chains, establishing provenance and ensuring the government can understand and sustain the system it is buying.
The point is not that every foreign component is malicious. It is that the buyer should know what the component is, where it came from, who controls it and what happens if the supply disappears.
THE PAYLOAD IS PART OF THE SYSTEM
Dannenberg’s most important contribution may be his insistence that the trust boundary cannot stop at the airframe.
Phoenix’s miniRANGER-3 Lite appears on the Blue UAS list, but Phoenix is fundamentally a payload and integration company. Its systems can move among uncrewed aircraft, crewed aircraft, vehicles and backpack configurations. From that vantage point, discussing “the drone” as the complete security object is incomplete.
A buyer can select a Blue UAS aircraft and attach a payload with an uncertain supply chain. The sensor may contain its own processor, firmware, storage, navigation inputs and communications interfaces. Its data may pass through a ground control station and into post-processing software or a cloud environment operated in another jurisdiction. Securing the airframe while ignoring those layers can defeat the reason for selecting a trusted aircraft.
“If you’re attaching a payload to a drone, those shouldn’t be separated,” Dannenberg said.
The Drone Dominance framework is beginning to reflect that systems view. It separately addresses flight controllers, communications, GNSS modules, companion computers, imaging and optical systems, ground control equipment and software repositories. That is an advance over treating compliance as a question about the country printed on an aircraft’s final assembly label.
Dannenberg argues that the principle should extend beyond drones. If a LiDAR payload collects sensitive infrastructure data from an uncrewed aircraft, its provenance and data path matter. The same should be true when it is mounted on a truck or crewed aircraft. The collection platform changes; the sensitivity of the data may not.
THE COMMERCIAL COMPLIANCE GAP
For the Department of Defense, the procurement process can eventually force the issue. A system headed toward military use may face physical teardown, cyber review and bill-of-materials scrutiny. A weak claim is more likely to be discovered before fielding at scale.
Federally funded civil work occupies a less certain middle ground. Dannenberg said many architecture, engineering and construction firms require NDAA-compliant equipment because they perform work connected to federal funding. Yet, those buyers generally do not have access to a DCMA-style teardown. They may receive a supplier letter and have no independent way to determine whether it covers the complete configuration delivered.
In the purely commercial market, buyers may interpret “NDAA compliant” as a military-grade endorsement—a sign equipment has been independently vetted for security, quality and durability—even when the claim only means the manufacturer believes it avoids specified prohibited sources.
That ambiguity creates a competitive imbalance. One company may invest in independent review, supplier audits, component substitutions and continuing configuration control. Another may make a narrower statutory representation using the same two words. To an unfamiliar buyer, the claims can look equivalent.
The risk is not confined to national security. A customer may discover after purchase that equipment cannot be used on a contract. A public agency may have to replace systems acquired with taxpayer funds. A contractor may be unable to complete promised work. A smaller integrator confronted with an installed base that must be returned or modified could face a financial and support crisis.
Dannenberg described the problem in the buyer’s voice: “I thought I bought something that’s compliant. It’s not compliant, and I can no longer use this.”
The importance of verified status is expanding beyond direct Pentagon procurement. Recent FCC actions extended a Covered List exemption for Blue UAS equipment through January 1, 2028, and proposed excluding Blue-cleared systems from certain broader capability-based restrictions. Blue UAS is beginning to function not only as a defense purchasing mechanism but also as a form of regulatory market access.
ENGINEER TO THE DESTINATION
Dannenberg does not believe the answer is to preserve an expanding collection of color-coded labels. He would prefer a consistent standard that carries the auditability of Blue UAS into a framework understood by military, federal, state and commercial buyers.
Whether Blue UAS is eventually replaced, absorbed or retained remains a government decision. The direction of travel is clearer: component provenance, software control and continuing auditability are becoming more important.
That is why Dannenberg rejects the idea that a new entrant should engineer only to today’s Blue minimum or stop at the Drone Dominance Program’s Phase 2 preferred requirements.
“You can’t look at Phase 2,” he said. “You have to look at Phase 4.”
Hardware development, supplier qualification and manufacturing changes do not happen in a few weeks. A company that waits until a preferred requirement becomes mandatory may discover the necessary domestic or nearshore source does not exist at the required volume, price or performance. The better response is to identify those vulnerabilities now, develop alternatives where possible and engage government customers early where the industrial base cannot yet satisfy the roadmap.
The confirmed nearshore boundary—Canada and Mexico under the applicable trade framework—makes that planning especially important. In LiDAR, as in motors, batteries, semiconductors and rare-earth materials, the government’s desired sourcing destination may be ahead of current production capacity. The roadmap is doing two things at once: setting a procurement standard and broadcasting where new industrial capacity is needed.
Dannenberg also cautions against viewing stronger supply chain controls only as added cost. Phoenix’s experience has been that better visibility can improve production stability, reduce unexpected substitutions and make delivery more predictable. The cheapest component at purchase may become the most expensive if it later must be redesigned, replaced or removed from an installed fleet.
That is the larger lesson from the miniRANGER-3 Lite review. Its value was not another logo for Phoenix marketing. It was evidence about the product the company had actually built—and the obligation to keep that evidence current.
“NDAA compliant” should not end a buyer’s inquiry. It should begin one.
Which provision applies? Does the claim cover the aircraft, payload or complete integrated system? Which product revision was reviewed? Was the representation self-declared or independently verified? Does it include the software, processing environment and data path? What happens when a supplier changes?
The Blue UAS process is not perfect, and the Drone Dominance framework is pushing the industrial base toward capabilities that do not yet exist everywhere at scale. But the market is moving away from compliance as a permanent badge and toward compliance as a maintained product state.
The companies most likely to remain eligible are not the ones making the broadest claim today. They are the ones engineering toward the evidence buyers will require tomorrow.

