As drones become essential infrastructure for government agencies, utilities, and critical infrastructure operators, the U.S. Government has established policies and programs to reduce cybersecurity and supply chain risks associated with untrusted technology.
This guide explains what NDAA compliance, Blue UAS, and Green UAS actually mean - and how they fit together for public-sector and regulated operators today.
This article focuses on U.S. policies and is not legal advice.
Why these policies exist
Drones collect sensitive data and increasingly support safety-critical operations. As missions scale, so do concerns over cybersecurity, foreign influence, and supply chain risk. Federal policy seeks to ensure that systems used in public-sector and critical infrastructure missions remain secure, reliable, and trusted throughout their operational life. It directly affects:
- Procurement eligibility and funding
- Cybersecurity and data-handling requirements
- Program scalability
- Confidence that platforms won’t be sidelined by future policy changes
What “NDAA-compliant” means for drones
The U.S. Government enacts a National Defense Authorization Act (NDAA) each fiscal year, and successive NDAAs have established cybersecurity and supply chain requirements for drones used by the U.S. Government and public agencies. These provisions restrict the procurement and operation of systems and critical components associated with certain foreign countries or manufacturers, helping to ensure that government drones are secure, trusted, and sourced from approved suppliers.
Why NDAA compliance now affects more than federal agencies
Recent NDAA provisions extend beyond federal fleets. The American Security Drone Act (ASDA), included in the FY24 NDAA, generally prohibits federal funds, including funds provided through contracts, grants, or cooperative agreements, from being used to procure or operate drones manufactured or assembled by covered foreign entities.
As a result, state and local agencies that rely on federal funding may be restricted from procuring or operating non-compliant drones on funded projects.
In practice, this has made NDAA compliance the baseline requirement for many public-sector, Department of Transportation, and critical-infrastructure drone programs, not just a federal checkbox.
What is Blue UAS?
The Blue UAS program, run by the Department of War's Defense Contract Management Agency (DCMA), identifies trusted drone systems for defense and national-security missions. Approved systems undergo extensive review for NDAA compliance, cybersecurity, supply chain integrity, and foreign influence.
There are two designations:
Blue UAS Cleared: DCMA has verified that the system meets applicable NDAA supply chain and cybersecurity requirements.
Blue UAS Select: A cleared platform that has been competitively selected or sponsored by a military service or Combatant Command and has an approved Authority to Operate (ATO).
What is Green UAS?
As drone use expanded beyond defense into civilian government, public safety, and critical infrastructure operations, a parallel security framework emerged for non-military use cases: the Green UAS program. Administered by the Association for Uncrewed Vehicle Systems International (AUVSI) and in coordination with the U.S. Government, Green UAS provides a standardized, scalable process to assess cybersecurity and supply chain risk for public-sector drone deployments.
Green UAS includes two designations:
Green UAS Cleared: Focuses on core NDAA supply chain compliance and baseline device security.
Green UAS Certified: Covers baseline security plus corporate cyber hygiene and remote operations and connectivity security.
To summarize
While these programs are related, they serve different purposes:
- NDAA compliance sets the legal baseline for hardware sourcing
- Blue UAS serves defense and national-security missions
- Green UAS serves civilian government, public safety, and infrastructure operations
In practice: most agencies require NDAA compliance, look to Green UAS to streamline procurement, and rely on Blue UAS when mission sensitivity requires DoW-grade vetting.
Where Skydio stands
Blue and Green UAS status and cybersecurity posture
Skydio is firmly committed to meeting the cybersecurity, supply chain security, and domestic sourcing objectives of the NDAA. Skydio has a long-standing history on the Blue UAS Select List with the X2D and X10D drones.
The Skydio X10, Dock for X10, and R10 are also included on the Blue UAS Cleared List, making Skydio the first and only provider of a Blue UAS-cleared Drone as First Responder (DFR) solution. This designation confirms that the listed systems satisfy applicable federal cybersecurity, supply-chain security, and NDAA requirements and may support eligibility for federal and state grant programs that require or prioritize Blue UAS-cleared technology.
Trusted drone operations require more than secure hardware - they demand equally rigorous protection of the cloud services connecting aircraft, operators, and mission data. As DFR programs scale, these cloud systems become critical infrastructure that must be fortified against evolving threats. Skydio aligns its cloud security with Cloud Security Alliance (CSA) Security Guidance v5 and FBI CJIS Security Policy v6.1, implementing controls across user access, software updates, fleet management, and mission data. This approach reinforces established practices in data protection, threat monitoring, incident response, and operational resilience.
Skydio maintains SOC 2 Type II, ISO 27001:2022, and AS9100D certifications, holds TX-RAMP Level 2 authorization, and implements FIPS 140-3 validated encryption for data at rest and in transit. Additional details are available at the Skydio Security Trust Center.
Skydio maintains its security posture through continuous evaluation of Blue and Green UAS-listed systems, components, suppliers, and manufacturing processes - catching emerging risks before they become problems. This approach ensures our platforms deliver the reliability that commercial, public-safety, and national-security missions demand.
Why this matters
These designations directly affect:
- Procurement eligibility and funding
- Cybersecurity and data-handling requirements
- Program scalability
- Confidence that platforms won’t be sidelined by future policy changes
As drones shift from tools to infrastructure, compliance isn’t just about today, it’s about choosing trusted, secure systems built to last.
Blue List - https://tyrionprod.servicenowservices.com/gsp?id=cleared_list
Green List - https://www.auvsi.org/certification-training/green-uas/cleared-list/
Additional reading
- Blue UAS List: https://bluelist.dcma.mil/
- Green UAS List: Green UAS program overview, FAQs, and Cleared List.
- Federal Communications Commission (FCC) – Addition of Uncrewed Aircraft Systems (UAS) and UAS Critical Components to the FCC Covered List (December 2025)












