A technology exporter ships hardware to a distributor in a third market. Its legal team has confirmed the item is EAR99 – no Export Control Classification Number required, no licence needed. Six months later, EU customs flags the same hardware under the EU dual-use regulation. The distributor is blocked from re-exporting to a downstream customer. How can the same product face two entirely different control determinations? The answer lies in how the US and EU classification regimes are structured, and how a business must operate both simultaneously.
ECCN classification under the US Export Administration Regulations assigns each controlled item an Export Control Classification Number (a five-character alphanumeric code under the US Commerce Control List that identifies an item's control parameters and the licence conditions attached to it). The EU dual-use regime uses a parallel but structurally distinct list and applies a different catch-all provision. As of April 2026, the two regimes share many control entries derived from multilateral arrangements, but diverge on scope, end-use controls, and the consequences of mis-classification in ways that create real exposure for cross-border businesses.
This analysis maps the divergence across the classification methodology, the catch-all rules, the licensing implications, the cross-regime risk stack, and the practical steps a business should take before it ships.
How does ECCN classification work under the EAR?
Under the EAR, administered by the US Bureau of Industry and Security, every item subject to the rules either carries an ECCN or falls into the residual EAR99 category. The ECCN is a five-character code: a letter identifying the product category, a digit identifying the Commerce Control List group, and three additional characters identifying the specific entry and the reasons for control. The reasons for control determine which destinations, end uses, and end users require a licence.
Classification begins with a self-assessment by the exporter. The exporter reads the Commerce Control List entry, applies the technical parameters of the item to the entry's specifications, and determines the ECCN. BIS does not pre-classify items as a matter of routine. An exporter who is uncertain can request a commodity classification (an official BIS determination of the ECCN), but that process takes time and BIS's response is item-specific.
The export control classification is then cross-referenced against the Commerce Country Chart. That chart maps each reason for control to each destination. The intersection of the ECCN and the destination – together with any end-use or end-user flag – determines whether a licence is required. An EAR99 item requires no licence for most destinations, but it can still be subject to end-use controls and entity-level restrictions if the end user appears on the Entity List or the Denied Persons List.
In our experience, the most common mis-classification error is treating EAR99 as a clean bill of health. It is not. An EAR99 designation resolves the commodity-control question; it does not resolve the party-screen question or the end-use question. Both must be addressed separately before any shipment clears compliance review.
How does the EU dual-use regime classify the same item?
The EU dual-use regime, established under the relevant EU Council regulation, uses a Dual-Use List that mirrors many – but not all – of the entries in the multilateral control arrangements to which both the US and EU adhere. The list is divided into ten product categories and five control groups, using a numbering convention that broadly tracks the Wassenaar Arrangement and other multilateral lists.
The structural difference begins at the classification stage. Under the EU regime, the competent national authority of each EU member state is the first point of contact for classification queries. There is no single EU-wide classification database equivalent to the Commerce Control List. An exporter operating from Germany addresses queries to a different authority than one operating from the Netherlands. This decentralised structure means that classification outcomes can vary between member states even for identical items, though the substantive list entries are the same EU-wide.
The EU regime also applies a catch-all control: an item that is not listed on the Dual-Use List can nonetheless require a licence if the exporter knows or has been informed that the item is or may be intended for a use connected with weapons of mass destruction or certain military programmes. The US catch-all mechanism under the EAR operates on similar principles but has different trigger conditions and a different administrative process. In practice, a catch-all notice received from a US authority does not automatically trigger the EU catch-all, and vice versa.
Where the EU and US lists genuinely diverge – entries that appear on one list but not the other, or where technical parameters are defined differently – a cross-border exporter faces the obligation to classify correctly under both regimes. Classifying the item under the EAR does not discharge the EU obligation, and classifying it under the EU list does not satisfy the US reporting and licensing requirements.
Where do the regimes diverge most sharply in practice?
The most significant areas of divergence fall into four categories: the treatment of software and technology, the scope of the catch-all provisions, the licensing exceptions available, and the end-use-certificate requirements.
On software and technology, the US regime applies the deemed export rule: releasing controlled technology or source code to a foreign national in the United States is treated as an export to that person's country of nationality. The EU regime does not operate an equivalent deemed-export control at the EU level. Some member states apply analogous controls under national law, but there is no harmonised EU deemed-export rule. A US-based technology company transferring controlled software to a foreign national employee must analyse the deemed-export question under the EAR. A European company doing the same is not subject to an equivalent EU-level obligation – though it may face US extraterritorial reach if the technology originated in the US.
On catch-all provisions, the EU regime includes a cyber-surveillance catch-all not present in the original EAR structure. Items that are not listed but are destined for internal repression uses can be caught under the EU regulation in ways that the standard EAR analysis would not flag. This divergence matters for exporters of dual-use technology to certain markets.
Licensing exceptions under the EAR – including the No Licence Required designation, licence exceptions such as those for Technology and Software under Restriction and for Strategic Trade Authorisation – have no direct EU equivalents. The EU general authorisations are issued at the EU level and at member-state level and have different geographic scopes, item scopes, and reporting obligations. A business that has structured its entire export programme around an EAR licence exception may find that the same shipment requires a case-by-case licence from a member state authority under the EU rules.
The position above covers the standard structural analysis. Your specific goods, the markets you serve, the entities in your supply chain, and the national authorities in the EU member states through which your products move – all of these change the detailed picture.
To assess your classification position under both regimes, contact Calder & Vance at info@caldervance.com.
How does OFAC sanctions exposure interact with ECCN classification risk?
ECCN classification under the EAR addresses the export-control dimension of a transaction. It is administered by BIS. OFAC administers a separate set of economic sanctions programmes that operate concurrently. The two regimes are parallel, not hierarchical, and compliance with one does not discharge obligations under the other.
The interaction between them is most acute for items destined for sanctioned jurisdictions, listed entities, or transactions that involve blocked property. An item that is EAR99 and requires no BIS licence may nonetheless be completely prohibited under an OFAC sanctions programme if the destination, the buyer, or an intermediate party is subject to OFAC's authority. Conversely, an item that carries a specific ECCN and qualifies for a licence exception may still require an OFAC specific licence – a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) – if an OFAC sanctions programme applies.
The principle is that the stricter prohibition governs. Where both BIS and OFAC restrictions apply, the exporter must satisfy both. Neither agency's clearance waives the other's requirement. In a cross-border transaction, this means an exporter must run the analysis twice: once against the EAR using the ECCN and the Commerce Country Chart, and once against the relevant OFAC programme for the specific counterparty and destination.
In a recent matter, a software business had correctly classified its product as EAR99 and confirmed no BIS licence was required for the destination. A mid-chain distributor had a minority shareholder that appeared on an OFAC list. The EAR99 designation offered no protection from OFAC's rules. We assessed the ownership and control position, identified the OFAC exposure, and advised on the steps required before the transaction could proceed. The matter illustrated how classification and sanctions screening are sequential, not alternative, obligations.
The EU dimension adds a third layer. The EU sanctions regime, maintained through Council regulations, operates independently of both the EAR and OFAC. An item cleared by BIS and supported by an OFAC licence can still be blocked under an EU sanctions regulation if the EU has a separate prohibition in place. The three regimes must be analysed together for any cross-border transaction with multi-jurisdictional exposure.
What risk flags should compliance teams prioritise?
Practitioners advising on export-control and sanctions matters consistently identify five categories of risk that mis-classification or incomplete cross-regime analysis generates.
The first is the EAR99 complacency risk. A determination that an item is EAR99 removes the commodity-control obligation under the EAR. It does not remove the party-screening obligation, the end-use obligation, or any OFAC obligation. Compliance programmes that treat EAR99 as a green light without running the further checks are exposed.
The second is the supply-chain contamination risk. Items that originate in the United States or contain US-origin technology above a de minimis threshold are subject to the EAR wherever they go. A European company that incorporates US-origin components into its product and then exports that product to a third country may be subject to EAR jurisdiction over the re-export, even though it is not a US person. The EU classification of the finished product does not remove the US re-export obligation.
The third is the deemed-export risk for businesses with internationally mobile workforces. A US-controlled entity that employs foreign nationals and provides them access to controlled technology must analyse the deemed-export position under the EAR. This is an internal-transfer question, not an export question, and it is frequently overlooked in businesses whose physical shipments are otherwise well-managed.
The fourth is the catch-all gap. An item that falls below the technical parameters of a specific list entry may still be subject to control if there are red flags about the end use. Both the EAR and the EU regime impose positive obligations to enquire further when red flags are present. An exporter who proceeds without addressing those flags cannot rely on the absence of a listed ECCN as a defence.
The fifth is the national-authority divergence risk within the EU. Because EU classification queries are addressed to national authorities, a multi-country European business may receive inconsistent guidance on the same item from different member state authorities. Documenting the basis for a classification determination, and applying it consistently across the group, reduces exposure if a divergent determination surfaces later.
If a shipment has already been flagged by a customs authority, or if an internal review has surfaced a possible mis-classification, an early assessment can preserve options that narrow significantly if an enforcement referral follows. Contact us at info@caldervance.com for a confidential review.
A common myth: one jurisdiction's licence clears the transaction everywhere
A persistent misconception in cross-border compliance is that obtaining a licence from one jurisdiction discharges the licensing obligation globally. It does not.
An OFAC specific licence authorises a defined transaction for OFAC's purposes. It does not authorise the same transaction under the EAR, under an EU Council regulation, under OFSI's financial-sanctions rules, or under the equivalent rules of any other jurisdiction whose law applies to the transaction. Each licence is regime-specific and, where it has geographic conditions, jurisdiction-specific.
The same is true in reverse. An EU general export authorisation covering a class of items to a set of destinations does not satisfy the EAR's licence requirements for the same items to the same destinations if those items are subject to US jurisdiction. The exporter must hold the appropriate authorisation under each applicable regime.
In our cross-border practice, we regularly advise businesses that have received an OFAC licence and assumed no further steps are required. That assumption is understandable when the OFAC process is the most visible part of the compliance review. But the EAR analysis, the EU analysis, and the OFSI analysis (where UK persons or goods are involved) are independent obligations. A properly structured export-control and sanctions compliance programme maps each transaction against every applicable regime, not only the most prominent one.
What does this mean in practical terms? It means that a business operating between the US and the EU needs a classification matrix that captures both the ECCN under the EAR and the equivalent EU list entry, a licence-requirement determination for each, and a sanctions screen under both OFAC and the relevant EU sanctions regulation. That is four discrete analytical steps, each of which can generate a separate obligation or a separate risk flag.
How Calder & Vance advises on cross-regime ECCN and classification matters
Our export-controls practice covers both the US EAR and the EU dual-use regime, and we work with local counsel in the relevant EU member state jurisdictions where national-authority queries are required. For US matters, we classify the item, confirm licence requirements and licence exceptions, and design the end-use controls. For EU matters, we assess the equivalent Dual-Use List position, identify the competent national authority, and prepare the classification file.
Where OFAC sanctions intersect with an export-control question – as they frequently do in transactions touching sanctioned jurisdictions or listed parties – we handle both the EAR analysis and the OFAC analysis in a single engagement. This avoids the gap that arises when export-control counsel and sanctions counsel work independently without sharing the full transaction picture.
For businesses with existing compliance programmes, we test the screening logic, map ownership and control chains, and redesign the programme to address both regimes. For businesses entering a new market or a new product line, we provide a classification determination before the first shipment. For businesses that have received an enforcement inquiry or a customs referral, we scope the apparent violation, advise on voluntary self-disclosure where relevant, and prepare the penalty defence.
Our work is structured around the transaction and the risk, not around a single regime. That is the only approach that gives a cross-border business a complete picture of its obligations.
Related practices
- Deemed export and technology controls under the EAR – identifying and managing US technology-transfer obligations for cross-border businesses
- ECCN classification: OFAC vs OFSI compared – how the US and UK classification regimes diverge on controlled-technology exports
- ECCN classification: OFSI vs Australia compared – the UK and Australian dual-use control positions for exporters serving both markets
Frequently asked questions on ECCN classification and the OFAC vs EU comparison
Where do the regimes diverge on ECCN classification?
The US and EU regimes diverge most significantly on the deemed-export rule, the catch-all provisions, the structure of licensing exceptions, and the role of national authorities within the EU. The US applies a deemed-export control for technology transfers to foreign nationals on US soil; the EU does not operate an equivalent at the EU level. The EU applies a cyber-surveillance catch-all that has no direct EAR equivalent. Licensing exceptions under the EAR have no direct EU counterparts, and EU general authorisations vary in scope across member states. A complete cross-border classification analysis must address both sets of rules independently.
Which regime is stricter on ECCN classification?
Neither regime is uniformly stricter than the other. The US EAR applies broader extraterritorial reach through the de minimis rule and re-export controls, capturing non-US companies that incorporate US-origin content. The EU regime applies a cyber-surveillance catch-all and decentralised national-authority oversight that can produce stricter outcomes for specific item categories in specific member states. For a given item and a given transaction, the more restrictive regime is determined by the technical parameters of the item, the destination, the end user, and the applicable catch-all conditions. Cross-border businesses must analyse both rather than assuming one is the governing standard.
What should a cross-border business do about ECCN classification?
A cross-border business should establish a classification matrix for each item in its product range that records the ECCN under the EAR, the equivalent EU Dual-Use List entry, the licence requirements under each regime for each destination, and the catch-all conditions that could apply. That matrix should be reviewed when the product changes, when the destination changes, and when either regime's list is updated. Where uncertainty exists, a commodity classification request to BIS or a query to the relevant national authority in the EU provides a defensible determination. Businesses with US-origin technology in their supply chain should also analyse the re-export and deemed-export positions before transferring controlled items or technology.
About the author
J. M. Aldridge advises multinationals and financial institutions on US sanctions and export controls, with a focus on OFAC licensing, secondary-sanctions risk, and BIS classification. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.