A Canadian software company finalises a distribution agreement with a US reseller. The product includes strong encryption. The US side raises a question that stops the contract review: does this shipment – or even this download – require a licence under US export-control rules? And what does Canadian export-control law independently require? The answer differs by regime, and getting it wrong in either direction carries real consequences.
Encryption export controls under US rules administered by the Bureau of Industry and Security (BIS, the US Commerce Department agency responsible for dual-use and commercial export controls) and OFAC operate through the Export Administration Regulations (the EAR), while Canada administers its parallel regime through Global Affairs Canada (GAC) under the applicable Canadian export-control instrument. Both regimes restrict the transfer of encryption items and associated technology to varying degrees, but they diverge significantly on classification methodology, licence exceptions, end-user obligations, and the interaction with financial-sanctions lists. As of April 2026, the two regimes have not harmonised their core classification approaches, and a product that qualifies for a mass-market exception under one regime may still require a separate authorisation under the other.
This analysis compares the two regimes across the criteria that matter most to a cross-border business: the classification process, licence exceptions, country scope, end-user controls, reporting obligations, and enforcement posture. It closes with a practical decision sequence and a note on when to involve counsel.
What legal instruments govern encryption export controls in each regime?
The US regime governing encryption export controls sits principally within the EAR, administered by BIS. OFAC's role is distinct: it administers financial-sanctions programmes under the International Emergency Economic Powers Act (IEEPA) and related statutory authorities. A transfer of encryption technology to a party on OFAC's SDN List (the list of Specially Designated Nationals and Blocked Persons maintained by the Office of Foreign Assets Control) is prohibited regardless of BIS classification. The two US authorities are complementary, not duplicative. BIS controls the item; OFAC controls the counterparty. An exporter must clear both.
Canada's regime is administered by GAC under the applicable country export-control instrument. Canada controls cryptographic items as a category of controlled goods, drawing on commitments under the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies – the same multilateral foundation that informs the US approach. However, the domestic implementation differs. GAC issues permits rather than licences, the classification structure uses national control-list entries rather than US Export Control Classification Numbers (ECCNs – the alphanumeric codes that determine what US export restrictions apply to a given item), and the exceptions regime operates through permit-exemption provisions that do not map precisely onto BIS licence exceptions.
For a business operating in both jurisdictions, neither regime defers to the other. Canadian authorisation does not discharge US requirements, and a BIS licence exception does not create a right to export under Canadian law. In our cross-border practice, we frequently see compliance teams assume that clearing one regime automatically clears the other. That assumption is incorrect and carries enforcement risk in both directions.
How does item classification work, and where do the approaches diverge?
Classification is the first analytical step in both regimes and the point where the practical divergence begins. Under the EAR, encryption items are classified by ECCN, with the specific entry depending on the cryptographic strength, the type of algorithm, the key length, and the intended application. Mass-market encryption products – those meeting defined technical parameters and available generally without restriction – may qualify for a favourable classification or a self-classification procedure, but exporters must still conduct the classification analysis and, where required, submit a notification to BIS before the first export.
Canada's classification process uses the national control list administered by GAC. The list similarly reflects Wassenaar Arrangement entries, but the operational application diverges. The Canadian approach incorporates certain decontrol thresholds that do not align precisely with BIS parameters, meaning a product decontrolled under one regime may remain controlled under the other. The determination of whether an encryption item falls within the controlled category requires separate analysis against each list. There is no automatic equivalence.
The deemed export (a release of technology to a foreign national within the exporter's home jurisdiction, treated as an export to that person's home country) dimension adds further complexity. BIS applies deemed-export controls to encryption technology: providing a foreign national with access to source code or technical data in the United States can constitute a controlled export to that person's home country. Canada maintains a comparable concept for controlled technology, though the operational scope differs. A business with a mixed national workforce – a common situation in technology companies – must assess deemed-export compliance under each regime independently. For a deeper analysis of deemed-export obligations under the EAR, see our companion page on deemed exports and technology controls under BIS and the EAR.
What licence exceptions and permit exemptions are available?
Both regimes provide authorisations that can remove or reduce the need for a case-by-case permit or licence for certain encryption items, but the conditions and scope of those authorisations differ materially. Understanding them is critical: an exporter that relies on an exception without satisfying its conditions is in violation even if the transaction would have been approvable on application.
Under the EAR, a key authorisation for encryption items permits export without a specific licence to most destinations for products meeting mass-market criteria, subject to a one-time notification submission to BIS. This notification is not the same as a licence; it is a regulatory step that activates the exception. The exception does not apply to exports or re-exports to parties subject to US financial sanctions or to destinations subject to comprehensive US embargo. Where a product does not meet the mass-market criteria – for example, because it is purpose-built for government or military use, or because the key length or algorithm type falls outside the defined parameters – a specific licence from BIS is required.
Canada's permit-exemption provisions allow certain transfers of controlled cryptographic items without a permit, subject to conditions that include destination, end-user, and end-use requirements. The exemptions are not identical to BIS exceptions in scope or in the conditions they impose. Critically, the Canadian regime includes destination-specific provisions that differ from the US country-tier structure. A destination that benefits from a broad BIS exception may still require a Canadian permit, or may be subject to a different exemption category with different conditions.
What should a compliance team do when the two regimes produce different outcomes for the same transaction? The answer is to apply both sets of rules independently and to satisfy the stricter requirement on each point. Where a BIS licence is needed but a Canadian permit exemption applies, the business must obtain the BIS licence. Where a Canadian permit is needed but a BIS exception is available, the business must apply for the Canadian permit. There is no mechanism for a waiver in one regime to substitute for compliance in the other.
How do sanctions lists interact with encryption export controls?
Sanctions-list screening is a mandatory overlay on both regimes' export-control analysis. Under the US regime, OFAC's SDN List and the other consolidated US sanctions lists must be screened against every party to a transaction: the buyer, the end-user, any disclosed intermediary, and, where relevant, the beneficial owners. A BIS licence exception does not authorise a transaction with an SDN. The prohibition is absolute and applies regardless of the encryption product's classification or its mass-market status.
Canada's sanctions regime, administered under the applicable Canadian sanctions instruments, similarly prohibits transactions with listed persons. GAC administers export-control permits; the listed-party prohibitions are enforced through separate legal authority. A Canadian exporter must screen against the Canadian consolidated sanctions list as well as against third-country lists where the transaction's routing gives those lists effect. A transaction involving a US-origin item or technology, or a transaction cleared through a US correspondent bank, triggers additional US sanctions exposure regardless of whether the Canadian exporter is a US person.
This is the extraterritorial dimension that catches Canadian businesses by surprise. US secondary-sanctions risk, and the reach of the EAR to re-exports and re-transfers of US-origin technology, mean that a Canadian company can have US sanctions and export-control exposure without being a US person and without the goods physically entering the United States. In our experience, this extraterritorial reach is the most common gap in a Canadian exporter's compliance programme. Have you assessed your US nexus for every transaction involving encryption items?
The position above covers the standard framework. Your facts – the product's technical specifications, the parties in the transaction, the routing, and the end-use – change the analysis at each step. For an assessment of your exposure under both regimes, contact Calder & Vance at info@caldervance.com.
What are the end-user obligations and re-export controls?
End-user controls are a structural feature of both regimes, but they operate differently in practice. Under the EAR, where a specific licence is required, BIS may impose end-use and end-user conditions as licence conditions. Even where a licence exception applies, the exporter must not proceed if it has knowledge that the encryption item will be used in a prohibited end-use or transferred to a prohibited end-user. Knowledge is interpreted broadly: a compliance team that avoids inquiry to preserve ignorance does not benefit from the lack of explicit knowledge.
Re-export controls are a particular feature of US law. US-origin encryption technology – including software and source code – is subject to BIS re-export rules when it moves from one foreign country to another. A Canadian distributor that receives a US-origin encryption product and then distributes it to end-users in third countries must apply the EAR re-export rules, even though the goods never return to the United States. The re-export destination, the end-user, and the end-use each require analysis against the EAR and against OFAC's lists.
Canada's permit regime does not impose equivalent statutory re-export controls on Canadian-origin goods once they have left Canada, but where a Canadian export includes US-origin content or technology, the US re-export rules apply in parallel. A Canadian manufacturer that incorporates US-origin encryption components into a product it then exports must assess whether the finished product is subject to EAR re-export obligations. The de minimis and foreign-direct-product rules under the EAR determine when that US-origin content is sufficient to bring the finished product within EAR jurisdiction. This analysis is product-specific and must be done before the first shipment.
If a transaction has already been flagged under either regime, or a permit or licence has been refused, an early compliance review can preserve options that narrow with time. Contact our team at info@caldervance.com.
What are the common risk flags and compliance mistakes?
Practical experience across both regimes surfaces a consistent set of compliance gaps. Each represents an enforcement risk that is avoidable with the right programme design.
- Treating a BIS notification as a BIS licence. The mass-market notification procedure activates a licence exception; it does not itself authorise exports to sanctioned parties or embargoed destinations. The distinction matters in enforcement.
- Missing the deemed-export dimension. Technology businesses routinely provide foreign national employees and contractors with access to encryption source code. Where those individuals' home countries are subject to controls, each access event may be a controlled export.
- Assuming Canadian authorisation covers US obligations. A Canadian permit or exemption operates under Canadian law. It does not affect the exporter's US obligations, which attach to the item's origin and the parties involved.
- Screening only against the domestic list. A Canadian exporter relying solely on the Canadian consolidated list, without screening against OFAC's SDN List, misses the extraterritorial exposure that US law creates for non-US persons dealing in US-origin goods or transacting through the US financial system.
- Failing to update classification on product change. An encryption item's classification can change when its technical parameters change – for example, when key length increases or a new algorithm is added. A product that was mass-market on first classification may no longer qualify after a software update.
- Inadequate end-user documentation. Both regimes rely on end-user and end-use representations. Where those representations are not collected, reviewed, and retained, the exporter cannot demonstrate due diligence in an enforcement proceeding.
Mythology also plays a role. A common assumption is that strong encryption is essentially unregulated today because mass-market products are widely available. That assumption conflates the availability of a product commercially with the legal position of a specific exporter making a specific transfer to a specific party. The commercial availability of encryption does not discharge the exporter's classification, screening, and authorisation obligations.
How do the enforcement postures compare?
Both BIS and OFAC maintain active enforcement programmes for export-control and sanctions violations. OFAC's civil penalty framework operates on a strict-liability basis for strict-liability violations: the absence of intent does not eliminate liability, though it is a factor in penalty calculation. BIS enforcement similarly distinguishes between wilful violations and those resulting from inadequate compliance controls, but administrative and criminal penalties are both available for serious violations.
Canada's enforcement regime under the applicable country export-control instrument provides for both administrative and criminal penalties for unlicensed exports and permit violations. The enforcement posture of GAC has historically been less prominent internationally than that of BIS or OFAC, but this should not be taken as an indicator of lower risk. Canadian enforcement capacity and regulatory attention have developed significantly, and the reputational and practical consequences of a finding of non-compliance under Canadian law are serious.
Voluntary self-disclosure (VSD – a proactive report of a potential violation to the relevant authority before enforcement action begins) is recognised as a mitigating factor by both BIS and OFAC in the US regime. Canada's applicable enforcement guidance similarly recognises proactive disclosure as a relevant consideration. In our practice, a timely and well-documented VSD, accompanied by a credible remediation plan, consistently produces better outcomes than a violation discovered through an external audit or a third-party report. The decision to disclose – and the timing and scope of that disclosure – requires careful analysis before any submission is made.
Do businesses regularly ask whether their compliance programme would withstand an enforcement inquiry? A programme that cannot answer that question affirmatively is a liability.
A practical decision sequence for cross-border encryption transactions
A cross-border business dealing in encryption items should work through the following sequence for each transaction. This is a decision framework, not a substitute for legal analysis on specific facts.
- Classify the item under each regime independently. Determine the ECCN (or controlled status) under the EAR, and determine the control-list status under the Canadian regime. Do not assume equivalence.
- Screen all parties. Run the buyer, end-user, all intermediaries, and their beneficial owners against OFAC's lists, the Canadian consolidated sanctions list, and any other applicable lists. A hit at any level changes the analysis.
- Identify applicable authorisations. Under the EAR, determine whether a licence exception is available and whether its conditions are met – including the notification requirement where applicable. Under the Canadian regime, determine whether a permit exemption applies and whether its conditions are satisfied.
- Assess the extraterritorial dimension. Where the goods are US-origin or incorporate US-origin content, apply the EAR re-export rules to any onward transfer, regardless of the exporter's home jurisdiction.
- Collect and retain end-user documentation. For each transaction requiring a licence or permit – and for transactions relying on exceptions or exemptions – collect signed end-user undertakings and retain them for at least the applicable record-keeping period under each regime.
- Apply the stricter requirement. Where the two regimes produce different outcomes, comply with the stricter obligation on each point. Do not assume that satisfying one regime discharges the other.
- Escalate where there is doubt. Where the classification, the screening result, or the applicable authorisation is genuinely uncertain, seek qualified counsel before the transaction proceeds. An uncertain position treated as clear is a compliance failure.
In a recent matter, a technology business was distributing an encryption software product across multiple markets, including through a Canadian subsidiary. Its US parent had completed BIS classification and activated the relevant exception. The Canadian subsidiary had not separately assessed the Canadian control-list position and had not screened end-users against OFAC's lists, reasoning that its parent's US compliance programme was sufficient. A compliance review identified both gaps. We assisted in completing the Canadian classification, conducting retrospective end-user screening, and establishing a consolidated compliance protocol covering both regimes. The matter was resolved without enforcement action, but the resolution required significant remediation work that earlier analysis would have avoided.
Related practices
- Deemed Exports and Technology Controls under BIS and the EAR – assessment and management of deemed-export obligations for foreign national employees and contractors
- OFAC vs OFSI: Encryption Export Controls Compared – parallel analysis covering the UK regime and its divergence from the US position
- OFSI vs EU: Encryption Export Controls Compared – UK and EU regime comparison for businesses operating across both jurisdictions