Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

OFAC vs OFSI: Encryption export controls: what businesses miss

A software company headquartered in the United States ships an encrypted communications platform to a reseller in the United Kingdom. The reseller then sub-licenses the product to end-users across the EU, the Gulf, and South-East Asia. The US compliance team cleared the original shipment. The UK team assumed OFSI had nothing to say about encryption. Neither team asked what the EU dual-use rules required. Months later, a routine audit surfaces the gap – and the question becomes how many transactions were out of compliance, not whether one was.

Encryption export controls sit at the intersection of two distinct legal regimes that most businesses treat as one. Under the US Export Administration Regulations administered by BIS, encryption items carry specific classification requirements and licence exception conditions that determine whether a cross-border transfer is authorised. Under OFSI and the UK export-control regime administered by ECJU, the controls derive from a separate statutory basis – the Sanctions and Anti-Money Laundering Act and the Export Control Order – and the triggers for a licence requirement differ in ways that matter operationally. As of April 2026, the gap between those regimes is widening, not closing.

This analysis maps the divergence between the US and UK regimes on encryption export controls, identifies where businesses routinely miss the exposure, and sets out a practical sequence for managing both sets of obligations simultaneously.

What are encryption export controls and why do they sit in two separate regimes?

Encryption export controls are restrictions on the cross-border transfer of cryptographic technology, software, and related items, applied because encryption capability has both civilian and military utility. Under the US regime, the Export Administration Regulations (the EAR, administered by BIS) classify encryption items under the Commerce Control List (CCL) and assign each item an Export Control Classification Number (ECCN, the alphanumeric identifier that determines which licence requirements and exceptions apply). Under the UK regime, controls flow from the Export Control Order and are supplemented by OFSI financial-sanctions rules where the end-user or the transaction involves a designated person.

The two regimes share a common historical origin – the Wassenaar Arrangement, a multilateral export-control regime covering conventional arms and dual-use goods – but they have diverged substantially in implementation. The US system is more granular, more frequently updated, and carries extraterritorial reach through the de minimis rule and the foreign direct product rule (FDPR). The UK system, post-Brexit, operates independently of EU dual-use regulations and ECJU has its own licensing categories. A business that treats clearance under one regime as clearance under both is making an assumption that enforcement history does not support.

In our cross-border practice, we regularly advise clients who have obtained a US licence exception for an encryption product and then discovered that the UK leg of the same transaction required a separate ECJU open or individual export licence – or that OFSI's asset-freeze rules blocked payment from the overseas buyer regardless of the export-control position.

How does the US EAR classify and control encryption items?

Under the EAR, encryption items are classified under a dedicated ECCN category on the CCL. The classification determines the applicable licence requirements and whether a licence exception is available. BIS maintains a review and classification process for encryption items that differs from the standard dual-use classification pathway; exporters of mass-market encryption products can seek a review finding that reduces the regulatory burden for subsequent exports.

The key distinction the EAR draws is between mass-market encryption products – broadly available consumer or commercial software with encryption features that are not specially designed for government or military use – and items with more capable or specialised cryptographic functionality. Mass-market products that meet the relevant criteria may qualify for a licence exception, subject to filing an encryption registration with BIS and observing the end-user and end-use conditions. Products that do not meet those criteria require an individual export licence or must rely on another applicable exception.

Three features of the US regime catch exporters by surprise. First, the EAR applies to re-exports: once a controlled encryption item enters a jurisdiction, a subsequent transfer to a third country may require a fresh authorisation. Second, the deemed export rule extends controls to transfers of technology to foreign nationals inside the United States – a point of particular relevance for software developers with international workforces. Third, BIS's Entity List operates independently of OFAC sanctions: a counterparty may be on the Entity List without being a Specially Designated National (SDN, a person or entity on OFAC's list of blocked parties) and vice versa. Both lists must be checked.

What does this mean for a company with a UK affiliate that receives US-origin encryption software and distributes it onward? The FDPR may mean that subsequent transfers from the UK affiliate trigger a US licence requirement even though no US person is involved in the second transfer. ECJU controls apply independently, but the FDPR exposure is a US-law obligation that the UK entity must observe.

How does the UK regime approach encryption export controls differently?

Under the UK Export Control Order, encryption items are controlled as dual-use goods and assessed against the UK Strategic Export Control Lists. ECJU administers the licensing function and issues both open individual export licences (standing authorisations for defined exporters, destinations, and items) and standard individual export licences (specific licences for individual transactions). The UK lists broadly mirror the categories derived from Wassenaar, but the UK's independent implementation has produced differences in scope, conditions, and the treatment of software updates and technical assistance.

A practical divergence concerns technical assistance and brokering. The UK Export Control Order extends controls not only to the physical or electronic transfer of encryption items but also to the provision of technical assistance and, in some circumstances, to brokering activities. A UK-based engineer providing remote support to configure an encrypted communications system in a third country may be providing controlled technical assistance, even if no item physically crosses a border. This extension does not have a precise equivalent in the EAR's treatment of encryption, creating a gap that a business moving encryption technology between the US and UK may not have mapped.

OFSI's role in encryption transactions is distinct but intersecting. OFSI administers financial-sanctions asset-freeze measures under SAMLA. If a counterparty in an encryption export transaction is a designated person under UK financial-sanctions regulations, the payment leg of the transaction will be blocked regardless of whether ECJU has issued a licence for the export. In our experience, export-control teams and financial-sanctions teams within the same firm often operate in silos – and the interaction between an ECJU licence and an OFSI freeze is the exact junction at which transactions stall unexpectedly.

The position above covers the standard case. Your facts – the counterparty, the technology, the destination, the payment route, and the regime in play – change the analysis materially.

For an assessment of your encryption export exposure under the US and UK regimes, contact Calder & Vance at info@caldervance.com.

Where does the EU dual-use regime add a third layer?

For businesses with EU operations or EU-based distributors, the EU dual-use regulation – a directly applicable Council regulation governing dual-use items including encryption technology – adds a further layer of obligations that neither the EAR nor the UK Export Control Order satisfies. The EU regime operates on a similar Wassenaar-derived classification structure but is enforced by member-state competent authorities and applies EU-wide to exporters established in EU member states.

One operationally important feature of the EU regime is the distinction between software supplied in the form of a tangible medium and software transmitted electronically. The EU regulation contains its own carve-outs for publicly available and basic scientific research encryption, but those carve-outs do not automatically correspond to the US mass-market exception or the UK equivalent. A product that qualifies for a BIS licence exception may still require an EU export authorisation from the relevant member-state authority.

Cross-regime alignment does not occur by default. A business supplying encryption technology from a US entity to an EU subsidiary and then onward to customers in third markets must separately satisfy: BIS classification and any applicable licence exception or licence requirement; ECJU controls if the UK entity is in the distribution chain; and the applicable EU member-state licensing authority for exports from EU territory. The addition of OFAC sanctions, OFSI financial sanctions, and any UN Security Council-mandated controls on the end-user adds further layers that sit alongside – not inside – the export-control analysis.

What are the critical risk flags that businesses routinely miss?

In a recent matter, a technology business distributing encrypted enterprise software across multiple markets had structured its compliance programme around BIS classification alone. When we mapped the full transaction flow, we identified that a UK entity in the group was issuing sub-licences that constituted separate controlled transfers under the UK Export Control Order, that several end-users were in jurisdictions subject to heightened scrutiny under both OFAC country-programme rules and OFSI designations, and that the payment channels ran through correspondent banks whose own sanctions-screening policies imposed additional restrictions. None of these exposures was visible from the BIS classification alone.

The risk flags we most consistently identify in encryption export transactions are as follows.

  • Re-export chains: encryption items transferred to a distributor in a third country and then sold onward without a fresh authorisation analysis. The EAR re-export obligation applies; so may the UK and EU equivalents.
  • Deemed-export exposure: encryption source code or technology shared with foreign-national employees or contractors without a deemed-export analysis under the EAR. This applies regardless of where the individual is located.
  • Software-update flows: automatic updates to deployed encryption software may constitute separate controlled transfers. Licensing that covers the initial deployment may not cover updates of increased capability.
  • Technical assistance: engineers and support staff providing configuration or troubleshooting assistance to end-users in controlled destinations may be performing acts that require a licence under UK and EU controls even if the original export was covered.
  • OFSI / OFAC divergence on the same counterparty: a counterparty may be designated under UK financial-sanctions regulations but not under OFAC, or vice versa. Screening only one list creates a gap. Both SDN and OFSI designations must be checked, as must the UN Consolidated List.
  • The 50 percent rule across regimes: the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in aggregate by blocked persons as themselves blocked) applies to the financial-sanctions analysis. The UK ownership-and-control test for OFSI designations is similar but not identical. A counterparty that passes one test may fail the other.
  • Intra-group technology transfers: transfers of encryption technology between entities in the same corporate group that cross borders are controlled transfers under the EAR and may require separate UK and EU authorisation. Internal transfers are not exempt by reason of group membership alone.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.

How do the ownership and control tests compare across the US, UK, and EU regimes?

The ownership and control tests for blocked and designated persons operate differently across the three regimes, and encryption transactions sit at their intersection. Under OFAC, the 50 percent rule applies a mechanical aggregate-ownership threshold: any entity owned 50 percent or more in the aggregate by one or more SDN-listed persons is treated as itself blocked, regardless of whether it is separately named on the SDN List. The test does not turn on control; ownership alone is determinative above the threshold.

Under OFSI, the test for whether a non-designated entity is caught by UK financial-sanctions obligations is framed in terms of both ownership and control. An entity held or controlled by a designated person is treated as caught, and control can be established by facts short of majority ownership – through board composition, veto rights, contractual dominance, or other means by which a designated person can direct the entity's affairs. This means the UK test can catch structures that fall outside OFAC's 50 percent threshold.

The EU position, under the relevant Council regulation, uses a similar ownership-and-control standard. Entities owned or controlled by designated persons are treated as caught. Member-state authorities and the EU General Court have in practice applied the control limb broadly, and annulment proceedings before the General Court have tested the limits of that application. The practical implication for an encryption transaction is that a counterparty with a minority designated shareholder who exercises de facto control over decision-making may be caught under UK and EU rules but not under OFAC – or vice versa at the opposite end of the ownership scale.

We regularly advise compliance teams on exactly this divergence. Running only one regime's ownership test and treating the result as determinative for all three regimes is one of the most common structural errors in cross-border due diligence.

A common misconception: does an EAR licence exception cover the UK and EU legs automatically?

Many businesses, including experienced exporters, proceed on the assumption that a BIS licence exception for an encryption item covers the transaction end-to-end. It does not. A BIS licence exception is a US-law authorisation for the export from US jurisdiction under US legal authority. It neither creates nor satisfies any obligation under the UK Export Control Order, ECJU licensing conditions, EU dual-use regulation, OFSI financial sanctions, or OFAC country-programme restrictions.

This misconception is understandable. The Wassenaar-derived classification categories are similar across regimes, and a product that qualifies for a low-restriction classification under the EAR will often carry a corresponding classification under the UK and EU lists. But classification determines whether a control applies; it does not determine whether an authorisation has been obtained. A UK-established exporter must hold a valid UK licence or fall within a UK exception, regardless of what BIS has authorised.

A second misconception is that OFSI is primarily a financial-institution concern. In fact, OFSI's asset-freeze obligations apply to all persons in the UK and all UK persons wherever located. An encryption transaction in which a UK entity provides software or technical services to a counterparty subject to an OFSI designation is a potential breach of OFSI financial-sanctions rules, irrespective of whether an ECJU licence covers the export of the item itself. The two obligations are parallel, not hierarchical.

Where two regimes impose controls on the same transaction, the stricter prohibition governs. A transaction that is permitted under the EAR but prohibited under OFSI cannot proceed until the OFSI position is resolved.

When should a business involve specialist counsel?

Specialist counsel should be involved at four identifiable points in an encryption export transaction or programme. Each point represents a juncture at which the cost of early advice is materially lower than the cost of correction after the fact.

The first point is product classification. Determining the correct ECCN for an encryption item – including the applicability of the mass-market criteria and the conditions of any relevant licence exception – requires an analysis of the item's cryptographic specifications against the current CCL. Where the item involves multiple cryptographic functions or is supplied as a component within a larger system, the classification question is not straightforward. A mis-classification that underestimates the control level is the source of most encryption export-control violations we see in practice.

The second point is the design of a distribution or sub-licensing structure. Any arrangement under which encryption technology is transferred to a distributor who then transfers it onward to end-users creates a chain of controlled transfers. The structure should be designed so that each link in the chain has the authorisation it requires. We assist by classifying the item, confirming licence requirements and exceptions, and designing the end-use controls that the distribution agreement should reflect.

The third point is due diligence on a new counterparty or acquisition target that holds or distributes encryption technology. Encryption items acquired in an M&A transaction carry their export-control history with them. An acquirer who inherits a distribution structure that was not correctly licensed under one or more regimes inherits the associated compliance exposure. We screen the counterparty and ownership chain, surface secondary-sanctions risk, and structure the transaction to address the exposure identified.

The fourth point is the identification of a potential violation or a regulator's enquiry. Where a business has identified that past transfers may not have been covered by the required authorisation, the question of whether and how to make a voluntary self-disclosure (VSD, a proactive disclosure of a potential violation to a regulator) is time-sensitive. We scope the apparent violation, advise on VSD, and prepare the penalty defence. Early action consistently produces better outcomes than delayed disclosure.

Related practices

Frequently asked questions on encryption export controls

Where do the regimes diverge on encryption export controls?

The principal divergence points are: the conditions for a licence exception (the US mass-market criteria do not map precisely onto UK and EU equivalents); the treatment of technical assistance (the UK and EU controls extend to this more explicitly than the EAR's encryption provisions); the extraterritorial reach of the EAR through the foreign direct product rule; and the interaction of OFSI financial-sanctions asset-freeze obligations with ECJU export-licensing requirements, which are separate obligations that a transaction must satisfy independently. Where the two regimes produce different conclusions on the same transaction, the stricter obligation governs.

Which regime is stricter on encryption export controls?

There is no single answer. The US EAR has the broader extraterritorial reach through the foreign direct product rule and the de minimis rule, meaning that US-origin encryption technology embedded in a foreign product can trigger a US licence requirement even for transfers in which no US person participates. The UK and EU regimes, however, impose explicit controls on technical assistance and brokering that can catch activities not covered by the EAR's encryption controls. The practical answer is that a business operating across both regimes cannot rely on clearing only one of them.

What should a cross-border business do about encryption export controls?

Three immediate steps are worthwhile regardless of how mature the existing programme is. First, confirm that every encryption product in the portfolio has a current, documented classification under each applicable regime – not just BIS. Second, map every point in the distribution chain at which a transfer of the product or related technology occurs and confirm that each transfer has the authorisation it requires. Third, run counterparty screening against both OFAC and OFSI designations and the UN Consolidated List, not just one of them. Where those steps surface a gap, involve counsel before completing the next transfer.


About the author

J. M. Aldridge advises multinationals and financial institutions on US sanctions and export controls, with a focus on OFAC licensing, secondary-sanctions risk, and BIS classification. Calder & Vance – International Sanctions & Export Control Counsel.

Published: 15 April 2026


About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.