Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

OFSI vs EU: Encryption export controls: the key divergences

A software company based in London ships end-to-end encrypted messaging applications to enterprise customers across the European Union, the Gulf, and South-East Asia. Its legal team has always classified the product under the EU dual-use regime. Post-Brexit, that single classification is no longer sufficient. The UK now operates its own export-control regime, and encryption technology sits at the intersection of both systems – with rules that have quietly diverged in ways that matter at the point of export.

Encryption export controls under the UK regime (administered by the Export Control Joint Unit, or ECJU) and the EU dual-use regime (governed by the relevant Council Regulation on dual-use items) share a common ancestry but have moved apart since the UK's exit from the EU. As of April 2026, the two systems differ in classification methodology, licence exception scope, cryptography-specific carve-outs, and the documentation standards that regulators apply at the enforcement stage. Neither regime should be read across to the other without a fresh analysis of the item, the destination, and the end-user.

This analysis sets out the governing authorities, maps the principal divergences criterion by criterion, identifies the risk flags for cross-border businesses, and explains when a practitioner review is necessary.

What governs encryption export controls in the UK and the EU?

In the UK, encryption items are controlled under the Export Control Order and the UK Strategic Export Control Lists, which the Department for Business and Trade maintains and the ECJU administers. The UK lists were derived from the EU lists at the point of exit but have since been amended independently. The legal basis sits in primary legislation governing strategic export controls, supplemented by ECJU guidance notes, Open General Export Licences (OGELs – standing authorisations that permit a defined category of exports without a case-by-case application), and standard individual export licences (SIELs).

In the EU, the equivalent instrument is the relevant Council Regulation on controls for dual-use items and technology. The regulation is directly applicable across member states, though national competent authorities administer licence applications in their own jurisdiction. Encryption items appear on the EU Common Military List and the EU dual-use control list; the latter incorporates the Wassenaar Arrangement control entries for cryptographic items, as both regimes do.

A shared Wassenaar baseline creates a surface impression of alignment. That impression is misleading. Each regime has incorporated the Wassenaar entries into its own domestic instrument, interpreted them through its own administrative guidance, and built a distinct set of exceptions and licensing routes around them. The divergence is real and has practical consequences for any exporter operating on both sides of the Channel.

How does classification of encryption items differ between the two regimes?

Classification is the first point of divergence, and it is where most cross-border exporters encounter difficulty. Both regimes use an Export Control Classification Number – referred to under the UK lists as a UK Export Control Classification, and under the EU lists as an ECCN-equivalent dual-use category entry – to determine whether an item is controlled. The entries for cryptographic items track the Wassenaar categories, covering hardware, software, and technology capable of cryptographic functions exceeding defined parameters.

Since exit, the UK has updated its lists on a different timetable from the EU. Where the EU has incorporated a Wassenaar amendment in one annual cycle, the UK may have incorporated the same amendment in a subsequent cycle, or drafted it with different implementing language. The result is a classification gap: an item may fall under one entry in the EU list and a slightly different entry – or no entry at all – under the UK list at any given point.

We regularly advise exporters who have classified an item correctly under the EU system, only to discover on a UK review that the UK entry carries a different scope or that an exception available under the EU instrument is not replicated in the current UK version of the list. The gap is not always in the UK's favour. In some instances the UK entry is narrower than the EU equivalent, creating an export that is controlled in the EU but not in the UK. In others, the reverse applies.

Practical implication: a business should maintain a parallel classification record for each encryption item – one under the UK Strategic Export Control Lists and one under the EU dual-use list. These should be reviewed each time either regime updates its lists and each time the item is materially modified.

Where do the regimes diverge on encryption export controls?

The divergences are most acute in five areas: licence exceptions for mass-market items, the treatment of intangible transfers of technology, end-use and end-user verification requirements, record-keeping obligations, and the enforcement posture of the respective authorities.

Mass-market exceptions. Both regimes contain exceptions for encryption items that are widely available to the public and offer no significant advantage over commercially available technology. However, the criteria used to determine whether an item qualifies differ. The EU instrument sets out a set of cumulative conditions; the UK instrument applies criteria that have, since exit, been updated independently. The parameters are similar but not identical, and a product that clearly meets the EU mass-market exception may sit in a grey area under the UK version – or vice versa.

Intangible transfers. The EU regulation contains provisions that address the transmission of controlled dual-use technology by electronic means, including software downloads, cloud services, and remote access to encryption tools. The UK instrument also controls intangible transfers, but the scope and the applicable exceptions differ, particularly for technology transferred to EU-based recipients by a UK exporter. Post-Brexit, a UK company providing remote access to an encryption tool to a French subsidiary must now consider whether that transfer requires a UK export authorisation, a question that did not arise before exit.

End-use and end-user controls. Both regimes impose obligations on the exporter to verify the end-use and end-user of controlled encryption items. The EU regulation includes a catch-all provision (a requirement that exporters consider whether an item not formally on the control list may be intended for a use that warrants controls), and this provision has been interpreted actively by some EU national competent authorities. The UK has a comparable provision under its regime, but ECJU's published guidance on its application to encryption technology has not always kept pace with EU guidance from the more active national authorities. In practice, an exporter subject to both regimes must apply the stricter of the two analyses – a point we return to below.

Record-keeping. Both regimes require exporters to maintain records of their controlled exports. Under the UK system, the standard obligation is to retain records for a defined period; ECJU guidance specifies the categories of document that must be kept. The EU instrument imposes a similar obligation administered at member-state level, meaning the precise retention period and documentation standard can vary by jurisdiction within the EU. A business exporting from both the UK and an EU member state must comply with both sets of obligations simultaneously and cannot collapse them into a single record-keeping policy without careful design.

Enforcement posture. ECJU's enforcement posture, and the criminal and civil consequences of a breach, differ from those available under EU member-state law. The EU regulation leaves enforcement to national authorities, and enforcement activity and penalty scales vary materially across member states. A cross-border exporter must assess the enforcement risk in each jurisdiction where it operates, not merely at the point of export.

Which regime is stricter on encryption export controls?

There is no single answer: the stricter regime depends on the specific item, the destination, the end-user, and the exception in question. Where the two regimes apply simultaneously – as they do for a UK exporter supplying to EU counterparties, or an EU-based entity with a UK subsidiary conducting its own exports – the operative principle is that the stricter prohibition governs each leg of the transaction independently.

In our cross-border practice, we see businesses make two characteristic errors. The first is to assume that the EU system is always stricter because it is more extensively documented and has a larger body of guidance. The second is to assume that the UK system is simpler and therefore more permissive. Neither assumption is reliable.

Consider a concrete example. A UK-based developer of encryption software for financial-messaging platforms receives an order from a buyer in a jurisdiction that neither the UK nor the EU has designated as a prohibited destination for encryption technology of this type. The UK OGEL for dual-use items permits the export under defined conditions. The EU instrument, as applied by the competent authority of the member state through which part of the delivery chain passes, may impose additional end-user undertaking requirements that the UK OGEL does not require. The exporter needs both a UK authorisation and an EU authorisation, and the conditions attached to each may differ.

The reverse scenario arises where an EU derogation or exception for a category of encryption software has been extended by the European Commission's implementing guidance in a way that the UK has not replicated. In that situation, the UK regime is the binding constraint, even though it is perceived as the less elaborate of the two systems.

Practical rule: map each export transaction against both regimes independently. Do not carry a single classification or a single exception analysis across the Channel.

How does OFSI interact with encryption export controls?

OFSI – the Office of Financial Sanctions Implementation – administers financial sanctions under the Sanctions and Anti-Money Laundering Act (SAMLA), a distinct legal instrument from the export-control regime. The two systems can interact when a counterparty in an encryption export transaction is a designated person or an entity caught by the ownership and control test (the UK test for whether a non-listed entity is caught through a listed person's holding or direction).

The intersection is relevant in two situations. First, where a buyer of encryption technology is subject to a UK financial sanction, the export-control authorisation and the financial-sanctions analysis must both be satisfied before the transaction can proceed. An ECJU licence does not override an OFSI prohibition, and vice versa. Second, where an exporter provides technical support, updates, or encryption-key management services to a customer who subsequently becomes designated, the exporter faces both an export-control question (is the continuing provision of technology a controlled transfer?) and a financial-sanctions question (does the service represent a payment or benefit to a designated person?).

OFSI operates a licensing regime under SAMLA that permits certain otherwise-prohibited transactions. Where an encryption-technology provider identifies that a customer has become designated, the appropriate response is to assess both the export-control position and the OFSI licensing position in parallel. These analyses are conducted under different legal instruments by different authorities, and the substantive tests differ. Early engagement with both sets of rules avoids the situation where a firm resolves one legal question only to find the other blocks the transaction anyway.

The position above covers the standard case. Your facts – the item, the counterparty, the destination, and the regimes in play – change the analysis materially. For a confidential review of a potential exposure, contact Calder & Vance at info@caldervance.com.

What are the principal risk flags for exporters of encryption technology?

From our practice advising exporters of encryption hardware, software, and technology, the following situations carry the highest risk of inadvertent non-compliance across the two regimes.

Post-Brexit classification drift. An exporter that classified its encryption product under the EU dual-use list before 2021 and has not revisited the UK classification since exit is exposed to the list-update gap described above. This is the single most common source of inadvertent breach in our experience. The correction is straightforward – a formal re-classification exercise under the current UK lists – but it requires time and a documented record.

Cloud-delivered encryption tools present a particular challenge. The intangible-transfer provisions of both regimes apply to remote access to encryption software, and the exceptions are not co-extensive. A UK provider making its encryption platform available to users in EU member states via a browser interface should verify the UK intangible-transfer position, the EU member-state position for each jurisdiction where users are located, and the position at each destination country where those users themselves transfer the technology.

Ownership and control reviews matter here too. Where a buyer of encryption technology is not itself listed but has a shareholder who is, the export-control analysis must address whether the export effectively benefits the listed person. Under the UK financial-sanctions regime, OFSI's ownership and control guidance is relevant. Under the export-control regime, the end-use and end-user analysis must address the same underlying risk through a different analytical lens.

Technology transfers embedded in commercial agreements are frequently overlooked. A licensing agreement that gives the counterparty access to encryption source code, design specifications, or cryptographic parameters is a transfer of technology, not merely a software delivery. Both regimes control technology transfers, and the conditions that apply to them are more demanding than those for the export of finished items.

Finally, re-export risk. Where an EU buyer of UK-origin encryption technology subsequently supplies it to a third-country customer, the UK end-use controls may apply to that re-export. The exporter should ensure that its supply agreements include appropriate re-export clauses and that it retains records sufficient to demonstrate the original end-use undertaking.

If a transaction has already been flagged, or a classification question has been raised by a regulator, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.

A common misconception: post-Brexit, UK exporters need only one set of controls

A persistent myth in the market is that a UK exporter, having left the EU system, now operates under a single, simpler set of controls and can disregard EU rules entirely. This is incorrect in three important respects.

First, a UK company with an EU-based subsidiary, branch, or distribution partner that re-exports encryption technology from an EU member state must comply with the EU regime for those exports. The nationality of the UK parent is irrelevant to the EU rules; what matters is where the export takes place and who is the exporter of record in the EU.

Second, many end-users in EU member states are themselves subject to EU dual-use rules on re-export and on intra-EU transfers of controlled technology. A UK exporter that ignores the EU position may find that its customers cannot lawfully use or transfer the technology they have received, creating commercial and contractual risk even where the UK export was perfectly lawful.

Third, secondary-sanctions risk under US rules adds a third layer. The US Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS), assert jurisdiction over encryption items with US-origin content or US-origin technology regardless of where the re-export originates. A UK-developed encryption product that incorporates US-origin cryptographic libraries or chips may carry EAR obligations in addition to UK and EU obligations. US extraterritorial reach in this area is well-established, and the consequences of a breach – including appearance on the Entity List – are severe.

The practical answer to this myth is not that UK exporters face less regulation post-Brexit. In many cases, they face more: two domestic regimes instead of one, plus the continuing reach of the US EAR for items with US-origin content.

What should a cross-border business do about encryption export controls?

The starting point is a classification exercise conducted under each applicable regime separately. For a business exporting from the UK to EU destinations, this means a formal UK classification under the current Strategic Export Control Lists and a separate EU classification under the relevant Council Regulation, in parallel. Both should be documented and reviewed each time the lists are updated or the product is modified.

The second step is an exception and licence-route analysis. Where a mass-market or similar exception is relied upon, the exporter must verify that the conditions are met under each regime independently. Reliance on an OGEL under the UK regime does not establish compliance with the EU equivalent; the conditions must be assessed separately.

The third step is end-use and end-user diligence. For encryption items above the exception threshold, both regimes require the exporter to understand who will use the technology and for what purpose. This means obtaining end-user undertakings in a form that satisfies both sets of requirements, and retaining those records for the period each regime specifies.

The fourth step is a financial-sanctions overlay. For each export destination and end-user, the exporter should run a financial-sanctions screening check against both the UK consolidated list and the EU asset-freeze lists. Where a counterparty has connections to designated persons, the OFSI licensing position and the ECJU licensing position must be assessed together.

Where the item has US-origin content, a fifth step – an EAR classification and licence-determination analysis – is required. This is not optional for items above the de minimis threshold; the EAR applies regardless of the exporter's nationality.

In a recent matter, a UK-based provider of encryption software for the financial-services sector had been operating under a single EU-era classification for several years after exit. On a routine review, we identified that the UK Strategic Export Control List had been updated in a way that narrowed the applicable exception for the product in question. The exporter was able to regularise its position by obtaining a SIEL before any enforcement question arose. The matter underlines that periodic classification reviews are not administrative housekeeping – they are a substantive compliance obligation.

Related practices

Frequently asked questions

Where do the regimes diverge on encryption export controls?
The primary divergences are in classification methodology, the scope of mass-market exceptions, intangible-transfer provisions, end-user documentation requirements, and record-keeping obligations. Because both regimes derive from the Wassenaar Arrangement but have been amended independently since Brexit, the same encryption product may be classified differently – or qualify for a different exception – under the UK Strategic Export Control Lists and the EU dual-use regulation. Neither set of rules should be assumed to replicate the other without a fresh analysis.
Which regime is stricter on encryption export controls?
There is no universal answer. Strictness depends on the specific item, destination, and exception in question. Where an EU mass-market exception has been extended through implementing guidance not yet replicated in the UK, the UK is the binding constraint. Where the UK OGEL conditions are narrower than the EU equivalent for a particular item, the UK is again the binding constraint. The operative principle is that, where both regimes apply to a transaction, the stricter provision governs that leg of the supply chain independently of the other.
What should a cross-border business do about encryption export controls?
A cross-border business should maintain a parallel classification record under each applicable regime, verify that any exception is met under each regime independently, conduct end-use and end-user due diligence to both regimes' standards, run a financial-sanctions screening overlay (OFSI and EU asset-freeze lists), and – where US-origin content is present – conduct a separate EAR analysis. These steps should be reviewed each time the relevant lists are updated or the product is modified. Where there is uncertainty, early legal advice is materially cheaper than a post-event enforcement response.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.