A technology exporter operating across the Atlantic faces a compliance question that splits along jurisdictional lines almost before the ink dries on the export paperwork. The goods are classified under the US Commerce Control List. The shipment routes through a European distribution partner. The end-customer is in a third country. Which classification governs? And if the two regimes reach different answers, which one wins?
EU dual-use classification and its US counterpart under the Export Administration Regulations (EAR – the US Department of Commerce Bureau of Industry and Security regime governing dual-use goods, software, and technology) share a common lineage in the Wassenaar Arrangement but produce materially different compliance obligations. An item may carry an Export Control Classification Number (ECCN – the alphanumeric identifier on the US Commerce Control List that determines applicable controls) yet still require a separate EU authorisation, or vice versa. As of April 2026, the divergence between these two regimes is widening, driven by unilateral additions to the US Entity List and EU-side amendments to the dual-use annexe.
This analysis sets out how classification works under each regime, where the criteria diverge in practice, what the cross-border extraterritorial dimension means for a business operating in both markets, and how to identify the moments when the misalignment creates acute enforcement risk.
How does EU dual-use classification work under the EU regime?
EU dual-use classification rests on a determination against the annexe to the relevant EU dual-use regulation, which lists controlled items by category across ten technology groups and five product categories, using a structure aligned to – but not identical with – the Wassenaar Arrangement. The classification exercise begins with a technical description of the item and proceeds to a systematic comparison against the parameters in the annexe. An item that matches a control entry is subject to authorisation requirements; an item that falls outside all control entries may still be caught by the catch-all control.
The catch-all is often where cross-border transactions become complicated. Under the EU rules, a non-listed item can still require authorisation if the exporter knows or has reason to suspect that the goods will be used for weapons of mass destruction purposes, for military end-use in an arms-embargoed destination, or in connection with certain re-export concerns. The obligation arises from the end-use information the exporter possesses, not from the technical parameters of the item itself. In our experience, exporters trained on the US classification system are often surprised to discover that an EU catch-all trigger can apply to something they would classify in the US as EAR99 – the lowest-control designation under the EAR indicating no ECCN applies.
Classification under the EU annexe is self-assessed. There is no direct equivalent to the US commodity classification request process as a mandatory first step, although exporters may request binding classification guidance from the competent national authority in their EU member state. Member-state competent authorities administer the regime; the European Commission provides guidance and oversight but does not itself issue licences. This distributed architecture means that an exporter in Germany and one in the Netherlands may, in practice, receive modestly different interpretations of the same annexe entry, although the legal text is uniform across the bloc.
How does the US EAR classification process differ?
Under the EAR, every item subject to US jurisdiction receives a classification – either a specific ECCN or a residual EAR99 designation – and the classification drives the licence requirement determination by reference to the Commerce Country Chart. The process runs: identify the ECCN, consult the Country Chart, determine whether any licence exceptions apply, and then assess entity-level restrictions through the Entity List, Denied Persons List, and Unverified List.
The US system places greater emphasis on formal classification tools. An exporter may submit a commodity classification request to BIS and receive a formal determination. Where the result is an ECCN, the control reasons – Anti-Terrorism (AT), National Security (NS), Regional Stability (RS), Crime Control (CC), and others – determine which country destinations trigger a licence requirement. The EU system uses destination and end-use as the primary variables; the US system uses destination, end-use, and control reason simultaneously.
What generates significant cross-border complexity is the de minimis rule and the foreign-direct product rule (FDPR – the US rule that extends EAR jurisdiction to certain foreign-made items incorporating controlled US technology or produced on US-origin equipment). An EU-origin item that contains controlled US-origin content above the de minimis threshold, or that is produced using US-origin technology, can be subject to EAR jurisdiction independently of its EU classification status. This means a product classified as controlled under the EU annexe may also carry EAR obligations that the EU classification exercise does not resolve and does not displace.
Have you mapped the US-origin content of your EU-classified product, or relied solely on the EU annexe determination? The two questions are legally distinct, and both require an answer before export.
Where do the classification criteria diverge most sharply?
The most significant divergences arise in three areas: the treatment of software and technology, the entity-based controls layer, and the scope of the catch-all.
On software and technology, the EAR extends jurisdiction to technology deemed exports – that is, the release of controlled technology to a foreign national within the United States is treated as an export to that person's home country. The EU dual-use regime has no direct equivalent to deemed export as a formal category, though member-state rules and the catch-all can produce comparable outcomes in specific fact patterns. For a business with mixed US and EU national employees accessing controlled technology in a research setting, this divergence creates a compliance gap that is easy to overlook.
On entity-based controls, the US Entity List operates as a licence requirement trigger that is entirely separate from ECCN-based classification. An entity on the Entity List requires a licence for most items, including many that would otherwise be EAR99. The EU has its own list of persons and entities subject to trade restrictions, but the architecture is different: EU restrictions tend to be embedded in thematic sanction regulations rather than in a single consolidated export-control list with its own licence-requirement overlay. A counterparty that triggers the EAR Entity List requirement may or may not be subject to equivalent EU-side restrictions, depending on the applicable sanction programme and the goods involved.
On the catch-all, the EU rule is arguably broader in its end-use framing. In our cross-border practice, we regularly advise on situations where an item with no EU annexe entry and an EAR99 designation nonetheless requires EU authorisation because the exporter has received information about a military end-use by an embargoed destination. The US catch-all under the EAR operates on similar end-use principles but with somewhat different triggers and thresholds. Where both catch-alls apply simultaneously, the stricter prohibition governs – and identifying which is stricter requires a fact-specific analysis of the end-use information in hand.
What is the extraterritorial reach of each regime and how do they interact?
The FDPR extends EAR jurisdiction to non-US items that meet certain criteria related to US-origin content or US-origin production technology. This extraterritorial reach means that an EU exporter shipping an EU-origin product may nonetheless require a BIS licence if the FDPR applies. The EU has no comparable outbound extraterritorial reach: EU controls apply to EU-origin exports and, in certain circumstances, to transfers within the EU and to EU persons, but they do not follow the product into the supply chain of a third-country manufacturer in the way the FDPR does.
For a business that manufactures in the EU, sells into the US supply chain, and re-exports from there, this asymmetry is operationally significant. The EU classification exercise does not answer the FDPR question. Conversely, completing the EAR analysis does not substitute for the EU authorisation process. Both must be run independently, and neither result displaces the other.
OFAC adds a further layer. Even if an item is EAR99 and has no EU annexe match, OFAC's programme-based prohibitions may block the transaction entirely if the end-counterparty is a Specially Designated National (SDN – a person or entity on OFAC's SDN List, with whom US persons and, under certain programmes, non-US persons are prohibited from transacting) or if the destination is subject to comprehensive sanctions. OFAC prohibitions operate independently of export-control classification: a cleared classification does not authorise a prohibited transaction.
In our experience, the most common error in cross-border OFAC and EU export-control matters is treating classification and sanctions screening as sequential rather than parallel tasks. They should run concurrently, because a failed screen can halt a cleared classification and a failed classification can block a clean-screened deal.
The position above covers the interaction at the level of general principle. Your specific facts – the goods, the route, the customer, the origin of the technology – change the analysis materially. For an assessment of your exposure under both regimes, contact Calder & Vance at info@caldervance.com.
Which regime is stricter on EU dual-use classification?
Neither regime is categorically stricter: the answer depends on the item, the destination, and the end-use, and the two regimes operate from different starting points. On specific technology categories – particularly advanced semiconductors, telecommunications equipment, and certain encryption products – US controls have in recent periods moved more rapidly, with Entity List designations and expanded FDPR rules producing effective prohibitions before equivalent EU-side measures are in place. On other items, the EU catch-all has produced authorisation requirements where EAR99 designation would indicate no US licence is needed.
The practical implication is that a cross-border business must run both classification exercises, cannot assume that the stricter result from one regime satisfies the other, and must maintain separate authorisation records for each regime. Where the two regimes diverge – for instance, where a US licence exception permits the export but an EU authorisation is still required – the exporter must comply with both, not elect between them.
A useful frame: the EU classification determination tells you whether the EU authorisation requirement is triggered. The EAR ECCN tells you whether the US licence requirement is triggered. The Entity List and the Denied Persons List tell you whether entity-level restrictions apply independently of classification. OFAC tells you whether the transaction is prohibited regardless of classification or authorisation. All four checks are mandatory; none is a proxy for the others.
Risk flags and common classification errors in cross-border practice
The misclassification patterns we encounter most frequently in practice fall into identifiable categories. Awareness of these patterns allows a compliance team to build targeted controls around the highest-risk points in the classification workflow.
The first risk area is technology transfer by means other than physical export. Transmitting controlled technology by email, cloud upload, or verbal disclosure at a conference is subject to both EAR and EU controls. Businesses that have robust physical-shipment controls sometimes have no equivalent process for technology transfers, including source code sharing with development teams in third countries.
The second risk area is classification drift over time. An item classified correctly at product launch may lose its original classification status when the annexe or the CCL is amended, or when the product is modified. In our experience, a product re-classification review at the point of any technical modification is the minimum adequate standard. Periodic reviews of the full product portfolio are also warranted.
The third risk area is reliance on a supplier's classification. A supplier-provided ECCN is an input to the exporter's analysis, not a substitute for it. The exporter bears the compliance obligation and cannot delegate it by contract. Where a supplier's classification is incorrect, the exporter's exposure is not eliminated by having relied on it, particularly where a reasonable classification check would have identified the error.
The fourth risk area is the consignee and end-use certificates. Both the EAR and the EU rules require the exporter to gather and retain end-use and end-user information in specified circumstances. Where that information indicates a controlled end-use, the catch-all may apply even to an otherwise uncontrolled item. Certification processes that are nominal – forms collected and filed without review – do not satisfy the substantive obligation.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Reach the Calder & Vance team at info@caldervance.com.
A common myth: clearing one regime clears both
A persistent misconception in cross-border export-control practice is that securing authorisation under one regime – say, a US licence from BIS – satisfies the equivalent EU requirement for the same shipment. This is incorrect. US and EU authorisations are issued by different legal authorities under different legislative instruments; each is regime-specific and neither is recognised as a substitute by the other.
The same logic applies in the reverse direction. An EU general trade authorisation does not authorise an export that requires a BIS licence. And neither a BIS licence nor an EU authorisation addresses the OFAC prohibition where one applies. In a transaction involving a US-origin item, an EU exporter, and an end-customer in a third country, up to three independent checks – BIS, EU, OFAC – may all be required, and clearing two of them does not satisfy the third.
In our practice, we regularly advise multinational procurement and compliance teams that have structured their authorisation processes around a single regime, typically the one they encountered first or the one that triggered the most visible internal alert. Rebuilding the process to run all applicable regime checks in parallel is not operationally complex, but it requires deliberate design and clear ownership.
For a practical review of your export-control classification and authorisation process across both regimes, contact Calder & Vance at info@caldervance.com.
Related practices
- Deemed Export – Technology and BIS/EAR – US deemed-export controls, technology release, and EAR licence assessment for cross-border businesses.
- OFAC vs OFSI: EU dual-use classification compared – analysis of how US and UK export controls and sanctions interact on dual-use items.
- OFSI vs EU: EU dual-use classification compared – practitioner comparison of UK and EU export-control regimes on dual-use classification and authorisation.