Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · EU

EU vs SECO: Licence-exception eligibility: the key divergences

A Swiss group exporting dual-use components to a research institute in a third country assumes the transaction is straightforward. The items clear Swiss Federal Council controls under a SECO general authorisation. Then the group's EU subsidiary is drawn into the supply chain. The EU parent holds the export licence file. Suddenly, two separate regimes govern the same shipment – and the eligibility conditions for each regime's licence exceptions diverge in ways the compliance team did not anticipate.

Licence-exception eligibility under the EU dual-use rules and Switzerland's SECO regime share a common origin in international control arrangements, but they diverge materially on scope, end-user certification requirements, and the treatment of intangible transfers. As of April 2026, both regimes have been updated following amendments to the control lists, and exporters operating across both jurisdictions must assess each shipment against each regime's conditions independently. A clearance under one does not guarantee clearance under the other.

This analysis maps the key divergences criterion by criterion, identifies the practical risk points for exporters managing dual EU-SECO exposure, and sets out when specialist export-control counsel should be engaged before shipment.

The legal authority behind each regime

The EU's dual-use export-control regime is grounded in a directly applicable EU regulation covering the export, brokering, transit, and transfer of dual-use items – including software and technology – across EU external borders. The regulation establishes a tiered structure: items on the EU control list require an individual, global, or general export authorisation; items not on the list may still require a licence under a catch-all clause if the exporter has reason to believe they will contribute to weapons proliferation. The regime is administered by the competent authority of the relevant EU member state – typically a national export-control licensing body – with the European Commission providing coordination guidance but not issuing individual licences.

Switzerland's regime operates through SECO – the State Secretariat for Economic Affairs – under the Goods Control Act and its associated ordinances. SECO maintains its own control list, aligned closely but not identically to the EU list. It issues individual and general authorisations, administers catch-all powers, and has independent enforcement authority. Switzerland is not an EU member and is not bound by the EU regulation; it participates in the Wassenaar Arrangement, the Nuclear Suppliers Group, and the Australia Group, which gives both regimes common reference points, but the implementing rules differ.

The fundamental point for a cross-border exporter is that the EU and Switzerland are two separate legal orders. A general authorisation under SECO does not substitute for an EU general export authorisation. An EU member-state individual licence does not satisfy SECO filing requirements. The regimes must be satisfied independently, and the conditions for licence exceptions under each are not interchangeable.

How does the EU define licence-exception eligibility for dual-use items?

The EU regulation provides several categories of general export authorisation – commonly called EU general export authorisations or EUGEAs – that function as standing licence exceptions for defined categories of transaction without a separate individual application. Eligibility for these authorisations turns on four principal factors: the nature and classification of the item, the destination country or territory, the end-use, and the end-user category.

On item classification, the EUGEAs are each tied to specific entries in the EU control list. An exporter must first confirm that the item is controlled – and at what level – before determining which EUGEA, if any, applies. Items not on the list may still be subject to catch-all controls if the exporter has received a notification from the competent authority, or has actual knowledge of a proliferation risk.

Destination is the next filter. Each EUGEA specifies the countries to which it applies. Some are limited to close allied jurisdictions. Others cover a broader range of low-risk destinations. Exports to certain destinations are explicitly excluded from all EUGEAs and require an individual licence regardless of item classification. In our practice, destination analysis is the single most common point of miscalculation: exporters assume an item is EUGEA-eligible without checking whether the destination country appears on the permitted list for the specific authorisation in question.

End-use certification is required under certain EUGEAs for identified categories of items or destinations. The exporter must obtain a written statement from the consignee confirming the intended use and confirming that the goods will not be re-exported to a restricted destination without authorisation. The format and content of this certification varies by authorisation category. Where catch-all exposure exists, a general assurance is insufficient; the certification must address the specific proliferation concern on the exporter's file.

Intangible transfers – software transmitted electronically, technology provided by email or training – are within scope of the EU regime. A general export authorisation that covers a physical shipment may or may not cover the related technology transfer. Many exporters treat the shipment authorisation as covering the whole transaction. It does not, unless the EUGEA specifically includes intangible transfers. This gap is a recurring compliance deficiency that we encounter when reviewing EU export-control programmes.

Where does SECO's eligibility test differ most sharply?

SECO's general authorisations cover broadly similar territory to the EU model but diverge on several points that matter to an exporter managing both regimes simultaneously.

First, the SECO control list, while aligned to the same international arrangements as the EU list, is not identical. Items may be listed at different control list entries, or may appear on one list but not the other. An exporter cannot assume that an item classified under the EU list maps directly to the same entry under the SECO list. Independent classification analysis is required for each regime. This doubles the classification burden and creates a risk of silent misclassification where an exporter performs one classification and assumes it covers both.

Second, SECO's general authorisations do not mirror the EUGEA structure precisely. The permitted destinations under a SECO general authorisation may differ from those under the closest EU equivalent. A destination that is eligible under a EUGEA may require an individual SECO authorisation, or may be ineligible under SECO's general authorisation framework altogether. Conversely, a destination excluded from all EUGEAs may fall within a SECO general authorisation's scope. The mapping is not one-to-one.

Third, the end-user certification requirements under SECO can differ in form. SECO may require an import certificate issued by the competent authority of the destination country, whereas the corresponding EU authorisation requires only a consignee end-user undertaking. For some categories of goods, SECO requires a delivery verification certificate after shipment. These post-shipment requirements have no exact parallel under the EU EUGEAs, which generally do not impose post-export confirmation obligations on the exporter beyond record-keeping.

Fourth, on intangible transfers, SECO has developed its own guidance on when a knowledge transfer, a training event, or a cloud-based software service constitutes a controlled export. The scope of SECO's intangible-transfer controls does not track the EU position exactly. In our experience, businesses that have mapped their EU intangible-transfer exposure carefully sometimes find unexpected additional obligations when they analyse the same transaction under SECO rules.

The sharpest single point of divergence in practice is the post-shipment verification requirement. An exporter accustomed to the EU's record-keeping and registration model – where the obligation is to document and retain – faces an additional affirmative obligation under SECO to obtain and file delivery confirmation for certain goods. Missing this obligation is an enforcement risk under the Swiss regime even where the EU side of the transaction is fully compliant.

What are the practical risk flags for dual-regime exporters?

For a business operating under both regimes, five risk patterns arise with regularity in cross-border dual-use transactions.

Silent re-export risk. A SECO-authorised shipment from Switzerland reaches a distribution hub in an EU member state. The EU subsidiary then onward-exports to the final customer. The EU leg is a separate export requiring its own EU authorisation. If the subsidiary is relying on an assumed licence exception, the assumption must be tested against EU eligibility conditions, not SECO's. The Swiss authorisation has no legal relevance to the EU leg of the transaction.

Technology release without an individual licence. An engineer in Switzerland demonstrates controlled software to a customer's technical team by video conference. The call is partly attended from locations outside both Switzerland and the EU. SECO controls on intangible transfer may be triggered by the Swiss engineer's participation. The EU may or may not have jurisdiction depending on where the EU-connected participants are located and in what capacity. Neither regime's general authorisation automatically covers an informal technology release of this kind.

Catch-all notice under one regime but not the other. A competent authority in an EU member state notifies an exporter that a specific transaction to a named destination requires an individual licence notwithstanding the item's classification. That notification is specific to the EU regime. SECO has no knowledge of it and no obligation to apply the same restriction. An exporter who then proceeds on the SECO side, relying on general authorisation, may be compliant with Swiss law but in a position that carries reputational and relationship risk if the EU competent authority later enquires.

Control list version lag. Both the EU and SECO update their control lists periodically following changes to the international arrangements. The timing of implementation is not always synchronised. An item may be added to the EU list before the corresponding SECO update takes effect. An exporter relying on a classification conducted before an EU update may be shipping without realising that an EU licence is now required. In our practice we recommend periodic re-classification reviews timed to known list update cycles.

Record-keeping divergence. EU rules impose a specific minimum record-keeping period for export-control documentation. SECO imposes its own period, which may differ. Where a group maintains a single compliance file, the file must satisfy the stricter of the two obligations. The file must also demonstrate, for each transaction, which regime's authorisation was used and why eligibility was satisfied under that regime – not simply that a clearance existed.

The position above covers the standard case. Your facts – the item, the destination, the end-user, the transfer route, and the timing of the shipment – change the analysis materially. If any of these five patterns appears in a proposed transaction, a pre-shipment review is warranted before relying on a general authorisation.

For a comparison of OFAC and BIS/EAR licence-exception eligibility, read our dedicated analysis.

How does the cross-regime interaction create compound exposure?

The EU and SECO regimes interact not only at the level of individual transactions but also at the level of a group compliance programme. A Swiss parent with EU subsidiaries faces a matrix of obligations: each entity must satisfy the rules of its own jurisdiction, and group-level technology sharing, intra-group transfers, and joint customer service arrangements may themselves constitute controlled exports under one or both regimes.

Intra-group transfers of controlled technology from a Swiss entity to an EU entity – or vice versa – are subject to licensing requirements in the same way as third-party transactions. The EU regime does not provide a blanket intra-group exception. SECO similarly treats intra-group technology transfers as subject to control where the items are on the relevant control list. A parent providing technical support to a subsidiary, or a subsidiary uploading controlled software to a group server hosted in a different jurisdiction, may require a licence that the group has not obtained.

The extraterritorial reach of certain EU controls adds a further dimension. The EU regulation includes provisions that can apply to EU persons acting outside the EU, and to non-EU persons who are subsidiaries of EU-based groups, depending on the facts. The interaction between these provisions and SECO's territorial scope is not always straightforward. A Swiss group that is majority-owned by an EU parent may need to consider whether the EU parent's export-control obligations have any bearing on the Swiss entity's transactions.

In a recent matter, a life-sciences group with manufacturing in Switzerland and commercial operations across several EU member states identified a gap in its intra-group technology-transfer controls. The group had managed EU and SECO authorisations separately at entity level, but had not licensed the controlled software updates passing between its Swiss R&D unit and its EU distribution entities. We mapped the controlled items across both regimes, identified the licence requirements for each intra-group transfer route, and assisted in restructuring the group's technology-sharing arrangements to bring them within an authorised model. The matter underscored that group-level compliance design requires analysis at regime level, not entity level alone.

If a transaction or a group arrangement has already been flagged by a competent authority, or if a self-review has identified a pattern of unlicensed transfers, an early and structured assessment can preserve remediation options that narrow with time. For a confidential review of potential compliance gaps across EU and SECO obligations, contact Calder & Vance at info@caldervance.com.

When do EU and SECO eligibility conditions run parallel – and when do they genuinely conflict?

It would be misleading to present the two regimes as wholly incompatible. For many low-sensitivity, widely traded dual-use items destined for allied-country counterparties, both regimes will be satisfied by equivalent general authorisations, and the practical compliance burden is largely one of parallel registration and record-keeping. The divergence becomes material in five categories of transaction.

First, transactions involving items in higher-sensitivity control list categories – particularly those with nuclear, biological, chemical, or missile-related applications – where both regimes impose more demanding individual-licence requirements and where general authorisations either do not apply or are subject to more restrictive conditions.

Second, transactions to destinations that one regime treats as eligible for a general authorisation but the other treats as requiring an individual licence. This destination-by-destination divergence is the most operationally significant: it converts what the exporter believes is a simple, pre-authorised transaction into one requiring a separate individual licence application, typically with a processing timeline measured in weeks rather than days.

Third, transactions where catch-all obligations are triggered under one regime but not the other. Once an EU competent authority has notified an exporter that a catch-all licence is required, that obligation exists irrespective of SECO's position on the same item and destination. The exporter must manage both positions independently.

Fourth, intangible and cloud-based technology transfers, where the detailed rules on what constitutes a "transfer" and what end-use certification is required differ between the regimes. Exporters providing software-as-a-service to customers in third countries must assess each regime's rules separately.

Fifth, post-shipment obligations, where SECO's delivery verification requirements apply in circumstances where the EU regime imposes only record-keeping obligations. An EU-only compliance programme will not capture these SECO obligations unless it has been specifically designed to do so.

Where the conditions genuinely conflict – that is, where satisfying one regime's eligibility conditions is inconsistent with satisfying the other's – the only compliant course is to obtain individual licences under both regimes and to structure the transaction to satisfy both sets of conditions simultaneously. In practice, genuine conflicts of this kind are rare, but they do arise in complex supply chains involving dual-use items at the higher end of the control list sensitivity scale.

How should a cross-border compliance programme address the divergences?

A compliance programme designed for dual EU-SECO export-control exposure must be built around four structural features.

Independent classification under each regime is the starting point. The programme must treat EU and SECO classification as separate exercises, conducted by reference to each regime's current control list, with documentation that records the classification outcome and the rationale under each. A single classification memo that references only the EU list – or only the SECO list – is insufficient for a business with obligations under both.

Destination eligibility mapping must be maintained as a living document. Because the permitted destinations under each regime's general authorisations differ, and because those lists can change following updates to the regime, an exporter's destination table must reflect both regimes' current positions and must be updated each time either regime amends its general authorisation scope.

End-user certification processes must satisfy the stricter of the two regimes' requirements for each transaction type. Where SECO requires an import certificate and the EU requires only a consignee undertaking, the programme must generate both. Where SECO requires a post-shipment delivery verification, the programme must have a mechanism to obtain and file it within the applicable timeframe.

Intangible-transfer controls – covering software, technology, and knowledge – must be assessed under each regime's rules separately. The programme must identify all channels through which controlled technology can be released: physical shipment, electronic transfer, cloud access, training, demonstration, and technical assistance. Each channel must be assessed against both regimes' eligibility conditions.

Record-keeping must satisfy the stricter of the two regimes' minimum retention requirements, and the compliance file for each transaction must contain sufficient documentation to demonstrate, per regime, why a general authorisation was used and on what eligibility basis. In an enforcement scenario, the exporter who can produce a well-organised dual-regime compliance file is in a materially stronger position than one who can show only that a shipment cleared customs.

Related practices

A common misconception: "If SECO clears it, the EU position is covered"

The most persistent myth among exporters managing dual EU-SECO exposure is that a SECO general authorisation provides some form of comfort on the EU side of the same transaction – and, conversely, that an EU general export authorisation simplifies the SECO analysis. Neither is true.

Switzerland and the EU are legally distinct jurisdictions. A SECO authorisation is issued under Swiss law by a Swiss authority. It has no legal effect under the EU regulation, which is a directly applicable EU instrument administered by EU member-state competent authorities. No EU competent authority is bound by, or required to take account of, a SECO authorisation when assessing an EU exporter's licence eligibility.

We regularly advise businesses that have operated for years on the assumption that a group-level SECO authorisation covers EU subsidiary operations. It does not. Each EU subsidiary exporting controlled items must satisfy the EU regime's eligibility conditions for each shipment, independently of any Swiss parent's SECO clearances. The costs of this misconception can include unlicensed exports from EU entities, exposure to EU enforcement, and the need to reconstruct a compliance file retrospectively – a significantly more difficult task than building it prospectively.

The corrective is straightforward in concept: treat each regime as a separate compliance obligation, with its own classification, its own eligibility analysis, and its own documentation. In practice, achieving this across a group with multiple exporting entities in both jurisdictions requires deliberate programme design and periodic review. To stress-test your screening and compliance programme across both regimes, reach our team at info@caldervance.com.

For a parallel analysis of OFAC and OFSI licence-exception eligibility divergences, see our separate briefing.

Frequently asked questions

Where do the regimes diverge on licence-exception eligibility?
The EU and SECO regimes diverge principally on three points: the list of permitted destinations under each regime's general authorisations, the end-user certification and post-shipment verification requirements, and the precise scope of intangible-transfer controls. Destination eligibility is the most operationally significant divergence: a country that qualifies under an EU general authorisation may require an individual SECO licence, or vice versa. Both regimes share a common origin in international control arrangements, but their implementing rules are set independently and are not synchronised.
Which regime is stricter on licence-exception eligibility?
Neither regime is categorically stricter across all transaction types. SECO imposes post-shipment delivery verification requirements for certain goods that the EU regime does not replicate. The EU catch-all regime can impose individual-licence requirements based on a competent authority notification that has no automatic parallel under SECO. Strictness depends on the specific item, destination, and end-use. An exporter should assess each proposed transaction under both regimes and apply whichever set of conditions is more demanding for that transaction – without assuming that one regime's general clearance resolves the other's requirements.
What should a cross-border business do about licence-exception eligibility?
A cross-border business with dual EU-SECO export obligations should take three practical steps. First, conduct independent classification under each regime's current control list, retaining documentation of the reasoning. Second, verify destination eligibility under each regime's general authorisation scope, updating the analysis when either regime amends its lists. Third, audit the end-user certification and post-shipment verification processes to ensure they satisfy the stricter of the two regimes' requirements for each transaction type. Where uncertainty remains – particularly for higher-sensitivity items, unfamiliar destinations, or intangible transfers – engage specialist export-control counsel before shipment, not after.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.