Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · EU

EU vs SECO: Re-export and extraterritorial reach: the key divergences

A Swiss trading company re-exports European dual-use components to a distributor in a third market. The goods left the EU months ago. The Swiss entity holds no EU establishment and has acted entirely within Switzerland. Yet counsel calls the following week to ask: does EU law still apply? And does SECO have something to say about this too? Both questions matter. The answers are not the same.

The EU dual-use regime and the Swiss export-control regime administered by SECO (the State Secretariat for Economic Affairs) address re-export and extraterritorial reach through different legal mechanisms, different trigger conditions, and different enforcement postures. As of April 2026, the EU's rules bind EU operators on goods, software, and technology that have left EU territory – including catch-all controls and end-use clauses that follow the item. SECO operates through Switzerland's autonomous sanctions ordinances and its own export-control framework, which can impose parallel re-export conditions independently of EU law. Where both regimes apply, the stricter prohibition governs each leg of the transaction.

This analysis maps the key divergences – on re-export triggers, extraterritorial reach, catch-all obligations, end-use controls, and enforcement exposure – and draws out the practical implications for businesses operating across the EU–Swiss corridor and beyond.

What legal basis does each regime use to control re-exports?

The EU dual-use regime rests on the relevant Council Regulation, which establishes a single authorisation mechanism across the Member States and attaches conditions to items originating in or transiting through the EU. Re-export controls flow from that regulation: an EU general export authorisation or a specific national licence may carry explicit end-destination restrictions that prohibit onward transfer without a further authorisation. The competent authority in the Member State of export is responsible for enforcement, but the legal obligation travels with the item when it is an EU-origin or EU-transiting good covered by the regulation.

SECO, by contrast, administers Switzerland's export controls under a distinct national legal instrument. Switzerland is not an EU Member State and is not bound by EU regulations. SECO's authority derives from Swiss federal law and the ordinances issued under it, including autonomous sanctions measures that Switzerland adopts in parallel with – but not automatically in line with – EU and UN positions. Re-export conditions imposed by SECO appear in the end-use and end-user commitments attached to Swiss export licences, and in the terms of any applicable catch-all notice issued by SECO itself.

The practical consequence is immediate. A single shipment can sit under two independent licence regimes simultaneously. In our cross-border practice, we regularly see exporters who have secured the EU authorisation assume that SECO requirements are automatically satisfied. They are not. Conversely, Swiss-headquartered traders sometimes treat SECO clearance as sufficient and overlook the EU restrictions that attach to goods transiting a Member State before they reach Switzerland. Both assumptions carry enforcement risk.

How does the EU extend its reach beyond EU territory?

The EU extends its reach beyond EU borders primarily through three mechanisms: the broker controls, the technical-assistance prohibitions, and the catch-all clause. Each can capture a non-EU person or a transaction that, on its face, has no EU nexus other than the origin of the goods or technology.

Broker controls in the relevant EU regulation can apply to persons established in the EU who arrange, negotiate, or facilitate the transfer of dual-use items between two non-EU countries. The activity is controlled irrespective of whether the items pass through EU territory. A compliance officer at an EU-headquartered trading group who arranges a sale from a warehouse in a third country to a buyer in another third country may be caught. This reach is a point of genuine divergence: SECO's brokering controls are more limited in scope and attach primarily to weapons-related transactions rather than the broader dual-use category.

The EU catch-all mechanism allows competent authorities to require an authorisation even for items not listed on the EU's dual-use control list, when the exporter has been informed – or has grounds to suspect – that the items are intended for use in weapons of mass destruction programmes or destinations of concern. That catch-all is triggered at the point of export from the EU, but subsequent knowledge can also raise reporting obligations. SECO operates a parallel catch-all regime; however, the thresholds for triggering it and the procedure for issuing a catch-all notice differ. An exporter dealing with both authorities must satisfy each independently.

Technical-assistance prohibitions in the EU can reach activities performed outside EU territory when the provider is an EU person or is using EU-controlled technology. This is an area where, in our experience, compliance teams frequently underestimate their exposure. The question is not only where the items are – it is where the service provider is established and what technology underpins the assistance.

Where do the regimes diverge most sharply on re-export and extraterritorial reach?

The sharpest divergences sit in four areas: the treatment of intangible technology transfers, the structure of catch-all obligations, the brokering perimeter, and the interaction with UN and autonomous sanctions.

On intangible technology, the EU regime controls the transfer of controlled technology by electronic means – email, cloud upload, and remote access – under the same framework as physical goods. SECO's approach to intangibles is comparable in principle but differs in the specific control-list categories and in the way it maps to Swiss federal licensing practice. A piece of software that is EAR99 under the US Commerce Control List may still require a Swiss or EU licence. And a technology transfer that the EU classifies as requiring a specific licence may or may not trigger a SECO requirement, depending on whether Switzerland has adopted the equivalent control in its own list.

On catch-all obligations, the EU's mechanism is more prescriptive in the sense that it is embedded in a single regulation with uniform text across all Member States. SECO's catch-all authority exists but is exercised through a more discretionary notice-based process. This means that a Swiss exporter may have slightly different early-warning obligations than a German exporter for what is, economically, the same transaction. For a group that routes its exports through both jurisdictions, alignment of internal escalation processes with both systems is a non-trivial compliance task.

On brokering, the distinction is material for trading intermediaries. EU law captures a wide range of facilitation activities, including the provision of financing and insurance if the provider has reason to believe the export would breach a prohibition. SECO's brokering rules are narrower. A Swiss broker facilitating a transfer of dual-use items between two third countries may have fewer formal SECO obligations than its EU-established counterpart – but that does not mean no obligations, and it does not reduce the Swiss entity's exposure under EU law if it uses EU-established affiliates or EU-origin components in the chain.

On sanctions interaction, both the EU and Switzerland impose autonomous measures that can, in practice, function as a de facto export ban regardless of the dual-use classification of the item. The EU's sanctions regulations, administered at Member State level, overlay the dual-use framework. SECO administers Switzerland's autonomous sanctions separately. Where a destination or end-user triggers both sets of autonomous measures, the exporter must satisfy both simultaneously. The stricter prohibition governs each leg. This is not a theoretical point: Switzerland's autonomous sanctions position has, at various times, diverged from the EU's, creating windows in which the same transaction is prohibited under one regime and permitted under the other.

What are the end-use and end-user control obligations under each regime?

End-use and end-user controls are the operational heartbeat of re-export management under both the EU and SECO regimes. Both systems require exporters to obtain, retain, and act upon end-use statements. Both attach conditions to licences that can restrict onward transfer. The differences are in the depth of the obligation and the procedural consequences of a breach.

Under the EU regime, end-use undertakings are frequently embedded in specific licences and can impose obligations on the importing party that the EU exporter is expected to monitor. The concept of enhanced due diligence – a heightened obligation to know the ultimate end-user and the intended application of the item – applies when a competent authority has indicated concern about a particular destination or user type. Where the EU catch-all is triggered, the exporter's knowledge of the end-use is determinative.

SECO imposes comparable end-user requirements through its licensing conditions and through the end-use statements that Swiss law requires for certain categories. The procedural form differs: SECO's end-use certificates follow a Swiss federal format, and the record-keeping obligations attach to Swiss export-law requirements rather than EU requirements. For a business that exports the same goods under an EU authorisation and then re-exports from Switzerland, the documentation trail must satisfy both sets of requirements independently.

Re-export conditions attached to an EU licence are a further complication. An EU global export authorisation may explicitly prohibit re-export to named destinations or require prior notification before re-export. A Swiss recipient of EU-authorised goods must therefore check the original licence conditions before arranging onward shipment, even where the onward leg is entirely outside the EU and governed by SECO alone. In practice, this means that the original EU exporter has a commercial and legal interest in monitoring downstream re-exports – and should contract for notification rights accordingly.

What enforcement posture does each authority take, and what risk does that create?

Enforcement posture shapes the practical risk calculus. An exporter who misunderstands which authority will act – and how – may underestimate exposure on one leg and over-invest on the other.

EU enforcement is decentralised: each Member State's competent authority enforces the EU regulation within its territory, applying its own procedural rules and penalty ranges. Member States differ substantially in enforcement intensity. Some have active investigation units with criminal referral powers; others rely predominantly on administrative penalties. The EU does not have a single, centralised enforcement authority equivalent to BIS or OFAC. This decentralisation means that the same breach can have very different consequences depending on which Member State's authority takes up the matter.

SECO is a unitary federal authority. It enforces Swiss export controls and autonomous sanctions through administrative and criminal procedures under Swiss federal law. SECO has the power to impose administrative penalties and to refer serious cases for criminal prosecution. The Swiss criminal threshold for export-control violations is not a trivial risk: intentional violations can attract custodial sentences. SECO's enforcement has been notably active in recent years on transactions involving goods with potential military end-use, and the authority has shown willingness to open investigations based on referrals from third-country authorities.

For a business with exposure under both regimes, the risk is additive. A single transaction that breaches both the EU regulation and a SECO ordinance can attract parallel investigations by two separate authorities, with no formal coordination mechanism between them. In our experience, businesses that have received a SECO inquiry do not always alert their EU compliance function promptly, and vice versa. That gap is a vulnerability.

What should a compliance officer do if goods have already been re-exported and a question arises about compliance? The answer is regime-specific. Under the EU regime, the competent authority of the Member State of export is the first point of contact. Under SECO, the relevant procedure involves engagement with the authority's enforcement unit. A VSD (voluntary self-disclosure to a regulator) can, in appropriate circumstances, influence the penalty outcome under both systems – but the procedural requirements and the decision to disclose require specialist advice before the approach is made.

Common misunderstandings that increase risk

Several myths persist in compliance teams that work across the EU–Swiss corridor. The first is that Swiss neutrality translates into lighter export-control obligations. It does not. Switzerland maintains an autonomous export-control regime that is, in several respects, as demanding as the EU's. SECO has enforcement powers and uses them.

The second myth is that an EU global export authorisation automatically authorises re-export by the overseas recipient. It does not. Re-export conditions are a standard feature of EU authorisations, and the recipient's right to re-export depends on the specific terms of the licence, the destination of the re-export, and whether a further authorisation is required under the re-exporting country's laws – including, if applicable, SECO.

The third myth is that catch-all controls only apply to goods on the control list. They do not. The catch-all mechanism is specifically designed to capture unlisted items when end-use or end-user concerns arise. A business that screens only against the control list and neglects catch-all risk is operating with a significant gap.

The fourth myth is perhaps the most operationally consequential: that a transaction is safe once the goods have cleared EU customs. The EU's brokering controls, technical-assistance prohibitions, and sanctions-based restrictions do not stop at the EU border for EU persons. And SECO's jurisdiction starts when goods enter the Swiss export chain, regardless of what happened upstream. The overlap zone – goods of EU origin transiting through Switzerland to a third-market destination – requires analysis under both regimes before, not after, the shipment is arranged.

Is your internal escalation process designed to catch this overlap? In our cross-border practice, we find that most businesses have one responsible team for EU export controls and a separate team or external adviser for Swiss compliance, with limited structured communication between them. That siloed structure is the single most common source of preventable dual-regime exposure.

When does this analysis change, and when should counsel be involved?

The analysis changes whenever the control list in either regime is updated, when SECO or an EU Member State authority issues a catch-all notice, when the autonomous sanctions position of either Switzerland or the EU shifts, or when a new end-user or destination enters the transaction chain. Both regimes update their positions with some regularity, and the updates are not always synchronised.

Counsel should be involved at the transaction-design stage, not after the first shipment. The cost of correcting a dual-regime breach – through voluntary disclosure, remediation, and enhanced compliance measures – consistently exceeds the cost of pre-clearance advice. The relevant questions for counsel are: which items require a licence under each regime; whether the proposed recipient is subject to end-use restrictions under either the EU authorisation or SECO conditions; whether any re-export from Switzerland to a third destination requires a further authorisation; and whether the transaction structure creates brokering exposure for any EU-established entity in the group.

We advise exporters, trading intermediaries, and financial institutions on the full range of dual-use and export-control questions across the EU and SECO regimes. In a recent matter, a European industrial manufacturer sought to supply components to a Swiss subsidiary for integration and re-export to an end customer in a third market. We classified the items under both the EU dual-use list and SECO's equivalent, identified a mismatch in the applicable control categories, and restructured the transaction to ensure that the authorisation obtained in each jurisdiction covered the actual goods flow. The matter closed without delay to the commercial schedule.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of your export-control position under the EU regime or under SECO, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

Where do the regimes diverge on re-export and extraterritorial reach?
The EU and SECO regimes diverge most markedly on brokering scope, catch-all trigger conditions, and the treatment of intangible technology transfers. The EU's brokering controls capture a wide range of facilitation activities by EU-established persons, even for transactions between two non-EU countries. SECO's brokering rules are narrower, focusing primarily on weapons-related activity. Both regimes operate catch-all mechanisms, but the procedural form and triggering threshold differ. For a business spanning both jurisdictions, each mechanism requires independent compliance analysis – alignment of one does not satisfy the other.
Which regime is stricter on re-export and extraterritorial reach?
Neither regime is uniformly stricter across all dimensions. The EU's brokering and technical-assistance controls reach further for EU-established persons. SECO's criminal enforcement framework imposes potentially severe consequences for intentional violations. Where both regimes apply to the same transaction, the stricter prohibition on each element governs. In practice, the combined obligation is more demanding than either regime standing alone. A compliance analysis that benchmarks against only one authority will systematically understate the actual legal exposure of a business operating across both jurisdictions.
What should a cross-border business do about re-export and extraterritorial reach?
A cross-border business should map every leg of its goods flow against both the EU dual-use framework and SECO's requirements before the first shipment. That means classifying items under each control list independently, reviewing re-export conditions in any existing EU authorisation, and confirming whether a SECO licence or end-use certificate is required for the onward leg. Internal escalation procedures should be structured to catch transactions that trigger both regimes simultaneously. Where items are re-exported by an overseas recipient, the original exporter should hold contractual rights to monitor and receive notification of intended re-exports. Counsel should be engaged at the transaction-structuring stage, not after a query has been raised by an authority.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.