A technology exporter with sales into multiple markets runs its products through US screening. The items appear controlled. The compliance team knows what an ECCN (Export Control Classification Number under the US Commerce Control List) is – but does the classification work the same way when the same goods also move through EU customs, UK export licensing, or a Singapore re-export? The short answer is no. And that gap is where enforcement exposure concentrates.
As of April 2026, the ECCN system administered by the US Bureau of Industry and Security under the Export Administration Regulations is the primary cross-border classification instrument for dual-use goods, software, and technology. Correct classification under the EAR is a legal prerequisite for identifying licence requirements, applying licence exceptions, and filing Electronic Export Information. Under parallel EU, UK, and other regimes, a different – but structurally similar – classification exercise runs independently, and the strictest prohibition governs any transaction that touches multiple jurisdictions simultaneously.
This guide walks through the classification process step by step, maps where the major regimes diverge, and identifies the risk flags that most frequently surface in cross-border practice.
Step 1: Understand what the ECCN system classifies – and who runs it
The ECCN system covers dual-use items – goods, software, and technology that have both commercial and potential military, proliferation, or surveillance applications – and is administered by the US Department of Commerce's Bureau of Industry and Security under the Export Administration Regulations. Classification begins with identifying whether an item falls on the Commerce Control List at all, or whether it is classified EAR99 (controlled but not on the list, and therefore subject only to general prohibitions).
The Commerce Control List is organised into ten categories – from nuclear materials at Category 0 to miscellaneous at Category 9 – and five product groups within each category (equipment, test apparatus; materials; software; technology; other). A correctly assigned ECCN takes the form of a one-digit category number, a letter for the product group, and a three-digit suffix that indicates the reason for control. The reason for control matters enormously: it determines which countries require a licence, which licence exceptions are available, and how de minimis calculations operate for foreign-made items incorporating US content.
In our cross-border practice, the single most common error at this stage is treating EAR99 as a clean bill of health. An EAR99 item can still be subject to end-use and end-user controls, the Entity List, and certain regional controls. Classification is the start of the analysis, not the conclusion.
Step 2: Apply the five-step classification sequence under the EAR
The BIS classification sequence proceeds in a defined order, and skipping steps produces unreliable results. Here is how practitioners work through it in practice.
- Review the product's technical specifications. Gather the detailed technical data sheet, bill of materials, and, for software, the functional description. Classification turns on objective technical parameters – performance specifications, frequencies, materials, bit counts – not on the item's commercial name or intended end use.
- Search the Commerce Control List by category and product group. Start with the most specific entry. If the item is a semiconductor manufacturing tool, begin with Category 3 (electronics), not Category 2 (materials processing). If there is a specific ECCN that matches the item's critical technical parameters, that ECCN governs.
- Check the control parameters precisely. Each ECCN entry carries technical thresholds. An item only falls within the ECCN if it meets or exceeds those thresholds. Below the threshold, the item may be EAR99 or may fall under a different, less restrictive ECCN. Do not classify above the item's actual specification.
- Confirm the reason-for-control codes. The ECCN's control reason codes (NS, MT, CB, AT, and others) determine the licence requirement matrix by destination, end use, and end user. An item controlled for national security reasons carries different licence requirements from one controlled for anti-terrorism reasons only.
- Document the classification rationale. BIS expects exporters to be able to demonstrate how they arrived at a classification. A written rationale – citing the technical parameters, the specific ECCN entry tested, and the conclusion – is the evidentiary record in any audit or enforcement proceeding. Keep it for at least five years, which is the standard record-retention period under the EAR.
Where internal technical expertise is limited, exporters have two formal options: a commodity jurisdiction request (for items that may be subject to the ITAR rather than the EAR) and a commodity classification request to BIS (for a binding administrative determination of ECCN). The latter takes time – weeks to months depending on item complexity – but produces a defensible record.
Step 3: Run the parallel classification under the EU dual-use regime
EU dual-use classification operates under the EU Dual-Use Regulation, which is administered nationally through each member state's competent authority but applies a single harmonised control list derived from the multilateral Wassenaar Arrangement, the Australia Group, the Missile Technology Control Regime, and the Nuclear Suppliers Group. The EU list mirrors the CCL structure closely – ten categories, five product groups – but the entries are not identical to the US entries, and the thresholds sometimes differ.
The practical implication is that an item classified at a specific ECCN under the EAR may fall within a different EU control list entry, or may fall outside EU controls entirely, or vice versa. Exporters moving items from an EU member state cannot simply rely on their US ECCN determination. A separate EU classification exercise is required, and that exercise is governed by the law of the exporting member state, not by BIS.
One point of consistent divergence is software and technology for intrusion, surveillance, and encryption. The EU Dual-Use Regulation has expanded its controls in these areas over recent years, and in some instances the EU parameters are tighter than the corresponding EAR entries. Have you checked whether a software item that is EAR99 in the United States still requires an EU general or individual export authorisation from the member state of export?
The cross-border dimension here is not academic. A US company shipping controlled software to a non-EU customer via a subsidiary in Germany must satisfy both US and EU export control requirements. The subsidiary's compliance team needs to run its own classification and licensing analysis under the relevant German implementing authority, regardless of what BIS has determined.
Step 4: Apply the UK export control classification
Following the UK's departure from the EU, the UK operates its own export control regime under the Export Control Order and the Strategic Export Controls: UK Military List and UK Dual-Use List. The UK dual-use list was initially aligned with the EU list at the point of departure, but it has since diverged on certain items as each regime has updated its controls independently.
The UK's ECJU (Export Control Joint Unit) administers export licensing, and classification under the UK list is the starting point for determining whether an Open General Export Licence applies or whether a Standard Individual Export Licence is required. The ECJU has published a product checker tool, but that tool is indicative only. Formal classification decisions for complex items should be sought through the ECJU's formal advisory service.
In our experience, businesses that managed UK export compliance as an extension of their EU process before 2021 frequently have compliance gaps. The UK list has moved, and the licensing routes differ. An item that was freely exportable under an EU general authorisation may require an individual licence from the ECJU for the same destination. We regularly advise clients on how to audit their legacy classification database against the current UK list and identify items that need reclassification.
The interaction between OFSI financial sanctions and ECJU export controls also deserves attention at this stage. An export licence authorises the physical transfer of controlled goods; it does not, on its own, authorise the associated financial transaction if the counterparty is subject to UK financial sanctions. Both streams of analysis must run in parallel.
Step 5: Assess re-export and third-country regime exposure
A classification exercise that ends at the point of first export is incomplete for goods that will move onward through a distribution chain. Re-export controls under the EAR apply extraterritorially: a controlled US-origin item, or a foreign item that incorporates more than a de minimis proportion of US-origin controlled content or is produced with certain US technology, remains subject to the EAR regardless of where it is when the re-export occurs.
The de minimis threshold for most destinations is 25 percent of the controlled US-content value of the item. For items subject to heightened controls for certain destinations, that threshold drops to 10 percent. These figures determine whether a foreign-made item is subject to the EAR at all. A European manufacturer incorporating US-origin technology into finished equipment must run a de minimis calculation for each product line. If the threshold is exceeded, US re-export licence requirements follow the item regardless of the exporter's nationality.
Singapore, Japan, the UAE, and other significant transit and re-export jurisdictions each maintain their own strategic export-control regimes, and in each case a separate national classification analysis is required. Singapore's Strategic Goods Control Act imposes permit requirements for strategic goods and technology; Japan's Foreign Exchange and Foreign Trade Act controls dual-use items across an export and re-export matrix; the UAE's In-Country Value and Strategic Goods regime requires registration and permit compliance for controlled items transiting or re-exported from UAE free zones. None of these obligations is discharged by a BIS or ECJU determination alone.
The practical message is that a cross-border classification project should map the full anticipated movement of the goods – origin, transit, destination, and probable re-export paths – and run the classification analysis against each relevant regime before the first shipment occurs.
Step 6: Identify licence requirements, exceptions, and documentation
With classifications confirmed across the relevant regimes, the next step is determining what licence or authorisation, if any, is required for the planned transaction. Under the EAR, the licence determination depends on the item's ECCN, the reason-for-control codes, the destination country, the end user, and the end use. BIS publishes a country chart that maps each control reason to each country and indicates whether a licence is required.
Licence exceptions under the EAR are specific carve-outs from the licence requirement. They are not discretionary waivers; they are defined conditions that either apply or do not. Common exceptions include those for items being returned after repair, technology for fundamental research, certain encryption items, and low-value shipments. Each exception carries its own eligibility criteria, and relying on an exception the item does not actually qualify for is itself an export-control violation.
Under the EU regime, authorisations come in three forms: national general export authorisations (which member states grant for certain categories of items and destinations), EU general export authorisations (which the Regulation itself provides for defined item-destination combinations), and individual licences. The UK regime mirrors this structure, with Open General Export Licences, Open Individual Export Licences, and Standard Individual Export Licences. In each case, the exporter's classification drives the authorisation determination.
Documentation requirements attach to the licence or exception used. Under the EAR, Electronic Export Information must be filed in the Automated Export System for shipments above certain value and weight thresholds. End-user undertakings, import certificates, and delivery verification certificates may be required as conditions of specific licences under the EU and UK regimes. A well-managed classification programme builds document management into the licensing workflow, not as an afterthought.
Risk flags and when to involve counsel
Certain patterns in cross-border classification engagements reliably indicate elevated risk, and counsel should be involved before – not after – a transaction proceeds.
The first flag is a mismatch between a supplier's classification and the buyer's intended end use. An item correctly classified for standard commercial export may be subject to additional controls if the end user has connections to a military or intelligence programme, a proliferation-sensitive industry, or a party on a restricted-party list. End-use screening and Know Your Customer analysis run alongside classification, not as a separate exercise.
The second flag is an item that sits close to a technical threshold. Marginal classifications – where the product's performance specification is near the ECCN's control parameter – carry audit risk. A well-documented, defensible classification memo is essential; an undocumented "below threshold" assumption is not. When in doubt, a commodity classification request to BIS or a formal technical assessment by external counsel reduces exposure significantly.
The third flag is a supply chain that includes jurisdictions subject to comprehensive or thematic sanctions programmes. Export controls and sanctions interact: a controlled item destined for a sanctioned end user requires not only a denied-party check but a full analysis of the applicable sanctions prohibitions and any available licence or authorisation. The export-control licence does not authorise the sanctioned-party transaction.
The fourth flag is a software or technology item. Intangible transfers – sending technical data by email, providing remote software access, giving a briefing to a foreign national – are export-controlled events under the EAR's deemed-export rule, the EU regime, and the UK Export Control Order. Many businesses with strong physical goods compliance have incomplete controls over technology transfer. If the technology is controlled, every transmission to a foreign national – including employees and contractors – needs analysis. See our service on deemed export and technology controls under BIS and the EAR for the detail of this analysis.
The fifth flag is an item being re-exported or incorporated into a foreign product for onward sale. As noted above, US-origin content triggers EAR obligations that follow the item. A business that manufactures or integrates US-origin items and distributes the finished product internationally must maintain a de minimis calculation and a re-export compliance programme, not just an initial export compliance process.
Is your classification database current? Many businesses classify items once, at product launch, and do not revisit the classification when product specifications change, control lists update, or the item is approved for a new market. Classification is not a one-time event.
The position above covers the standard classification workflow. Your specific facts – the item's technical specifications, the distribution chain, the destinations, and the regimes in play – change the analysis materially. For an initial assessment of your cross-border export-control position, contact Calder & Vance at info@caldervance.com.
Related practices
- Deemed export and technology controls – BIS/EAR analysis of intangible technology transfers to foreign nationals
- ECCN classification guide, part 3 – advanced topics in cross-border dual-use classification
- ECCN classification guide, part 4 – licensing, exceptions, and enforcement defence in cross-border transactions