A software company is about to ship an update to its distributor network across twelve jurisdictions. The update includes a new encryption module. Someone in legal asks whether an export licence is required. The compliance team is not sure. The answer – and the liability – turns on a classification exercise that most technology businesses underestimate.
Encryption items are controlled under the Export Administration Regulations ("EAR"), administered by the Bureau of Industry and Security ("BIS"), through a dedicated category of the Commerce Control List ("CCL"), covering hardware, software, and technology with cryptographic functionality. As of April 2026, most commercial encryption products can qualify for a licence exception rather than a full licence application – but that eligibility is conditional on correct classification, annual reporting, and, in some cases, a one-time review submission. Miss any element and the exception falls away, leaving an unlicensed export.
This guide walks through the classification and compliance sequence for encryption items under BIS / EAR, identifies where businesses most frequently go wrong, and explains how the US position compares with the EU and UK regimes that often apply to the same product.
Step 1: Understand what "encryption item" means under the EAR
An encryption item under the EAR is any hardware, software, or technology that uses, or is specifically designed to use, cryptographic functions for confidentiality, authentication, or digital signature purposes. The scope is broader than most companies expect.
Businesses routinely assume that only dedicated security products – firewalls, VPN appliances, full-disk encryption tools – are caught. In practice, any product that incorporates a cryptographic library, including consumer-facing mobile applications, enterprise SaaS platforms with at-rest or in-transit encryption, and firmware with secure boot functions, may carry a controlled Export Control Classification Number ("ECCN", the alphanumeric code under the CCL that identifies the controlled item and the reasons for control). The relevant category on the CCL covers "information security" items and is subdivided by product type and by the nature of the cryptographic function.
The first question is therefore not "do we need a licence?" but "what is the correct ECCN?" Everything downstream depends on getting that right. In our experience, the single most common entry point for an encryption-controls problem is a company that assumed its product was EAR99 – not listed on the CCL and therefore not subject to licence requirements – without ever conducting a proper classification review.
Step 2: Classify the item and determine the applicable licence requirement
Correct classification under the CCL determines whether a licence exception is available or whether a full licence application to BIS is required; it also governs the annual reporting obligation that applies to many encryption items regardless of whether a licence is used.
Classification draws on the technical parameters of the item: key length, algorithm type, whether the cryptographic function is the primary function of the product or merely incorporated for internal use, and whether the item is "publicly available" within the meaning of the EAR. Each of those parameters affects which part of the relevant CCL category applies and, critically, whether the item qualifies for the mass-market or comparable licence exception pathway.
Where classification is genuinely uncertain, the EAR provides a commodity classification request mechanism through which a company can seek a formal binding determination from BIS. This is not always the fastest route – processing times vary and can run to several weeks – but for high-volume product lines or items likely to be exported repeatedly, a classification ruling provides certainty and a documented basis for future compliance. We regularly advise clients to weigh the delay of a formal request against the exposure of an unsupported self-classification, particularly where the product will be distributed into multiple markets simultaneously.
For encryption items subject to an anti-terrorism ("AT") control reason only, and for items that qualify as "mass-market" encryption, the EAR provides specific licence exceptions. Eligibility requires the item to meet the technical parameters defined in the EAR for mass-market treatment and, in most cases, requires the exporter to submit a one-time classification review notification to BIS before first export. That submission is not a licence application; it is a notification, and the absence of an objection from BIS within the applicable review period is not approval – it is the trigger for ongoing eligibility to use the exception.
Step 3: Complete any required submissions and establish the reporting cycle
One of the features of the encryption export-controls regime that most consistently catches businesses off guard is the annual reporting obligation: exporters who use certain licence exceptions for encryption items are required to file annual self-classification reports with BIS, listing the items exported and identifying the countries of destination.
The reporting window runs from the first of January to the first of February each year, covering exports made in the preceding calendar year. Missing the deadline – even where the underlying exports were fully licence-exception eligible – constitutes a separate violation of the EAR. The reporting obligation applies to a wider range of encryption items than many compliance programmes account for; it is not limited to the highest-controlled tiers of the list. Businesses that believe they have "ticked the box" with a one-time notification often discover, sometimes during an audit, that the annual reporting chain was never established.
Practical discipline here requires three things: a register of every encryption item exported under each licence exception, a tracking mechanism that captures country-of-destination data throughout the year, and a calendar trigger for the January reporting window. Larger organisations often manage this through their export-compliance management system; smaller ones tend to track it manually, which increases the risk of a missed filing. Either way, the obligation runs from the first export and does not wait for the business to notice it.
The position above covers the standard case. Your facts – the product architecture, the distribution model, the end-user base, the destination mix – may change the analysis materially. For a structured review of your encryption product line, contact Calder & Vance at info@caldervance.com.
Step 4: Apply destination and end-user controls
Even where a licence exception is available, it does not override the destination and end-user restrictions that run through the EAR as a whole. An item that is exception-eligible for most destinations may require a full licence application – or may be entirely prohibited from export – to certain destinations, to parties appearing on BIS's Entity List or Denied Persons List, or to end-users engaged in prohibited activities.
Encryption items, because of their dual-use nature, carry particular sensitivity under the end-use controls. BIS maintains authority under the EAR to impose additional licence requirements on specific end-users or transactions even where the item is otherwise licence-exception eligible. These informed by restrictions – arising from a "red flag" about the end-user's activities, affiliation, or destination – require the exporter to stop and resolve the doubt before proceeding. Proceeding in the face of a known red flag extinguishes the licence exception and creates the basis for an enforcement action.
Exporters should also be alert to BIS's Military End-User ("MEU") rule, which imposes additional licence requirements on exports to designated destinations where the end-user is or may be a military entity. Encryption items are among the categories subject to MEU scrutiny. A distribution model that routes product through a reseller network rather than selling direct does not shift the originating exporter's responsibility: the EAR's know your customer obligation follows the transaction, not just the immediate buyer.
Screening the full chain – the buyer, the consignee, the end-user, any freight forwarder – against BIS's restricted-party lists and OFAC's Specially Designated Nationals ("SDN") list is therefore a required step before each export, not a one-time onboarding exercise. We have acted for clients who had strong encryption-classification programmes but inadequate ongoing transaction screening; the exposure in those matters ran to the same potential liability as a straightforward misclassification.
How does the BIS / EAR encryption regime compare with the EU and UK positions?
The EU and UK maintain their own dual-use export-control regimes for encryption items, and the divergences between the three regimes are material enough to require a jurisdiction-specific analysis for any cross-border product.
Under the EU's dual-use rules, encryption items are likewise listed on the EU Common Military List's civilian counterpart and on the EU list of dual-use goods. The EU regime uses a different list structure and different technical parameters to determine control status; an item that is mass-market eligible under the EAR does not automatically qualify as unrestricted under EU rules, and vice versa. The licensing authority in each EU member state applies the same common EU list, but procedural timelines and administrative practice differ across member states – a practical consideration for businesses with European manufacturing or re-export operations.
Under the UK's Export Control Order, encryption items are controlled through the UK's own strategic export-control lists, which were aligned with the pre-Brexit EU lists but have since diverged in certain areas. ECJU – the Export Control Joint Unit – administers UK export licensing for dual-use goods, including encryption. One significant difference from the US position is the absence of a direct equivalent to the US annual self-classification report; the UK regime's transparency mechanism operates differently, through open general export licence conditions and compliance visits. That does not make the UK position simpler – it means that a compliance programme designed around US obligations may leave gaps on the UK side.
The practical consequence for a business exporting the same product from the United States, an EU member state, and the United Kingdom simultaneously is that three separate classification exercises are needed and that the licence-exception eligibility for one regime provides no safe harbour under the others. Where the product incorporates open-source cryptographic components, there is an additional layer of analysis in each regime around whether the "publicly available" or equivalent exclusion applies. In our cross-border practice, the failure to run parallel classification exercises is one of the most frequently observed structural gaps in technology-company export-compliance programmes.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
What are the key risk flags in encryption export-controls compliance?
Several recurring fact patterns generate disproportionate enforcement exposure under the EAR's encryption controls; recognising them early is the most effective risk-reduction measure available to a compliance team.
The first is self-classification without documented technical review. A product classified as EAR99 on the basis that "it is not a security product" – without an engineer-led review of the cryptographic parameters and a written record of the analysis – is a classification that will not survive an audit. BIS's enforcement guidance treats an unsupported self-classification as evidence of lax compliance, and lax compliance is an aggravating factor in penalty proceedings.
The second is product updates that change the encryption functionality without triggering a reclassification review. Software development cycles are fast. An encryption module added to address a new regulatory requirement, or a library upgrade that changes key length, can move a product from one part of the CCL to another, or from exception-eligible to requiring a full licence. Compliance programmes need a change-management trigger that connects the product-development process to the export-classification record.
The third risk flag is acquisitions. When a business acquires a company that develops or distributes encryption-enabled products, the acquirer inherits the target's export-classification decisions – and its past filing history, or lack of one. Pre-acquisition diligence that does not include a review of encryption-classification records and annual reporting compliance frequently surfaces post-closing violations that are the acquirer's problem to remediate.
A fourth, and underappreciated, risk is the deemed export – the disclosure of controlled technology to a foreign national within the United States. Sharing encryption source code or detailed technical parameters with a foreign-national engineer, whether an employee, contractor, or partner, can constitute a deemed export requiring a licence unless an exception applies. Technology companies with internationally diverse engineering teams frequently overlook this. Does your employment or contractor onboarding process include a deemed-export screen?
Finally, consider the voluntary self-disclosure ("VSD") route. Where a company identifies a potential violation – a missed annual report, an export made under an exception that was not eligible, an inadequate pre-shipment screen – a timely, thorough, and accurate VSD to BIS can be a significant mitigant in penalty proceedings. The VSD process involves specific procedural requirements; a submission that is incomplete, or that surfaces additional violations the company had not identified, can complicate rather than assist the matter. Counsel experienced in BIS enforcement should be involved before any VSD submission is made.
A common misconception about encryption licence exceptions
A persistent belief among technology businesses is that once an item has been notified to BIS as mass-market encryption, or once it has been through a commodity classification request, the compliance obligation is complete. That belief is wrong in two distinct ways.
First, licence exception eligibility is not a one-time determination. It must hold true for each export. If the item changes – technically, through an update – or if the destination, end-user, or end-use changes, the eligibility analysis must be repeated. A single classification decision provides the baseline; it does not operate as a standing clearance for all future exports of that product class.
Second, the annual reporting obligation runs independently of the classification. Even a product that has been formally reviewed and confirmed as mass-market eligible is subject to the annual reporting requirement. Companies that treat the initial notification as the end of the compliance process are systematically under-reporting. In a BIS administrative inquiry, a multi-year gap in annual reports is a substantive compliance failure, not a paperwork formality.
The distinction matters for enforcement posture. BIS draws a clear line between businesses that have a genuine compliance programme – classification records, annual reports filed, transaction screening documented – and those that have a compliance programme in name only. The former receive materially different treatment. Compliance discipline is not an academic exercise; it is the primary factor that determines the outcome if a violation is identified.
Related practices
- Deemed export and technology controls under BIS / EAR – assessing foreign-national technology disclosure in US operations.
- Encryption export controls: advanced licensing and end-use controls – detailed guidance on full licence applications and end-use undertakings.
- Encryption export controls under the Canadian regime – parallel obligations for businesses also exporting from Canada.