Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · BIS / EAR

Encryption export controls under BIS / EAR: step by step

A software company is finalising a cross-border distribution agreement. Its product contains an encryption module. The compliance team asks a simple question: does this need a licence? The answer is more layered than it appears – and getting it wrong exposes the company to civil penalties, denial of export privileges, and, in serious cases, criminal liability.

Under the Export Administration Regulations (the EAR, administered by the US Bureau of Industry and Security – BIS), encryption items are subject to dedicated controls that apply to both hardware and software, to source code, and to technology transferred by any means, including electronic transmission. Most commercial encryption products can be exported or re-exported under a licence exception, but that exception requires a classification review, an annual reporting obligation, and – in many cases – a prior notification filing before the first shipment. As of April 2026, these obligations remain in force and have not been materially relaxed.

This guide walks through the classification step, the applicable licence exceptions, the notification and reporting mechanics, the cross-border dimension (UK, EU, and other regimes), the risk flags that trigger a compliance review, and when to involve external counsel.

Step 1: Classify the item – does the EAR's encryption control apply to your product?

The first task is to determine whether the product falls within the EAR's encryption controls at all. BIS controls encryption items under the Commerce Control List (CCL), and an item's classification – its Export Control Classification Number (ECCN, the alphanumeric code on the CCL that determines applicable controls and licence requirements) – drives every subsequent obligation.

Encryption functionality is the trigger. If a product – hardware, software, or technology – performs, enables, or incorporates a cryptographic function for data confidentiality, it will ordinarily fall within the relevant encryption ECCN rather than the catch-all EAR99 classification. EAR99 items, by contrast, require no licence for most destinations and no encryption-specific reporting. Misclassifying a controlled item as EAR99 is one of the most common – and most consequential – errors we see in practice.

The classification analysis requires a technical review of the cryptographic parameters: the algorithm, the key length, and the mode of operation. It also requires a functional analysis: is the encryption feature integral to the product's primary function, or is it ancillary? Products where encryption is purely for authentication rather than confidentiality sit in a different part of the CCL. This is not a compliance-team decision alone; it requires an engineer and a classification adviser to reach a defensible position.

Do you have a written classification determination for every product you export that contains cryptographic code? If not, that gap is a material risk.

Step 2: Identify which licence exception applies – and its conditions

Once the classification confirms that the EAR's encryption controls apply, the next question is whether a licence exception covers the transaction, or whether a licence application to BIS is required. For most commercial encryption products destined to most markets, a licence exception is available – but it comes with conditions that must be satisfied before the first shipment, not after.

BIS provides several licence exceptions relevant to encryption items. The conditions and scope of each vary. Some are available only for products that have been reviewed and classified by the exporter through an annual self-classification process; others require a one-time review request submitted to BIS before the exception can be used. A few categories of end-user – government end-users in certain countries, and entities on the Entity List (BIS's list of parties requiring a licence for specified items) – are excluded from particular exceptions regardless of the product's classification.

The destination matters considerably. Exports to certain countries require a licence regardless of the exception that would otherwise apply. The applicable regime also matters: re-exports from a third country to another destination trigger a fresh analysis under the EAR's re-export rules, even if the original export was made under an exception.

In our cross-border practice, we regularly see exporters assume that because a product was exported once under an exception, all subsequent transactions – including re-exports by a foreign distributor – are automatically covered. They are not. Each transaction requires its own analysis against the exception's conditions at the time of the transaction.

Step 3: Complete the notification or classification filing before the first shipment

Several of the licence exceptions available for encryption items under the EAR condition their use on a prior step: submitting a classification or notification filing to BIS through the Simplified Network Application Process Redesign (SNAP-R) system before the first export under the exception. This is not a licence application; it is a procedural prerequisite. BIS does not issue an approval, but the filing must be completed and a confirmation obtained before the exception can be used.

The filing requires the exporter to describe the product, state the encryption parameters, and identify the applicable ECCN. BIS may ask follow-up questions; in our experience, products with non-standard algorithm implementations or unusual key management architectures attract closer scrutiny. The process is typically straightforward for standard commercial products, but it can take several weeks if BIS requests supplemental information.

Skipping this step is a common source of violations. An exporter that begins shipping under a licence exception before completing the required filing has violated the EAR even if the product itself would have qualified. The procedural violation is independent of whether the substantive exception was available. Voluntary self-disclosure of a filing failure is generally treated more favourably by BIS than a failure discovered through an audit or a third-party referral – but the best position is to complete the filing correctly before the first shipment.

Step 4: Meet the annual reporting obligation

Exporters using certain EAR licence exceptions for encryption items must submit an annual self-classification report to BIS covering all encryption items exported or re-exported under those exceptions during the preceding calendar year. The report is due each year and must be filed electronically. Missing the deadline, or filing an incomplete report, is a separate violation from any error in the original classification.

The annual report requires the exporter to list each product by ECCN, to state the markets and end-user categories supplied, and to confirm that the conditions of the exception were met throughout the reporting period. It is, in effect, a compliance attestation. In our practice, we treat the annual report preparation process as a useful internal audit: it surfaces discrepancies between what the export operations team shipped and what the compliance team recorded as the approved classification.

For businesses that have grown through acquisition or that have expanded their product line during the year, the annual report is often the moment when unclassified or mis-classified products are identified. That discovery is better made during report preparation than by a BIS inspector. Where a discrepancy is found, the question of whether to submit a voluntary self-disclosure (VSD, a formal self-report of an apparent violation to BIS) should be considered promptly and with legal advice.

Step 5: Apply the cross-border dimension – the UK, EU, and other regimes

The EAR does not operate in isolation. A product classified and exported under a BIS licence exception may also be subject to control under the UK export-control regime (administered by ECJU, the Export Control Joint Unit), the EU's dual-use regulation (administered nationally by competent authorities applying the EU framework), and the regime of the destination country. Each regime applies its own classification, its own thresholds, and its own licensing conditions.

Under the EU's dual-use rules, encryption items appear on the EU control list. The EU list is substantially aligned with the international Wassenaar Arrangement, as is the UK list following the UK's departure from the EU. However, alignment is not identity. Key lengths, algorithmic categories, and the treatment of mass-market exceptions differ in detail between the US, UK, and EU instruments. A product that qualifies for an exception under the EAR may require a licence under the applicable UK or EU regime, or vice versa.

The UK regime, post-Wassenaar alignment, follows a broadly similar structure to the EU's for encryption items – both tiered by the technical parameters of the cryptography – but the UK's export-licensing authority (ECJU) operates its own processing timelines, its own open licences, and its own conditions for use. For a business shipping the same product from the United States, a European distribution hub, and a UK operation, three parallel compliance streams may be live simultaneously.

Secondary sanctions risk is also relevant where the end-user or the destination is in a jurisdiction subject to US economic sanctions administered by OFAC. An export that is technically lawful under the EAR may still be prohibited if the transaction would involve a party on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or an entity subject to comprehensive sanctions under an OFAC programme. The EAR and OFAC are separate regimes; a licence exception under one does not authorise a transaction prohibited by the other. Where stricter prohibition governs, it controls – and that principle applies across all the regimes discussed here.

Step 6: Maintain records and prepare for an audit

The EAR imposes a record-keeping obligation on exporters: records relating to export transactions must be retained for five years from the date of the export, re-export, or transfer. This includes the classification determination, the notification filing confirmation, the shipping documentation, the end-user statements, and any internal correspondence relating to the compliance decision. The five-year period is a minimum; where a transaction is under investigation, records must be preserved until the matter is resolved.

In our experience, record-keeping is the area where exporters are most frequently caught short during a BIS audit or a pre-acquisition due diligence review. The classification memo written by an engineer three years ago may be the only contemporaneous evidence that a defensible decision was made at the time. If it cannot be found, the exporter cannot demonstrate compliance. A systematic records programme – product classification on file, notification confirmations archived, annual reports retained – is the foundation of a defensible position.

For businesses that are targets of an M&A transaction, the acquirer's due diligence will include a review of encryption export-control compliance. Gaps identified during due diligence – a product that was never classified, a filing that was never made, an annual report that was never submitted – carry transaction risk that is addressable before signing if identified early enough. After closing, the acquiring entity assumes the compliance history of the target, including any undisclosed violations.

Risk flags that warrant immediate legal review

Not every encryption export-control question requires external counsel. But several situations reliably indicate that the risk has moved beyond routine compliance management and that external legal advice is warranted.

  • A product has been exported for years under an assumed EAR99 classification that has never been formally reviewed.
  • A foreign distributor has re-exported the product to a country not covered by the original classification filing or notification.
  • An annual report has been missed for one or more years.
  • A product acquisition or a software library acquisition introduced encryption functionality that was not identified as controlled at the time of acquisition.
  • BIS has made an administrative inquiry or a pre-penalty notice has been received.
  • An employee or a former employee has raised a concern about historical compliance practice.
  • A transaction has involved an end-user that appears, or may appear, on the Entity List or the SDN List.

If any of these situations applies, the question is not whether to involve counsel – it is how quickly. The window for voluntary self-disclosure, and for the cooperation credit that a timely VSD can attract, narrows as the facts develop outside the exporter's control.

The position above describes the standard classification and exception pathway. Your product's specific technical parameters, the markets you serve, and the distribution structure you operate through may each change the analysis materially.

To discuss a classification review, a filing gap, or a BIS inquiry, contact Calder & Vance at info@caldervance.com.

A common myth about encryption export controls

The most persistent misconception we encounter is that the EAR's encryption controls apply only to purpose-built security products – encryption appliances, VPN clients, dedicated cryptographic hardware. In practice, controls extend to any product that incorporates a controlled cryptographic function, including business software with a routine login module, mobile applications with secure messaging features, and industrial control systems with encrypted communications protocols. The encryption is in the product; the fact that the primary purpose of the product is something else does not remove the control.

A related misconception is that open-source encryption code is never controlled under the EAR. This is partially correct – there is a specific treatment for publicly available encryption source code under the EAR – but that treatment has conditions. Code that meets the publicly available standard and that has been posted as required under the EAR is treated differently from proprietary code; but the conditions for that treatment must be actively satisfied, and the annual reporting obligation may still apply depending on how the code is distributed commercially.

If a transaction has already been flagged internally, or a product's classification has been questioned in a due diligence process, an early review preserves options that narrow with time. Contact our team at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to manage encryption export controls under BIS / EAR?
The core sequence is: (1) obtain a written ECCN classification for every product containing encryption functionality; (2) identify the applicable licence exception and confirm that its conditions are met; (3) complete any required notification or classification filing with BIS before the first shipment; (4) submit the annual self-classification report on time; (5) maintain records for five years; and (6) extend the analysis to parallel UK and EU controls and to any OFAC prohibition that may apply to the end-user or destination. Each step has its own procedural requirements and its own failure modes.
What is the most common mistake in encryption export controls?
The most common mistake is classifying a product as EAR99 – outside the encryption controls – without a formal, documented technical review. Exporters regularly assume that because a product's primary function is not security-related, the encryption it contains is not controlled. That assumption is wrong. The correct starting point is a technical review of the cryptographic parameters, documented in writing, against the relevant CCL category. A related error is failing to complete the required pre-shipment notification filing before relying on a licence exception; the procedural violation stands independently of whether the exception would otherwise have been available.
How does BIS / EAR differ from other regimes here?
The EAR's encryption controls are among the most detailed of any major regime – with specific ECCN categories, dedicated licence exceptions with granular conditions, and a mandatory annual reporting obligation that has no direct equivalent in the UK or EU frameworks. The UK and EU controls are broadly aligned through the Wassenaar Arrangement but differ in the scope of open licences, the processing timelines for case-by-case applications, and the treatment of mass-market and publicly available items. Crucially, the EAR can also apply extraterritorially to re-exports by foreign distributors, whereas UK and EU controls generally require a UK or EU nexus. A business distributing globally through a non-US hub must analyse all three regimes, and where they diverge, the stricter prohibition governs each leg of the transaction.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.