Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · Canada

Encryption export controls under Canada: step by step

A software company based in Toronto prepares to ship an encrypted communications platform to a distributor in a third market. Its legal team knows the product contains strong cryptography. Does it need an export permit from Global Affairs Canada? Which category does it fall under? And how does the Canadian position compare with what the company's US parent must clear through BIS? These questions are not academic. An uncontrolled export of a controlled encryption product can trigger enforcement action, seizure of goods, and reputational damage that outlasts the transaction.

Canada controls encryption products and software through the Export and Import Permits Act ("EIPA") and the regulations made under it, administered by Global Affairs Canada ("GAC"). The key operative instrument is the Export Control List ("ECL"), which mirrors the structure of the Wassenaar Arrangement's information-security controls. Most commercial encryption goods and software with a key length above a defined technical threshold require classification against the ECL and, depending on the destination and end-user, may require an export permit before shipment.

This guide walks through the classification, permit-determination, and application process step by step, identifies where GAC's position diverges from the US, EU, and UK regimes, and sets out the risk flags that should bring export-control counsel into the matter early.

Step 1 – Understand the governing regime and the authority behind it

Canada's encryption export controls sit within the broader export-control regime established under EIPA, with GAC as the administering authority. GAC publishes and maintains the ECL, processes permit applications, and enforces compliance, with criminal prosecutions referred to the Public Prosecution Service of Canada. The ECL is structured to reflect Canada's Wassenaar Arrangement commitments, meaning the information-security controls track the agreed multilateral control lists on cryptographic items – covering hardware, software, and technology for the development, production, or use of encryption.

The critical first point for any exporter is that Canada operates a permit-based system. An item that falls within a controlled ECL category requires either an individual export permit ("IEP"), a general export permit ("GEP") where one exists and the destination qualifies, or confirmation that the item falls outside control scope entirely. There is no automatic exemption for commercial-grade encryption solely because the product is widely available; the assessment is item-specific and destination-specific.

As of April 2026, GAC has not issued a blanket decontrol notice equivalent to the US EAR's mass-market encryption provisions, though certain general export permits do cover specified encryption goods to low-risk destinations. Verify the current GEP inventory before relying on any general authorisation.

Step 2 – Classify the encryption item against the Export Control List

Classification is the threshold step, and it is where most errors originate. The ECL groups controlled encryption items primarily within the information-security entry of the dual-use technology group, reflecting the Wassenaar information-security category structure. The exporter must assess whether the product meets the technical parameters set out in that entry – principally the cryptographic specifications, including algorithm type, key length, and whether the functionality is specifically designed to defeat, bypass, or monitor security controls.

The classification exercise covers three product forms: the physical hardware item (for example, a hardware security module or an encrypted communications device), the software (including source code for cryptographic applications), and the underlying technology (design and production know-how). Each form is assessed independently. A product that contains both a hardware token and embedded software may require separate analysis of each element.

Key practical points in the Canadian classification:

  • The algorithm and key-length parameters matter most. Products using widely-deployed symmetric or asymmetric algorithms at standard commercial key lengths are typically within the information-security controls, not outside them.
  • Products with non-standard or government-designed cryptography warrant particular care; those may attract additional controls beyond the standard dual-use entry.
  • Open-source cryptographic software is not automatically uncontrolled. The technical parameters, not the licensing model, determine classification.
  • A product that has received a US EAR classification under ECCN 5E002 or similar will often, but not invariably, align with the equivalent Canadian ECL entry. The alignment is not mechanical; Canadian and US control parameters can diverge at the margins.

In our experience, exporters frequently misapply a US ECCN to the Canadian ECL without re-running the technical assessment under GAC's parameters. That shortcut creates risk. We regularly advise clients to treat each regime's classification as a separate analytical exercise, informed by but not determined by the other.

Step 3 – Determine whether a permit is required, or a general export permit applies

Once classification confirms the item is controlled, the next step is the permit-determination matrix: does the destination and end-user combination qualify for a general export permit, or is an individual permit required?

GAC's general export permits cover certain categories of encryption goods to specified allied or low-risk destinations. Where the destination is covered and the end-user is not a prohibited party or a party of concern, the GEP route avoids a full individual application. However, GEP use is not unconditional – the exporter must confirm eligibility against the GEP's terms, retain records demonstrating that eligibility, and report usage where the GEP requires it.

Where no GEP applies, an IEP is required. The IEP route involves a written application to GAC, submission of technical specifications and end-use documentation, and assessment by GAC of the destination risk, end-user profile, and any applicable international commitments. GAC does not publish a binding processing timeline for IEPs, but in practice applications for straightforward commercial encryption products to standard commercial end-users in allied destinations process within a matter of weeks rather than months. Complex applications – those involving sensitive destinations, state-adjacent end-users, or novel technology – take materially longer.

The position above covers the standard case. Your facts – the specific product parameters, the destination, the end-user, the intended use, and any known diversion risk – change the analysis. For an initial classification and permit-determination review, contact Calder & Vance at info@caldervance.com.

Step 4 – Prepare and submit the individual export permit application

Where an IEP is needed, the application package typically includes the following elements. GAC's published application requirements should be consulted for the current form and supporting documentation list, as these are updated periodically.

  1. Technical product description – a precise description of the item, including cryptographic specifications, to allow GAC to confirm the ECL classification.
  2. End-user information – the name and address of the ultimate consignee, the intermediate parties in the supply chain, and the intended end-use. GAC takes end-user diversion risk seriously; a vague end-use statement will delay or defeat the application.
  3. End-use certificate or undertaking – for certain destinations and categories, GAC requires a formal end-use undertaking from the buyer or end-user confirming the declared use and prohibiting re-export without authorisation.
  4. Export transaction details – the quantity, value, and proposed shipment route.
  5. Supporting commercial documentation – the purchase order or contract, and any relevant product literature.

A well-prepared IEP application anticipates GAC's likely queries. In our practice, applications that are refused or returned for further information most often fail at the end-user documentation stage. The technical description is either too general to confirm the ECL classification, or the end-use undertaking is absent or inadequate. Investing time in the preparation stage reduces the back-and-forth materially.

Once submitted, the application enters GAC's review queue. GAC may issue queries (a "return for additional information"), which restart the clock on the review period. An application that has been returned should be treated as a priority; a slow response to GAC's queries prolongs the gap between the intended shipment date and the permit issuance.

How does Canada's encryption control approach compare with the US, EU, and UK regimes?

The cross-regime comparison matters for any exporter operating in more than one jurisdiction – and for the multinational that must clear the same product through several regimes before the shipment can proceed.

United States (BIS / EAR). The US regime under the EAR controls encryption through a detailed classification structure. The EAR contains specific provisions covering mass-market encryption products and encryption technology made available to the public, which, when met, can shift the classification to a lower-control category and in some cases remove the individual licence requirement for most destinations. BIS also operates an encryption registration and review process for certain products before the mass-market provisions apply. The US controls extend extraterritorially to foreign-made items incorporating US-origin encryption technology above a de minimis threshold, a reach that Canada's regime does not replicate in the same way. An exporter with a US parent or US-origin technology in its stack must clear both BIS and GAC before shipping.

European Union. The EU controls dual-use items including encryption under the EU dual-use regulation, with the same Wassenaar information-security category structure informing the control list. The EU has introduced a catch-all provision allowing member states to impose controls on items not otherwise listed where there is reason to believe the items are or may be intended for end-uses of concern. EU general licences for encryption exports exist in certain member states and at EU level for specific categories and destinations, but the availability and scope of those licences vary by member state. For a comparison of the EU position, see our EU encryption export controls guide.

United Kingdom. Following the UK's departure from the EU, the ECJU now administers encryption export licensing independently through the UK Strategic Export Licensing regime under the Export Control Order. The UK control list, while initially mirroring the EU list, is now maintained separately and may diverge over time. Open general export licences (OGELs) are available for certain encryption goods to specified destinations. The UK retains a catch-all mechanism and applies its own end-use risk assessment. Exporters who previously relied on EU licences must now assess UK requirements separately.

Key divergence point. The most practically significant difference between Canada and the other major regimes is the scope and availability of general authorisations. The US mass-market encryption provisions, when met, can substantially reduce the individual licensing burden for standard commercial encryption. Canada's GEP structure provides a more limited general authorisation framework. An exporter who qualifies for a US mass-market determination may still require an individual permit in Canada for the same product to the same destination. Do not assume that a clearance in one jurisdiction translates to clearance in another.

If a transaction has already been flagged by a foreign counterpart's regulator, or a shipment has been detained at a port of entry, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.

Risk flags and common failure points in Canadian encryption export compliance

Several patterns produce the majority of compliance failures we see in the encryption export space.

Assuming a decontrol based on a foreign classification. As noted above, a US EAR determination that a product qualifies as mass-market encryption is not a proxy for Canadian decontrol. The two regimes share a common lineage but are separately administered with separate parameters. Re-running the analysis under GAC's ECL is mandatory, not optional.

Overlooking the technology and source-code dimensions. Companies frequently focus on the physical hardware or executable software and overlook the controlled nature of the underlying technology – design know-how, specifications, and source code. Transmitting encryption source code to a foreign developer, or providing design specifications to an overseas manufacturing partner, can constitute a controlled export of technology requiring a permit. Is your product-development workflow reviewed against the ECL, or only your outbound shipments?

Inadequate record-keeping. GAC's enforcement posture under EIPA requires exporters to maintain records sufficient to demonstrate compliance with any permit conditions and with the basis for any GEP reliance. Records must be retained for the applicable period under GAC's requirements. An exporter that cannot produce the end-use undertaking for a GEP shipment two years after it occurred is exposed if an enforcement review is initiated.

Ignoring re-export obligations. Where the Canadian export is to an intermediary who will re-export to a third destination, the permit conditions may impose obligations on the intermediary, and the Canadian exporter may bear responsibility for downstream compliance. End-use undertakings serve this function in part, but they are not a complete substitute for understanding the re-export chain.

Missing the deemed-export dimension. The disclosure of controlled encryption technology to a foreign national on Canadian soil – for example, in an R&D context – may constitute a controlled "deemed export" under the Canadian regime. This is an area where the Canadian position is less explicitly developed than the US deemed-export provisions under the EAR, but the risk exists and should be assessed for any organisation with an international workforce working on controlled encryption technology. See also our US coverage of deemed export and technology transfer controls under BIS and the EAR.

A common myth about Canadian encryption controls

The most persistent misconception we encounter is that Canadian encryption export controls are less stringent than the US or EU equivalents and that a product freely exportable from Canada must be cleared for export everywhere. Neither part of that proposition is correct.

Canada implements the Wassenaar Arrangement's information-security controls with the same substantive parameters as its major trading partners. The administrative process may differ and, in certain respects, the general authorisation framework may be more or less permissive than in other regimes, but the technical trigger for control is broadly aligned. A product that meets the Wassenaar information-security parameters is controlled in Canada, in the US, in the EU, and in the UK, regardless of which regime the exporter treats as its primary reference point.

Equally, a product that is not controlled for export from Canada to destination A may be controlled for export from a US affiliate to the same destination if US-origin encryption technology is present in the stack. Secondary-sanctions and extraterritoriality considerations can create an obligation under the US EAR even where the Canadian export is clean. Cross-border advice that covers both regimes simultaneously is the only reliable approach for a multinational exporter.

We have acted for exporters in the technology sector who discovered mid-transaction that their Canadian permit was in order but their US parent's EAR obligation had not been separately assessed. Resolving that gap – without halting the shipment or triggering an enforcement referral – required coordinated advice across both regimes on a tight timetable. That kind of cross-regime coordination is exactly what our practice is structured to provide.

When to involve export-control counsel

Not every encryption export requires legal advice. A well-resourced compliance team with current training on the ECL and access to GAC's published materials can manage routine classification and GEP determinations internally. However, several fact patterns make counsel involvement advisable before the transaction proceeds.

  • The product involves novel cryptographic architecture, post-quantum algorithms, or a combination of encryption and another controlled technology.
  • The destination is outside Canada's standard allied-partner group, or the end-user is a state-adjacent entity, a university with defence affiliations, or a party that appears on any screening list.
  • The supply chain involves re-export through a third jurisdiction, particularly one where a separate export-control regime applies to the intermediary.
  • US-origin technology or software is embedded in the product, triggering a concurrent BIS / EAR obligation alongside the Canadian permit process.
  • The exporter has received a GAC query, a shipment detention, or a disclosure requirement from a customs authority.
  • The business is undergoing M&A or restructuring that will change the export-related entities in the permit applications.
  • The organisation is designing or updating its export-compliance programme and needs to incorporate encryption-specific controls.

Early involvement compresses timelines and reduces the risk of a permit refusal or a regulatory inquiry. In our experience, the cost of a compliance review before shipment is materially lower than the cost of an enforcement defence after the fact. For a confidential review of your encryption export position under Canada and any applicable concurrent regime, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to manage encryption export controls under Canada?
The core sequence is: classify the item against Canada's Export Control List under the information-security controls; determine whether a general export permit covers the destination and end-user; if not, prepare and submit an individual export permit application to GAC with full technical and end-use documentation; retain records of the permit and any GEP reliance; and review re-export obligations before the goods move onward. Each step should be completed before the preceding one is fully resolved. Parallel classification under any applicable concurrent regime – particularly the US EAR where US-origin technology is present – should proceed simultaneously, not sequentially.
What is the most common mistake in encryption export controls?
The most common mistake is treating a foreign classification – typically a US EAR determination – as a proxy for the Canadian position. The two regimes share Wassenaar foundations but are separately administered, and the technical parameters, general authorisation scope, and permit conditions differ. An exporter who skips the Canadian classification step because the US analysis is complete is exposed to an uncontrolled export under EIPA, regardless of the EAR outcome. The second most common error is overlooking controlled technology and source code, focusing only on the physical goods or executable software being shipped.
How does Canada differ from other regimes here?
Canada's most significant difference from the US regime is the absence of a direct equivalent to the US mass-market encryption provisions under the EAR, which can substantially reduce individual licensing obligations for standard commercial encryption when certain criteria are met. Canada's general export permit framework provides some equivalent relief, but it is narrower in scope and destination coverage. Compared with the EU, Canada's administration is centralised through a single national authority (GAC) rather than distributed across member states, which simplifies the single-jurisdiction analysis but does not reduce the obligation for exporters who must also clear EU member-state licences for the same product.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.