Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · EU

Encryption export controls under EU: a practical guide

A software company headquartered in Berlin prepares to ship an updated product suite to a distributor in Singapore. The bundle includes end-to-end encrypted messaging functionality. The compliance team asks a straightforward question: does the EU dual-use regime require an export authorisation before this shipment leaves the customs territory? The answer turns on classification, destination, end-use, and the specific exemptions available – and getting any element wrong can halt the transaction or, worse, expose the business to enforcement.

Encryption items are controlled under the EU dual-use rules as technology or software capable of providing confidentiality. The governing instrument is the EU Dual-Use Regulation, which establishes the EU Common List (the list of controlled items, including cryptographic products). Most mass-market encryption software benefits from a specific general authorisation, but that authorisation is not unconditional: destination, end-user, and technical parameters all determine whether it applies.

This guide walks through the classification test, the authorisation options, the cross-border dimensions – including where the EU position diverges from the US and UK – and the risk flags that most commonly cause problems in practice.

Step 1: Understand the governing authority and legal basis

The EU dual-use export-control regime is administered by the competent authorities of each Member State, operating within a framework set by the EU Dual-Use Regulation. The Regulation establishes a common list of controlled goods, software, and technology; it defines the general and national general authorisations available; and it sets the conditions under which individual licences are required.

Encryption falls within a dedicated category of the Common List that covers information security items – specifically goods, software, and technology designed or modified to use cryptographic techniques for confidentiality. The category is detailed and covers not only the encryption algorithm itself but also the equipment or software in which it is embedded. If your product handles encryption as a core or ancillary function, it is almost certainly on the list, at least in principle.

Each Member State designates a national competent authority to issue licences, process notifications, and conduct enforcement. In Germany that authority is the Federal Office for Economic Affairs and Export Control (BAFA); in France it is the Service des Biens à Double Usage (SBDU); in the Netherlands it is the Central Import and Export Office. Where your business is established determines which authority you deal with. In our experience, the quality and speed of licensing decisions vary between Member States, and for a business with export flows from multiple EU locations the choice of establishment can have material operational consequences.

The EU Dual-Use Regulation also preserves individual Member State competence to impose stricter national controls in defined circumstances. A product that sits outside the EU Common List may still require a national licence in certain Member States. Practitioners should verify the national position alongside the EU instrument.

Step 2: Classify the encryption item correctly

Correct classification is the foundation of the entire compliance analysis. Misclassification is the most common single error in encryption export control work – and it flows in both directions: firms over-classify, holding up legitimate trade, and under-classify, creating enforcement exposure.

The classification exercise for an encryption item involves three questions. First: does the item use or contain cryptographic techniques that provide confidentiality? Second: does it meet the technical parameters set out in the Common List – key length, algorithm type, and whether the cryptographic functionality is the primary purpose or an ancillary feature? Third: does any of the exclusions or carve-outs apply?

Several important carve-outs exist within the EU list itself. Items designed for personal use – mass-market products sold to the general public – attract a lighter treatment, as do items that use only commonly available cryptography (for example, standard TLS/HTTPS implementations). However, these carve-outs are not self-applying. The business must assess whether its specific product meets the technical criteria for the carve-out. Relying on a carve-out without a documented analysis is a risk flag in any enforcement review.

In our practice, we routinely advise clients to prepare a written classification record that sets out the item's technical specifications, the applicable list entry, the reasoning for any carve-out claim, and the date of the review. That record should be updated whenever the product changes in a way that could affect its classification. The EU Dual-Use Regulation imposes record-keeping obligations, and a well-maintained classification record is the first document an authority will request during an inspection.

A practical complication arises when an item straddles categories or when the encryption functionality is bundled within a larger software product. In those cases, the classification analysis must isolate the encryption component and assess it separately before returning to the product as a whole. Have you mapped every encryption module in your product, including third-party libraries incorporated at the code level?

Step 3: Identify the correct authorisation pathway

Once an item is confirmed as controlled, the next question is which authorisation applies. The EU Dual-Use Regulation provides three main pathways: EU general export authorisations, national general export authorisations, and individual licences. For encryption specifically, the most significant general authorisation is the one covering certain cryptographic items exported to a defined list of low-risk destinations. It is a standing authorisation – meaning no prior approval is needed, only registration and record-keeping – but it is conditional on destination, end-user type, and product specification.

Destinations not covered by the general authorisation will generally require an individual licence unless a national general authorisation applies. Individual licences are issued by the Member State competent authority; they are transaction-specific and cover named consignees and defined quantities. The application must include technical documentation, end-use undertakings, and, where applicable, an import certificate from the receiving country.

A critical point about general authorisations: using one does not relieve the exporter of the obligation to verify the end-user and end-use. The EU Dual-Use Regulation contains a catch-all control (a provision under which an exporter who knows, or has been informed, that an item is or may be intended for a prohibited end-use must seek individual authorisation regardless of whether a general authorisation would otherwise apply). Encryption technology directed at a military end-user in a country subject to an arms embargo is not covered by a mass-market general authorisation even if the technical parameters would otherwise qualify. That distinction trips up compliance teams who treat general authorisations as unconditional.

The catch-all is particularly important for encryption because of the dual-use nature of strong cryptography: civilian-grade encryption tools have direct application in intelligence, surveillance, and military communications. In our experience, end-use verification is the step most commonly skipped under time pressure, and it is the step most likely to produce an enforcement issue.

The position above covers the standard case. Your facts – the specific product, the destination, the end-user profile, and any indications of end-use – change the analysis substantially. For a confidential assessment of which authorisation pathway applies to your product and distribution model, contact Calder & Vance at info@caldervance.com.

Step 4: Address the cross-border dimension – how does the EU differ from the US and UK?

A business exporting encryption technology from the EU rarely operates in a regulatory vacuum. US rules under the Export Administration Regulations (EAR), administered by BIS, apply extraterritorially to items of US-origin content above a defined de minimis threshold. UK rules under the Export Control Order, administered by ECJU, apply to exports from Great Britain. The three regimes are broadly aligned in their approach to encryption controls – all three use a list-based system, all three include a mass-market carve-out – but the practical details diverge in ways that can catch cross-border businesses.

Three divergences are particularly significant. First, the US maintains a detailed encryption review and reporting procedure under the EAR. Certain exports or re-exports of encryption items to non-government end-users in most countries require a one-time product classification review filing with BIS before the first export. The EU and UK do not have a directly equivalent pre-export product-review filing requirement, though they do impose licence requirements for controlled destinations. A business established in the EU that incorporates US-origin encryption technology must assess whether the EAR's own controls apply in addition to the EU regime.

Second, the de minimis rule under the EAR means that foreign-made products containing more than a defined threshold of US-controlled content are subject to BIS jurisdiction even when exported from a non-US location. For an EU business, this means that a product shipped from Frankfurt may require BIS authorisation if it incorporates a qualifying amount of US-origin encryption software or source code. That extraterritorial reach has no precise equivalent in the EU Dual-Use Regulation, which is jurisdiction-based rather than content-based.

Third, the UK maintains its own export control list, which largely mirrors the EU Common List as it stood at the point of UK departure from the EU single market, but the UK list has subsequently been updated independently. Items that have been added to or removed from the EU list since that date may be treated differently under UK rules. For a business exporting from both EU and UK locations, maintaining two aligned classification records is necessary.

The practical implication is that an EU exporter of encryption technology needs to assess at least three potential control regimes – EU, US (EAR), and UK – and, depending on the destination, possibly additional national regimes. If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss the cross-regime position.

For US BIS deemed-export considerations involving technology transfer, see our service page on deemed export technology controls under BIS/EAR. For the Japanese encryption export control regime, our guide on encryption export controls under Japan addresses the specific requirements there. For OFAC considerations affecting encryption technology, see our guide on encryption export controls under OFAC.

Step 5: Record-keeping, notifications, and post-export obligations

EU dual-use export control obligations do not end at the point of shipment. The Dual-Use Regulation imposes record-keeping requirements on exporters: all relevant export documentation – licences, authorisation records, end-use undertakings, shipping documents, classification records – must be retained for a prescribed period following the export. Verify the current record-keeping period under the applicable Member State implementation before establishing your retention schedule.

Where a general authorisation is used, many Member States require the exporter to register its use of that authorisation with the competent authority before the first export and to submit periodic activity reports. The frequency and content of those reports differ between Member States. A business using EU general authorisations across multiple Member States needs a tracking mechanism that captures each use separately, by country and by authorisation type.

Internal compliance programmes should include a post-export audit function. This means periodically verifying that shipments made under general authorisations were within the technical and destination parameters of those authorisations, and that end-use undertakings remain accurate. Where a post-export review reveals that a shipment should not have been made under the authorisation used, the business should assess whether a voluntary disclosure to the competent authority is appropriate. In our practice, early and voluntary disclosure consistently produces a more favourable outcome than discovery by the authority through an inspection or third-party report.

Encryption technology businesses should also be alert to the brokering and technical assistance provisions of the EU Dual-Use Regulation. These extend controls to the provision of intermediary services and technical support in connection with controlled items, not just to the physical export of goods. A company providing remote technical support, key management services, or software updates to an end-user in a controlled destination may be providing controlled technical assistance, even if the original export was properly authorised.

Step 6: Common risk flags and when to involve counsel

Six risk patterns recur in our encryption export control work. Each represents a point at which the business is exposed and may not realise it.

The first is software-as-a-service and cloud delivery. Traditional export controls were designed around physical shipments. When encryption functionality is delivered as a service or via a cloud platform, the question of whether an "export" has occurred – and if so, to which jurisdiction – is legally contested. The EU Dual-Use Regulation addresses this partially through its provisions on non-physical transfers of technology, but the application of those provisions to cloud delivery models is an area of active regulatory development. Do not assume that a cloud delivery model removes the control; assume the opposite and verify.

The second is open-source encryption. Many businesses incorporate open-source cryptographic libraries into their products and assume that open-source means uncontrolled. This assumption is incorrect under the EU regime. The controlled status of an item turns on its technical characteristics, not its licensing model. Open-source encryption code that meets the technical parameters of the Common List is controlled, and the business that incorporates it into a commercial product and exports that product is the exporter for the purposes of the Regulation.

The third is product updates that change classification. A software update that strengthens the encryption parameters of a product – increasing key length, adding a new algorithm, or enabling end-to-end encryption where the previous version did not – may change the product's classification. Businesses that reviewed classification once at the point of initial product development and have not revisited it since are exposed to undetected drift in their compliance position.

The fourth is distributor and reseller chains. The EU Dual-Use Regulation places obligations on the exporter of record, but when the product passes through a distributor or reseller before reaching the end-user, the original manufacturer may have limited visibility of the ultimate destination and end-use. End-use screening at the point of sale to a distributor is not sufficient if the distributor subsequently on-sells to a controlled destination without authorisation. Contractual protections and audit rights over distributors are a necessary, if imperfect, mitigation.

The fifth is the interaction with financial sanctions. An export that is technically authorised under the dual-use rules may still be prohibited if the end-user or the transaction is subject to financial sanctions administered by OFSI or OFAC. The two regimes operate independently, and clearance under one does not confer clearance under the other. In our experience, teams that focus exclusively on export licensing without running a sanctions screen on the end-user and payment parties are regularly surprised by a hit at the payment stage.

The sixth – and the one most likely to be met with the response "that is not our problem" – is the position of a business that receives encryption technology from outside the EU and re-exports it to a third country. The EU Dual-Use Regulation covers re-exports of controlled items from the EU customs territory. If the item was imported from the US, the EAR's re-export rules also apply. A business that imports US-origin encryption software and then ships it from Germany to a restricted destination may be in breach of the EAR as well as the EU Regulation, regardless of whether it obtained a German export licence.

Related practices

Frequently asked questions

What are the steps to manage encryption export controls under EU?
The process runs in sequence: classify the item against the EU Common List, determine whether a general authorisation covers the destination and end-user, obtain an individual licence where one is required, register the use of any general authorisation with the relevant Member State authority, screen the end-user under both export control and sanctions rules, retain all documentation for the prescribed period, and conduct periodic post-export audits to verify that shipments remained within the authorisation parameters. Each step should be documented contemporaneously, because competent authorities assess the adequacy of the compliance process as well as the outcome of any individual transaction.
What is the most common mistake in encryption export controls?
Misclassification is the most frequent error, and it most often arises from two sources: failure to assess encryption modules embedded within a larger software product, and reliance on a carve-out – such as the mass-market exception – without documenting that the product actually meets the technical criteria for that carve-out. A second common error is treating a general authorisation as unconditional, when in practice the catch-all control can override it where there are indications of a controlled end-use.
How does EU differ from other regimes here?
The EU Dual-Use Regulation is jurisdiction-based: it controls exports from the EU customs territory and applies to the exporter of record in that territory. The US EAR, by contrast, is partly content-based: it extends to foreign-made products containing a defined threshold of US-origin controlled content, regardless of where they are exported from. The UK Export Control Order broadly mirrors the EU list as it stood at the time of UK regulatory divergence, but the two lists have since developed independently. An EU exporter of encryption technology should assess all three regimes, not just the EU instrument, because the US and UK rules may apply concurrently.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.