Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · EU

Encryption export controls under EU: what businesses must know

A technology company headquartered in Germany prepares to ship a software update to a distributor in Singapore. The update includes an encryption library. The export licensing team asks a simple question: does the EU dual-use regime require a licence for this transfer? The answer turns on classification, destination, and end-use – and getting it wrong carries consequences that extend well beyond a delayed shipment.

Encryption products and software are controlled under the EU dual-use rules because they have both civilian and potential security applications. The governing instrument is EU Regulation 2021/821, which establishes the Union's export control regime for dual-use items, including cryptographic technology. Most commercial encryption falls within a defined category of the EU's export control list; whether a licence is required depends on the item's technical parameters, the destination, and the end-user. Some transfers benefit from a Union General Export Authorisation, removing the need for a case-by-case licence, but only where strict conditions are met.

This guide sets out the classification test, the licence and authorisation options, the cross-regime picture, the most common compliance failures, and the practical steps an exporter should take before any transfer of encryption technology leaves the EU.

What governs encryption export controls in the EU?

The EU dual-use regulation – currently EU Regulation 2021/821, as currently in force, verify before reliance – is the primary legal instrument governing the export of dual-use items from EU member states, and encryption technology sits squarely within its scope. The regulation replaced and updated an earlier regime and introduced a more explicit technology-neutral approach to emerging and sensitive technologies, including advanced cryptography.

The regulation is administered at the member-state level: each EU country designates its own competent authority, which processes applications, issues licences, and enforces the rules within its territory. In Germany that authority is the Federal Office of Economics and Export Control; in France it is the Directorate General of Customs; in the Netherlands, the Central Import and Export Office. The European Commission maintains an advisory and coordination role, and the Dual-Use Coordination Group brings member-state authorities together to harmonise practice. But a licence granted by one member state is not automatically recognised across the Union for all purposes. Exporters operating from multiple EU locations must verify the position in each relevant jurisdiction.

The legal basis for the specific controls on encryption sits in the Annex to the regulation – the EU's export control list. This list mirrors, to a significant degree, the Wassenaar Arrangement's List of Dual-Use Goods and Technologies. The relevant category covers information security items, including cryptographic equipment, software, and technology. Classification within that category determines what controls apply and what authorisations may be available.

How does the classification test work for encryption products?

Classifying an encryption product is the first and most consequential step: if an item does not fall within the controlled category, no export licence is required, and a business that self-classifies incorrectly – in either direction – creates either unnecessary cost or undisclosed compliance exposure.

The classification analysis turns on technical parameters. The key questions are whether the product uses cryptographic functionality beyond certain defined performance thresholds, whether that functionality is the primary purpose of the product, and whether the product is designed for or marketed to users in a way that could enable security or intelligence applications. Mass-market encryption products that meet specific criteria – available to the public, not specially designed for military or government use, with no unusual access to cryptographic parameters – may fall within a decontrol or a simplified authorisation pathway. The EU regulation preserves a carve-out for mass-market items, but its conditions are technical and specific, not simply commercial.

In our cross-border practice, a significant proportion of classification errors arise not from misreading the technical threshold but from failing to review a product after an update. A software release that adds a new encryption module, changes key-length parameters, or enables end-to-end encryption for a category of users can push a previously non-controlled item into a controlled category. Product development and compliance must run in parallel, not sequentially.

Once a product is classified, the exporter must determine the correct entry on the EU control list. Items classified within the information security category carry an alphanumeric reference. That classification should be documented in the exporter's internal records and reviewed periodically. The classification also drives the choice of authorisation route – general, global, individual, or no licence required.

What authorisation routes are available?

For most commercial encryption products, the EU regime provides a Union General Export Authorisation ("UGEA") that eliminates the need for a case-by-case individual licence where the destination country and the end-user meet the conditions specified in the UGEA. This is the principal mechanism that makes routine commercial transfers of encryption software practicable at scale, without a per-shipment application to the competent authority.

The UGEAs are set out in Annex II of the regulation. There are several UGEAs; the one most relevant to encryption technology covers exports to a defined list of destinations considered lower-risk. The exporter must register with the competent authority in its member state before using a UGEA for the first time, keep full records of all transfers made under it, and comply with any specific conditions attached to the UGEA – which may include reporting obligations and end-user undertakings. The registration requirement varies by member state in its mechanics, but the obligation to register and to maintain records is uniform across the EU.

Where the UGEA does not cover the destination – because the country is not on the list, or because the end-user or end-use falls outside the UGEA's scope – the exporter must apply for an individual licence or a global licence. An individual licence covers a specific item, a specific end-user, and typically a defined value or quantity over a defined period. A global licence covers multiple consignees in multiple destinations, subject to conditions, and is better suited to exporters with high-volume recurring transfers.

The standard individual licence application requires: a precise description of the item and its classification reference, the technical parameters, the end-user statement, information on the intended end-use, and evidence of due diligence on the consignee and any intermediaries. Competent authorities may request additional information. Processing times vary by member state and by the complexity of the case; a straightforward commercial application to a lower-risk destination is typically decided more quickly than one involving a novel technology or a destination that requires additional review. Exporters should build licence lead times into commercial timetables.

The position above covers the standard case. Your specific product, destination, and end-user – and the applicable authorisation route – require a fact-specific assessment. For an initial review of your encryption classification and authorisation position, contact Calder & Vance at info@caldervance.com.

How does the EU approach differ from the US and UK regimes?

Businesses that export encryption technology from or through multiple jurisdictions must manage a layered and sometimes divergent set of controls. The EU, the United States, and the United Kingdom each maintain their own encryption export controls, and the differences are material.

In the United States, encryption items are primarily controlled under the Export Administration Regulations (the "EAR"), administered by the Bureau of Industry and Security ("BIS"). US controls on encryption have historically been among the most detailed globally. The EAR uses the Export Control Classification Number ("ECCN") system; encryption items carry specific ECCNs under Category 5, Part 2. The US regime includes a technology review process for encryption products, and some items require a one-time review submission before they can be exported under a licence exception. BIS also maintains the Entity List and other restricted-party lists that interact with encryption licensing decisions.

A critical point for EU-based businesses is the reach of US controls through the de minimis rule and the foreign-direct-product rule. Where EU-manufactured encryption software incorporates US-origin cryptographic code or is produced using certain US equipment or technology, BIS may assert jurisdiction over that item even when it is exported by a non-US person from a non-US territory. We regularly advise EU exporters who have assumed the EAR does not apply to their products, only to find that a US-origin software library embedded in their stack brings the product within US jurisdiction.

In the United Kingdom, encryption export controls sit within the UK's Strategic Export Licensing regime, administered by the Export Control Joint Unit ("ECJU"). Since the UK's departure from the EU, the UK has maintained a control list closely aligned with the Wassenaar Arrangement, and the UK's approach to encryption mirrors in broad outline what the EU requires. However, the UK's general export licences have different terms and different destination coverage from the EU's UGEAs, and an exporter relying on a UGEA for transfers from an EU member state cannot assume the same authorisation covers transfers from the UK. For businesses with operations in both jurisdictions, a dual-compliance framework is necessary.

There is also the question of secondary-sanctions risk. Where encryption technology is destined for, or capable of diversion to, a jurisdiction subject to comprehensive US or EU sanctions, the export-control analysis intersects with sanctions law. A licence under the EU dual-use regulation does not override a sanctions prohibition, and vice versa. The two bodies of law operate independently; both must be satisfied before a transfer proceeds.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For advice on a specific export-control or licensing matter, contact us at info@caldervance.com.

What are the risk flags exporters consistently miss?

In our experience advising exporters across multiple EU jurisdictions, the same risk patterns recur. Identifying them early is the most cost-effective form of compliance management.

The first is the re-export and transit question. An item exported from an EU member state to a distributor in a third country may subsequently be re-exported to a further destination. EU export controls attach an end-use and end-user obligation to the original transfer. If the distributor re-exports to a destination or user that would not have been licensable under the original authorisation, the EU exporter may face questions about due diligence and whether it knew or suspected the onward movement. The UGEA and individual licences both contain conditions about known or anticipated re-export; exporters must not treat a first-leg licence as unconditional permission for subsequent movement of the item.

The second is the deemed export question. A deemed export occurs when controlled technology is transferred to a foreign national within the territory of the exporting country, rather than physically shipped abroad. EU Regulation 2021/821 includes a specific provision on intra-EU and external technology transfers by non-tangible means, including cloud transfer, remote access, and oral transmission. A software company that provides a foreign national employee with access to its encryption codebase may be effecting a deemed export. This is an area where EU practice is developing, and national competent authorities have begun to apply it more actively. Have you mapped your remote-access architecture for deemed export risk?

The third is the catch-all control. EU Regulation 2021/821 introduced an enhanced catch-all mechanism. Where an exporter knows or has been informed by its competent authority that an item – even one not listed in the Annex – is or may be intended for use in connection with certain end-uses of concern, the exporter is required to apply for a licence. Encryption technology with potential intelligence applications could fall within this mechanism if facts emerge about the end-user's activities. The catch-all is not a theoretical residual; it has been applied in practice, and it requires exporters to maintain active due diligence on end-users throughout the transaction lifecycle, not only at the outset.

The fourth is internal compliance governance. Many businesses have a classification and licensing process but lack a mechanism to feed product-development changes back into the export compliance team. A new encryption feature released in a product update, a new OEM arrangement that embeds a third-party encryption module, or a new sales channel into a previously unlicensed territory can each trigger new control obligations. Regular review cycles – not one-time classification assessments – are the standard of care that competent authorities expect.

A practical compliance sequence for EU encryption exporters

The following sequence sets out the steps an exporter should work through before any transfer of encryption technology from an EU member state. It is not exhaustive; specific products and destinations may require additional steps.

  1. Classify the item. Determine whether the encryption product or software falls within the EU's export control list. Document the technical parameters, the relevant list entry, and the rationale for the classification. Review the classification whenever the product is updated.
  2. Screen the destination and end-user. Check the destination country against the UGEA destination lists and against the EU and UN sanctions lists. Screen the end-user and any known intermediaries against all applicable lists, including the EU Consolidated List and the UN Consolidated List. For US-origin content, screen against US denied-parties lists as well.
  3. Determine the authorisation route. If a UGEA applies, verify that all conditions are met – destination, end-use, end-user, and any reporting obligations. If a UGEA does not apply, assess whether an individual or global licence is needed and begin the application process in the relevant member state early enough to accommodate processing time.
  4. Register with the competent authority. If you are using a UGEA for the first time, complete the registration with your national competent authority before the transfer.
  5. Obtain the end-user undertaking. For individual licences and certain UGEA uses, a signed end-user statement from the consignee is required. The statement should cover the intended end-use, the commitment not to re-export to unlicensed destinations, and the right of the exporter to conduct post-shipment verification if required.
  6. Assess the deemed export position. Review whether any foreign nationals have access – physical or remote – to the controlled encryption technology. Document the assessment and, where access exists, determine whether a separate authorisation is required.
  7. Maintain and retain records. EU Regulation 2021/821 requires exporters to keep records of all export transactions for a defined period. Records should include the classification rationale, the authorisation used or applied for, the end-user undertaking, and the shipping and payment documentation. National implementing rules may specify additional requirements.
  8. Run a cross-regime check. Confirm that the US EAR and UK export-control position have been assessed where US-origin content is present or the exporter has UK operations. Confirm that no sanctions prohibition applies independently of the export-control authorisation.

This sequence applies to the standard commercial case. Where the encryption product is novel, the destination is higher-risk, or the end-user is a government or military entity, additional diligence and a pre-submission dialogue with the competent authority are advisable.

A common misconception about EU encryption controls

A frequently encountered assumption is that mass-market or widely available commercial encryption products are automatically exempt from EU export controls. The reasoning is intuitive: if the same product is available for download from any public repository, what purpose does an export licence serve? This assumption is wrong, and acting on it creates real liability.

The mass-market decontrol in the EU regulation is a defined set of conditions, not a general principle of commercial availability. A product that meets all the technical and commercial conditions for the decontrol is indeed not controlled. But many commercial encryption products – including products sold off-the-shelf to businesses – do not satisfy every condition. Strong encryption with configurable parameters, products sold under commercial licence to professional or enterprise users, and products with an administrative unlock for cryptographic access are examples that may fall outside the mass-market decontrol even though they are commercially available. The label "commercial" does not perform the legal analysis; only the technical and condition-by-condition assessment does.

We regularly advise businesses that have been operating on the mass-market assumption and discover on a compliance review – or on a regulatory enquiry – that the assumption was not warranted. The remediation path in those cases involves a retroactive classification exercise, an assessment of past transfers, and in some cases a voluntary disclosure to the competent authority. Early advice prevents that sequence.

Related practices

Frequently asked questions on EU encryption export controls

What are the steps to manage encryption export controls under EU?

The core steps are: classify the item against the EU export control list, screen the destination and end-user against sanctions and restricted-party lists, determine whether a Union General Export Authorisation applies or an individual licence is needed, register with the national competent authority, obtain the end-user undertaking, assess the deemed export position, and maintain records for the required retention period. A cross-regime check for US EAR and UK controls should run in parallel where US-origin content is present or UK operations are involved. Exporters should embed this sequence into their product-launch and release processes, not apply it retrospectively.

What is the most common mistake in encryption export controls?

The most consistent error is treating the initial product classification as permanent. When a software update adds or modifies encryption functionality, the classification must be reviewed. A product that was non-controlled before the update may become controlled after it. Equally common is relying on the mass-market decontrol without a condition-by-condition technical assessment: commercial availability alone is not a sufficient basis for concluding that a product is decontrolled. Both errors are correctable but become more costly if discovered during a regulatory review rather than an internal audit.

How does EU differ from other regimes here?

The EU dual-use regulation controls encryption at the item level and provides Union General Export Authorisations for lower-risk destinations, reducing the need for individual licences in routine commercial flows. The US EAR applies a technology-review process and a foreign-direct-product rule that can reach non-US products containing US-origin encryption components. The UK regime broadly mirrors the EU in structure but operates independently since 2021, with different general licence terms. All three regimes interact: where US-origin content is present in an EU-produced encryption product, BIS jurisdiction may co-exist with EU controls, and both authorisation requirements must be met before a transfer proceeds.


About the author

Claire Dubois advises on EU sanctions and export controls, including Council-regulation analysis, ownership-and-control questions, dual-use classification, and annulment actions before the EU General Court. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.