A technology exporter preparing to ship cryptographic software to a customer in the Asia-Pacific region discovers mid-transaction that Japan's export-control rules apply – not only to physical goods crossing the border, but also to technology transmitted electronically. The licensing question was not flagged at the deal stage. Now the clock is ticking, and the shipment cannot move until the classification is confirmed and any required authorisation is in hand.
Japan regulates the export of encryption goods and technology through the Foreign Exchange and Foreign Trade Act, administered by the Ministry of Economy, Trade and Industry. Whether a specific licence is required depends on the item's cryptographic specification, its destination, and its end-use. For most commercial encryption products destined for ordinary business use, a streamlined route exists – but the classification step cannot be skipped, and the consequences of getting it wrong include criminal liability for individuals.
This guide walks through the classification and authorisation process step by step, identifies the most common risk points, and compares the Japanese regime with the US, UK, and EU approaches where the rules diverge in ways that matter to cross-border businesses.
Step 1: Understand the governing authority and legal basis
Japan's encryption export controls sit within the broader dual-use export-control regime established under the Foreign Exchange and Foreign Trade Act, commonly known as FEFTA. The Ministry of Economy, Trade and Industry administers the regime through its Trade and Economic Security Bureau, and the relevant instrument is the Export Trade Control Order, which incorporates the Foreign Exchange Order's annexures listing controlled items.
Japan is a member of the Wassenaar Arrangement, the multilateral export-control regime that covers conventional arms and dual-use goods and technologies, including encryption. Japan's control lists are substantially aligned with the Wassenaar Arrangement's technical parameters, which means that items controlled in the United States under the Export Administration Regulations, or in the European Union under the dual-use regulation, will typically trigger classification review in Japan as well. This alignment is important for businesses managing multi-jurisdictional shipments: a single product may require simultaneous classification under the EAR, the EU rules, and FEFTA.
The fundamental question under FEFTA is whether the item falls within the relevant annex of the Export Trade Control Order. Encryption products are captured primarily through the dual-use annex, which mirrors the Wassenaar Arrangement's Category 5 Part 2 controls. If the item does not appear in that annex, it may still require a catch-all review if the exporter has reason to know the item could contribute to weapons of mass destruction programmes or conventional arms – but for commercial encryption, the annex-based classification is the starting point.
Step 2: Classify the item against the Japan control list
Classification is the first operative decision in every Japan encryption export transaction. The exporter must determine whether the cryptographic functionality of the product – its key length, algorithm, mode of operation, and whether it is designed for general-purpose use or for a specific application – places it within the controlled categories of the Export Trade Control Order.
Japan's dual-use annex classifies encryption goods using technical parameters consistent with the Wassenaar Arrangement. Symmetric key cryptography with key lengths above a defined threshold, asymmetric systems meeting certain specifications, and products with cryptanalysis functions are the primary capture points. The classification is item-specific and cannot be assumed from prior classification under another regime, even though the technical parameters are similar across Wassenaar-aligned systems.
In our experience, the classification step is where multi-regime transactions most commonly stall. A product that has been self-classified under the US Commerce Control List – assigned an ECCN (Export Control Classification Number under the US Commerce Control List) in Category 5 Part 2 – is a strong indicator that a Japanese classification review is also required. But the reverse is not always true: Japan's annexure structure and the specific technical definitions in the domestic implementing instruments can produce different outcomes from the US or EU classification for the same product. Relying on a US or EU classification without a Japan-specific review is a common source of exposure.
The practical classification process involves three steps. First, identify the cryptographic specification of the product from the technical documentation. Second, compare that specification against the annex parameters in the Export Trade Control Order. Third, document the classification outcome and the basis for it. Where the specification is genuinely ambiguous – for example, because the product is a multi-function platform with encryption as one component – a pre-shipment enquiry to METI is available and, in our practice, advisable.
Step 3: Determine the destination and end-use profile
Once the item is classified as controlled, the next analytical layer is the destination and end-use matrix. Japan's export-control rules, like those of its Wassenaar Arrangement partners, operate a tiered destination system. Destinations regarded as presenting lower proliferation risk attract more streamlined authorisation routes; destinations presenting higher risk require individual licence review.
Japan maintains a list of countries that qualify for a general bulk licence known as the "white country" or favourable-treatment list. Exports to these destinations of items that meet certain criteria can proceed under a simplified authorisation rather than an individual specific-licence application. The favourable-treatment destinations broadly correspond to Japan's close trading and security partners – members of the Wassenaar Arrangement and allied nations. Exports to destinations outside that list, or exports of items that do not meet the criteria for the simplified route even to favourable destinations, require individual authorisation.
End-use is equally important. Military end-use, or end-use by a party of concern (a restricted end-user under the METI catch-all list), can trigger licence requirements even for items or destinations that would otherwise qualify for a streamlined route. The exporter must screen the end-user against METI's lists and must obtain and retain credible end-use documentation. What does adequate end-use documentation look like in practice? At minimum, a signed end-user statement identifying the specific application, the location of use, and the identity of the ultimate user – checked against the relevant restricted-party lists before the shipment departs.
Step 4: Select the authorisation route
Japan offers several authorisation routes for controlled encryption exports. The individual export licence is the baseline route: a specific application to METI for authorisation to export a defined item to a defined consignee. Processing times for individual licences vary depending on the item's sensitivity and the destination, but applicants should plan for several weeks and should not treat a pending application as equivalent to a granted licence.
For qualifying transactions, METI operates general bulk licences that cover categories of items to categories of destinations without requiring a transaction-by-transaction application. The Special Bulk Export Licence and the General Bulk Export Licence are the principal instruments. Eligibility depends on the exporter establishing an internal compliance programme that meets METI's specified requirements – a documented classification procedure, a training regime, an end-use monitoring system, and record-keeping to prescribed standards. The compliance programme must be assessed and, depending on the licence type, independently audited.
The compliance-programme-based route is attractive for volume exporters but requires upfront investment and ongoing discipline. We regularly advise clients that the real cost of a general bulk licence is not the application fee but the sustained programme management. Missing an audit cycle, failing to update the classification database when the control list changes, or allowing end-use monitoring to lapse can result in suspension or revocation of the licence – with consequences for all in-scope shipments, not just the one that triggered the review.
A third route applies to certain mass-market encryption products. The Wassenaar Arrangement includes a mass-market exception for encryption goods that are generally available to the public and that cannot reasonably be restricted. Japan has implemented a corresponding simplified treatment for qualifying mass-market items. Whether a product meets the mass-market criteria requires analysis of its distribution channel, the absence of proprietary encryption, and the degree to which the cryptographic functionality has been customised for specific end-users.
Step 5: Prepare and submit the application
An individual export licence application to METI must include the technical specification of the item, the commercial documentation for the transaction (invoice, contract), the end-user statement, and any additional supporting information METI requires based on the item category and destination. Applications are submitted through METI's electronic system.
The quality of the technical specification is the single most influential variable in processing time. An incomplete or ambiguous specification triggers supplementary information requests, which pause the clock and can add significant delay. In a recent matter, a software company experienced repeated supplementary requests because its specification described the encryption module at the application layer without providing the underlying cryptographic parameters. Once the specification was restructured to address those parameters directly, the licence was granted without further queries.
The end-user statement must be sufficiently specific. A generic statement that the buyer will use the product "for internal IT purposes" is unlikely to satisfy METI's requirements for a sensitive item or a non-favourable destination. The statement should identify the business activity, the specific system into which the encryption will be integrated, and the physical location of deployment. For cloud-based products, where the physical location of processing is distributed or variable, additional explanation of the technical architecture may be necessary.
Record-keeping requirements under FEFTA are significant. Exporters must retain all licence applications, supporting documents, end-user statements, and shipping records. Verification of current retention periods before relying on any figure stated here is essential, as the requirement can extend for a number of years after the transaction. The record-keeping obligation applies to all controlled exports, including those made under general bulk licences, and METI has authority to inspect records during a compliance review.
Step 6: Manage post-export obligations and ongoing compliance
The export licence is not the end of the compliance obligation. Post-export duties under the Japan regime include record retention, end-use verification for sensitive items, and reporting obligations if circumstances change after the licence is granted. If the exporter becomes aware that the item has been diverted to an unlicensed end-user or an unauthorised destination, a reporting obligation arises and the matter requires immediate legal review.
The catch-all rule under FEFTA is an ongoing consideration. Even after an item has been exported under a valid licence, the exporter's compliance programme should include mechanisms to detect post-shipment red flags – enquiries about re-export destinations, requests for technical assistance inconsistent with the stated end-use, or information suggesting the original end-user has transferred the technology. The catch-all rule can apply to re-exports by the original buyer, and in some circumstances METI can look to the original exporter's knowledge and due diligence when assessing liability.
Annual internal audits of the classification database are advisable. The Wassenaar Arrangement updates its control parameters periodically, and Japan implements those updates through amendments to the Export Trade Control Order. A product classified as EAR99 or its Japanese equivalent in one review cycle may become controlled in the next if the technical parameters tighten. We have acted for clients who discovered mid-shipment-run that a product that had been shipping under a simplified route for two years had become individually controlled following a control-list amendment.
How Japan's encryption controls compare with the US, UK, and EU regimes
Japan's regime is Wassenaar-aligned but differs from the US, UK, and EU approaches in several operationally significant ways. Understanding those differences is essential for any business managing parallel compliance obligations across these regimes.
Under the US EAR, encryption items classified under ECCN 5E002 or 5D002 are subject to the EAR's encryption review framework, which includes a self-classification reporting requirement and the possibility of a review by the Bureau of Industry and Security. The US regime also applies extraterritorially through the de minimis and foreign-direct-product rules, meaning a Japanese-origin product incorporating a threshold percentage of US-controlled encryption technology may require US authorisation for onward export. This extraterritorial reach is not present in the Japanese regime in the same form, and the two systems must be managed in parallel rather than treated as alternatives.
The UK's Export Control Order, administered by ECJU, similarly implements the Wassenaar Arrangement controls and uses a broadly comparable classification structure. The UK's Open General Export Licences provide a route broadly analogous to Japan's general bulk licence for qualifying transactions. However, the compliance-programme requirements for UK open general licences differ in detail from METI's requirements, and a compliance programme built for the Japan regime may not satisfy ECJU without adaptation.
The EU dual-use regulation, which applies to EU-based exporters and to re-exports from EU territory, includes the Wassenaar Category 5 Part 2 controls and provides for general export authorisations for certain destinations. The EU regime has introduced changes to its dual-use rules in recent years, including expanded controls on cyber-surveillance technology, that go beyond the Wassenaar baseline in some respects. A business exporting from both Japan and an EU member state needs to manage both sets of controls, which may produce different authorisation requirements for the same product shipped from different originating locations.
The cross-regime point that most frequently surprises in-house teams is the treatment of cloud-based encryption services. Under the Japan regime, the provision of technology via electronic means – including cloud-hosted cryptographic services accessed by a foreign customer – is treated as a deemed export and is subject to the same classification and authorisation analysis as a physical export. The US EAR similarly captures technology "releases" to foreign persons as deemed exports. Both the UK and EU regimes include comparable concepts. The practical implication is that a software-as-a-service business offering encryption capability to overseas customers cannot assume that the absence of a physical shipment means no licence is required. This is a point where involvement of export-control counsel at the product-design stage, rather than at the shipping stage, can prevent a structural compliance gap.
For guidance on the US EAR dimension of encryption exports, see our analysis at Deemed Export Technology – BIS/EAR, which covers deemed-export obligations for technology and software under the US regime. For OFAC's treatment of encryption-related transactions and the licensing considerations under US sanctions, see Encryption Export Controls – OFAC Guide and Encryption Export Controls – OFAC Guide (Part 2).
Risk flags and when to involve counsel
Several fact patterns should prompt immediate review by export-control counsel rather than a self-classification exercise. The first is any transaction where the end-user or destination has appeared on a restricted-party list or is subject to a catch-all inquiry from METI or another authority. The second is any transaction where the customer has asked for technical assistance that goes beyond the licensed scope – for example, requests for source code access, requests to modify the cryptographic parameters, or requests to integrate the product into a system whose description is inconsistent with the stated end-use.
The third risk flag is a re-export inquiry. If a customer in a favourable destination asks about shipping the product on to a third country, the exporter needs to assess whether that re-export would itself require a Japanese licence, and whether the original end-user undertaking covered that scenario. FEFTA's reach can extend to re-exports facilitated by the original exporter, and the knowledge standard – what the exporter knew or should have known about the likely re-export – is evaluated broadly.
A fourth flag is a change of ownership at the customer. If the end-user company is acquired by an entity on a restricted-party list, or by a party with connections to a programme of concern, the existing end-user documentation may no longer be adequate and the exporter should seek fresh documentation and, where necessary, amended or new authorisation.
Finally, any discovery that an export has been made without the required licence should be addressed promptly and with legal advice. The Japan regime provides for voluntary disclosure to METI in certain circumstances, and in our experience prompt, well-structured disclosure – accompanied by root-cause analysis and a remediation plan – is treated more favourably than a disclosure that follows METI's own inquiry. This is consistent with the approach of analogous voluntary self-disclosure mechanisms under the US EAR and UK export-control rules.
A common misconception among exporters new to the Japan regime is that because Japan is a close partner of the major Western economies, its export-control requirements are essentially the same as the US and EU rules and can be managed with the same compliance programme. That is not correct. While the control lists are broadly aligned through the Wassenaar Arrangement, the authorisation routes, the compliance-programme requirements for general licences, the catch-all formulations, and the enforcement posture differ materially. A compliance programme designed for the EAR requires Japan-specific adaptation before it can be relied upon for FEFTA compliance.
Related practices
- Deemed Export Technology – BIS/EAR – US EAR deemed-export obligations for controlled technology and software releases to foreign persons.
- Encryption Export Controls – OFAC Guide – OFAC licensing considerations for encryption transactions under US sanctions.
- Encryption Export Controls – OFAC Guide (Part 2) – Extended analysis of US encryption-related authorisations and dual-use intersection.