A software company preparing to release an encrypted communications platform to enterprise customers in multiple markets runs a routine screening check. The buyer list is clean. But has the team considered whether any customer's country of incorporation triggers OFAC prohibitions – or whether the encryption itself carries a separate export-control obligation that OFAC's sanctions layer compounds? As of April 2026, these two regimes sit side by side in US law, and conflating them is one of the most consistent sources of compliance failure we see.
Encryption export controls under OFAC operate at the intersection of two distinct US regulatory regimes: the Export Administration Regulations (the EAR, administered by the Bureau of Industry and Security) govern whether encrypted items may be exported at all, while OFAC's sanctions programmes impose transaction prohibitions that apply regardless of whether an EAR licence has been obtained. A business that clears BIS classification and obtains the relevant encryption authorisation may still be prohibited from completing the transaction if the end-user or destination is subject to OFAC's comprehensive or targeted sanctions.
This guide walks through the applicable US legal regime, the step-by-step procedure for managing encryption export controls in a sanctions context, the cross-border comparison with the UK and EU positions, the key risk flags practitioners consistently identify, and when to bring in specialist counsel. It is written for compliance officers, General Counsel, and export-control teams at technology businesses, cloud providers, and financial-infrastructure companies exporting encryption-enabled products or technology.
What governs encryption exports from the US – and where does OFAC fit?
Encryption products and technology are controlled under the EAR through the Commerce Control List (CCL), which assigns each item an Export Control Classification Number (ECCN – the unique identifier that specifies the applicable controls and licence requirements for a given item). Encryption items typically fall within the "EI" (encryption items) and "AT" (anti-terrorism) control categories, though the exact ECCN depends on the item's technical parameters and end-use.
OFAC sits alongside the EAR, not within it. Where the EAR asks "may this item be exported?", OFAC asks "may this transaction involve this person or destination?" A US person exporting encryption software must satisfy both tests independently. The EAR licence – or a licence exception such as ENC – authorises the export in technical terms. It provides no cover for sanctions exposure. OFAC's prohibitions under IEEPA and TWEA apply to the transaction regardless of the BIS position.
In our cross-border practice, the separation of these two gatekeepers is the first point we establish with clients. A clean EAR classification review and an encryption registration do not substitute for an OFAC transaction screen. Teams that treat a completed BIS review as an all-clear for the deal routinely miss the second step.
Step 1 – Classify the item and identify the applicable EAR controls
Before any OFAC analysis is possible, the exporter must determine whether the item is subject to the EAR and, if so, what its ECCN is. An item with no ECCN is classified "EAR99" and carries no licence requirement unless destined for a sanctioned destination or a party on a restricted-party list. Encryption items, however, are rarely EAR99.
The classification exercise turns on technical specifications: key length, algorithm, whether the cryptographic functionality is the primary feature, and whether the item meets the definition of "mass-market" encryption under the applicable EAR provisions. Mass-market products satisfying those criteria may qualify for the ENC licence exception after a one-time review submission to BIS. Non-mass-market items, or those designed for government end-use, will require a more detailed licensing analysis and potentially a formal EAR licence application.
The practical output of Step 1 is a written classification memo. Without a documented ECCN determination, the exporter cannot know which licence exceptions are available, which EAR controls attach, or what the item's interaction with OFAC's sanctions layers will be. We regularly advise exporters who have shipped encryption products for years without a documented classification. When an OFAC review is triggered – by a new customer, a corporate acquisition, or an enforcement inquiry – the absence of that record creates a significant gap in the compliance record.
Step 2 – Screen the transaction against OFAC's sanctions programmes
Once the EAR classification is established, the transaction must be screened against every active OFAC sanctions programme that could apply. OFAC administers both comprehensive sanctions (which prohibit virtually all transactions involving a particular country or territory) and targeted or list-based sanctions (which prohibit transactions involving specific designated persons, wherever located).
For encryption exports, the relevant OFAC analysis covers three layers.
- Destination: Is the end-user country subject to comprehensive or partial OFAC sanctions? Certain destinations are subject to near-total prohibitions; others are subject to targeted measures only.
- End-user and intermediate parties: Does any party to the transaction – buyer, distributor, reseller, freight forwarder, financial institution processing payment – appear on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or on any other OFAC-administered list?
- Ownership and control: Does the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) capture any counterparty that did not appear on a list in its own name?
This three-layer screen must be run at the time of the transaction and re-run if the transaction extends over time, if the counterparty structure changes, or if there are amendments to relevant OFAC designation lists. Screening once at contract signature and not again at delivery is one of the most common procedural failures we encounter. Have you mapped the full downstream distribution chain, or only the immediate buyer?
Step 3 – Assess whether an OFAC licence or authorisation is available
Where screening identifies a potential OFAC conflict, the next question is whether a general licence (a standing authorisation that permits a defined category of transactions without a separate application) or a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is available.
OFAC has issued general licences in various sanctions programmes that authorise the export or re-export of certain internet-based communications services and related software – including, in some programmes, certain encryption-enabled personal communications tools. The scope and conditions of these authorisations differ materially by programme; the existence of a general licence in one programme does not mean an equivalent authorisation exists in another. Checking the wrong programme's general licences is a recurrent error.
Where no general licence applies, a specific licence application to OFAC may be the available route. The application process requires a detailed description of the transaction, the parties, the goods or technology, the end-use, and the policy basis for the requested authorisation. Timelines for OFAC specific-licence decisions are not fixed by statute and vary considerably by programme and by the complexity of the matter. In our experience, applicants who submit complete, well-structured applications with clear policy arguments receive decisions materially faster than those who submit bare-bones requests. Poorly prepared applications are returned for additional information, which restarts the clock.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the sanctions programme in play – change the analysis materially. For a preliminary assessment of whether a licence route is available, contact Calder & Vance at info@caldervance.com.
Step 4 – Manage encryption-specific EAR licensing and complete the transaction record
Assuming the OFAC screen is clear and any required OFAC authorisation is in place, the parallel BIS/EAR obligations must be completed. For encryption items qualifying for the ENC licence exception, this typically requires a one-time BIS submission and, in some cases, annual reporting. The EAR also imposes record-keeping obligations on exporters; records must be maintained for five years from the date of the export, re-export, or other transaction.
The transaction record should integrate the ECCN determination, the licence or exception used, the end-user screening results, any OFAC authorisation obtained, and any end-use documentation collected from the buyer. A fragmented record – where the BIS file and the OFAC file are maintained separately and neither references the other – complicates any subsequent review and creates unnecessary exposure if an enforcement inquiry is opened.
Where the encryption export involves a deemed export – the release of controlled technology to a foreign national inside the United States, which is treated as an export to that person's home country – the BIS analysis and the OFAC screening obligation both apply. Deemed-export risks are a frequent blind spot for technology businesses hiring internationally. Our team regularly advises on the intersection of the EAR's deemed-export rules and OFAC's sanctions programmes; for a detailed treatment of that topic, see our guide on deemed export and technology controls under BIS and the EAR.
How do the UK and EU encryption export-control regimes compare with OFAC's approach?
Cross-border comparison is essential for any business exporting encryption products from or through the UK or European Union alongside the United States. The regimes share a common concern with encryption as a dual-use category but diverge significantly in structure, administration, and ownership-and-control tests.
In the United Kingdom, encryption products are controlled as dual-use items under the Export Control Order. OFSI administers UK financial sanctions under SAMLA and the relevant thematic regulations; the ECJU administers export licensing. The UK's ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) extends beyond the mechanical 50 percent ownership threshold used by OFAC and captures entities that a designated person controls through other means – including through board representation or contractual authority. This means a transaction that passes OFAC's ownership screen may still be caught under OFSI's broader control test. For a detailed treatment of the UK position, see our guide on encryption export controls under OFSI.
In the European Union, encryption falls within the EU dual-use regulation. The EU's sanctions ownership-and-control test similarly goes beyond a mechanical percentage and turns on whether a designated person is able to exercise significant influence over the entity. The practical gap between OFAC's 50 percent rule and the EU/UK control test matters when an entity is, say, 40 percent owned by a designated person who also holds governance rights. OFAC's test is not triggered; the EU and UK tests may well be.
For businesses exporting through the UAE, Singapore, or Japan, the applicable country regime imposes its own controls on dual-use and encryption items; those regimes are increasingly aligned with international standards but differ in procedure and enforcement posture. Our guide on encryption export controls in the UAE covers the UAE position in detail.
The cardinal cross-border principle is this: where two or more regimes apply, the stricter prohibition governs. Clearing the US position does not clear the UK or EU position. Clearing all three does not relieve the exporter of obligations under the applicable country regime at destination.
Common risk flags and mistakes in encryption export-control compliance
Certain failure patterns appear with regularity across encryption export-control matters. Identifying them in advance is more efficient than correcting them after a regulatory inquiry.
- Treating BIS clearance as an OFAC clearance. An EAR licence or a BIS encryption registration authorises the export for EAR purposes. It has no bearing on OFAC's transaction prohibitions. These are independent requirements.
- Screening only direct counterparties. The 50 percent rule aggregates holdings of blocked persons across an ownership chain. A distributor that appears clean in a direct screen may be indirectly owned or controlled by a blocked person at a deeper level. Screening must reach the ultimate beneficial owner.
- Applying the wrong general licence. OFAC operates multiple sanctions programmes, each with its own set of general licences. A general licence in one programme does not transfer to another. Cloud and SaaS businesses that assume a general licence covering personal communications in one programme covers their enterprise product line in a different programme are routinely wrong.
- Failing to re-screen on renewal or update. A multi-year software licence agreement or a recurring cloud subscription signed when all parties were clean may later involve a counterparty that is subsequently designated. Sanctions exposure runs from the date of the new designation; the prior clean screen provides no protection going forward.
- Ignoring deemed-export exposure. Technology businesses that employ foreign nationals and grant them access to controlled encryption source code have a deemed-export obligation. Many do not recognise this until an acquisition due diligence review surfaces the gap.
- Incomplete transaction records. A voluntary self-disclosure (VSD – a self-initiated report of an apparent violation to a regulator) to OFAC or BIS is evaluated in part by reference to the quality of the compliance programme. Incomplete or fragmented records undermine the mitigating value of a VSD.
If a transaction has already been flagged, or a BIS or OFAC inquiry has been received, an early review can preserve options that close quickly. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.
A common myth: obtaining a BIS encryption registration means the export is approved
We encounter this misconception regularly among technology clients who have invested significant effort in the BIS encryption-review process. The myth runs as follows: "We completed our BIS registration and received confirmation. Our encryption export is approved."
It is not accurate. BIS confirmation means the item satisfies the conditions of the relevant EAR licence exception for encryption. It addresses the export-control classification question under the EAR. It does not address, and cannot address, whether OFAC's sanctions prohibitions apply to the specific transaction, counterparty, or destination in question. These are separate legal questions with separate governing regimes and separate legal consequences for non-compliance.
The same myth appears in reverse: businesses that obtain an OFAC general-licence authorisation for internet communications software sometimes assume this clears their BIS obligations. Again, the regimes are independent; each must be satisfied on its own terms.
In our practice, we routinely find that technology businesses have completed one half of the required analysis thoroughly and the other not at all. The cost of correcting that gap after an enforcement inquiry is substantially higher than the cost of integrating both reviews at the outset.
Related practices
- Deemed export and technology controls under BIS and the EAR – classification, licence exceptions, and end-use controls for technology exporters
- Encryption export controls under OFSI – UK financial-sanctions and ECJU export-licensing obligations compared with the US position
- Encryption export controls in the UAE – applicable country regime, dual-use obligations, and cross-border considerations for UAE-connected transactions
Frequently asked questions on encryption export controls under OFAC
What are the steps to manage encryption export controls under OFAC?
The procedural sequence runs in four stages: first, classify the encryption item under the EAR and determine its ECCN; second, screen all transaction parties and the destination against OFAC's sanctions programmes, including the SDN List and the 50 percent rule; third, identify any applicable OFAC general licence or apply for a specific licence if required; and fourth, complete any BIS encryption-registration or reporting obligations and assemble a unified transaction record covering both the EAR and OFAC reviews. Both regimes must be satisfied independently before the transaction proceeds.
What is the most common mistake in encryption export controls?
The single most consistent error is treating a completed BIS encryption registration or EAR licence determination as an all-clear for OFAC purposes. The two regimes are independent: BIS governs whether the item may be exported; OFAC governs whether the transaction may involve the specific counterparty or destination. A clean BIS file provides no protection against an OFAC violation. The second most common error is screening only direct counterparties and missing blocked-person ownership at deeper levels of the ownership chain, which the 50 percent rule captures regardless of whether the entity appears on any list directly.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: 50 percent or more aggregate ownership by blocked persons triggers blocking, without reference to control or intent. The UK's OFSI and the EU apply a broader ownership-and-control test that can capture entities below the 50 percent threshold where a designated person exercises control through governance or contractual rights. Additionally, OFAC and BIS are entirely separate US regulatory bodies with separate legal bases and separate enforcement mechanisms; the UK and some other jurisdictions administer export licensing and financial sanctions through different agencies with closer procedural alignment. For any cross-border transaction, the most restrictive applicable regime governs.
About the author
J. M. Aldridge advises multinationals and financial institutions on US sanctions and export controls, with a focus on OFAC licensing, secondary-sanctions risk, and BIS classification. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.