Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

Encryption export controls under OFAC: a practical guide

A software company closes a licensing deal with a distributor in a third country. The product includes strong encryption. The compliance team runs the counterparty through screening and finds no direct hit. The export goes ahead. Months later, a review surfaces that the destination country is subject to comprehensive US sanctions – and the encryption product required a licence that was never sought. As of April 2026, encryption export controls under the Export Administration Regulations (EAR – the US Commerce Department rules administered by the Bureau of Industry and Security, "BIS") and the sanctions programmes administered by the Office of Foreign Assets Control ("OFAC") together create one of the most consequential compliance intersections in cross-border technology trade.

Encryption export controls under OFAC involve two distinct but overlapping regulatory regimes: the EAR governs whether the item may leave the United States or be transferred to a foreign national, while OFAC's sanctions programmes can independently prohibit the same transaction by blocking dealings with designated persons, sanctioned territories, or entities owned or controlled by blocked parties. Compliance requires satisfying both regimes simultaneously. Neither a clean OFAC screen nor a valid BIS licence on its own is sufficient.

This guide walks through the key steps for managing encryption export controls in a cross-border business: understanding the two-regime structure, classifying the product, screening the transaction, obtaining any required authorisations, and maintaining the records that regulators will expect to see.

Step 1: Understand the two-regime structure governing encryption exports

Encryption export controls sit at the junction of two separate US regulatory systems, each with distinct legal bases, administering agencies, and enforcement consequences. Understanding that junction is the starting point for any practical compliance programme.

The EAR, administered by BIS, controls the export, re-export, and in-country transfer of dual-use goods and technology, including encryption items. Most encryption products are classified under the Commerce Control List under a specific Export Control Classification Number ("ECCN" – the alphanumeric code on the Commerce Control List that determines which destinations, end-uses, and end-users require a licence). Encryption ECCNs carry controls for national security, anti-terrorism, and crime-control reasons. They also carry specific encryption-reporting and review requirements that other categories do not.

OFAC, a bureau of the US Treasury, administers economic and trade sanctions. Its authority derives principally from the International Emergency Economic Powers Act ("IEEPA"). OFAC prohibitions are transaction-based: they restrict dealings with designated persons (listed on the SDN List – OFAC's list of Specially Designated Nationals and blocked persons), transactions involving sanctioned territories, and dealings with entities that blocked persons own 50 percent or more in the aggregate under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, even if not separately listed).

The two regimes are independent. A transaction that is BIS-clean can still violate an OFAC prohibition. A transaction for which OFAC issues a specific licence may still require a separate BIS licence or the use of a BIS exception. In our cross-border practice, the single most common structural error is treating a clean OFAC screen as the end of the enquiry. It is not.

The position above covers the standard case. Your facts – the product's encryption strength, the counterparty's ownership chain, the destination country, and the intended end-use – change the analysis materially.

For a confidential review of your encryption export exposure, contact Calder & Vance at info@caldervance.com.

Step 2: Classify the encryption item under the EAR

Correct classification of the encryption item under the EAR is the technical foundation of the entire compliance analysis. An item's ECCN determines which authorisations are available and which countries, end-users, and end-uses require a licence.

Encryption items occupy a dedicated section of the Commerce Control List. Classification turns on several technical parameters: the algorithm type, the key length, the intended function, and whether the encryption is mass-market or purpose-built. Mass-market encryption products meeting defined technical criteria may qualify for a streamlined review process, but this does not mean they are uncontrolled. The exporter must still confirm the applicable ECCN, assess whether any exception applies, and – for many encryption products – submit a one-time review request or annual classification report to BIS before using certain licence exceptions.

The EAR also defines deemed exports (the transfer of controlled technology to a foreign national inside the United States, treated as an export to that person's home country). For encryption software and source code, a deemed-export analysis is required whenever a foreign national is given access to the technology, whether as an employee, contractor, researcher, or visitor. This is a dimension that pure OFAC screening entirely misses.

Classification errors compound downstream. An exporter who mis-classifies an encryption item as EAR99 (items subject to the EAR but not listed on the Commerce Control List and therefore not requiring a licence for most destinations) may unknowingly export without a required authorisation to a country or end-user that a correct ECCN would have flagged. Under the EAR, strict liability applies to certain violations: intent is relevant to the severity of the penalty, not to whether a violation occurred.

Our practice regularly advises exporters who discover a classification error after shipments have already occurred. The remediation path – which typically involves a voluntary self-disclosure, a self-classification review, and enhanced controls going forward – is far less costly when started promptly. Have you independently verified the ECCN assigned by your product team or vendor?

Step 3: Screen the transaction against OFAC's sanctions programmes

Once the item is classified, the transaction must be screened against the relevant OFAC sanctions programmes. For encryption products, the key programmes are those covering comprehensively sanctioned territories and designated persons. No BIS licence or exception removes the OFAC prohibition.

OFAC screening for an encryption export involves at least three distinct checks. First, the destination country: OFAC maintains comprehensive sanctions programmes against certain territories. Exports of any goods, including encrypted software and technology, to those territories are generally prohibited without an OFAC licence, regardless of what BIS may otherwise permit. Second, the named parties: the buyer, any identified intermediary, the freight forwarder, the end-user, and the beneficial owners of the purchasing entity must all be screened against the SDN List and other OFAC-maintained lists. Third, the 50 percent rule: screening must extend beyond directly listed persons to entities that blocked persons own in the aggregate at or above the 50 percent threshold.

The ownership-chain question is where most technology exporters run into difficulty. A cloud-software distributor may be wholly clean on its face – no SDN hit, no apparent territorial nexus. But if a designated person holds a significant stake in the distributor's parent, the distributor itself may be blocked under the 50 percent rule, even without appearing on any list. OFAC does not maintain a separate list of 50-percent-rule-blocked entities: the burden falls on the transacting party to conduct its own analysis.

For encryption items with broad distribution (for example, software made available for download), the screening obligation extends to the distributor's customer base in a general sense. OFAC guidance indicates that exporters are expected to use due diligence proportionate to the risk profile of the transaction and the destination.

If a transaction has already been flagged by a screen, or if a filing has been refused, an early review can preserve options that narrow with time.

To discuss a specific OFAC screen result or ownership-chain question, write to info@caldervance.com.

Step 4: Determine which authorisation – BIS licence exception or OFAC licence – applies

Where the classification and screening steps identify a control, the next question is whether an authorisation is available and, if so, which one applies. For encryption exports, BIS and OFAC operate separate authorisation systems that must be addressed in parallel.

Under the EAR, encryption items may be eligible for one or more licence exceptions (standing authorisations in the EAR that permit exports without a case-by-case BIS licence application, subject to conditions). Whether a given exception is available depends on the ECCN, the destination, the end-user, and the end-use. Certain exceptions for encryption items also carry annual self-classification reporting requirements: the exporter must file a classification report with BIS by a defined date each year for products shipped under specified exceptions. Failure to file the required report is itself a violation of the EAR, independent of whether the underlying export was otherwise lawful.

Under OFAC, authorisations take the form of general licences (standing authorisations that permit a defined category of transactions without a separate application) or specific licences (case-by-case authorisations for transactions not covered by a general licence). Certain OFAC sanctions programmes include general licences covering personal communications software, internet-freedom tools, or specific categories of commercially available software, including software with encryption. These are programme-specific and subject to their own conditions; they do not apply uniformly across all OFAC programmes.

Where no general licence applies and the OFAC programme does not prohibit the transaction outright, a specific licence application may be available. OFAC receives and reviews specific licence applications on a case-by-case basis. Timing is not guaranteed. In our experience, well-prepared applications that address the licensing criteria clearly and provide complete supporting documentation proceed more efficiently than those submitted without prior analysis of the available licence policy statements and designating authority.

The interaction between a BIS licence exception and an OFAC general licence is not automatic. An exporter who relies on a BIS exception still needs to confirm independently that OFAC does not prohibit the transaction. Equally, an OFAC general licence covering a category of software does not substitute for the required BIS exception or licence for the same item.

Step 5: Address the cross-regime dimension – UK, EU, and other jurisdictions

The US is not the only jurisdiction controlling encryption exports. A business operating across multiple markets must map its obligations under each applicable regime and identify where the requirements diverge – because where they diverge, the stricter prohibition governs the transaction.

In the United Kingdom, the Export Control Order administered by the Export Control Joint Unit ("ECJU") controls dual-use goods and technology, including encryption items, in line with the UK's national controls following its departure from the EU. Cryptographic items appear on the UK Strategic Export Controls List and are classified according to a national schedule that is substantially aligned with the Wassenaar Arrangement. The ECJU issues open general export licences (standing licences covering defined categories) and individual licences for items or destinations not covered by an open licence. OFSI, the UK financial-sanctions authority, runs separately from the ECJU: a UK exporter must satisfy both regimes, just as a US exporter must satisfy both BIS and OFAC.

In the European Union, dual-use export controls are administered under the applicable EU dual-use regulation. Encryption items are listed on the EU's dual-use control list, also aligned with Wassenaar. Member states issue licences through their national competent authorities. EU economic sanctions, adopted by the Council of the EU, prohibit transactions with designated persons and may restrict exports of certain goods to specific destinations independently of the dual-use controls. For an EU-established business supplying encryption technology to a US-sanctioned counterparty, the EU sanctions analysis is required in addition to – not instead of – the US analysis.

Secondary-sanctions risk adds a further dimension for non-US businesses. Certain OFAC sanctions programmes carry potential consequences for non-US persons who engage in significant transactions with designated parties. An EU or UK distributor re-exporting encryption technology to a sanctioned person risks not only violations under its home regime but also potential exposure to US secondary-sanctions measures. In our cross-border practice, we regularly advise non-US businesses on this exact intersection.

Canada, Australia, Singapore, and Japan each maintain their own export-control regimes covering cryptographic items. These regimes are generally Wassenaar-aligned but differ in their licence structures, exceptions, and enforcement posture. The applicable country regime must be confirmed for each destination, exporter location, and supply chain node. The principle applies consistently: where multiple jurisdictions control the same transaction, the most restrictive requirement sets the floor.

Step 6: Maintain records and monitor for programme changes

Record-keeping is a legal obligation under both BIS and OFAC, not a housekeeping preference. For encryption exporters, it is also the primary evidence base if a question arises later about whether a transaction was properly authorised.

Under the EAR, exporters must retain records of export transactions – including shipping documents, the classification basis, the applicable licence or exception, the end-user and end-use representations, and any BIS correspondence – for five years from the date of export or, for technology, from the date of the last export or re-export. This five-year period is a minimum; a more cautious approach in sectors subject to heightened enforcement attention is to retain records for longer.

OFAC imposes its own record-keeping expectations, and compliance programme documentation – screening records, ownership-chain analyses, licence applications, and general-licence eligibility assessments – should be maintained consistently with those expectations. Where a voluntary self-disclosure ("VSD" – a voluntary report of an apparent violation made to the regulator before it becomes aware through its own investigation) is later necessary, contemporaneous records of the compliance steps taken at the time of the transaction are a central mitigating factor in any penalty assessment.

Encryption export-control rules change. BIS updates the Commerce Control List and the applicable licence exceptions. OFAC amends, revokes, or adds to its general licences within individual sanctions programmes. New SDN designations occur at any time. A product that qualified for a particular BIS exception at launch may not qualify for the same exception after a regulatory update. For encryption products with a long commercial life, annual reviews of the classification, the applicable authorisations, and the current OFAC programme terms are a baseline expectation under any defensible compliance programme.

Does your compliance programme include a scheduled review cycle for the authorisations underpinning your encryption exports, or are you relying on a one-time assessment that may now be out of date?

Step 7: Know the risk flags and when to involve counsel

Certain patterns in encryption export transactions consistently generate elevated risk. Recognising them early is the practical difference between a manageable compliance issue and a significant enforcement matter.

The highest-risk pattern is the multi-hop supply chain: encryption technology exported to a distributor in a low-risk jurisdiction that then re-distributes to customers in sanctioned territories or to sanctioned persons. Under the EAR, re-exports are controlled. Under OFAC, the original US exporter may bear exposure if it knew or had reason to know that the goods were ultimately destined for a prohibited end-user. Robust contractual end-use assurances and supply-chain diligence are the first line of defence.

A second risk flag is source-code access. Encryption source code is itself a controlled item under the EAR, and access to it – whether through a code repository, a development environment, or a remote access arrangement – can constitute a deemed export requiring separate analysis. Companies that use distributed development teams with foreign nationals need a deemed-export assessment for every encryption product in active development.

A third flag is the ownership-complexity risk in the buyer or distributor. Privately held technology distributors in markets adjacent to sanctioned territories often have layered ownership involving investment vehicles across multiple jurisdictions. A single layer of screening that reaches only the direct counterparty is insufficient. The 50 percent rule requires aggregation analysis across the full ownership tree.

Counsel involvement is warranted at several specific points: when a classification produces an ECCN result that carries crime-control or anti-terrorism controls; when an ownership-chain analysis raises questions about potential blocked-person ownership in the buyer; when a BIS exception is being relied on for mass-market qualification and the product has been updated; when a VSD is being considered; and when a transaction has proceeded and a compliance review has identified a potential violation. The timing of VSD filings, in particular, is significant – the procedural and substantive benefits are reduced, and in some cases eliminated, if the apparent violation first comes to OFAC's or BIS's attention through channels other than the company's own disclosure.

Related practices

A common myth: an OFAC-clean screen means the export is permitted

The most persistent misconception we encounter in cross-border technology compliance is that a clean OFAC screening result means a transaction is approved. It does not. OFAC screening addresses only one regulatory regime – the US sanctions layer. It does not address BIS licence requirements, the 50 percent rule analysis beyond directly listed persons, re-export controls, deemed-export obligations, or the requirements of any non-US regime.

A clean SDN-list screen confirms that no directly listed person appears as a counterparty. It says nothing about whether the counterparty's parent is a 50-percent-owned entity of a designated person. It does not confirm that the encryption item has been correctly classified under the Commerce Control List, that the applicable BIS licence exception conditions have been satisfied, or that the annual classification report required for certain exceptions has been filed. And it does not address the UK, EU, or other regime analysis at all.

We have acted for technology businesses that relied entirely on OFAC-screen automation and later discovered significant EAR compliance gaps for the same transaction set. The remediation process – classification reviews, voluntary disclosures, programme redesign – is substantially more demanding than the up-front compliance work would have been.

In a recent matter, a technology company in the payments sector discovered during an M&A diligence process that its encryption software had been distributed under a BIS licence exception whose conditions had not been fully satisfied for several years of shipments. We conducted a transaction-by-transaction classification review, assessed the apparent violations under the EAR's mitigation framework, prepared and submitted a VSD, and assisted the company in designing enhanced classification and exception-monitoring controls. The matter resolved within a defined timeline. No guarantee of outcome was given or could be given, but early action and a well-prepared disclosure were significant factors in the resolution.

Frequently asked questions

What are the steps to manage encryption export controls under OFAC?
Managing encryption export controls under OFAC requires a sequential, two-regime approach. First, classify the encryption item under the EAR to identify its ECCN and the controls that apply. Second, screen all parties and the destination against OFAC's sanctions programmes, including the 50 percent rule ownership analysis. Third, confirm that an applicable BIS licence or exception and any required OFAC authorisation are both in place. Fourth, satisfy any reporting obligations specific to the applicable BIS exception. Finally, maintain records for at least five years and implement a programme to monitor regulatory changes that may affect the authorisations in use.
What is the most common mistake in encryption export controls?
The most common mistake is treating OFAC screening and BIS licence-exception qualification as separate, independent checklists rather than as parts of a single transaction-level analysis. Businesses frequently conduct thorough OFAC screening but apply the wrong ECCN, miss an exception condition, or fail to file the annual classification report required under certain BIS encryption exceptions. The result is a transaction that passes the OFAC screen but is not lawfully authorised under the EAR – or vice versa. Both regimes must be satisfied simultaneously, and each must be addressed with the same care.
How does OFAC differ from other regimes here?
OFAC's primary function is to prohibit transactions with designated persons and sanctioned territories, regardless of the nature of the goods. It does not classify items by technical characteristics the way BIS does. By contrast, BIS controls turn on what the item is – its ECCN, its encryption parameters, its end-use profile. The EU and UK regimes combine both approaches: they classify items (aligned broadly with Wassenaar) and also prohibit dealings with designated persons. Where all regimes apply to the same transaction, each must be independently satisfied. Secondary-sanctions risk under certain OFAC programmes adds a further layer for non-US businesses dealing with US-designated counterparties.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.