A software company based in the United Kingdom prepares to export an encrypted communications platform to a distributor in a third market. The compliance team assumes that because the product is "just software", it sits outside the export-control regime. That assumption is wrong – and acting on it can expose the business to a criminal prosecution, a denied export privilege, and sanctions-related liability running in parallel. As of April 2026, encryption products remain one of the most consistently misunderstood categories in UK export-control and financial-sanctions practice.
Encryption export controls in the UK are administered primarily by the Export Control Joint Unit (ECJU – the licensing authority within the Department for Business and Trade), not by OFSI (the Office of Financial Sanctions Implementation, which administers financial sanctions). The two regimes interact, however: a proposed export to a sanctioned destination or a sanctioned end-user engages OFSI's prohibitions at the same time as ECJU's licensing requirements. Managing both simultaneously is the core procedural challenge for any exporter of encryption goods or software.
This guide sets out the governing regime, the step-by-step procedure, where the UK position diverges from OFAC, the EU, and other major regimes, the risk flags that practitioners encounter most frequently, and when to involve sanctions and export-control counsel.
Step 1: Understand which regime governs – and why the OFSI/ECJU distinction matters
The first question in any UK encryption export matter is whether the control arises under export-licensing rules, financial-sanctions rules, or both simultaneously. Conflating the two is the most common source of procedural error in our cross-border practice.
ECJU administers the Export Control Order and related instruments. That body determines whether a licence is required to export, transfer, or make available encryption items. The classification of an encryption product – whether it is controlled under the UK's strategic export-control lists, and under which entry – drives the licence requirement. OFSI, by contrast, administers the UK financial-sanctions regime under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations. OFSI's prohibitions are triggered by the identity of the counterparty, not the nature of the goods. If the proposed recipient, or any entity in the chain, is a designated person or is owned or controlled by one, OFSI's rules apply regardless of the product.
The regimes converge when an exporter proposes to ship an encryption item to a destination where OFSI sanctions are in force. In that situation, an ECJU open general export licence may be unavailable, and an OFSI licence may be required before any value is transferred to the counterparty – including payment. An exporter who obtains an ECJU standard individual export licence but fails to address the OFSI dimension is only half-compliant.
Step 2: Classify the encryption item under the UK strategic export-control lists
Before any licence application is prepared, the exporter must determine whether the product is listed and, if so, under which control entry – because that entry dictates the applicable licence conditions, the available exceptions, and the end-use controls required.
UK controls on encryption goods and software are derived from the Wassenaar Arrangement and are implemented through the UK's strategic export-control lists. The classification exercise requires the exporter to assess the product's technical parameters: the algorithm, key length, mode of operation, and whether the encryption function is the primary feature or is embedded in a wider system. Products with a security function that meets the technical thresholds are caught as dual-use items. Items designed or modified for military use engage a separate part of the control list.
One practical difficulty is that many software products acquired off-the-shelf contain encryption functionality that the exporter's team did not design and may not fully understand. In those circumstances, the classification analysis must go to the source code or the vendor's technical specification, not merely the product description. We regularly advise technology companies that discover, mid-transaction, that their platform carries an embedded encryption module that triggers a licence requirement they had not anticipated.
The UK classification list broadly mirrors the EU dual-use controls implemented under EU Regulation 2021/821, but the two lists diverged after the UK's exit from the EU. A product that qualifies for an EU general authorisation may not automatically benefit from the equivalent UK open general export licence. Exporters operating in both markets must run the classification exercise twice.
Step 3: Screen the counterparty and the end-user against OFSI sanctions lists
Classification of the product addresses only the ECJU dimension. The second, parallel step is to screen every party in the transaction – the buyer, the distributor, the ultimate end-user, any freight forwarder, and the financial institution facilitating payment – against OFSI's consolidated list of designated persons and against the UN Consolidated List.
The ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) applies here. Unlike OFAC's 50 percent rule (which treats entities owned 50 percent or more by blocked persons as themselves blocked), OFSI's test adds a control limb. A non-listed entity may be caught if a designated person controls it – through board appointments, veto rights, or contractual arrangements – even where the designated person's shareholding falls below the ownership threshold. That additional limb materially widens the population of potentially prohibited counterparties and is consistently underweighted in automated screening tools calibrated to the OFAC ownership threshold.
The practical consequence is that an exporter whose screening tool flags only direct listings or majority-owned subsidiaries may receive a clear result on a counterparty that OFSI would regard as controlled by a designated person. A manual review of the ownership and governance structure is required when the automated screen produces a result close to, but not quite at, the control threshold.
Record-keeping discipline at this stage is critical. OFSI's enforcement guidance expects that a person who carries out a relevant transaction has documented the screening undertaken, the information relied upon, and the conclusion reached. Failure to maintain that record weakens any subsequent mitigation argument and makes it harder to demonstrate that reasonable steps were taken.
Step 4: Determine which licences are required and apply in the correct sequence
Once classification and screening are complete, the exporter must determine whether the transaction can proceed under an open general export licence or whether a standard individual export licence from ECJU is required, and – separately – whether an OFSI licence is needed to authorise any otherwise prohibited dealing with a designated person or sanctioned entity.
For encryption items, a number of ECJU open general licences are available for exports to approved destinations. If the proposed destination is not covered by an available open general licence, a standard individual export licence application must be submitted to ECJU. ECJU's published service standard provides a target for most standard applications, though complex or sensitive cases take longer. Exporters should not treat any published target as a guarantee.
Where OFSI sanctions are engaged, an OFSI specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) must be sought separately. The grounds on which OFSI will grant a licence are set by the relevant SAMLA-based regulations – they are narrow, and a commercial preference is not a qualifying ground. OFSI's published guidance describes the application requirements: the applicant must set out clearly the nature of the activity, the parties involved, the sanctions ground engaged, and the basis on which the statutory licensing ground is met. Incomplete applications result in delays that can be measured in months.
The ECJU and OFSI applications run on separate tracks and must be submitted to separate authorities. Neither authority will grant its licence conditional on the other authority's approval, but both licences must be in place before the activity proceeds. The sequencing question – which to apply for first – depends on the facts. In our experience, applying to OFSI first is often more efficient in cases involving a sanctions-sensitive counterparty, because the OFSI outcome can inform how the ECJU application is framed.
A decision matrix for the most common situations is set out below.
- Listed destination, controlled encryption item: standard individual export licence from ECJU required; OFSI specific licence required where a designated person is in the chain; both must be obtained before shipment or payment.
- Non-listed destination, controlled encryption item, counterparty with designated person in the ownership chain: open general export licence may be available for ECJU purposes; OFSI licence required because of the control nexus; the OFSI dimension cannot be resolved by the ECJU instrument alone.
- Non-listed destination, controlled encryption item, clean counterparty: open general export licence is the starting point; confirm applicability to the specific product and destination; document the review; keep the record for the statutory period.
- Non-controlled encryption item (following classification), clean counterparty: no ECJU licence required; standard OFSI screening sufficient; document the classification conclusion.
The position above covers the standard cases. Your specific facts – the destination, the counterparty's ownership structure, the product's technical parameters, and the applicable thematic regulations – can alter the analysis materially. For an initial assessment of your position, contact Calder & Vance at info@caldervance.com.
Step 5: Manage end-use obligations and post-shipment record-keeping
Obtaining a licence is the start of the obligation, not the end of it. Both ECJU and OFSI licences typically carry conditions, and breach of a licence condition is itself a criminal or civil offence.
ECJU standard individual export licences for encryption items commonly require the exporter to obtain an end-use undertaking from the consignee – a written assurance that the item will be used only for the purpose stated in the application and will not be re-exported without further authorisation. The quality of that undertaking matters. A form that is signed but not verified is of limited value in a subsequent enforcement review. Where the end-user is an intermediary or distributor, the exporter should consider what steps are proportionate to verify onward use.
For OFSI licences, the conditions will be specific to the terms approved. Where the licence permits a payment to be made, the specific amount, the parties, and the timing will be specified. Any deviation from those terms requires a variation, which in practice requires a further application. Making a payment outside the licence terms – even where the difference is minor – constitutes a dealing with a designated person's funds without authorisation.
Record-keeping under both regimes is a substantive legal obligation, not a housekeeping matter. OFSI's enforcement guidance confirms that a person who undertakes a licensed activity should retain documents demonstrating compliance with the licence conditions. The statutory record-keeping period under the applicable SAMLA regulations is a matter of years; exporters should retain the licence, the application, the end-use undertaking, the shipping documentation, and the payment records for the full period, even after the licence expires.
How does OFSI compare with OFAC, the EU, and other regimes on encryption controls?
Encryption export controls are not purely a UK matter. A business exporting from or through the United States, a Member State of the European Union, or other major trading nations faces parallel controls – and the regimes are not identical.
Under US rules, the EAR (the Export Administration Regulations administered by BIS – the Bureau of Industry and Security) imposes controls on encryption items using an ECCN (Export Control Classification Number under the US Commerce Control List). Many encryption items are controlled under a specific ECCN within the 5E category. Certain exports, re-exports, and transfers of encryption software are subject to a notification or review requirement, even where a licence exception is available. OFAC's sanctions apply in parallel on the counterparty-screening side, using the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the 50 percent rule. The BIS and OFAC tracks are separately managed. For a UK business with any US-origin content or US-person involvement in its product, BIS's extraterritorial reach through the de minimis rule and the foreign direct product rule can bring the EAR into play even where the exporter is not itself a US person. Our colleagues who advise on US export-control matters regularly flag this interaction for clients who assume that UK origin breaks the US nexus.
Under EU rules, encryption items are controlled under EU Regulation 2021/821 on dual-use items. Following the UK's departure from the EU, the UK strategic export-control list and the EU list are separate instruments and have developed independently. A product that benefits from an EU general authorisation – for instance for export to certain approved destinations – must be separately assessed under the UK open general export licence regime. EU financial sanctions administered through Council regulations differ from OFSI's regime in their ownership and control thresholds: the EU test uses ownership of 50 percent or more OR control, broadly consistent with OFSI, but the detailed analysis of control varies across Member States in implementation. EU General Court annulment practice has influenced how designations are assessed and challenged, with implications for whether a counterparty that has contested its listing should be treated differently from one that has not.
Other regimes add further layers. Singapore, the UAE, and Japan each maintain export-control regimes with their own encryption-specific controls. Where a UK exporter routes goods or software through a third jurisdiction, the applicable country regime must be assessed independently. The stricter prohibition governs in any multi-regime analysis: compliance with the UK regime does not authorise an act that the US regime prohibits, and vice versa.
If a transaction has already been flagged by a regulator, a bank, or a counterparty compliance team, early legal review preserves options that narrow quickly as time passes. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
Risk flags and when to involve counsel
Most enforcement attention in UK encryption export-control matters does not fall on deliberate violations. It falls on exporters who misclassified the product, relied on an open general export licence without checking its scope, or failed to identify the OFSI dimension because their screening tool was not calibrated to the control test.
The following patterns generate disproportionate risk.
- Relying on vendor classification without independent verification. A supplier's statement that a product is "EAR99" (not controlled under the EAR) or equivalent does not constitute a UK classification decision. ECJU expects the UK exporter to take responsibility for the classification under UK rules.
- Assuming that software-only transfers are uncontrolled. The UK strategic export-control list controls technology and software, not just physical goods. An encrypted application delivered by download or cloud access is an export of software and can trigger the same licence requirements as a physical shipment.
- Treating an open general export licence as a blanket authorisation. Each open general export licence has specific conditions – destinations, end-users, product categories, and usage limitations. Using an open general licence without confirming that all conditions are met is not compliance; it is an undocumented assumption.
- Failing to re-screen at payment stage. The counterparty who was clean at the point of classification may appear on an OFSI list by the time the invoice is paid. Screening at a single point in the transaction lifecycle – rather than at each material step – leaves a gap.
- Ignoring the OFSI dimension because no financial payment goes to the counterparty directly. OFSI's prohibitions extend to making funds indirectly available to a designated person. A payment to an intermediary that on-pays to a designated person's controlled entity is caught, even if the exporter's contract is with the intermediary alone.
A common myth in this area is that encryption controls apply only to defence contractors and state-sponsored buyers. In practice, commercial encryption software used in fintech, enterprise communications, and cloud services is routinely controlled. The technical parameters of the product, not its intended commercial market, determine whether a licence is required. We have advised businesses across multiple sectors – financial technology, telecommunications, industrial automation, and maritime – that discovered a licensing requirement only when a transaction was already in progress.
Counsel should be involved at the outset when: (i) the destination or counterparty is in a jurisdiction subject to UK or US sanctions; (ii) the product carries encryption functionality whose specification has not been formally reviewed; (iii) the transaction involves re-export through a third jurisdiction; (iv) the business has received a query from ECJU, OFSI, or a correspondent bank; or (v) the business is structuring a new product line or distribution arrangement that will involve encryption technology.
Related practices
- Deemed export and technology controls under the EAR – assessing US-origin content and the foreign direct product rule for cross-border technology transfers.
- Encryption export controls: UAE guide – how the UAE's applicable country regime interacts with UK and US controls on encryption items.
- Encryption export controls: UN guide – understanding how Security Council measures interact with national export-licensing obligations on controlled technology.