Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · UAE

Encryption export controls under UAE: a compliance guide

A technology exporter ships a product containing standard AES-256 encryption to a business partner in Dubai. The shipment clears US customs, arrives in the UAE, and is then onward-distributed to a regional network. Months later, a compliance review flags the transaction. Was a UAE export-authorisation step missed? Did the US export licence cover the onward movement? These questions are not hypothetical. They surface in our cross-border practice with regularity, and the answers turn on the specific interaction of the UAE regime with the exporter's home jurisdiction controls.

Encryption products are subject to export controls under the UAE's applicable national instruments, administered by the relevant competent authority. The UAE regime operates alongside – and is frequently triggered in sequence with – US EAR controls, EU dual-use rules, and UK ECJU licensing requirements. A UAE-based re-export, distribution arrangement, or technology-transfer can engage all of these simultaneously. The stricter prohibition governs at each step.

This guide works through the classification question, the authorisation procedure, the cross-regime interaction, the principal risk flags, and the practical steps a compliance team should take before a shipment moves.

Step 1: Understand the governing authority and legal basis

The UAE controls the import, export, re-export, and transfer of dual-use goods and technology – including encryption items – under its applicable national legal instruments. The regulatory authority responsible for licensing and enforcement has oversight of strategic goods, which encompass cryptographic products above defined capability thresholds. Compliance counsel advising UAE-nexus transactions must identify this authority early, because its process differs materially from the OFAC/BIS model many multinationals know by default.

The UAE is a member of several international export-control arrangements. Participation in those arrangements shapes which control lists the UAE references when classifying goods. Encryption items appear on those lists by reference to their key length, algorithm, and functional scope. A product that is decontrolled or licence-exempt in one member state is not automatically decontrolled in another. This is the first conceptual error we see exporters make: assuming that a US EAR licence exception for encryption carries through the supply chain without further UAE-specific analysis.

The legal basis for UAE controls has evolved. As of April 2026, businesses with UAE distribution networks should verify the current classification thresholds and the applicable procedural rules with a practitioner current on the regime, because the UAE has updated its strategic goods controls in recent years. Verify the current position before relying on any summary, including this one.

Step 2: Classify the encryption item against the UAE control list

Classification is the foundation of the entire analysis. An encryption product's control status under the UAE regime turns on its technical parameters – primarily the maximum key length in bits, the cryptographic algorithm family, the access-control architecture, and whether the encryption functionality is the primary purpose of the item or merely an incidental feature.

Mass-market products with symmetric encryption up to a broadly accepted threshold, and products designed solely for personal authentication without the capacity to encrypt or decrypt files or communications, often attract a different treatment from purpose-built cryptographic hardware or software development kits that expose the underlying cipher engine. The line between these categories is technical, not commercial. A product sold on a consumer platform can still require an authorisation if its technical specifications cross the relevant threshold.

The classification exercise has three stages. First, identify the item's Export Control Classification Number (ECCN – the alphanumeric code assigned under the US Commerce Control List, or the equivalent entry on the relevant international arrangement's list) or the equivalent entry under the UAE control list structure. Second, check whether a general authorisation or licence exception applies. Third, confirm whether the UAE destination, the stated end-use, or the end-user triggers additional requirements regardless of the general rule. We regularly advise clients that skip stage three and later discover that an end-user restriction overrides an otherwise available exception.

One practical point on documentation: the technical parameters used in classification must be recorded and retained. Regulators reviewing a shipment after the fact will ask for the classification rationale. A contemporaneous record, prepared by or reviewed by qualified counsel, is substantially more defensible than a retrospective reconstruction.

Step 3: Determine whether an authorisation is required – and which type applies

Once classification is complete, the next step is to map the classified item to the UAE regime's authorisation architecture. The UAE system, like most comparable regimes, distinguishes between items that may move under a general authorisation (a standing permission for defined categories) and items that require a specific licence (a case-by-case permission obtained before the transaction). For encryption items above the relevant threshold, a specific authorisation is typically required.

The application process under the UAE regime involves submitting technical documentation for the item, end-use and end-user information, and in some cases an end-use certificate executed by the buyer. Processing timelines vary and are not guaranteed. In our experience, applications that are incomplete at submission – missing technical specifications, unclear end-use descriptions, or absent end-user certificates – extend significantly beyond the standard administrative window. Prepare the full package before lodging the application.

A common planning failure is treating the authorisation as a post-contract step. Where a specific licence is required, the authorisation should be sought before the contract is signed or, at minimum, before delivery obligations crystallise. A signed contract that cannot be performed because a licence is refused creates both a commercial and a legal problem. The standard approach in our practice is to include a sanctions and export-control condition precedent in the sale agreement, making delivery conditional on obtaining the necessary authorisation.

The position above covers the standard case. Your facts – the specific encryption product, the UAE counterparty, the stated end-use, and whether the goods move to a third country after UAE entry – change the analysis. For a review of your specific transaction, contact Calder & Vance at info@caldervance.com.

Step 4: Map the cross-regime interaction – US EAR, EU dual-use, and UK ECJU

A UAE-destined encryption shipment almost always engages at least one other regime. The nature of the interaction depends on where the product originated, what technology was transferred, and whether the UAE is the final destination or a transit or re-export hub.

Under the EAR (the US Export Administration Regulations, administered by BIS), encryption items controlled by ECCN are subject to US jurisdiction wherever they are in the world, if they were manufactured in the United States, contain a threshold proportion of US-origin content, or were produced outside the United States using US-origin technology or software – the so-called de minimis rule and the foreign direct product rule. A UAE re-exporter handling US-origin encryption products is not outside EAR jurisdiction simply because it is located outside the United States. This extraterritorial reach is one of the most frequently misunderstood aspects of US export-control compliance.

For EU-origin products, the EU dual-use regulation establishes its own encryption controls, with a general export authorisation available for a defined list of destinations. The UAE is a permitted destination under some of those general authorisations, but the conditions attached – technology transfer limits, end-use restrictions, and post-shipment reporting – must still be satisfied. A UAE distributor that receives EU-origin encryption technology and then further develops it or incorporates it into a product for onward sale may take the resulting product outside the scope of the original authorisation.

UK controls under the ECJU follow a broadly comparable classification structure but apply their own jurisdiction rules and licence conditions. Post-Brexit, UK and EU controls have diverged in procedural detail, and a licence under one does not substitute for the other. Where a product has UK-origin components alongside EU-origin software, the applicable controls must be analysed for each origin strand separately. The stricter prohibition governs at each decision point.

The practical consequence is that a single distribution arrangement centred on the UAE can require parallel authorisation processes in three or more jurisdictions. In a recent matter, a technology business with a UAE distribution partner discovered mid-transaction that its product required authorisations under both the EAR and the UAE national regime, and that the two application timelines did not align. We structured a sequenced authorisation strategy and advised on the interim contractual protections. The matter resolved without a compliance breach.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Reach the Calder & Vance team at info@caldervance.com.

What are the principal risk flags in UAE encryption export compliance?

Several indicators should trigger heightened scrutiny before a shipment proceeds. Each represents a pattern that regulators in multiple jurisdictions treat as a marker of elevated diversion or control risk.

  • Re-export risk. The UAE is a significant re-export hub. Products entering the UAE for onward distribution to third countries – particularly to destinations subject to heightened controls under any of the major regimes – require specific diligence. The authorisation obtained for UAE entry does not automatically cover re-export. A separate analysis, and often a separate authorisation, is required for each onward destination.
  • End-use ambiguity. Encryption products are dual-use by nature. A product sold for commercial network security can also be used for intelligence applications. Where the stated end-use is vague, where the buyer's business does not obviously align with the product's commercial function, or where the buyer resists providing an end-use certificate, these are risk flags that should pause the transaction.
  • Unusual payment or routing structures. Encryption transactions with payment routed through unrelated third countries, or with logistics that involve circuitous shipping routes, may indicate diversion risk. These patterns appear in enforcement actions across multiple regimes and are reviewed by regulators as indicators of intent to circumvent controls.
  • Counterparty screening. The UAE's own designation lists, as well as the UN Consolidated List and the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons), must be checked against the buyer, the ultimate end-user, and relevant intermediaries. A clear screening result at point of sale does not eliminate the obligation to monitor for subsequent designations during a continuing distribution relationship.
  • Technology transfer alongside hardware. Where technical support, training, or software updates accompany an encryption hardware sale, that transfer of technology may itself require a separate authorisation under the UAE regime and under the home-jurisdiction controls. Technology transfers are a significant source of inadvertent violations in our practice.

Are you certain your screening covers the full ownership chain of the UAE distributor, not just the entity you contract with directly? The ownership and control test (the test for whether a non-listed entity is caught through a listed person's ownership or control) applies under multiple regimes and can extend liability beyond the named counterparty.

How does the UAE regime differ from OFAC, EU, and UN encryption controls?

The UAE regime's treatment of encryption export controls is distinctly national in character, even though it references international arrangement control lists. Several features distinguish it from the OFAC, EU, and UN positions.

OFAC does not itself operate an encryption export-control regime – that is BIS's domain under the EAR. OFAC's relevance to a UAE encryption transaction is through sanctions on specific persons, entities, or countries that may be involved in the supply chain. The BIS/EAR encryption controls are extraterritorial and technology-tracing in a way that the UAE regime is not. The UAE primarily controls goods and technology physically moving across its border or transferred from UAE territory; the EAR follows US-origin technology wherever it goes. These are complementary but structurally different mechanisms.

The EU dual-use regulation takes a list-based approach similar to the UAE's, with defined encryption parameters triggering control. However, the EU's internal market creates an exemption for intra-EU transfers that has no analogue in the UAE regime. A product moving freely between two EU member states still requires an export authorisation when it leaves the EU for the UAE. That asymmetry surprises some manufacturers who assume that their EU compliance programme covers third-country exports automatically.

At the UN level, there is no general multilateral encryption-specific export control instrument. The UN Security Council's targeted sanctions regimes impose arms embargoes and related controls, but encryption goods as a commercial category are addressed primarily at the national and regional level through the international arrangement frameworks that the UAE participates in. The UN Consolidated List remains relevant for screening the transaction parties.

Singapore and Japan, both significant trading partners of the UAE, operate their own encryption controls under their respective strategic goods regimes. Where a supply chain involves goods or technology with Singapore or Japan origin – or where UAE-based goods are re-exported to those jurisdictions – a separate analysis under those national instruments is required. We have acted for clients whose UAE distribution arrangements inadvertently triggered Japanese foreign exchange and trade control requirements because a component in the encryption product had Japanese-origin technology embedded in it.

Related practices

When should you involve counsel – and what does the process look like?

The threshold for involving specialist counsel is lower than most in-house teams assume. Classification decisions for encryption products are technically demanding and legally consequential. An incorrect classification that results in a shipment proceeding without the required authorisation is a potential violation under the UAE regime and, if US-origin technology is involved, under the EAR simultaneously. The exposure under each regime is independent.

Counsel should be involved at classification stage for any encryption product above a basic capability threshold – not only at the point where a specific licence is being considered. Early involvement means the classification rationale is documented, the cross-regime interaction is mapped, and the contractual protections are built into the commercial agreement before execution. Retroactive compliance is more expensive and less reliable than prospective planning.

A typical engagement for UAE encryption export compliance moves through four phases. First, a classification review covering the product's technical parameters and the applicable UAE and home-jurisdiction control lists. Second, a cross-regime mapping exercise identifying which authorisations are required and in which sequence. Third, preparation and submission of the relevant applications, with accompanying technical documentation, end-use certificates, and end-user declarations. Fourth, ongoing monitoring of the distribution arrangement for changes in the counterparty's ownership or use profile that could affect the continuing validity of authorisations obtained.

The myth we encounter most frequently is that UAE encryption export compliance is a documentation exercise that a logistics team can handle with a checklist. It is not. The classification question alone involves technical parameters that require legal-technical training to apply correctly. The cross-regime interaction requires current knowledge of at least three separate regulatory regimes. And the consequences of error – in the form of enforcement action, shipment seizure, or denial of future licensing – are significant. Treating this as a bureaucratic formality is the pattern we see in a large proportion of the voluntary self-disclosures that come to our practice after the fact.

Frequently asked questions

What are the steps to manage encryption export controls under UAE?
The process has four sequential steps: classify the encryption product against the UAE control list and applicable international arrangement lists; determine whether a general authorisation covers the shipment or a specific licence is required; apply for the necessary authorisation before the contractual delivery obligation is fixed; and map the cross-regime interaction with the home-jurisdiction controls – US EAR, EU dual-use, or UK ECJU – to identify any parallel authorisation requirements. Document each step contemporaneously. The classification rationale and the authorisation record should be retained for a period that satisfies the record-keeping requirements of each applicable regime; verify the current requirement before relying on any stated period.
What is the most common mistake in encryption export controls?
The most common mistake is treating a licence exception or decontrol determination from one regime as carrying through the entire supply chain. A product that qualifies for a US EAR licence exception for encryption is not automatically exempt from UAE authorisation requirements, and vice versa. Each regime applies its own classification criteria and its own exceptions. A second common error is failing to analyse the technology-transfer component of a hardware sale – technical assistance, training, and software updates can each require a separate authorisation that the hardware licence does not cover.
How does UAE differ from other regimes here?
The UAE applies its controls at the point of import, export, re-export, and in-country transfer, referencing the relevant international arrangement control lists but through its own national instruments and administrative process. Unlike the US EAR, it does not assert extraterritorial jurisdiction over foreign-origin goods based on their technology content. Unlike the EU regime, it has no internal-market exemption. The UAE is also a significant re-export hub, which means that an authorisation obtained for UAE entry does not automatically cover onward movement to a third country. Each leg of the supply chain must be analysed separately under the applicable national regime for that movement.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.