Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · UN

Encryption export controls under UN: a compliance guide

A technology exporter finalises terms with a buyer in a third market. The goods include software with built-in encryption. The export team assumes the transaction is a straightforward commercial deal. Then a compliance review surfaces a question: does the UN Consolidated List affect this shipment, and how do the parallel controls under the major national regimes interact with whatever the UN framework requires? That question – deceptively simple on its face – carries the weight of potential licence conditions, end-use obligations, and enforcement exposure across multiple jurisdictions simultaneously.

Encryption export controls under the UN operate primarily through Security Council arms embargo resolutions, which restrict transfers of controlled technology – including dual-use encryption goods – to designated states, entities, and individuals on the UN Consolidated List (the Security Council's roster of designated persons and entities under Chapter VII resolutions). The UN regime does not itself issue encryption licences; instead, it sets the floor that national implementing regimes must meet. As of April 2026, exporters face a layered compliance task: satisfying the UN baseline, then clearing the stricter national rules that almost always go further.

This guide explains how the UN encryption-export-controls regime works in practice, how it interacts with the US, UK, EU, and other national regimes, and how an exporter can build a reliable step-by-step compliance process before shipment.

Step 1: Understand the UN's role in encryption export controls

The UN regime establishes the mandatory baseline, but it does not directly classify encryption products or issue individual licences. The Security Council, acting under Chapter VII of the UN Charter, adopts resolutions that impose arms embargoes and technology-transfer restrictions on specific country, entity, or individual targets. Member states are bound to implement those restrictions through their national legal orders. For encryption exporters, the critical point is this: if a proposed transaction touches a target on the UN Consolidated List – buyer, end-user, freight forwarder, financial intermediary – the UN-mandated prohibition applies regardless of what any national licence may say.

Encryption goods and software appear in this context because modern dual-use technology (goods and software with both civil and military or intelligence applications) includes cryptographic items. High-strength encryption can serve civilian e-commerce or secure military communications. That dual character is precisely why Security Council technology-transfer restrictions capture it. An exporter who asks only "do I need a BIS licence?" without also asking "is any party on the UN Consolidated List?" has completed only half the check.

In our experience, the UN-layer question is the one most frequently skipped in automated screening workflows, particularly when the counterparty is not a well-known state actor but a logistics intermediary domiciled in a third country.

Step 2: Screen against the UN Consolidated List and national implementing lists

Effective screening begins with the UN Consolidated List and must extend to every national implementing list that applies to the exporter's jurisdiction. The UN list is publicly accessible and updated by the relevant Security Council sanctions committees. National lists – OFAC's SDN List (Specially Designated Nationals and blocked persons), OFSI's financial-sanctions list, the EU's Consolidated Financial Sanctions List, and their equivalents in Switzerland (SECO), Canada (GAC), Australia (DFAT), Singapore, Japan, and the UAE – overlap substantially with the UN list but are not identical. Each national authority typically adds designations that go beyond the UN baseline.

The screening obligation covers more than the named buyer. An exporter should screen:

  • The direct buyer and any parent, subsidiary, or affiliate above the relevant ownership threshold
  • The stated end-user, where different from the buyer
  • Freight forwarders, customs brokers, and re-export agents in the transaction chain
  • Banks and payment intermediaries processing the transaction
  • Any party named in the end-use certificate or import authorisation

Do you screen only the first name on the purchase order, or the full transaction chain? The UN-level risk can sit several tiers back in the distribution structure. Exporters who limit screening to the direct contractual counterparty frequently miss the exposure that materialises at enforcement.

Step 3: Classify the encryption item under the applicable national control list

The UN regime does not maintain its own product-classification list for encryption items. Classification happens under national control lists, each of which implements the Wassenaar Arrangement's common control list and related multilateral regimes. In the United States, encryption items are classified under the Commerce Control List (the CCL, maintained by BIS under the Export Administration Regulations). In the EU, dual-use encryption goods are controlled under the EU dual-use rules (Council Regulation on dual-use items). The UK's equivalent is the UK Strategic Export Control Lists, administered by ECJU. Other Wassenaar-participating states maintain parallel lists.

Classification determines which licence requirements or exceptions may apply at the national level. But classification under a national list does not resolve the UN question. Even a product that qualifies for a national licence exception is still subject to the UN-mandated prohibitions if a party in the transaction is on the UN Consolidated List. The two analyses run in parallel; clearing one does not clear the other.

An ECCN (Export Control Classification Number under the US Commerce Control List) identifies the specific control parameters for an item under the EAR. Exporters moving encryption goods from the United States need to determine whether the relevant ECCN triggers a licence requirement for the destination and end-user. Under the EAR, certain encryption products are eligible for licence exceptions, but those exceptions are unavailable when the transaction is caught by an OFAC or UN restriction. Classification and sanctions-screening are therefore co-dependent steps, not sequential ones.

Step 4: Apply the cross-regime comparison – where the regimes diverge

A practitioner advising a cross-border exporter must map the divergences between the UN baseline and the national regimes. Four dimensions matter most.

Scope of the technology-transfer restriction. The UN arms embargo resolutions typically focus on direct transfers of arms and related materiel, including technology for military end-use. National regimes – particularly the EAR and the EU dual-use rules – apply broader controls covering civil-use encryption above specified technical parameters. An encryption product below the threshold that triggers UN concern may still require a national licence. Conversely, a product controlled under the UN framework triggers an absolute prohibition that no national licence can override.

Ownership and control tests. OFAC's 50 percent rule (treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical. The UK OFSI test and the EU test extend further into control – a designated person's ability to direct the entity's affairs without necessarily holding a majority equity stake. For encryption exporters, this matters when the buyer is a company with a complex ownership structure: passing the mechanical ownership check may not be sufficient under OFSI or EU rules.

Extra-territorial reach. US controls under the EAR apply to US-origin technology wherever it travels, including re-exports by non-US parties. The EU controls apply to items physically leaving EU territory and, in certain dual-use categories, to intangible technology transfers (deemed exports) within the EU. The UN regime's reach is jurisdictionally implemented by each member state; it has no direct extra-territorial operator of its own. Practically, however, because major trading jurisdictions all implement UN resolutions, the effective reach is broad.

Licensing and authorisation routes. Under OFAC and BIS, specific licences can authorise individual transactions; general licences authorise defined categories. Under OFSI, a specific licence (a case-by-case authorisation) or a licence applying to a defined class of transactions may be available. The EU regime similarly provides for national licensing by member-state competent authorities. None of these national licensing routes, however, can override a direct UN Consolidated List prohibition. Where the UN restriction applies, the correct route is a Security Council sanctions committee exception process – not a national licence application.

In our cross-border practice, the most consequential gap we see is between exporters who obtain a national licence and incorrectly treat it as the full compliance answer, and those who have traced the obligation to its UN source and verified that no Consolidated List designation catches a party in the chain.

Step 5: Assess end-use and end-user controls for encryption goods

Encryption items are acutely sensitive to post-shipment diversion risk. A strong encryption product transferred to a compliant buyer in a permissible destination can still generate liability if the exporter had reason to believe the goods would be re-transferred to a restricted end-user or applied to a restricted end-use. Most national regimes – and the UN's technology-transfer restrictions – impose substantive obligations at this point.

End-use controls typically require an exporter to:

  1. Obtain an end-use certificate or import certificate from the buyer stating the intended application
  2. Insert contractual no-re-transfer and no-re-export clauses consistent with the originating licence conditions
  3. Conduct a plausibility check on the stated end-use against the buyer's known business
  4. Apply enhanced diligence where the destination or the buyer's sector raises diversion risk (for example, where a commercial buyer operates in proximity to restricted sectors)
  5. Maintain records for the required retention period to demonstrate compliance at any later audit or enforcement review

For an exporter moving encryption software to a buyer in a jurisdiction that itself borders a targeted state, the diversion question is not theoretical. We regularly advise on transactions where the surface facts look clean but the end-use diligence reveals a materially elevated risk of re-transfer that the initial screening missed entirely.

For further guidance on end-use and end-user controls in the cross-border context, see our end-use and end-user controls cross-border guide. For the Canadian regime specifically, our end-use and end-user controls Canada guide covers the applicable country regime in detail.

Step 6: Identify red flags and know when to involve counsel

Red flags in encryption exports are the points where routine screening produces an incomplete picture and the risk of non-compliance rises sharply. They are not always obvious at first review.

The following patterns consistently appear in matters that escalate to enforcement:

  • A buyer who requests removal of the encryption functionality from product documentation or marketing materials before contract signature
  • Payment routed through a jurisdiction unconnected to the stated buyer or delivery address
  • An end-use certificate that describes a general commercial application for a product whose technical specifications exceed what that application requires
  • A freight forwarder or logistics agent that appears on a government advisory list for transshipment risk
  • A buyer affiliated with a state research or defence entity in a country subject to UN technology-transfer restrictions
  • Unusual urgency, unusual payment terms, or a request to alter the description of the goods on shipping documents

Any single red flag warrants a pause and a closer review. Combinations are an instruction to stop the transaction and take advice. The cost of a brief pre-shipment review is a fraction of the cost of a post-shipment enforcement inquiry.

When should counsel be involved before shipment? Where the item has a high encryption strength, where the end-user has any government or defence affiliation, where any party in the chain is on a watchlist or operates in a high-risk transshipment corridor, or where the exporter has not previously shipped encryption goods to that destination. A voluntary self-disclosure (VSD) – a proactive disclosure to the relevant regulator of a potential violation before the regulator discovers it independently – is also something that should be structured with legal advice, not submitted on a first-draft basis.

Step 7: Build and maintain the compliance record

Documentation is not a formality. It is the evidential basis on which an exporter defends a compliance posture at audit or enforcement review. For encryption goods subject to UN-based controls, the record should demonstrate that the exporter identified every applicable restriction, screened all relevant parties, assessed the end-use, obtained the necessary certificates, and applied any required licence conditions.

National regimes prescribe minimum record-retention periods. The specific periods vary by regime; verify the current requirement for each jurisdiction before relying on any single standard. As a working minimum, exporters should plan for a multi-year retention obligation and should not dispose of transaction records until they have confirmed the applicable period has expired. Records should be maintained in a form that can be retrieved and produced to a regulator on reasonable notice.

The record should include: the original screening results with the date and database version used; the classification determination and the reasoning for it; the end-use certificate and any supporting communications; licence applications, approvals, and conditions; shipping documents; and any internal escalation memos where a red flag was identified and resolved. Where the exporter applied a licence exception rather than a specific licence, the factual basis for the exception should be documented at the time of export, not reconstructed afterwards.

For technology transfers that may constitute a deemed export – the release of controlled technology to a foreign national within the exporting country, which is treated as an export to that person's country of nationality under the EAR – the compliance record should also reflect the exporter's assessment of the deemed-export risk and any authorisation obtained. For detailed guidance on deemed exports under the BIS and EAR, see our deemed export technology service page.

Common objections and myths in encryption export compliance

One persistent misconception in our practice is that encryption controls apply only to "military-grade" products. In fact, national control lists and the Wassenaar common list control encryption above defined technical parameters – key lengths, algorithm types – without reference to the stated military or civilian intent of the product. A commercially available enterprise security product can sit squarely within the controlled parameters and trigger licence requirements irrespective of its intended market. The designation of a product as "commercial" does not resolve the classification question.

A second misconception is that a licence exception obtained under a national regime fully resolves the UN exposure. It does not. As this guide explains, the UN-mandated prohibition flows from Security Council resolutions binding on all member states. A national licence exception carves out certain transactions from the national licence requirement; it cannot override a Chapter VII restriction. The two analyses must both be completed.

A third misconception is that encryption software transmitted electronically – cloud delivery, SaaS deployment, a software download – falls outside export-control jurisdiction because nothing physically crosses a border. This is incorrect under the EAR and under the EU dual-use rules. Intangible technology transfers are controlled. The export of encryption software by electronic means is an export for control purposes, and the same screening and classification steps apply.

Related practices

Related practices

Frequently asked questions

What are the steps to manage encryption export controls under UN?
Managing encryption export controls under the UN requires a sequential process: establish whether any party in the transaction is on the UN Consolidated List; classify the encryption item under the applicable national control list; assess the end-use and end-user risk; obtain any required national licences or apply any available exceptions; insert contractual re-transfer restrictions; and maintain a full compliance record. Where the UN restriction applies directly, no national licence resolves it – a Security Council exception process is required instead.
What is the most common mistake in encryption export controls?
The most common mistake is treating the national licence or licence exception as the complete compliance answer, without separately verifying that no party in the transaction chain is on the UN Consolidated List or a national implementing list. Screening limited to the direct contractual counterparty is the second most common failure: end-users, freight forwarders, and financial intermediaries carry the same risk. Automated screening tools that do not aggregate partial ownership and control information across entity layers also produce systematic blind spots.
How does the UN regime differ from other regimes here?
The UN regime sets the floor through Security Council resolutions binding all member states under Chapter VII. It does not itself classify encryption products, issue licences, or maintain a product-control list; those functions belong to national implementing regimes. The key difference is that a UN-mandated restriction cannot be overridden by a national licence. National regimes – the EAR, the EU dual-use rules, OFSI controls – typically go further than the UN baseline, applying broader technology-transfer controls and ownership tests that can catch transactions the UN alone would not. Both layers must be cleared.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.