Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · BIS / EAR

EU dual-use classification under BIS / EAR: procedure and pitfalls

A European exporter wins a contract to supply advanced optical sensing equipment to a buyer in a third market. The equipment was designed and manufactured entirely within the EU, and the exporter's legal team has obtained an EU dual-use classification under the relevant Council Regulation. Compliance signs off. The shipment departs. Then the US customer of record contacts them: the same equipment, it turns out, incorporates a US-origin software module, and the buyer is located in a destination that triggers additional US licence requirements. The deal that cleared EU controls may have violated the Export Administration Regulations ("EAR" – the US export-control rules administered by the Bureau of Industry and Security, or "BIS") without anyone realising it.

As of May 2026, any product with US-origin content, US-origin technology, or US-origin software may be subject to BIS / EAR jurisdiction even when it is manufactured, classified, and exported from the EU. EU dual-use classification under the applicable Council Regulation does not extinguish US obligations. Exporters must run both classification analyses in parallel, because the two regimes use different control lists, different thresholds, and different licence exceptions.

This guide walks through the classification procedure under each regime, identifies where they diverge, maps the risk flags that practitioners see most often, and explains when to involve specialist export-control counsel.

Step 1 – Understanding which regime governs (and why both may apply)

The first classification step is jurisdictional: before you classify the item, you must determine which legal regimes have authority over it. The answer often involves more than one.

EU dual-use controls apply to items listed in Annex I of the relevant EU dual-use rules. Those rules require an export authorisation for controlled items leaving EU customs territory, with country-specific tiers and a catch-all for certain non-listed items that could contribute to weapons of mass destruction programmes. The relevant authority in each EU Member State administers the regime, and national licences do not automatically transfer across borders.

BIS jurisdiction under the EAR is broader and turns on three distinct triggers. First, items physically located in the United States. Second, US-origin items wherever they are in the world. Third – and most relevant to EU-based exporters – items that incorporate US-origin content above a defined de minimis threshold (the proportion of controlled US-origin value in the finished item) or that are produced using US-origin technology through what the EAR calls the foreign direct product rule (FDPR – a rule that can extend US jurisdiction to foreign-made goods when they are produced using certain US technology or software).

In our experience, the FDPR is the provision that surprises European exporters most often. A product designed entirely in Germany using US-origin electronic design automation software may be subject to EAR classification even if it contains no US-origin components. That is a jurisdictional question that must be answered before classification begins, not after.

The practical starting point is therefore a jurisdiction map: trace the item's design history, component origins, and software inputs, identify any US-origin element, and apply the de minimis and FDPR tests before touching either control list.

Step 2 – Classifying the item on the EU control list and the US Commerce Control List

Once jurisdiction is established, classification means matching the item's technical parameters to the entries on each control list. The two lists share the same Wassenaar Arrangement architecture – both are organised around Export Control Classification Numbers (ECCN – the alphanumeric code on the US Commerce Control List that determines the reasons for control and the licence requirements) – but they diverge in detail and in interpretation.

The EU Annex I uses the same ten-category, five-product-group structure as the Wassenaar lists. A classification under Category 5 Part 2 (information security) in the EU does not guarantee that BIS will classify the identical item in the same ECCN. BIS publishes its own classification guidelines, and in several technology categories – particularly 5A002 (information security), 3A001 (electronic components), and dual-use biological items – US parameters are stricter or use different performance thresholds than their EU equivalents.

The classification procedure under each regime involves three questions. What is the item? What are its technical parameters (speed, frequency, accuracy, material composition, software function, or other controlled characteristics)? Do those parameters meet or exceed the control list thresholds? For complex items, the answer to the third question may differ between the EU and the US lists even where the underlying Wassenaar entry is the same.

Where an item does not appear to match any control list entry, it is classified as EAR99 (the US residual classification for items subject to the EAR but not listed on the Commerce Control List) or as equivalent "not listed" under the EU regime. EAR99 is not a licence-free green light. Certain destinations, end-users, and end-uses require a licence even for EAR99 items – which is why jurisdictional and counterparty screening must follow classification, not replace it.

We regularly advise clients on contested classifications in Categories 3, 4, and 7, where the gap between the EU text and the BIS text is widest. A classification that is correct for EU purposes can still leave a business exposed under the EAR if the BIS parameters have been applied incorrectly or not applied at all.

Step 3 – Applying the correct licence exception or seeking authorisation

After classification, the exporter must determine whether a transaction requires a licence and whether an available exception or authorisation covers it. This is where the two regimes diverge most sharply in practical effect.

Under the EU regime, authorisations come in four main forms: national general export authorisations (NGEAs, standing permissions for certain low-risk destinations and items), Union general export authorisations (UGEAs, regime-wide standing permissions for defined categories), global export authorisations (individual multi-shipment licences), and individual licences for single transactions. The availability and terms of each depend on the Member State administering the regime and the destination involved.

Under the EAR, BIS provides a range of licence exceptions (standing authorisations that permit defined exports without a separate licence application). The most commonly used for technology and software exports are LVS (low-value shipments), TMP (items for temporary use), and ENC (encryption items meeting BIS's technology review criteria). The ENC exception is particularly important for information-security products: it permits exports of many encryption items to most commercial end-users without a licence, but it requires classification as 5E002 or within a specific ECCN range, and it has conditions that must be documented.

A critical divergence: certain EU UGEAs allow exports to multiple destinations under a single general authorisation, whereas the equivalent EAR exception may require a separate application, impose end-user statement requirements, or simply not exist for the same destination. Exporters who assume that a UGEA covers their US obligations – or vice versa – regularly find gaps that only appear at the point of a BIS inquiry.

Where no exception or general authorisation applies, the exporter must file a specific licence application with BIS (or the relevant EU Member State authority). BIS licence applications require an export licence application form with the item's ECCN, the proposed end-use and end-user, and supporting documentation. Processing times are not fixed by statute for most applications, but in our practice BIS applications for dual-use items to non-sensitive destinations are often processed within several weeks; applications involving higher-controlled items or sensitive destinations take materially longer and may be referred to interagency review.

The position above covers the standard case. Your facts – the item's technology parameters, the destination, the end-user's profile, the US-origin content in the supply chain – change the analysis at every step.

For an assessment of your exposure under the EAR or the EU dual-use regime, contact Calder & Vance at info@caldervance.com.

Step 4 – Screening end-users and end-uses against the restricted-party lists

Classification determines the control status of the item. Restricted-party screening determines whether the buyer, consignee, freight forwarder, or end-user appears on a list that prohibits or conditions the transaction regardless of the item's classification.

Under the EAR, BIS maintains several lists that exporters must screen against: the Entity List (parties requiring a licence for exports of any EAR-controlled item, often with a policy of denial), the Denied Persons List (parties with whom virtually all transactions are prohibited), and the Unverified List (parties whose legitimacy BIS has been unable to verify). OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) operates in parallel: an item that clears BIS controls may still be blocked because the buyer appears on OFAC's list.

Under the EU regime, exporters must screen against the EU Consolidated List (the EU list of designated persons and entities subject to asset freezes and other measures) and against the UN Security Council Consolidated List. Some Member States also maintain national lists.

The two regimes interact. A counterparty on the EU Consolidated List is not automatically on the SDN List, and vice versa. A party on the Entity List may not appear on either sanctions list. Exporters who rely on a single list check – or a single database that covers only one regime – regularly miss hits in the other. Effective screening covers all relevant lists, is matched against all parties in the transaction chain, and is documented.

End-use screening is a separate obligation. Under the EAR's know your customer guidance, red flags – payment in cash for high-value controlled goods, a buyer whose business does not appear consistent with the item's use, a shipping address different from the stated end-user – trigger a duty to enquire. Proceeding without resolving a red flag can constitute a violation even without a positive list hit.

Step 5 – Documenting, record-keeping, and post-shipment obligations

Export-control compliance does not end at the point of shipment. Both the EAR and the EU regime impose record-keeping and, in some cases, post-shipment reporting and verification obligations.

Under the EAR, exporters must retain export records – the classification, the licence or exception used, the Electronic Export Information (EEI) filing, end-user statements, and supporting transaction documents – for five years from the date of export. This is a hard statutory requirement, and BIS routinely requests records in the course of audit and enforcement inquiries. Inadequate records are themselves a basis for penalty.

Under the EU regime, record-keeping requirements vary by Member State but generally follow the same multi-year retention standard. Some Member States require exporters to submit annual or periodic reports on the use of general authorisations. Failure to report can result in suspension of the UGEA or imposition of a specific licence requirement.

Post-shipment verification – providing a delivery verification certificate or allowing a post-shipment check by the relevant authority – may be a condition of a specific licence under either regime. Where it is a condition, failure to comply can affect the licensee's ability to obtain future licences, independently of whether a violation occurred.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time.

To discuss a licensing matter or a classification review, write to Calder & Vance at info@caldervance.com.

Where the two regimes diverge: five practical risk flags

Classification errors under the EAR and the EU dual-use regime rarely arise from a misunderstanding of a single rule. They arise from the assumption that the two regimes are equivalent. They are not.

Risk flag 1 – FDPR exposure missed. EU-manufactured goods produced using US-origin software tools, design technology, or manufacturing equipment may fall within BIS jurisdiction under the FDPR even without a single US-origin component. This analysis is frequently overlooked in supply chains where design and manufacturing are entirely European but the software stack includes US-licensed tools.

Risk flag 2 – Parameter divergence. The EU and US control lists use the same Wassenaar framework but apply different performance thresholds in several categories. An item that does not meet the EU control parameter may still meet the BIS threshold, or vice versa. Classification must be performed against each list independently.

Risk flag 3 – General authorisation coverage gaps. A EU UGEA covering a destination may have no equivalent BIS licence exception for the same product and destination combination. Exporters who assume parallel coverage regularly discover on inquiry that BIS required a specific licence that was never obtained.

Risk flag 4 – Entity List additions after initial classification. BIS adds parties to the Entity List on a rolling basis, sometimes with immediate effect. A classification and end-user check performed at the time of the contract may be outdated by the time of shipment. Screening must be repeated immediately before each export.

Risk flag 5 – Voluntary self-disclosure window. Under the EAR, a VSD (voluntary self-disclosure to BIS) can significantly affect the outcome of an enforcement matter. The window to disclose is not open indefinitely, and the quality of the disclosure – completeness, accuracy, and the presence of a credible remediation plan – affects how BIS treats it. Acting quickly matters.

In a recent matter, a technology manufacturer in central Europe discovered, during a routine internal audit, that a series of exports of optical testing equipment had proceeded under a EU UGEA while the US-origin software development kit embedded in the firmware brought the product within BIS jurisdiction. The classification had never been run against the Commerce Control List. We assessed the FDPR exposure, classified the items under the EAR, identified the applicable licence exception for the majority of shipments, and advised on a VSD to BIS for the remainder. The matter was resolved through the disclosure process without a referral to civil penalty proceedings.

Related practices

A common myth: "our goods are EAR99, so no US controls apply"

One of the most persistent misconceptions we encounter is that an EAR99 classification ends the export-control analysis. It does not. EAR99 means only that the item does not appear on the Commerce Control List as a specifically controlled item. It does not mean that no US restrictions apply.

Even EAR99 items require a BIS licence – or are outright prohibited – when the end-user appears on the Entity List or the SDN List, when the destination is subject to comprehensive US sanctions, when the stated end-use involves weapons of mass destruction, or when known red flags have not been resolved. Proceeds of thought that "EAR99 = no licence needed" have resulted in enforcement actions that a basic end-user screening step would have prevented.

The same logic applies in the EU: an item not listed in Annex I may still require an authorisation under the catch-all provision if the exporter has reason to believe the goods may contribute to programmes of concern. Classification and end-user screening are two distinct obligations; neither substitutes for the other.

Frequently asked questions

What are the steps to classify a dual-use item in the EU under BIS / EAR?
Classification under both regimes involves five sequential steps: (1) establish jurisdiction – determine whether the item is subject to EU controls, EAR controls, or both, by analysing US-origin content and the FDPR; (2) classify the item against the EU Annex I and the US Commerce Control List independently, applying the technical parameters of each; (3) identify the applicable licence exception or authorisation under each regime; (4) screen all parties in the transaction against the relevant restricted-party lists, including the Entity List, SDN List, and EU Consolidated List; and (5) retain records for the required period under each regime and comply with any post-shipment conditions. Missing either the jurisdictional step or the parallel-list classification step is the source of most compliance failures in our practice.
What is the most common mistake in EU dual-use classification?
The most common mistake is assuming that a valid EU classification automatically satisfies BIS obligations, or that an EAR99 classification means no controls apply. In our practice, the FDPR is the most frequently overlooked source of US jurisdiction over EU-manufactured goods. Exporters who run only a single-regime classification – whether EU-only or US-only – routinely discover the gap only after a shipment has departed or after a BIS inquiry has commenced. Running both classification analyses from the outset, and repeating restricted-party screening immediately before each shipment, prevents the majority of enforcement exposure we see.
How does BIS / EAR differ from other regimes here?
BIS / EAR is extraterritorial in a way that most other export-control regimes are not. The EU regime controls items leaving EU customs territory; BIS / EAR controls items with US-origin content or technology anywhere in the world. That extraterritorial reach – through the de minimis rule and the FDPR – is the defining difference. The EU regime relies on destination-based tiering and general authorisations; the EAR uses a CCN-based licence exception structure with parallel restricted-party controls. The two regimes share a Wassenaar foundation but diverge in thresholds, exceptions, and enforcement posture. A business that maps only one regime misses the other's reach entirely.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.