A machinery exporter in Germany receives a purchase order from a distributor in South-East Asia. The goods leave the factory without an export licence. Six months later, a customs audit flags the shipment: the item carries a dual-use classification that required authorisation under EU rules. The exporter faces a potential enforcement action, reputational scrutiny, and the immediate problem of a supply chain that cannot continue without a licence.
EU dual-use classification is the process by which businesses determine whether goods, software, or technology appear on the EU's dual-use control list and, if so, which licence obligations follow. The governing instrument is EU Regulation 2021/821, which replaced the earlier dual-use regulation and extended its scope to include new categories of cyber-surveillance technology. Misclassification – in either direction – carries serious legal and commercial consequences.
This guide walks through the classification process step by step, identifies the most common risk points, and explains where EU rules diverge from those of comparable regimes. It is written for compliance officers, legal teams, and export managers who need a practitioner's view of how the process works in practice.
Step 1: Understand what EU dual-use rules cover
The EU dual-use regime controls the export, brokering, technical assistance, and transit of items that have both legitimate civilian uses and potential military or proliferation applications. The governing instrument, EU Regulation 2021/821 (as currently in force; verify before reliance), applies across all EU Member States and establishes a single list of controlled items alongside a set of authorisation types.
The list is structured around ten categories: nuclear materials and equipment; materials, chemicals, micro-organisms and toxins; materials processing; electronics; computers; telecommunications and information security; sensors and lasers; navigation and avionics; marine; and aerospace and propulsion. Each category is further divided into product groups. Software and technology related to listed items are controlled separately from the physical goods themselves – a distinction that catches many businesses off guard.
The 2021 regulation also introduced an explicit control on cyber-surveillance items not otherwise listed. This is a significant change. A business may export equipment that appears on no numbered entry in the list but that still requires authorisation if it is designed or modified for covert surveillance. In our experience, this catch-all provision is underused as an analytical tool during classification reviews.
One further point: the EU dual-use regime does not stand alone. Member States retain the right to impose national controls on items not appearing on the EU list, and the regulation itself provides a general catch-all that allows Member States to refuse export where there are grounds to suspect end-use in weapons of mass destruction or conventional arms programmes. Classification against the EU list is necessary but not always sufficient.
Step 2: Locate the correct entry on the EU Control List
The EU Control List is the definitive reference for establishing whether an item is subject to export control, and the entry must be read precisely: the product description, the technical parameters, and any notes or exclusions all form part of the classification.
Start with the item's technical specifications. Gather the manufacturer's data sheet, the full technical manual, and any available test reports. The classification exercise is a comparison of the item's actual technical parameters against the threshold values or descriptive criteria in each potentially applicable list entry. Where there is ambiguity – and in dual-use work there frequently is – the analysis does not stop at the product description. The related controls on software and technology must also be assessed.
Notes matter as much as the main entries. Many list entries carry exclusions for mass-market goods, academic research, or specific end-use configurations. A note stating that an entry does not apply to items "designed for" a civil purpose may not apply if the item has been specially configured or if the exporter has knowledge of a military end-use. Read the note; do not rely on a paraphrase of it.
We regularly advise businesses that have conducted classification by comparison with competitors' export control classifications. That approach is unreliable. Competitor classifications may be wrong, out of date, or based on a different product specification. The classification is product-specific and exporter-specific; it cannot be borrowed.
Step 3: Apply the technical parameters – and document the analysis
Classification against a technical threshold requires a methodical, documented comparison: the specification, the threshold, the source of the threshold, and the conclusion. The documentation is not a bureaucratic formality. It is the defence in an enforcement enquiry.
Several categories of risk arise at this stage. First, performance parameters may be given in different units or at different test conditions from those used in the list entry. Conversion errors are common and can shift an item from controlled to uncontrolled – or vice versa. Second, the technical parameters of a product may change between product generations without triggering a new classification review. An item that was uncontrolled two years ago may now fall within a tightened list entry. Third, software updates can change the effective performance of hardware, potentially engaging a classification that did not apply to the original item.
For items close to a threshold, the analysis should be reviewed by a technically qualified person – an engineer or a qualified external specialist – not only by the compliance or legal team. The classification is a technical conclusion with legal consequences, not purely a legal judgment.
As of May 2026, EU enforcement authorities across multiple Member States have increased their focus on technical-threshold compliance. The direction of travel in enforcement is toward greater technical scrutiny of exporters' classification records. Businesses that cannot produce a documented technical comparison are at a disadvantage in any enforcement dialogue.
How does EU dual-use classification differ from other regimes?
The EU dual-use regime and the US Export Administration Regulations share a common foundation in the Wassenaar Arrangement and other multilateral export-control regimes, but they diverge in significant ways that affect cross-border supply chains.
Under the US regime, the classification produces an ECCN (Export Control Classification Number under the US Commerce Control List), a five-character alphanumeric code that determines the licence requirements for a given item to a given destination. An item that is not listed receives the designation EAR99, meaning it is subject to the EAR but not to a specific licence requirement for most destinations. The EU does not use a single equivalent code in the same way. An EU classification produces a list-entry reference, and the licence requirement is determined by the combination of that entry and the destination country.
A critical practical consequence: an item may be classified as EAR99 under US rules but as controlled under the EU list, or vice versa. A business that has classified its product for US export purposes cannot simply assume the same classification applies in the EU. Cross-reference is always required. This is a point our practice encounters regularly in M&A due diligence, where target companies have classified their products for their primary export market but not for the regime of the acquirer's jurisdiction.
The UK regime, following departure from the EU, maintains a list that closely tracks the EU Control List but is now updated separately by ECJU. Divergence between the two lists is limited at present but is growing at the margin, particularly for emerging technology categories. A business exporting the same product from both an EU and a UK entity must check both lists independently.
Switzerland, Canada, and Australia each operate regimes that draw on the same multilateral foundations, but update cycles, catch-all provisions, and end-user statement requirements vary. A shipment cleared for export from the EU may still require separate authorisation in a transit country operating its own controls. The strictest applicable prohibition governs at each stage of the transaction.
For businesses supplying technology that could have defence or proliferation applications, the US concept of deemed exports – the disclosure of controlled technology to a foreign national, even within a single country's borders – has no direct EU-law equivalent at the EU level, though some Member States apply comparable controls nationally. Teams advising on cross-border technology licensing should consult deemed export and technology transfer under the BIS/EAR alongside EU classification work.
Step 4: Determine the correct authorisation – and identify exceptions
Once a list entry is confirmed, the next question is which type of authorisation applies. EU Regulation 2021/821 provides for several: general export authorisations (standing permissions for defined categories of transactions to defined destinations), global export authorisations (company-specific licences covering multiple transactions), and individual export authorisations (single-transaction licences). The correct type depends on the item, the destination, and the end-user.
General export authorisations cover a significant range of low-risk exports to designated allied destinations. A business exporting to one of those destinations for a clearly civilian end-use should check whether it qualifies for a general authorisation before applying for an individual licence. Using an individual licence where a general authorisation would suffice adds time and cost without adding legal protection.
Where a general authorisation applies, it typically comes with conditions: registration requirements in some Member States, record-keeping obligations, and an obligation to ensure that the exporter knows, or does not have grounds to suspect, that the goods will be used for a prohibited purpose. These conditions are not optional. An exporter that relies on a general authorisation without meeting its conditions has not lawfully exported the goods.
End-use and end-user statements are required for many authorisations and for certain catch-all assessments. The exporter is responsible for the reliability of those statements and for conducting proportionate due diligence on the end-user. Where there are red flags – an atypical purchasing pattern, an unusual end-use claim, an intermediary without a visible commercial rationale – the exporter must escalate the analysis, not proceed and hope. See our related guide on EU dual-use classification and the OFAC interface for the interaction between EU controls and US secondary-sanctions risk in end-user assessment.
What are the most common risk flags in EU dual-use classification?
Several recurring patterns lead to classification errors and, ultimately, to enforcement enquiries. Recognising them in advance is the most efficient form of risk management.
The first is product-line thinking rather than item-by-item analysis. A business that classifies a product line once and applies that classification to every subsequent product generation, software release, or configuration variant is running a structural compliance failure. Classification must follow the specific item, not the brand or the product family.
The second is the technology and software gap. Many businesses rigorously classify their hardware but fail to assess whether the software embedded in it, or the technology transferred to the buyer to allow the buyer to operate or maintain it, is independently controlled. Technology and software associated with a controlled item are typically controlled to the same level as the item itself, even if transferred by electronic means.
The third is overreliance on customer declarations. A buyer that confirms in writing that the goods are for a civilian end-use provides a useful document but does not transfer the exporter's legal obligation. If the exporter has information suggesting the declared end-use is implausible – the item's capability far exceeds the stated civilian application, the end-user has no visible civilian operations, the destination is a known transshipment point – that information cannot be set aside on the strength of a signed statement.
The fourth is failure to reassess after regulatory change. The EU Control List is updated periodically to reflect changes agreed in the Wassenaar Arrangement and other multilateral forums. An item that was correctly classified as uncontrolled at the time of its initial assessment may subsequently become controlled when a new list entry comes into force. Businesses without a structured re-classification trigger linked to regulatory updates will miss these changes.
The fifth, and perhaps the most underappreciated, is the catch-all risk. Even where an item is correctly classified as not appearing on the EU Control List, the exporter remains subject to the regulation's general catch-all provisions if it knows or has reason to suspect that the items are intended for use in connection with weapons of mass destruction, military end-uses in embargoed countries, or re-export to a prohibited destination. Classification is a precondition for the catch-all analysis, not a substitute for it.
Step 5: Build and maintain the classification record
A classification without documentation is functionally worthless in an enforcement context. The record must be sufficient to allow a regulator – or an internal auditor – to retrace the classification step by step, understand the technical comparison that was made, identify who approved it, and confirm that the relevant list entries and notes were considered.
At minimum, the classification record should include: the item description and technical specification relied upon; the list entries considered and the reason for the conclusion on each; the technical data source; the name and qualification of the person who reached the technical conclusion; the date of the classification; and a note of any catch-all assessment conducted. Where external specialist advice was obtained, that advice should be retained as part of the record.
Record-keeping periods under EU dual-use rules and national implementing legislation vary. Some Member States require records to be maintained for a period of years after the export; the specific period should be verified in each Member State of export. The obligation applies to all export documentation, including shipping documents, end-user statements, and correspondence with customers about the intended end-use.
Classification records should be reviewed when: a new product generation is introduced; a software or firmware update is issued; the product is sold into a new market or end-use application; there is a change to the EU Control List; or there is a change to the company's ownership or group structure that affects the classification responsibility. In our experience, the last trigger – ownership change – is the one most frequently overlooked during M&A integration. For further guidance on the due-diligence dimension, see our related analysis at EU dual-use classification: the OFAC comparison guide (part 2).
A transaction has already been flagged, or a filing has been refused. An early review can preserve options that narrow with time. If you are facing a customs query, an enforcement letter, or a denial of an authorisation application, contact Calder & Vance at info@caldervance.com before responding to the authority.
When should a business involve counsel?
The question of when to involve external sanctions and export-control counsel is itself a risk-management decision. The earlier the involvement, the broader the options.
Counsel adds most value at four points. First, at the initial classification of a new product or technology, particularly where the item is close to a threshold, involves dual-use software or technology components, or will be exported to multiple jurisdictions under different regimes. Second, before entering a new market, where the catch-all risk is elevated and the end-user due diligence must be calibrated accordingly. Third, when there has been a change to the regulatory position – a new list entry, a new restrictive measure, a national-level change in implementing rules – that may affect the classification of existing products. Fourth, when there is any reason to believe that a past export may have been made without the correct authorisation.
A common concern we hear from compliance teams is that external review of a classification signals doubt about the internal programme. The opposite is true. Regulators regard documented external review as a mark of a well-functioning compliance programme, not as an admission of error. The myth that seeking a second opinion undermines a prior classification is precisely that – a myth. It has no basis in the enforcement practice of EU Member State authorities or of OFAC and BIS in the comparable US context.
Where a business has already exported without the correct classification or authorisation, the relevant question is whether a voluntary self-disclosure (VSD – a proactive report to the competent authority of an apparent violation, made before the authority has opened its own enquiry) is appropriate and how to structure it. The treatment of voluntary disclosure in EU Member State practice varies considerably from Member State to Member State. Engaging counsel at that point – rather than self-assessing and making a disclosure without advice – is particularly important.
Related practices
- Deemed export and technology transfer under BIS/EAR – US control of technology disclosures to foreign nationals, cross-border comparison
- EU dual-use classification and OFAC interface – how EU export controls and US sanctions interact in practice