Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · EU

Export-licence determinations under EU: what businesses must know

A trading company in the Netherlands contracts to supply precision measurement instruments to a buyer in a third country. The goods are technically advanced but not obviously military. The compliance team asks: do we need an export licence? The answer determines whether the shipment leaves the warehouse or sits in a queue for months. Get the classification wrong and the consequences range from a blocked consignment to a criminal investigation.

Under the EU dual-use regime, an export licence is required whenever goods, software, or technology listed on the EU Common Military List or the dual-use list are exported from the customs territory of the European Union without a valid authorisation. As of May 2026, the governing instrument is the EU dual-use regulation, administered at the national-authority level in each Member State, with the European Commission coordinating policy. The determination process has five steps: classification, end-user and end-use analysis, destination screening, licence-type selection, and application.

This guide walks through each step, identifies the points where determinations most often go wrong, and explains how the EU regime compares with the positions taken by OFAC, BIS, and OFSI on equivalent questions.

What is the EU dual-use regime and who administers it?

The EU dual-use regime controls the export of goods, software, and technology that have both civil and military applications – the test that gives dual-use its name. The governing instrument is the EU dual-use regulation, a directly applicable regulation that applies uniformly across all Member States. Licensing decisions are taken by the competent national authority in the Member State from which the goods are exported, not by the European Commission directly.

That split matters in practice. A business exporting from Germany faces the German national authority; one exporting from France faces SGDSN / SBDU. Procedural timelines, application formats, and case-officer practice differ by Member State, even though the substantive classification criteria and control list are common. In our cross-border practice, this fragmentation regularly surprises businesses that assumed one EU clearance would suffice for all Member States.

The control list itself – the EU Common Military List and the dual-use annexes – is maintained at EU level. It is divided into categories covering materials, chemicals, electronics, computers, telecommunications, sensors, lasers, navigation, marine, and aerospace goods and technology. Each category entry sets out the technical parameters that trigger control. Exporters who read only the general category heading and miss the technical specification notes are a recurring source of mis-classification errors.

The regime also operates a catch-all control: goods not on the list may still require a licence if the exporter has reason to believe they will be used in connection with weapons of mass destruction or certain military programmes. The catch-all is triggered by knowledge or notice, not by the physical characteristics of the goods alone. That is a materially different logic from the list-based classification, and it creates a second determination layer that some compliance programmes overlook entirely.

Step 1: Classify the goods, software, or technology

Classification is the foundation of every export-licence determination. The first question is whether the item – product, software, or technology – is described by any entry on the EU dual-use list. The determination is technical, not commercial: the same device can be controlled in one configuration and not in another, depending on parameters such as operating frequency, processing speed, temperature range, or materials composition.

The classification exercise should be conducted against the technical specifications of the item as it is actually configured for export, not the broadest possible version the manufacturer offers. Over-classification wastes licence capacity and delays routine shipments. Under-classification is the greater risk: it can result in a shipment being stopped by customs, a licence demand on arrival, or a referral to the enforcement authority.

Where the classification is genuinely uncertain, EU rules provide a mechanism to request a binding classification determination from the competent national authority. Not every business uses it. Practitioners who do find it creates a defensible record and reduces subsequent customs challenge. If your classification exercise produces an answer at the margin, that formal route is worth considering before the first shipment departs.

Software and technology present a particular challenge. The EU regime controls technology in the sense of technical data – drawings, specifications, instructions, know-how – whether transferred physically, electronically, or verbally. A product that ships freely may still require a licence for the associated technical documentation or for the engineering support provided remotely. That gap between hardware classification and technology-transfer controls is one of the most frequently missed points in EU export-compliance programmes.

Step 2: End-user and end-use analysis – what does the destination change?

Even when goods are not listed, the identity of the end-user and the stated end-use are legally relevant under the EU regime. The catch-all control, and separately the obligation to refuse if the exporter knows of a prohibited end-use, means that end-user analysis is a mandatory component of every determination, not a discretionary add-on.

End-user screening must go beyond a name check against the EU Consolidated List and the UN Consolidated List. The relevant questions are: who is the ultimate recipient, what will the goods be used for, is there a risk of diversion to a third party or a third country, and does the stated end-use align with the buyer's apparent capabilities and commercial activity? These questions require judgement, not merely list-matching.

In our experience, the most common failure at this stage is treating end-user analysis as a one-time pre-export check rather than a continuing obligation. If information emerges after a licence is granted that changes the end-use picture, the exporter may be obliged to notify the competent authority and, in some circumstances, to suspend shipments. Compliance programmes that treat the licence as a permanent clearance rather than a conditional one create ongoing exposure.

The cross-regime comparison is instructive here. Under the US EAR administered by BIS, the Entity List and the denied-parties lists operate as hard stops regardless of classification. Under the EU regime, the control is more principles-based: an unlisted end-user with a concerning profile may still trigger the catch-all obligation. Neither system is purely mechanical. Both require the exporter to maintain documentary evidence of the analysis conducted, because that record is central to any enforcement defence.

Step 3: Destination screening and sanctions overlay

Destination matters at two levels in an EU export-licence determination. First, certain destinations trigger the EU arms embargo or a sectoral trade restriction under the EU sanctions regulations, which operate independently of and in addition to the dual-use regime. Second, the destination itself is a factor the competent national authority weighs when deciding whether to grant a licence.

The EU maintains a consolidated arms embargo list and a series of destination-specific trade restrictions under Council regulations. These are distinct legal instruments from the dual-use regulation, but they interact: goods that are not controlled under the dual-use list may still be prohibited or restricted under a sanctions regulation if the destination, the end-user, or the intended use falls within a sanctions provision. Running the two analyses in sequence – dual-use classification first, sanctions screen second – is the correct sequence, but the analyses must both be completed.

A further overlay arises from the EU's General Export Authorisations (GEAs). These are standing authorisations – broadly equivalent to the general licences used by OFAC and OFSI – that permit exports of specified goods to specified destinations without a case-by-case licence application, subject to registration requirements and reporting obligations. Not all EU Member States register GEA use in the same way, and the registration requirement is itself a compliance obligation with a timeline that varies by Member State.

For a business shipping from multiple EU Member States, the practical question is whether a GEA covers the transaction in each Member State of export or whether a national general authorisation (NGA), a global project licence, or a specific individual licence is required for some of the legs. That analysis must be done separately for each Member State of export. Treating a GEA that is valid in one Member State as automatically applicable in another is an error we see regularly in multi-site exporters.

The position above covers the standard classification-and-destination case. Your facts – the specific configuration of the goods, the counterparty structure, the route, and the Member State of export – can change the analysis entirely.

For an initial assessment of your EU export-licence position, contact Calder & Vance at info@caldervance.com.

Step 4: Selecting the right licence type

Once classification and destination analysis confirm that a licence is required, the exporter must select the correct licence type. The EU system offers four main forms: a Union General Export Authorisation, a national general authorisation, a global project authorisation, and a specific individual licence. Each has different scope, conditions, and administrative obligations.

A Union General Export Authorisation covers a defined list of items to defined destinations. It is self-executing for eligible transactions, but the exporter must register with the competent national authority before first use in most Member States, and must maintain records of each use. The GEA is the most efficient route when it is available, but its item and destination scope is narrower than many exporters assume.

A global project authorisation covers multiple consignments to one or more end-users under a defined project. It is suited to long-term supply relationships and project-based contracts. It requires the exporter to describe the scope of the project and the expected volume and value of exports, and it carries ongoing reporting requirements. In our cross-border practice, global licences are often underused by businesses that default to individual licences for every shipment, creating unnecessary administrative load.

A specific individual authorisation is the baseline where no general or global licence is available. It covers a defined consignment to a defined end-user for a defined end-use. The application must include a technical description of the goods, an end-user undertaking, and supporting documentation on the intended use. The processing time varies by Member State and by the sensitivity of the transaction.

Selecting the wrong licence type – for example, relying on a GEA for a transaction where the destination or item is outside its scope – is a compliance violation even if the underlying export would have been licensable. The authorisation must match the transaction. That matching analysis is the fourth step of the determination and should be documented in the compliance file.

Step 5: Application, documentation, and post-approval obligations

The application stage differs by Member State, but the substantive content requirements are broadly consistent. Every application needs a technical description of the goods, the classification reference, end-user information including the end-user undertaking, and information about the transaction parties. Some competent authorities require a copy of the contract; others require a government end-user certificate for sensitive destinations.

Record-keeping is a distinct obligation. The EU dual-use regulation requires exporters to maintain records of authorisations, export declarations, commercial documentation, and end-user undertakings for a period set by the applicable national implementing rules. In practice, this means a five-year minimum in most Member States, though some have adopted longer periods. Those records must be available on demand for inspection by the competent authority and customs.

Post-approval obligations do not end with the licence grant. If the transaction changes materially – the goods are reconfigured, the end-user changes, the stated end-use changes – the exporter must assess whether the existing licence still covers the transaction or whether a new authorisation is required. Automatic notification obligations may apply. Shipping against an authorisation whose conditions have been superseded by a change in facts is an often-litigated ground of enforcement.

The cross-border dimension surfaces again here. If the exported goods incorporate items controlled under the US EAR – for example, US-origin technology or components that have been incorporated into a product subsequently exported from the EU – then BIS re-export controls may apply in addition to the EU licence obligation. A de minimis analysis under the EAR is required whenever a product destined for export from the EU contains US-origin controlled content above the applicable threshold. Running the EU and US analyses in parallel, rather than treating them as mutually exclusive, is the correct approach for any goods with a mixed-origin supply chain.

If a transaction has already been flagged by customs or a competent authority has raised a query, an early review can preserve options that narrow significantly with time. To discuss a specific situation confidentially, write to info@caldervance.com.

Common risk flags and when to involve counsel

Certain patterns in an export-licence determination raise the risk profile of a transaction materially. Identifying them early is the purpose of a well-designed pre-export review process.

The first flag is an end-user who operates in a sector – electronics procurement, aerospace component distribution, advanced manufacturing tooling – that is commonly associated with diversion to controlled programmes. The goods need not be inherently sensitive for this flag to apply: the diversion risk arises from the end-user's profile, not only from the technical specification of the item.

The second flag is a transaction structure that breaks the normal commercial logic: a buyer with no apparent business in the field, payment terms that are inconsistent with the stated commercial relationship, or a request to re-route or re-consign after the sale is agreed. These patterns are precisely what the catch-all control is designed to capture, and they are also exactly what enforcement agencies look for when building a case.

The third flag is a multi-jurisdiction supply chain. Where goods incorporate US-origin content, are transshipped through a third country with its own controls, or involve a party subject to any sanctions regime, the export-licence determination becomes a multi-regime exercise. A determination that is correct under EU law may still leave the business exposed under the EAR or under the applicable sanctions regulations of another jurisdiction.

A common myth in this area is that obtaining a specific individual licence from the competent national authority resolves all export-control obligations for the transaction. It does not. The EU licence addresses the EU dual-use obligation. It does not resolve US re-export controls on US-origin content, UK export-control obligations if the goods pass through UK territory, or the arms-embargo restrictions that operate under separate EU regulations. Each obligation must be satisfied independently, and the stricter prohibition governs where they diverge.

Counsel should be involved when: classification is genuinely uncertain and a formal determination from the competent authority is being considered; when an end-user raises concerns under the catch-all analysis; when the goods have a mixed US/EU origin and a de minimis assessment under the EAR is required; or when a customs authority has detained a shipment or opened an inquiry.

How the EU determination compares with BIS, OFAC, and OFSI

The EU dual-use regime and the US EAR share a common architecture: both use a control list, both apply end-user and end-use conditions, and both provide general and specific authorisation routes. The differences are in the mechanics of administration, the scope of extraterritorial reach, and the post-export obligations.

Under the EAR, BIS uses a unique classification identifier – the ECCN (Export Control Classification Number under the US Commerce Control List) – to designate controlled items, and the relevant reasons for control determine which licence exceptions and licences apply. The EU system uses a category-and-entry structure without a single equivalent to the ECCN, which means that a product with a BIS classification cannot be mapped mechanically to the EU list; a separate EU classification must be conducted.

The BIS regime has a materially broader extraterritorial reach through the de minimis rule and the foreign direct product rule (FDPR): US controls can follow goods outside the United States when they incorporate controlled US-origin content above the applicable threshold or when they are produced using certain US technology or equipment. The EU regime does not have an equivalent general extraterritorial reach, though EU arms embargoes and sectoral measures can apply to EU-connected persons and entities regardless of where a transaction occurs.

OFAC operates primarily as a sanctions authority, not an export-control authority. Where the EU dual-use regime controls items by their technical characteristics, OFAC controls transactions by the identity of the parties and the destination. The two regimes can bite simultaneously on the same transaction when the goods are dual-use controlled and the end-user or destination is also sanctioned. For that class of transaction, both a dual-use licence and a sanctions licence (or a sanctions determination that no licence is required) are needed before the shipment can proceed.

OFSI in the UK administers financial sanctions, not export licensing. UK export licensing sits with the ECJU under the Export Control Order. Post the United Kingdom's departure from the EU, the UK has maintained a control list that is based on the EU list but has since diverged incrementally. A business that licensed an export from the UK under the EU list prior to that divergence cannot assume the classification remains valid; a fresh UK-specific analysis is required for UK exports.

For a detailed comparison of US deemed-export controls and the EU technology-transfer obligations, see our guide on deemed-export technology controls under BIS and the EAR. For the next step in the EU export-licence determination process, see our follow-on guide covering EU licensing applications and post-licence compliance. For the OFAC equivalent analysis, see our guide on export-licence determinations under OFAC.

Related practices

Frequently asked questions

What are the steps to determine the export-licence requirement under EU?
There are five steps: first, classify the goods, software, or technology against the EU dual-use list; second, conduct end-user and end-use analysis including a catch-all assessment; third, screen the destination against EU arms-embargo provisions and sanctions regulations; fourth, identify the correct licence type – GEA, national general authorisation, global authorisation, or specific individual licence; fifth, prepare and submit the application with the required documentation and maintain records for the period required by the applicable national rules. Each step must be completed and documented before the shipment departs.
What is the most common mistake in export-licence determinations?
The most common mistake is treating the EU dual-use licence as the only export-control obligation. Businesses routinely overlook the independent layer of EU sanctions regulations that may restrict the same transaction on different grounds, and they miss the US re-export obligations that apply when the goods incorporate US-origin controlled content. A determination that is correct under EU dual-use rules alone is incomplete for any transaction involving mixed-origin goods, sanctioned-country destinations, or parties connected to a US-regulated supply chain.
How does EU differ from other regimes here?
The EU regime is administered at Member State level, which means that procedural requirements, timelines, and case-officer practice differ across the EU despite the common control list. Unlike the US EAR, the EU regime does not use a single classification code equivalent to the ECCN, so US and EU classifications cannot be mapped mechanically to each other. The EU also lacks the broad extraterritorial reach of the BIS foreign direct product rule, though EU arms embargoes and sanctions regulations may apply extraterritorially to EU-connected persons. The UK export-control regime, post-divergence, must now be treated as a separate analysis from the EU.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.