A payments firm operating between Singapore and the United States processes a token transfer for a decentralised-finance protocol. The protocol's smart-contract deployer is incorporated in a jurisdiction under a US-administered sanctions programme. The compliance team asks: does the Bureau of Industry and Security (BIS) – the US agency responsible for export controls under the Export Administration Regulations (EAR) – have anything to say about this transfer? The answer is more consequential than most VASP compliance programmes assume.
As of August 2026, crypto assets, blockchain-based payment rails, and the software that underlies them are squarely within the EAR's scope where they meet the definition of a controlled commodity, software, or technology. BIS administers the EAR under the authority of the Export Control Reform Act. Violations carry both civil and criminal exposure – and the extraterritorial reach of US controls means that a non-US VASP using US-origin software or routing through US infrastructure can be caught regardless of where it is incorporated.
This briefing explains who administers these obligations, what the EAR prohibits in the crypto and VASP context, how the ownership-and-control tests interact with OFAC's parallel sanctions rules, and where the EU and UK regimes diverge in ways that matter for cross-border compliance teams.
Who administers crypto and VASP sanctions compliance under the EAR – and what is the legal basis?
BIS, within the US Department of Commerce, administers the EAR under the authority of the Export Control Reform Act. The EAR governs the export, re-export, and in-country transfer of controlled items: commodities, software, and technology. Cryptographic software, encryption-enabled payment applications, and the underlying code that powers virtual-asset service providers (VASPs – firms that facilitate the exchange, transfer, or custody of crypto assets on behalf of others) all fall within this perimeter when they are listed on the Commerce Control List (CCL – BIS's master list of controlled items, each assigned an Export Control Classification Number, or ECCN).
The jurisdictional hook is broad. An export occurs not only when hardware or physical media crosses a border. A download of controlled software to a non-US person – including a counterparty accessing a VASP's platform from a restricted destination – can itself constitute an export under the EAR. In our cross-border practice, we regularly advise VASPs that have structured their licensing and customer-onboarding programmes around OFAC alone, without mapping the BIS layer. That gap is significant.
OFAC and BIS operate on parallel tracks. OFAC administers economic sanctions – it prohibits transactions with designated persons and blocked jurisdictions. BIS administers export controls – it prohibits or conditions the supply of controlled items to restricted end-users, end-uses, and destinations. A VASP can be fully clear of OFAC's SDN List while still requiring a BIS export licence to supply its software or services to a counterparty in a controlled destination. The two regimes must be read together.
What does the EAR prohibit in the crypto and VASP context?
The EAR's core prohibition is the unlicensed export, re-export, or in-country transfer of a controlled item to a restricted end-user, end-use, or destination. For a VASP, this prohibition surfaces in at least three distinct ways.
First, the VASP's own software platform may carry an ECCN. Encryption-enabled applications – which describes virtually every VASP trading or custody platform – are classified under the CCL's encryption controls. Depending on the classification, a licence or a licence exception may be required before that software can be made available to users outside the United States. "Available" is deliberately broad: it includes making the software downloadable, accessible via an API, or operable through a web interface.
Second, the Entity List (BIS's list of foreign persons subject to licence requirements because of their involvement in activities contrary to US national security or foreign-policy interests) is a distinct restriction layer. A counterparty or institutional client of a VASP that appears on the Entity List triggers a licence requirement for any item subject to the EAR – including software, technical data, and services. The Entity List is separate from OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons); an entity can be on one list but not the other, and the compliance action required differs accordingly.
Third, end-use controls under the EAR mean that even where an item is not formally listed on the CCL, a transaction may be prohibited if the exporter has knowledge that the item will be used in connection with a weapon of mass destruction programme, a restricted military end-use, or certain nuclear activities. In the crypto context, this is relevant for firms supplying analytics tools, monitoring software, or transaction-tracing technology where the end-user is an entity in a controlled sector.
What does knowledge mean here? The EAR defines knowledge to include not only actual awareness but also wilful blindness. A VASP that structures its onboarding to avoid learning the identity of its end-users – a pattern sometimes dressed up as a privacy-preserving design choice – cannot rely on ignorance as a defence.
How does the EAR interact with OFAC's crypto sanctions rules?
OFAC and BIS share a conceptual vocabulary but operate distinct legal standards. Understanding the interaction is essential for any VASP building a unified US-compliance programme.
Under OFAC's rules, a non-listed entity is treated as blocked if one or more blocked persons own it 50 percent or more in the aggregate, directly or indirectly – the 50 percent rule. The test is mechanical. It applies to smart-contract deployers, protocol governance entities, and token issuers just as it applies to conventional corporate structures. A VASP that processes a transaction for a protocol whose governance token is 50 percent or more controlled by a blocked person is, in OFAC's analysis, transacting with a blocked entity regardless of whether the protocol's address appears on any list.
BIS's Entity List analysis is different. There is no single ownership-percentage trigger. Instead, BIS assesses whether the foreign person concerned is acting on behalf of, or under the direction or control of, a restricted entity. The operative concept is end-user: who will actually receive and use the controlled item? A VASP must therefore conduct a two-track analysis: the OFAC 50-percent-rule screen for blocked-person ownership, and a separate EAR end-user assessment looking through any nominee or intermediary structure to identify the true beneficiary of the technology or software being transferred.
In a recent matter, a financial-technology firm supplying a blockchain-analytics platform to institutional VASP clients discovered during our diligence review that one client's ultimate beneficial owner appeared on the Entity List. The client was not on the SDN List; it would have passed a standard OFAC screen. The EAR exposure was nonetheless material, and we assisted the firm in scoping the apparent violation, advising on voluntary self-disclosure, and restructuring the onboarding programme to capture Entity List checks at the point of institutional account approval rather than solely at the transactional level.
What are the extraterritorial reach and the de minimis rules?
The EAR's extraterritorial reach is among the most far-reaching features of US export-control law. It catches non-US persons in two principal ways.
The de minimis rule determines whether a foreign-made product containing US-origin content remains subject to the EAR. Where US-controlled content exceeds a defined percentage threshold of the total value of a foreign-made product, the EAR continues to govern that product's export and re-export. For software products destined for certain countries, the applicable threshold is lower than for general destinations. A non-US VASP that builds its platform on a US-origin encryption library, or that integrates a US-origin payment-processing SDK, may find that its product is subject to the EAR even though neither the firm nor its platform was built in the United States. The current de minimis percentages are set out in the EAR; verify the applicable figure before relying on an exception.
The foreign direct product rule (FDPR) extends EAR jurisdiction to certain foreign-made items that are the direct product of US-origin technology or software. Several country-specific FDPR rules have been introduced in recent years, broadening the reach of US controls to foreign-produced semiconductors, software, and electronic components. For a VASP whose platform uses chips or firmware produced outside the US but derived from US-origin design tools, the FDPR analysis is a necessary – and often overlooked – step.
The cross-border implication is direct. A VASP incorporated in the EU, UK, or Singapore is not outside EAR jurisdiction merely because it has no US nexus in its corporate structure. If it uses US-origin software, routes transactions through US-hosted nodes, or incorporates US-origin technology in its platform, it operates inside the EAR's perimeter. We regularly advise EU and UK-based VASPs on this point; the assumption that US export controls stop at the US border is one of the most persistent and costly misunderstandings in this space.
How does the EU and UK regime compare – and where does the divergence matter?
The EU and the UK each maintain export-control regimes for dual-use items that intersect with the crypto and VASP sector, but neither has the same jurisdictional breadth as the EAR.
EU export controls for dual-use goods and technology are governed by EU Regulation 2021/821, which controls items listed in the EU's own control lists. Cryptographic software and technology appear on those lists, and the EU regime requires authorisation for export to non-EU destinations above certain technical parameters. However, the EU de minimis and foreign-direct-product rules are substantially narrower than their EAR equivalents. The EU does not assert the same reach over foreign-produced items that merely incorporate EU-origin content.
The UK operates its own export-control regime through the Export Control Order administered by the Export Control Joint Unit (ECJU). The UK's control lists broadly mirror the pre-Brexit EU lists, with periodic divergence as each regime updates its schedules independently. UK-based VASPs need to assess both sets of controls where they serve EU-based counterparties, because a transaction lawful under the UK regime may require separate authorisation under EU rules.
The practical implication for a cross-border VASP operating across all three jurisdictions is that the EAR sets the highest common denominator. Where the EAR requires a licence, compliance with EU and UK controls will not remedy that requirement. But the reverse is also true: a VASP that obtains a BIS licence exception does not thereby satisfy its EU or UK export-control obligations. Each regime must be satisfied independently. For a detailed analysis of the EU position, see our EU crypto and VASP compliance regime briefing.
What are the key risk flags for VASPs under the EAR?
Several patterns recur in our experience reviewing VASP compliance programmes, and each represents a material EAR exposure point.
Unclassified software. A VASP that has not obtained a formal classification determination for its platform software from BIS – and has not assessed whether a licence exception is available – cannot know whether it is operating lawfully. Many firms assume that because their platform is publicly downloadable or cloud-based, export controls do not apply. The EAR does not support that assumption.
Entity List gap in screening. Most VASP screening programmes are configured against OFAC lists. The Entity List, the Unverified List, and the Denied Persons List – all administered by BIS – are distinct and must be screened separately. A counterparty that clears an OFAC screen may nonetheless be on the Entity List, triggering a licence requirement for any controlled software or technology transferred to it.
Token and protocol exposure. The EAR's reach to software used in the deployment or operation of tokens, smart contracts, and decentralised protocols is unsettled in places, but the general principle is clear: if the software is subject to the EAR and it is made available to a restricted end-user, there is a potential violation. VASPs that list tokens or support protocol access without assessing the EAR classification of their own infrastructure are accepting a risk they may not have quantified.
Inadequate know-your-customer depth. The EAR's knowledge standard means that a VASP must look through its direct counterparty to assess the true end-user. Institutional clients that operate sub-accounts, omnibus wallets, or aggregated API access require enhanced diligence to confirm that the ultimate beneficiary is not a restricted end-user or end-use.
Re-export and cloud-service exposure. A VASP that hosts its platform on US-based cloud infrastructure and grants access to users in controlled destinations is, in OFAC and BIS analysis, potentially both providing services to a restricted destination and re-exporting controlled technology. The cloud provider's own licence conditions may not protect the VASP from its own export-control obligations.
How is the EAR enforced, and what does a voluntary self-disclosure involve?
BIS enforces the EAR through the Office of Export Enforcement. Civil penalties under the EAR are among the most significant in US administrative law: the maximum per-violation civil penalty is substantial, and where violations are wilful or involve items controlled for national-security reasons, criminal referral to the Department of Justice is available. The exact current penalty figures are set in the EAR and are periodically adjusted; verify the current amounts before relying on any figure.
BIS operates a voluntary self-disclosure (VSD – a mechanism by which a potential violator discloses an apparent violation to BIS before it is discovered by the agency) programme that is formally similar to, but distinct from, OFAC's VSD process. A well-prepared BIS VSD – including a root-cause analysis, a corrective-action plan, and a transaction chronology – can result in a significant reduction in the penalty base. Timing matters: a VSD submitted after BIS has initiated its own inquiry receives less credit than one submitted proactively.
The decision to file a VSD requires careful assessment. It is not always the right route. Where the violation is technical, isolated, and unlikely to be discovered, the cost-benefit analysis may point elsewhere. Where the pattern is systemic, or where a third party (a bank, a counterparty, a regulator in another jurisdiction) has already flagged the issue, prompt disclosure is generally preferable. In our enforcement-defence practice, we scope the apparent violation, advise on whether VSD is appropriate, and prepare the submission if the decision is made to proceed.
The interaction with OFAC enforcement is also relevant. A single transaction involving a restricted VASP counterparty in a sanctioned jurisdiction may constitute a simultaneous OFAC violation (for the transaction itself) and a BIS violation (for the supply of controlled software or technology). Multi-agency enforcement is increasingly common in the crypto space. Coordinating a VSD strategy across both agencies – and, where applicable, across OFSI or EU competent authorities – requires a unified approach rather than separate siloed filings.
When should a VASP involve external counsel – and what does the engagement look like?
The honest answer is: earlier than most do. In our experience, the cost of a proactive EAR classification review and a compliance-programme gap analysis is a small fraction of the cost of responding to a BIS enforcement inquiry or a multi-agency investigation. Is your organisation confident that its software classification is current and formally documented? If the answer requires a search of institutional memory rather than a compliance file, that is itself a risk indicator.
Three situations call for immediate external advice. The first is a transaction hit: a counterparty appears on the Entity List, the Denied Persons List, or the Unverified List during a screening run, and the VASP does not know what its obligations are. The second is a potential historic violation: a compliance review or an M&A diligence process surfaces a pattern of transactions that may have involved restricted end-users. The third is a regulatory inquiry: BIS or a partner agency (DOJ, OFAC, FinCEN) has made contact, however informally.
Beyond those trigger events, an annual EAR compliance review is appropriate for any VASP that operates across borders, uses US-origin software in its platform, or serves institutional counterparties with complex ownership structures. That review should cover software classification, licence-exception eligibility, screening-list coverage, end-user diligence procedures, and record-keeping against the applicable retention standard.
The position above covers the standard compliance posture. Your facts – the jurisdiction of your counterparties, the classification of your software, the origin of your infrastructure – change the analysis materially. To assess your EAR and OFAC exposure, contact Calder & Vance at info@caldervance.com.
For VASPs operating across the Asia-Pacific region, the Japanese export-control and sanctions obligations present distinct requirements. Our Japan crypto and VASP compliance briefing addresses those obligations in detail.
Related practices
- Sanctions compliance audit and testing (Australia) – independent testing of screening logic, ownership-chain mapping, and programme design against Australian and cross-border standards.
- EU crypto and VASP compliance regime briefing – analysis of EU dual-use export controls and Council-regulation sanctions obligations for virtual-asset businesses.