Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Crypto and VASP sanctions compliance under BIS / EAR: legal support

A virtual-asset service provider with US-linked technology infrastructure processes a token transfer for a counterparty whose controlling shareholder appears on a restricted-party list. The compliance team is uncertain whether the BIS / EAR applies, how it interacts with OFAC's parallel sanctions obligations, and whether the firm's screening programme is structured to catch exactly this scenario. As of August 2026, enforcement attention on digital-asset businesses across US, EU, and UK regimes has intensified markedly. The question is not whether crypto and VASP sanctions compliance under BIS / EAR matters – it does. The question is whether your programme is built to the standard the regulators now expect.

The Bureau of Industry and Security administers the Export Administration Regulations, which apply to the export, re-export, and transfer of items – including certain software, technology, and digital tools – subject to US jurisdiction. For virtual-asset service providers and crypto businesses, BIS / EAR (the Export Administration Regulations administered by the US Bureau of Industry and Security) overlaps with OFAC sanctions obligations in ways that a compliance programme designed for traditional financial institutions will not automatically capture. The combined exposure is real, and missing either layer can produce significant civil or criminal penalties.

This page explains who the regime applies to, where the legal obligations sit, how the BIS / EAR analysis interacts with OFAC and the EU and UK regimes, what the high-risk patterns look like in practice, and how Calder & Vance assists businesses to build, audit, and defend a programme that holds up to regulatory scrutiny.

What does the BIS / EAR regime cover for crypto businesses and VASPs?

The EAR applies to any item that has US origin, contains a specified proportion of US-controlled content, or was produced using US technology – regardless of where the exporting entity is located. For crypto and virtual-asset businesses, the most operationally significant items within scope are software (including wallet software, cryptographic tools, and exchange engines), technology associated with those items, and certain hardware used in distributed-ledger infrastructure.

The starting point for any compliance review is item classification. Export Control Classification Numbers (ECCNs – the codes on the Commerce Control List that determine whether an item requires a licence) must be determined for every product a VASP develops, deploys, or transfers to a counterparty outside the United States. If the item falls outside any ECCN – classified as EAR99 – it is still subject to the EAR's end-user and end-use controls, including the Entity List and denied-party restrictions administered by BIS. The common assumption that open-source cryptographic software is always free of EAR obligations is not reliable; the carve-out is narrower than it appears.

An equally important point: the EAR's reach is extraterritorial. A non-US VASP that re-exports US-origin software to a restricted destination, or that provides a US-origin platform to a user on the BIS Entity List, can fall within BIS jurisdiction without any US establishment of its own. In our experience, this extraterritorial dimension is the most common gap in compliance programmes reviewed outside the United States.

How does the BIS / EAR analysis interact with OFAC sanctions obligations?

BIS and OFAC operate distinct but complementary regimes, and a transaction can trigger both simultaneously. OFAC's sanctions programmes prohibit dealings with designated persons and blocked jurisdictions; BIS controls the movement of specific items to specific end-users or end-uses. A token transfer to a non-designated counterparty in a non-sanctioned jurisdiction can still breach the EAR if the underlying software or infrastructure has a US nexus and the destination or use is restricted under the Commerce Control List.

The practical interaction that most frequently catches VASPs is this: OFAC screening identifies whether the counterparty is blocked; EAR due diligence identifies whether the item being transferred, the platform being accessed, or the technology being provided is restricted to that counterparty's jurisdiction or end-use. A programme that runs only OFAC screening will clear a transaction that the EAR would nonetheless prohibit.

A further complexity arises from BIS's Entity List (the list of foreign persons subject to specific licence requirements because of activities contrary to US national security or foreign policy interests). The Entity List is not the same as the OFAC SDN List. An entity can appear on one and not the other. Screening logic that queries only OFAC lists will not surface Entity List exposure. Both lists must be checked, and the logic for matching – including transliteration of non-Latin-script names and common alias patterns – must be calibrated specifically.

Where the two regimes diverge, the stricter prohibition governs. A business with a lawful OFAC licence for a transaction must still confirm that no independent BIS restriction applies. The licence from one authority does not authorise what the other prohibits.

The position above covers the standard case. Your facts – the software stack, the counterparty's jurisdiction, the ownership chain, and the end-use – change the analysis at every level.

For a parallel review of how the EU sanctions and dual-use regime applies to crypto and VASP businesses, see our EU-focused service page, which addresses Council regulation obligations and the divergences with the BIS / EAR standard.

What is the cross-border exposure for non-US VASPs?

Extraterritoriality is not a theoretical risk for digital-asset businesses. A non-US VASP that operates a platform built on US-origin software, hosts nodes with US-origin hardware, or routes transactions through US-based infrastructure is likely to be an exporter or re-exporter for EAR purposes. The analysis turns on the item's classification, the extent of US content, and the nature of the transfer.

For businesses operating under the EU regulatory regime, the interaction is particularly important. The EU dual-use regulation and the BIS / EAR are not identical. An item that falls outside EU export-control scope may still be caught by the EAR because of its US-origin content. In our practice, we routinely advise European VASPs that are already compliant with EU requirements but carry unexamined EAR exposure because their software stack includes US-origin components.

The UK position adds another layer. Post-Brexit, the UK operates its own export-control regime under the Export Control Order, administered by ECJU. Again, classification under UK rules does not automatically resolve classification under the EAR. A VASP regulated under the Financial Conduct Authority's registration regime for cryptoasset businesses must consider all three regulatory environments if it has US-origin technology in its stack.

For businesses with users in multiple jurisdictions – which is the default for most crypto exchanges and wallet providers – the question of which regime applies to which transaction, which user, and which item is not answered by a single compliance programme designed for one jurisdiction. Cross-regime mapping is a prerequisite for an effective programme.

For cross-border matters involving Japanese regulatory obligations, our Japan-focused service page addresses how VASP licensing and sanctions compliance interact under the applicable country regime.

What are the common risk patterns and high-risk scenarios for VASPs under the EAR?

In our experience advising VASPs and crypto businesses across multiple regimes, the following patterns generate the most significant BIS / EAR exposure. They are worth understanding not as an abstract checklist but as the specific scenarios that enforcement attention has repeatedly focused on.

The first pattern is software-as-a-service deployment to restricted end-users. A VASP providing exchange, custody, or DeFi infrastructure through a cloud-based or API-accessible service is, in regulatory terms, exporting or re-exporting the underlying software each time it grants access to a new user outside the United States. If the software has a relevant ECCN, that access may require a BIS licence depending on the destination or the end-user's profile. Automated onboarding without EAR-specific due diligence is a structural gap.

The second is developer and open-source contributions. A VASP employing engineers outside the United States who access and modify controlled technology on internal systems may be conducting a deemed export or deemed re-export under the EAR – a deemed export being the release of technology to a foreign national within the US, and a deemed re-export the release to a foreign national outside the US. Both can require a licence. Most VASPs have not mapped their technology-access permissions against the nationality profiles of their development workforce.

The third is token or platform access by Entity-Listed counterparties. As noted above, the Entity List is distinct from OFAC lists. A token sale, an institutional API relationship, or a market-making arrangement with a counterparty that appears on the Entity List can trigger a BIS licence requirement even if that counterparty is not an OFAC-designated person. The screening gap is common and straightforward to close – but only if the compliance programme is designed to close it.

The fourth is M&A and investment activity. A VASP acquiring another business inherits its technology assets and their classification status. If the acquired entity's software stack includes items with specific ECCN designations, the acquiring entity's post-merger operations may require licences that the original compliance programme did not contemplate. Pre-acquisition EAR diligence is as important as OFAC designation screening of the target.

If a transaction has already been flagged, or a review has surfaced a potential violation, an early assessment preserves options that narrow with delay. A voluntary self-disclosure (VSD – a proactive disclosure to BIS of an apparent violation) is a meaningful mitigation tool; its value diminishes the longer it is deferred.

What does a well-structured BIS / EAR compliance programme for a VASP look like?

A well-structured programme is built on five functional elements: item classification, restricted-party screening, licence determination, record-keeping, and incident response. Each element must be calibrated specifically for the digital-asset context; a programme transposed from a traditional financial institution or a non-digital goods exporter will have structural gaps.

Item classification is the foundation. Every software product, technology asset, and hardware component in the VASP's stack must be reviewed against the Commerce Control List to determine its ECCN or its EAR99 status. This is not a one-time exercise. Classification must be revisited when the product changes materially, when the regulatory regime changes, or when a new destination or end-use is introduced. We regularly find that classification reviews have not kept pace with product development cycles.

Restricted-party screening must cover OFAC lists, the BIS Entity List, the Denied Persons List, and the Unverified List as a minimum. Screening must be applied at onboarding, at the point of transaction, and on a periodic refresh basis. The matching logic must account for name variations, transliterations, and ownership-and-control chains. A single-database screening tool that does not aggregate across all relevant lists introduces a systematic blind spot.

Licence determination is the analytical step that follows classification and screening. Once you know what item is moving and who the counterparty is, the programme must have a defined process for determining whether a licence is required, whether a licence exception applies, and – if neither – how to escalate and halt the transaction. This process must be documented, and the documentation must be retained. Record-keeping obligations under the EAR run for a defined period and cover both the underlying transaction documents and the compliance determination.

Incident response covers the scenario where a potential violation is identified, whether through internal review, a counterparty notification, or a regulatory enquiry. The VSD mechanism is important here. The decision whether to make a VSD is legal in nature and fact-specific; it should not be delegated to the compliance team alone. External counsel should be involved at the point where a violation appears probable.

What the programme also needs, and what many digital-asset businesses underinvest in, is a live audit cycle. Sanctions and export-control rules across all regimes are updated regularly. A programme designed for last year's regulatory environment may not cover today's obligations. The audit cycle should be tied to a defined review frequency and should test both the written procedures and the operational reality of how those procedures are applied.

For cross-jurisdictional compliance audit and testing, our sanctions risk and compliance team works across the major regimes to stress-test programme design and identify gaps before a regulator does.

A common misconception: does the EAR only apply to physical goods?

The most persistent myth we encounter from crypto and VASP clients is that the EAR applies only to physical exports of hardware and equipment, and that software, platform access, and technology transfers in the digital-asset context fall outside its scope. This is incorrect.

The EAR explicitly covers software and technology, including the release of technology by any means – electronic transmission, visual inspection, oral communication, or any other method. A platform that a VASP makes accessible to a user in a restricted destination is an export or re-export of the software for EAR purposes. The fact that no physical goods cross a border does not change the analysis.

The misconception is consequential. VASPs that operate on this assumption typically have no ECCN classification process, no licence-determination workflow, and no Entity-List screening. They are exposed across the full range of the regime's prohibitions without knowing it. The correction requires a structured review, not a patch to an existing programme.

A related misconception is that because a VASP is regulated by a financial authority – the Financial Crimes Enforcement Network, the Financial Conduct Authority, a national competent authority under the applicable country regime – it has satisfied its US export-control obligations. Financial regulation and export-control regulation are distinct regulatory environments with different authorities, different instruments, and different enforcement mechanisms. Compliance with one does not address the other.

How Calder & Vance assists VASPs and crypto businesses on BIS / EAR compliance

We work with VASPs, crypto exchanges, digital-asset custodians, DeFi infrastructure providers, and token issuers to build and maintain compliance programmes that address BIS / EAR obligations alongside the OFAC, EU, and UK frameworks that most of these businesses also face.

Our work in this area covers six defined activities. First, we classify the client's technology stack against the Commerce Control List, identifying ECCN designations and EAR99 items, and map the results to the client's product deployment and user-access patterns. Second, we design and test the restricted-party screening programme, covering all relevant lists and calibrating the matching logic to the specific counterparty profile of the business. Third, we build the licence-determination workflow, covering the applicable exceptions and the escalation and record-keeping procedures required when a potential licence requirement is identified. Fourth, we advise on cross-border EAR issues, including extraterritorial reach, deemed exports, and the interaction with EU, UK, and other national export-control obligations. Fifth, where a potential violation has been identified, we scope the apparent breach, advise on whether a VSD is appropriate, and prepare the submission. Sixth, we conduct periodic audit reviews to keep the programme current as the regulatory environment changes.

In a recent matter, a European crypto infrastructure provider discovered, during a pre-investment compliance review, that its platform software contained US-origin components with a specific ECCN designation. The business had been operating under the assumption that EU dual-use rules were the only applicable export-control regime. We classified the items, mapped the user base against the Commerce Control List's country and end-use controls, identified two categories of access that required a BIS licence, and assisted the client in applying for the appropriate authorisation before the investment completed. The matter resolved without enforcement action.

In our experience, early engagement – before a transaction is signed, before a product is deployed to a new market, or before an acquisition closes – is almost always more effective and less costly than remediation after the fact. Compliance counsel is not just a cost of operation; it is the mechanism by which a business avoids a cost that can be far larger.

To stress-test your screening and compliance programme, or to discuss a specific EAR exposure, reach our team at info@caldervance.com.

Related practices

Frequently asked questions

How long does managing crypto sanctions exposure take under BIS / EAR?
The timeline depends on the scope of the review and whether a licence application is required. An initial item-classification review for a mid-sized VASP typically requires several weeks. Restricted-party screening design and testing adds further time depending on system complexity. Licence applications to BIS are subject to the agency's processing times, which vary by item and destination; verify the current position before relying on any indicative figure. A voluntary self-disclosure process runs on its own timeline, which is fact-specific and should be managed with external counsel from the outset.
What are the main risks in crypto and VASP sanctions compliance under BIS / EAR?
The principal risks are: providing platform access to Entity-Listed counterparties without a licence; exporting or re-exporting US-origin software to restricted destinations without EAR classification having been completed; failing to apply the deemed-export rules to a development workforce with non-US nationalities; and maintaining screening logic that covers OFAC lists but not BIS restricted-party lists. Each risk can produce civil or criminal liability under the EAR. The compounding factor for digital-asset businesses is the speed of product deployment; compliance infrastructure rarely keeps pace with product development unless it is designed to do so.
Do we need specialist counsel for crypto and VASP sanctions compliance?
For businesses with US-origin technology in their stack, users or counterparties across multiple jurisdictions, or any prior indication of a potential EAR issue, specialist counsel is the practical standard. General compliance counsel and financial-crime lawyers typically do not carry export-control expertise. The BIS / EAR analysis is a distinct legal discipline requiring specific knowledge of ECCN classification, licence exceptions, and the EAR's enforcement posture. In our practice, businesses that engage counsel only after a potential violation has surfaced face a narrower set of options and, in most cases, higher costs than those that build a compliant programme from the outset.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.