When developing, shipping, or funding cryptographic technology, a principal reference for rules governing the export of encryption can be found in the national controls maintained by each jurisdiction. In practice, this means the commercial and security law of the country where the supplier, developer, or customer resides, as well as the destination and transit countries. This evergreen explainer describes the core regimes, obligations, and practical steps organizations should use to determine whether their encryption products or services are controlled and how to comply.
What export controls cover encryption
Export controls are government rules intended to limit the transfer of specific technologies, including encryption, across borders. Controls apply not only to physical goods but also to technical data, software, and related services. While objectives vary by country, they commonly address national security, foreign policy, crime prevention, and proliferation risks. Encryption is treated as a dual-use good: it has civilian and commercial uses, but can also affect law enforcement and security capabilities. As a result, many jurisdictions require authorization or notification before exporting, reexporting, or even transferring encryption technology to another country or to a foreign national within your own country.
Key definitions and scope
In most regimes, the scope turns on the item’s encryption standard and its intended use. Controls typically cover:
- Software designed to perform cryptographic functions, such as key agreement, authentication, encryption, digital signatures, and hashing.
- Embedded encryption in broader systems, devices, or applications that incorporate controlled cryptographic functionality.
- Technical documentation, source code, and related design information that enables the development or integration of encryption.
- Services that provide cryptographic engineering, customization, or hosted solutions when the underlying technology is controlled.
Many systems use thresholds based on key length, algorithm type, or technical parameters to determine whether an item is subject to control. For example, items featuring certain symmetric or asymmetric algorithms above specified key lengths are more likely to be classified as controlled encryption technology. Whether the same controls apply to consumer apps, open source code, or mass-market products depends on the specific regime and the item’s characteristics.
Major jurisdictional regimes
The principal reference for rules governing the export of encryption differs by country, but several regimes consistently shape global compliance. Each has its own scope, licensing processes, and list of controlled destinations, parties, and technologies.
United States: EAR and related frameworks
In the United States, the Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS), are the primary rules for most commercial encryption items. The EAR applies to U.S. persons and items with a sufficient connection to the United States, including foreign-made goods that incorporate controlled U.S. encryption technology or are controlled for other reasons. Encryption subject to the EAR may require a license for export or reexport, depending on the destination, end user, and technology type. For lower-risk shipments, a license may not be required if the item qualifies for an exemption, such as the Export Control Reform Act (ECRA) presumption or specific license exceptions designed for widely used technologies. The EAR also governs publication and fundamental research disclosures involving controlled encryption.
European Union and the Dual-Use Regulation
At the EU level, the Dual-Use Regulation sets the framework for exporting controlled goods and technologies, including encryption. A centralized authorization system handles cases where a license from the national competent authority is required. The regulation classifies controlled items into categories, annexes, and groupings, with encryption often listed under specific control groups based on capability and risk. Member states implement and enforce the rules, so a shipment may require additional national permits beyond the EU-level authorization. Transit rules and end-use checks are also part of the EU approach.
Other significant regimes
Outside the U.S. and EU, many countries apply their own controls or reference multilateral arrangements. Examples include:
- United Kingdom: The Strategic Export Controls regime, enforced by the Department for Business and Trade, includes encryption under specific license groups.
- China: Controlled through the Export Control Law and related catalogs administered by ministries and commissions.
- Russia, Turkey, and others maintain national lists and procedures that may require separate approvals.
- Multilateral frameworks such as the Wassenaar Arrangement provide baseline guidance, but national rules may be stricter.
Because rules vary widely, a principal reference for rules governing the export of encryption in one jurisdiction may not apply in another. Organizations must identify which regimes reach their products and activities.
Practical compliance obligations
Compliance typically involves understanding when controls apply, classifying items, and completing required procedures before shipping or publishing technical information. Even if a license is not required, record-keeping and due diligence responsibilities usually remain.
Steps organizations commonly follow
- Determine whether your item is controlled encryption under each applicable regime.
- Identify the destination(s), transit countries, and foreign nationals involved.
- Check license requirements, exemptions, and license-exempt destinations on the official control lists.
- Prepare and submit applications where required, including technical descriptions and end-use assurances.
- Implement internal controls, such as screening, classification, and training, to reduce risk.
- Maintain records of reviews, decisions, and submissions to support audits or inquiries.
Consequences of non-compliance
Export control violations can carry serious repercussions, including civil penalties, criminal charges, denial of future licenses, and reputational harm. Authorities in different countries may conduct audits, inspections, or investigations, particularly for high-risk or high-value items. Because encryption technologies can affect national security and public policy, regulators often treat violations seriously. For these reasons, organizations should adopt a disciplined, documented approach to assessing controls and dependencies throughout their supply chain.
When to consult authorities and specialists
Regulations, classifications, and license policies can change, and public guidance may not cover every product or scenario. A principal reference for rules governing the export of encryption is most useful when combined with official sources and qualified review. Consider reaching out to the relevant national authority or a compliance professional when:
- Your product involves strong or novel cryptographic algorithms.
- You plan to ship to embargoed or sanctioned destinations.
- Your item integrates encryption with other controlled technologies.
- You rely on open source components that may still be subject to export controls.
Staying current on regulatory updates and interpreting them in context reduces risk and supports responsible innovation in encryption.
Summary table: Key features at a glance
| Attribute | Verified Detail | Source Type |
|---|---|---|
| Core scope | Encryption technology, software, source code, and related services | Regulations (EAR, Dual-Use, national laws) |
| U.S. authority | Export Administration Regulations (EAR) administered by BIS | U.S. government |
| EU framework | EU Dual-Use Regulation with centralized licensing | EU legislation |
| Common threshold | Controls often tied to algorithm type and key length | Regulatory criteria |
| Typical obligations | Classification, destination checks, licensing, record-keeping | Compliance practice |
| Enforcement risks | Civil penalties, criminal liability, license denial | Regulatory actions |
Comparison of primary jurisdictions at a high level
| Jurisdiction | Primary regime | Typical characteristics |
|---|---|---|
| United States | EAR | Risk-based licensing, broad reach to U.S. persons and U.S.-origin items |
| European Union | Dual-Use Regulation | |
| United Kingdom | Strategic Export Controls | |
| China | Export Control Law + catalog | |
| Multilateral | Wassenaar Arrangement |
Bottom line
A principal reference for rules governing the export of encryption can be found in the national export control systems that classify, restrict, and require oversight for cryptographic technology. In most cases, this means the laws and regulations of the country where your organization is based, where your product is developed or shipped from, and where it is destined. By classifying your item correctly, checking license requirements, documenting decisions, and staying updated on regulatory changes, you can manage compliance effectively and reduce legal and reputational risk over the long term.