INTERNATIONAL TRADE LAW

Exporting Software & Technology: U.S. Controls

To export software or technology from the U.S. legally, you must first classify it under the Export Administration Regulations (EAR), then confirm whether your specific item, destination, end user, and end use require a license. Most commercial software needs no license to most countries — but “most” is doing a lot of work in that sentence. Encryption, “dual-use” capability, and the rule that sharing code with a foreign colleague inside the U.S. can itself be an export are where companies get caught.

This guide covers the framework. Because controls in this area change frequently, treat any specific classification as something to confirm against the current Commerce Control List before each shipment.

Step 1: Figure out which regulations govern your item

Two regimes split most technology exports:

  • The EAR (15 CFR Parts 730–774), administered by the Bureau of Industry and Security (BIS), covers commercial and “dual-use” software and technology — items with both civilian and potential military or proliferation uses.
  • The ITAR (22 CFR Parts 120–130), administered by the State Department’s Directorate of Defense Trade Controls (DDTC), covers defense articles and defense-related technical data on the U.S. Munitions List.

If your software was designed for or modified for a military application, assume ITAR until proven otherwise. Everything else is an EAR analysis.

Step 2: Classify the item (ECCN or EAR99)

Under the EAR, every item has an export classification. You are looking for one of two answers:

  • An Export Control Classification Number (ECCN) — a five-character code on the Commerce Control List that ties your item to specific reasons for control (national security, encryption, missile technology, and so on).
  • EAR99 — the residual category for items subject to the EAR but not listed with an ECCN. Most ordinary commercial software lands here and ships license-free to most destinations.

You can self-classify, ask a supplier, or request an official classification (a CCATS) from BIS. Do not guess: the ECCN determines whether you need a license and which license exceptions you can use.

Step 3: Pay special attention to encryption

Software that performs encryption is one of the most commonly controlled categories. Information-security items using cryptography for data confidentiality above defined thresholds are controlled under ECCN 5A002 (hardware) and ECCN 5D002 (software), with related technology under 5E002.

The EAR provides License Exception ENC (15 CFR 742.15) that authorizes most exports of qualifying encryption items — but it comes with conditions, including classification or self-classification reporting, mass-market provisions for retail products, and a hard prohibition on shipping to or releasing source code to nationals of Country Group E:1 (currently Cuba, Iran, North Korea, and Syria). Open-source and “publicly available” encryption source code has its own treatment. The thresholds and reporting rules here are technical; confirm them for your build before relying on the exception.

Step 4: Don’t forget deemed exports

A deemed export is the release of controlled technology or source code to a foreign person inside the United States — and the EAR treats it as an export to that person’s home country (15 CFR 734.13). That means letting a foreign-national employee, contractor, or visitor access controlled technical data — by email, screen-share, a demonstration, or a lab visit — can require a license without anything physically leaving the country.

This is the rule companies miss most often, because it turns ordinary internal collaboration into a regulated transfer. If you employ foreign nationals and handle controlled technology, build deemed-export screening into your hiring and access controls.

Step 5: Screen parties, destinations, and end uses

Classification is only half the analysis. Even an EAR99 product can be blocked by who is receiving it or what it will be used for:

CheckSource
Is the destination embargoed?OFAC sanctions programs; EAR Country Groups
Is the buyer or end user barred?BIS Entity List, Denied Persons List; OFAC SDN list
Is there a prohibited end use?EAR Part 744 (e.g., certain military, nuclear, or proliferation end uses)
Any “red flags”?BIS Know Your Customer guidance

International regimes such as the Wassenaar Arrangement and the Missile Technology Control Regime (MTCR) sit behind many of these controls and explain why certain software is listed at all.

Step 6: Keep records

The EAR requires exporters to keep export records — classifications, license determinations, screening results, and shipping documents — generally for five years. Good records are also your best defense if BIS ever asks how you reached a “no license required” conclusion.

Frequently asked questions

Does my software need an export license? Often not — most commercial software is EAR99 and ships license-free to most destinations. But encryption features, dual-use capability, the end user, and the destination can all flip that answer. Classify first.

What is a deemed export? Releasing controlled technology or source code to a foreign person located in the U.S. The EAR treats it as an export to that person’s country, so it can require a license even though nothing leaves the country.

Is open-source software controlled? Publicly available software and “published” encryption source code generally fall outside the EAR’s license requirements, but the rules are specific and have conditions. Confirm before you assume your release qualifies.

How long do I keep export records? Generally five years from the date of export under the EAR.

Shipping software or technology abroad and unsure how it classifies? Reidel Law Firm provides a flat-fee Import/Export Compliance Memo that works through your ECCN, license exceptions, and screening obligations in plain English. Get an import/export compliance memo →