INTERNATIONAL TRADE LAW
Classifying Software & Technology Exports Under the EAR

Software and technology are classified for export the same way physical goods are — against the Commerce Control List — but they sit in their own product groups and carry rules that hardware never triggers. Under the Export Administration Regulations (EAR), software falls in product group D and technology in product group E of each Commerce Control List (CCL) category, and an export can happen without anything leaving the country. If you write code, license a platform, or share technical specifications with people abroad — or with foreign nationals at home — classification is where compliance starts.
Software and Technology Are “Items Subject to the EAR”
The EAR controls three kinds of “items”: commodities (hardware), software, and technology. All three are classified against the same CCL, which is organized into ten categories (0–9) and five product groups (A–E). For software and technology, two product-group letters do most of the work:
| Product group | Covers | Example ECCN |
|---|---|---|
| D — Software | Programs and source code tied to a controlled item | 3D001 |
| E — Technology | Information needed to develop, produce, or use a controlled item | 3E001 |
If your software or technology is described by an ECCN, that code and its reasons for control drive the license decision. If it is subject to the EAR but not listed anywhere on the CCL, it is EAR99 — the catch-all that covers most ordinary commercial code and documentation. EAR99 usually ships without a license, but a license can still be required for an embargoed destination, a restricted party, or a prohibited end use.
“Technology” Is Defined Narrowly — and Broadly at the Same Time
Under the EAR, technology means the specific information necessary for the “development,” “production,” or “use” of an item. That can be blueprints, formulas, engineering specifications, manuals, or technical assistance. It is not your marketing brochure or general know-how. The practical trap is that controlled technology travels through email, a shared drive, a video call, or a conversation — so an “export” of technology rarely looks like a shipment.
Deemed Exports: An Export That Never Crosses a Border
The rule that surprises most companies is the deemed export. Under 15 CFR 734.13, releasing technology or source code (but not object code) to a foreign person inside the United States is “deemed” an export to that person’s most recent country of citizenship or permanent residency. Showing controlled designs to a foreign national engineer in your U.S. lab, or giving a foreign contractor access to controlled source code, can require the same license you would need to ship the technology to their home country.
Deemed-export exposure is highest in R&D teams, universities, and any workforce that includes foreign nationals. The compliance answer is the same as for any export: classify the technology first, then check whether a license is required for the relevant country.
The Published-Information Carve-Out
Not all technical information is controlled. Under 15 CFR 734.3(b)(3) and 734.7, information and software that are “published” — made available to the public without restrictions on further dissemination — are generally not subject to the EAR at all. Published includes information distributed through open journals and media, presented at open conferences, available in issued patents and published patent applications, or posted on a website accessible to the public at no more than the cost of reproduction.
Two cautions: the carve-out turns on whether the information is genuinely public, not on whether you intended to publish it; and encryption source code and software (Category 5, Part 2) have their own publication and notification rules that do not track the general carve-out.
EAR or ITAR? Classify the Jurisdiction First
Before you assign an ECCN, confirm the item is even on the Commerce side. Software and technology that are defense articles on the U.S. Munitions List are controlled by the International Traffic in Arms Regulations (ITAR), administered by the State Department’s Directorate of Defense Trade Controls — not the EAR. If jurisdiction is genuinely unclear, the formal way to resolve it is a commodity jurisdiction request. Getting jurisdiction right comes before classification, because ITAR and EAR use entirely different control lists and license processes.
How to Classify Your Software or Technology
The workflow mirrors hardware classification, with the wrinkles above layered on:
- Confirm jurisdiction — EAR (dual-use) versus ITAR (defense article).
- Identify the related hardware. Software and technology ECCNs (the D and E entries) usually attach to the equipment they support, so find the relevant Category first.
- Work the technical parameters of the candidate ECCN, or ask the developer/manufacturer for the classification.
- Request a CCATS from BIS through SNAP-R when you need an authoritative answer. How that determination works is covered in the role of rulings in export classification.
- Document the basis for your classification and keep the record. For background on the code itself, see ECCN Explained.
The exporter remains responsible for the accuracy of the classification, so when the item is sensitive or the answer is ambiguous, get BIS’s determination rather than guessing.
Frequently Asked Questions
How is software classified differently from hardware?
Software is classified against the same Commerce Control List but sits in product group D, while the related hardware sits in group A and the underlying technology in group E. Source code can also trigger deemed-export rules that hardware does not.
What is a deemed export?
A deemed export is the release of controlled technology or source code to a foreign person inside the United States. Under 15 CFR 734.13 it is treated as an export to that person’s home country, which can require a license even though nothing physically ships abroad.
Is publicly available software subject to the EAR?
Generally no. Information and software that are genuinely published — freely available to the public without restrictions on dissemination — are usually not subject to the EAR under 15 CFR 734.3(b)(3) and 734.7. Encryption items are an important exception with their own rules.
Does my software need an export license?
It depends on the ECCN and the destination. Determine the ECCN (or confirm EAR99), check the reasons for control against the destination country, and screen the parties. Encryption, sanctioned destinations, and restricted parties can require a license regardless of the ECCN.
Software and technology are where export-control mistakes hide, because the “export” can be an email or a new hire. Reidel Law Firm helps exporters classify software and technology, manage deemed-export risk, and document the basis for every call on flat-fee terms. Get an export compliance memo.


