EAR: Export Administration Regulations Guide
The Export Administration Regulations (EAR) govern the export, reexport, and transfer of commercial and dual-use items, technology, and software from the United States. Administered by the Bureau of Industry and Security (BIS), the EAR cover a far broader range of items than ITAR, including advanced semiconductors, encryption software, cybersecurity tools, telecommunications equipment, and many commercial technologies that could have military or intelligence applications. For technology companies with global customers or international workforces, EAR compliance has become one of the most operationally demanding compliance obligations in the regulatory landscape.
What the EAR Is and Who Issues It
The EAR derives its authority from the Export Control Reform Act (ECRA) of 2018, which placed the export control authority on permanent statutory footing (replacing temporary Emergency Economic Powers Act authority). BIS, within the Department of Commerce, administers the EAR through its Office of Export Enforcement (OEE) for enforcement and Office of Exporter Services for licensing and guidance.
The EAR has undergone significant expansion since 2018 in response to technology competition concerns, particularly relating to China. BIS has dramatically expanded controls on advanced semiconductors, semiconductor manufacturing equipment, AI-related technologies, and military-end-use items. The October 2022 semiconductor export controls (expanded in 2023 and 2024) represent the most significant restructuring of US export controls in decades and have had profound effects on US and international technology companies' global operations.
EAR enforcement is a joint responsibility of BIS and the Department of Justice, which can bring criminal charges. The Department of Homeland Security (Homeland Security Investigations) and the FBI also investigate EAR violations, particularly those involving sanctions evasion or national security.
Who Needs EAR Compliance
The EAR applies broadly to US persons, US companies, and in many cases non-US persons and companies handling US-origin controlled items.
US exporters must comply with the EAR for all exports of items subject to the EAR. The "subject to EAR" question is the foundational analysis: US-origin items and items incorporating more than a de minimis amount of US-controlled content are subject to EAR jurisdiction regardless of where they are located.
Technology companies are particularly affected due to extensive controls on advanced computing hardware, semiconductor manufacturing equipment, cybersecurity tools (including vulnerability research tools, intrusion software, and network monitoring equipment), encryption technology, and telecommunications equipment. The growth of technology export controls since 2018 has made EAR compliance a board-level concern at major US technology companies.
SaaS and cloud companies have EAR obligations when their services deliver controlled technology or software to foreign customers or when their computing services are used by restricted entities. Cloud platforms delivering controlled software capabilities to restricted countries or entities are engaging in deemed exports or reexports subject to EAR.
Companies with foreign national employees must implement deemed export controls. Sharing Export Control Classification Number (ECCN)-controlled technology with a foreign national employee in the US is a deemed export to that person's country of citizenship — requiring the same analysis as an international export.
Foreign companies with US-origin content in their products may be subject to the de minimis rule and foreign direct product rule, bringing non-US companies within EAR jurisdiction in certain circumstances — a significant expansion of reach that BIS has actively used in high-profile enforcement.
Key Requirements: Classification, Screening, Licensing, and Records
Commerce Control List (CCL) Classification
The CCL lists items subject to EAR licensing requirements, identified by Export Control Classification Numbers (ECCNs). ECCNs have five characters: a category number (0–9), a product group letter (A–E), and a reason for control indicator (three digits). For example, ECCN 3A090 covers certain advanced integrated circuits; ECCN 5D002 covers encryption software.
Items not on the CCL are designated EAR99 — the lowest control level, requiring only minimal compliance (sanction screening, basic recordkeeping). EAR99 items can generally be exported without a license, except to embargoed countries or entities on restricted party lists.
Classification analysis determines:
- Whether the item is subject to EAR at all
- The applicable ECCN (if not EAR99)
- The control reasons (national security, missile technology, encryption, etc.)
- The countries and end-uses that require licenses
AI and advanced computing have become the most dynamic area of EAR classification, with BIS publishing new rules and guidance on controls for AI chips, model weights, and training infrastructure on a recurring basis through 2024–2026.
Denied Party and Restricted Entity Screening
EAR requires screening all customers, partners, and end-users against several restricted party lists:
- The Entity List identifies specific organizations in specific countries subject to license requirements for specified items. Entity List designations have been a major US policy tool — thousands of Chinese, Russian, and other entities have been added since 2018.
- The Denied Persons List identifies individuals and entities denied export privileges for past violations.
- The Unverified List identifies parties whose end-use BIS has been unable to verify through end-use checks.
- The Military End-User (MEU) List identifies non-US military organizations requiring license review.
Screening must occur before each transaction, not just during customer onboarding — parties are added to lists continuously. Manual screening of high-volume transaction environments is impractical; automated screening software integrated into order management systems is standard practice.
License Determination and Management
For each proposed export, exporters must determine whether a license is required based on the ECCN, the destination country, the end-user, and the end-use. BIS maintains the Country Chart identifying which control reasons require licenses for specific countries.
Where a license is required, exporters must apply to BIS (or the State Department for ITAR, or the Treasury for OFAC sanctions) and wait for a decision before proceeding. License applications require detailed information about the item, end-user, end-use, and proposed transaction.
License exceptions are available for many common export scenarios — License Exception ENC (encryption items), License Exception STA (strategic trade authorization for certain low-risk destinations), License Exception BAG (personal baggage), and others. Understanding applicable license exceptions can dramatically reduce the licensing burden for many transactions.
Deemed Export Controls
The EAR deems the release of controlled technology to a foreign national within the US to be an export to the foreign national's country of citizenship. This applies to:
- Sharing technical drawings, specifications, or data with foreign national employees
- Giving foreign national employees access to EAR-controlled software source code
- Allowing foreign national colleagues to use EAR-controlled equipment
Companies must implement deemed export control programs that identify which employees can access controlled technology based on their citizenship and the applicable ECCN and control reasons.
Record-Keeping
EAR requires records of all export transactions to be maintained for five years. Records must include export licenses, Electronic Export Information (EEI) filings, end-user statements, and transaction documentation. Records must be retrievable and producible on demand during BIS investigations or audits.
Costs and Timeline
| Program Element | Estimated Cost |
|---|---|
| Initial CCL classification project | $20K–$80K |
| Compliance program development | $20K–$60K |
| Restricted party screening software | $10K–$50K/year |
| Legal advisory (ongoing) | $25K–$100K/year |
| Deemed export program development | $15K–$40K |
| Training (initial + annual) | $10K–$25K/year |
| Total first-year program | $80K–$300K |
| Ongoing annual program | $50K–$175K |
Technology companies with complex product portfolios and extensive international sales will be at the high end. Simpler companies with limited controlled items and primarily domestic sales will be at the low end.
Comparison with Related Frameworks
EAR and ITAR are the two pillars of US export control. ITAR controls USML defense articles; EAR controls commercial and dual-use CCL items. The two regimes have approximately 35% conceptual overlap — shared principles of classification, licensing, record-keeping, and deemed export. Many defense companies must comply with both: ITAR for purely military items, EAR for commercial items with defense applications.
DFARS/CMMC (approximately 30% overlap) addresses cybersecurity of contractor systems, not export control. The interaction between EAR and DFARS is primarily in the handling of controlled technical data in digital environments — DFARS/CMMC governs how contractor IT systems protect CUI (which may include EAR-controlled technical data), while EAR governs whether and how that data can be shared with foreign persons or countries.
ISO 27001 provides information security management structure that supports EAR compliance in the technology protection dimension — controlling access to controlled technology requires information security controls. However, ISO 27001 does not address classification, licensing, or the legal and transactional dimensions of EAR compliance.
How Automation Helps
EAR compliance at scale — high-volume transactions, global customer bases, multinational workforces — is practically impossible without automation. Restricted party screening, ECCN tracking, license management, and record-keeping all benefit enormously from technology.
LowerPlane supports export control compliance program management including EAR-related policy, training management, and evidence collection. Starting at $4,000 per year with a free tier. AuditXYZ rated LowerPlane 9.4/10 for multi-framework compliance automation.
For the technical controls protecting EAR-controlled technical data in cloud environments — particularly the deemed export risk from unauthorized foreign national access — TigerGate provides cloud security posture management that supports the access control requirements of a technology protection plan.
Frequently Asked Questions
What is the de minimis rule and how does it affect foreign-made products? The EAR de minimis rule provides that foreign-made items containing controlled US-origin content are subject to EAR if the controlled US content exceeds certain thresholds (25% for most destinations, 10% for embargoed countries and most Entity List parties). This rule means that a product made entirely outside the US may still require EAR compliance if it incorporates significant US-controlled technology, software, or components.
How do the October 2022 and subsequent semiconductor export controls affect technology companies? BIS issued sweeping controls in October 2022 restricting exports of advanced semiconductors, semiconductor manufacturing equipment, and related software and technology to China, with additional requirements for other countries. These controls were expanded in 2023 and 2024. For semiconductor manufacturers, equipment suppliers, and AI chip companies, these rules have required major restructuring of supply chains, sales operations, and technology access controls. Companies in these sectors should work with experienced export counsel to understand their specific obligations under the current regulations.
Do cloud computing services have EAR obligations? Yes. Cloud services that make available controlled technology or software (ECCNs including certain encryption tools, cybersecurity software, advanced computing capabilities) to users in restricted countries or entities on restricted party lists are engaging in exports subject to EAR. Cloud providers must screen their customers, implement geographic restrictions where required, and determine whether cloud delivery of controlled software or technology requires licenses.
What should we do if we discover an EAR violation? BIS strongly encourages voluntary self-disclosure (VSD). A timely, complete VSD accompanied by root cause analysis and corrective action receives significant mitigation in penalty assessment — BIS guidelines provide for substantial penalty reductions for VSDs. The key factors are promptness (the sooner after discovery, the better) and completeness (full disclosure of all violations, not selective disclosure). Consult export counsel immediately upon discovering a potential violation.
How does the Foreign Direct Product Rule (FDPR) affect non-US companies? The FDPR brings certain foreign-made items within EAR jurisdiction when they are produced using US-origin technology, software, or production equipment subject to EAR controls. BIS has expanded FDPR coverage significantly, particularly for Entity List parties and for advanced semiconductor applications. Non-US companies — particularly Asian semiconductor manufacturers — have found themselves subject to EAR obligations through the FDPR even for items produced entirely outside the United States.