ECCN 5A002 is the Export Control Classification Number that the Bureau of Industry and Security (BIS) uses for systems, equipment, and components that use cryptography to protect the confidentiality of data. It sits in Category 5, Part 2 of the Commerce Control List, the “information security” section, and it carries three reasons for control: National Security, Anti-Terrorism, and Encryption Items.1eCFR. 15 CFR 742.15 – Encryption Items The Encryption Items control is the one that bites hardest: it requires a license for exports to every destination except Canada unless a license exception applies. Related software falls under 5D002 and related technology under 5E002. Get the classification or the authorization wrong and the exposure is real: up to 20 years in prison and $1 million per violation for willful criminal violations under the Export Control Reform Act.2Bureau of Industry and Security. Enforcement
What 5A002 Actually Captures
The reach of 5A002 is intentionally broad. Under 5A002.a, an item is controlled if information security is its primary function, if it is a digital communications or networking system, or if it is a computer or other device whose primary function is information storage or processing.3Bureau of Industry and Security. 5A002 a.1-a.5 That last bucket is what sweeps commercial networking gear, enterprise storage, and general-purpose computers with built-in encryption into scope alongside the obvious candidates like hardware security modules, cryptographic accelerators, VPN concentrators, and network encryption appliances.
Items that use cryptography solely for authentication, digital rights management, or other purposes that do not protect data confidentiality fall outside 5A002. Publicly available encryption source code classified under 5D002 is not subject to the EAR at all, provided the exporter files the notification the regulations require.1eCFR. 15 CFR 742.15 – Encryption Items
The Mass Market Off-Ramp
Most consumer and off-the-shelf commercial products with encryption do not stay at the 5A002 control level. Note 3 to Category 5, Part 2 of the Commerce Control List reclassifies qualifying “mass market” items to ECCN 5A992 for hardware or 5D992 for software, which drops the National Security and Encryption Items controls and allows export to most destinations without a license.4Bureau of Industry and Security. Mass Market (Section 740.17)
The mass market test looks at how a product is sold, not just what it does. The item has to be generally available to the public through retail sales, and the buyer must not be able to easily modify its cryptographic functionality. Standard laptops, smartphones, and off-the-shelf consumer software routinely qualify. Specialized enterprise equipment with configurable encryption usually does not, even when it uses the same algorithms.5eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
Confirming Jurisdiction and Classifying the Item
Before working through the ECCN itself, confirm the product is under BIS jurisdiction rather than the State Department’s. Cryptographic equipment specifically designed for military command-and-control systems or defense platforms can fall under the International Traffic in Arms Regulations and the U.S. Munitions List instead.6eCFR. 22 CFR Part 121 – The United States Munitions List Genuine ambiguity gets resolved through a commodity jurisdiction request to the Directorate of Defense Trade Controls.
Once EAR jurisdiction is settled, classification runs one of two ways. Self-classification means comparing the product’s algorithm type, key length, and function against the CCL entry parameters. The alternative is a formal classification request to BIS, which returns a Commodity Classification Automated Tracking System (CCATS) number.7eCFR. 15 CFR 748.3 – Classification Requests and Advisory Opinions A CCATS determination is interagency and binding, so it gives the exporter more certainty. Misclassifying a 5A002 item as EAR99 is one of the most common compliance failures, and it can trigger enforcement action even without any intent to violate.
License Exception ENC and Its Tiers
License Exception ENC is the primary lawful path for exporting 5A002 items, along with related 5D002 software and 5E002 technology, without an individual license. It is completely unavailable for shipments to Cuba, Iran, North Korea, and Syria (Country Groups E:1 and E:2). Those destinations require an individual license, and BIS maintains a general policy of denial for them.8eCFR. Supplement No. 1 to Part 740 – Country Groups
ENC has three tiers, and the tier determines both how soon you can ship and what reports you owe afterward:5eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
- Paragraph (b)(1) authorizes immediate export of commodities self-classified under 5A002.a or 5A002.z.1, plus related 5B002 test equipment and 5D002 software, subject to filing a self-classification report. Mass market items get reclassified to 5A992 or 5D992 at this stage.
- Paragraph (b)(2) covers network infrastructure items and certain other products. The exporter must file a classification request with BIS and wait 30 days before exporting, with semiannual sales reporting afterward.
- Paragraph (b)(3) covers items that fit neither of the above tiers, including items destined for government end-users outside the Supplement No. 3 countries. It also requires a 30-day classification request and later reporting.
Favorable-Treatment Countries and Government End-Users
Supplement No. 3 to Part 740 lists countries whose private-sector end-users get the most favorable treatment under ENC, including NATO members, Australia, Japan, and New Zealand.9eCFR. Supplement No. 3 to Part 740 – License Exception ENC Favorable Treatment Countries Exports to private-sector end-users headquartered in these countries can proceed under paragraph (a) of ENC without a classification request, self-classification report, or sales report when the purpose is internal development and production of new products.10eCFR. 15 CFR Part 740 – License Exceptions
Government end-users get more scrutiny. Sales to government entities inside Supplement No. 3 countries can generally move under ENC once the tier requirements are met. Government end-users outside that list usually require a full license application unless a specific ENC paragraph covers the transaction. Certain regions of Ukraine, Russia, and Belarus, along with the E:1 and E:2 destinations, face additional restrictions that can rule out license exceptions entirely.
Reporting Obligations
Using ENC generates ongoing paperwork, and the required report depends on the tier.
- Self-classification reports cover items exported under paragraph (b)(1) that were self-classified. The report for each calendar year must reach BIS and the ENC Encryption Request Coordinator no later than February 1 of the following year.5eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
- Semiannual sales reports cover items exported under paragraphs (b)(2) and (b)(3)(iii) to destinations other than Australia, Canada, or the United Kingdom. They are due by August 1 for January-through-June exports and by February 1 for July-through-December exports.
Missing a reporting deadline does not retroactively invalidate the underlying export authorization. It is still a regulatory violation, and it draws enforcement attention.
Deemed Exports to Foreign Nationals
An “export” under the EAR does not require anything to physically leave the country. Sharing controlled encryption technology with a foreign national inside the United States counts as a “deemed export” to that person’s home country. If the technology is classified under 5E002 and a physical export to that country would require a license, so does the release to the foreign national.11Legal Information Institute (LII) / Cornell Law School. Deemed Export License
ENC does authorize certain deemed exports for internal company use, including development and production of new products, when the foreign national is an employee, contractor, or intern of a U.S. company or its subsidiary. That authorization does not extend to nationals of Country Group E:1 or E:2 countries, and it does not apply when the exporter knows the technology will be used to compromise information systems without authorization.5eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC) Cloud storage layers on another concern: uploading 5E002 technology to a server accessible by foreign nationals can itself be an export, depending on who can access the data and where the server sits.
Foreign-Made Products With U.S. Encryption Content
Foreign-made products that incorporate U.S.-origin encryption components or software can remain subject to the EAR under the de minimis rules, and Category 5, Part 2 items get stricter treatment than the standard 25% threshold.
For encryption technology classified under 5E002, the de minimis threshold is zero: any foreign-produced encryption technology incorporating U.S.-origin 5E002 stays subject to the EAR no matter how small the U.S. content.12eCFR. 15 CFR 734.4 – De Minimis U.S. Content For commodities and software classified under 5A002 and 5D002, de minimis calculation is available, but the U.S.-origin encryption components must first have been authorized under ENC before being incorporated. And if the U.S.-origin content was authorized under the paragraph (b)(2) or (b)(3) tier, the foreign-made product cannot be sent to E:1 or E:2 destinations.
Screening and Red Flags
Every export needs restricted-party screening before shipment. The Consolidated Screening List aggregates the lists maintained by Commerce, State, and Treasury. On the BIS side, the key ones are the Denied Persons List, the Entity List, the Unverified List, and the Military End-User List.13Bureau of Industry and Security. Guidance on End-User and End-Use Controls and U.S. Person Controls A Denied Persons List match ends the transaction: the party cannot participate in any export subject to the EAR.14Bureau of Industry and Security. Denied Persons List (DPL)
Even when every list clears, BIS expects exporters to watch for red flags that suggest possible diversion.15eCFR. Supplement No. 3 to Part 732 – Know Your Customer Guidance and Red Flags The regulatory guidance flags reluctance to share end-use information, a product’s capabilities not fitting the buyer’s line of business or the destination’s technical level, cash offers for expensive equipment that would normally involve financing, customers declining installation or training that usually comes with the sale, and shipping routes or delivery dates that make no logistical sense. When a red flag appears, the exporter has to investigate and resolve it before shipping. Ignoring one can convert a civil violation into a criminal one, because it establishes “reason to know.”
Penalties and Voluntary Self-Disclosure
Criminal penalties for willful EAR violations reach up to 20 years of imprisonment and up to $1 million in fines per violation.2Bureau of Industry and Security. Enforcement Civil penalties can hit $300,000 per violation or twice the value of the transaction, whichever is greater.16Office of the Law Revision Counsel. 50 USC 4819 – Penalties BIS can also place violators on the Denied Persons List, which effectively ends their ability to export anything subject to the EAR.
BIS encourages voluntary self-disclosure when a company finds it may have violated the EAR. For minor or technical infractions without aggravating factors, BIS runs a fast-track process that can produce a warning or no-action letter within 60 days of final submission.17Bureau of Industry and Security. Voluntary Self-Disclosure Self-reporting is not a guaranteed shield, but it is a strong mitigating factor. Sitting on a known violation is almost always worse than disclosing it.
Recordkeeping
Records related to EAR-controlled transactions have to be kept for at least five years. The clock runs from the latest of the export, any known reexport or in-country transfer, or any other termination of the transaction.18eCFR. 15 CFR 762.6 – Period of Retention If BIS or another agency requests specific records, those records cannot be destroyed without written permission, even after the five-year window closes. Classification documents, CCATS determinations, license exception eligibility analyses, self-classification and semiannual reports, transaction records, end-user certifications, and screening results all belong in the file.