License Exception ENC lets you export many encryption products without applying for an individual export license from the Bureau of Industry and Security, but the authorization you actually get depends on which of three tiers your product falls into. Paragraph (b)(1) items ship immediately after self-classification. Paragraphs (b)(2) and (b)(3) require a classification request to BIS and a 30-day waiting period, and (b)(2) items face an ongoing restriction on sales to government end users. Every tier carries reporting obligations, and none of them can be used to ship to Cuba, Iran, North Korea, or Syria.
What ENC Covers
ENC applies to items that use cryptography to protect the confidentiality or integrity of data and are classified under ECCN 5A002, 5B002, 5D002, 5E002, or 5A004. That scope reaches encrypted hard drives, VPN routers, cryptographic software libraries, and the technology used to develop them.1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC) Cryptanalytic tools and digital forensics products classified under 5A004 or 5D002 fall inside ENC too, though they carry the heaviest restrictions.
Everything downstream in the process depends on your ECCN. Misclassify the product and you may pick the wrong tier, which means the export you thought was authorized was not. Compare your product’s technical specifications against the control parameters in Category 5, Part 2 before you rely on ENC at all.
Products That Fall Outside These Controls
Not every product with encryption in it needs ENC. Several categories sit outside Category 5, Part 2 entirely.
Under Note 4 to Category 5, Part 2, products where encryption merely supports a primary function unrelated to information security are excluded. The test is whether the main reason someone buys the product is something other than securing data, computing, communications, storage, or networking.2Federal Register. Encryption Export Controls – Revision of License Exception ENC and Mass Market Eligibility, Submission Procedures, Reporting Requirements Industrial robots, medical diagnostic equipment, automotive systems, gaming platforms, household appliances, HVAC controls, Blu-ray players, and CAD software all qualify.
Short-range wireless devices controlled under 5A002, 5B002, or 5D002 only because of short-range wireless encryption are also exempt when the range is 100 meters or less and the device complies with IEEE 802.11 (Wi-Fi) or IEEE 802.15.1 (Bluetooth).2Federal Register. Encryption Export Controls – Revision of License Exception ENC and Mass Market Eligibility, Submission Procedures, Reporting Requirements The exemption disappears if the device would still be controlled without the wireless encryption, for instance a gateway that also handles network-level encryption.
Publicly available encryption source code classified under 5D002 is not subject to the EAR at all if it uses standard, published cryptography. If it implements non-standard cryptography, you must email the URL or a copy to BIS at crypt@bis.doc.gov and the ENC Encryption Request Coordinator at enc@nsa.gov, and send an updated notification when the hosting URL or the cryptographic functionality changes.3eCFR. 15 CFR 742.15 – Encryption Items
Destinations Where ENC Cannot Be Used
ENC cannot authorize any export to a country in Country Group E:1 or E:2, no matter how basic the encryption. As of 2026 that means Cuba, Iran, North Korea, and Syria; Cuba sits in both groups.4eCFR. 15 CFR Supplement No. 1 to Part 740 – Country Groups Those shipments need an individual license.
The regulation also blocks the use of ENC when you know or have reason to know the item will be used to compromise the confidentiality, integrity, or availability of information systems without the owner’s authorization. That end-use screen has to happen alongside the country screen.
The Three Tiers
Which paragraph your product falls under is the most consequential decision in ENC compliance, because it drives every step that follows.
Paragraph (b)(1): Immediate Authorization After Self-Classification
Products under (b)(1) can ship immediately after the exporter self-classifies them. No request goes to BIS, and there is no waiting period. The tier covers commodities self-classified under ECCN 5A002.a, 5A002.z.1, or 5B002, along with equivalent software under 5D002, provided the product does not fall into (b)(2) or (b)(3).1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
Many consumer electronics and standard business software products land here. Immediate authorization does not mean no paperwork; you still owe an annual self-classification report covering everything you shipped under (b)(1) during the prior calendar year.
Paragraph (b)(2): 30-Day Wait Plus a Government End-User Bar
Before you can ship a (b)(2) item, you have to file a classification request with BIS and wait 30 days.1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC) The tier captures products with capabilities that raise heightened national security concerns:
- High-throughput network infrastructure: WAN, VPN, and backhaul equipment with encrypted throughput of 250 Mbps or more; satellite gear exceeding 10 Mbps; media gateways handling encryption for more than 2,500 endpoints; and terrestrial wireless infrastructure exceeding 1,000 meters with elevated data rates or voice channel counts.
- Non-public encryption source code classified under 5D002.
- Products designed or modified specifically for government end users, and products where the cryptographic functionality can be easily changed by the user.
- Quantum encryption commodities or software under 5A002.c, 5A002.z.3, or 5D002.
- Encryption products capable of attacking, denying, or disrupting cyber infrastructure.
- Public safety radio implementing TETRA or APCO Project 25.
- Cryptanalytic items classified under 5A004 or 5D002.
Even after the 30 days pass, (b)(2) items cannot be transferred to government end users or for government end uses without separate authorization. That prohibition is permanent for the tier. Semi-annual sales reporting also applies. One accelerator is available: right after submitting the classification request, you can export most (b)(2) items (cryptanalytic tools excluded) to non-government end users in countries listed in Supplement No. 3 to Part 740, which covers close U.S. allies.
Paragraph (b)(3): 30-Day Wait, No Government End-User Bar
Paragraph (b)(3) covers encryption products that need government review but don’t match a specific (b)(2) category. The filing and 30-day wait are the same, but once the period ends the product can go to any end user, including government entities.1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
Non-mass-market encryption chips, chipsets, electronic assemblies, field-programmable logic devices, cryptographic libraries, development kits, and toolkits typically fall here, along with products implementing non-standard cryptographic algorithms.5Bureau of Industry and Security. Elimination of Reporting Requirements for Certain Encryption Items
Who Counts as a Government End User
The government end-user restriction in (b)(2) sweeps much wider than most exporters expect. A government end user is any national, regional, or local government department or agency, but the term extends beyond ministries and traditional government offices.
The regulations single out “more sensitive government end users” for the strictest treatment: intelligence agencies, military and armed services, defense ministries, law enforcement and police, national telecommunications authorities, customs and immigration agencies, prison systems, legislative bodies, judiciary systems including supreme courts, central banks and monetary authorities, port and airport authorities, and executive offices of state such as presidential administrations and royal courts.6eCFR. 15 CFR 772.1 – Definitions of Terms as Used in the Export Administration Regulations
State-owned enterprises like public utilities, government-run telecommunications providers, and state media organizations also qualify. A state-owned telecom company buying VPN equipment triggers the same restriction as a defense ministry buying it. When you’re unsure whether a foreign customer qualifies, treat it as a government end user until due diligence proves otherwise.
Mass Market: The Path Into (b)(1)
Whether a product qualifies as “mass market” under Note 3 to Category 5, Part 2 often decides whether it lands in (b)(1) or gets pulled out of Category 5 entirely, which eliminates ENC classification requests and most reporting.
BIS evaluates mass market eligibility along two pathways.7Bureau of Industry and Security. Mass Market (Section 740.17) The first covers retail products generally available to the public, weighed on sales volume, price, technical skill required to use the product, existing sales channels, the typical customer, and whether the supplier restricts who can buy it. A consumer messaging app distributed through an app store looks very different from a custom encryption appliance sold to a handful of enterprise clients.
The second pathway covers hardware or software components of an existing mass market product. The component must be the same one factory-installed in the mass market product, or a functionally equivalent replacement with the same form, fit, and function. Information security cannot be its primary function, it must add no new encryption capabilities to the product, and its features must be fixed rather than customizable.7Bureau of Industry and Security. Mass Market (Section 740.17)
Filing the Classification Request
Requests are filed through SNAP-R (Simplified Network Application Process Redesign), the electronic portal BIS uses for license applications and commodity classification requests.8Bureau of Industry and Security. BIS SNAP-R Your company needs a Company Identification Number to access it. The person who registers becomes the account administrator and can add other users, and registration requires company name, physical address (no P.O. boxes), phone number, email, and EIN.9Bureau of Industry and Security. SNAP-R Frequently Asked Questions
Along with the request you must submit the technical questionnaire in Supplement No. 6 to Part 742: a non-technical product description, all symmetric and asymmetric encryption algorithms and their key lengths, how encryption keys are generated and managed, whether the product uses non-standard cryptography, any pre-processing applied before encryption, and every communication protocol the product supports.10eCFR. Supplement No. 6 to Part 742 – Technical Questionnaire for Encryption and Other Information Security Items If the product has been classified before, reference the prior CCATS number and describe only what changed. Marketing materials and manuals can supplement the questionnaire but never replace it. Incomplete submissions are the most common cause of delay.
Reporting After Export
Getting a product classified is only the start. ENC reporting continues for as long as you export under the exception, and missed deadlines can cost you the exception itself.
Annual Self-Classification Report
If you export under (b)(1) or (b)(3), you owe an annual self-classification report covering the previous calendar year. It must reach BIS and the ENC Encryption Request Coordinator by February 1.1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
The report is a CSV file with 12 required fields: product name, model number, manufacturer, ECCN, authorization type (either “ENC” or “MMKT”), item type, submitter name, telephone number, email address, mailing address, non-U.S. components, and non-U.S. manufacturing locations. No field can be blank; use “NONE” or “N/A” where a field does not apply.11Bureau of Industry and Security. Annual Self-Classification Send it to crypt-supp8@bis.doc.gov and enc@nsa.gov. That BIS address is different from the one used for other encryption correspondence.
Semi-Annual Sales Report
Exports of (b)(2) items and certain (b)(3) items (those described in paragraph (b)(3)(iii)) require semi-annual sales reports covering exports to all destinations other than Australia, Canada, and the United Kingdom, plus re-exports from those three countries. January–June exports are due by August 1; July–December exports by February 1.1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
Each report includes the CCATS number, the product name, and recipient details. For distributor or reseller sales, report the distributor’s name, address, quantity, and the end user’s identity if you collected it. For direct sales, report the recipient’s name, address, and quantity. For encryption components or source code sent to foreign manufacturers for incorporation into their own products, identify the manufacturer and, when available, provide a non-proprietary description of the foreign product. Semi-annual reports go to crypt@bis.doc.gov and enc@nsa.gov.
Re-Exports, Foreign-Made Products, and Deemed Exports
ENC authorizes re-exports of classified items from one foreign country to another when the re-export meets the same terms that applied to the original export. The prohibited-destination rules still apply: no re-exports to E:1 or E:2 countries.1eCFR. 15 CFR 740.17 – Encryption Commodities, Software, and Technology (ENC)
Foreign-manufactured products incorporating U.S.-origin encryption components face a separate jurisdictional question. Under the de minimis rule, if U.S.-origin controlled content is 25% or less of the foreign product’s total value, the product is generally not subject to the EAR when shipped to countries outside E:1 and E:2. For shipments to E:1 or E:2 countries, the threshold drops to 10%.12eCFR. 15 CFR 734.4 – De Minimis U.S. Content
There is one hard exception. Foreign-produced encryption technology incorporating U.S.-origin technology controlled under ECCN 5E002 is subject to the EAR regardless of how small the U.S.-origin content is. There is no de minimis level for encryption technology; if you license U.S.-developed encryption technology to a foreign manufacturer, the resulting foreign product stays within EAR jurisdiction no matter the percentage of U.S. content.12eCFR. 15 CFR 734.4 – De Minimis U.S. Content
The “deemed export” rule catches technology companies that hire globally. Releasing controlled encryption technology to a foreign national inside the United States is treated as an export to that person’s home country. If a non-U.S. citizen or permanent resident on your engineering team gains access to encryption source code or design technology classified under ECCN 5E002, you may need ENC authorization (or another license exception) exactly as if you were shipping the technology overseas. The compliance obligation is the same regardless of where the person is physically standing. Screen the country of citizenship before sharing controlled technology with foreign-national employees or contractors.
Records and Penalties
The EAR requires you to retain all records related to export transactions for five years, running from the date of export, any known re-export or transfer, or any other termination of the transaction, whichever is latest.13eCFR. 15 CFR 762.6 – Period of Retention Classification requests, CCATS numbers, self-classification reports, semi-annual sales reports, technical questionnaires, and BIS correspondence all need to be accessible for audit. Auditors will compare sales reports against shipping logs and classification records.
Civil penalties can reach $300,000 per violation or twice the value of the transaction, whichever is greater. For a high-value networking shipment, the transaction-value multiplier can dwarf the $300,000 floor. Willful violations carry criminal penalties of up to $1,000,000 in fines and up to 20 years in prison for individuals.14Office of the Law Revision Counsel. 50 USC 4819 – Penalties BIS can also deny export privileges outright.
If you discover a violation, BIS treats voluntary self-disclosure to the Office of Export Enforcement as a mitigating factor and treats a deliberate decision not to disclose a significant violation as an aggravating factor.15eCFR. 15 CFR 764.5 – Voluntary Self-Disclosure For minor or technical violations, an abbreviated narrative report may be enough. For significant violations, notify the Office of Export Enforcement as soon as possible, then conduct an internal review and submit a full narrative account within 180 days.