ECCN 4D004
NSATSoftware specially designed or modified for the generation, command and control, ordelivery of intrusion software.
What This ECCN Covers
ECCN 4D004 controls "software" specially designed or modified for the generation, command and control, or delivery of "intrusion software." It is the software counterpart to 4A005 within the Wassenaar-derived cybersecurity controls and is controlled for National Security and Anti-Terrorism reasons.
Who needs to check this?
Developers of intrusion/offensive-security tooling and the security teams that build or share such software.
Compliance tip
The control targets software for generating, commanding, or delivering "intrusion software" — not "intrusion software" itself, and not most defensive or research tools. Carve-outs exist for vulnerability disclosure and cyber-incident response; verify the §734.7 "published" exclusion and the current entry, and treat classification as a legal question.
Items Covered
- a.The update or upgrade operates only with the authorization of the owner or administrator of the system receiving it; and
- b.After the update or upgrade, the "software" updated or upgraded is not any of the following:
Control Reasons
Items controlled for national security reasons under multilateral export control regimes.
Items controlled for anti-terrorism reasons. Most items on the CCL have AT controls.
Disclaimer
This information is for reference only. For official classifications, consult BIS or a qualified export control professional.