ECCN 5D002
NSRSATEISoftware as follows .
What This ECCN Covers
ECCN 5D002 controls software that performs or manages cryptographic functions for information security — including encryption libraries, VPN clients, secure messaging applications, disk encryption tools, SSL/TLS implementations, key management systems, and cryptanalysis software. The control applies because of functional capability, not informational value, which is why even compiled binaries are controlled.
Who needs to check this?
Software companies shipping encryption-capable products (VPN apps, secure email clients, encrypted backup services), cybersecurity firms, and developers of cryptographic libraries or key management tools.
Compliance tip
Open-source encryption source code requires a notification to BIS ([email protected]) with the URL, after which it is "publicly available" and not subject to EAR. However, compiled/commercial products built from open-source must still be independently classified.
Items Covered
- a."Software" specially designed or modified for the "development," "production" or "use" of any of the following:
- 1. Equipment specified by 5A002 or "software" specified by 5D002.c.1;
- 2. Equipment specified by 5A003 or "software" specified by 5D002.c.2; or
- 3. Equipment or "software", as follows:
- 3.a. Equipment specified by 5A004.a or "software" specified by 5D002.c.3.a;
- 3.b. Equipment specified by 5A004.b or "software" specified by 5D002.c.3.b;
- b."Software" having the characteristics of a 'cryptographic activation token' specified by 5A002.b;
- c."Software" having the characteristics of, or performing or simulating the functions of, any of the following:
- 1. Equipment specified by 5A002.a, .c, .d or .e;
- 2. Equipment specified by 5A003; or
- 3. Equipment, as follows:
- 3.a. Equipment specified by 5A004.a;
- 3.b. Equipment specified by 5A004.b.
- z.Other software, as follows:
- z.1.a Software that is described in 5D002.a.1, and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.1.b Software that is described in 5D002.a.1, and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.2.a Software that is described in 5D002.a.2, and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.2.b Software that is described in 5D002.a.2, and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.3.a Software that is described in 5D002.a.3a, and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.3.b Software that is described in 5D002.a.3a, and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.4.a Software that is described in 5D002.a.3.b, and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.4.b Software that is described in 5D002.a.3.b, and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.5.a Software that is described in 5D002.b and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.5.b Software that is described in 5D002.b and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.6.a Software that is described in 5D002.c.1 and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.6.b Software that is described in 5D002.c.1 and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.7.a Software that is described in 5D002.c.2 and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.7.b Software that is described in 5D002.c.2 and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.8.a Software that is described in 5D002.c.3.a and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a;
- z.8.b Software that is described in 5D002.c.3.a and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b;
- z.9.a Software that is described in 5D002.c.3.b and that also meet or exceed the performance parameters in 3D001 for 3A090.a or 4D001 for 4A090.a; or
- z.9.b Software that is described in 5D002.c.3.b and that also meet or exceed the performance parameters in 3D001 for 3A090.b or 4D001 for 4A090.b.
2 items reserved by BIS (not shown)
Control Reasons
Items controlled for national security reasons under multilateral export control regimes.
Items controlled for regional stability reasons.
Items controlled for anti-terrorism reasons. Most items on the CCL have AT controls.
Items controlled for encryption-related reasons under the Wassenaar Arrangement.
Disclaimer
This information is for reference only. For official classifications, consult BIS or a qualified export control professional.