Loading…
Loading…
The rule operationalises the 2017 Wassenaar Arrangement plenary decisions on cybersecurity tools. Prior to 2021, intrusion software and surveillance platforms occupied a regulatory grey zone in the EAR: many were not captured by existing ECCNs (EAR99 or misclassified) and could be exported without a licence even to authoritarian end-users.
New ECCN structure:
intrusion software (hardware layer)
full-packet capture at the backbone level
License Exception ACE (§ 740.22): Authorises exports/reexports to most destinations without a licence, except:
are completely prohibited
unless the end-user is in the allied A:6 subgroup (Cyprus, Israel, Taiwan as of 2021)
systems without authorization" is prohibited regardless of destination
The rule was the first comprehensive US codification of dual-use cybersecurity tool controls at the ECCN level, shifting enforcement from reactive entity-listing toward a classification-based preventive regime.
had to reassess product-line classifications; tool features affecting payload delivery may now require review for ECCN 4D004 or 4E001.c status
fall within 4D004 scope; exports to D-group government customers require licences
captured under 5A001.j — restricts sales of telecom surveillance gear to authoritarian telecom authorities
the list would trigger both mechanisms; ACE provides no exception for listed parties
highlighted compliance complexity; BIS noted it would issue supplemental guidance
following the public-comment period
(LLM-assisted red-teaming); BIS has not yet issued interpretive guidance
exports to Russian or Iranian security-sector entities
software categories; transatlantic divergence in ACE vs. EU general authorisations remains a compliance friction point for multinational vendors