Loading…
Loading…
BIS published the October 21, 2021 interim final rule (FR Doc 2021-21313) establishing new Export Administration Regulations (EAR) controls on cybersecurity items — primarily covering ECCNs 4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, and 5E001. The rule also introduced License Exception ACE (Authorized Cybersecurity Exports), permitting exports of affected items to most destinations except those subject to arms-embargo or narcotics-control restrictions.
The original rule carried a 90-day delayed effective date (to January 19, 2022) to allow for a 45-day comment period (closed December 12, 2021). Twelve commenters — predominantly industry compliance officers and trade counsel — flagged the difficulty of updating export-management systems and training programs within the original window, and requested both a delay and additional BIS guidance on classification thresholds.
BIS agreed and delayed the effective date by an additional 45 days to March 7, 2022. The underlying controls and License Exception ACE structure were unchanged by this procedural rule. The rulemaking ultimately concluded with BIS publishing the final rule on May 26, 2022 (FR Doc 2022-11282), which revised and narrowed certain ACE conditions before the controls took permanent effect.
(EMS) classifications and training materials before the ACE regime activated.
friction — a leading indicator for the revisions BIS later adopted in the May 2022 final rule (narrowing government-end-user carve-outs in Country Group D:5 / A:6 destinations).
licensing framework that governs commercial exports of intrusion and surveillance tools to most destinations today.
issue before March 7, 2022 — worth monitoring for any supplemental FAQs or advisory opinions published in the February–March 2022 window.