Loading…
Loading…
The 2022-05-26 final rule closes the regulatory loop opened by the October 21, 2021 interim rule that first introduced controls on cybersecurity items under new ECCN categories and created License Exception ACE. The interim rule drew public comments about over-breadth and ambiguity in the "government end user" definition and about overlap with existing License Exception ENC (encryption). The final rule addresses those comments with three main changes:
1. Government end user definition tightened. The final rule adds an illustrative enumerated list to the "government end user" definition, making clear which entities qualify (e.g., national militaries, intelligence agencies, law enforcement) versus which do not (e.g., state-owned commercial entities). This matters because government-end-user transactions to Country Groups D:1–D:5 require a license regardless of whether the software would otherwise qualify for ACE.
2. Paragraph (c)(2)(i) corrected for A:6 destinations. The pre-final rule text was ambiguous about exports of "digital artifacts" (forensic evidence, content intercepted in transit) to A:6 country law-enforcement bodies. The final rule limits such exports to police and judicial bodies conducting bona fide criminal investigations — closing a loophole that could have been read to permit surveillance-tool transfers to intelligence agencies in A:6 countries.
3. ENC interaction clarified. License Exception ENC (for dual-use encryption products) is given new restrictions for certain cybersecurity items to prevent ACE/ENC overlap from creating an unintended low-control path.
Controlled ECCNs:
Destination framework (as of May 2022):
| Country Group | Status under ACE |
|---|---|
| E:1 (Cuba, Iran, DPRK, Sudan, Syria) | Prohibited — no exception |
| E:2 (Russia, Belarus, Myanmar, Cambodia) | Prohibited — no exception |
| D:1–D:5 (China, and others) for government end users | License required |
| A:6 (law enforcement partners) | Limited ACE eligible (criminal investigations only) |
| Most other destinations | ACE eligible for approved end uses |
Scale context: 2020 AES data (the most recent available at rulemaking) showed approximately 980 annual export shipments of controlled cybersecurity items valued at $39.1 million, of which roughly 120 shipments ($1.9 million) would require licensing under the new framework. BIS estimated approximately 170 net new annual license applications.
vulnerability research tools, network-intrusion kits) must classify against the ECCNs above and assess each government-end-user transaction against the revised ACE criteria.
Group (already blocked) and for US-headquartered pen-testing companies (Cobalt Strike, Immunity CANVAS) exporting to government customers in D-group destinations.
products that previously moved under ENC may now require ACE assessment.
telecom providers that also provide lawful-intercept infrastructure).
explicitly enumerated under current ECCNs (rulemaking was initiated via ANPRM in 2023).