Loading…
Loading…
The 1974 Encryption Order (issued under the Control of Commodities and Services Law, 5718-1957) created a uniquely Israeli parallel-track regime: any "engagement" in encryption — manufacture, possession, sale, import, export — required a Ministry of Defense licence, regardless of whether the item was a defense-grade cipher module or a consumer smartphone with TLS. The regime was anomalous internationally: most peer jurisdictions had migrated encryption export controls into their Wassenaar-list dual-use frameworks decades ago, leaving Israel as one of the few countries with a standalone civilian encryption licensing authority.
The 18 November 2025 revocation, effective 21 March 2026, dissolves this parallel track and routes encryption items into the same two- agency architecture that handles all other Israeli dual-use exports:
retains jurisdiction over defense-grade and military dual-use encryption items (e.g., classified-grade cryptographic modules, defense-tech with embedded encryption, items aligned with the Wassenaar Munitions List).
takes jurisdiction over civilian dual-use encryption items aligned with the Wassenaar Dual-Use List (Category 5, Part 2).
encryption (handsets, browsers, off-the-shelf SaaS) drop out of the control regime entirely, aligning with the EU and US treatment of mass-market encryption under Wassenaar Note 3.
Concurrent with the revocation, DECA updated its product-registration specification to require evidence of (a) foreign ownership / control structure of the exporter, and (b) use of artificial intelligence in the controlled product — bringing Israeli registration practice into line with the foreign-ownership scrutiny embedded in US BIS quantum / biotech / additive-manufacturing controls (5 Sep 2024) and the AI- focused Category 4 expansion in the EU's dual-use update of 8 September 2025.
the B2C / mass-market carve-out removes a long-standing licensing drag on companies like Check Point's consumer line, NICE Actimize's fraud-detection SaaS, and the broader Israeli cybersecurity ISV cluster targeting non-defence customers.
startups**: items previously cleared under the relatively narrow Encryption Order may be re-classified into Wassenaar Category 5 Part 2 (information security) or Category 4 (computers / AI), where end-use, end-user and country-group restrictions are stricter.
bringing Israeli export controls onto the Wassenaar baseline that the US (BIS quantum IFR), Japan, Netherlands, and EU (Delegated Regulation 2025/2003) all use, this measure removes a divergence point that previously made Israeli-origin encryption / quantum tech harder to integrate into Western allied dual-use coordination.
US-affiliated operations**: the unified DECA + ECA architecture reduces dual-licensing burdens (Israeli Encryption Order + US EAR) that previously created compliance overlap for cross-border Israeli–US R&D arrangements.
empty despite Israel hosting one of the densest defense-tech / quantum / cyber clusters globally; this filing opens the IL action series.
triggers retroactive review of already-licensed Israeli AI exports (Mobileye, NICE, Cellebrite, Verint).
they default to ECA / Wassenaar Cat 5.A.2 or to DECA's defense-grade track.
by Shibolet's Q1 2026 update (separate from this revocation) introduces a single statutory dual-use law to consolidate the DECA / ECA architecture, replacing the still-fragmented current layering of the Defense Export Control Law of 2007 + Control of Commodities and Services Law of 1957.