Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Israel's Minister of Defense signed an order on 18 November 2025 revoking the Order Governing the Control of Commodities and Services (Engagement in Encryption Items) of 1974, with effect on 21 March 2026 (four-month implementation period). The 51-year-old standalone Encryption Order regime — which licensed both civilian and defense-grade encryption items through a parallel Ministry of Defense track — is replaced by a unified architecture in which defense-grade dual-use items move to the Defense Export Controls Agency (DECA) at the Ministry of Defense, and civilian dual-use items (Wassenaar list) move to the Export Control Agency (ECA) at the Ministry of Economy and Industry. Many B2C consumer products with embedded encryption are decontrolled outright; B2B / commercial products remain controlled but under DECA or ECA rather than the legacy Encryption Order regime.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
BIS finalized changes to the Export Administration Regulations (EAR) governing controls on cybersecurity items — primarily intrusion software, command-and-control platforms, and surveillance tools capable of disrupting or monitoring information systems without authorization. The final rule, effective May 26 2022, revises License Exception ACE (Authorized Cybersecurity Exports) originally established by an October 2021 interim rule and narrows end-user carve-outs for government end users in Country Group D:5 and A:6 destinations. Exports of affected ECCNs (4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, 5E001) to Country Groups E:1 and E:2 remain prohibited; D:1 through D:5 government-end-user transactions require a license.
On November 4, 2021, BIS added four entities to the Entity List under a policy of denial: NSO Group and Candiru (Israel), Positive Technologies (Russia), and Computer Security Initiative Consultancy PTE (Singapore). NSO Group and Candiru were designated for supplying commercial spyware to foreign governments used to maliciously surveil government officials, journalists, activists, and academics; Positive Technologies and CSIC for trafficking cyber tools enabling unauthorized access to information systems. All four entities now require BIS licenses for any export, re-export, or in-country transfer of EAR-controlled items, with a presumption of denial.
BIS published an interim final rule on October 21, 2021 establishing new Export Control Classification Numbers (ECCNs 4A005, 4D004, 4E001.c, and 5A001.j) for intrusion software systems, command-and-control platforms, and IP network surveillance tools, implementing the Wassenaar Arrangement 2017 cybersecurity decisions into the Export Administration Regulations (EAR). The rule simultaneously created License Exception ACE (Authorized Cybersecurity Exports), codified at § 740.22, to authorize exports to most destinations while imposing licence requirements — or outright prohibitions — for sales to Country Groups E:1/E:2 governments and certain D-group government end-users. Carve-outs for vulnerability disclosure and cyber-incident-response activities were included to protect legitimate security research. The effective date was subsequently delayed from January 19, 2022 to March 7, 2022 by a separate interim rule (FR 2022-00448), and the rule was finalized with revisions on May 26, 2022 (FR 2022-11282).
The Bureau of Industry and Security amended the Export Administration Regulations by adding six Russian technology entities to the Entity List, all designated consistent with Executive Order 14024 on blocking property associated with harmful foreign activities of the Russian government. The designated entities operate in Russia's technology sector and have been determined to support Russian intelligence services, including notable cybersecurity firms and defense-innovation institutions. All items subject to the EAR require a BIS licence for export, reexport, or transfer to these parties, subject to a presumption-of-denial review policy with no licence exceptions available. The rule also corrects an existing FSB entry to reference updated General Licence No. 1B.
Regulation (EU) 2021/821, adopted 20 May 2021 and applied from 9 September 2021, establishes the Union regime for controlling exports, brokering, technical assistance, transit, and transfer of dual-use items, repealing Regulation (EC) No 428/2009. Annex I lists controlled items implementing internationally agreed dual-use controls under the Wassenaar Arrangement, MTCR, Australia Group, NSG, and Chemical Weapons Convention. The regulation introduces a new catch-all control on cyber-surveillance technologies that could facilitate human-rights violations (Art. 5 and Annex IV), and strengthens cooperation between Member States and the European Commission, placing specific obligations on exporters. It serves as the statutory anchor for all EU export licences, every multilateral-regime transposition into EU law, and coordination mechanisms with US BIS, UK ECJU, JP METI, and KR MOTIE export-control regimes.
BIS published an interim final rule on 5 October 2020 implementing multilateral export controls on six emerging technology categories agreed at the December 2019 Wassenaar Arrangement Plenary meeting, revising Commerce Control List ECCNs 2B001, 3D003, 3E004, 5A004, 5D001, and 9A004. The six technologies are: hybrid additive-manufacturing/CNC machine tools; computational lithography software for extreme-ultraviolet (EUV) mask fabrication; wafer-finishing technology for 5 nm-node production; digital forensics tools that circumvent device authentication to extract raw data; software for monitoring and analysis of communications acquired from a handover interface; and sub-orbital craft. As the first of two US implementing actions for the 2019 Wassenaar Plenary, this rule elevated nascent commercial technologies into permanent CCL classifications enforceable against all non-EAR99 destinations.