Podcasts
Watch videos featuring supply chain experts
A software company hires a promising engineer on a work visa and gives him full access to the codebase on day one. Nobody checks whether any part of that technology is export-controlled, or whether handing it to a foreign national inside a US office building counts as an export in the first place.
It does, under certain conditions. This is the kind of gap that catches companies off guard, because "export compliance" sounds like it only applies to goods physically crossing a border. It doesn't.
This guide covers what export compliance actually means, the regulations that govern it, who it applies to, and what a compliance program needs to address.
Export compliance is the set of legal obligations a person or company must satisfy before sending goods, software, technology, or technical information outside the United States, or in some cases, before sharing it with a foreign national inside the United States.
It exists separately from customs and duty obligations. Customs asks what you're bringing in and what you owe. Export compliance asks whether you're allowed to send something out, based on what it is, where it's going, who's receiving it, and what it will be used for.
Three things make export compliance distinct from other trade obligations:
Most US export control questions fall under one of two regulatory frameworks, administered by two different agencies.
| Regime | What It Covers | Administering Agency |
|---|---|---|
| Export Administration Regulations (EAR) | Dual-use items: goods, software, and technology with both civilian and military, terrorism, or WMD-related applications | Department of Commerce, Bureau of Industry and Security (BIS) |
| International Traffic in Arms Regulations (ITAR) | Defense articles and services specifically designed or modified for military use | Department of State, Directorate of Defense Trade Controls (DDTC) |
Items specifically designed or modified for military use generally fall under the US Munitions List, administered separately from the CCL under ITAR, even though both regimes are commonly discussed together under the broader label "export controls."
This guide focuses primarily on the EAR, since it applies to the widest range of commercial exporters. Companies working with defense articles or services should treat ITAR as a distinct, additional compliance obligation with its own registration and licensing requirements.
How the EAR Actually Works
The EAR governs "items subject to the EAR," which includes commodities, software, and technology. Understanding how it classifies and controls those items is the foundation of export compliance.
The Commerce Control List (CCL) is the master list of dual-use items subject to the EAR, organized into ten numbered categories, 0 through 9, covering distinct technology areas from nuclear materials to aerospace and propulsion. An item that matches a specific CCL entry is assigned an Export Control Classification Number (ECCN); an item that doesn't match any CCL entry falls into the residual EAR99 classification.
Most commercial products end up classified as EAR99. This doesn't mean no rules apply. EAR99 items can still require a license depending on destination, end user, or end use, though the licensing burden is generally lighter than for CCL-listed items.
The three questions that determine licensing
Once an item's classification is known, three additional factors determine whether an export license is required:
A company can get the classification right and still violate the EAR by missing a destination, end-user, or end-use restriction. All three checks are necessary, not just the first one.
Not every controlled item requires a full license application. The EAR includes license exceptions, specific, conditional authorizations that allow an export without a license if the transaction meets defined terms. A license exception isn't a blanket exemption. It applies only when every condition specified for that exception is met, and only if none of the general restrictions on license exceptions apply to the transaction.
One of the most misunderstood parts of export compliance is that an "export" doesn't require anything to physically leave the country.
Under the EAR, the release of controlled technology to a foreign person inside the United States is treated as a deemed export to that person's home country, even though nothing physically crosses a border. Deemed exports can occur through a product demonstration, a conference presentation, an oral briefing, a plant visit, or the electronic transmission of non-public technical data.
Employees with permanent US residence, citizenship, or protected individual status are exempt from the deemed export rule, but employees on temporary work visas are not automatically exempt just because they're legally authorized to work in the US.
Organizations handling controlled technology need to determine whether a foreign employee's access to that technology requires a license before granting it, not after the fact. This is a common blind spot in technology, engineering, and research organizations that hire internationally without factoring export control into onboarding.
Deemed reexports add another layer: releasing controlled technology to a third-country national outside the US, for example, a foreign employee of an overseas subsidiary, can also trigger a licensing requirement, separate from the original deemed export analysis.
Even a fully uncontrolled item can become a compliance problem if it's sold to the wrong party. Export compliance requires checking counterparties against restricted and denied party lists before a transaction closes, not just checking the product.
Key lists include:
Screening needs to happen at multiple points: before onboarding a new customer or distributor, before each individual transaction, and periodically for existing relationships, since these lists change on an ongoing basis rather than a predictable schedule.
This became more complex in September 2025, when BIS extended Entity List and Military End-User List restrictions to affiliates owned 50% or more, directly or indirectly, by a listed party. A counterparty that has never appeared on any list by name can still be restricted today if its ownership structure includes a listed entity, which means screening based on ownership, not just party name, has become a practical necessity rather than a best practice. Trademo sanctions and PEP screening and ownership and control screening capabilities are built to screen at this ownership level.
Export compliance starts with an accurate ECCN determination, and getting it wrong in either direction creates risk.
Classifying a controlled item as EAR99 when it actually matches a CCL entry results in an unlicensed export of a controlled item, a serious compliance failure. Over-classifying an item creates unnecessary licensing burden and can delay shipments that didn't need to be restricted at all.
Large or frequently changing product catalogs, especially in electronics, industrial equipment, and technology, generally can't sustain accurate ECCN classification through manual, one-off review. Trademo's ECCN classification capability applies AI-driven classification logic to help determine export control classification consistently across a product catalog, alongside HS classification for customs purposes.
Beyond classifying individual products, companies also need a process for screening goods against export control and dual-use restrictions at the transaction level, particularly when the same product ships to multiple destinations with different licensing outcomes.
Trademo's goods screening capability supports this kind of product-level screening for export control and dual-use restriction requirements.
Recordkeeping and Recognizing Red Flags
Export compliance obligations don't end when a shipment leaves. Companies need to retain export documentation, including license applications, license exceptions used, and end-use certifications, for the retention period required under applicable regulations.
Beyond documentation, BIS has published a standard list of "red flags" that should prompt additional due diligence before a transaction proceeds, including:
None of these red flags automatically prohibits a transaction, but each one warrants closer review before proceeding.
Export control violations carry real consequences, and both civil and criminal penalties apply depending on the violation's severity and intent.
Civil penalties under IEEPA-related sanctions programs can reach the greater of $377,700 per violation or twice the value of the underlying transaction, based on OFAC's current inflation-adjusted penalty schedule. Export violations under the EAR carry their own penalty structure, and willful violations can result in criminal prosecution, not just civil fines.
Voluntary self-disclosure to BIS or OFAC, when a company identifies and reports its own violation, can meaningfully reduce penalties compared to a violation discovered through enforcement action. This is one reason a functioning compliance program matters even when violations occur: how a company responds affects the outcome as much as the violation itself.
An effective export compliance program generally includes the same core elements regulators look for across export control and sanctions compliance: