The Export Administration Regulations (EAR) are US rules, administered by the Commerce Department’s Bureau of Industry and Security (BIS), that control the export, re-export and transfer of commercial and dual-use items, software and technology. Dual-use means something with both civilian and potential military uses, such as certain electronics, sensors, encryption or manufacturing equipment. For IT buyers, the EAR matters because controlled technology and source code can live in cloud storage, code repositories and collaboration tools, and releasing it to a foreign person can count as an export. This entry is general information, not legal advice; confirm your obligations with export counsel.
At a glance
- The EAR covers commercial and dual-use items listed on the Commerce Control List (CCL), plus many everyday items that fall into the EAR99 category.
- Whether a license is needed depends on the item’s classification, the destination, the end user and the end use.
- Releasing controlled technology or source code to a foreign person, including in the US, can be a “deemed export”.
- There is no EAR certification for IT providers; providers can only support your controls.
- Defense items on the US Munitions List fall under ITAR instead of the EAR.
What problem it solves
The EAR lets the US government restrict sensitive commercial technology from reaching certain countries, organizations and end uses, while leaving most trade free to flow. For companies, it turns that policy into a decision process: classify what you export, check where it is going and who will use it, and get a license when the rules require one.
The IT side of the problem is often overlooked. A software company with engineers abroad, a manufacturer sharing designs with an overseas supplier, or a firm whose MSP has offshore staff may be exporting controlled technology through ordinary access rights. The EAR makes buyers think about where data sits, who can read it and which countries are involved.
How it works
Classification. Each item is checked against the Commerce Control List. If it matches an entry, it has an Export Control Classification Number (ECCN) describing why it is controlled. Items subject to the EAR that match no entry are EAR99.
License determination. The ECCN is compared with the destination country, and the end user and end use are screened against restricted-party lists and prohibited activities. The result is no license required, a license exception, or a license application to BIS.
Deemed exports. Sharing controlled technology or source code with a foreign person inside the US is treated as an export to that person’s home country, which is why system access and hiring practices matter.
Encryption. Encryption items have their own rules. The EAR also sets conditions under which data secured with qualifying end-to-end encryption is not treated as exported; confirm how they apply with counsel.
Recordkeeping and screening. Companies keep export records and screen customers and partners.
Classifications and licensing outcomes
The EAR has no levels. Its structure is a classification followed by a licensing outcome, summarized here in general terms.
| Outcome | When it applies | How it is decided | What a company typically shows |
|---|---|---|---|
| EAR99, no license required | Item is subject to the EAR but not on the CCL, and no restricted destination, party or end use is involved | Self-classification and screening | Classification record and screening results |
| ECCN, no license required | Item is on the CCL, but the destination does not require a license | Self-classification against the CCL and country chart | ECCN and license determination |
| License exception | A license would be required, but a listed exception fits | Self-determined, with conditions and records | Exception used and its basis |
| License | A license is required and no exception fits | Application to BIS | License number and conditions |
| Classification request | Unsure of the ECCN | Request to BIS | BIS classification ruling |
When it matters for buyers
- When you sell technology products abroad. Customers and distributors may ask for your ECCN.
- When engineers, contractors or support staff abroad need access. Repositories and file shares may hold controlled technology.
- When choosing cloud, MSP or help desk providers. Where data sits and who administers it can matter.
- When expanding into new countries. Some destinations carry far stricter controls.
- When you also handle defense data. ITAR and CMMC requirements may apply to the same environment.
Our governance, risk and compliance overview covers advisors and tools for classification, screening and access controls.
Questions to ask vendors
- In which countries are our data, backups and logs stored or processed?
- Where are support and administrative staff located, and can access be limited by location or nationality where needed?
- Can you restrict our data to specific regions, and is that restriction in the contract?
- How is our data encrypted, and who holds the keys?
- For software we buy: what is your product’s ECCN, and are there export restrictions we should know about?
- Will you notify us before changing data locations or support arrangements?
How it differs from ITAR
ITAR covers defense articles, services and technical data on the US Munitions List and is administered by the State Department. The EAR covers commercial and dual-use items on the Commerce Control List, and many ordinary items as EAR99, and is administered by the Commerce Department. ITAR is generally stricter and offers fewer exceptions, while EAR outcomes depend heavily on destination and end user. Many defense contractors handle data under both, which is why they often appear together with CMMC and NIST Special Publication 800-171 requirements.
