Encryption & Cat 5

Cloud Computing and Encryption Export Controls

Cloud Services and the EAR

Cloud computing creates unique export control challenges because encrypted data and encryption software may be stored on servers in multiple jurisdictions. The EAR applies to cloud-based encryption software and technology, and the location of servers, the nationality of users, and the accessibility of encryption functionality all factor into the compliance analysis.

BIS has provided guidance clarifying that storing encrypted data on foreign servers does not by itself constitute an export of encryption software if the data remains encrypted and the encryption keys are not accessible from the foreign server.

When Cloud Triggers Export Control

An export occurs when encryption software is made available to foreign persons, whether through cloud access or direct download. If a cloud service provides encryption functionality — not just encrypted storage — the encryption software embedded in the service may require classification and potentially a license or license exception.

SaaS applications with client-side encryption components should classify the client-side software. Server-side encryption infrastructure is typically not 'exported' if it remains under U.S. control, but providing access to the encryption capability to foreign users may constitute a deemed export.

Practical Compliance for Cloud

Cloud service providers should maintain awareness of where their infrastructure is located, who has access to encryption functionality, and whether end-to-end encryption keys are managed by the user or by the provider. Access controls that restrict cloud service availability by geography can help manage export control obligations.

Multi-tenant cloud architectures should evaluate whether providing encryption-as-a-service to foreign customers constitutes an export of encryption items. The analysis depends on the specific service architecture and the degree to which encryption functionality is made available to the end user.

Frequently Asked Questions

Does storing encrypted data on foreign servers count as an export?

Not necessarily. BIS guidance indicates that storing encrypted data on foreign servers does not constitute an export of encryption software if the data remains encrypted and encryption keys are not accessible from the foreign server.

Do SaaS encryption features require export classification?

Yes, if a SaaS application provides encryption functionality to users, the client-side encryption software should be classified under Category 5 Part 2 of the CCL.

Classify Your Item Now

Use our AI-powered ECCN classification tool to find the correct export control classification for any item.

Try ECCN.help Free →
EH
ECCN.help
AI-powered export control classification and compliance guidance.