Understanding Encryption Controls
Category 5 Part 2 of the Commerce Control List controls items that perform information security functions using cryptographic algorithms for data confidentiality. This is one of the most frequently relevant control areas for technology companies because virtually all modern software and hardware incorporates some form of encryption.
The key distinction is between items controlled under 5A002 (or 5D002 for software) — which carry significant license requirements — and items classified under 5A992/5D992 — which qualify for mass-market treatment and are largely decontrolled. The classification depends on whether the item meets the criteria in Note 3 to Category 5 Part 2.
5A002: Fully Controlled Encryption
ECCN 5A002 controls information security systems, equipment, and components that use cryptography for data confidentiality and do not qualify for any exclusion or mass-market treatment. Items classified under 5A002 require licenses for most destinations outside of close U.S. allies and have limited license exception availability.
Items that stay at 5A002 include enterprise-grade encryption hardware, network security appliances with customizable encryption, and items where the cryptographic functionality can be easily modified by the user.
5A992: Mass-Market Encryption
ECCN 5A992 applies to items that meet all four criteria of Note 3 to Category 5 Part 2: (1) generally available to the public by being sold from stock at retail points, (2) cryptographic functionality cannot be easily changed by the user, (3) designed for installation by the user without substantial supplier support, and (4) details of the items are accessible to the competent authority upon request.
Most consumer electronics — smartphones, laptops, routers, consumer VPN software — qualify for 5A992 under the mass-market provisions. However, failing any single criterion means the item remains at 5A002.