77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Software is an export: Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 and the Cryptography Note
Governance & Compliance

Software is an export: Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 and the Cryptography Note

15 September 202611 min readBy Dr. Henrik Bauer
CIVAC

Whoever makes software available electronically to a user outside the EU is exporting. What the Dual-Use Regulation then requires, which notes decontrol, and which file has to exist even when the product is decontrolled.

Key takeaways

  • Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 counts as export 'making available in an electronic form such software and technology to natural or legal persons or to partnerships outside the customs territory of the Union'. A user account for a customer in a third country is therefore an export transaction.
  • Under Art. 3(1) only the export of items listed in Annex I requires an authorisation; under Art. 4(1) also unlisted items, where the competent authority has informed the exporter of a critical end-use.
  • The General Software Note decontrols software that is generally available or in the public domain, but expressly not software covered by Category 5 Part 2 ('Information Security'). For encryption the separate Cryptography Note applies.
  • The Cryptography Note decontrols mass-market cryptographic products, but its condition No. 4 requires that details of the goods are accessible and provided to the competent authorities on request; the German version speaks of detailed technical descriptions to be kept. The decontrol is tied to a file.
  • An Internal Compliance Programme is mandatory under Art. 12(4) only for users of global export authorisations. Art. 8 concerns technical assistance, not the ICP.
  • Exporting listed items without authorisation is punishable under § 18(5) No. 1 AWG with imprisonment of three months to five years; negligent conduct is an administrative offence under § 19(1) AWG.

Why a software company exports without a customs declaration

In Germany export control is perceived as a mechanical-engineering subject: machine tools, valves, sensors, a container, a customs declaration. Regulation (EU) 2021/821, which has governed the control of dual-use items in the Union since 9 September 2021, is wider at this point than the usage suggests. Art. 2 No. 1 defines dual-use items as 'items, including software and technology, which can be used for both civil and military purposes'. Software is an item, not an accessory.

The decisive provision is the definition of export in Art. 2 No. 2. Beside the export procedure, re-export and outward processing under the Customs Code, lit. d names 'transmission of software or technology by electronic media, including by fax, telephone, electronic mail or any other electronic means to a destination outside the customs territory of the Union; it includes making available in an electronic form such software and technology to natural or legal persons or to partnerships outside the customs territory of the Union; it also includes the oral transmission of technology when the technology is described over a voice transmission medium'.

Three transactions that take place daily in a software company fall under this wording: the download of an installation package by a customer in Switzerland, the United Kingdom or the United States; the creation of a user account for a subsidiary in India through which the application runs in the browser; and the handover of source code or design data to a development contractor in a third country. Whether a data carrier crosses the border plays no role. The customs territory of the Union is, under Art. 2 No. 17, the customs territory within the meaning of Art. 4 of the Union Customs Code; Norway, Switzerland and the United Kingdom lie outside it.

The first question: is the software listed?

Art. 3(1) reads: 'An authorisation shall be required for the export of dual-use items listed in Annex I.' Annex I is the Union control list, divided into Categories 0 to 9 and within each category into sub-categories A (systems), B (test equipment), C (materials), D (software) and E (technology). Whether a product requires an export authorisation is therefore first a question of classification: does the software fall under an entry in sub-category D, or under none? Annex I is amended annually by Commission delegated regulation to follow the decisions of the international control regimes; the version in force at the time of export governs classification. The list was replaced in full by Delegated Regulation (EU) 2024/2547 of 5 September 2024, the version § 18(5) AWG also refers to; later amendments are to be checked before every classification.

For the overwhelming majority of business software the answer is: no entry. Inventory management, accounting, HR administration, project control and most specialist applications meet no technical parameter of the list. Two areas demand a close look. First, software intended for the 'development', 'production' or 'use' of a listed item, such as control software for listed machine tools or simulation software for listed components; here the software follows the item. Second, Category 5 Part 2, 'Information Security': entry 5A002 covers systems and equipment with certain cryptographic functions, entry 5D002 the associated software. Any application that encrypts, stores or transmits data has to be checked against these two entries before it is enabled for users in third countries.

The second question: does a note apply?

Annex I contains two general decontrols that matter more for software than any single entry. The General Software Note states that the categories of the list do not control 'software' which is either generally available to the public by being sold, without restriction, from stock at retail selling points by means of over-the-counter, mail order, electronic or telephone transactions, and designed for installation by the user without further substantial support by the supplier (lit. a), or 'in the public domain' (lit. b), or the minimum necessary object code for the installation, operation, maintenance or repair of items whose export has been authorised (lit. c).

The note carries a restriction that is regularly read past in practice: lit. a of the General Software Note does not release software controlled by Category 5 Part 2 ('Information Security'). For encryption it is therefore not enough that the product is freely sold. For that there is the second decontrol, the Cryptography Note, and it is built differently.

The Cryptography Note: decontrolled, but with a file

The Cryptography Note in Category 5 Part 2 states, in its first part, that entry 5A002 and sub-entries 5D002.a.1, 5D002.b and 5D002.c.1 do not control items meeting all of the following: 1. generally available to the public by being sold, without restriction, from stock at retail selling points by means of over-the-counter, mail order, electronic or telephone transactions; 2. the cryptographic functionality cannot easily be changed by the user; 3. designed for installation by the user without further substantial support by the supplier; and '4. When necessary, details of the goods are accessible and will be provided, upon request, to the competent authorities of the EU Member State in which the exporter is established in order to ascertain compliance with conditions described in paragraphs 1. to 3. above'. The German language version of the same condition reads that detailed technical descriptions of the items are to be kept ('vorzuhalten') and produced on request; both versions are equally authentic.

The fourth condition is the point this article hangs on. The decontrol is not a determination a company makes once and forgets. It is tied to a document that has to be kept: a technical description from which it follows that the product is generally available, that the user cannot easily change the cryptographic function and that the user can install the product without substantial support. Whoever relies on the note and cannot produce this description on request from the Federal Office for Economic Affairs and Export Control (BAFA) cannot evidence the conditions of the decontrol. For a software company that means: export control does not begin with an authorisation application but with a file that nobody asks for until somebody asks for it.

The second part of the note, lit. b, additionally decontrols components and executable software developed for such decontrolled items, provided that 'information security' is not the primary function or set of functions of the component or executable software and that it does not change or add cryptographic functionality of the existing items. For applications that use a standard library for transport encryption without offering cryptography themselves, that is the relevant route; it too wants documenting.

The third question: end-use and recipient

Software that falls under no entry of Annex I is not thereby free of control. Art. 4(1) requires an authorisation for the export of unlisted dual-use items 'if the exporter has been informed by the competent authority that the items in question are or may be intended, in their entirety or in part' for use in connection with chemical, biological or nuclear weapons or their means of delivery, or for a military end-use where the purchasing or destination country is subject to an arms embargo, or as parts of listed military items exported without authorisation. Art. 5(1) contains a corresponding rule for unlisted cyber-surveillance items where they are or may be intended for use in connection with internal repression or serious violations of human rights and international humanitarian law.

These provisions attach to notification by the authority and to the exporter's own knowledge. Operationally, the check 'who is the recipient, what is the product used for' therefore does not only mean the sanctions-list screening but also the question of end-use and destination. For the great majority of customers the answer is given in seconds; the record that the question was asked is the evidence.

What an Internal Compliance Programme is and when it is mandatory

Art. 2 No. 21 defines the 'internal compliance programme' or ICP as 'ongoing effective, appropriate and proportionate policies and procedures adopted by exporters to facilitate compliance with the provisions and objectives of this Regulation and with the terms and conditions of the authorisations implemented under this Regulation, including, inter alia, due diligence measures assessing risks related to the export of the items to end-users and end-uses'.

The Regulation prescribes an ICP in one place: Art. 12(4) provides that exporters using global export authorisations shall implement an ICP, unless the competent authority considers it unnecessary due to other information it has taken into account when processing the application. Whoever provides only unlisted software or products falling under the notes is not subject to this obligation. The statement common in the market that the ICP follows from Art. 8 of the Regulation is incorrect: Art. 8 governs the authorisation requirement for technical assistance related to listed items. What remains even without the obligation is the question of how a company without a documented procedure intends to show that it classified the product, checked the note and kept the description under condition No. 4.

What is at stake

§ 18(5) of the German Foreign Trade and Payments Act (AWG) makes it a criminal offence to infringe Regulation (EU) 2021/821 by exporting dual-use items or cyber-surveillance items 'without an authorisation under Article 3(1), Article 4(1), Article 5(1) or Article 10(1)'; the sentencing range of paragraph 5 refers to paragraph 1 and is imprisonment of three months to five years. Under § 18(6) AWG the attempt is punishable. Whoever commits such an act negligently acts as an administrative offence under § 19(1) AWG; the fine can, under § 19(6) AWG, amount to up to five hundred thousand euros in these cases. For a company that enables its software worldwide without classification and without a file, the negligence variant is the realistic one.

One instrument the wording expressly provides is rarely used: § 8(2) sentence 2 AWG mentions 'certificates of the Federal Office for Economic Affairs and Export Control (BAFA) that an export does not require an authorisation'. Whoever is uncertain about the classification of a product can apply for this certificate and then holds the authority's answer in the file instead of their own assessment.

How the check enters operations

The wording yields a sequence a software company runs once per product and again on every material change. First: are there users outside the customs territory of the Union? If not, the Regulation does not apply to this transaction; transfers within the Union follow their own, narrower rules. Second: does the product fall under an entry of Annex I, in particular 5A002 or 5D002? The classification is recorded with date, author and reasoning. Third: does the General Software Note or the Cryptography Note apply? If so, the technical description under condition No. 4 is produced and filed. Fourth: are there indications of an end-use under Art. 4 or Art. 5, or a notification by the authority? Fifth: has the recipient been screened against the sanctions lists? Only then is the account created.

This check is not an officer-appointment duty. The Regulation prescribes no particular person, and neither the AWG nor the AWV requires a nomination to BAFA for unlisted software. It requires a decision that somebody takes and documents. In CIVAC the classification can be run per product as a task with resubmission, the technical description under condition No. 4 filed as a document on the record, and the sanctions screening per customer held with a timestamp, so that when the authority asks, the file exists rather than gets created.

Where this article ends

CIVAC is not a law firm and provides no legal services within the meaning of the German Legal Services Act (Rechtsdienstleistungsgesetz). This article sets out the wording of Regulation (EU) 2021/821 and of the AWG and describes which records a company should keep. Whether a particular product falls under entry 5A002 or 5D002 and whether the conditions of the Cryptography Note are met in the individual case is a classification decision the company takes and can have certified by BAFA. The control list in Annex I is amended annually; the version in force at the time of export governs, not the one quoted here.

Frequently asked questions

Is software-as-a-service an export under the Dual-Use Regulation?

Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 covers 'making available in an electronic form such software and technology to natural or legal persons or to partnerships outside the customs territory of the Union'. A user account through which a person in a third country uses the application is making available in electronic form. The transaction requires an authorisation, however, only if the software is listed in Annex I or a case under Art. 4 or Art. 5 exists.

Does software with encryption need an export authorisation?

Only if it falls under entry 5A002 or 5D002 of Category 5 Part 2 and no note applies. The Cryptography Note decontrols products that are generally available, whose cryptographic function the user cannot easily change and which can be installed without substantial support. Condition No. 4 requires that details of the goods are accessible and provided to the competent authorities on request; the German version speaks of detailed technical descriptions to be kept. Lit. a of the General Software Note expressly does not help for Category 5 Part 2.

Is an Internal Compliance Programme mandatory for software companies?

Under Art. 12(4) of Regulation (EU) 2021/821 an ICP is prescribed for exporters using global export authorisations. Whoever exports no listed items is not subject to this obligation. Art. 8 of the Regulation concerns technical assistance, not the ICP. Independently of the obligation, the question remains how a company without a documented procedure intends to evidence the classification and the description under the Cryptography Note.

What penalty applies to an unauthorised export of software?

§ 18(5) No. 1 AWG threatens the export of listed items without an authorisation under Art. 3(1), Art. 4(1), Art. 5(1) or Art. 10(1) of the Regulation with imprisonment of three months to five years; the attempt is punishable under § 18(6) AWG. Negligent conduct is an administrative offence under § 19(1) AWG with a fine of up to five hundred thousand euros under § 19(6) AWG.

How do I evidence that my product does not require an authorisation?

With a documented classification against Annex I in the version in force, with the technical description under condition No. 4 of the Cryptography Note if you rely on it, and, in case of doubt, with a BAFA certificate under § 8(2) sentence 2 AWG that the export does not require an authorisation. All three records belong to the product, not to the individual customer.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles