EAR vs. ITAR: What the Export Administration Regulations Actually Control
Many exporters wrongly assume export controls apply only to obviously military goods — weapons, munitions, defense hardware. That assumption is both common and costly. The Export Administration Regulations (EAR) reach far beyond military goods, controlling dual-use items — commercial technology with military applications — through a licensing and enforcement regime that catches organizations off guard more often than the more narrowly scoped ITAR does, precisely because EAR’s reach feels less obviously “defense-related” until an organization is already in violation of it.
This guide covers what EAR actually controls, how it differs from ITAR and OFAC sanctions, how classification and licensing work in practice, and what current enforcement looks like.
Executive Summary
Main Idea: EAR controls dual-use items — those with both civilian and military applications — administered by Commerce’s Bureau of Industry and Security. It’s distinct from ITAR, which governs defense-specific articles and services under the State Department’s DDTC, and from OFAC sanctions, which restrict transactions with specific countries, entities, and individuals regardless of item classification.
Why You Should Care: The Bureau of Industry and Security (BIS) imposed over $1.5 billion in penalties for export violations in fiscal year 2024 alone. Misclassifying an item, skipping a required license, or inadvertently disclosing controlled technology to a foreign person are among the most common — and costly — export compliance mistakes, and they happen disproportionately to organizations that assumed EAR didn’t apply to their commercial, non-weapons products.
Key Takeaways
- EAR governs dual-use items — not defense articles specifically. Dual-use items have both civilian and military applications: a commercial drone component, encryption software, or a semiconductor manufacturing tool can all fall under EAR even though none is a weapon.
- EAR and ITAR are administered by different federal agencies and cover different categories of items. EAR is administered by Commerce’s Bureau of Industry and Security and covers dual-use items. ITAR is administered by State’s Directorate of Defense Trade Controls and covers defense articles, services, and technical data specific to military use. An item generally falls under one regime or the other, not both — but organizations working across both commercial and defense-related product lines often need compliance programs addressing each.
- Classification against the Commerce Control List determines what a license requires — most items fall under EAR99 and need no license at all. Every item potentially subject to EAR needs to be classified with an Export Control Classification Number (ECCN) from the Commerce Control List, or determined to be EAR99 — a catch-all designation for items not specifically listed, most of which require no license for most destinations.
- EAR has its own “deemed export” rule, parallel to ITAR’s. Releasing controlled technology or source code to a foreign person inside the United States counts as an export to that person’s home country under EAR — the same principle that applies under ITAR, just for a different category of controlled items.
- Export filings go through the Automated Export System (AES), not a paper Shipper’s Export Declaration. The SED was retired years ago. Electronic Export Information (EEI) is now filed through AES under the Census Bureau’s Foreign Trade Regulations, generally required when a shipment’s value exceeds $2,500 per Schedule B classification or when a license is required, regardless of value.
How EAR Differs From ITAR and OFAC Sanctions
U.S. export controls operate through three distinct regimes, and confusing them is a common and consequential mistake. EAR, administered by Commerce’s Bureau of Industry and Security, governs dual-use items — goods, software, and technology with both commercial and military applications, controlled under 15 CFR Parts 730–774. ITAR, administered by State’s Directorate of Defense Trade Controls, governs defense articles, defense services, and technical data specifically designed or modified for military use, listed on the United States Munitions List. OFAC sanctions, administered by Treasury’s Office of Foreign Assets Control, restrict or prohibit transactions with specific countries, entities, and individuals — operating independently of what the item itself is.
The practical distinction that trips people up most often: an item’s classification generally determines which single regime applies — something on the U.S. Munitions List falls under ITAR, not EAR — but an organization exporting both defense-related and commercial dual-use products often needs to maintain compliance programs addressing both regimes simultaneously, plus screening for sanctions restrictions that apply regardless of item classification. If your organization works with defense-related technical data specifically, see our ITAR compliance guide for the requirements that apply there instead of, or alongside, EAR.
What Data Compliance Standards Matter?
How EAR Classification and Licensing Actually Work
Determining whether an item requires an export license under EAR involves three practical steps.
Classify the item. Check the Commerce Control List (CCL) to determine whether the item has a specific Export Control Classification Number (ECCN) — a five-character code identifying why the item is controlled (national security, anti-terrorism, and similar categories) and under what conditions. Items not specifically listed on the CCL are generally classified as EAR99, a catch-all designation. Most EAR99 items don’t require a license for most destinations, though a license may still be required depending on the specific destination, end user, or end use.
Check the Commerce Country Chart. For items with a specific ECCN, the Commerce Country Chart cross-references the item’s reasons for control against the destination country to determine whether a license is required for that specific export.
Screen all parties against restricted party lists. Regardless of item classification, exporters must screen the end user, end-user’s organization, and any intermediaries against BIS’s restricted and denied party lists, since a transaction involving a listed party can require a license or be prohibited outright even for an otherwise unrestricted item.
Licensing decisions ultimately hinge on three factors working together: the end-use (what the item will actually be used for), the end-user (who will receive it), and the destination (where it’s being shipped) — the same item can require a license for one combination of these factors and not another.
Deemed Exports Under EAR
EAR’s deemed export rule mirrors the same principle that applies under ITAR: releasing controlled technology or source code to a foreign person inside the United States is treated as an export to that person’s home country, even though nothing physically crosses a border. Sharing technical specifications, source code, or proprietary manufacturing processes with a foreign national employee, contractor, or visitor — even in a routine internal meeting or a shared document — can trigger EAR’s deemed export provisions if the underlying technology is controlled.
This has direct implications for how organizations manage digital collaboration involving EAR-controlled technology: access to controlled technical data needs to be restricted based on nationality and authorization status, not just general employment status within the organization.
Filing Requirements: AES, Not SED
Export filings are handled through the Automated Export System (AES), which collects Electronic Export Information (EEI) under the Census Bureau’s Foreign Trade Regulations (15 CFR Part 30). This replaced the paper Shipper’s Export Declaration years ago — any reference to an SED reflects outdated guidance.
AES/EEI filing is generally required when a shipment’s value exceeds $2,500 per Schedule B classification, or when an export license is required regardless of value. Filing must occur before the shipment departs (predeparture filing), though approved companies may qualify for postdeparture filing in specific circumstances. The U.S. Principal Party in Interest (USPPI) bears ultimate legal responsibility for filing accuracy, even when an authorized agent such as a freight forwarder files on the USPPI’s behalf.
Current EAR Enforcement
BIS enforcement activity has been substantial in recent years — the agency imposed over $1.5 billion in penalties for export violations in fiscal year 2024 alone. Enforcement covers the full range of EAR obligations: exporting controlled items without a required license, misclassifying items to avoid licensing requirements, transacting with restricted or denied parties, and deemed export violations involving unauthorized disclosure of controlled technology to foreign persons.
Penalties can include substantial civil fines, criminal prosecution for willful violations, and denial of export privileges — a consequence that, similar to ITAR debarment, can effectively end an organization’s ability to participate in export activity regardless of the financial penalty involved.
How Kiteworks Supports EAR-Related Data Governance
Kiteworks provides governance and access control capabilities relevant to organizations managing EAR-controlled technology and technical data, particularly around preventing deemed export exposure in digital collaboration.
A unified Data Policy Engine enforces granular, role-based access controls across secure email, secure file sharing, managed file transfer, and SFTP — directly relevant to restricting access to EAR-controlled technology based on authorization status, helping prevent inadvertent deemed export exposure. AES-256 encryption with FIPS 140-3 validated cryptographic modules protects controlled technical data at rest and in transit, and a single, consolidated, immutable audit trail provides the recordkeeping evidence an export compliance program depends on — tracking exactly who accessed, edited, or shared controlled technology, and when.
Kiteworks also holds FedRAMP Moderate Authorization, independently assessed since June 2017, relevant for organizations whose EAR compliance program intersects with federal contracting requirements. For organizations managing both EAR and ITAR obligations, see our ITAR compliance guide for the parallel requirements that apply to defense-specific articles and technical data.
To see how Kiteworks supports your organization’s export control data governance, schedule a custom demo.
Frequently Asked Questions
EAR, administered by the Commerce Department’s Bureau of Industry and Security, governs dual-use items — goods, software, and technology with both civilian and military applications. ITAR, administered by the State Department’s Directorate of Defense Trade Controls, governs defense articles, services, and technical data specifically designed or modified for military use and listed on the U.S. Munitions List. An item’s classification generally determines which single regime applies, though organizations working across both commercial and defense product lines often need compliance programs addressing both.
No. Most items, once classified, fall into the EAR99 catch-all designation and don’t require a license for most destinations. Licensing requirements depend on the specific combination of the item’s Export Control Classification Number (or lack thereof), the destination country, the end user, and the end use — the same item can require a license for one combination of these factors and not another. Checking the Commerce Control List, the Commerce Country Chart, and restricted party lists is the standard three-step process for determining whether a specific export requires a license.
A deemed export occurs when controlled technology or source code is released to a foreign person inside the United States — treated as an export to that person’s home country even though nothing physically crosses a border. This mirrors the identical principle under ITAR, applied to EAR-controlled dual-use technology instead of defense articles. Sharing technical specifications or proprietary processes with a foreign national employee or contractor can trigger this rule if the underlying technology is controlled, making access restriction based on nationality a practical requirement for organizations managing EAR-controlled technical data.
No. The Shipper’s Export Declaration was retired and replaced by electronic filing through the Automated Export System (AES). Exporters now file Electronic Export Information (EEI) through AES under the Census Bureau’s Foreign Trade Regulations, generally required when a shipment’s value exceeds $2,500 per Schedule B classification or when an export license is required regardless of value. Any current guidance still referencing the SED reflects outdated information.
EAR enforcement is active and financially significant — the Bureau of Industry and Security imposed over $1.5 billion in penalties for export violations in fiscal year 2024 alone. Violations can result in substantial civil fines, criminal prosecution for willful violations, and denial of export privileges, which can effectively end an organization’s ability to participate in export activity regardless of the specific financial penalty assessed. Common violations include exporting without a required license, misclassifying items, transacting with restricted parties, and deemed export violations involving unauthorized disclosure to foreign persons.
Additional Resources
- Blog Post The Tug-of-War Over Your Data: How the CLOUD and SHIELD Acts Pit Security vs. Privacy
- Blog Post Secure Sensitive Data by Mapping DSPM to Your Compliance Goals
- Brief Top 3 FERPA Violations and How to Avoid Them
- Blog Post Executive Order 14117: Protecting Americans’ Bulk Sensitive Personal Data
- Blog Post Need NIS2 Compliance? Start With ISO 27001