The Export Administration Regulations (EAR) are a set of rules established by the U.S. Department of Commerce that control the export, reexport, and transfer of dual-use items — goods, software, and technology with both civilian and military applications. Administered by the Bureau of Industry and Security (BIS) under 15 CFR Parts 730–774, EAR governs a far larger share of U.S. export activity than most organizations assume, precisely because “dual-use” captures an enormous range of ordinary commercial technology alongside anything more obviously sensitive.

EAR

Why EAR Exists

EAR’s statutory basis has a more complicated history than its current stability suggests, and understanding that history explains why the regulation is structured the way it is today. The Export Administration Act of 1979 (EAA) originally provided the legal framework authorizing the Commerce Department to regulate the export of dual-use goods, software, and technology. Throughout the 1970s, Congress had been steadily liberalizing export controls — in 1977, for instance, Congress moved away from treating a country’s status as Communist as the sole determining factor in export restrictions, shifting instead toward a more nuanced assessment of each country’s actual relationship with the United States.

The EAA expired in 2001 and was never permanently reauthorized. For the following 17 years, EAR was kept in legal effect only through a series of presidential executive orders issued under the International Emergency Economic Powers Act (IEEPA) — an unusual and somewhat precarious arrangement, since IEEPA is designed for national emergencies and required continuous annual renewal to keep the underlying export control framework operating.

This changed with the Export Control Reform Act of 2018 (ECRA), signed into law on August 13, 2018 as part of that year’s National Defense Authorization Act. ECRA gave EAR a permanent statutory foundation for the first time in nearly two decades, with no sunset provision requiring future reauthorization. One of ECRA’s primary policy motivations was addressing growing concern — shared across Congress and industry — about the risk of critical emerging and foundational technologies reaching countries of concern, a concern that has only intensified in the years since around technologies like semiconductors and artificial intelligence.

The practical reason EAR exists, in other words, is straightforward even though its legislative history is not: dual-use items sit at the intersection of ordinary commerce and national security, and the government needs a mechanism to prevent sensitive technology from reaching adversaries or contributing to weapons proliferation, without halting the much larger volume of legitimate international trade that dual-use classification would otherwise sweep in.

What EAR Covers

EAR applies to items of U.S. origin, and in some cases to foreign-made items that incorporate controlled U.S. technology or were produced using controlled U.S. equipment — a scope that has expanded over time as global supply chains have become more complex and harder to trace to a single national origin.

Every item potentially subject to EAR is classified using an Export Control Classification Number (ECCN) from the Commerce Control List, or falls under EAR99, a catch-all designation for items not specifically listed. Most EAR99 items don’t require an export license for most destinations; items with a specific ECCN may require a license depending on the destination, end user, and end use.

How EAR Differs From ITAR

EAR and ITAR are frequently confused but govern different categories of items under different federal agencies. EAR, administered by Commerce’s BIS, covers dual-use items. ITAR, administered by the State Department’s Directorate of Defense Trade Controls, covers defense articles, services, and technical data specifically designed for military use. An item generally falls under one regime or the other based on its classification, though organizations working across both commercial and defense-related products may need to comply with both. For the full comparison, including how deemed exports and licensing mechanics work under each regime, see EAR vs. ITAR: What the Export Administration Regulations Actually Control.

Who Enforces EAR and How

BIS enforces EAR primarily through its Office of Export Enforcement (OEE), which investigates suspected violations of export control and antiboycott regulations. OEE’s stated mission is protecting national security by keeping the country’s most sensitive items out of the hands of the world’s most dangerous actors — language that reflects how seriously the agency treats even seemingly minor administrative violations, such as failing to classify an item correctly or overlooking a required license.

A central feature of BIS’s enforcement approach is the Voluntary Self-Disclosure (VSD) program. If an organization believes it may have violated EAR, BIS strongly encourages reporting the suspected violation to OEE before it’s discovered through other means — audits, investigations, or a third party. This isn’t a purely symbolic gesture: BIS has stated that historically fewer than 3% of voluntary self-disclosure submissions have resulted in a civil penalty, and even where a penalty is ultimately assessed, voluntary disclosure is a significant mitigating factor that can cut the maximum civil penalty for a non-egregious violation in half. BIS has also implemented a “fast-track” resolution process for minor or technical infractions without aggravating factors, allowing an abbreviated disclosure process rather than a full investigation.

BIS also distinguishes between willful and non-willful violations when determining enforcement response — a distinction that matters considerably for how a case is handled and what penalties ultimately apply. An organization with a documented, risk-based compliance program in place before a violation occurs is generally treated more favorably during enforcement than one without any compliance infrastructure at all, since BIS views an effective compliance program as evidence of good-faith effort rather than the violation itself as a compliance failure.

Consequences of Non-Compliance

EAR enforcement carries substantial financial and operational consequences, and BIS enforcement activity has been significant in recent years — the agency imposed over $1.5 billion in penalties for export violations in fiscal year 2024 alone.

Civil penalties can be assessed regardless of intent, and criminal penalties apply to willful violations, carrying the possibility of significant fines and imprisonment. Beyond direct financial penalties, violations can result in denial of export privileges — a consequence that can be more operationally devastating than the financial penalty itself, since it can effectively exclude an organization from participating in export activity at all, regardless of how much of its business depends on international trade.

Common violation categories include exporting a controlled item without a required license, misclassifying an item to avoid licensing requirements (whether intentionally or through inadequate internal review), transacting with parties on BIS’s restricted or denied party lists, and “deemed export” violations — disclosing controlled technology to a foreign person inside the United States, which is treated the same as a physical export under EAR.

Building an Effective EAR Compliance Program

BIS publishes formal guidelines — the Export Compliance Guidelines: The Elements of an Effective Export Compliance Program — describing what a risk-based compliance program should include, and offers a free Export Compliance Plan (ECP) review service to help organizations evaluate their program against these elements.

A few practices consistently distinguish stronger compliance programs from weaker ones. Management commitment is foundational — a compliance program that exists only as a document, without genuine leadership backing and resourcing, tends to break down under real operational pressure. Systematic classification of every item, technology, and piece of software an organization exports — determining its ECCN or EAR99 status proactively, rather than reactively when a shipment is already pending — prevents the misclassification errors that account for a large share of violations. Restricted party screening should be built into standard transaction workflows, checking every counterparty, end user, and intermediary against BIS’s Consolidated Screening List before a transaction proceeds, not as an afterthought.

Recordkeeping matters considerably, both for demonstrating compliance and for supporting an accurate voluntary self-disclosure if a violation is later identified. Training for employees who handle export decisions, technical data, or international collaboration is what actually operationalizes a compliance program day to day — a well-designed policy that employees don’t understand or don’t follow in practice provides little real protection. And when a potential violation is discovered internally, BIS’s own guidance is direct: stop the transaction immediately, investigate promptly, and strongly consider a voluntary self-disclosure given the significant mitigation it typically provides.

Organizations managing digital collaboration involving export-controlled technology have a specific and often underappreciated compliance dimension: technical data shared internally with foreign national employees, contractors, or partners can trigger deemed export obligations even without any physical shipment occurring. Building access controls that restrict controlled technical data based on nationality and authorization status — not just general employment status — is a practical compliance measure that pairs directly with the broader program elements BIS recommends.

How Kiteworks Supports EAR Compliance

Kiteworks provides governance and access control capabilities for organizations managing EAR-controlled technology, directly supporting the technical data protection dimension of a broader export compliance program. A unified Data Policy Engine enforces role-based access controls across secure email, secure file sharing, managed file transfer, and SFTP — helping restrict controlled technical data to authorized personnel and reducing deemed export exposure in digital collaboration.

AES-256 encryption with FIPS 140-3 validated cryptographic modules protects controlled technical data at rest and in transit, and a single, consolidated, immutable audit trail provides exactly the kind of recordkeeping evidence BIS’s compliance guidelines call for — documenting who accessed, shared, or modified controlled technology, and when. That evidence base is also what supports an accurate, well-documented voluntary self-disclosure, should one ever become necessary.

To see how Kiteworks supports your organization’s export control data governance, schedule a custom demo.

Frequently Asked Questions

EAR’s current statutory foundation is the Export Control Reform Act of 2018 (ECRA), which gave the regulations permanent legal authority for the first time since the original Export Administration Act of 1979 expired in 2001. Between 2001 and 2018, EAR was maintained only through a series of presidential executive orders under the International Emergency Economic Powers Act, an arrangement that required continuous annual renewal. ECRA removed that uncertainty and remains in effect today with no sunset provision.

A Voluntary Self-Disclosure (VSD) is a report an organization submits to BIS’s Office of Export Enforcement when it believes it may have violated EAR, submitted before the violation is discovered through other means. BIS strongly encourages this practice: historically, fewer than 3% of VSD submissions have resulted in a civil penalty, and even where a penalty is assessed, voluntary disclosure can cut the maximum civil penalty for a non-egregious violation in half. BIS also offers a fast-track resolution process for minor, non-aggravated infractions disclosed voluntarily.

The most common categories are exporting a controlled item without a required license, misclassifying an item’s ECCN to avoid licensing obligations, transacting with a party on BIS’s restricted or denied party lists, and deemed export violations — disclosing controlled technology or source code to a foreign person inside the United States, which EAR treats the same as a physical export. Many violations stem from inadequate internal classification processes rather than deliberate evasion, which is part of why BIS treats a documented compliance program as a meaningful mitigating factor during enforcement.

BIS publishes formal guidance — the Export Compliance Guidelines: The Elements of an Effective Export Compliance Program — and offers a free review service for organizations building or updating a compliance program. Core elements generally include documented management commitment, systematic classification of all exported items and technology, restricted party screening built into standard transaction workflows, thorough recordkeeping, and employee training for anyone involved in export decisions or handling controlled technical data. Organizations that discover a potential violation internally are advised to stop the transaction immediately, investigate, and strongly consider a voluntary self-disclosure.

No, and this is one of the most common misconceptions about EAR. EAR governs dual-use items — technology, software, and goods with both civilian and military applications — which covers a much broader range of ordinary commercial products than most organizations assume, including certain encryption software, semiconductor manufacturing equipment, and other advanced commercial technologies. Many exporters wrongly assume that because their product isn’t a weapon, EAR doesn’t apply, an assumption that BIS’s enforcement history shows is both common and costly.

 

Back to Risk & Compliance Glossary

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks