Software

The software industry is one of the fastest growing and globally integrated industries, driven by rapid technological innovation, evolving regulatory landscapes, and increasingly complex international trade dynamics. With advances in cloud computing, artificial intelligence, SaaS (Software as a Service) platforms, and cybersecurity, software products are traded across borders, requiring companies to navigate diverse regulations, intellectual property protections, data privacy standards, and compliance requirements. 

Software products and related services are often classified as dual-use items (items with both potential civil and military/intelligence application). As a result, they are subject to export controls under U.S. regulations, including the Export Administration Regulations (EAR) and International Traffic in Arms Regulations (ITAR). The EAR, administered by the Bureau of Industry and Security (BIS), governs the export of dual-use items, including software that may be used for general business purposes or in more sensitive, strategic applications. Software related to encryption, network security, and advanced algorithms often requires an export license to be transferred to certain countries. The ITAR, managed by the Directorate of Defense Trade Controls (DDTC), covers software with direct defense applications and is particularly stringent, with restrictions on the export of source code, algorithms, and software products that could enhance foreign military capabilities. 

The software industry’s role will continue to  grow in the coming years, driven by technological advancements such as artificial intelligence, cloud computing, and the Internet of Things (IoT). Expanding global digital infrastructure and increased data privacy needs also create new opportunities and challenges for the software industry. As the industry adapts to emerging technology and regulatory environments, the U.S. will continue to play a leading role in developing secure, innovative software solutions for both commercial and governmental applications on a global scale. 

In recent years, software, particularly SaaS, has come under additional scrutiny from government regulators. Torres Trade Law has assisted many companies in navigating these regulations. Representative experience includes:

  • Advising multiple software companies on the potential application of Committee on Foreign Investment in the U.S. (CFIUS) regulations to investments and acquisition by foreign investors.
  • Classifying software and SaaS products pursuant to EAR encryption classification regulations, including obtaining favorable government classifications of SaaS products.
  • Representing a SaaS company before the Department of the Treasury Office of Foreign Assets Control (OFAC) related to apparent violations of Cuban and Libyan sanctions programs.
  • Assisting software companies determine export classification and licensing requirements for products used in industrial fields.

Software Trade & Export Law FAQs

1. Which U.S. agencies regulate software exports and software-related trade compliance?

The Bureau of Industry and Security (BIS) is the primary agency responsible for regulating dual-use and commercial software under the EAR. The International Traffic in Arms Regulations (ITAR) regulate the export of defense-related software, technical data, and defense services. The Office of Foreign Assets Control (OFAC) administers sanctions that may restrict software transactions involving sanctioned jurisdictions, entities, or individuals. U.S. Customs and Border Protection (CBP) may become involved when software is imported or exported as part of hardware, machinery, electronic devices, or other physical goods. The Committee on Foreign Investment in the United States (CFIUS) may also review certain foreign investments in U.S. software companies when the business involves critical technologies, sensitive personal data, cybersecurity tools, artificial intelligence, defense applications, or other national security concerns.

2. How are encryption software products regulated under the EAR?

Encryption software is subject to special rules under the EAR and often implicates detailed and complex classification reviews. BIS explains that License Exception ENC is the main license exception used for items in Category 5, Part 2, and that most encryption products can be exported to most destinations under License Exception ENC after the exporter complies with applicable classification and reporting requirements. Some encryption items, end users, destinations, or uses may still require a license. Careful classification, assistance form internal or external legal counsel, and detailed documentation on classification analyses are essential for ensuring proper export compliance for software products.

3. When is software subject to the EAR?

Software is generally subject to the EAR when it is U.S.-origin software, located in the United States, or exported from the United States. Software may be classified under an Export Control Classification Number on the Commerce Control List or may be designated EAR99 if it is subject to the EAR but not specifically listed on the CCL. BIS guidance explains that the EAR covers exports, reexports, and transfers of items subject to the EAR, and certain releases of source code or technology can also constitute exports.

For software companies, the EAR may apply to encryption software, cybersecurity tools, source code, object code, development tools, software used with controlled equipment, software for advanced computing or semiconductors, aerospace-related software, and other software with military, intelligence, surveillance, or proliferation-sensitive applications. A license requirement depends on the software’s classification, destination, end user, and end use.

4. When is software subject to the ITAR?

Software may be subject to the ITAR when it is specifically listed on the U.S. Munitions List or directly related to an ITAR-controlled defense article. Under ITAR § 120.40(g), software includes functional design, logic flow, algorithms, application programs, operating systems, and support software for design, implementation, testing, operation, diagnosis, and repair. ITAR-controlled software may be regulated because it constitutes technical data, such as source code revealing controlled design details, or because it is used to operate, test, produce, or support an ITAR-controlled system.

Common ITAR software issues arise in connection with military electronics, fire control systems, laser and imaging systems, guidance systems, spacecraft, classified articles, and other defense technologies. Software may also be controlled if it supports the development, production, operation, maintenance, or testing of defense articles. Companies should not assume that software is outside the ITAR merely because it is intangible, cloud-based, or delivered electronically.

5. What is the difference between ITAR-controlled software and EAR-controlled software?

ITAR-controlled software generally relates to defense articles or defense systems listed on the U.S. Munitions List. In contrast, EAR-controlled software generally covers dual-use, commercial, or less-sensitive military-related software listed on the Commerce Control List. The distinction matters because ITAR-controlled software is generally subject to stricter licensing requirements, narrower exemptions, and more severe restrictions on access by foreign persons.

Companies should conduct a jurisdiction and classification analysis before exporting, sharing, licensing, uploading, or granting access to software that may have defense or national security applications.

6. What is “technical data,” and why does it matter for software companies?

Technical data can include controlled information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a controlled item. For software companies, this may include source code, algorithms, architecture documents, functional design, logic flow, specifications, test protocols, debugging materials, technical manuals, and development documentation.

Technical data matters because export controls may apply not only to the finished software product, but also to the underlying information that allows someone to develop, reproduce, modify, test, or operate controlled software or hardware. Sharing source code with a foreign developer, granting access to a private GitHub repository, sending controlled technical documentation to an offshore engineering team, or allowing a foreign person to access controlled software development environments may create export-control issues.

7. Can providing software access to a foreign person count as an export?

Yes. Under the EAR, releasing controlled technology or source code to a foreign person may constitute a deemed export. BIS materials explain that a deemed export can occur when controlled technology or source code subject to the EAR is released to a foreign national. Under the ITAR, releasing controlled technical data to a foreign person can also constitute an export.

8. Does uploading controlled software to the cloud create export-control risk?

Yes. Uploading controlled software, source code, or technical data to cloud platforms can create export-control risk if foreign persons can access the data or if the data is stored, mirrored, supported, or administered in a way that creates an unauthorized export or reexport. Risks may arise from shared drives, code repositories, cloud development environments, ticketing systems, backups, foreign administrator access, customer portals, or third-party vendor support. Companies should understand where controlled software is stored, who can access it, whether access logs are maintained, whether foreign persons have administrator privileges, and whether encryption, access restrictions, or licensing authorizations are required.

INSIGHTS

Persistent Errors in the Export Classification of Software Products

By: Olga Torres, Managing Member
Date: 04/20/2024

Many companies, particularly Software-as-a-Service (“SaaS”) and start-up companies, continue to struggle with the concept of export control classification of items with encryption functionality. This ongoing confusion is understandable for a few reasons. First, many SaaS companies do not export their software in the traditional sense. Software purchasing has moved beyond the days of downloading and installing software onto a computer from, for example, a CD-ROM. (Most newer laptops no longer contain disc drives.) But these companies may still unknowingly be exporting software according to regulatory definitions.

Commerce Finalizes ICTS Supply Chain Rule

By: By Derrick Kyle, Senior Associate
Date: 10/31/2023

On June 16, 2023, the U.S. Department of Commerce (“Commerce”) issued a long-awaited final rule (the “Final Rule”), effective July 17, 2023, related to the Information and Communications Technology Supply Chain.1 Among other clarifications, the Final Rule identifies the Under Secretary of Commerce for Industry and Security as responsible

BIS Releases New Rules Updating Restrictions on Advanced Computing Chips, Manufacturing Equipment, and Supercomputing Items to Countries of Concern

By: Olga Torres, Managing Member Derrick Kyle, Senior Associate
Date: 10/31/2023

On October 17, 2023, the U.S. Department of Commerce Bureau of Industry & Security (“BIS”) released three rules amending the Export Administration Regulations (“EAR”) to strengthen export controls on advanced computing semiconductors and semiconductor manufacturing equipment to arms embargoed countries, including the People’s Republic of China (“China”), and to place certain additional entities in China on BIS’s Entity List. 

OFAC and BIS Announce Microsoft Settlement of Sanctions and Export Control Violations

By: Derrick Kyle, Senior Associate, Veronica Ochoa, Paralegal
Date: 04/25/2023

On April 6, 2023, the Department of Treasury Office of Foreign Assets Control (“OFAC”) and the Department of Commerce Bureau of Industry and Security (“BIS”) announced a settlement with Microsoft Corporation (“Microsoft”) and issued a combined $3.3 million in civil penalties to settle potential violations of sanctions and export control laws pertaining to Russia and other sanctioned jurisdictions. 

New U.S. Rules on Securing the Information and Communications Technology and Services Supply Chain Mean Increased Scrutiny of ICTS Transactions

By: Olga Torres, Managing Member & Matt Lapin, Of Counsel
Date: 04/08/2021

On January 19, 2021, the Department of Commerce (“Commerce”) published an interim final rule, “Securing the Information and Communications Technology and Services Supply Chain,” (“ICTS Rule”) implementing Executive Order 13873.

President Trump Adds Teeth to CFIUS Bite: Chinese Company Ordered to Divest Acquisition of U.S. Hotel-Software Company

By: Olga Torres, Managing Member & Maria Alonso, Associate
Date: 04/05/2020

The U.S. Department of the Treasury finalized the new Committee on Foreign Investment in the United States (“CFIUS”) regulations, which became effective on February 13, 2020.[1]

Amongst other matters, the new regulations significantly expand CFIUS’s jurisdiction for non-controlling investments, including the review of transactions involving U.S. businesses that manage or collect “sensitive personal data” of U.S. citizens.