ultimate-guide
EAR Export Control: A Step-by-Step Compliance Guide
Table of Contents
- What You Need to Know About EAR Export Control Regulations
- Understanding ECCN Classification in the Export Control Process
- Step 1: Determine Your Product's Classification Status
- Step 2: Build Your EAR Compliance Checklist for Defense Contractors
- Step 3: Establish Export Control Recordkeeping Requirements
- Step 4: Execute Your Internal Audit Workflow
- Common Mistakes to Avoid in EAR Export Control
- Frequently Asked Questions
Last Updated: September 3, 2026
What You Need to Know About EAR Export Control Regulations
The Export Administration Regulations (EAR) govern the export of commercial items, technical data, and software with potential military applications. Organizations in defense, aerospace, and advanced manufacturing must understand these rules to avoid civil penalties, criminal enforcement, and reputational damage.
EAR export control applies to any transfer of controlled technology, physical shipment, electronic transmission, or in-person technical assistance, to foreign nationals or destinations outside the United States. The regulations enforce national security and foreign policy objectives by requiring licenses for dual-use items, encryption technology, and advanced manufacturing processes.
Many organizations underestimate EAR's scope. The regulations don't only apply to weapons or military hardware. A software repository, a technical training session with an international partner, or a design specification shared with an overseas subsidiary can trigger licensing requirements. "Deemed export" scenarios, where technical data is shared with foreign nationals in the U.S., create the greatest legal exposure and are where most compliance programs fail.
At DIAGRAM8, we work with defense contractors and multinational manufacturers to translate dense regulatory language into executable compliance workflows. The difference between reactive and proactive approaches comes down to three things: understanding your product's classification status, building audit-ready documentation, and establishing internal controls that catch problems before they reach your legal team.
This guide walks through the four-step process for establishing EAR export control compliance at your organization, with practical checklists and documentation standards regulators expect during audits.
Understanding ECCN Classification in the Export Control Process
Every item subject to EAR control must be assigned an Export Control Classification Number (ECCN). This 5-character code, consisting of a category (0-9) and product group (A-E), determines whether your product requires a license, qualifies for a license exception, or can be shipped freely.
Understanding ECCN classification is foundational to EAR compliance because misclassification is one of the most common violations. A product classified as EAR99 (uncontrolled) when it should be ECCN 3A001 creates immediate legal liability. The Commerce Control List (CCL) is the authoritative source, but the language is technical and often ambiguous. Many organizations rely on commodity jurisdiction requests to the Bureau of Industry and Security (BIS) when internal classification efforts yield uncertainty.
The ECCN process also determines which countries and end-users are off-limits. Some ECCNs carry destination restrictions; others prohibit sales to sanctioned entities or denied persons. This is where end-user verification becomes critical.
Step 1: Determine Your Product's Classification Status
Start with a clear inventory of what you're exporting: tangible products, technical data (drawings, specifications, source code), and software. For each item, determine whether it falls under EAR control and what ECCN applies.
Identifying dual-use items
A dual-use item is a commercial product with potential military application. Most items in defense and aerospace supply chains are dual-use by definition. A semiconductor used in consumer electronics can power military radar systems. A precision machining tool can produce civilian components or weapons-grade parts. The CCL controls items based on technical specifications, not intent.
Review your product's technical performance parameters. Does your item exceed the performance thresholds listed on the CCL? If you manufacture integrated circuits with processing speed above 5 GHz, you may trigger ECCN controls. If your composite material exceeds certain tensile strength specifications, it may be subject to export licensing.
Many organizations miss dual-use controls by assuming their product is "commercial" and therefore uncontrolled. A software encryption algorithm with a key length above a certain threshold is controlled even if sold commercially. A drone with specific range and payload capabilities is controlled regardless of civilian marketing. The CCL doesn't care about intent, only technical specifications.
Reviewing the Commerce Control List
The CCL is organized by product category and includes detailed technical parameters for each controlled item. Reviewing it is not optional, it's the legal foundation for your classification decision.
Identify which CCL categories apply to your products. If you manufacture aerospace components, focus on Category 7. If you produce telecommunications equipment, start with Category 3. Within each category, cross-reference your product's technical specifications against the performance thresholds listed for each ECCN.
Document this review process. Create a classification worksheet for each product line showing which CCL entries were reviewed, what technical specifications were compared, and what classification decision was reached. This documentation becomes your defense if regulators challenge your classification.
| Step | Action | Documentation Required |
|---|---|---|
| 1 | Identify product technical specs | Product datasheet, performance parameters |
| 2 | Cross-reference CCL categories | CCL review notes, threshold comparison |
| 3 | Determine ECCN or EAR99 status | Classification worksheet, decision rationale |
| 4 | Document classification decision | Signed classification memo, CCL evidence |
Step 2: Build Your EAR Compliance Checklist for Defense Contractors
Once you've classified your products, screen transactions before they proceed. This is where most compliance breaches occur, not because organizations don't understand the rules, but because they lack systematic controls to apply them consistently.
An EAR compliance checklist for defense contractors should cover four core elements: customer screening, end-user verification, license determination, and transaction documentation.
Screening against denied persons lists
Before accepting any order, screen the customer against the Denied Persons List (DPL), the Entity List, and the Unverified List maintained by BIS. These lists identify individuals and organizations prohibited from receiving exports or whose export eligibility is uncertain.
Many organizations screen only the customer name, missing variations, aliases, or related entities. A customer listed as "Acme Manufacturing LLC" may appear clean, but the beneficial owner or parent company may be on the Entity List under a different name. Effective screening requires checking multiple name variations, corporate family relationships, and geographic indicators.
Automated screening tools reduce manual error but require human oversight. A tool might flag a match based on partial name similarity that's a false positive, or miss a match if the customer uses a transliterated name.
Document every screening result: the date, the lists checked, the customer name variations searched, and the results. If a customer is flagged, document the review process that cleared them or the decision to decline the transaction. This documentation is essential during audits.
Verifying end-user credentials
End-user verification confirms that the customer is who they claim to be, has a legitimate need for the product, and will use it for the stated purpose.
For controlled items, end-user verification typically requires an end-use statement describing the intended application, the end-user's business, and certifications that the product will not be diverted to prohibited uses or destinations. For some ECCN classifications, you may also need to verify the customer's business credentials, facility information, and technical capability.
A simple email from a customer stating intended use is insufficient. You need documentary evidence: business registration records, facility certifications, technical specifications showing the customer can use the product, and sometimes third-party verification.
The verification process also includes assessing diversion risk. Is the customer in a region where gray-market exports are common? Does the customer's stated end-use align with their industry and facility capabilities? Has the customer requested unusual quantities or specifications suggesting potential diversion? These red flags trigger additional due diligence.
Step 3: Establish Export Control Recordkeeping Requirements
Recordkeeping is where many organizations fail audits. Regulators want documented evidence that your compliance program was executed consistently across every transaction.
Documentation standards under 15 CFR Part 762
The Code of Federal Regulations (15 CFR Part 762) specifies the records you must maintain for exports subject to EAR control. These records must be kept for a minimum of five years and must be available for inspection by BIS.
Required records include:
- Purchase orders and invoices showing customer, product description, quantity, and value
- Classification documents showing the ECCN or EAR99 determination
- License applications and license documents (if required)
- Denied persons list screening results
- End-user statements and verification documents
- Shipping documents showing destination and carrier
- Technical data transfer records (if applicable)
- Internal compliance approvals and authorizations
The regulations don't specify a particular format. Records can be maintained in paper or electronic form, as long as they're organized, retrievable, and complete. Many organizations use document management systems, but spreadsheets or filing systems work if documentation is systematic.
A common mistake is maintaining records in isolated systems. The customer file is in the CRM; the classification decision is in email; shipping documents are in logistics; compliance approval is in a separate folder. When an auditor requests records for a specific transaction, you're scrambling to assemble documents from multiple sources, and something is inevitably missing.
Creating audit-ready records
Audit-ready records are organized, complete, and traceable. They show a clear chain of decision-making from initial customer inquiry through final shipment, including evidence supporting each decision and approvals authorizing the transaction.
Create a transaction checklist for every export documenting each compliance step: customer identification, denied persons screening, classification review, license determination, end-user verification, and final approval. Attach supporting documents to this checklist and file the entire package together.
For each transaction, create a summary document showing:
- Customer name, location, and business description
- Product description and ECCN classification
- Quantity, value, and intended use
- Denied persons screening results and date
- License requirement determination and license number (if applicable)
- End-user verification documents
- Shipping details and carrier information
- Compliance approval signature and date
This summary becomes your audit trail. If a regulator asks about a specific transaction years later, you can retrieve the summary and supporting documents immediately.
Step 4: Execute Your Internal Audit Workflow
An internal audit identifies and corrects compliance problems before regulators do. It's the most effective way to strengthen your compliance culture and demonstrate that your organization takes EAR export control seriously.

A comprehensive internal audit workflow includes four phases: planning, document review, transaction testing, and remediation.
Planning phase: Define your audit scope. Will you review all transactions from the past three years, or focus on a specific product line or customer segment? Document the audit objectives and evaluation criteria.
Document review: Assess whether your compliance policies are current, comprehensive, and aligned with regulatory requirements. Review classification determinations for CCL analysis support. Examine denied persons screening procedures for consistency and documentation. Check recordkeeping practices against 15 CFR Part 762 requirements.
Transaction testing: Select a sample of transactions and verify that the compliance process was followed correctly. For each transaction, confirm denied persons screening was conducted, the product was correctly classified, the appropriate license was obtained (if required), and required documentation was maintained. Transaction testing often reveals gaps: a customer was screened but results weren't documented, a classification decision wasn't recorded, or shipping documents are missing.
Remediation: Document deficiencies and create a corrective action plan. For minor issues like missing documentation, locate the missing records or recreate them with supporting evidence. For systemic issues like inadequate procedures or training gaps, implement process improvements and retrain personnel.
Common Mistakes to Avoid in EAR Export Control
Organizations typically make the same compliance errors repeatedly. Understanding these mistakes helps you build a program that avoids them.
Misclassifying products as EAR99 when they're actually controlled. Many assume commercial products are uncontrolled. This is incorrect. Always review the CCL before concluding a product is EAR99. If uncertain, request a commodity jurisdiction determination from BIS.
Failing to screen customers before accepting orders. This is the most common violation. An organization receives a purchase order, focuses on fulfilling it quickly, and defers compliance screening or skips it entirely. Screen every customer against denied persons lists before accepting the order.
Inadequate end-user verification for controlled items. A customer's statement about legitimate use is insufficient. Require documentary evidence: business registration, facility information, technical specifications, and sometimes third-party verification.
Failing to document classification decisions. Many classify products informally, a conversation or email later deleted. If regulators question your classification, you have no documented evidence of your reasoning. Always create a classification worksheet showing which CCL entries were reviewed, what specifications were compared, and what decision was reached.
Inadequate recordkeeping. Records scattered across multiple systems, incomplete transaction files, and missing supporting documents are red flags during audits. Implement systematic recordkeeping ensuring every transaction has a complete file with all required documentation.
Insufficient staff training. Compliance depends on people understanding rules and applying them consistently. Conduct annual training for all personnel involved in export decisions, and provide targeted training when procedures change.
Failing to monitor regulatory changes. The CCL is updated regularly. Items uncontrolled last year may be controlled this year. Subscribe to BIS updates and review changes quarterly.
Compliance with EAR export control regulations requires systematic process discipline, not just good intentions. Organizations that succeed build compliance into standard operating procedures, maintain audit-ready documentation, and treat compliance as a shared responsibility across sales, engineering, legal, and operations.
DIAGRAM8 helps defense contractors and multinational manufacturers establish this discipline through institutional governance frameworks and multi-jurisdictional compliance integration. Our audit-grade execution approach ensures your compliance program withstands regulatory scrutiny and protects your organization from civil penalties, criminal enforcement, and reputational damage that follow violations. Request a formal introduction to DIAGRAM8 to discuss how we can strengthen your export control compliance infrastructure.
Frequently Asked Questions
What is the 50% rule in EAR export control?
The 50% rule determines whether a product containing controlled components requires an export license. If a controlled item makes up 50% or more of the total value of a product, the entire product may be subject to EAR export control restrictions. This applies to dual-use items and affects classification decisions. Understanding this threshold is critical when assembling products with multiple components sourced from different suppliers, as it directly impacts licensing requirements and compliance obligations.
How do I determine the correct ECCN classification for my product?
Start by reviewing the Commerce Control List to identify whether your item matches any listed categories. If it does not appear on the list, it receives EAR99 classification. For items that may match, consult the technical specifications against each ECCN definition. Consider the product's intended use, technical capabilities, and end-user application. If classification remains unclear, request a commodity jurisdiction determination from the appropriate authority. Document your classification rationale for audit purposes, as regulators expect written evidence of your decision-making process.
What recordkeeping requirements apply under Part 762 of the Export Administration Regulations?
Part 762 mandates that you maintain records of all export transactions, including purchase orders, invoices, shipping documents, and end-user certifications, for a minimum of five years. Records must be organized, retrievable, and available for inspection. Include documentation of your classification decisions, license applications, denied persons list screening results, and any deemed export determinations. Electronic storage is acceptable provided records remain legible and tamper-proof. Audit-grade execution requires indexing systems that allow rapid retrieval during compliance reviews or regulatory inquiries.
What is a deemed export under EAR regulations?
A deemed export occurs when controlled technical data or source code is disclosed to a foreign national within your organization or facility, even if no physical shipment crosses borders. This transfer of information is treated as an export subject to licensing requirements. Deemed exports apply to software source code, technical specifications, manufacturing processes, and training materials. Your compliance program must identify foreign nationals with access to controlled information and document whether licenses or license exceptions apply to those disclosures. Failure to recognize deemed exports is a common violation.
Frequently Asked Questions
What is the 50% rule in EAR export control?
The 50% rule determines whether a product containing controlled components requires an export license. If a controlled item makes up 50% or more of the total value of a product, the entire product may be subject to EAR export control restrictions. This applies to dual-use items and affects classification decisions. Understanding this threshold is critical when assembling products with multiple components sourced from different suppliers, as it directly impacts licensing requirements and compliance obligations.
How do I determine the correct ECCN classification for my product?
Start by reviewing the Commerce Control List to identify whether your item matches any listed categories. If it does not appear on the list, it receives EAR99 classification. For items that may match, consult the technical specifications against each ECCN definition. Consider the product's intended use, technical capabilities, and end-user application. If classification remains unclear, request a commodity jurisdiction determination from the appropriate authority. Document your classification rationale for audit purposes, as regulators expect written evidence of your decision-making process.
What recordkeeping requirements apply under Part 762 of the Export Administration Regulations?
Part 762 mandates that you maintain records of all export transactions, including purchase orders, invoices, shipping documents, and end-user certifications, for a minimum of five years. Records must be organized, retrievable, and available for inspection. Include documentation of your classification decisions, license applications, denied persons list screening results, and any deemed export determinations. Electronic storage is acceptable provided records remain legible and tamper-proof. Audit-grade execution requires indexing systems that allow rapid retrieval during compliance reviews or regulatory inquiries.
What is a deemed export under EAR regulations?
A deemed export occurs when controlled technical data or source code is disclosed to a foreign national within your organization or facility, even if no physical shipment crosses borders. This transfer of information is treated as an export subject to licensing requirements. Deemed exports apply to software source code, technical specifications, manufacturing processes, and training materials. Your compliance program must identify foreign nationals with access to controlled information and document whether licenses or license exceptions apply to those disclosures. Failure to recognize deemed exports is a common violation.