Cryptographic software and dual-use items: export control procedures in France
Key Takeaways
The European regime governing exports of dual-use items is separate from the French regime governing cryptographic means. The same export transaction involving cryptographic means may therefore be subject to formalities both with ANSSI and with the French dual-use Goods Department (Service des biens à double usage – SBDU).
The export of software incorporating cryptographic functions may fall under two separate regulatory regimes: the French cryptology regime, governed by the Law for Confidence in the Digital Economy (Loi pour la confiance dans l’économie numérique – LCEN), which may require a declaration or an application for authorization to ANSSI depending on the circumstances; and the Regulation of May 20, 2021 on dual-use items, which subjects certain software and technologies to export controls. (1) These regimes pursue different objectives but may both apply to the same transaction.
A previous article addressed the formalities required by ANSSI. This article explains the dual-use regime applicable to cryptographic software, including its classification and the export authorizations that may be required.
1. When would cryptographic software be classified as a dual-use item?
The European Regulation of 20 May, 2021 defines dual-use items as “items, including software and technology, which can be used for both civil and military purposes, and includes items which can be used for the design, development, production or use of nuclear, chemical or biological weapons or their means of delivery, including all items which can be used for both non-explosive uses and assisting in any way in the manufacture of nuclear weapons or other nuclear explosive devices.”
Dual-use items subject to controls are primarily listed in Annex I to the Regulation. This list is updated at least once a year to reflect changes in international export control regimes. The most recent update to Annex I dates from September 8, 2025. (2) However, certain items not listed in that Annex may also be subject to authorization in the circumstances provided for in articles 4, 5, 9 and 10 of the Regulation.
1.1 Information security software
Cryptographic software is assessed under Category 5, Part 2 “Information Security” of Annex I to the Regulation. Classification depends on technical criteria, including cryptographic functions, algorithms used, key lengths, the purpose of those functions, and the applicable notes. Certain software may fall under entry 5D002.
The mere fact that software incorporates cryptographic algorithms therefore does not automatically mean that it qualifies as a controlled dual-use item.
1.2 Notes excluding certain items from control
Annex I contains several technical notes that exclude certain items from control where the relevant conditions are met (commonly referred to as “decontrol”).
Category 5, Part 2 includes a “Cryptography Note” that may exclude certain software from the scope of entry 5D002, depending in particular on its market availability, the way it is marketed, whether the user can modify its cryptographic functionality, and the conditions under which it can be installed.
The Cryptography Note must be distinguished from the “mass-market” classification used under the French cryptology regime. Although the two mechanisms share certain similarities, they fall under separate regulatory frameworks: the LCEN for cryptographic means classified as mass-market products, and the Regulation of May 20, 2021 for European dual-use export controls.
1.3 The specific case of cryptanalysis software
Software designed or modified to perform or simulate cryptanalytic functions may fall under entry 5D002. Certain references relating to cryptanalysis also appear in Annex IV, which covers particularly sensitive items. Transfers of such items between EU Member States are therefore subject to authorization.
Consequently, while software listed only in Annex I is, in principle, subject to authorization when exported outside the European Union, software falling under both Annexes I and IV may also require authorization when transferred between EU Member States.
2. How Is the software classification determined?
The company contemplating the export is primarily responsible for determining the software’s classification based on the then current version of Annex I and its definitions, entries, and technical notes.
2.1 Criteria to be taken into account
For cryptographic software, the analysis should include, in particular:
· the version of the software being exported, its encryption functions, and their purpose (authentication, integrity, confidentiality, signature);
· the algorithms used and, where applicable, key lengths;
· whether the cryptographic functions are primary or ancillary and which functionalities are accessible to or can be activated by the user;
· any notes that may exclude the software from control; and
· the possible presence of cryptanalysis functions.
This analysis should be repeated if the software’s functionalities or cryptographic mechanisms evolve, where a new major version of the software is released, or when the European list of controlled items is updated.
2.2 Items not listed in Annex I may still be subject to control
The fact that an item is not classified under Annex I does not always mean that it is free from controls. The Regulation provides for several mechanisms applicable to items not listed in Annex I.
Articles 4 and 5 establish, in particular, mechanisms commonly referred to as “catch-all” controls. Article 4 covers certain uses connected with chemical, biological or nuclear weapons, certain military end uses in a country subject to an arms embargo, or incorporation into certain military equipment that has been unlawfully exported. Article 5 concerns certain cyber-surveillance items that may be intended for use in connection with internal repression or the commission of serious and systematic violations of human rights or international humanitarian law.
2.3 Where there is doubt about the software classification: the non-license application
Where a technical analysis has been carried out but uncertainty remains as to the software’s classification or the applicable entry, a non-license application (demande hors licence or DHL), may be submitted to the SBDU through the Egide portal. Accompanied by a description of the product, this application may be used, in particular, to obtain the administration’s opinion on its classification under Annex I or to ask whether one of the “catch-all” provisions may apply.
The opinion issued by the SBDU provides certainty as to the classification of the item vis-à-vis the French and European customs authorities.
3. When is an export required?
The applicable regime depends first on the type of software and the contemplated transaction.
3.1 Exports outside the European Union
Where software is listed in Annex I, its export outside the European Union is, in principle, subject to authorization. It should be noted that the control is not limited to the physical shipment of storage media. It may also apply to the electronic transmission or the provision of software or technology when the conditions for an export as defined by the Regulation are met.
3.2 Transfers within the European Union
Items listed only in Annex I may circulate within the European Union without an export authorization.
As an exception, an authorization is required for certain particularly sensitive items listed in Annex IV, including certain categories relating to cryptanalysis.
3.3 Different types of exports
Article 12 identifies four categories of export authorizations depending on the contemplated transactions: individual export authorizations, global export authorizations, national general export authorizations, and Union general export authorizations.
The first two are reviewed by the SBDU. Global export authorizations are intended for regular exporters and generally require an internal compliance program (ICP). For individual and global export authorizations, the Regulation sets a maximum validity period of two years unless otherwise determined by the competent authority.
General authorizations are based on a simplified procedure where their applicable conditions are met.
3.4 Summary table
|
Type of authorization |
Scope |
Procedure |
Validity / observations |
|
Individual export authorization |
One exporter; one or more items; one identified end-user or consignee in a third country |
Application to the SBDU through Egide; review of the application |
Maximum validity: 2 years; may cover multiple shipments |
|
Global export authorization |
One exporter; one category of items; several identified end-users and/or several third countries |
Application to the SBDU through Egide; internal compliance program (ICP) required where applicable |
Maximum validity: 2 years; semiannual reporting; recurring flows |
|
National general export authorization |
Transactions meeting the conditions of a general authorization established by France |
Application/registration with the SBDU; conditions specific to the authorization |
In France: 1 year, automatically renewable; semiannual reporting |
|
Union general export authorization |
Exports to certain destinations or for certain transactions defined in Annex II |
Simplified procedure with the SBDU; may be used only if all applicable conditions are met |
EU001 to EU008; no time limit while the conditions continue to be met; semiannual reporting |
The procedures are therefore not identical. Individual and global export authorizations require an application and review by the SBDU, while general authorizations operate under a simplified regime where the exporter and the transaction satisfy the applicable conditions. Processing times consequently depend on the type of authorization and, for individual or global authorizations, on the complexity and sensitivity of the application.
4. What checks should be carried out before export?
Before exporting any software incorporating cryptographic functions, several checks should be carried out in advance. In particular, the company should:
· identify the software’s cryptographic functions and determine whether it falls under an entry in Annex I to the Regulation (Category 5, Part 2, “Information Security”);
· review the applicable technical notes and the Cryptography Note, as well as the possible presence of cryptanalysis functions that could result in enhanced controls;
· determine the nature of the transaction and the destination—export outside the European Union or intra-EU transfer and, in the latter case, determine whether the software is listed in Annex IV;
· identify the consignee, end-user, and end use, and determine whether any “catch-all” provision, international sanctions, or restrictive measures may apply;
· determine the applicable authorization. Where there is uncertainty as to classification, a non-license application (DHL) may be submitted to the SBDU;
· check the applicable ANSSI formalities in parallel and factor administrative processing times into the handling of the matter.
Failure to comply with the regulations governing dual-use items may result in significant penalties.
Under article L.513-2 of the French customs code, the import or export without declaration of civil and military dual-use items subject to circulation restrictions under the Regulation of May 20, 2021 is punishable by five years’ imprisonment and a fine equal to three times the value of the goods involved in the offense.
An irregularity may also result in the suspension of the review of the application or of customs clearance procedures. For certain transactions involving dual-use items, customs officers have powers to detain the items concerned. These measures may result in delays and contractual or commercial consequences for the exporter. (3)
Dual-use controls should therefore not be treated as a mere customs formality to be addressed at the time of shipment. The regulatory classification of the software and the transaction should be carried out sufficiently early, ideally as part of the preparation for the product’s international distribution.
* * * * * * * * * * *
(1) Regulation (EU) 2021/821 of 20 May, 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items.
(2) Commission Delegated Regulation (EU) 2025/2003of 8 September, 2025 amending Regulation (EU) 2021/821 as regards the list of dual-use items. This Regulation became effective on November 15, 2025.
(3) Articles L.426-1 to L.426-9 of the French customs code.
Bénédicte DELEPORTE
Avocat
Deleporte Wentz Avocat
www.dwavocat.com
September 2026