5A002.a

2025-01-15

ECCN 5A002.a controls information security systems, equipment, and components employing cryptography exceeding specified parameters. Export licensing depends on the encryption's function, key length, and end-use under 15 CFR § 774, Supp. 1.

Category 5 — Telecommunications and Information Security — A. Systems, Equipment and Components

Reasons for Control

NS1AT1EI

Regulatory Citation

15 CFR § 774, Supp. 1, ECCN 5A002

Licensing Policy

License required for exports to Country Group E:1 and E:2 for AT and EI reasons. For most destinations, License Exception ENC (§ 740.17) is the primary vehicle for mass-market and commercial encryption products following a one-time classification review (CCATS) by BIS. Items not eligible for ENC require individual licenses on a case-by-case basis.

Controlled Technical Parameters

Technical Parameters

Parameter NameControlled ThresholdUnitRegulatory Note
Symmetric Key Length> 56 bitsbits (excluding parity)AES-128, AES-256, ChaCha20, and virtually all modern symmetric ciphers exceed the 56-bit threshold. DES (56-bit effective key) is at the exact threshold boundary.
Asymmetric Key Length (Factorization)> 512 bitsbitsRSA-1024, RSA-2048, RSA-4096 all exceed the 512-bit threshold. RSA-512 is at the boundary but is cryptographically broken and rarely used.
Elliptic Curve Key Length> 112 bitsbitsNIST P-256 (128-bit security), P-384 (192-bit), and Curve25519 (128-bit) all exceed the threshold. This parameter captures modern ECC implementations used in TLS 1.3, Signal Protocol, and WireGuard.

Interactive License Determination Sandbox

Interactive License Determination Sandbox

Select Destination...
Military End-Use / Military End-User (§ 744.21)
%

AWAITING DESTINATION

Select a destination country above to perform a real-time export license determination against ECCN 5A002.

License Exception Matrix

License Exceptions Matrix

Exception CodeFull NameKey ConditionsCFR Reference
ENCEncryption Commodities, Software, and TechnologyPrimary exception for mass-market encryption items. Requires submission of a classification request (CCATS) or self-classification notification to BIS and the ENC Encryption Request Coordinator. Not available for E:1/E:2 destinations. Separate provisions for § 740.17(b)(1) mass-market products and § 740.17(b)(2) non-mass-market products.15 CFR § 740.17
TSUTechnology and Software — UnrestrictedAvailable for publicly available encryption source code (e.g., open-source software) per § 740.13(e), subject to notification to BIS and the ENC Encryption Request Coordinator. Applied to products like OpenSSL and Linux kernel cryptographic modules.15 CFR § 740.13
GOVGovernments and International OrganizationsAvailable for exports of encryption items to U.S. government agencies abroad and to NATO and allied government entities.15 CFR § 740.11
STAStrategic Trade AuthorizationAvailable for exports to the 36 STA-eligible destinations (§ 740.20(c)(1)) for NS-controlled 5A002 items following classification review.15 CFR § 740.20

Enforcement Case Studies

Enforcement Case Studies

BIS Settlement — ZTE Corporation

3/6/2017ZTE Corporation$1.19 Billion (Combined Criminal/Civil); BIS Monitor Installed

ZTE agreed to the largest export control penalty in BIS history for a scheme to export U.S.-origin encryption-enabled telecommunications equipment (including items classified under 5A002 and related ECCNs) to Iran and North Korea through a network of shell companies. The scheme included systematic falsification of end-user certificates and deletion of internal compliance records.

View Official Record

United States v. Noshir Gowadia

1/23/2011Noshir Gowadia32 Years Imprisonment

Former Northrop Grumman engineer convicted of communicating classified and export-controlled information, including encrypted communications technology, to the PRC. While primarily an ITAR case, the prosecution also established EAR violations for commercial encryption components that Gowadia had obtained and transferred without required licenses.

View Official Record

Frequently Asked Questions

Frequently Asked Questions

Is my commercial VPN appliance or firewall controlled under ECCN 5A002?
Very likely yes, if it uses encryption exceeding the technical thresholds — which virtually all modern commercial security products do (AES-128/256, RSA-2048, etc.). However, most commercial network security products qualify for License Exception ENC (§ 740.17) following a one-time classification review (CCATS request) submitted to BIS. Mass-market encryption products like consumer-grade routers and VPN appliances typically qualify for self-classification under § 740.17(b)(1) with only a notification to BIS, not a full review. The ENC exception makes 5A002 one of the most commonly used ECCNs in commercial technology exports.
Do I need to submit an encryption review to BIS for open-source software?
Publicly available open-source software employing encryption is eligible for License Exception TSU under § 740.13(e), which requires a notification (not a review) to BIS and the ENC Encryption Request Coordinator. The notification must include the Internet URL where the source code is available. This provision is used for projects like OpenSSL, Linux kernel crypto modules, GnuPG, and similar open-source cryptographic software. Note that object code (compiled binaries) of open-source encryption software may require separate classification if distributed commercially.
What is the difference between ECCN 5A002 and ECCN 5A992?
ECCN 5A002 covers encryption items that are controlled for National Security (NS) and Encryption Items (EI) reasons. ECCN 5A992 covers 'mass market' encryption commodities and other information security equipment not meeting the 5A002 technical thresholds, or items that have received a mass-market classification from BIS. Items classified as 5A992 generally have fewer restrictions and broader license exception availability. A product initially classified as 5A002 can be reclassified to 5A992 after BIS conducts a mass-market review and determines the product qualifies under the 'mass market' provisions of Note 4 to Cat. 5, Part 2.
Are cloud-based encryption services (e.g., AWS KMS, Azure Key Vault) subject to 5A002?
Cloud-based encryption key management services involve complex EAR analysis. The encryption software and hardware physically located in U.S. data centers is not 'exported' when accessed remotely. However, providing access to encryption capabilities to foreign persons may constitute a 'deemed export' of technology under § 734.2(b). Additionally, if the cloud service generates or stores encryption keys in data centers outside the U.S., the keys and the cryptographic functionality may be subject to export controls. Most major cloud providers have obtained CCATS classifications and operate under License Exception ENC provisions.

Need a binding classification? Request an expert consultation below.

Binding Classification Consultation

Connect with our export compliance engineers for a definitive ECCN determination. Secure, defense-grade analysis for your technical parameters.

Regulatory Disclaimer

REGULATORY DISCLAIMER: This tool provides informational guidance only and does not constitute legal advice. Consult the Bureau of Industry and Security (BIS) or qualified export-control counsel for binding classification determinations. 15 CFR § 774; 50 U.S.C. § 4801 et seq.