Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Understanding U.S. Export Controls and Open-Source Projects: The 2021 Update

The Linux Foundation’s 2021 update focused on notifications for publicly available encryption software using non-standard cryptography. Its explanation also distinguishes public project releases from downstream distribution and separate OFAC sanctions questions.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Linux Foundation’s 15 July 2021 update described a narrower U.S. export-control notification requirement for certain publicly available encryption software: under its account, email notifications were required for software implementing “non-standard cryptography,” rather than for all software in the relevant classification. That was a dated explanation of a change to the Export Administration Regulations (EAR), not a complete statement of current U.S. law. Open-source status alone does not resolve every export-control or sanctions question.

What changed in the 2021 update?

The Linux Foundation said its 15 July 2021 update reflected a change to the EAR’s treatment of publicly available encryption software classified under ECCN 5D002. In the Foundation’s account, the earlier notification treatment applied whether or not the cryptography was standardized; after the change, email notifications were required only for software implementing “non-standard cryptography.”

This describes the Foundation’s summary of the 2021 change. It should not be read as a current, project-specific classification or legal determination. Whether a particular item is subject to the EAR, how it is classified, and what obligations apply depend on the facts and the rules in force.

When does open-source material count as “published” in the Foundation’s explanation?

The Linux Foundation’s expanded guidance describes the EAR as applying to items “subject to the EAR.” It explains that exports can include making software electronically available to people outside the United States, as well as certain releases of technology within the United States.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In that guidance, the key condition for the published treatment is public availability without restrictions on further dissemination. The Foundation lists publicly available software, specifications, hardware design files, and binaries as examples of material that may qualify. The practical point is that the label “open source” by itself is not the test in the Foundation’s explanation: the way the material is made available and any limits on further dissemination matter.

This is the Foundation’s explanation of the EAR, not regulatory text or legal advice. For an actual release, confirm the current rules and the facts of the distribution rather than assuming that a public repository settles the issue.

How does encryption affect an open-source release?

The Foundation’s expanded guidance says that, as of 2021, projects using standard cryptography had no additional requirements or analysis under the provision it discusses. It says projects using non-standard cryptography classified under ECCN 5D002 might still need to send an email notification. These are statements about the Foundation’s account of that provision and period; classification and requirements should be checked for the specific software and current rules.

For projects distributing encryption software, the Foundation recommends several operational practices:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Identify a responsible legal entity and contact where applicable.
  • Retain evidence that any required notice was delivered, and make delivered notices publicly available where appropriate.
  • Keep source code publicly available when distributing encryption software in object-code form, consistent with the conditions described in its guidance.
  • Use source-code scanning tools as an aid to identifying cryptographic code, not as proof that all relevant code has been found; the Foundation cautions that automated scanning is imperfect.

The Foundation also recommends keeping technical discussions, decisions, and outcomes public when feasible. A private exchange may not satisfy the public-availability condition described in its overview. For security disclosures, it suggests considering public release after a fix is available rather than keeping the information permanently within a confidential list.

Does a project’s public release cover downstream redistributors?

Not necessarily. The Foundation’s guidance addresses the open-source project itself and says downstream redistributors must assess their own circumstances. A party that modifies code or distributes a derived product whose source is not publicly available cannot assume that the upstream project’s public source release answers its EAR compliance questions.

That distinction is especially important when a downstream product adds restrictions, changes the software, or is distributed in a form that is not accompanied by publicly available source. The applicable analysis depends on the downstream party’s item and distribution, not just the upstream project’s publication history.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are OFAC sanctions the same as EAR export controls?

No. Export controls under the EAR and sanctions administered by the Office of Foreign Assets Control (OFAC) are separate regimes. The Linux Foundation’s 29 January 2025 discussion warns that sanctions may apply to transactions or interactions even when software or technology is publicly available. It also says the application of sanctions to open-source and standards activity is not fully defined.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Accordingly, the Foundation’s 2021 description of the published treatment under the EAR does not, by itself, resolve whether an interaction is permitted under OFAC rules. Sanctions questions may require attention to the people, entities, locations, and transaction involved, as well as current restrictions and lists.

What is the scope of the 2021 guidance?

The 2021 update is best read as a historical explanation of a particular notification change, paired with the Foundation’s broader account of public availability and project practices. It is not a complete compliance decision tree, nor does it establish that every open-source release or encryption implementation is outside U.S. export controls.

The expanded guidance also flags a 2020 addition concerning certain neural-network-driven geospatial analysis training and says publicly available software in that category may receive the published treatment. The Foundation’s discussion is not enough to determine how a particular project or release is treated under current rules.

Before acting on a release, verify the applicable current EAR and BIS guidance, and separately review relevant OFAC regulations and sanctions lists. The Foundation’s articles can explain the issues to examine, but they cannot substitute for a current review of the specific software, distribution, and parties involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.