Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesThe Linux Foundation’s 15 July 2021 update described a narrower U.S. export-control notification requirement for certain publicly available encryption software: under its account, email notifications were required for software implementing “non-standard cryptography,” rather than for all software in the relevant classification. That was a dated explanation of a change to the Export Administration Regulations (EAR), not a complete statement of current U.S. law. Open-source status alone does not resolve every export-control or sanctions question.
What changed in the 2021 update?
The Linux Foundation said its 15 July 2021 update reflected a change to the EAR’s treatment of publicly available encryption software classified under ECCN 5D002. In the Foundation’s account, the earlier notification treatment applied whether or not the cryptography was standardized; after the change, email notifications were required only for software implementing “non-standard cryptography.”
This describes the Foundation’s summary of the 2021 change. It should not be read as a current, project-specific classification or legal determination. Whether a particular item is subject to the EAR, how it is classified, and what obligations apply depend on the facts and the rules in force.
When does open-source material count as “published” in the Foundation’s explanation?
The Linux Foundation’s expanded guidance describes the EAR as applying to items “subject to the EAR.” It explains that exports can include making software electronically available to people outside the United States, as well as certain releases of technology within the United States.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
In that guidance, the key condition for the published treatment is public availability without restrictions on further dissemination. The Foundation lists publicly available software, specifications, hardware design files, and binaries as examples of material that may qualify. The practical point is that the label “open source” by itself is not the test in the Foundation’s explanation: the way the material is made available and any limits on further dissemination matter.
This is the Foundation’s explanation of the EAR, not regulatory text or legal advice. For an actual release, confirm the current rules and the facts of the distribution rather than assuming that a public repository settles the issue.
How does encryption affect an open-source release?
The Foundation’s expanded guidance says that, as of 2021, projects using standard cryptography had no additional requirements or analysis under the provision it discusses. It says projects using non-standard cryptography classified under ECCN 5D002 might still need to send an email notification. These are statements about the Foundation’s account of that provision and period; classification and requirements should be checked for the specific software and current rules.
For projects distributing encryption software, the Foundation recommends several operational practices:
Rank #3
- Used Book in Good Condition
- Identify a responsible legal entity and contact where applicable.
- Retain evidence that any required notice was delivered, and make delivered notices publicly available where appropriate.
- Keep source code publicly available when distributing encryption software in object-code form, consistent with the conditions described in its guidance.
- Use source-code scanning tools as an aid to identifying cryptographic code, not as proof that all relevant code has been found; the Foundation cautions that automated scanning is imperfect.
The Foundation also recommends keeping technical discussions, decisions, and outcomes public when feasible. A private exchange may not satisfy the public-availability condition described in its overview. For security disclosures, it suggests considering public release after a fix is available rather than keeping the information permanently within a confidential list.
Does a project’s public release cover downstream redistributors?
Not necessarily. The Foundation’s guidance addresses the open-source project itself and says downstream redistributors must assess their own circumstances. A party that modifies code or distributes a derived product whose source is not publicly available cannot assume that the upstream project’s public source release answers its EAR compliance questions.
That distinction is especially important when a downstream product adds restrictions, changes the software, or is distributed in a form that is not accompanied by publicly available source. The applicable analysis depends on the downstream party’s item and distribution, not just the upstream project’s publication history.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Are OFAC sanctions the same as EAR export controls?
No. Export controls under the EAR and sanctions administered by the Office of Foreign Assets Control (OFAC) are separate regimes. The Linux Foundation’s 29 January 2025 discussion warns that sanctions may apply to transactions or interactions even when software or technology is publicly available. It also says the application of sanctions to open-source and standards activity is not fully defined.
Best Value
Accordingly, the Foundation’s 2021 description of the published treatment under the EAR does not, by itself, resolve whether an interaction is permitted under OFAC rules. Sanctions questions may require attention to the people, entities, locations, and transaction involved, as well as current restrictions and lists.
What is the scope of the 2021 guidance?
The 2021 update is best read as a historical explanation of a particular notification change, paired with the Foundation’s broader account of public availability and project practices. It is not a complete compliance decision tree, nor does it establish that every open-source release or encryption implementation is outside U.S. export controls.
The expanded guidance also flags a 2020 addition concerning certain neural-network-driven geospatial analysis training and says publicly available software in that category may receive the published treatment. The Foundation’s discussion is not enough to determine how a particular project or release is treated under current rules.
Before acting on a release, verify the applicable current EAR and BIS guidance, and separately review relevant OFAC regulations and sanctions lists. The Foundation’s articles can explain the issues to examine, but they cannot substitute for a current review of the specific software, distribution, and parties involved.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




