Telecommunications and 'Information Security'
'Information security' systems, equipment and components therefor, as follows:
| Reference | Parameter | Threshold |
|---|---|---|
| 5A002.a.1 | symmetric algorithm key length | > 56 bits |
| 5A002.a.1 | asymmetric algorithm (factorisation, e.g. RSA) | > 512 bits |
| 5A002.a.1 | asymmetric algorithm (discrete log in Z/pZ, e.g. DH) | > 512 bits |
| 5A002.a.1 | asymmetric algorithm (discrete log in other group, e.g. ECDH) | > 112 bits |
| 5A002.a.2 | symmetric algorithm key length | > 56 bits |
| 5A002.a.2 | asymmetric algorithm (factorisation) | > 512 bits |
| 5A002.a.2 | asymmetric algorithm (elliptic curve) | > 112 bits |
| 5A002.a.3 | symmetric algorithm key length | > 56 bits |
| 5A002.a.3 | asymmetric algorithm (factorisation) | > 512 bits |
| 5A002.a.3 | asymmetric algorithm (elliptic curve) | > 112 bits |
| 5A002.d.1 | A bandwidth | > 500 MHz |
5A002.aSystems, equipment, application specific 'electronic assemblies', modules and integrated circuits for 'information security', as follows, and other specially designed components therefor: Designed or modified to use 'cryptography for data confidentiality' having a 'described security algorithm', where that cryptographic capability is usable, has been activated, or can be activated by any means other than secure 'cryptographic activation':
5A002.a.1Items having 'information security' as a primary function
5A002.a.2Digital communication or networking systems, equipment or components, not controlled by 5A002.a.1
5A002.a.3Computers, other items having information storage or processing as a primary function, and components therefor, not controlled by 5A002.a.1 or 5A002.a.2
5A002.a.4Items, not controlled by 5A002.a.1 to 5A002.a.3, where the 'cryptography for data confidentiality' supports a non-primary function of the item and is performed by incorporated equipment or 'software' that would, as a stand-alone item, be controlled by Category 5 Part 2
5A002.bDesigned or modified to perform cryptanalytic functions
5A002.cNon-cryptographic 'information security' systems and equipment designed or modified to use quantum cryptography
5A002.dDesigned or modified to use quantum computing techniques for breaking or weakening cryptographic algorithms or their key management
5A002.a.1Items having "information security" as a primary function;
5A002.a.2Digital communication or networking systems, equipment or components, not specified in 5A002.a.1.;
5A002.a.3Computers, other items having information storage or processing as a primary function, and components therefor, not specified in 5A002.a.1. or 5A002.a.2.;
5A002.a.4Items, not specified in 5A002.a.1. to 5A002.a.3., where the ‘cryptography for data confidentiality’ having a ‘described security algorithm’ meets all of the following: a. It supports a non-primary function of the item; and b. It is performed by incorporated equipment or "software" that would, as a standalone item, be specified in Category 5, Part 2.
5A002.d.1A bandwidth exceeding 500 MHz; or
5A002.d.2A "fractional bandwidth" of 20 % or more;
5A002.eDesigned or modified to use cryptographic techniques to generate the spreading code for "spread spectrum" systems, other than those specified in 5A002.d., including the hopping code for "frequency hopping" systems.
Decontrol note
Note 3 (Note Crypto) - la plupart des produits grand public (smartphones, navigateurs, OS) sont decontroles si la cryptographie ne peut pas etre facilement modifiee par l'utilisateur. Reglement UE 2021/821, Note 3, Cat. 5 Partie 2.
General Technology Note (GTN)
The export of 'technology' which is 'required' for the 'development', 'production' or 'use' of items controlled in Categories 0 to 9 is controlled according to the provisions in each Category. 'Techno...
General Software Note (GSN)
The Lists do not control 'software' which is either: 1. Generally available to the public by being: a. Sold from stock at retail selling points, without restriction, by means of: (1) Over-the-counter ...
Note 2 to Category 5 Part 2 - Personal Use Exception
Category 5 Part 2 does not control items when accompanying their user for the user's personal use.
Note 3 to Category 5 Part 2 - Cryptography Note (Mass-Market Exception)
Category 5 Part 2 does not control items meeting all of the following: a. Generally available to the public by being sold, without restriction, from stock at retail selling points by means of any of t...
Note 4 to Category 5 Part 2 - Ancillary Cryptography Exception
Category 5 Part 2 does not control items where the 'information security' functionality is limited to providing any of the following: a. 'Personalisation' which is limited to what is necessary for the...