Skip to content
OverviewTARIC NomenclatureClassification GuideBTIEU Classification RulingsCJEU Case Law - Tariff ClassificationMarket IntelligenceOrigin of GoodsExport ControlCBAM CalculatorEUDR CheckerClassifyAI SHCustoms ValueIncoterms® 2020
Overview

Tariff Classification

TARIC Nomenclature
Classification Guide
BTI
EU Classification Rulings
CJEU Case Law - Tariff Classification
Market Intelligence

Origin of Goods

Origin of Goods
Origin guides

Export control

Export Control

Environmental

CBAM Calculator
EUDR Checker

Tools

ClassifyAI SH/TARIC
Customs Value
Incoterms® 2020
ClassifyAI SH/TARIC

Automated tariff classification with GRI justification

Classify a product
Need help?

Ask a question about this code or find a tariff classification expert.

Ask a question
  1. The Trade Hub
  2. ...Customs Intelligence
  3. Export Control
  4. Guides
  5. Encryption Products
5A002

Encryption Product Classification

12 min readLast updated: March 2026

Table of Contents

  1. 1. Why encryption is controlled
  2. 2. Entry 5A002: thresholds and criteria
  3. 3. The Crypto Note (Note 3) explained
  4. 4. Decision tree for classification
  5. 5. Practical cases
  6. 6. Special case: software and technology
  7. 7. Notification obligations and documentation

Why encryption is controlled

Encryption has been at the heart of export controls since the 1990s. Cryptographic algorithms can protect civilian communications just as effectively as they secure military transmissions. This dual-use nature places products incorporating cryptography within the scope of Regulation (EU) 2021/821.

Category 5, Part 2 (Information Security) of Annex I specifically covers systems, equipment and components using cryptography. The main entry is 5A002 - information security systems - which defines the technical thresholds triggering control.

The Wassenaar Arrangement coordinates these controls among 42 participating states. The Crypto Note (Note 3 of Category 5, Part 2) is the central mechanism that determines whether a product qualifies for a mass-market exemption or remains controlled.

Entry 5A002: thresholds and criteria

Entry 5A002 controls systems, equipment and components designed or modified to provide information security using cryptography. The control criteria are:

  • •Symmetric key length exceeding 56 bits (excluding authentication)
  • •Asymmetric key length exceeding 512 bits for integer factorisation, 112 bits for elliptic curves
  • •Use of quantum cryptography

Important: just because a product uses AES-256 does not mean it is automatically controlled. The Crypto Note may exempt it if the mass-market decontrol criteria are met. The analysis must always follow the complete decision tree: first check whether the product falls within the scope of 5A002, then evaluate the decontrol notes.

The Crypto Note (Note 3) explained

Note 3 of Category 5, Part 2 (the Crypto Note) is the most widely used decontrol mechanism for mass-market encryption products. It exempts products from 5A002 control when all of the following conditions are met:

  1. 1.Generally available to the public by being sold without restriction from stock at retail selling points by means of over-the-counter transactions, mail-order transactions, electronic transactions, or telephone call transactions
  2. 2.The cryptographic functionality cannot be easily changed by the user
  3. 3.Designed to be installed by the user without further substantial support by the supplier
  4. 4.When necessary, details of the product are accessible and will be provided upon request to the competent authority

Critical point: all four criteria are cumulative. A product sold exclusively to businesses (B2B) with user-configurable cryptographic features does not qualify for decontrol, even if it uses standard algorithms.

Decision tree for classification

To correctly classify an encryption product, follow this systematic decision tree:

  1. 1.Does the product use cryptography? If not, it is not controlled under Cat. 5/2.
  2. 2.Is the cryptography used solely for authentication (password, digital signature, access control)? If yes, not controlled under 5A002 (but check other entries).
  3. 3.Does the product fall within the scope of 5A002 (key length thresholds exceeded)? If not, not controlled.
  4. 4.Does the product meet all four criteria of the Crypto Note? If yes, decontrolled (no licence required).
  5. 5.Does the product benefit from another decontrol note (Software Note, personal use)? If yes, decontrolled.
  6. 6.If no exemption applies, the product is controlled under 5A002. An export licence is required.

Keep documentary evidence of your analysis at each step. In the event of a customs inspection, this analysis justifies your decision.

Practical cases

Commercial VPN router (AES-256, IPsec): The router uses AES-256, which exceeds the 56-bit threshold of 5A002. However, it is sold to the general public in electronics stores, the cryptography cannot be modified by the user, and it installs without vendor support. It meets all four Crypto Note criteria and is therefore decontrolled.

Banking HSM (Hardware Security Module): The HSM manages cryptographic keys with configurable algorithms (RSA-4096, ECC P-384). It is sold exclusively B2B with vendor installation. It fails criteria 1 and 3 of the Crypto Note and is therefore controlled under 5A002. Licence required.

Encrypted messaging mobile app (Signal, WhatsApp): The app uses end-to-end encryption (Signal Protocol, AES-256). It is freely downloadable by the general public, not modifiable, and installs without support, so it is decontrolled under the Crypto Note. However, the cryptographic SDK sold to developers may be controlled.

Special case: software and technology

Encryption software (5D002) and technology (5E002) follow the same scheme as equipment, but with specific considerations:

  • •Open-source software whose source code is publicly available is generally excluded from control (General Software Note, GSN)
  • •Software available for free download qualifies for the Crypto Note if it meets the criteria
  • •Development technology (5E002.a) for products controlled under 5A002 is itself controlled
  • •Intangible transfer of technology (email, cloud access) is subject to the same regime as physical export

Cryptographic libraries (OpenSSL, BoringSSL) are a frequent case: the open-source code is excluded, but a compiled product incorporating these libraries must be assessed independently. The exporter must analyse the final product, not just the library.

Notification obligations and documentation

Even when a product qualifies for decontrol under the Crypto Note, some Member States require prior notification:

  • •France (SBDU): declaration of supply of cryptographic means (Article 30 LCEN). DM form and/or AT form as applicable.
  • •Germany (BAFA): notification obligation for products decontrolled under the Crypto Note.
  • •Other Member States have similar requirements.

Documents to retain for each classification: - Detailed technical description of the product - Classification analysis with reference to ECN entries - Justification of decontrol (Crypto Note criteria documented) - End-user and destination information - Retention period: minimum 5 years (Article 26 of Regulation 2021/821)

Guides

Catch-All Assessment - Articles 4 and 5

Practical guide to assess whether an unlisted product requires a license: WMD, military end-use, cyber-surveillance.

Export License Application Process

Steps for individual license (IL) application, general authorizations (EUGEA), timelines, required documents, competent authorities.

The Trade Hub
The Trade Hub
  • Q&A Forum
  • Regulatory Watch
  • Regulations
Log inSign up
Log inSign up