The Olam
Real Economy

The BIS Entity List: NSO Group, Candiru, and What Listing Actually Does to an Israeli Company

By The Olam Editorial Team · Jul 28, 2026

The BIS Entity List: NSO Group, Candiru, and What Listing Actually Does to an Israeli Company

The deadliest single instrument in US export control. The November 2021 additions of NSO Group and Candiru — what listing operationally does to an Israeli company's supply chain, valuation, and Israeli MOD licensing exposure.

The US Commerce Department's Entity List is the deadliest single instrument in the US export-control architecture. Additions restrict US-origin exports — hardware, software, technology — to the listed entity. Delistings are rare. And in November 2021, four cybersecurity firms were added by name — two of them Israeli — with operational consequences that reshaped the Israeli offensive-cyber industry.

NSO Group. Candiru. The Bureau of Industry and Security added Positive Technologies (Russia) and Computer Security Initiative Consultancy PTE. LTD. (Singapore) in the same tranche. The framing was human rights: the four firms, per the BIS notice, had supplied spyware used to target journalists, activists, and government officials. The mechanism was export control. The effect on NSO and Candiru's supplier relationships was immediate.

What Is the BIS Entity List, and How Do Companies Get Added?

The Entity List is maintained by BIS at 15 CFR Part 744, Supplement No. 4. Adding an entity imposes a license requirement on exports, re-exports, and in-country transfers of items subject to the EAR to that entity, generally with a policy of denial. In practice: no US-origin hardware, no US-origin software, no US-origin technology.

The listing designation carries additional operational restrictions. A specific Entity List entry can include broader controls than the default, and specific de minimis rules can be tightened for individual listed entities. The default 25% de minimis threshold on foreign-made items is reduced — sometimes to zero — for listed parties in specified cases.

Additions require an interagency End-User Review Committee (ERC) determination — Commerce, State, Defense, Energy, and where relevant Treasury vote on the addition. The threshold for addition is a "reasonable cause to believe" the entity is involved in activities contrary to US national security or foreign policy interests. Delistings require the same interagency process — and are rarely granted. A listed party can seek delisting by demonstrating that the reason for listing no longer applies, but the burden of proof is on the listed entity, and the process runs on federal-agency timelines.

As of mid-2026, the Entity List runs to more than 3,000 individual entries across dozens of jurisdictions. Additions and modifications are published in the Federal Register and take effect on publication — no grace period, no phase-in.

Why Were NSO Group and Candiru Added to the Entity List in November 2021?

On November 3, 2021, BIS published the Federal Register notice adding NSO Group Technologies Limited, Q Cyber Technologies (an NSO affiliate), Candiru Ltd., Positive Technologies, and COSEINC to the Entity List.

The Israeli two were the largest offensive-cyber firms in the sector. NSO — founded 2010 by Shalev Hulio, Omri Lavie, and Niv Karmi — had sold its Pegasus spyware to state customers globally. Candiru — founded 2014, headquartered in Tel Aviv, previously operating under names including Grindavik and DF Associates — operated in the same category with a smaller footprint and a lower public profile.

The BIS rationale, stated in the Federal Register notice: the firms "developed and supplied spyware to foreign governments that used these tools to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers." Citizen Lab, Amnesty International, and the Pegasus Project consortium had documented cases across dozens of countries in the years preceding the listing.

The commercial impact ran across the supply stack. US cloud providers (AWS, Microsoft Azure, Google Cloud) withdrew or restricted services. US chip suppliers (Intel, AMD, and by extension the broader semiconductor supply chain running through US-origin design tools) faced supply restrictions. US software vendors — Microsoft, Salesforce, Oracle — restricted licenses.

The Israeli government protested the additions through diplomatic channels. Washington did not reverse the listings.

What Happens Operationally When an Israeli Company Is Added to the Entity List?

An Entity-Listed company continues to exist. It continues to have Israeli operations, Israeli employees, and Israeli customers. What it loses is US-origin supply access.

For a software company selling to state customers globally, US-origin supply access includes cloud infrastructure, code-signing certificates, developer tools, cybersecurity infrastructure, chip supply for hardware components, licensed software libraries, and the payment infrastructure that runs on US-based payment processors. The list is longer than the operational leadership at most Israeli firms had anticipated before the listing.

The compliance workaround — sourcing from non-US suppliers, restructuring to move US content out of the product, developing internal replacements — takes time and money. Both NSO and Candiru pursued variants of these paths in 2022–2024 with mixed success. The Israeli offensive-cyber sector's post-2021 supplier map looks materially different from the pre-2021 one: European cloud (OVHcloud, Deutsche Telekom's T-Systems), European code-signing, non-US developer tooling where practical, careful sourcing on hardware components.

None of it fully substitutes for the US ecosystem. Cost, latency, and capability gaps remain. Banking access is a distinct problem — US-clearing banks apply their own risk overlays on Entity-Listed counterparties, and correspondent-banking relationships with Israeli institutions serving these firms have narrowed.

How Did Israel's Ministry of Defense Respond to the NSO and Candiru Listings?

The Israeli Ministry of Defense responded in the same month with the most substantive Israeli cyber export-control policy shift in a decade. In November 2021, the MOD reduced its approved-country list for cyber-offensive exports from 102 countries to 37 — democracies and specified partners only, with case-by-case exceptions for others.

The reduction was operational. It removed a large share of NSO's and Candiru's addressable market at the Israeli licensing layer, even where BIS listing left US supply issues aside. The net effect: Israeli offensive-cyber firms lost simultaneous US supply access and Israeli export permission to a large fraction of their historical customer base.

The 2021 policy shift is the most substantive Israeli export-control policy change in a decade. The catalyst was BIS. The Israeli government sequenced its own tightening to the American action. Under the 2007 Defense Export Control Law, the MOD carried the statutory authority to make the shift; the political trigger was Washington.

How Does Entity List Designation Affect Company Valuation?

NSO's enterprise value at peak — pre-listing — was reported in the $1 billion range. Post-listing, its ability to raise capital, close deals, and retain customers deteriorated sharply. By 2022, reports of a possible sale process circulated. By 2023, restructuring and layoffs. The company survived; its valuation trajectory did not. Reports in 2024–2025 tracked continued distressed-position financing and periodic acquisition rumors that did not close. Berkeley Research Group's court-appointed monitoring role in the Israeli court proceedings surrounding NSO's ownership disputes added further pressure to enterprise-level decision-making.

Candiru's smaller scale meant its post-listing trajectory received less coverage. Its operational compression tracked the same pattern.

The listing did not shut either firm. It reshaped the corridor they operate in — narrower customer set, higher supply cost, tighter Israeli licensing, and a reputational overhang that affects everything from banking to talent retention to insurance markets. Directors and officers insurance for Entity-Listed firms carries premiums materially above sector average; some insurers decline coverage outright.

Are Other Israeli Cybersecurity Firms Under BIS Scrutiny?

Post-2021 BIS scrutiny of Israeli offensive-cyber has extended beyond NSO and Candiru. Reports of BIS inquiries and legal-diligence tightening have surfaced across the sector. Multiple Israeli offensive-cyber firms — some operating under names that shift periodically for commercial and legal reasons — have restructured operations, headquartered outside Israel, or scaled back US-facing product lines.

As of mid-2026, no further Israeli offensive-cyber additions to the Entity List have followed the 2021 tranche. The compliance posture across the Israeli sector has shifted substantially — driven simultaneously by US export control and the Israeli MOD's 37-country regime. Sector fundraising has adjusted: US venture capital participation in Israeli offensive-cyber has essentially disappeared, replaced where present by European, Asian, and Gulf sources.

Which Other Israeli Entities Have Appeared on the Entity List?

Beyond offensive-cyber, other Israeli-affiliated entities have surfaced on the Entity List across the years — typically for reasons unrelated to cyber (transshipment concerns, third-country diversion, sanctions circumvention allegations). Each individual case is fact-specific. The pattern is not: Israel is a normalized Entity-List jurisdiction. NSO and Candiru remain the reference cases because the policy signal was explicit and the sector-wide consequences were durable.

Related BIS instruments touch a broader set of Israeli firms without full Entity List designation. The Unverified List identifies parties BIS could not verify in end-use checks — additions here do not carry the presumption-of-denial standard but do impose additional recordkeeping and require the Israeli exporter to obtain statements from the counterparty. The Military End User List extends specific restrictions to identified military end users in China, Russia, Venezuela, and Myanmar — Israeli firms selling into any adjacent supply chain need to screen against it.

What Three Quarterly Checks Should Every Israeli Tech Firm Run?

  1. Are any of my customers on the Entity List? US-origin content in my product cannot ship to them without a license — and the license is generally denied.
  2. Are any of my suppliers dependent on a US-origin chain that could shift under a policy change? Sole-source US dependencies are the highest-risk category.
  3. What would happen to my business if my own firm were listed? What fraction of my supply stack is US-origin, and what is the substitutability path?

The third question is not paranoia. It is scenario planning. The NSO and Candiru cases established the precedent. The compliance posture across the Israeli sector has adjusted accordingly. Board-level risk registers at Israeli tech companies routinely now include an Entity List exposure line item, quantified against revenue and supply-chain concentration.

What Other US Export Control Mechanisms Should Israeli Firms Watch?

The BIS Entity List is not the only US mechanism reshaping Israeli technology industry access to the American ecosystem. The Foreign Direct Product Rule, semiconductor licensing rules under the October 2022 regime, and the CFIUS review architecture on inbound investment all extend the reach of US export control into decisions Israeli firms make about product design, corporate structure, and customer selection. The OFAC sanctions regime — administered by Treasury — operates parallel to BIS, with distinct listings (SDN List, Sectoral Sanctions Identifications) and its own enforcement mechanisms.

The Entity List is the sharpest instrument. The others operate at scale.


Related in Olam:

Crypto & Digital Assets

View all →

Universities & Research

View all →