The US Export Administration Regulations: An Israeli Operator's Manual

Every Israeli tech company using US components or selling US-side sits inside EAR. The BIS regime catching encryption, semiconductors, drones, AI hardware — and why "Made in Israel" doesn't exempt anything above the 25% de minimis threshold.
Every Israeli technology company selling into the US market — or using US components in its own product — sits inside the Export Administration Regulations. EAR is the Commerce Department control regime. It is not the same as ITAR. It is not administered by the same department. It does not cover the same items. And it catches more Israeli companies than any other US export-control framework — because encryption, semiconductors, drones, and AI hardware all live inside it.
The Bureau of Industry and Security — BIS, inside the Department of Commerce — runs EAR. The Commerce Control List (CCL) defines what's controlled. The Entity List identifies who cannot receive US-origin controlled goods. The Foreign Direct Product Rule extends US jurisdiction over foreign-made items that used US technology. This is the operator's manual.
What Is the US Export Administration Regulations (EAR), and Who Enforces It?
EAR covers "dual-use" and less-sensitive military items — items with both civilian and defense applications, plus certain military goods not covered by the State Department's ITAR framework. Chip design software, encryption algorithms, semiconductor manufacturing equipment, some categories of drones and sensors, biological and chemical precursors, and advanced computing hardware all sit inside EAR.
The regulation runs to more than 800 pages of the Code of Federal Regulations at 15 CFR Parts 730–774. BIS enforces it through Export Enforcement's field offices in Boston, Chicago, Dallas, Los Angeles, Miami, New York, San Jose, and Washington — with Federal Register listings, Temporary Denial Orders, and administrative subpoenas as the standing enforcement tools. Criminal referrals go to the Department of Justice's National Security Division.
The operational structure narrows to four working questions:
- What is the item?
- Where is it going?
- Who is the end user?
- What will the end user do with it?
Match those four against the CCL, the country chart, the end-user restrictions (Entity List, Denied Persons List, Unverified List, Military End User List), and the end-use controls. The answer: license required, no license required, or license exception applies.
How Does the Commerce Control List Classify Israeli Products?
Every item under EAR jurisdiction receives an Export Control Classification Number (ECCN) — five characters, alphanumeric, indicating the CCL category and the type of control. ECCN 3A001 is integrated circuits. ECCN 5A002 is encryption commodities. ECCN 3B001 is semiconductor manufacturing equipment. ECCN 5D002 is encryption software. ECCN 4A003 covers digital computers, and ECCN 4D001 the associated software.
Items not on the CCL are designated EAR99 — the residual category. EAR99 goods can generally ship without a license, but not to embargoed destinations (Cuba, Iran, North Korea, Syria) and not to Entity-Listed parties.
The ECCN determines the reason for control — National Security, Missile Technology, Chemical/Biological, Nuclear Non-Proliferation, Regional Stability, Firearms, Anti-Terrorism, Crime Control, Encryption Items, Significant Items — and each reason maps to specific countries requiring a license under the Commerce Country Chart at Supplement No. 1 to Part 738. An Israeli chip shipped to Germany may face zero restrictions under the National Security column; the same chip shipped to China faces licensing at the presumption-of-denial standard.
Why Doesn't "Made in Israel" Exempt Products From US Export Control?
The de minimis rule extends EAR jurisdiction over foreign-made items that incorporate US-origin controlled content. The threshold: 25% by value for most destinations, 10% for embargoed destinations. For select entity-listed parties and certain semiconductor items, the threshold has been reduced to zero.
Practical implication for Israeli industry: an Israeli-manufactured system with 26% US-origin controlled components remains subject to EAR on re-export. Israeli firms that assumed "Made in Israel" exempted them from US control have been repeatedly disabused. The de minimis calculation is by fair market value of controlled US content over the total value of the finished item — and controlled US content includes software and technology, not just hardware.
For firms above the threshold, the compliance obligation is a US license or license exception on re-export, regardless of where the finished item is manufactured. Documentation requirements include supplier certifications, bill-of-materials analysis, and running de minimis calculations that need re-verification every time a supplier or component changes.
How Does EAR Regulate Israeli Cybersecurity and Encryption Exports?
Encryption commodities and software (Category 5, Part 2 of the CCL) is where the largest share of Israeli technology sits. Cybersecurity software, VPN, secure messaging, digital signature, blockchain infrastructure, endpoint protection, network monitoring — all Category 5 Part 2.
The framework runs through three principal license exceptions:
- ENC (Encryption) — mass-market items with a self-classification and semi-annual reporting requirement
- TSU (Technology and Software Unrestricted) — certain publicly available encryption source code
- NLR (No License Required) — for select destinations and item types after classification review
Most Israeli cybersecurity firms operate under ENC self-classification, with semi-annual reports to BIS. The compliance layer is low-friction but not zero. A BIS classification review request (CCATS) can run six to eight weeks. Firms shipping into embargoed destinations, or to Entity-Listed parties, gain nothing from ENC. And any encryption product with a key length above defined thresholds may face review beyond the mass-market exception, particularly for government end users in specified countries.
How Do the US Semiconductor Rules Affect Israeli Chip Companies?
The October 7, 2022 BIS semiconductor rule — significantly expanded in October 2023, and again in December 2024 — restricted export of advanced logic and memory chips, chip-design software, and semiconductor manufacturing equipment to China. The rule applies to a broad set of foreign-made items via the Foreign Direct Product Rule. Israeli firms in EDA, chip design, and semiconductor equipment supply chains — from Cadence and Synopsys competitors to Applied Materials suppliers — sit inside its scope.
The operational consequence for Israeli semiconductor firms selling into Chinese customers: a licensing regime with a presumption of denial for advanced-node items, near-blanket denial for named Chinese fabs (SMIC, YMTC, CXMT), and case-by-case review for downstream applications.
The rule redrew the addressable market for advanced-semiconductor Israeli firms overnight. Israeli engineering leadership in AI accelerator chip design — Habana Labs (sold to Intel in 2019 for $2 billion), Hailo, various stealth-mode designers — operates entirely inside the post-October 2022 regime. The Nvidia Kiryat Tivon expansion is happening under this regime, not around it.
When Does an Israeli Drone Fall Under EAR vs ITAR?
Category 9 of the CCL covers propulsion systems, autonomous vehicles, and select aerospace equipment. Israeli drone and counter-drone manufacturers frequently sit inside 9A012 (UAVs) or 9A610 (military unmanned aerial systems — though primary jurisdiction for military UAS often shifts to ITAR under USML Category VIII).
The dual-use / military-item overlap is where the ITAR-EAR jurisdictional line is most contested for Israeli companies. Which framework applies determines which license is required, which agency reviews the transaction, and how long the review takes. A Commodity Jurisdiction (CJ) request to State clarifies where the line falls. The 2013 Export Control Reform initiative moved a substantial share of aerospace parts and vehicle components from ITAR to EAR under the "600 series" of ECCNs — reducing licensing burden but not eliminating it.
What Happens When an Israeli Company Lands on the BIS Entity List?
The Entity List is the operational teeth of EAR. Adding an entity to the list restricts US-origin exports to that entity — no US-origin controlled goods, no US-origin software, no US-origin technology. Israeli companies added to the list in the November 2021 addition (NSO Group, Candiru) discovered the scope in practice: US cloud providers withdrew services, US chip vendors withdrew supply, US software vendors withdrew licenses.
The Entity List and the NSO / Candiru cases are covered separately in this pillar. What matters for the EAR operator's manual: any Israeli firm engaging with US technology needs to know its counterparties are not listed, and needs to know the process for delisting if its own name lands there. The vetting obligation is standing — Entity List additions happen at BIS's discretion and take effect on Federal Register publication.
What Six Questions Should Every Israeli Exporter Answer Before Shipping?
Any Israeli technology company selling US-side or building on US content needs answers to all six before shipping.
- What is the ECCN of my product?
- What US-origin content sits inside it, and is it above de minimis?
- Who is my customer, and are they on the Entity List, Denied Persons List, Unverified List, or Military End User List?
- What is the end-use, and does it trigger end-use controls (military intelligence, weapons of mass destruction, human rights)?
- Which license exception applies, or do I need a license?
- What is my recordkeeping obligation, and when do I need to file a semi-annual or annual report?
Answering these is not lawyer work in the first pass. It is operator work. The lawyers are needed when the answer is ambiguous or when a license application requires drafting. Penalties for violations are substantial — administrative fines up to $364,992 per violation (inflation-adjusted, as of 2025) and criminal exposure up to $1 million per violation and 20 years' imprisonment under the Export Control Reform Act of 2018.
How Does EAR Interact With Israel's Own Export Control Regime?
EAR is the framework the Israeli Trade Levy Directorate (Ministry of Economy) and DECA (Ministry of Defense) coordinate around, not against. Israeli firms operating dual-use goods will typically face parallel Israeli and US licensing requirements. The two frameworks are not identical in scope, and the sequencing matters: US license first for US-origin content, then Israeli license for the export from Israel.
The 2007 Defense Export Control Law gives Israel its statutory framework; the Order for Free Export under the Ministry of Economy covers the dual-use civilian track. Coordination between the two Israeli tracks — and between both and Washington — is the standing operational challenge for Israeli technology firms with US-content exposure.
The one certainty: Israeli technology cannot cleanly opt out of EAR. The framework is extraterritorial by design.
Related in Olam:
- Israel's 2007 Defense Export Control Law: The SIBAT–DECA Licensing Architecture
- ITAR: The US Munitions Ceiling on Israeli Defense Exports
- The BIS Entity List: NSO Group, Candiru, and What Listing Actually Does to an Israeli Company
- DECA: How Israel Licensed $14.8B in Defense Exports in 2024
- SIBAT: The MoD's Weapons Salesman
- The Abraham Accords Trade Corridors



