ECCN.DEV by Cancelli

Sending and storing

Is your encrypted data an export

Both regimes say that properly encrypted data, stored in the right places, has not been exported by being sent or stored. Both attach conditions. This works through them one at a time and tells you which ones your stack does not meet, and which ones nobody has established.

The two are not the same rule. The EAR version has four conditions. The ITAR version has five, and its storage condition points at a different list, so a stack can satisfy one and fail the other. Both are assessed.

Is any of this data classified national security information?

Classified information is outside both carve-outs entirely. Its handling is governed elsewhere.

Between the sender and the recipient, can anyone read the data in unencrypted form?

This means the cloud provider, a hosting company, an email service, an IT contractor, or anyone else in the middle. The question is not whether they would, it is whether they can.

Who holds the means of decryption?

A managed key service where the provider can decrypt on request is the provider holding the means, even when the console shows the key as yours.

Are the cryptographic modules FIPS 140-2 or 140-3 validated?

The rule asks for compliance with FIPS 140-2 or its successors, or other equally or more effective means. Most major providers publish which of their modules are validated.

Where is the data intentionally stored?

Pick every region that holds a copy, including backups, disaster recovery and anything a laptop syncs to. Data crossing the internet on its way somewhere is not stored where it passed through.

Is the data ever sent from a proscribed country?

Somebody travelling with a laptop, or logging in from abroad, sends data from wherever they are. The ITAR carve-out has a condition about this that the EAR carve-out does not.

Who are the intended recipients?

At the ends, who can open the data once it is decrypted?

The carve-out is about sending and storing. It does not decide who may read the plaintext at either end.

The rule, as it stands

§ 734.18 Activities that are not exports, reexports, or transfers.

EAR · 734.18 · version 2026-08-18, retrieved 2026-08-26

(a) Activities that are not exports, reexports, or transfers. The following activities are not exports, reexports, or transfers:

(1) Launching a spacecraft, launch vehicle, payload, or other item into space.

(2) Transmitting or otherwise transferring “technology” or “software” to a person in the United States who is not a foreign person from another person in the United States.

(3) Transmitting or otherwise making a transfer (in-country) within the same foreign country of “technology” or “software” between or among only persons who are not “foreign persons,” so long as the transmission or transfer does not result in a release to a foreign person or to a person prohibited from receiving the “technology” or “software.”

(4) Shipping, moving, or transferring items between or among the United States, the District of Columbia, the Commonwealth of Puerto Rico, or the Commonwealth of the Northern Mariana Islands or any territory, dependency, or possession of the United States as listed in Schedule C, Classification Codes and Descriptions for U.S. Export Statistics, issued by the Bureau of the Census.

(5) Sending, taking, or storing “technology” or “software” that is:

(i) Unclassified;

(ii) Secured using 'end-to-end encryption;'

(iii) Secured using cryptographic modules (hardware or “software”) compliant with Federal Information Processing Standards Publication 140-2 (FIPS 140-2) or its successors, supplemented by “software” implementation, cryptographic key management and other procedures and controls that are in accordance with guidance provided in current U.S. National Institute for Standards and Technology publications, or other equally or more effective cryptographic means; and

(iv) Not intentionally stored in a country listed in Country Group D:5 (see supplement no. 1 to part 740 of the EAR).

Data in-transit via the internet is not deemed to be stored.

(b) Definitions. For purposes of this section, End-to-end encryption means (i) the provision of cryptographic protection of data such that the data is not in unencrypted form between an originator (or the originator's in-country security boundary) and an intended recipient (or the recipient's in-country security boundary), and (ii) the means of decryption are not provided to any third party. The originator and the recipient may be the same person.

(c) Ability to access “technology” or “software” in encrypted form. The ability to access “technology” or “software” in encrypted form that satisfies the criteria set forth in paragraph (a)(5) of this section does not constitute the release or export of such “technology” or “software.”

§ 120.54 Activities that are not exports, reexports, retransfers, or temporary imports.

ITAR · 120.54 · version 2026-08-18, retrieved 2026-08-26

(a) The following activities are not exports, reexports, retransfers, or temporary imports:

(1) Launching a spacecraft, launch vehicle, payload, or other item into space;

(2) Transmitting or otherwise transferring technical data to a U.S. person in the United States from a person in the United States;

(3) Transmitting or otherwise transferring within the same foreign country technical data between or among only U.S. persons, so long as the transmission or transfer does not result in a release to a foreign person or transfer to a person prohibited from receiving the technical data;

(4) Shipping, moving, or transferring defense articles between or among the United States as defined in § 120.60;

(5) Sending, taking, or storing technical data that is:

(i) Unclassified;

(ii) Secured using end-to-end encryption;

(iii) Secured using cryptographic modules (hardware or software) compliant with the Federal Information Processing Standards Publication 140-2 (FIPS 140-2) or its successors, supplemented by software implementation, cryptographic key management and other procedures and controls that are in accordance with guidance provided in current U.S. National Institute for Standards and Technology (NIST) publications, or by other cryptographic means that provide security strength that is at least comparable to the minimum 128 bits of security strength achieved by the Advanced Encryption Standard (AES-128); and

(iv) Not intentionally sent to a person in or stored in a country proscribed in § 126.1 of this subchapter; and

Data in-transit via the internet is not deemed to be stored in a country it transits.

(v) Not sent from a country proscribed in § 126.1 of this subchapter;

(6) The taking of a defense article subject to the reexport or retransfer requirements of this subchapter on a deployment or training exercise outside a previously approved country, provided:

(i) There is no change in end-use or end-user with respect to the defense article;

(ii) The defense article is transported by and remains in the possession of the previously authorized armed forces of a foreign government or United Nations military personnel; and

(iii) The defense article is not being exported from or temporarily imported into the United States; and

(7) The transfer of a foreign defense article previously imported into the United States that has since been exported from the United States pursuant to a license or other approval under this subchapter, provided:

(i) The foreign defense article was not modified, enhanced, upgraded, or otherwise altered or improved in a manner that changed the basic performance of the item prior to its return to the country from which it was imported or a third country;

(ii) A U.S.-origin defense article was not incorporated into the foreign defense article; and

(iii) The defense article is not being exported from or temporarily imported into the United States.

(b)(1) For purposes of this section, end-to-end encryption is defined as:

(i) The provision of cryptographic protection of data, such that the data is not in an unencrypted form, between an originator (or the originator's in-country security boundary) and an intended recipient (or the recipient's in-country security boundary); and

(ii) The means of decryption are not provided to any third party.

(2) The originator and the intended recipient may be the same person. The intended recipient must be the originator, a U.S. person in the United States, or a person otherwise authorized to receive the technical data, such as by a license or other approval pursuant to this subchapter.

(c) The ability to access technical data in encrypted form that satisfies the criteria set forth in paragraph (a)(5) of this section does not constitute the release or export of such technical data.