Regulation (EU) 2021/821 — scope and application
Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 sets up the EU regime for the control of exports, brokering, technical assistance, transit, and transfer of dual-use items (the "EU Dual-Use Regulation"). The Regulation entered into force on 9 September 2021, repealing and replacing Regulation (EC) No 428/2009, though licensing applications submitted before 9 September 2021 continued to be processed under the prior regulation.
Dual-use items are defined in Article 2(1) as items — including goods, software, and technology — that can be used for both civilian and military purposes. Examples range from advanced semiconductors and encryption software to biological agents and uranium enrichment equipment. The term captures items that have legitimate commercial applications but also pose proliferation or national-security risks if diverted.
Article 1 establishes the scope: the Regulation controls five categories of activities:
- Export (Article 2(2)): the physical sending, electronic transmission, or personal carriage of dual-use items from the EU customs territory to a third country.
- Brokering (Article 2(5)): the negotiation or arrangement of transactions involving dual-use items between third countries (i.e., when neither the origin nor the destination is within the EU).
- Technical assistance (Article 2(6)): technical support related to the design, development, manufacture, assembly, testing, maintenance, or any other technical service for dual-use items, including instruction, advice, training, and consulting, whether delivered in person, electronically, or verbally.
- Transit (Article 2(13)): the movement of non-EU dual-use items through EU territory without being placed under a customs procedure such as release for free circulation.
- Transfer (Article 2(14)): the intra-EU movement of certain particularly sensitive dual-use items listed in Annex IV of the Regulation (for instance, specific materials used in nuclear fuel cycles and certain military-applicable stealth technologies). Most dual-use items may move freely within the EU; only Annex IV items require a transfer authorization.
Any natural or legal person — including researchers, exporters, brokers, and technical-assistance providers — established or resident in the EU customs territory may be subject to the Regulation's requirements when engaged in one of these five activities.
Territorial application extends across the entire EU customs territory, which currently comprises the 27 EU Member States. The Regulation does not apply to exports of military items (which fall under Council Common Position 2008/944/CFSP and national military-export laws), nor does it govern items covered by separate EU sanctions regimes, though both frameworks may apply concurrently.
Article 3(1) sets the core licensing requirement: an authorisation is required for the export of dual-use items listed in Annex I of the Regulation. Annex I implements the control lists agreed by the four multilateral export-control regimes — the Wassenaar Arrangement (conventional arms and dual-use goods), the Missile Technology Control Regime (MTCR), the Nuclear Suppliers Group (NSG), and the Australia Group (chemical and biological weapons precursors) — as well as commitments under the Chemical Weapons Convention. Annex I is updated at least annually by the European Commission through delegated regulations to incorporate changes agreed in those multilateral fora.
Additional "catch-all" controls in Articles 4 and 5 may require an authorisation for items not listed in Annex I if a Member State competent authority informs the exporter that the items are or may be intended for weapons of mass destruction (Article 4), military end-use in an embargoed country (Article 4), or — under Article 5 — internal repression involving cyber-surveillance technology that could enable serious human-rights violations.
The Regulation replaced the previous regime (Regulation 428/2009) with a recast framework that introduced several modernisations: expanded controls on cyber-surveillance items under Article 5, new Union General Export Authorisations (UGEAs) for intra-group transfers of software and technology (EU007, Annex II-G) and for encryption items (EU008, Annex II-H), mandatory internal compliance programmes (ICPs) for holders of global export authorisations, and an enhanced Dual-Use Coordination Group (Article 24) to harmonise national licensing practices and share information on denials.
Member States retain the power under Article 9 to impose national controls on non-listed items for reasons of public security or human rights, and under Article 10 of Regulation (EU) 2015/479 to prohibit or restrict exports on other public-policy grounds, though such measures must be notified to the Commission and published in the Official Journal.
Annex I — classification structure and the ten control categories
Annex I to Regulation (EU) 2021/821 establishes the common EU control list of dual-use items — goods, software, and technology — that require an export authorisation under Article 3(1) when exported from the EU customs territory to third countries. The Annex implements the control lists agreed by four multilateral export-control regimes (the Wassenaar Arrangement, the Missile Technology Control Regime, the Nuclear Suppliers Group, and the Australia Group) and commitments under the Chemical Weapons Convention. The Commission updates Annex I at least annually through delegated regulations to reflect new international agreements on proliferation-sensitive technologies.
Annex I organises controlled items into ten categories, numbered 0 through 9. Each category corresponds to a distinct technology domain or industrial sector. An exporter must determine which category, if any, applies to its item — and then review the specific entries, sub-entries, and technical parameters within that category — to decide whether an authorisation is required. The ten categories are:
- Category 0 — Nuclear Materials, Facilities and Equipment
Covers nuclear reactors, specially designed or prepared nuclear-fuel-cycle equipment (enrichment, reprocessing, heavy-water production), nuclear materials (source material, special fissionable material, and items above specified isotopic thresholds), and deuterium and heavy water. Implements Nuclear Suppliers Group trigger lists and dual-use nuclear controls.
- Category 1 — Special Materials and Related Equipment
Includes composite and ceramic materials (fibrous/filamentary materials exceeding specified tensile strengths or elastic moduli), metals and alloys (maraging steels, titanium alloys, aluminium alloys meeting aerospace-grade specifications), toxins, pathogens, genetic elements, and other materials with proliferation or biological-weapons concern. Implements Australia Group biological- and chemical-precursor lists and Wassenaar advanced-materials entries.
- Category 2 — Materials Processing
Machine tools (including numerically controlled lathes, milling machines, and coordinate measuring machines meeting precision thresholds), dimensional-inspection or measuring systems exceeding specified accuracy levels, controlled-atmosphere and vacuum furnaces, isostatic presses, and vibration-test equipment. Relevant for precision manufacturing of missile components, centrifuge parts, and aerospace structures.
- Category 3 — Electronics
Integrated circuits (including microprocessors, analog-to-digital converters, and field-programmable gate arrays exceeding specified performance parameters), microwave and millimetre-wave items (travelling-wave tubes, power amplifiers), electronic assemblies and components (capacitors, switches, connectors meeting military or radiation-hardened specifications), and semiconductor manufacturing equipment (epitaxy reactors, ion implanters, photolithography equipment).
- Category 4 — Computers
Electronic computers and related equipment exceeding specified aggregate computational performance thresholds (measured in weighted teraFLOPS, WT), hybrid computers, electronic assemblies specially designed for signal or image enhancement under specific conditions, and "software" specially designed for the "development," "production," or "use" of controlled computer equipment.
- Category 5 — Telecommunications and Information Security
Subdivided into Part 1 (Telecommunications) (optical-fiber communication cables, underwater communication equipment, radio equipment exceeding specified frequency or output-power parameters, fibre-optic items) and Part 2 ("Information Security") (cryptographic systems, cryptanalytic systems, software and hardware using symmetric or asymmetric algorithms exceeding key-length thresholds, systems specially designed for command-and-control or intelligence applications). Part 2 is particularly sensitive and many items are listed in Annex IV, meaning they require authorisation even for intra-EU transfers among Member States.
- Category 6 — Sensors and Lasers
Optical sensors and lasers (including continuous-wave and pulsed lasers exceeding specified wavelengths, output power, or pulse-repetition rates), cameras (focal-plane arrays, streak cameras, framing cameras for high-speed imaging), optics (mirrors, windows, lenses meeting specified surface-finish or wavefront-distortion parameters), and magnetometers, gravimeters, and radiation-detection equipment exceeding sensitivity thresholds. Relevant for precision-guided munitions, missile seekers, and intelligence-surveillance-reconnaissance (ISR) platforms.
- Category 7 — Navigation and Avionics
Accelerometers and gyroscopes meeting specified bias-stability or drift-rate parameters, inertial navigation systems, Global Navigation Satellite System (GNSS) receiving equipment capable of operation above specified altitude and speed coordinate limits (the "COCOM limits"), radar systems, flight-control systems (including "FADEC" — Full Authority Digital Engine Control systems), and airborne-refueling equipment.
- Category 8 — Marine
Submersible and surface vessels (including unmanned underwater vehicles, remotely operated vehicles, and manned submersibles exceeding specified depth ratings), underwater-detection systems (sonar, acoustic arrays, magnetometers, electric-field sensors), marine propulsion systems, and hydrofoil systems, surface-effect vehicles, and air-cushion vehicles.
- Category 9 — Aerospace and Propulsion
Aero gas-turbine engines and components (including those meeting specified thrust-to-weight ratios or specific fuel consumption parameters), ramjet, scramjet, or combined-cycle engines, rocket propulsion systems and components (nozzles, thrust-vector-control systems, turbo-pumps, combustion chambers, solid propellants), unmanned aerial vehicles (UAVs) and remotely piloted aircraft systems exceeding specified range or endurance parameters, launch vehicles, spacecraft buses, and re-entry vehicles.
Each category is further subdivided into lettered sections:
- Section A — End products, systems, and equipment
- Section B — Test, inspection, and production equipment
- Section C — Materials
- Section D — Software
- Section E — Technology
Within each section, items are identified by alphanumeric Entry Control List Numbers (ECLNs) — for example, 3A001 designates a category-3 (Electronics), section-A (end products), entry 001 integrated circuit; 5A002 designates a category-5, section-A, entry 002 "information security" system. Sub-entries are denoted by lower-case letters and further nested numbers (e.g., 3A001.a.1). An exporter must read the entry text, the technical parameters, and all relevant notes to determine coverage.
Technology entries in Section E warrant special attention. Under the general technology note, "technology" for the "development," "production," or "use" of controlled goods in Categories 1–9 is itself controlled according to the provisions of the relevant category, even when the technology is applicable to non-controlled goods. However, controls do not apply to technology that is "in the public domain" (defined in the General Technology Note), to "basic scientific research" (pre-competitive fundamental research in educational institutions), or to the minimum technology necessary for the installation, operation, maintenance, or repair of goods whose export has been authorised.
The Annex I introductory notes and definitions section (approximately 100 pages in recent consolidated versions) defines over 400 terms used throughout the list — including "accuracy," "adapted for use in space," "aircraft," "ASW" (anti-submarine warfare), "CAS latency time," "critical temperature," "development," "FADEC," "fibrous or filamentary materials," "information security," "laser," "production," "required," "software," "spacecraft," "technology," "use," and many industry-specific technical parameters. These definitions are binding: an item meets a control description only if it satisfies the defined terms.
Classification is a fact-intensive, technically demanding exercise. Exporters who cannot reliably determine an item's control status may request a classification opinion from the competent export-control authority of the Member State in which they are established (national procedures vary; in Germany, BAFA; in France, SBDU of the DGE; in the Netherlands, the RVO). Obtaining a written classification opinion is advisable for novel items, items with marginal technical parameters, or where a licensing decision depends on the classification.
Annex I is a living document. Delegated Regulation (EU) 2023/996 (updating the list effective 25 May 2023), Delegated Regulation (EU) 2024/2547 (updating the list effective 8 November 2024), and Delegated Regulation (EU) 2025/2003 (updating the list effective 15 November 2025) each added new items (including quantum-technology controls, advanced semiconductor manufacturing equipment, chemical precursors, and cyber-surveillance tools) and modified existing entries. Exporters must consult the current consolidated version of the Regulation to avoid applying a superseded control text.
Catch-all controls — WMD, military end-use, and cyber-surveillance (Articles 4 and 5)
Articles 4 and 5 of Regulation (EU) 2021/821 impose catch-all export-authorisation requirements for dual-use items not listed in Annex I when the exporter has been informed by a competent authority — or is aware, based on due diligence — that the items are or may be intended for weapons of mass destruction (WMD) use, military end-use in an embargoed country, use as components of unauthorised military items, or cyber-surveillance for internal repression or serious human-rights violations. These provisions extend the EU dual-use export-control regime beyond the list-based controls in Annex I to cover proliferation, military-diversion, and human-rights risks associated with otherwise uncontrolled goods, software, and technology.
**Article 4 — WMD and military end-use catch-all**
Article 4(1) requires an authorisation for the export of dual-use items not listed in Annex I if the exporter has been informed by the competent authority that the items in question are or may be intended, in their entirety or in part, for:
- (a) WMD use: use in connection with the development, production, handling, operation, maintenance, storage, detection, identification, or dissemination of chemical, biological, or nuclear weapons or other nuclear explosive devices, or the development, production, maintenance, or storage of missiles capable of delivering such weapons;
- (b) Military end-use in an embargoed country: military end-use (incorporation into military items listed on the EU Common Military List, or use of production equipment, components, or technology for military items) in a country subject to an arms embargo imposed by a decision or common position adopted by the Council of the European Union, a decision of the Organisation for Security and Co-operation in Europe (OSCE), or a binding resolution of the United Nations Security Council; or
- (c) Components of unauthorised military items: use as components for military items that were exported from the territory of a Member State without authorisation or in violation of an authorisation required by the national law of that Member State or by Council Common Position 2008/944/CFSP.
When the competent authority informs the exporter in writing that one or more of these end-uses applies or may apply to a proposed export, the exporter must apply for an individual export authorisation under Article 11 before proceeding, even if the items are not in Annex I.
Article 4(2) imposes a self-notification duty on exporters: where an exporter is aware that dual-use items which it proposes to export, not listed in Annex I, are intended, in their entirety or in part, for any of the uses in Article 4(1), the exporter shall notify the competent authority. The competent authority shall then decide whether to make the export subject to an authorisation requirement. "Aware" means the exporter has actual knowledge or reasonable grounds to suspect — based on customer inquiries, technical specifications, end-use declarations, published sanctions lists, open-source intelligence, or prior dealings — that a proliferation, military-diversion, or unauthorised-component risk exists.
Article 4(3) permits Member States to adopt or maintain national legislation imposing an authorisation requirement on the export of dual-use items not listed in Annex I if the exporter has grounds for suspecting that those items are or may be intended for any of the Article 4(1) uses. National measures adopted under Article 4(3) or Article 9 (public security and human-rights grounds) must be notified to the Commission and published in the C series of the Official Journal of the European Union. The list of national measures is compiled and updated by the Commission and available on the Commission's trade-policy website.
The Article 4 catch-all applies to all items capable of WMD or military end-use, not only those with obvious proliferation sensitivity. Examples include: general-purpose machine tools used to manufacture centrifuge components for uranium enrichment; commercially available software used in ballistic-missile trajectory modelling; metal alloys, composite materials, or electronic components incorporated into military drones or precision-guided munitions; and chemical precursors for nerve agents or blister agents that are below the concentration thresholds in Annex I Category 1 but can be concentrated or reacted by the end-user.
Article 4(4) through (8) establish information-sharing, consultation, and denial-notification procedures among Member States and between Member States and the Commission. When a Member State denies an authorisation under Article 4 for a transaction involving non-listed items, it must notify all other Member States and the Commission (through the secure electronic system under Article 23(6)), and Member States must inform their customs authorities and other relevant national authorities. The consultation mechanism in Article 15 applies to essentially identical transactions (same exporter, same end-user, same items, and same intended use): if Member State A denies an application under Article 4 and an exporter in Member State B submits an essentially identical application, Member State B must consult Member State A before granting the authorisation and must take utmost account of the circumstances of the denial.
**Article 5 — Cyber-surveillance catch-all**
Article 5(1) requires an authorisation for the export of cyber-surveillance items not listed in Annex I if the exporter has been informed by the competent authority that the items in question are or may be intended, in their entirety or in part, for use in connection with internal repression and/or the commission of serious violations of human rights and international humanitarian law.
"Cyber-surveillance items" are defined in Article 2(23) as items specially designed to enable the covert surveillance of natural persons by monitoring, extracting, collecting, or analysing data from information and telecommunication systems. Examples include:
- Intrusion software (malware, spyware, remote-access trojans) designed to compromise computers, mobile phones, or network infrastructure to extract communications, files, or location data without the knowledge of the user;
- Deep packet inspection (DPI) systems and telecommunications interception equipment designed to intercept and analyse internet traffic, voice-over-IP calls, messaging-app communications, or mobile-network signalling data at scale;
- IMSI catchers (cell-site simulators) and other mobile-network interception devices that masquerade as legitimate base stations to intercept mobile communications or track the location of mobile devices;
- Forensic tools for extracting data from locked or encrypted devices;
- Monitoring centres and lawful-intercept management systems designed to aggregate, store, and analyse intercepted communications and metadata; and
- Technology (technical assistance, know-how, training, or software updates) for the development, production, or use of any of the above.
Internal repression includes the use of cyber-surveillance items to monitor, harass, intimidate, arbitrarily arrest, detain, or torture human-rights defenders, journalists, lawyers, political opponents, or members of ethnic, religious, or other minority groups; to suppress peaceful protests or freedom of expression; or to enforce discriminatory laws or practices. Serious violations of human rights include torture, extrajudicial killings, enforced disappearances, and unlawful surveillance that enables such violations.
Article 5(2) imposes a due-diligence and self-notification duty on exporters: where an exporter is aware, according to its due diligence findings, that cyber-surveillance items which the exporter proposes to export, not listed in Annex I, are intended, in their entirety or in part, for any of the uses in Article 5(1), the exporter shall notify the competent authority. The competent authority shall decide whether to make the export subject to an authorisation requirement. Commission Recommendation (EU) 2024/2659 of 11 October 2024 provides detailed guidelines on the export of cyber-surveillance items under Article 5, including transaction-screening measures, item-classification methodologies, risk-assessment criteria, and due-diligence practices. The Recommendation advises exporters to review whether the non-listed item is a cyber-surveillance item, to assess whether the destination country or end-user presents internal-repression or human-rights-violation risk (based on EU sanctions lists, UNSC resolutions, reports by the UN Human Rights Council, the European External Action Service, UN special rapporteurs, or credible non-governmental organisations), and to document the due-diligence process.
Article 5(3) permits Member States to adopt national legislation extending the Article 5 catch-all to situations where the exporter has grounds for suspecting that cyber-surveillance items may be used for internal repression or human-rights violations, even if the exporter is not yet aware under Article 5(2). National measures must be notified to the Commission and published in the Official Journal.
Article 5(6) and (7) establish a multilateral publication mechanism: where all Member States notify each other and the Commission that an authorisation requirement should be imposed for essentially identical transactions involving cyber-surveillance items, the Commission shall publish in the C series of the Official Journal information regarding the cyber-surveillance items and, where appropriate, destinations subject to authorisation requirements as notified by Member States. Member States must review this published information at least annually. This multilateral process is designed to build consensus on emerging cyber-surveillance risks (e.g., spyware sold to authoritarian regimes, intrusion tools used to target civil-society activists) and to extend controls incrementally before formal addition to Annex I through a delegated regulation.
Article 5(8) and (9) extend the denial-notification and consultation procedures in Article 16 to cyber-surveillance items not listed in Annex I, and require that all exchanges of information under Article 5 take place via secure electronic means (the system under Article 23(6)) with due consideration for the protection of personal information, commercially sensitive information, or protected defence, foreign-policy, or national-security information.
**Exporter obligations and penalties**
Both Article 4 and Article 5 impose affirmative duties on exporters: competent-authority notification is not optional when the exporter is aware (Article 4(2)) or aware according to due diligence (Article 5(2)) of a covered end-use. Failure to notify or to obtain an authorisation when required is a criminal or administrative violation of the Regulation, subject to penalties under Article 21 and national implementing law. Member States must lay down rules on penalties and ensure they are effective, proportionate, and dissuasive, including — where appropriate under national law — criminal penalties for serious breaches (Article 21(1)).
Exporters are also prohibited from using any general export authorisation (UGEA in Annex II or NGEA) if they have been informed by a competent authority or are aware that the items are or may be intended for any of the uses in Article 4(1) or Article 5(1), even if the items are listed in Annex I and the transaction otherwise meets the conditions of the UGEA or NGEA. The same prohibition applies to individual and global export authorisations: an exporter may not use an already-granted authorisation if it becomes aware of a WMD, military-end-use, or internal-repression risk after the authorisation was issued but before shipment (Article 4 and Article 5, read in conjunction with the general due-diligence obligations in Article 14 on Internal Compliance Programmes).
**Guidance and enforcement**
The Commission and the Council are required under Article 26(1) to make available guidelines for exporters on the application of Articles 4 and 5, on due diligence, and on the interpretation of terms such as "aware," "internal repression," and "serious violations of human rights and international humanitarian law." Commission Recommendation (EU) 2024/2659 (published 16 October 2024) is the first such guideline for Article 5; guidelines on Article 4 WMD and military-end-use catch-all were previously issued under the predecessor Regulation (EC) No 428/2009 and remain relevant for interpreting analogous provisions in Regulation 2021/821.
Enforcement is the responsibility of the competent authorities and customs authorities of the Member States. Competent authorities conduct risk-based inspections of exporters, review licensing compliance, and investigate suspected violations. Customs authorities at points of export verify that the exporter has furnished proof of the necessary export authorisation (or, for catch-all controls, that the exporter has properly self-assessed non-applicability or obtained a catch-all authorisation). Member States share information on violations, seizures, and prosecutions through the Dual-Use Coordination Group (Article 24) and the secure electronic information-sharing system (Article 23(6)).
Internal Compliance Programmes (ICPs) — Article 14 requirements and Commission guidance
Internal Compliance Programmes (ICPs) are formalized compliance systems required under Article 14 of Regulation (EU) 2021/821 for certain categories of dual-use export authorisations. Exporters applying for a global export authorisation (Article 12(2)) or wishing to use Union General Export Authorisation EU007 for intra-group software and technology transfers (Annex II, Section G) must demonstrate the existence of an "effective, appropriate and proportionate" ICP as a precondition for authorisation.
Article 14 ICP requirement
Article 14(1) provides that the ICP must be scaled to the exporter’s size, organisational complexity, and the risks arising from the nature, volume, and destination of the exports. The Regulation defines an ICP as a set of ongoing policies and procedures designed to ensure compliance with export-controls—including item classification, screening of end-users and destinations, transaction monitoring, internal reporting, and staff training. Importantly, the adequacy of an ICP is assessed by the competent authority as part of each relevant licensing process. Absence or inadequacy of an ICP may result in refusal, suspension, or withdrawal of the authorisation.
Elements and Commission guidance
While Article 14 prescribes the obligation in principle, the European Commission has issued a Recommendation (C(2021) 8693 final, 15 December 2021) delineating non-binding guidance on ICP minimum elements. According to the Recommendation, a robust ICP should include: management commitment, organisational structure, screening and verification procedures, security of information systems, internal reporting, training and awareness, auditing, and procedures for corrective action. The Recommendation directly informs competent authority practice and is used as a standard reference in reviewing ICP submissions, despite its non-binding nature.
Exporters making use of global authorisations or UGEA EU007 must ensure their ICP covers these Commission-identified elements. The Commission also encourages all dual-use exporters—regardless of whether an ICP is strictly mandatory—to adopt such programmes voluntarily, citing their value in mitigating compliance risks and streamlining licensing.
Record-keeping and enforcement
The Regulation requires all exporters to keep export-related records for five years pursuant to Article 26 (not Article 14) and includes penalties for non-compliance under Article 21. Non-adherence to Article 14 (ICP) requirements may lead to licence denial or revocation and, if wilful, can trigger administrative or criminal sanctions as set by Member State law.
For application templates, checklists, and concrete examples, practitioners should consult the latest Commission Recommendation and any implementing notices from their Member State authority.
Source: Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021, Article 14 Source: Commission Recommendation of 15.12.2021 on Internal Compliance Programmes for dual-use trade
Transit of dual-use items through the EU — authorisation requirements and exemptions
Transit under the EU dual-use regime is defined by Regulation (EU) 2021/821, Article 2(13), as the passage of non-EU dual-use items through the EU customs territory without those items being released for free circulation (i.e., remaining under a transit customs procedure at all times). This covers, for example, goods entering the Port of Rotterdam or Frankfurt Airport bound for onward export outside the EU, with no customs importation into the Union where risk controls might otherwise be triggered.
When does a transit authorisation apply?
Under Article 6(1), a transit authorisation is required for non-listed dual-use items only if the person responsible for the transit has been notified by the competent authority of an EU Member State that the items are or may be intended (in whole or in part) for prohibited end-uses—specifically, uses described in Article 4(1)(a) (WMD proliferation), (b) (military end-use in embargoed destinations), or (c) (components of unauthorised military items). In the absence of such notification, there is no automatic EU-level authorisation requirement for transits of non-listed items.
For items listed in Annex I, Article 6(2) empowers Member States to make the transit subject to authorisation where they have notified the responsible party that the items are or may be intended for covered end-uses under Article 4 or 5 (the latter covers cyber-surveillance for human-rights abuse). Again, trigger is notification by a competent authority—not automatic for all such goods in transit.
Exemptions from the transit authorisation requirement
Article 6(4) sets out key exemptions. No transit authorisation is required if:
- The items are Union goods (i.e., have Union status under the Union Customs Code); or
- The items are not unloaded, trans-shipped, or otherwise removed from the means of transport that brought them into the EU, except for technical reasons supported by customs; and
- The items remain under customs supervision throughout their passage.
This means that most sealed-container transits through EU ports or airports—where there is no unloading or transfer—are outside the authorisation trigger unless a specific risk notification is issued.
National measures and customs cooperation
Article 9 permits Member States to impose stricter national rules on transit for public security or human rights reasons, provided these are notified to the European Commission. Article 23 formalises information exchange and cooperation among national authorities for the detection and enforcement of transit control violations.
Operational takeaway: If you are a carrier, forwarder, or exporter arranging transit through the EU and receive notification from a Member State’s competent authority concerning these end-use risks, you must obtain a transit authorisation before your goods can continue. Exemptions apply if the goods remain sealed and under customs supervision, but vigilance for competent authority notifications or national measures is essential for lawful passage.
Source: Regulation (EU) 2021/821, especially Articles 2(13), 4, 5, 6, 9, and 23
Brokering controls for dual-use items — regulatory scope and authorisation triggers
Regulation (EU) 2021/821 regulates "brokering" of dual-use items as a distinct activity from export, transit, or technical assistance. Article 2(5) defines "brokering services" as negotiating or arranging transactions that transfer items listed in Annex I from one third country to another third country. The key point: the dual-use items in question do not enter EU customs territory at any stage. Brokering controls address proliferation and sanctions circumvention risks where an EU-based actor orchestrates trade flows entirely outside the Union.
Who is regulated? Brokering controls apply to any natural or legal person that is resident or established in an EU Member State (Article 2(5), Article 6). Coverage of legal persons established outside the EU but controlled by an EU parent may be extended only if implemented by national law (see Article 15; there is no automatic EU-wide rule). Intra-EU transactions—brokering between Member States—do not fall under these brokering control provisions.
When is authorisation required? Article 6 establishes two authorisation triggers:
- (a) If a Member State competent authority informs the broker that the items may be intended for uses involving weapons of mass destruction (WMD), military end-use in an embargoed destination, or violation of EU or UN restrictive measures (Article 6(1)).
- (b) For "cyber-surveillance items" (as specifically defined in Article 2(23)), if notified by the authority that the risk involves internal repression or serious human rights abuse (Article 6(1a)).
A broker who "is aware—according to the findings of their due diligence"—of such risk (WMD, military, embargo breach, or cyber-surveillance misuse) must self-notify the competent authority, which may require authorisation (Article 6(3)).
What is exempt? Brokering authorisation is not required for dual-use items in Annex I unless the competent authority notifies the broker, or the broker's due diligence establishes a covered risk. Non-listed items are not subject to these brokering provisions unless covered by national law under Article 9. Routine brokering where none of the Article 6 risks apply does not trigger an authorisation requirement.
National flexibilities and procedure Member States can set stricter rules for brokering by national measure, provided they notify the European Commission (Article 9). Applications are made to the competent authority of the broker’s Member State of residence or establishment. Authorisations are time- and transaction-limited and require detailed recordkeeping under Article 22. The authority’s assessment criteria are set out in Article 12 and include end-use screening, multilateral denials, and proliferation and sanctions risk.
Operational takeaway: Brokering of listed dual-use items between third countries by EU-based brokers (or non-EU subsidiaries, if covered by national rules) is authorisation-controlled for WMD, military, embargo, or cyber-surveillance end-use risks, with a direct self-notification duty under Article 6(3).
National Controls — Article 9 and Article 10 supplementary export restrictions
Under Regulation (EU) 2021/821, Member States retain substantial authority to impose national controls on exports of non-listed dual-use items for public security, human rights, or other policy reasons. These powers, located in Article 9 (national controls for public security and human rights) and Article 10 (emergency restrictions on non-listed items), are a key operational risk for exporters whose goods fall outside Annex I or who assume that the published EU lists are exhaustive.
Article 9 — National public security and human rights controls Article 9(1) allows any Member State to impose an authorisation requirement for the export of specified items for reasons of public security (including the prevention of acts of terrorism) or for human rights considerations. These national controls must be notified to the European Commission, which publishes them in the C series of the Official Journal and maintains an updated list. A Member State may also require authorisation for brokering, technical assistance, or transit in these contexts. Article 9(2) ensures mutual recognition: once a national control is notified, all other Member States must also impose an authorisation requirement for the same item and destination, to prevent circumvention by routing through less-restrictive territories. This notification obligation gives exporters some transparency, but national controls are dynamic—frequently updated to reflect emerging security or human-rights concerns.
Article 10 — Emergency restrictions This provision enables Member States, in immediately urgent situations, to prohibit or restrict the export, brokering, or transit of items not listed in Annex I, for example to prevent supply to a country of concern or a high-risk entity. The measure must be justified on the grounds listed in Article 10(1) and notified to the Commission under Article 10(2). Such temporary emergency controls lapse unless adopted at the EU level within a prescribed period (often through subsequent Commission delegated regulations or Council decisions).
How are controls published and applied? Notifications under Articles 9 and 10 must be published in the Official Journal C series and/or on the Commission’s website, with details on scope (item, destination, rationale). The comprehensive, consolidated list of Member State notifications is maintained by the European Commission and was most recently published as a dedicated compilation in the Official Journal (C/2026/3577, 3 July 2026). Exporters must check both the current Regulation and the most recent national measure notifications before export, as controls can be imposed on short notice and are binding across all Member States once notified. These controls may add significant compliance risk, especially for custom or innovative products.
Practical implications: Exporters of items not listed in Annex I, or those shipping to destinations outside the usual risk profile, must check the consolidated national measure notifications before assuming no licence is needed. National controls sometimes cover technology, individual consignees, or intangible transfers. Compliance teams should subscribe to Commission updates and systematically screen transactions against newly published national controls.
Source: Regulation (EU) 2021/821, Articles 9 and 10 Source: Official Journal of the EU, C/2026/3577 — Compilation of National Control Measures (3 July 2026)
Exporter record-keeping obligations — Article 22 and Article 26 compliance
Exporters, brokers, transit agents, and technical assistance providers handling dual-use items under Regulation (EU) 2021/821 must comply with specific record-keeping requirements, regardless of the authorisation type (individual, global, Union General Export Authorisation/UGEA, or national). Article 22(1) requires that all relevant records be kept for at least five years after the end of the calendar year in which the export, brokering, transit, or technical assistance took place.
Statutory requirements:
- Who must keep records: Any natural or legal person exporting, brokering, transiting, or providing technical assistance for dual-use items under the Regulation (Article 22(1)).
- Content: Records must include all documents and information (commercial invoices, authorisations, end-use statements, customs declarations, contracts, transport docs) sufficient to identify:
- Description and quantity of items exported,
- Names and addresses of consignor, consignee, end-user, and recipient,
- Origin and final destination of the items,
- Date and value of export,
- The export authorisation(s) relied upon (type and number).
- Duration: Records must be kept for at least five years after the end of the year in which the relevant transaction occurred (Article 22(1)).
- Form: Article 22 does not prescribe a record format. Electronic records are permitted, provided information can be furnished promptly and is legible (Article 22(1)-(2)).
- Inspection: The competent authority of the Member State may examine records at any time during the retention window for compliance verification (Article 22(2)).
Penalties: Article 21 requires Member States to lay down penalties for breaches, but does not standardise whether violations are administrative or criminal; this varies by country.
Overlap with Internal Compliance Programmes (ICPs): Exporters who require an ICP under Article 14 (e.g., users of global authorisations, UGEA EU007) should ensure record-keeping procedures are integrated. However, the Regulation does not prescribe specific ICP elements for record-keeping beyond the general duty to document compliance (Article 14).
Commission and Member State guidance: Article 26(1) obliges the Commission and Member States to publish updated compliance guidance and forms on official websites. However, exporters remain responsible for meeting the core record-keeping requirements of Article 22, whether or not a recommended template is supplied.
Where the Regulation is silent about particular best practices—such as written recordkeeping policies or documenting chain of custody—these may be prudent but are not mandated by the statute as of June 2026.
Annex IV intra-EU transfer controls — which dual-use items require authorisation for movement between Member States?
The EU's general principle is that dual-use items (goods, software, technology listed in Annex I of Regulation (EU) 2021/821) may circulate freely within the customs territory. However, Article 3(2) creates an important exception for items listed in Annex IV—these are highly sensitive dual-use goods and technology for which intra-EU movement is subject to an export authorisation regime analogous to export outside the Union.
What is Annex IV? Annex IV comprises a subset of the Annex I dual-use control list: items that, by virtue of international undertakings or national security interests, require the same or near-equivalent controls for transfers between Member States as for exports outside the EU. This includes, for example, advanced cryptographic hardware and software (e.g., 5A002, 5D002), certain high-performance electronics, nuclear materials, and items subject to specific international export-control regime requirements (notably the Wassenaar Arrangement and the Nuclear Suppliers Group). The list is updated periodically by delegated act.
Legal basis and procedure. Under Article 3(2) and (3), Annex IV items may only be transferred from one Member State to another if the exporter (sender) obtains a prior authorisation from the competent authority of the Member State where it is established. The authorisation requirement applies whether the recipient is an end-user, a distributor, or an affiliate. There are two parts in Annex IV:
- Part 1: Items that may be transferred to another Member State on the basis of an authorisation granted by the competent authority of the exporter’s Member State.
- Part 2: Particularly sensitive items that may only be transferred on the basis of an authorisation granted by the competent authority of the exporting Member State after consultation or approval of the competent authority of the Member State of destination.
Process:
- The exporter must apply for a transfer authorisation, supplying technical specifications, the intended recipient’s details, and end-use. For Part 2 items, the competent authority of the Member State of destination may veto or set conditions on the transfer.
- The transfer authorisation is granted according to Article 11 procedures, with similar information and record-keeping requirements as for extra-EU exports.
Exemptions. Article 3(4) allows the Commission to adopt regulations exempting certain items from transfer authorisation requirements if justified by the degree of sensitivity, security risk, or international obligation. As of June 2026, nearly all items listed in Annex IV remain subject to transfer authorisation.
Operational risk: Failure to secure an Annex IV intra-EU transfer authorisation is a breach of Regulation (EU) 2021/821 and may trigger administrative or criminal penalties under national law. Customs and enforcement authorities in both the state of origin and destination may verify compliance.
Source: Regulation (EU) 2021/821, Articles 3, 11, and Annex IV
Technical Assistance Controls — Article 8 provisions and compliance triggers
Regulation (EU) 2021/821, effective as of 9 September 2021, extends dual-use export controls beyond goods and technology to cover the provision of technical assistance—a category that includes technical support, repair, development, manufacture, assembly, testing, maintenance, or any other technical service tied to dual-use items.
Definition (Article 2(6)): "‘Technical assistance’ means any technical support related to repairs, development, manufacture, assembly, testing, maintenance or any other technical service. It may take forms such as instruction, advice, training, transmission of working knowledge or skills or consulting services and may involve assistance provided orally, by telephone or by electronic means."
Core Controls (Article 8(1)-(2)): A person established or resident in a Member State must not provide technical assistance from the Union customs territory, or—if they are an EU citizen or permanent resident—from outside the Union, if:
- (a) They have been informed by the competent authority that the assistance is or may be intended for uses listed in Article 4(1): connection with WMD, military end-use in embargoed destinations, or as components for military items unlawfully exported from the EU.
- (b) Or, per Article 8(2), if the person is aware—according to their findings—of these prohibited end-uses, they must notify the competent authority, which will decide whether an authorisation is needed.
Territorial Scope: Article 8 reaches services supplied both from within the EU and by EU nationals or permanent residents acting abroad, save for the carve-outs below.
Exemptions and National Flexibility (Articles 8(3)-(6)): Member States may impose stricter requirements for technical assistance involving public security or human rights, provided these are notified to the European Commission. Exemptions include:
- Technical assistance provided in a third country to nationals or permanent residents of that country, unless the destination is under an EU arms embargo (Article 8(5)).
- Technical assistance relating to items covered by Annex I, if the support falls under the General Technology Note (publicly available, basic scientific research), as referenced in Article 8(6).
Compliance and Penalties: Operators must carefully screen technical assistance transactions, be alert to notification obligations if aware of covered end-use risk, and maintain records as with export of goods or technology. Failure to comply triggers penalties under Article 21 of the Regulation and national enforcement law.
Article 8 fills a critical compliance gap for service-based sectors and R&D-heavy exporters. Practitioners should review the exact statutory text for nuance, particularly around notification and authorisation triggers and national overlays.
Source: Regulation (EU) 2021/821 of the European Parliament and of the Council, Article 8
Denial notification and consultation procedure — Article 15 multilateral licensing controls
Article 15 of Regulation (EU) 2021/821 creates the denial-notification and consultation system fundamental to preventing “forum shopping” for export authorisations within the European Union. This process ensures that if a licence for dual-use exports (or related activities such as brokering, transit, or technical assistance) is denied in one Member State, all other Member States and the European Commission are notified promptly by secure electronic means (Article 15(1), Article 23(6)).
Denial notification: Whenever a competent authority from any Member State refuses an export-related authorisation under the Regulation, the refusal must be communicated immediately to the Commission and all other Member States. The notification includes enough information to allow recognition of the denied transaction—typically the item, end-user, and destination country. This mechanism is designed to stop exporters from circumventing a denial by applying in another Member State for the same authorisation.
Consultation for essentially identical transactions: If a new application is submitted to another Member State for what the Regulation terms an “essentially identical transaction”—that is, one involving the same exporter, same dual-use item, same end-user or consignee, and same planned end-use as the transaction already denied—the Member State considering the new application is legally obliged to consult with the authority that issued the denial (Article 15(2)). If, after consultation, the Member States disagree, the second Member State must delay any decision for at least 30 working days from the initial consultation, but it may ultimately decide independently if agreement cannot be reached (Article 15(3)). There is no absolute veto but the prior denial carries significant practical weight, and authorities are required to exchange all relevant information. The requirement is focused on “essentially identical” transactions; it does not expressly cover transactions that are merely similar but technically distinct.
Scope: Article 15’s consultation and notification rule applies to all denials under Regulation (EU) 2021/821. This covers listed dual-use items, catch-all controls (Articles 4 and 5), and national measures notified under Article 9—if such authorisations are denied, they are subject to the same coordinated process. This ensures regulatory coherence even with the national-control overlay that may be added by individual Member States.
Practical consequences: The Article 15 process prevents “Member State shopping” by requiring transparency and communication on negative licensing decisions. The risk for exporters is that attempts to reapply elsewhere for authorisation of the same transaction are very likely to be flagged and scrutinised by all relevant authorities across the EU. Compliance teams should closely track denial notifications throughout the Union and view any such notice as a substantial compliance and enforcement risk.
Source: Regulation (EU) 2021/821 of the European Parliament and of the Council, Article 15
Re-export controls and extraterritorial application — does the EU Dual-Use Regulation cover non-EU re-exports?
Does the EU Dual-Use Regulation apply to re-exports or non-EU parties?
Unlike the US Export Administration Regulations (EAR), which create extensive "reexport" and extraterritorial controls on U.S.-origin goods and certain foreign-made items containing U.S. controlled content, the EU dual-use regime is fundamentally territory-based. Regulation (EU) 2021/821 generally applies to activities conducted by natural or legal persons who are resident or established in the EU customs territory (Article 2(3)), and to export, transfer, brokering, transit, or technical assistance activities that touch the customs territory of the Union.
No general re-export catch: If EU-origin dual-use goods are lawfully exported to a third country, subsequent re-exports by a third-country party are not generally subject to EU law, unless a condition of the original authorisation attaches post-export obligations (e.g., an end-use/end-user restriction or re-export notification) that bind the original exporter or, by contract, the recipient. EU Member States do not assert a regulatory jurisdiction over third-country parties re-exporting EU goods from outside Union territory, except where specific international undertakings or sanctions apply (see Article 32 safeguards).
Extraterritorial scope — limited reach: The Regulation’s extraterritorial controls are narrowly focused. Article 8 (technical assistance) extends to EU citizens and permanent residents acting outside the EU, but this is the exception, not the norm. By contrast, exports, brokering, and transit provisions do not sweep up non-EU actors dealing in EU goods or technology outside the customs union. There is no direct European equivalent of the US de minimis or foreign direct product rules.
Re-export undertakings possible: The granting authority may, under Article 11 or in the terms of an individual or global export authorisation, require the exporter to contractually prohibit unauthorized re-exports, or to seek notification if the recipient intends onward transfer to specified destinations or end-users. This is implemented by contract rather than statutory extraterritoriality, and Article 26 places responsibility for practical guidance on the Commission and Member States. However, such restrictions do not bind third parties absent contractual enforcement.
Sanctions overlay: Certain EU sanctions regimes, especially those established by Council decisions or implementing UN Security Council resolutions, can create re-export and "no re-transfer" rules even for third-country actors. However, such rules operate via international law, not the EU dual-use Regulation, and must be checked separately (see EU Sanctions Map and relevant Council Regulations).
Operational takeaway: Once EU dual-use goods or technology are outside the customs territory, only contractual obligations or parallel international sanctions create a continuing control obligation. EU law does not claim the broad extraterritorial sweep found in US law. Compliance officers managing mixed-origin supply chains should focus on the terms of their original licenses and international sanctions overlays.