Export Controls for Hardware Startups: The EAR/ITAR Compliance Guide Every Deeptech Founder Needs Before Shipping Internationally
Hardware startups shipping internationally face EAR/ITAR export control obligations they may not know exist. Learn ECCN classification, deemed export rules for foreign-national engineers, BIS license exceptions, and real enforcement penalties before you ship.
If you're building a hardware startup in Texas—a state that hosts semiconductor giants like Texas Instruments, Samsung Austin, and NXP—export controls are probably not the first compliance issue on your radar. But they should be. The Bureau of Industry and Security (BIS) has dramatically escalated enforcement of the Export Administration Regulations (EAR), particularly against semiconductor and advanced computing companies. If your deeptech startup ships hardware internationally, shares technical data with foreign-national engineers, or even accepts CHIPS Act funding, you may already be subject to federal export control obligations you don't know exist.
Here's the reality: as of January 2025, the maximum administrative penalty for an EAR violation is $374,474 per violation or twice the transaction value, whichever is greater. Criminal penalties can reach up to $1 million and 20 years of imprisonment per violation. And these aren't hypothetical risks—BIS has been actively pursuing semiconductor companies for violations ranging from Entity List shipments to deemed export failures.
In this guide, we walk through the five things every hardware founder needs to understand before shipping internationally: how to determine whether EAR or ITAR applies, how to self-classify your product, how deemed export rules affect your foreign-national hires, what license exceptions might save you time, and what enforcement actually looks like in practice.
EAR vs. ITAR: Which Regime Applies to Your Hardware?
U.S. export controls operate through two primary regulatory frameworks, and knowing which one governs your product is step one.
The Export Administration Regulations (EAR)
The EAR, codified at 15 CFR Parts 730–774, is administered by the Bureau of Industry and Security within the Department of Commerce. It governs "dual-use" items—technologies that have both commercial and potential military applications. Most hardware startups will fall under EAR jurisdiction because their products are commercial in nature but could conceivably have defense applications. Think semiconductors, advanced computing chips, sensors, lasers, and telecommunications equipment.
The International Traffic in Arms Regulations (ITAR)
ITAR, codified at 22 CFR Parts 120–130, is administered by the Directorate of Defense Trade Controls (DDTC) within the Department of State. It governs defense articles and defense services listed on the United States Munitions List (USML). If your hardware is specifically designed, developed, or modified for military applications—such as missile components, military-grade night vision systems, or certain firearms technology—ITAR likely applies.
How to Tell Which One Applies
The key distinction is whether your item is "inherently military" (ITAR/USML) or "dual-use" (EAR/Commerce Control List). This isn't always obvious. A drone designed for agricultural surveying might be EAR-controlled, while the same drone adapted for military reconnaissance could be ITAR-controlled. When the jurisdiction is unclear, you can submit a Commodity Jurisdiction request to DDTC, which will formally determine whether your item belongs on the USML or the CCL.
For most hardware startups, especially in the semiconductor and deeptech space, EAR will be the applicable regime. But the consequences of getting this wrong are severe—if you assume EAR applies when ITAR actually governs, you could face DDTC enforcement for unregistered arms trafficking. And if you're building anything with even a plausible defense application, you should get your compliance house in order early, before you start shipping or hiring.
Self-Classification: ECCN vs. EAR99
Once you've determined that the EAR applies, the next step is classifying your item. Every item subject to the EAR must be assigned either an Export Control Classification Number (ECCN) or the designation EAR99.
What EAR99 Means
According to the International Trade Administration, "most of the products, services, and technologies that fall within the scope of the EAR are not specifically controlled for export, and are given the classification of EAR99." These are generally low-technology consumer goods that don't require a license in most situations. However, EAR99 items still require careful due diligence—you cannot ship to embargoed countries, prohibited end-users, or for prohibited end-uses without a license.
When You Need an ECCN
An ECCN is a five-digit alphanumeric designation that identifies items on the Commerce Control List (CCL) because they have specific performance characteristics, technical parameters, or designed end-uses that warrant control. For hardware startups, the most relevant CCL categories include:
- Category 3: Electronics—includes semiconductors, microprocessors, and integrated circuits
- Category 4: Computers—includes high-performance computing systems and related equipment
- Category 5 Part 1: Telecommunications
- Category 5 Part 2: Information Security—includes encryption technology
- Category 6: Sensors and Lasers
For semiconductor startups, ECCN 3A001 is particularly important—it covers controlled microcircuits, and the specific technical parameters (like clock frequency, transistor count, or manufacturing process node) determine whether your chips are controlled. The October 2023 and December 2023 BIS rule changes significantly expanded the scope of controlled semiconductor items, meaning many advanced chips that were previously uncontrolled now require licenses for export to certain destinations.
Self-classification involves reviewing your product's technical specifications against the CCL criteria. You can also request a formal classification from BIS through the SNAP-R system, which provides legal certainty but can take months. Many startups self-classify initially and seek formal confirmation as they scale. The important thing is to document your classification rationale—if BIS asks, you need to show you made a good-faith effort to classify correctly.
Deemed Exports: When Hiring a Foreign-National Engineer Is an Export
This is the export control trap that catches the most hardware founders by surprise. Under the EAR, sharing controlled technology with a foreign person inside the United States is "deemed" to be an export to that person's country of nationality. This means that giving a foreign-national engineer access to controlled technical data—through blueprints, source code, engineering discussions, or even lab tours—can constitute an export requiring a BIS license.
How Deemed Exports Work
The deemed export rule is described in Section 734.13(b) of the EAR. A "release" of controlled technology occurs when technology is made available to a foreign person through visual inspection, oral exchange, or by applying the technology under the foreign person's direction. The release is "deemed" to be an export to the person's country or countries of nationality—meaning if you have an H-1B engineer from a country that requires a license for your ECCN-controlled technology, you may need a deemed export license before that engineer can work on the project.
Who Is Exempt
U.S. citizens, U.S. permanent residents (green card holders), and persons granted status as "protected individuals" under 8 U.S.C. 1324b(a)(3) are exempt from the deemed export rule. The rule applies to foreign nationals on H-1B, OPT, L-1, TN, and other temporary work visas. It also applies to dual nationals—a foreign national with citizenship in both a friendly country and a restricted country may trigger licensing requirements based on the restricted nationality.
Practical Steps for Hardware Startups
If you're hiring foreign-national engineers to work on ECCN-controlled technology, you should:
- Classify your technology first. You can't assess deemed export risk until you know your ECCN and the reason for control.
- Screen each foreign-national employee's country of nationality against the EAR's country chart for your specific ECCN's control reason.
- Apply for deemed export licenses through BIS's SNAP-R system before releasing controlled technology. BIS publishes deemed export licensing guidelines to help with this process.
- Implement technology control plans (TCPs) that segregate controlled technology from unauthorized access, including badge access controls, IT system permissions, and lab access restrictions.
This is not just a large-company problem. Even a five-person startup with one H-1B engineer working on controlled semiconductor designs may need a deemed export license. And as we discussed in our post about why startup employment policies can't wait, getting these fundamentals right from day one is far cheaper than fixing problems after a violation.
BIS License Exceptions: STA, TSR, and When They Apply
Not every export of ECCN-controlled items requires a full license application. The EAR provides license exceptions—authorizations described in Part 740 of the EAR that allow you to export or reexport controlled items under stated conditions without submitting a formal license application. For hardware startups, two exceptions are particularly relevant.
License Exception STA (Strategic Trade Authorization)
License Exception STA, found in Section 740.20 of the EAR, is one of the most broadly useful exceptions. It authorizes exports, reexports, and transfers of certain EAR-controlled items to eligible destinations—primarily Country Group A:5, which includes close U.S. allies such as the United Kingdom, Japan, Australia, and most NATO members. STA applies to items controlled for national security (NS), regional stability (RS), or anti-terrorism (AT) reasons, but not to items controlled for missile technology (MT) or chemical/biological weapons (CB) reasons.
To use STA, the consignee must be a "STA-eligible" end-user, and the exporter must maintain records demonstrating eligibility. STA can significantly streamline exports to allied countries, but it does not apply to Entity List parties or embargoed destinations.
License Exception TSR (Technology and Software, Restricted)
License Exception TSR, found in Section 740.6, authorizes exports of certain technology and software to Country Group A:1 destinations, which include most developed nations. TSR applies to technology controlled for national security reasons and can be particularly useful for startups sharing technical data with partners or subsidiaries in allied countries.
License Exception NAC (Notified Advanced Computing)
For semiconductor and AI hardware startups, License Exception NAC (Section 740.8) has become increasingly important following the October 2023 expanded controls on advanced computing items. NAC allows exports of certain advanced computing items to specified destinations, but requires prior notification to BIS through SNAP-R. This exception is narrower than STA or TSR and comes with significant conditions, so careful review is essential before relying on it.
License exceptions are powerful tools, but they are not a substitute for classification and screening. You still need to know your ECCN, verify your end-user against the Entity List and other restricted-party lists, and maintain documentation. Misapplying a license exception doesn't just negate the exception—it creates an independent violation.
Enforcement Risk: Real Cases and Real Penalties
The enforcement landscape for export controls has shifted dramatically. BIS's 2024 Export Enforcement Year in Review highlighted a record number of cases focused on semiconductor and advanced technology transfers. Understanding how enforcement works in practice helps founders grasp what's at stake.
The GlobalFoundries Case
In November 2024, BIS imposed a $500,000 penalty on GlobalFoundries for 74 violations of the EAR involving unauthorized exports to SJ Semiconductor (SJS), a company on BIS's Entity List. Between February 2021 and October 2022, GlobalFoundries shipped approximately 5,700 semiconductor wafers valued at $17 million to SJS without the required BIS licenses.
The root cause was surprisingly mundane: a data-entry error in GlobalFoundries' Oracle Global Trade Management module listed the wrong "ship-to" party, causing the automated screening system to miss SJS's Entity List designation. This case illustrates that export compliance failures often stem from internal process gaps—not from intentional wrongdoing. For a startup without GlobalFoundries' compliance infrastructure, the risk is even greater.
Penalties: What You're Actually Exposed To
According to BIS's official penalties page, violations of the EAR can result in both criminal and administrative penalties:
- Criminal: Up to 20 years imprisonment and up to $1 million in fines per violation
- Administrative: Up to $374,474 per violation or twice the transaction value, whichever is greater (as of January 2025, adjusted annually for inflation)
- Denial of export privileges: BIS can deny your ability to participate in any export transaction subject to the EAR, which can effectively shut down an international hardware business
Beyond formal penalties, there's reputational damage, loss of government contracts, and the potential for related enforcement actions from OFAC or the Department of Justice. The Entity List itself is a compliance trap—shipping to a listed party without authorization is a strict liability violation, meaning intent doesn't matter.
CHIPS Act Guardrails
If your startup accepts CHIPS Act funding, additional export-control-adjacent obligations apply. The CHIPS Act Guardrails Rule, published in September 2023, prohibits covered entities from expanding semiconductor manufacturing in foreign countries of concern for ten years and restricts joint research or technology licensing with foreign entities of concern. Violations can result in recovery of the full amount of the CHIPS award. Entities on BIS's Entity List are also designated as "foreign entities of concern" under the Guardrails Rule, creating overlapping compliance obligations.
Actionable Next Steps
Export control compliance can feel overwhelming, but the path forward is manageable if you approach it systematically. Here's what we recommend for hardware founders:
- Determine jurisdiction. Assess whether your product falls under EAR or ITAR. If there's any plausible defense application, consider filing a Commodity Jurisdiction request with DDTC for certainty.
- Classify your items. Self-classify against the Commerce Control List or engage an export compliance specialist to assign ECCNs. Document your rationale—BIS expects a good-faith classification process.
- Audit your workforce. Identify every foreign-national employee, contractor, and collaborator who has or will have access to controlled technology. Cross-reference their countries of nationality against the EAR country chart for your ECCNs.
- Screen your customers and partners. Run every export transaction against the Entity List, Denied Persons List, Unverified List, and OFAC's SDN List. Automated screening tools exist, but even manual checks are better than none.
- Evaluate license exceptions. For exports to allied countries, determine whether STA, TSR, or NAC might apply—but verify eligibility carefully before relying on any exception.
- Build a technology control plan. Implement access controls, IT system permissions, and physical security measures that prevent unauthorized access to controlled technology.
- Consider voluntary self-disclosure. If you discover a potential violation, BIS's Voluntary Self-Disclosure program can significantly reduce penalties. GlobalFoundries received a relatively modest penalty in part because it self-disclosed.
- Get professional help early. As with stock issuance decisions that can make or break your startup, getting export control fundamentals right at the formation stage is far less expensive than remediation after a violation.
Export controls are not just a large-company concern. For deeptech and semiconductor startups operating in Texas's booming hardware ecosystem, EAR and ITAR compliance is a fundamental business risk that deserves attention from day one. The penalties are severe, the enforcement environment is aggressive, and the rules have expanded dramatically with the U.S.-China tech competition. But with proper classification, screening, and documentation, most hardware startups can navigate these requirements without stifling their growth.
Building a hardware startup and unsure whether your products, technical data, or foreign-national hires trigger EAR or ITAR obligations? We help deeptech and semiconductor founders classify their technology, implement compliance programs, and navigate BIS licensing before they ship.