EU dual-use export controls
Dual-use controls are the part of the framework that catches teams by surprise — because an item can be controlled by what it does, not by the tariff code it sits under.
What "dual-use" means
Dual-use items are goods, software and technology that have legitimate civilian applications but can also be used for military purposes or contribute to the proliferation of weapons of mass destruction. The category is deliberately broad: it takes in machine tools, sensors, encryption software, certain chemicals, telecommunications equipment, navigation systems and a great deal of ordinary industrial equipment that happens to meet a technical threshold.
The EU framework is Regulation (EU) 2021/821, the recast Dual-Use Regulation, which has applied since September 2021. It establishes a Union-wide control regime with a common control list, while leaving licensing itself to the National Competent Authority of each Member State.
How dual-use control differs from sanctions screening
This is the distinction that matters operationally:
- Sanctions annexes list CN codes. You screen by classification code, and the annex tells you whether the code is in scope.
- The dual-use control list works by technical parameter. Entries are described by specification — operating temperature, accuracy, frequency, key length, thickness, purity — and an item is controlled if it meets the parameter, whatever its tariff code. Two products under the same CN code can differ in control status because one exceeds a threshold and the other does not.
The practical consequence: you cannot fully discharge dual-use obligations by screening codes. Code screening tells you where to look; the control determination requires the item's technical datasheet against the control-list entry. Any tool that maps dual-use entries to indicative CN codes — ours included — is giving you a triage signal, not a classification.
The catch-all controls
Even an item that is not on the control list can require authorisation. The regulation contains "catch-all" provisions that bite where the exporter has been informed by the competent authority — or is aware, or has grounds for suspecting — that the item is or may be intended, in whole or in part, for a use of concern. Typical triggers include military end use in an embargoed destination, or a connection to a WMD programme.
Catch-all controls turn knowledge into an obligation. That is why end-use documentation and diversion-risk assessment are part of dual-use compliance rather than optional extras, and why an unusual purchasing pattern or an implausible end user is itself a compliance event.
Licence types
Authorisations come in several forms: Union General Export Authorisations for lower-risk destinations and item categories, subject to conditions and registration; national general authorisations issued by individual Member States; global licences covering multiple shipments to specified consignees; and individual licences for a single transaction. Which is available depends on the item, the destination and the exporter's compliance record — an Internal Compliance Programme is a precondition for some of them.
Where dual-use and sanctions overlap
The two regimes stack rather than replace one another. For an embargoed destination, a dual-use item will typically be caught both by the dual-use regulation and by the country sanctions regulation — and the sanctions prohibition is usually the stricter of the two, removing licensing routes that would otherwise exist. Screening one and not the other leaves a real gap in both directions.
Several EU sanctions instruments also cross-refer to the EU Common Military List, and the Iran UAV regulation is an example of a measure built around components rather than finished goods.
Practical steps
- Build and maintain a technical file for each product, sufficient to test it against control-list parameters.
- Classify against the control list on the technical file, not on the tariff code.
- Screen the CN code against the sanctions annexes separately — both determinations are needed.
- Assess end use and end user, and record the assessment, so a catch-all trigger is visible before shipment rather than after.
- Establish an Internal Compliance Programme proportionate to your exposure.
- Re-check on every control-list update, and whenever a product's specification changes.
Step three is what TRADESANCTIONS.EU automates: screening a catalogue of codes against the EU sanctions regimes in one pass, with the annex, article and derogations attached to each hit. Steps one, two and four remain engineering and compliance judgement — no tool substitutes for the technical file. Start with the screening overview if you are building the control from scratch.
Frequently asked questions
- What are dual-use goods?
- Dual-use items are goods, software and technology with legitimate civilian uses that can also serve military purposes or contribute to weapons proliferation. In the EU they are controlled under Regulation (EU) 2021/821, which applies a common control list across all Member States while leaving licensing to national authorities.
- Is dual-use screening the same as sanctions screening?
- No. Sanctions annexes list Combined Nomenclature codes, so you screen by classification. The dual-use control list describes items by technical parameter, so an item is controlled if it meets a specification regardless of its tariff code. Two products sharing a CN code can differ in dual-use status. Both determinations are required, and neither substitutes for the other.
- Can an item that is not on the dual-use control list still need a licence?
- Yes. The catch-all provisions require authorisation where the exporter has been informed by the competent authority, or is aware or has grounds for suspecting, that the item may be intended for a use of concern such as a military end use in an embargoed destination or a WMD programme. This applies to items that appear nowhere on the control list.
- Which regulation governs EU dual-use exports?
- Regulation (EU) 2021/821, the recast Dual-Use Regulation, which has applied since September 2021. It replaced the earlier Regulation (EC) No 428/2009 and broadened the framework, notably in relation to cyber-surveillance items and compliance programme expectations.