Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Linux Foundation’s 15 July 2021 update described a narrower U.S. export-control notification requirement for certain publicly available encryption software: under its account, email notifications were required for software implementing “non-standard cryptography,” rather than for all such software classified under ECCN 5D002. That was a dated explanation of one change—not a complete or current statement of U.S. export law. Open source status alone does not answer every export-control or sanctions question.

What changed in the Linux Foundation’s 2021 update?

The Linux Foundation said its 15 July 2021 update reflected a change to the U.S. Export Administration Regulations (EAR). Previously, its guidance said, email notifications were required for publicly available encryption software classified under ECCN 5D002 whether or not its cryptography was standardized. Following the change described in the update, notifications were required only for software implementing “non-standard cryptography.”

This summary concerns the notification treatment described by the Foundation in 2021. It should not be read as a statement that every open-source project is exempt from export rules, or as a substitute for checking the rules that apply to a particular release today.

When does public availability matter under the EAR?

The Foundation’s expanded guidance explains that the EAR applies to items “subject to the EAR.” It describes exports as potentially including electronic availability of software to people outside the United States, as well as certain releases of technology within the United States.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In that explanation, publicly available open-source technology can be considered “published” when it is available without restrictions on further dissemination. The Foundation lists public software, specifications, hardware design files, and binaries as examples. Its explanation is an industry publisher’s account of the EAR, not the regulation itself; whether a particular item qualifies depends on the applicable rules and facts.

How does encryption affect a project’s obligations?

The Foundation’s expanded guidance distinguishes standard from non-standard cryptography in the context of the provision it discusses. It says that, as of 2021, projects using standard cryptography had no additional requirements or analysis under that provision, while software implementing non-standard cryptography classified under ECCN 5D002 might still require email notification.

That distinction does not establish that a project has correctly classified its software or that no other requirements apply. The Foundation recommends that projects using encryption consider the following practices:

  • Identify whether the software uses standard or non-standard cryptography and assess whether ECCN 5D002 is relevant.
  • Where a notice is required, retain evidence that it was delivered; the Foundation also recommends making delivered notices publicly available.
  • Identify a responsible legal entity and contact where applicable.
  • If distributing encryption software in object-code form, keep the corresponding source code publicly available, consistent with the Foundation’s guidance.
  • Use source-code scanning tools as an aid, not as proof that encryption has or has not been detected; the Foundation cautions that automated scanning is imperfect.

What should projects consider when publishing technical information?

The Foundation recommends keeping technical conversations, decisions, and outcomes public when feasible. Private exchanges may not meet the public-availability condition described in its guidance. For security disclosures, it suggests considering publication after a fix is available rather than keeping the information permanently within a confidential list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same guidance notes a 2020 addition concerning certain neural-network-driven geospatial analysis training and says publicly available software in that category may receive the published treatment. That limited point does not establish how any particular technology or release should be classified.

Does a project’s public source release settle the position for redistributors?

No. The Foundation’s explanation addresses the open-source project itself. A downstream redistributor shipping modified code or a derived product whose source is not publicly available must assess its own circumstances. The original project’s public release does not, by itself, answer whether the redistributor’s version or product meets the relevant conditions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are OFAC sanctions covered by the 2021 EAR update?

No. Export controls under the EAR and sanctions administered by the Office of Foreign Assets Control (OFAC) are distinct regimes. In a 29 January 2025 article, the Linux Foundation cautioned that sanctions may apply to transactions or interactions even when software or technology is publicly available, and that the application of sanctions to open-source activity is not fully defined. The EAR’s treatment of published material therefore does not automatically resolve sanctions questions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.