5A004 Category 5A
“Systems,” “equipment” and “components” for defeating, weakening or bypassing “information security,” as follows (see List of Items Controlled).
Category 5: Telecommunications and “Information Security”
Reasons for control
- NS: National security
- RS: Regional stability
- AT: Anti-terrorism
- EI
Country chart
| Control | Column |
|---|---|
| AT applies to entire entry | AT 1 |
| EI applies to entire entry | None |
| NS applies to entire entry | NS 1 |
| RS applies to items controlled by 5A004.z.1.a, z.2.a | None |
| RS applies to items controlled by 5A004.z.1.b, z.2.b | None |
List-based license exceptions
| Exception | As stated in the entry |
|---|---|
| ENC | Yes for certain EI controlled commodities. See § 740.17 of the EAR for eligibility. NAC/ACA: Yes, for 5A004.z.1.b, z.2.b AIA: Yes for 5A004.z.1.a, z.2.a ACM: Yes for 5A004.z LPP: Yes for 5A004.z.1.a, z.2.a |
| GBS | N/A |
| LVS | Yes: $500 for “components”; N/A for 5A004.z. N/A for systems and equipment. |
Items
- a. Designed or modified to perform 'cryptanalytic functions.'
- b. Items, not specified by ECCNs 4A005 or 5A004.a, designed to perform all of the following:
- b.1. 'Extract raw data' from a computing or communications device; and
- b.2. Circumvent “authentication” or authorization controls of the device, in order to perform the function described in 5A004.b.1.
- c. through y. [Reserved]
- z. Other commodities, as follows:
- z.1.a Commodities that are described in 5A004.a and that also meet or exceed the performance parameters in 3A090.a or 4A090.a;
- z.1.b Commodities that are described in 5A004.a and that also meet or exceed the performance parameters in 3A090.b or 4A090.b;
- z.2.a Commodities that are described in 5A004.b and that also meet or exceed the performance parameters in 3A090.a or 4A090.a; or
- z.2.b Commodities that are described in 5A004.b and that also meet or exceed the performance parameters in 3A090.b or 4A090.b.
Related controls
(1) ECCN 5A004.a controls “components” providing the means or functions necessary for “information security.” All such “components” are presumptively “specially designed” and controlled by 5A004.a. (2) See also ECCNs 3A090 and 4A090.
Notes
Note: See § 740.2(a)(9)(ii) of the EAR for license exception restrictions for ECCN 5A004.z.
Note: 5A004.a includes systems or equipment, designed or modified to perform 'cryptanalytic functions' by means of reverse engineering.
Technical Note: For the purposes of 5A004.a, 'cryptanalytic functions' are functions designed to defeat cryptographic mechanisms in order to derive confidential variables or sensitive data, including clear text, passwords or cryptographic keys.
Technical Note: For the purposes of 5A004.b.1, 'extract raw data' from a computing or communications device means to retrieve binary data from a storage medium, e.g., RAM, flash or hard disk, of the device without interpretation by the device's operating system or filesystem.
Note 1: 5A004.b does not apply to systems or equipment specially designed for the “development” or “production” of a computing or communications device.
Note 2: 5A004.b does not include: a. Debuggers, hypervisors; b. Items limited to logical data extraction; c. Data extraction items using chip-off or JTAG; or d. Items specially designed and limited to jail-breaking or rooting.
Source: eCFR, version
2026-08-01, retrieved
2026-08-20T04:04:59+00:00.