skenai
EAR · CCL15 CFR 774, Supplement No. 1, ECCN 5A002

Information security systems and equipment — ECCN 5A002

Controls hardware using cryptography for data confidentiality above stated key length thresholds, whether or not security is the primary function.

The entry, quoted as it reads today

a. Designed or modified to use 'cryptography for data confidentiality' having a 'described security algorithm', where that cryptographic capability is usable, has been activated, or can be activated by any means other than secure “cryptographic activation”, as follows: a.1. Items having “information security” as a primary function; a.2. Digital communication or networking systems, equipment or components, not specified in paragraph 5A002.a.1; a.3. Computers, other items having information storage or processing as a primary function, and components therefor, not specified in paragraphs 5A002.a.1 or .a.2; N.B. : For operating systems see also 5D002.a.1 and .c.1. a.4. Items, not specified in paragraphs 5A002.a.1 to a.3, where the 'cryptography for data confidentiality' having a 'described security algorithm' meets all of the following: a.4.a. It supports a non-primary function of the item; and a.4.b. It is performed by incorporated equipment or “software” that would, as a standalone item, be specified by ECCNs 5A002, 5A003, 5A004, 5B002 or 5D002. N.B. to paragraph a.4: See Related Control Paragraph (4) of this ECCN 5A002 for examples of items not controlled by 5A002.a.4. Technical Notes: 1. For the purposes of 5A002.a, 'cryptography for data confidentiality' means “cryptography” that employs digital techniques and performs any cryptographic function other than any of the following: 1.a. “Authentication;” 1.b. Digital signature; 1.c. Data integrity; 1.d. Non-repudiation; 1.e. Digital rights management, including the execution of copy-protected “software;” 1.f. Encryption or decryption in support of entertainment, mass commercial broadcasts or medical records management; or 1.g. Key management in support of any function described in paragraphs 1.a to 1.f of this Technical Note paragraph 1. 2. For the purposes of 5A002.a, 'described security algorithm' means any of the following: 2.a. A “symmetric algorithm” employing a key length in excess of 56 bits, not including parity bits; 2.b. An “asymmetric algorithm” where the security of the algorithm is based on any of the following: 2.b.1. Factorization of integers in excess of 512 bits (e.g., RSA); 2.b.2. Computation of discrete logarithms in a multiplicative group of a finite field of size greater than 512 bits (e.g., Diffie-Hellman over Z/pZ); or 2.b.3. Discrete logarithms in a group other than mentioned in paragra
15 CFR 774, Supplement No. 1, ECCN 5A002 · retrieved 2026-08-29

Corpus last verified 2026-08-29. Skenai never shows unquoted regulation.

In plain language

5A002.a applies to items designed or modified to use cryptography for data confidentiality with a described security algorithm. The capability must be usable, activated, or activatable by means other than secure cryptographic activation. Dormant hardware capability that can be switched on still counts.

The entry then sorts by where the cryptography sits. Paragraph a.1 covers items whose primary function is information security, and a.2 covers networking equipment. Paragraphs a.3 and a.4 cover computers, and items where confidentiality supports a non-primary function.

Two technical notes carry the thresholds. Cryptography for data confidentiality excludes authentication, digital signature, data integrity, non-repudiation and digital rights management. A described security algorithm means a symmetric key above 56 bits, or an asymmetric algorithm resting on factorisation or discrete logarithms above 512 bits.

The questions this entry turns on

  1. 01Does the item use cryptography for data confidentiality, rather than only authentication, signature or integrity?
  2. 02Is the cryptographic capability usable, activated, or activatable other than by secure cryptographic activation?
  3. 03Does the algorithm use a symmetric key exceeding 56 bits, not counting parity bits?
  4. 04Does an asymmetric algorithm rest on factorisation or discrete logarithms above 512 bits?
  5. 05If confidentiality supports a non-primary function, would the incorporated equipment or software be specified by 5A002 or 5D002 standalone?
Run a Triage on your product

Free, no account. Dossier $249 if you want the record.

What typically falls in, and what typically falls out

Typically in

  • A telemetry radio with AES-256 link encryption, which typically reads onto 5A002.a.2
  • A robot controller running a TLS stack for confidentiality of its data link, typically caught by 5A002.a.4
  • A ground station appliance whose primary function is encrypted data transport, typically caught by 5A002.a.1

Typically out

  • A device using cryptography only for authentication and firmware signature checks
  • A sensor that hashes payload data for integrity and never encrypts it
  • A media device using encryption only for copy protection of software content

These are typical cases, not determinations. Which side a specific product lands on turns on the answers in the Interview.

Adjacent entries

Does your product land on this entry?

The Interview asks 5 to 9 questions, only the ones this entry turns on, and names the Determination free. The Dossier is the dated, cited record of how it was reached.

Run a Triage on your product

Free, no account. Dossier $249 if you want the record.