Examples
Worked examples
- Is an instance
A university lab imports a piece of dual-use test equipment for a federally funded project. The export control office runs it through BIS's Commerce Control List 'Order of Review' (15 CFR Part 774, Supplement No. 4), checking the item's technical parameters against the relevant Category and Product Group entries. It matches an entry describing equipment above a specified performance threshold, so it is self-classified under that ECCN rather than EAR99, and any subsequent export or foreign-national access is evaluated against that classification, separately from whether the research results themselves qualify for the fundamental research exclusion.
- Is an instance
A PI's lab develops custom software with cryptographic functionality as part of a research tool. Because encryption classification can be technically ambiguous and carries higher compliance risk if misclassified, the export control office submits a formal classification request to BIS through the Simplified Network Application Process Redesign (SNAP-R) system, per 15 CFR 748.3, rather than relying on self-classification. BIS's response -- a CCATS determination with an assigned tracking number -- becomes the institution's documented, authoritative classification for that item going forward.
Counter-examples
Looks similar, but isn't
- Not an instance
A researcher assumes that because their project is basic research intended for open publication, none of the equipment or code involved needs an ECCN determination at all. This confuses the fundamental research exclusion (which can apply to research *results*) with item/technology classification (which applies to what is *used* to produce those results) -- a controlled instrument or software package does not lose its EAR classification just because the surrounding project is publishable, and using it, or letting a foreign national operate it, can still trigger a licensing requirement independent of the exclusion.
Editorial commentary
The ECCN determination process is how a research institution’s export control office figures out whether a specific item, software package, or piece of technology is controlled under the US Export Administration Regulations (EAR), and if so, which Export Control Classification Number (ECCN) applies. The EAR (15 CFR Parts 730-774) are administered by the Department of Commerce’s Bureau of Industry and Security (BIS) and control “dual-use” items — those with both civilian and military, terrorism, or weapons-of-mass-destruction-related applications — through the Commerce Control List (CCL).
Every ECCN is a five-character alphanumeric code with a defined structure: the first digit (0-9) identifies the broad product category (for example, Category 3 covers electronics, Category 5 covers telecommunications and information security), the second character (A-E) identifies the product group within that category (A = equipment/assemblies/components, B = test/inspection/production equipment, C = materials, D = software, E = technology), and the final three digits identify the specific CCL entry and the reasons for control attached to it (national security, missile technology, nuclear nonproliferation, and so on). If an item is subject to the EAR but does not match any CCL entry, it is designated EAR99 — a residual catch-all that generally does not require a license for most destinations and end users, though restricted parties, end uses, or embargoed destinations can still trigger a license requirement even for an EAR99 item.
Two paths to a determination
Institutions reach a classification one of two ways:
- Self-classification. Export control staff (or, informally, a researcher) work through the CCL’s own “Order of Review” (15 CFR Part 774, Supplement No. 4) and BIS’s public tools — the interactive CCL and classification decision tools published on bis.gov — comparing the item’s actual technical parameters against CCL entries to reach a classification in-house. Self-classification is an accepted, routine method and is what export control offices use for the large majority of items, provided the technical parameters are clear-cut.
- Requesting a formal Commodity Classification from BIS. Where an item’s parameters are genuinely ambiguous, sit close to a control threshold, or the compliance risk of getting it wrong is high (encryption items are a common example), an institution can submit a classification request to BIS itself under 15 CFR 748.3, filed electronically through BIS’s Simplified Network Application Process Redesign (SNAP-R) system. BIS’s response is tracked and returned through the Commodity Classification Automated Tracking System (CCATS) — a formal, BIS-issued determination with its own tracking number that the institution can then rely on as documented, authoritative evidence of the item’s classification if the determination is later questioned.
Self-classification is faster and is the default for routine items; a formal BIS request takes longer (commonly cited in export-control practitioner guidance as taking on the order of weeks to a couple of months, though BIS does not publish a fixed processing-time guarantee) but removes classification uncertainty and shifts the documented determination to the regulator itself.
Why this matters for fundamental research exclusion analysis
The fundamental research exclusion, rooted in National Security Decision Directive 189 (1985), can remove a university project’s published results from EAR or ITAR control when the research is basic or applied research intended for open publication with no restriction on results. It does not, however, retroactively declassify the specific items, software, or technical data used to conduct that research. An export-controlled instrument, code library, or dataset brought into an otherwise fully publishable project keeps its own classification, and using it — or allowing a foreign national to operate it, which can itself constitute a deemed export — can trigger a licensing obligation independent of whether the resulting research paper is exclusion-eligible. This is exactly why export control offices run an ECCN determination on the equipment, software, and technical inputs to a project as a distinct step from evaluating whether the project’s outputs qualify for the fundamental research exclusion; the two analyses answer different questions and a favorable answer on one does not resolve the other. See the guide Export Control (EAR/ITAR) and International Research Collaboration for how this determination fits into the broader compliance workflow, and Technology Control Plan (TCP) for the controls typically put in place once an item is confirmed controlled.
References
- Export Administration Regulations, 15 CFR Parts 730-774, and the Commerce Control List, 15 CFR Part 774 (including the Order of Review at Supplement No. 4), administered by the Bureau of Industry and Security, US Department of Commerce.
- 15 CFR 748.3, Classification requests and advisory opinions; BIS SNAP-R electronic filing system; BIS “Classify Your Item” guidance, bis.gov/licensing/classify-your-item.
- National Security Decision Directive 189 (1985), National Policy on the Transfer of Scientific, Technical and Engineering Information.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="ECCN Determination Process"
vocab-term-identifier="https://casrai.org/dictionary/term/eccn-determination-process" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/eccn-determination-process",
"name": "ECCN Determination Process",
"identifier": "https://casrai.org/dictionary/term/eccn-determination-process",
"description": "The process by which a specific item, technology, or piece of software is assigned an Export Control Classification Number (ECCN) under the US Export Administration Regulations (EAR, 15 CFR 730-774), determining whether and how it is controlled for export under the Commerce Control List (CCL) administered by the Department of Commerce's Bureau of Industry and Security (BIS). An item is either classified against a specific ECCN entry on the CCL, or, if it is subject to the EAR but matches no CCL entry, falls into the residual 'EAR99' catch-all category. Determination can be done in-house by self-classification against the CCL, or by requesting a formal, binding Commodity Classification from BIS (a Commodity Classification Automated Tracking System, or CCATS, determination). In a university research setting, the outcome of this determination is a prerequisite input to fundamental research exclusion analysis: the exclusion (rooted in NSDD-189, 1985) can remove a project's published *results* from EAR/ITAR control, but it does not retroactively declassify a controlled *item, software, or technical data set* used to get there -- so export control offices classify the underlying technology first, independent of whether the surrounding research is intended for open publication.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/research-security#set",
"url": "https://casrai.org/dictionary/term/eccn-determination-process",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-18T06:30:48",
"inLanguage": "en"
}






