Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

EU Dual-Use Export Control Regulation 2021/821 and Internal Compliance Programmes

A guide to the EU’s dual-use export control regime for universities and research organisations: Regulation (EU) 2021/821, Commission Recommendation (EU) 2021/1700 on internal compliance programmes, and the 2025 Annex I control-list update.

Most of CASRAI’s export-control content covers the US regime — the Export Administration Regulations (EAR), the International Traffic in Arms Regulations (ITAR), and the Empowered Official role that ITAR requires. Those mechanics do not apply to a university or research organisation operating under EU law. The European Union runs its own, structurally different dual-use export control regime — Regulation (EU) 2021/821 — with its own control list, its own guidance on internal compliance programmes for research organisations specifically, and its own 2025 update cycle. This guide covers that regime on its own terms, without conflating it with US mechanics.

What Regulation (EU) 2021/821 actually controls

Regulation (EU) 2021/821 of 20 May 2021 (in force since 9 September 2021) is the EU’s dual-use export control regulation — a recast of the earlier Regulation (EC) 428/2009. It sets up an EU-wide system for controlling the export, brokering, technical assistance, transit, and transfer of dual-use items: goods, software, and technology that can be used for both civilian and military purposes, or that can contribute to the proliferation of weapons of mass destruction.

For a research organisation, three features of the Regulation matter more than the general trade-compliance mechanics:

  • “Technology” is controlled independently of the medium it’s transferred in. The Regulation’s definitions cover technology and software transferred by electronic means, fax, or telephone, as well as technical assistance delivered orally — not only physical shipments. In practice, this reaches presentations, training, code repositories, and knowledge shared with a foreign national working in an EU lab, in a way that a narrow reading of “export” as a physical shipment would miss.
  • Catch-all controls extend beyond the listed items on Annex I: an export can require authorisation if the exporter is informed, or has reason to suspect, that items are or may be intended for use connected to weapons of mass destruction, military end-use in an embargoed destination, or (following changes carried over from the 2021 recast) serious human rights concerns tied to cyber-surveillance items.
  • The 2021 recast added human-rights-based controls on cyber-surveillance items that did not exist under the 2009 predecessor regulation — a genuinely new category of dual-use control, not just a list update, and one that can catch research involving surveillance, monitoring, or interception technology that has no obvious military application.

Authorisation requirements and general authorisations vary by destination and item; the operative text (and its amendments) is maintained on EUR-Lex, which is the authoritative source for the current consolidated text and should be checked directly for any authorisation decision, not summarised secondhand.

Commission Recommendation (EU) 2021/1700: internal compliance programmes for research organisations

Regulation (EU) 2021/821 itself does not tell a university how to build a compliance function. That guidance comes from Commission Recommendation (EU) 2021/1700, issued specifically to help research organisations — and the researchers, research managers, and compliance staff inside them — identify, manage, and mitigate dual-use export-control risk, and build an internal compliance programme (ICP) proportionate to their activity.

The Recommendation is non-binding — Member States and research organisations are encouraged to take account of it, not mandated to adopt it verbatim — but it is the closest thing the EU has to an official ICP template for the sector, and it builds on the same general ICP framework the Commission set out for exporters broadly (Recommendation (EU) 2019/1318) rather than inventing a separate structure from scratch. An ICP under that framework is generally organised around a recurring set of elements: visible senior-management commitment to compliance; a defined organisational structure with clear responsibility (who in the institution actually owns export-control risk, and with what authority and resources); training and awareness-raising for staff and researchers who handle controlled items, software, or technology; a transaction- and activity-screening process that flags red-flag indicators before a transfer, collaboration, or visit proceeds; recordkeeping and documentation sufficient to demonstrate what was screened and why; physical and information security controls over controlled items and technology; and periodic internal review, audit, and corrective action.

What 2021/1700 adds on top of that general skeleton is research-specific: guidance tailored to how dual-use risk actually shows up on a campus rather than in a trading company — incoming and outgoing researcher and visiting-scholar screening, international collaboration and joint-publication review, conference and training-material review, and the tension between export-control screening and the norms of open scientific exchange and academic freedom that a university-specific ICP has to navigate in a way a commercial exporter’s ICP does not.

Because the Recommendation is guidance rather than law, the size, risk profile, and activity mix of the institution is meant to shape how much of it applies — a large technical university running classified or defence-adjacent contract research needs a materially more developed ICP than a humanities-heavy institution with little dual-use exposure. Building a genuinely proportionate ICP starts with an honest institutional risk assessment (what disciplines, what collaborations, what visiting-researcher flows actually create exposure), not with adopting the full structure by default.

The 2025 update to the control list: Commission Delegated Regulation (EU) 2025/2003

Annex I of Regulation (EU) 2021/821 — the actual list of controlled dual-use items — is not static. It is updated periodically to track decisions made within the multilateral export control regimes the EU implements (the Australia Group, the Missile Technology Control Regime, the Nuclear Suppliers Group, the Wassenaar Arrangement, and the Chemical Weapons Convention), plus EU-specific additions where member states agree on a control that hasn’t yet been adopted multilaterally.

Commission Delegated Regulation (EU) 2025/2003, adopted 8 September 2025 and published in the Official Journal on 14 November 2025 (entering into force the following day, 15 November 2025), replaced Annex I in full with an updated list. For research organisations, the substantive change worth tracking is scope, not just item count: the 2025 update broadens controls across several technology areas that map directly onto active university research portfolios — semiconductors, quantum technologies, advanced computing, additive manufacturing (3D printing), biotechnology, materials science, and space-related items — along with a new tranche of “500-series” item entries and amendments to existing definitions and control parameters.

The practical implication for a compliance office: a research group or export-control review that classified a technology as uncontrolled under the pre-2025 Annex I should not assume that classification still holds, particularly in the technology areas above. Annex I classification is not a one-time determination — it needs to be re-checked against the current consolidated text whenever the list is amended, and the current text (not a summary, including this one) is the only thing to rely on for an actual export decision. The consolidated Regulation, with Annex I as amended, is published on EUR-Lex.

How this differs from the US EAR/ITAR regime

Institutions operating internationally, or evaluating US-trained compliance staff against an EU obligation, should not assume the two regimes map onto each other cleanly. CASRAI’s Export Control (EAR/ITAR) and International Research Collaboration guide and The Four Pillars of Export Control Compliance cover the US mechanics in depth; a few structural differences worth flagging explicitly here rather than assuming:

  • No single “fundamental research exclusion” carve-out in the same form. US EAR/ITAR practice leans heavily on the fundamental research exclusion to keep most unclassified, publicly-shareable university research outside controlled-technology scope. Regulation (EU) 2021/821 does not build its research-sector treatment around an equivalent single carve-out — which is exactly why a research-organisation-specific ICP recommendation (2021/1700) exists: the EU addresses academic dual-use risk through tailored compliance guidance rather than a blanket exclusion.
  • No single “Empowered Official” role. ITAR requires a specific, personally-liable Empowered Official to authorise controlled defense-article transactions. The EU ICP framework instead calls for a defined organisational structure and clear internal responsibility — the specific title, reporting line, and authority are left to the institution and (where applicable) national implementing measures, not fixed by the EU framework itself.
  • Different list architecture and update cadence. The EAR’s Commerce Control List and Regulation 2021/821’s Annex I both implement the same multilateral regimes (Wassenaar, Australia Group, MTCR, NSG) but are separate legal instruments, updated on separate schedules, with separate national licensing authorities behind them — a US CCL classification is not evidence of an EU Annex I classification, or vice versa.
  • Enforcement and licensing sit with individual EU member states, not a single EU-level agency — Regulation (EU) 2021/821 sets the common framework, but each member state designates its own competent authority for licensing decisions and enforcement, which is a meaningfully different institutional landscape than the US Bureau of Industry and Security (EAR) / Directorate of Defense Trade Controls (ITAR) structure.

A multinational research organisation with both EU and US operations needs both compliance tracks running in parallel, mapped separately — treating one regime’s screening outcome as satisfying the other is a real and recurring source of compliance gaps.

How this relates to Horizon Europe research-security screening

CASRAI’s Horizon Europe Research Security guide covers a related but distinct obligation: the EU’s “as open as possible, as closed as necessary” framing for Horizon Europe-funded projects, and the sensitive-technology screening that can apply to grant applicants and participants under that programme. That framework is a funding-programme mechanism — it governs eligibility and conduct within Horizon Europe grants specifically. Regulation (EU) 2021/821 is a trade-law mechanism — it applies to any covered export, transfer, or technical assistance involving dual-use items, regardless of whether the underlying research is Horizon Europe-funded, funded by another source, or unfunded. A project can be fully compliant with Horizon Europe’s research-security screening and still trigger a separate dual-use export-control obligation under 2021/821, or vice versa — the two frameworks need to be checked independently, not treated as substitutes for one another.

Building a proportionate ICP: where to start

Recommendation (EU) 2021/1700 is guidance, not a checklist to complete mechanically. Institutions that have implemented it in some workable form generally start from the same sequence:

  1. Map actual dual-use exposure before designing controls — which departments, disciplines, funded projects, and international collaborations plausibly touch Annex I items, controlled technology, or the newer cyber-surveillance/human-rights catch-all, rather than assuming exposure is uniform across the institution.
  2. Assign clear ownership for export-control screening and decisions, with a documented escalation path to the institution’s designated national competent authority when a licence question arises.
  3. Build screening into points where risk actually enters — incoming visiting-researcher and collaboration agreements, outgoing technology or software transfers, conference presentations and training materials involving controlled technical content, and procurement or partnership decisions involving embargoed or restricted destinations.
  4. Train the people who trigger the obligation day to day — principal investigators, international-office staff, and lab managers, not only a central compliance office that never sees the underlying research.
  5. Re-check Annex I classifications against the current consolidated text whenever a new Delegated Regulation amends it — 2025/2003 is the current version as of this writing, but it will not be the last.
  6. Document the screening that was done, even where the conclusion was “not controlled” — recordkeeping is one of the recurring ICP elements precisely because a defensible compliance programme needs to show its work, not just its conclusions.

Frequently asked questions

Is Regulation (EU) 2021/821 the same thing as ITAR or the EAR?

No. They are separate legal regimes in separate jurisdictions, implementing overlapping but not identical multilateral commitments, with different control lists, different exemption structures, and different enforcement authorities. An institution operating in both the EU and the US needs to run both compliance tracks, not assume one satisfies the other.

Is an ICP under Recommendation (EU) 2021/1700 legally required?

The Recommendation itself is non-binding guidance, not a legal mandate — but Regulation (EU) 2021/821 does impose binding obligations (authorisation requirements, catch-all screening, recordkeeping expectations tied to actual export decisions), and some EU member states attach ICP-related expectations to their own national implementing measures or to specific licence types (such as global or general authorisations, where an effective ICP can be a precondition). Institutions should check their own member state’s national implementing rules rather than assume the EU-level Recommendation is the complete picture.

Does “dual-use” here mean the same thing as Dual-Use Research of Concern (DURC)?

No, and this is a common point of confusion. Dual-Use Research of Concern (DURC) is a life-sciences biosecurity concept — research that is legitimate and beneficial but could be misapplied to cause harm, reviewed through an institutional biosafety framework. “Dual-use items” under Regulation (EU) 2021/821 is a trade-law export-control concept covering a much broader range of goods, software, and technology (not limited to life sciences) whose transfer across a border, or to a foreign national, is what triggers the control — not the nature of the research itself. An institution can have DURC obligations, export-control obligations under 2021/821, both, or neither for the same project.

Where is the authoritative text of Regulation (EU) 2021/821 and its amendments?

EUR-Lex maintains the consolidated text. Because Annex I is amended periodically (2025/2003 being the most recent as of this writing), any classification decision should be checked against the current consolidated version, not a saved or summarised copy.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →