In brief: The Foreign Direct Product Rule (FDPR), codified at 15 CFR § 734.9, extends U.S. export-control jurisdiction to items made entirely outside the United States when those items are the “direct product” of specified U.S.-origin technology or software, or are produced by a plant (or a major component of one) that is itself such a direct product. For research institutions, FDPR exposure most often surfaces through foreign-made lab equipment built on U.S.-origin design tools, and through international collaborations where a foreign-made item later moves to a restricted destination or end user. Most FDPR problems are handled as civil/administrative matters by the Bureau of Industry and Security (BIS). Criminal liability is a separate, higher bar: it requires proof of a willful violation under 50 U.S.C. § 4819, prosecuted by the Department of Justice, and it can reach individuals — not just the institution.
What Is the Foreign Direct Product Rule?
The FDPR is one of the mechanisms by which the Export Administration Regulations (EAR) reach beyond items physically located in the United States. Under 15 CFR § 734.9, a foreign-made item can become “subject to the EAR” — and therefore subject to the same licensing requirements as a U.S.-origin item — if it is the direct product of certain controlled U.S.-origin technology or software, or if it was produced using a plant, or a major component of a plant, that is itself the direct product of such technology or software. In practice this means a piece of equipment manufactured entirely overseas, by a non-U.S. company, using no U.S.-origin parts, can still fall under EAR jurisdiction if the design or manufacturing process traces back to controlled U.S. technology.
This is a jurisdictional expansion, not a separate list of controlled items: the FDPR determines whether the EAR applies to a foreign-made item at all, and once it does, the item is generally treated the same as any other EAR-controlled item for licensing purposes.
The FDPR Has Several Destination-Specific Variants
15 CFR § 734.9 sets out a general FDP rule plus several narrower, destination- or end-user-specific variants that BIS has added over time as its scope has expanded. The two most consequential for research institutions with international ties are:
- The Russia/Belarus FDP rule (734.9(f)): covers foreign-produced items that are the direct product of specified U.S.-origin software or technology, or produced by a plant or major component that is itself such a direct product, when the exporter, reexporter, or transferor knows the item is destined for Russia or Belarus.
- The Russia/Belarus-Military End User FDP rule (734.9(g)): a broader variant that reaches the direct product of a wide range of software and technology (EAR “product group” D or E, i.e., software and technology) under essentially any Export Control Classification Number, when destined for a Russian or Belarusian military end user or an entity flagged with the Entity List’s “footnote 3” designation — including entities 50% or more owned by a listed party.
An Entity List-specific FDP rule applies more generally to certain parties named on the BIS Entity List, independent of the Russia/Belarus destination. Because these variants layer on top of the general rule and change periodically as BIS amends the regulation, an institution should not assume a foreign-made item is FDPR-clear just because it isn’t shipped directly from the United States — the current rule text at 15 CFR § 734.9 (available via the eCFR) is the authoritative source, and export control staff should re-check it against any new collaboration or procurement involving a listed country, entity, or military end user.
Why This Reaches Research Institutions
Export control compliance in research settings is usually framed around outbound technology transfer: sharing controlled technical data with a foreign national in the lab (a deemed export) or shipping U.S.-origin, EAR- or ITAR-controlled hardware abroad. The FDPR adds a less intuitive exposure: equipment and instrumentation an institution buys, rather than exports, can itself be FDPR-covered if it was manufactured overseas using controlled U.S.-origin design software, fabrication tools, or technology — a scenario that arises most often with advanced semiconductor, computing, and precision-manufacturing equipment. Reexporting, transferring, or even providing remote access to such equipment to a restricted destination or listed party can trigger the same licensing requirements as if the item had shipped directly from the United States.
International research collaborations compound this: a project that shares controlled technology with a foreign partner institution, which then incorporates it into equipment manufactured in a third country, can create an FDPR-covered item without anyone in the chain having exported anything from the United States directly. This is a distinct question from whether the underlying research itself qualifies for the fundamental research exclusion — a project can be openly published fundamental research and still involve equipment or components that are separately FDPR-covered for export purposes. See CASRAI’s guides on export control and international research collaboration, the ECCN lookup process for research equipment, and ITAR and the U.S. Munitions List for the related classification groundwork.
How Criminal Liability Attaches: The Willfulness Standard
Most FDPR and broader EAR violations are resolved as civil, administrative matters. BIS’s Office of Export Enforcement can impose civil penalties directly, without a criminal conviction, and without having to prove the higher criminal standard of intent. Under 50 U.S.C. § 4819, the civil penalty ceiling is a fine of the greater of a set statutory amount (subject to periodic inflation adjustment) or twice the value of the underlying transaction, per violation.
Criminal liability is a separate track, reserved for willful violations. 50 U.S.C. § 4819 makes it a crime to willfully commit, attempt, conspire to commit, or aid and abet a violation of the Export Control Reform Act or any regulation, order, license, or authorization issued under it — which includes the EAR and its FDPR provisions. A willful violation carries a fine of up to $1,000,000, and for an individual, up to 20 years’ imprisonment, or both. The willfulness requirement is the key distinction from civil exposure: export-control criminal enforcement generally requires the government to show the defendant acted with knowledge that the conduct was unlawful, not merely that a violation occurred through negligence, carelessness, or a compliance failure. That said, “knowledge” in export-control law can be established through actual knowledge or through conscious avoidance of facts that would have made the violation apparent — a research office cannot insulate itself from criminal exposure simply by not asking questions it had reason to ask.
The Department of Justice, principally through its National Security Division working with U.S. Attorneys’ offices, brings criminal export-control prosecutions under this and related statutes (including IEEPA-based sanctions provisions where applicable). BIS’s civil enforcement and DOJ’s criminal enforcement are not mutually exclusive — the same conduct can be pursued civilly, criminally, or both, depending on the facts BIS and DOJ develop.
Institutional vs. Individual Exposure
Both the institution and specific individuals can face liability for the same conduct, and the two are assessed somewhat differently:
- Institutional exposure can arise under general federal principles of corporate criminal liability, which can attribute a violation to the institution when an employee acting within the scope of their duties commits it, at least in part, to benefit the institution or its programs (for example, obtaining or preserving an international research relationship or piece of equipment). Civil, administrative FDPR/EAR liability under BIS’s enforcement authority does not require this “corporate benefit” analysis at all — it can attach to the institution as the exporter or reexporter of record regardless of individual intent.
- Individual exposure falls on the person or people who actually caused the violation — commonly the principal investigator directing the collaboration, an export control officer who cleared a transaction improperly, or a researcher who personally shipped, transferred, or granted access to a covered item or technology. A PI’s or export control officer’s personal criminal exposure is a genuinely separate question from the institution’s; an institution that reaches a favorable resolution with DOJ or BIS does not automatically protect an individual employee from prosecution for their own willful conduct.
DOJ’s Enforcement Posture: The Disruptive Technology Strike Force
In February 2023, the Department of Justice and Department of Commerce announced the creation of a joint Disruptive Technology Strike Force, co-led by the Assistant Attorney General for DOJ’s National Security Division and the Assistant Secretary for Export Enforcement at BIS. The Strike Force is directed at preventing sensitive technology — including advanced computing, biotechnology, and other dual-use categories relevant to university and national-lab research — from being illegally acquired or diverted by hostile actors, and represents a standing, cross-agency structure specifically built around aggressive investigation and prosecution of export-control diversion schemes, including FDPR-covered conduct. For institutions with substantial international research equipment procurement or collaboration involving advanced computing, semiconductor, or similar technology, this is the enforcement body most likely to be involved if a case escalates beyond a routine BIS administrative inquiry.
Voluntary Self-Disclosure Can Materially Change the Outcome
DOJ’s National Security Division maintains a voluntary self-disclosure (VSD) policy specific to export control and sanctions violations, most recently reinforced in a September 2022 department-wide enforcement policy announcement. Under that policy, when an organization (1) voluntarily self-discloses a potential export control violation, (2) fully cooperates with the resulting investigation, and (3) timely and appropriately remediates the underlying problem, there is a presumption that DOJ will decline prosecution or offer a non-prosecution agreement without a fine — absent aggravating factors such as egregious conduct, senior management involvement, or a significant national security harm. This does not eliminate civil exposure with BIS, and it does not automatically extend the same protection to an individual employee whose own conduct was willful, but it is a substantial, real mitigating pathway for an institution that discovers a potential FDPR or broader export-control problem internally.
The practical implication for research administration: an institution that discovers a possible FDPR issue — for example, learning that equipment shared with an international partner was reexported to a restricted destination, or that a piece of foreign-manufactured equipment turns out to be FDPR-covered after the fact — is generally far better positioned by disclosing promptly through export control counsel than by staying silent and hoping the issue does not surface through a BIS inquiry, an audit, or a whistleblower.
Practical Risk-Avoidance Steps
- Classify before you collaborate or procure. Determine the correct Export Control Classification Number (ECCN) for equipment and technology involved in a collaboration or purchase, using self-classification or BIS’s SNAP-R commodity classification process where the classification is genuinely unclear — see CASRAI’s ECCN lookup guide.
- Screen the full chain, not just the direct counterparty. Check collaborators, equipment vendors, and downstream partners against the BIS Entity List and other restricted-party lists before sharing technology or accepting foreign-made equipment into a project, particularly where China, Russia, Belarus, or an Entity List-flagged party is anywhere in the supply or collaboration chain.
- Don’t assume the fundamental research exclusion resolves FDPR exposure. The exclusion addresses whether published, open research is subject to the EAR at all; it does not resolve whether a specific foreign-made instrument, component, or piece of equipment used in that research is itself FDPR-covered for procurement, transfer, or reexport purposes.
- Document due diligence contemporaneously. Screening records, classification determinations, and internal sign-offs are exactly the evidence that distinguishes a good-faith compliance program (relevant both to negating willfulness and to VSD eligibility) from the kind of conscious avoidance that can support a criminal case.
- Escalate ambiguity early, to export control staff and counsel — not after the fact. Because FDPR classification questions turn on manufacturing and technology-transfer details that are rarely obvious from a purchase order or MOU, ambiguous cases should go to the institution’s export control officer or legal counsel before equipment ships, before access is granted, or before a collaboration agreement is signed, not after a problem is flagged externally.
Frequently Asked Questions
Is the Foreign Direct Product Rule the same thing as a deemed export?
No. A deemed export is the release of controlled technology or technical data to a foreign national physically present in the United States, treated as an export to that person’s home country. The FDPR is a jurisdictional rule that determines whether a foreign-made item, manufactured entirely outside the United States, is subject to the EAR at all because of the U.S.-origin technology or software behind its design or production. The two can interact — a deemed export of controlled technology to a foreign national who later uses it to help manufacture an item abroad can be the trigger that makes that foreign-made item FDPR-covered — but they are legally distinct concepts.
Can a university or research institution be criminally prosecuted, not just fined administratively?
Yes. Institutions face civil/administrative penalties from BIS as a matter of course for EAR and FDPR violations, but where the government can show a willful violation under 50 U.S.C. § 4819, DOJ can bring a criminal case against the institution itself, in addition to or instead of any individual involved, under general corporate criminal liability principles.
What does “willful” actually require the government to prove?
Broadly, that the person or institution acted with knowledge that the conduct violated the law, rather than through mere negligence, carelessness, or a good-faith misunderstanding of a genuinely ambiguous classification. Knowledge can be shown directly or through evidence of deliberate avoidance of facts that would have revealed the violation.
Does self-reporting a possible FDPR problem make things worse?
Generally not, and it is often the better path. DOJ’s National Security Division voluntary self-disclosure policy creates a presumption of declination or a non-prosecution agreement for an organization that discloses promptly, cooperates fully, and remediates the underlying issue, absent aggravating factors. This is a decision to make with export control counsel promptly upon discovering a potential issue, not something to defer.
Who within a research institution is most exposed to personal criminal liability?
Whoever actually directed or knowingly participated in the willful conduct — most often a principal investigator managing an international collaboration or an export control officer who cleared a transaction. Institutional-level cooperation with DOJ or BIS does not automatically shield an individual whose own conduct meets the willfulness standard.
This guide provides general information on FDPR criminal-liability mechanics for research administration purposes. It is not legal advice; institutions facing an actual or suspected FDPR or export-control issue should engage export control counsel directly, and promptly.







