Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

Sanctions, Embargoes, and Countries of Concern in University Research

OFAC sanctions, BIS/ITAR export controls, the CHIPS Act’s countries of concern, and the DOJ’s Data Security Program under EO 14117 are four separate regimes, not one list. A decision guide mapping research activities — data sharing, shipping, payments, visiting scholars — to the regime, the office, and the list that applies.

Ask about Sanctions, Embargoes, and Countries of Concern in University Research

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Last verified: August 16, 2026. Sanctions, export-control, and “countries of concern” designations change on their own schedules and are maintained by different federal agencies. This guide explains how the pieces fit together and where to check current designations — it is general orientation, not a substitute for an institution-specific determination from your export control officer, empowered official, or general counsel.

“Countries of concern” is not one list. It is a phrase used, with different meanings and different legal consequences, by at least four separate federal regimes: Treasury’s OFAC sanctions program, Commerce’s export-control system (the EAR), the CHIPS and Science Act’s research-security provisions, and the Department of Justice’s newer Data Security Program under Executive Order 14117. A country can appear on one of these lists and not another, and a research activity can trigger one regime while being entirely untouched by the others. A university research office that treats “countries of concern” as a single fixed list will misroute the easy cases and miss the hard ones.

This guide is written for the research administrator who needs to recognize when a sanctions, embargo, or countries-of-concern issue is in play — a collaborator’s institutional affiliation, an item or dataset headed abroad, a payment to a foreign national, a visiting scholar’s onboarding — and to route it to the right office and the right list before, not after, the activity happens.

The distinct regimes that use “countries of concern” language

Each of the following operates independently, with its own designated list, its own trigger, and its own updating process. Treat them as separate questions, not one lookup.

  • OFAC comprehensive sanctions and embargoes (Treasury Department, Office of Foreign Assets Control) — a short list of countries and regions subject to broad, near-total restrictions on transactions, plus the much longer Specially Designated Nationals (SDN) list of specific blocked individuals and entities anywhere in the world. This is the list most people mean by “OFAC sanctioned countries” or “embargoed countries.” CASRAI covers the current list and its research implications in detail in Embargoed Countries List for Export Control; see also the OFAC List (SDN List) dictionary entry. The authoritative source is Treasury’s Sanctions Programs and Country Information page and the SDN list itself, both at treasury.gov/ofac.
  • BIS export controls (Commerce Department, Bureau of Industry and Security) — the Export Administration Regulations (EAR) control the export, re-export, and in-country transfer of dual-use items, software, and technology based on the item’s classification (ECCN) and the destination, end user, and end use, including the BIS Entity List of specific restricted parties. See CASRAI’s ITAR/EAR compliance guide and the Commerce Control List (CCL) and ECCN dictionary entries.
  • ITAR arms embargoes (State Department) — a separate list of countries subject to policy-based arms embargoes under 22 CFR 126.1, layered on top of the general International Traffic in Arms Regulations controls on defense articles and services. See ITAR US Munitions List (USML).
  • The CHIPS and Science Act’s statutory “countries of concern” (Title VI, Part B) — a narrow, named list (China, Russia, Iran, and North Korea by statute, with authority for the Secretary of State to designate additional countries) that underpins two specific research-administration obligations: the Malign Foreign Talent Recruitment Program (MFTRP) prohibition and Foreign Financial Disclosure Reporting (FFDR). CASRAI covers this list and exactly which restrictions attach to it in Countries of Concern Under the CHIPS and Science Act, and covers the MFTRP prohibition itself in Malign Foreign Talent Recruitment Program (MFTRP).
  • The DOJ Data Security Program’s “countries of concern” (28 CFR Part 202, implementing Executive Order 14117) — a list specific to this one program, governing transactions in bulk U.S. sensitive personal data and government-related data. It is not the same list as the CHIPS Act’s, and it is not the same list as OFAC’s embargoed countries. See the dedicated section below.

Some university export-control or research-security offices publish a single internal reference — sometimes described informally as a “countries of concern list” running to a couple dozen entries — that combines several of these regimes (OFAC-embargoed countries, ITAR arms-embargoed countries, State Sponsors of Terrorism, and CHIPS Act designations) into one screening checklist for convenience. That combined count is an institutional aggregation, not a single federal designation, and it will vary between institutions and change as any one underlying list changes. If you encounter a specific number attached to a “countries of concern list,” confirm which underlying source list(s) it aggregates and its as-of date before relying on it, rather than treating the number itself as a fixed federal designation.

When this actually comes up in research administration

These regimes rarely announce themselves. They surface inside ordinary research-administration workflows:

  • Setting up a subaward or collaboration agreement with a foreign institution or company
  • A prospective collaborator, co-PI, or visiting scholar’s institutional affiliation or funding history
  • Shipping equipment, reagents, biological materials, or physical samples abroad
  • Granting access to controlled software, source code, or a cloud environment to a foreign national, on campus or remotely (a “deemed export”)
  • Sharing human-subjects, genomic, biometric, or health datasets with a foreign collaborator, contractor, or cloud vendor
  • Hosting a visiting scholar, paying an honorarium, or reimbursing travel for someone based abroad
  • Accepting a gift, contract, or foreign talent recruitment offer connected to a country of concern
  • Selecting lab or field equipment with encryption, sensing, or other dual-use technical characteristics for an international project

The table below maps these activities to the regime(s) that may apply, who in the institution to ask first, and what actually gets screened. It is a starting point for routing, not a substitute for a case-by-case determination.

Decision table: activity, regime, and who to ask

What you’re doing Regime(s) that may apply Who to ask first What gets screened
Sharing a dataset — especially genomic, health, biometric, or precise geolocation data — with a foreign collaborator, contractor, or cloud vendor DOJ Data Security Program (28 CFR Part 202, EO 14117); possibly EAR if the data is also export-controlled technical data Export control officer / empowered official, plus privacy or IRB office Data category and volume against DSP bulk thresholds; recipient’s country and any “covered person” relationship; whether a restricted, prohibited, or exempt transaction category applies
Shipping equipment, biological materials, software, or technical data abroad EAR (ECCN classification, Entity List), ITAR (US Munitions List), OFAC embargoes Export control officer Item classification (ECCN/USML category); destination country; end user and end use against the BIS Entity List and OFAC SDN list
Paying an honorarium, consulting fee, or subaward to a foreign person or entity OFAC sanctions (SDN and blocked-persons lists); possibly BIS restricted-party lists Export control officer, sponsored programs, and accounts payable Restricted-party screening of the payee against the OFAC SDN list and BIS Entity, Denied Persons, and Unverified Lists
Hosting a visiting scholar or foreign national in a lab or on a project Deemed-export rules under the EAR/ITAR; NSPM-33 disclosure obligations; MFTRP if the scholar’s prior program qualifies Export control officer and research security office Citizenship and prior institutional affiliations; technology or data access the individual will have and whether a deemed-export license is needed
Receiving a gift, contract, or recruitment offer connected to a country of concern CHIPS Act Foreign Financial Disclosure Reporting; MFTRP certification Research security office or conflict-of-interest office Dollar value against the FFDR threshold; the funding source’s country against the CHIPS Act countries-of-concern list
Entering an MOU, collaboration agreement, or software license with an entity in a comprehensively sanctioned country OFAC comprehensive embargo (may require a specific or general OFAC license) Export control officer and general counsel Counterparty’s country against OFAC’s current comprehensively-sanctioned-countries list
Selecting equipment or software with encryption, sensing, or other dual-use technical characteristics for an international project EAR classification, drawn from Commerce Control List categories that track the multilateral Wassenaar Arrangement dual-use list Export control officer ECCN classification of the specific item or software; destination and end-user screening

Executive Order 14117 and the DOJ Data Security Program: what’s new for data sharing

Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern,” was signed on February 28, 2024, and directed the Department of Justice to establish a regulatory program — the Data Security Program (DSP), codified at 28 CFR Part 202 — restricting certain transactions that would give countries of concern, or entities/individuals connected to them, access to bulk U.S. sensitive personal data or specified government-related data.

For a university research office, the categories the rule reaches are the ones to register: it addresses bulk transfers of categories such as genomic and other biometric data, precise geolocation data, personal health data, and personal financial data, alongside certain government-related data regardless of volume, when the transaction involves a country of concern or a covered person connected to one. That description covers real research activity — multi-site genomic studies, international health-data collaborations, biometric datasets shared with a foreign subcontractor or cloud vendor.

Two things matter more than any summary of the rule’s mechanics:

  • The DSP designates its own list of “countries of concern” for this specific program — a different designation from the CHIPS Act’s countries of concern and from OFAC’s comprehensively-embargoed countries. Do not assume a country’s status under one list carries over to this one. Confirm the current designated countries, the exact data categories and volume thresholds, and the transaction exemptions directly at the Department of Justice’s National Security Division Data Security Program materials and at 28 CFR Part 202, rather than from any secondary summary, including this one.
  • The rule reaches transactions — data brokerage, vendor, employment, and investment agreements meeting its definitions — not research activity in the abstract. Whether a specific data-sharing arrangement with a foreign collaborator, contractor, or cloud vendor falls inside a restricted or prohibited category, or inside an exemption, is a determination for your export control office or general counsel, informed by the actual data types, volumes, and counterparties involved.

The fundamental research exclusion doesn’t automatically cover this

The fundamental research exclusion is an export-control concept: under NSDD-189 and the EAR/ITAR framework, basic and applied research intended for open publication, with no restrictions on publication or foreign-national participation, generally falls outside export-control jurisdiction. It is a well-established, load-bearing principle for university export-control offices — but it is specific to that framework.

It does not automatically extend to OFAC sanctions (an embargoed-country transaction can still be restricted even where the underlying research is fundamental), to the CHIPS Act’s MFTRP prohibition or Foreign Financial Disclosure Reporting requirement, or to the DOJ Data Security Program’s data-transaction restrictions, each of which has its own scope and its own exemptions, if any. Don’t assume fundamental-research status resolves a sanctions, CHIPS Act, or DSP question just because it resolves an EAR/ITAR classification question — check each regime on its own terms, or ask your export control office to do so.

The Wassenaar Arrangement: the multilateral framework behind export-control lists

The Wassenaar Arrangement is a multilateral export-control regime established in 1996, with 42 participating states. It maintains two control lists — a Munitions List and a Dual-Use Goods and Technologies List — covering conventional arms and sensitive dual-use technologies. It is not itself a country-of-concern list, and it is not directly binding: participating states agree to maintain their own national export controls consistent with the Wassenaar lists, implemented through domestic legislation, and decisions are made by consensus at an annual plenary.

For a US university, the practical relevance is upstream of any single transaction: the Commerce Control List that BIS maintains under the EAR tracks, and periodically updates in response to, changes agreed at Wassenaar’s plenary meetings, particularly for dual-use categories like semiconductors, telecommunications equipment, cryptography, and certain sensing and aerospace technologies. An ECCN classification that was accurate last year can become outdated when Wassenaar’s control list changes and BIS updates the CCL accordingly — one more reason equipment and software classifications used in international collaborations need periodic re-checking, not a one-time determination. See CASRAI’s ECCN and Commerce Control List (CCL) entries, and the ITAR/EAR compliance guide for how classification review actually works.

Restricted-party screening ties these regimes together operationally

Because a single collaborator, vendor, or destination can implicate several of these regimes at once, most institutions run restricted-party screening as one operational process that checks a name or entity against multiple lists together — the OFAC SDN list, the BIS Entity, Denied Persons, and Unverified Lists, and State Department nonproliferation lists — rather than running a separate check per regime. CASRAI covers how that screening process actually works, including when it’s required, who performs it, and how to handle a potential match, in Restricted Party Screening. This guide is about recognizing which regimes are in play and where to route the question; that one is about the mechanics of running the check itself.

Practical steps for a research-administration office

  • Ask the routing questions early, ideally at proposal or agreement drafting, not after a shipment is packed or a dataset is ready to transfer: What country is the counterparty, destination, or funding source in? What is the item, software, service, or data category involved? Who is the individual, and what is their institutional history?
  • Screen at every stage where a new party or destination enters the picture — proposal submission, award and subaward setup, vendor and visiting-scholar onboarding, shipping, and data-transfer agreements — not as a single one-time check.
  • Route to the right office for the right regime: export control officer or empowered official for EAR/ITAR and OFAC questions; research security or conflict-of-interest office for CHIPS Act MFTRP/FFDR and NSPM-33 disclosure questions; privacy office and export control jointly for DOJ Data Security Program data-transaction questions; general counsel where a license or formal determination may be needed.
  • Keep a record of screening results and the reasoning behind any “no regime applies” determination, not just the flagged matches — that record is what an audit or federal inspection will ask to see.
  • Don’t self-determine a close call. These lists change, the categories are technical, and the consequences of a wrong call — unlicensed export, a prohibited transaction, a false certification — are institutional and sometimes personal liability. Escalate.

Frequently asked questions

Is the “countries of concern list” the same as the OFAC sanctioned-countries list?

No. OFAC’s comprehensively-embargoed countries, the CHIPS and Science Act’s statutory countries of concern, and the DOJ Data Security Program’s countries of concern are three separate designations maintained by three different parts of the federal government, updated on different schedules, for different purposes. A country can appear on one and not the others. Check the specific list that governs the specific regime in question rather than assuming one list answers for all of them.

Does the fundamental research exclusion cover data-sharing under the DOJ Data Security Program?

Not automatically. The fundamental research exclusion is an export-control (EAR/ITAR) concept. The DOJ Data Security Program is a separate regulatory regime under Executive Order 14117 with its own scope and its own exemptions, if any apply to a given transaction. Confirm the DSP’s own exemption structure at 28 CFR Part 202 rather than assuming fundamental-research status resolves it.

What triggers restricted-party screening for a research collaboration?

Typically the introduction of a new counterparty, destination, or funding source into a project — a new collaborator or subrecipient institution, a vendor, a visiting scholar, a shipment destination, or a payment recipient. See Restricted Party Screening for when institutions typically require it and how re-screening of existing relationships is handled.

Does the Wassenaar Arrangement itself restrict what a US university can export?

No. The Wassenaar Arrangement is not self-executing and not directly binding on US institutions. What actually restricts a US export is the Commerce Control List under the EAR (and the US Munitions List under ITAR), which the US maintains as its own national implementation, informed by but not identical to the Wassenaar lists.

Who should a university ask before assuming a country isn’t on any relevant list?

The export control officer or empowered official for EAR/ITAR and OFAC questions, and the research security office for CHIPS Act and NSPM-33 questions. Given how often these lists change and how narrowly some of them are defined, a negative determination is worth documenting through that office rather than relying on an informal check.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →