LODLINE
EN / SV

compliance-sanctions-cyber

Export control and dual-use classification: step by step

Export control and dual-use classification: step by step follows five sequential decisions: identify whether a product, piece of software or technology has an actual or potential military application, match it against the applicable control list, screen the destination and end-user, decide whether a licence is required, and document the assessment before the first shipment leaves Sweden.

Who this concerns

The obligation applies to any Swedish entity that exports, brokers, transfers or discloses controlled goods, software or technology, regardless of size or sector. In practice the question comes up most often for manufacturers of electronics, sensors, precision machine tools, encryption products, aerospace components, specialty chemicals and materials with both civilian and military applications. It also reaches transactions that do not look like exports at all: uploading source code to a server outside Sweden, giving a foreign engineer remote access to a design file, or briefing a visiting researcher on a controlled process can all count as a transfer under the wider compliance, sanctions and cyber practice that governs cross-border trade in sensitive goods and technology.

Group structures raise the same question internally. Moving technology to a foreign subsidiary, letting an overseas parent company access a Swedish research server, or routing production through a contract manufacturer abroad is treated the same way as a sale to an external customer: the classification step has to happen before the transfer, not after a customs query.

Research institutions and universities sit inside the same perimeter whenever they host visiting researchers from outside Sweden or share controlled data sets with a foreign partner. A grant agreement or an academic collaboration agreement does not substitute for a classification file; it sits alongside it.

What the law says

Sweden classifies and licenses dual-use trade under two layers that apply in parallel. The first is the EU dual-use regime, directly applicable in every member state, which sets out the control list determining which goods, software and technology require a licence before they leave the customs territory of the Union. The second is national strategic products legislation, which extends control to military items and to certain civilian goods the EU regime does not reach, and which designates the national authority responsible for issuing, amending, suspending and revoking licences.

Both layers work from the same starting question: does the item, on its technical parameters, match a category on the current control list, or does it fall under a catch-all clause because the exporter knows or has reason to suspect an end-use connected to weapons of mass destruction, an arms embargo or a sanctioned end-user? Under Swedish law as it currently stands, that second question survives even when the item itself is not listed anywhere, which is why classification cannot stop at a catalogue lookup.

Sanctions regimes add a third, overlapping layer. A transaction can be lawful under the dual-use regime and still be blocked because the counterparty, the destination or the ultimate parent company appears on a restrictive measures list. Where the buyer, the end-user or the group structure sits outside Sweden, the classification step has to be run against all three layers together, not sequentially, because a licence granted under one regime does not clear the other two.

How it works in practice

A defensible classification file is built in a fixed order. Skipping a step, or reordering them to fit a shipping deadline, is the single most common source of a licensing problem that surfaces months later during an audit.

Step 1: Describe the item on its technical parameters, not its catalogue name

Classification starts from what the product actually does, not from its marketing description or its harmonised customs tariff code. Two products with the same commercial name can sit on opposite sides of a control threshold once their processing speed, frequency range, encryption strength or chemical purity is measured against the list criteria. The technical file has to record the parameters that were checked, the source of each figure, and the date the check was performed.

Step 2: Match against the current control list and the catch-all clauses

The item is checked against the control list category by category, and separately against the catch-all clauses that apply regardless of listing: end-use connected to weapons of mass destruction, military end-use in an embargoed destination, or an end-user already subject to restrictive measures. A negative result on the list does not close the file until the catch-all question has also been answered and recorded.

Step 3: Screen the destination, the end-user and the chain behind them

Destination screening covers the immediate buyer, any intermediate consignee, the stated end-user and, where the corporate structure makes it relevant, the ultimate parent company. A distributor in a low-risk jurisdiction does not remove the need to identify who receives the goods after resale; brokered transactions are screened at every link in the chain, not only at the first one.

Step 4: Decide the licence type

Once the product is classified and the destination is screened, the exporter decides whether an individual licence, a general licence or a global licence covering repeated shipments to the same destinations is the right instrument. The choice depends on how repetitive the trade flow is, how sensitive the destination is, and how much post-shipment reporting the exporter is prepared to run.

Step 5: Assemble the supporting documents

A complete file typically includes the technical description used for classification, the end-user statement or end-use certificate, evidence of the screening carried out on the buyer and consignee, the internal sign-off on licence type, and, where the transaction relies on an exemption, the reasoning for why the exemption applies. Missing any one of these is what most often turns a routine licence application into a request for further information.

Step 6: Submit, respond to queries and track the decision

Applications are submitted to the competent national authority with the assembled file attached. Queries from the authority are answered on the file already prepared rather than reconstructed from memory, which is why the documentation step above is not optional even for shipments the exporter considers low risk. The decision, once issued, states any conditions, the validity period and the destinations or end-users it actually covers.

Step 7: Re-classify when the product, the buyer or the group changes

A classification is not permanent. A firmware update, a change in encryption strength, a new end-user on an existing contract, or a change in the ownership of the counterparty all trigger a fresh classification, because the licence in place was granted against a specific configuration of product, destination and end-user.

Step 8: Treat intangible transfers the same way as physical shipments

Software downloads, cloud access, remote technical assistance and briefings to foreign nationals are transfers in the same sense as a container leaving a port, and they are classified before they happen, not logged afterwards. This is also where export control intersects with cross-border data flows: technology embedded in a data set or a platform accessible from outside the EEA raises the same review points covered in personal data transfers outside the EEA, and the two assessments are usually run together rather than separately.

Step 9: Keep the audit trail after the licence is granted

A licence decision is not the end of the file. Shipments made under a general or global licence are logged against the conditions stated in the decision, and the file is kept in a state that would let a third party reconstruct why a given shipment was considered covered, not just that it went ahead.

What to check before the first shipment

  • The technical parameters actually measured against the current control list, not the parameters assumed from the product name
  • Whether a catch-all clause applies independently of the list result
  • The identity of every party in the chain: buyer, consignee, end-user and, where relevant, the ultimate parent
  • Whether the destination or any party in the chain is subject to a restrictive measures list
  • Which licence type the transaction actually qualifies for, and whether it covers repeat shipments
  • Whether the end-user statement matches the stated use in the commercial contract
  • Whether the classification file has been updated since the last product revision

Does classification also cover software and technical data, not just physical goods?

Yes. The control list applies to software and technology in the same way it applies to hardware, and the transfer can take the form of a download, a remote access session or a technical briefing rather than a shipment. An assessment that only checks the physical goods leaving a warehouse misses the transfers that most often go unclassified.

Is a licence required for moving dual-use technology within the same corporate group?

It can be. A transfer to a foreign subsidiary, a foreign parent company or an overseas contract manufacturer is treated the same way as a transfer to an external customer once the technology crosses a border or becomes accessible from outside Sweden. Intra-group agreements do not remove the classification step; at most they change which licence type fits the pattern of repeat transfers.

What happens if a product is exported before classification is completed?

The exporter carries the exposure for a transfer made without the required licence, regardless of whether the omission was deliberate or the result of an incomplete review. Consequences reach the individual shipment and the exporter's standing to receive future licences, and they are not limited to a fine calculated after the fact.

The numbers

No statutory maximum processing period is published for a licence application; the length of the review depends on how complete the file is when it is submitted and on how sensitive the authority considers the destination or the end-user. A file that arrives with the technical parameters, the screening results and the end-user statement already assembled moves through review faster than one the authority has to complete by asking follow-up questions, but neither path carries a guaranteed number of weeks.

The control list itself is amended periodically at EU level, and a classification carried out against last year's list is not a defence if the item has since moved onto or off a category. The version in force on the date of the transfer is the one that matters, which is why a classification file records the list version checked, not only the result.

Licence validity periods, where a licence is granted, are set by the authority in the decision itself rather than by a fixed statutory term, and a licence for one destination or end-user does not extend to a different one even within the same shipment window. Record-keeping obligations attach to the file itself and outlast the shipment they relate to, which is why the file is built to be read by someone who was not in the room when the shipment went out.

Where it usually goes wrong

Assuming the harmonised customs tariff code decides the outcome. Two items with the same code can sit on opposite sides of a control threshold, and the tariff code was designed for duty calculation, not for dual-use screening.

Screening only the first party in the chain. A distributor cleared as low risk does not clear the end-user it sells on to, and brokered transactions are screened at every step, not at the point of first sale.

Assuming a general or global licence already in place covers a new destination or a new end-user by default. Licences are granted against a specific configuration; a new counterparty or a new country is a new classification question, not an extension of the existing file.

Treating remote access, cloud hosting and technical briefings as outside the scope because nothing physically crossed a border. Intangible transfers are transfers, and the classification obligation attaches at the moment the technology becomes accessible from outside Sweden, not at the moment a physical shipment would have occurred.

Where the boundary genuinely shifts is the intra-group case: a wholly Swedish transaction between two Swedish entities does not raise an export control question at all, however sensitive the product, because nothing leaves Swedish jurisdiction. The moment a foreign parent, a foreign subsidiary or a foreign contract counterparty enters the picture, that boundary disappears and the full classification sequence applies, including the catch-all and sanctions screening described above.

What to do next

The steps above cover what a compliance team can run internally: technical description, list matching, destination screening, licence-type decision and documentation. Where the exercise usually needs outside input is at the catch-all judgment call, at the sanctions overlap when a counterparty sits in a grey zone, and at the point where a licence condition needs to be read against an actual contract rather than a template.

A preliminary assessment takes the classification file as it stands, tests it against the current list and the catch-all clauses, and identifies whether the transaction needs a licence, an exemption, or further screening before it can proceed. Book a preliminary assessment once the technical description and the destination details are assembled; going in with an incomplete file is the most common reason an assessment has to be repeated.

Request a preliminary assessment