TariffWolf Logo TariffWolf

How Companies Self-Classify Under the EAR: NetApp, Semiconductors, and Real Examples

July 27, 2026 13 min read Blog
Learn how companies self-classify under the EAR through real examples, including NetApp and semiconductor products, with practical export compliance insights.

Under the Export Administration Regulations, there’s a fact that surprises a lot of first-time exporters: the government doesn’t classify your products for you. You do. BIS will issue an official determination if you ask, but the default — and the legal responsibility — is self-classification. You compare your product against the Commerce Control List and assign its ECCN (or confirm EAR99) yourself.

That sounds intimidating until you realize it’s a system companies run every single day — and that many of them publish the results. The fastest way to understand self-classification isn’t an abstract walkthrough; it’s looking at how real companies do it. So this guide does exactly that: the enterprise-tech pattern (why a search like “NetApp ECCN” exists), the hardest frontier (semiconductors and advanced computing), and the classic trap (the product everyone “knew” was EAR99 until it wasn’t).

The short version: Self-classification means the exporter assigns the ECCN, taking responsibility for it. Easy products (a cotton t-shirt) are obviously EAR99. The hard ones cluster around encryption, computing, and sensors — which is why enterprise vendors self-classify their gear (often into Category 5’s encryption entries under License Exception ENC) and publish it for customers to rely on, and why semiconductors have become the most consequential self-classification problem of 2026.

What “self-classification” actually means

The EAR puts the burden on you. As BIS frames it, exporters are responsible for classifying their own products — comparing technical specifications against the parameters on the Commerce Control List and assigning the result. You can request an official Commodity Classification (CCATS) from BIS through SNAP-R, but most companies self-classify the large majority of their catalog and reserve CCATS for the genuinely ambiguous or high-stakes items.

The process follows the CCL Order of Review: confirm the item is subject to the EAR, then work category → product group → specific entry, landing on an ECCN or — if nothing on the list describes it — EAR99.

The difficulty is wildly uneven across products:

  • Easy self-classification. A cotton t-shirt, a wooden chair, a basic hand tool — clearly not on the CCL, confidently EAR99, no expert needed.
  • Hard self-classification. Anything whose technical characteristics approach or cross a controlled parameter — encryption strength, computing performance, sensor resolution, certain materials. Here, “it feels commercial” is not a classification, and getting it wrong is expensive.

Almost every difficult self-classification a commercial company faces lives in one of a few areas. The biggest, by far, is encryption — which is where our first real example starts.

Real example 1: The enterprise-tech pattern (why “NetApp ECCN” is a search)

Type “NetApp ECCN” into a search engine and you’ll find people looking for a specific thing: the export classification that NetApp — an enterprise data-storage vendor — has assigned to its products. NetApp is far from alone; Cisco, Dell, HPE, Microsoft and most major technology vendors publish export-control classification information for their products on public export-compliance pages. Understanding why they do this explains self-classification better than any definition.

Why storage and networking gear gets controlled

Modern enterprise hardware — storage arrays, controllers, switches, security appliances — almost always incorporates encryption for data confidentiality. And encryption is one of the most heavily controlled areas of the EAR. Items that use cryptography for data confidentiality above modest thresholds (symmetric algorithms over 56-bit, asymmetric over 512-bit — i.e., virtually all modern encryption) fall under Category 5, Part 2 of the CCL, typically:

  • ECCN 5A002 — information security hardware (encrypted storage systems, security appliances, HSMs, secure comms).
  • ECCN 5D002 — the software equivalent.
  • ECCN 5A992 / 5D992 — the “mass-market” classification (Note 3 to Category 5, Part 2) for retail-type products whose cryptography can’t easily be modified by the user; less restrictive than 5A002/5D002.

So an enterprise storage vendor self-classifying a new array isn’t asking “is this controlled?” so much as “which Category 5 entry, and which export pathway?”

License Exception ENC and the annual report

Most encryption items don’t need an individual license to export — they ship under License Exception ENC (§740.17 of the EAR), which authorizes export to most destinations (not the embargoed Country Groups E:1/E:2) once the item is classified. Depending on the product, the company either files a classification request with BIS or relies on self-classification, and many ENC items require an annual self-classification report to BIS (due February 1 for the prior year). It is not enough to know the ECCN; the exporter must also know which ENC provision applies, since each authorizes a different scope.

The flow-down: why vendors publish, and you can rely on it

Here’s the part that makes “NetApp ECCN” a sensible search. The EAR explicitly allows a downstream party to export based on the manufacturer’s classification and ENC authorization for a product. So when NetApp (or any vendor) self-classifies a product and publishes the ECCN and ENC details, its customers, resellers, and integrators can rely on that published classification rather than re-classifying the hardware themselves.

That’s the practical workflow if you’re shipping someone else’s product:

  1. Find the manufacturer’s export-compliance / product-classification page.
  2. Locate your specific product and model — classifications are product- and version-specific.
  3. Read the published ECCN (e.g., a Category 5 entry) and the ENC provision / authorization.
  4. Apply it to your transaction — because the ECCN is only the start; your destination, end user, and end use still drive whether you can ship and how. (See the licensing walkthrough.)
  5. Verify and document. Confirm you’re looking at the right model and a current classification, and keep the record.

The lesson of the enterprise-tech pattern: self-classification is a discipline serious vendors invest in and publish — and a well-documented, reliable classification is an asset their whole channel depends on.

Real example 2: Semiconductors and advanced computing — the high-stakes frontier

If encryption is the most common hard self-classification, semiconductors are the most consequential one in 2026.

Advanced computing chips and the equipment to make them have moved to the center of U.S. export control. The relevant self-classification now runs through entries such as:

  • ECCN 3A090 — advanced computing integrated circuits meeting specific performance parameters.
  • ECCN 4A090 — computers and systems incorporating those chips.
  • ECCN 3B090 (and related 3B entries) — semiconductor manufacturing equipment.

What makes these the high-stakes frontier is the combination of three things. First, the thresholds are precise and consequential — a chip a hair above a performance line is controlled; below it, maybe not. Second, the rules moved — items that were comfortably EAR99 or lightly controlled a couple of years ago now sit in controlled entries with license requirements to sensitive destinations. Third, the licensing posture is severe — exports of these items to certain destination groups (and entities, including based on their ultimate parent) require licenses, with some categories shifted to case-by-case review rather than routine approval.

There’s even a vivid illustration of how tangled self-classification gets at this frontier: the CCL now includes “.z” provisions that capture items described under the encryption entries (5A002) that also meet advanced-computing parameters (3A090/4A090). In other words, a single product can sit at the intersection of two of the hardest control areas at once. Self-classifying it correctly is genuinely expert work — and getting it wrong, given the destinations and stakes involved, is not a small error.

This is the practical face of the broader shift we wrote about in The New Iron Curtain Is Made of Silicon, and a core reason “AI export control” has become a live concern: the chips that train and run advanced AI are exactly the items these entries now capture.

Real example 3: The “we assumed EAR99” trap

The most common self-classification failure isn’t an exotic chip — it’s an ordinary-looking product a company assumed was EAR99.

Picture a manufacturer of industrial cameras. Not on the USML, not obviously on the CCL — the team concluded EAR99 and assumed they could sell freely. Then a foreign customer mentioned wanting the cameras for a military installation in a country of concern. That end use triggered controls the company hadn’t accounted for, and a shipment that “felt commercial” suddenly needed a license. They nearly shipped without one.

Two lessons sit inside that story:

  • A product can look mundane and still cross a controlled parameter — a security camera with encryption, a high-accuracy GPS module, a software-defined radio, a sensor with a particular resolution. “Seems like an ordinary consumer good” is not an analysis.
  • Even a correct EAR99 classification doesn’t mean “ship anywhere.” EAR99 items can still require a license because of the destination, the end user, or the end use. Classification answers what the item is; it never answers the whole export question by itself. (And if there’s any doubt the item is even Commerce-jurisdiction, that’s an ITAR-or-EAR question first.)

Self-classification done well means checking the assumption against the actual CCL parameters — not confirming what you hoped was true.

What good self-classification looks like

Across all three examples, the companies that self-classify well follow the same handful of practices:

  • Start from the spec sheet, not the marketing copy. Classification lives in technical parameters — key lengths, performance figures, frequencies, resolutions — not in product names.
  • Work the Order of Review. Confirm EAR jurisdiction, then category → product group → entry, before defaulting to EAR99.
  • Document the rationale. Write down why — which entry, which parameter, why not a controlled ECCN. That audit-ready record is what demonstrates reasonable care.
  • Use the manufacturer’s classification when you’re downstream — and verify it. Rely on published vendor ECCNs for their products, but confirm the model and that the classification is current.
  • Re-classify when the product or the rules change. A new firmware that enables encryption, or a BIS rule that adds an entry, can change the answer. Classifications have a shelf life.
  • Keep a human on the hard ones. Encryption, advanced computing, and threshold-adjacent items deserve expert review, not autopilot — the same human-in-the-loop, audit-ready model that holds across trade compliance tooling.

This is precisely what TariffWolf and ECCN.help are built to support: a reasoned self-classification from a plain product description, with the why shown so you can verify it, scalable across a catalog, and honest about when an item is close enough to a threshold that it deserves a human’s — or BIS’s — second look.

Why self-classification got harder in 2026

Three trends have raised the difficulty at once. Encryption is everywhere — it’s baked into ordinary hardware and software, pulling more products into Category 5 than teams expect. Advanced-computing controls expanded — semiconductors and AI hardware moved into controlled entries with serious licensing consequences. And the lists move faster — a self-classification that was right last year can be wrong now because BIS revised a threshold or added an entry. Self-classification was never “set it and forget it”; in 2026 it’s an ongoing obligation that rewards a documented, re-runnable process over a one-time spreadsheet guess.

Quick reference

If you’re classifying…It often lands in…Watch out for…
Hardware/software with encryption5A002 / 5D002 (or mass-market 5A992 / 5D992)Which License Exception ENC provision applies; the annual self-classification report
Advanced computing chips / systems3A090 / 4A090 (equipment: 3B090)Precise thresholds; license requirements to sensitive destinations; case-by-case review
Someone else’s productWhatever the manufacturer publishedRight model/version; current classification; your destination/end-use still apply
An “obviously EAR99” itemPossibly EAR99 — verify itHidden controlled features; end-use/end-user license triggers

Frequently asked questions

Does the government assign my product’s ECCN? Generally no — under the EAR you self-classify, and you’re responsible for the result. BIS will issue an official Commodity Classification (CCATS) if you request one through SNAP-R, but most companies self-classify the bulk of their products and reserve CCATS for ambiguous or high-stakes items.

How do I find a product’s ECCN, like a NetApp ECCN? For a product you didn’t make, check the manufacturer’s public export-compliance or product-classification page — major tech vendors publish ECCNs (and, for encryption items, the applicable License Exception ENC details). The EAR lets you export based on the manufacturer’s classification, but confirm you have the right model and a current classification, and remember your destination, end user, and end use still govern the shipment.

Why do so many tech products have ECCN 5A002? Because they contain encryption. Items using cryptography for data confidentiality above low thresholds (symmetric over 56-bit, asymmetric over 512-bit — essentially all modern encryption) fall under Category 5, Part 2, commonly ECCN 5A002 for hardware and 5D002 for software. Many ship under License Exception ENC; some qualify as less-restrictive “mass-market” 5A992/5D992.

How are semiconductors classified for export? Advanced computing chips meeting specific performance parameters fall under ECCN 3A090, systems incorporating them under 4A090, and semiconductor manufacturing equipment under entries like 3B090. These carry license requirements to sensitive destinations, with some categories under case-by-case review — making accurate, current self-classification especially important.

Can I just assume my product is EAR99? No — verify it. Plenty of ordinary-looking products carry controlled features (encryption, high-accuracy GPS, certain sensors), and even genuine EAR99 items can require a license based on destination, end user, or end use. “It feels commercial” isn’t a classification; checking it against the CCL parameters is.

What is License Exception ENC? It’s the EAR provision (§740.17) that lets most encryption items export without an individual license, to most destinations (excluding embargoed Country Groups E:1/E:2), after classification. It has multiple provisions covering different product types, and many items require an annual self-classification report to BIS — so knowing the ECCN alone isn’t enough; you also need the right ENC provision.

How often should I re-check a self-classification? Whenever the product changes in a way that affects its controlled characteristics (e.g., enabling encryption), and whenever the rules change — BIS revises the CCL regularly, as the 2026 advanced-computing controls show. Treat classifications as having a shelf life, and keep your rationale documented so re-checks are quick.

The honest bottom line

Self-classification under the EAR isn’t a mystery reserved for compliance specialists — it’s a discipline that real companies run every day, and that the best of them document and publish. The easy cases are easy; the hard cases cluster predictably around encryption, advanced computing, and ordinary-looking products with hidden controlled features. The companies that get it right start from the spec, work the Order of Review, document the why, lean on (and verify) manufacturers’ published classifications, keep a human on the hard ones, and re-check as products and rules change.

That’s the workflow TariffWolf and ECCN.help are built to make fast and defensible — export-control classification with reasoning you can read, scalable across a catalog, honest about its limits.

Don’t take our word for it. Don’t Trust Us. Try Us.


This article is for general information and is not legal advice. Company names are used only as illustrations of standard industry practice; verify any product’s classification against the manufacturer’s current published information. Export controls change frequently — consult the current EAR and BIS guidance, or qualified counsel, for specific products and transactions.

Share: