The Four Mass-Market Criteria
Note 3 to Category 5 Part 2 provides the pathway for encryption items to receive less restrictive classification under 5A992/5D992/5E992. All four criteria must be met — failing any single criterion keeps the item at the more restrictive 5A002/5D002/5E002 level.
The criteria are designed to identify consumer-grade encryption products that do not pose significant national security concerns due to their widespread availability and non-modifiable nature.
Criterion-by-Criterion Analysis
Criterion 1 requires that the item is generally available to the public by being sold without restriction from stock at retail selling points. Criterion 2 requires that the cryptographic functionality cannot be easily changed by the user. Criterion 3 requires that the item is designed for installation by the user without substantial further support from the supplier. Criterion 4 requires that details of the items are accessible to the competent government authority upon request.
Each criterion must be evaluated independently. A product sold exclusively to enterprises (fails criterion 1), or one where encryption algorithms can be swapped by the user (fails criterion 2), would not qualify regardless of meeting the other criteria.
Common Assessment Scenarios
A consumer smartphone with built-in AES encryption meets all four criteria: sold at retail, encryption is not user-modifiable, installs automatically, and Apple/Samsung/Google cooperate with government inquiries. An enterprise VPN appliance with configurable cipher suites likely fails criterion 2 because the user can modify the cryptographic functionality.
Cloud services present unique challenges. The encryption classification typically applies to the client-side software, not the server infrastructure. A web browser with TLS support is generally mass-market; the server-side encryption infrastructure may have a different classification.