Encryption & Cat 5

Mass Market Encryption: Note 3 Criteria and Classification

The Four Mass-Market Criteria

Note 3 to Category 5 Part 2 provides the pathway for encryption items to receive less restrictive classification under 5A992/5D992/5E992. All four criteria must be met — failing any single criterion keeps the item at the more restrictive 5A002/5D002/5E002 level.

The criteria are designed to identify consumer-grade encryption products that do not pose significant national security concerns due to their widespread availability and non-modifiable nature.

Criterion-by-Criterion Analysis

Criterion 1 requires that the item is generally available to the public by being sold without restriction from stock at retail selling points. Criterion 2 requires that the cryptographic functionality cannot be easily changed by the user. Criterion 3 requires that the item is designed for installation by the user without substantial further support from the supplier. Criterion 4 requires that details of the items are accessible to the competent government authority upon request.

Each criterion must be evaluated independently. A product sold exclusively to enterprises (fails criterion 1), or one where encryption algorithms can be swapped by the user (fails criterion 2), would not qualify regardless of meeting the other criteria.

Common Assessment Scenarios

A consumer smartphone with built-in AES encryption meets all four criteria: sold at retail, encryption is not user-modifiable, installs automatically, and Apple/Samsung/Google cooperate with government inquiries. An enterprise VPN appliance with configurable cipher suites likely fails criterion 2 because the user can modify the cryptographic functionality.

Cloud services present unique challenges. The encryption classification typically applies to the client-side software, not the server infrastructure. A web browser with TLS support is generally mass-market; the server-side encryption infrastructure may have a different classification.

Frequently Asked Questions

What happens if my product fails one of the four criteria?

The product remains classified under 5A002/5D002 rather than receiving mass-market treatment under 5A992/5D992. License requirements are significantly more restrictive at the 5A002 level.

Do smartphones qualify as mass-market encryption?

Yes, virtually all consumer smartphones qualify for mass-market classification under 5A992 because they meet all four criteria: sold at retail, non-modifiable encryption, user-installable, and manufacturer cooperates with government inquiries.

Classify Your Item Now

Use our AI-powered ECCN classification tool to find the correct export control classification for any item.

Try ECCN.help Free →
EH
ECCN.help
AI-powered export control classification and compliance guidance.