When Does Exporting Software with Encryption Require a SCOMET Licence?
Encryption is everywhere — in banking apps, messaging platforms, VPN services, cloud storage, and virtually every modern software product. For India’s massive software industry, a critical question arises: when does exporting software with encryption functionality trigger SCOMET controls? The answer lies in the intersection of Category 8 Sub-category 5 (Information Security), the General Software Note, and the specific technical thresholds that distinguish controlled cryptographic products from everyday commercial software.
What Is Controlled?
SCOMET Category 8, Sub-category 5, Part II (Information Security) controls items with cryptographic capability, including hardware, software, and technology for encryption, decryption, and cryptanalysis. Entry 8A502 covers information security systems and equipment with cryptographic functionality. Entry 8D502 covers the corresponding software. The controls target military-grade, custom, and advanced cryptographic systems — not the encryption embedded in ordinary consumer products.
The General Software Note Exemption
The General Software Note provides critical exemptions for software that is “generally available to the public” (sold from retail stock, designed for user installation without substantial vendor support) or “in the public domain.” However, there is a crucial carve-out: the General Software Note explicitly states that its first exemption (generally available) does NOT release software controlled under Sub-category 5 Part II (Information Security). This means that even commercially available encryption software may still be controlled, depending on its technical specifications.
Mass Market Exemption
Despite the General Software Note carve-out, many encryption products qualify for exemption under the mass market provisions. Products designed for personal, home, or business use without customisation for government or military applications, and which are widely available through retail channels, generally qualify. Standard HTTPS/TLS implementations, consumer VPN applications, commercial messaging apps with end-to-end encryption, and general-purpose operating systems with built-in encryption are typically Non-SCOMET.
SaaS and Cloud Implications
Software-as-a-Service (SaaS) companies present unique export control considerations. When an Indian SaaS company provides a cloud-based service to foreign users, the delivery of encryption functionality across borders may constitute an export of controlled technology. Companies offering cloud-based encryption services, secure communication platforms, or data protection solutions should evaluate whether their service involves the transfer of controlled cryptographic capabilities.
Conclusion
Most standard commercial software with encryption is likely Non-SCOMET under mass market exemptions. However, custom cryptographic solutions, military-grade encryption hardware, and advanced information security systems remain controlled. Indian software companies should evaluate their encryption products against Category 8 Sub-category 5 thresholds. For classification help, use the SCOMET AI Assistant.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Encryption export controls are complex and fact-specific. Always verify with DGFT. For queries, contact scomet@tariffwolf.com.
Need Help with SCOMET Classification?
Use our AI-powered assistant to check if your item is SCOMET-controlled, find the right category code, and understand licensing requirements.
Try SCOMET AI Assistant