Skip to content

Export and Deployment Policy

How ARROW hardware, virtual appliances, and cloud images may be delivered, and where.

Policy numberVTEM-EXP-2026-0002
Version2.0
EffectiveAugust 18, 2026
SupersedesVersion 1.1, April 2026
Applies toARROW physical devices, virtual appliances, and cloud images

VTEM Labs, Inc. is a U.S.-based provider of advanced cybersecurity and penetration testing technology. Our ARROW platform is a purpose-built solution for remote red team operations, ethical hacking engagements, and secure infrastructure assessments. The ARROW platform is available in two formats.

  • Physical Device. A custom Linux appliance with full-disk encryption and multi-carrier cellular connectivity, managed through an automated encrypted VPN tunnel to the ARROW platform.
  • Virtual Appliance or Cloud Image. A hardened, pre-built image the customer imports into its own hypervisor or cloud account. Seven deployment targets are supported, listed at clause 7.2.

This policy governs the export, distribution, and use of ARROW products globally and reflects compliance with U.S. export control laws, including the Export Administration Regulations (EAR, 15 CFR Parts 730 to 774), the sanctions programs administered by the Office of Foreign Assets Control (OFAC), and the Wassenaar Arrangement as implemented in the Commerce Control List. ARROW is a commercial product and is not a defense article on the United States Munitions List, so the International Traffic in Arms Regulations do not apply to it.

The policy applies to every VTEM Labs employee, contractor, reseller, and distributor, and to every customer, evaluator, and trial user who receives ARROW in any form. It applies equally to hardware shipped in a case and to an image downloaded over the internet. A download is an export.

ARROW devices and virtual machines are dual-use technologies and are subject to the EAR based on their capability for cybersecurity testing and their inclusion of encryption and VPN components. Two families of control apply, and VTEM Labs applies the more restrictive outcome to every transaction.

  • Cybersecurity items. The EAR controls intrusion software tooling and IP network communications surveillance items under ECCNs 4A005, 4D001.a, 4D004, 4E001.a, 4E001.c, 5A001.j, and the related 5B, 5D, and 5E entries. These are subject to License Exception ACE at 15 CFR 740.22.
  • Encryption items. ARROW uses full-disk encryption and an encrypted management tunnel, which brings the Category 5 Part 2 encryption controls and License Exception ENC at 15 CFR 740.17 into scope, together with the associated classification and annual self-classification reporting obligations.

Customers who need classification information for their own filings should request it in writing.

2.1 License Exception ACE does not cover everything

Section titled “2.1 License Exception ACE does not cover everything”

This is the single most important thing for a customer to understand about deploying a U.S.-origin penetration testing platform abroad. License Exception ACE authorizes many exports of cybersecurity items, but it is expressly unavailable in the situations that matter most. VTEM Labs will not release ARROW where any of the following is true.

  • The destination is in Country Group E:1 or E:2, currently Iran, North Korea, Syria, and Cuba.
  • The recipient is a government end user in any Country Group D destination. The definition is broad, and it includes state-owned or partially state-owned utilities, telecommunications and internet service providers, transport operators, and government research institutions. Partial ownership means 25 percent or more of the voting securities, or the ability to appoint a majority of the board.
  • The recipient is a non-government end user in a Country Group D:1 or D:5 destination, outside the narrow carve-outs for vulnerability disclosure and cyber incident response.

These are destination and end-user tests. They turn on where the item is going and who the recipient is, which are facts VTEM Labs establishes at the point of supply. They do not turn on the content of any engagement, and VTEM Labs does not evaluate its customers’ work. See clause 7.6.1.

ClassificationPhysical DeviceVirtual Machine
Prohibited CountriesNot PermittedNot Permitted
Restricted CountriesReviewed Case-by-CaseReviewed Case-by-Case
Permitted CountriesAllowed (with compliance)Allowed (with compliance)

Table 1. Policy summary by destination classification.

The classification follows the deployment, not the invoice. A customer headquartered in a permitted country cannot order ARROW for deployment in a restricted or prohibited one, and cannot grant access to personnel located there. Where the ordering entity, the billing address, the shipping address, and the deployment site are not all in the same country, the most restrictive of them governs.

VTEM Labs does not ship devices, release images, grant download access, or provision cloud instances to the following destinations under any circumstance. There is no review process for these and no fee will be quoted, because the answer will not change.

DestinationBasis
CubaCountry Group E:2
IranCountry Group E:1
North KoreaCountry Group E:1
SyriaCountry Group E:1
Crimea, and the Donetsk, Luhansk, Kherson, and Zaporizhzhia regions of UkraineComprehensive sanctions

Table 2. Prohibited destinations.

These are the destinations in Country Group E:1 and E:2 of the EAR, together with the regions of Ukraine subject to comprehensive sanctions. This prohibition applies to both physical shipments and virtual machine access, and it applies to a customer located elsewhere who intends to deploy or operate ARROW in one of these destinations.

Syria warrants a specific note, because U.S. policy toward Syria changed substantially during 2025 and is still moving. A number of Syria sanctions were revoked and the OFAC country program was restructured. Export controls did not follow at the same pace, so a license is still required for effectively all items subject to the EAR, Syria remains in Country Group E:1, and License Exception ACE is therefore not available. VTEM Labs will revisit this determination if and when the country group listing changes.

The following destinations are subject to U.S. export licensing requirements or regulatory review. VTEM Labs will not export physical devices or permit virtual machine downloads to these destinations without explicit authorization.

DestinationBasis
AfghanistanD:5 arms embargo
ArmeniaD:1 national security
AzerbaijanD:1 national security
BelarusD:1 and D:5; Russia-related controls
Burma (Myanmar)D:1 and D:5; military end user rule
CambodiaD:1; military end user rule
Central African RepublicD:5 arms embargo
ChinaD:1 and D:5; military end user rule
Congo (Democratic Republic of)D:5 arms embargo
EritreaD:5 arms embargo
GeorgiaD:1 national security
HaitiD:5 arms embargo
Hong KongNot a separate destination; treated as China
IraqD:1 and D:5; EAR 746.3
KazakhstanD:1 national security
KyrgyzstanD:1 national security
LaosD:1 national security
LebanonD:5 arms embargo
LibyaD:1 and D:5 arms embargo
MacauD:1; treated with China
MoldovaD:1 national security
MongoliaD:1 national security
NicaraguaD:1 and D:5; military end user rule
RussiaD:1 and D:5; EAR 746.8, policy of denial
SomaliaD:5 arms embargo
South SudanD:5 arms embargo
SudanD:5 arms embargo
TajikistanD:1 national security
TurkmenistanD:1 national security
UzbekistanD:1 national security
VenezuelaD:1 and D:5; military end user rule
VietnamD:1 national security
YemenD:1 national security
ZimbabweD:5 arms embargo

Table 3. Restricted destinations. The basis for each is in Annex A.

This list is the union of Country Group D:1 (national security) and Country Group D:5 (U.S. arms embargoed), less the destinations already prohibited above. The reason the list is drawn this way is specific to this product. License Exception ACE is unavailable for cybersecurity items to government end users anywhere in Country Group D, and to non-government end users in D:1 or D:5. For ARROW, a D:1 or D:5 listing is a hard licensing bar rather than a matter of enhanced diligence.

Requests will be evaluated on a case-by-case basis and may ultimately be denied. Please note that VTEM Labs will assess and invoice legal review fees for any formal request involving these countries, regardless of outcome. The fee is quoted and agreed in writing before the review begins.

All other countries, including U.S. allies and most of the world, may receive ARROW shipments and download virtual machines, provided that:

  • the requesting entity is not listed on any U.S. denied, debarred, or restricted party list;
  • the use case is authorized, legal, and involves client-approved penetration testing or internal red team operations; and
  • the device or software is not re-exported to a prohibited or restricted destination.

A number of permitted destinations sit in Country Group D:2, D:3, or D:4 without being in D:1 or D:5. Commercial customers in those destinations are reachable, but a government end user is not, because License Exception ACE excludes government end users throughout Country Group D. These destinations are marked in the reference table at Annex A.

Separately, some permitted destinations are recognized transshipment routes to restricted markets. Orders routed through them receive additional scrutiny of the end user and the deployment site. This is diligence, not a restriction, and the order proceeds once the end use is verified.

7. Virtual machine deployment in place of physical shipment

Section titled “7. Virtual machine deployment in place of physical shipment”

Some destinations cannot receive a physical device even though the customer, the engagement, and the destination are entirely lawful. The obstacle is logistics and customs, not sanctions. In those cases VTEM Labs deploys ARROW as a virtual appliance or cloud image instead, and the engagement proceeds without hardware.

7.1 When VTEM Labs requires a virtual deployment

Section titled “7.1 When VTEM Labs requires a virtual deployment”

VTEM Labs may require virtual deployment, at its discretion, where any of the following applies.

  • Customs formalities cannot be completed. Some destinations require import documentation, licensing, or local registration that can only be produced by an entity established in that country. Where no such filing can be made from the United States, the hardware cannot lawfully enter and the shipment will not be attempted.
  • Encryption import controls apply. A number of countries restrict the import or domestic use of encryption hardware and require prior authorization or registration held by a local party. ARROW devices use full-disk encryption and an encrypted management tunnel, so these controls are engaged.
  • Radio approval cannot be obtained. ARROW devices contain cellular transmitters. Many countries require type approval or homologation of radio equipment before it may be imported or operated, and that approval is normally held by a locally established entity. Where it cannot be obtained for a short engagement, the hardware cannot lawfully be used even if it clears customs.
  • No compliant carrier service is available. Carrier coverage changes with regulatory, geopolitical, and operational conditions, and some lanes are suspended or unsupported for equipment of this type.
  • Return shipment cannot be assured. Where VTEM Labs cannot generate a compliant return label and the customer cannot commit to a lawful return, the device does not go out in the first place.
  • Duty, tariff, or seizure exposure is unreasonable. Where duties, tariffs, or the risk of hold or seizure make physical delivery commercially or operationally unsound for either party.
  • The customer prefers it. Virtual deployment is available on request in any permitted destination. It is often faster, because there is no transit time and no customs clearance.

VTEM Labs builds and supports the following targets.

Deployment TargetImage FormatTypical Host
VMware (OVA)OVA / OVF / VMXWorkstation, Fusion, ESXi and vSphere 6.7 and later
VirtualBox (OVA)OVADesktop and laboratory hosts on Windows, macOS and Linux
QEMU/KVM (QCOW2)QCOW2 / IMGLinux virtualization hosts and libvirt-managed infrastructure
Hyper-V (VHDX)VHDXWindows Server and Windows desktop hypervisor hosts
Azure (VHD)Fixed-size VHD in ZIPMicrosoft Azure, imported as a managed image then launched
AWS (AMI)VMDK in ZIPAmazon Web Services, imported as a snapshot then registered
GCP (raw.tar.gz)disk.raw.tar.gz in ZIPGoogle Cloud, imported as a Compute Engine custom image

Table 4. ARROW virtual and cloud deployment targets.

Setup guides for each target are under VM Deployment.

7.3 What virtual deployment changes, and what it does not

Section titled “7.3 What virtual deployment changes, and what it does not”

Virtual deployment removes the shipping problem. It does not remove the export control problem, and customers should not read it as a way around a restricted destination.

ConsiderationPhysical DeviceVirtual or Cloud Image
Customs entryRequiredNone
Duties and tariffsPayable by recipientNone
Carrier availabilityCan block deliveryNot applicable
Transit timeDays to weeksDownload time
Return obligationDevice must be returnedImage destroyed or deactivated
Export license rulesApply in fullApply in full
Screening and end useRequiredRequired
Re-export restrictionsApplyApply

Table 5. Physical delivery compared with virtual deployment.

For cloud deployments, the customer selects the account, project, and region into which the image is imported. The customer is responsible for ensuring that the chosen region, and the location of every person granted access to the running instance, are permitted under this policy. Provisioning an ARROW instance in a permitted region and then operating it from, or granting access to it from, a prohibited destination is a violation of this policy and of the customer’s agreement.

Images are supplied to the contracted customer only. They must not be passed on, republished, mirrored, or redistributed in any form, and any credentials supplied with an image should be changed on first login.

7.5 When the management tunnel cannot call out

Section titled “7.5 When the management tunnel cannot call out”

ARROW is managed through an encrypted tunnel that the deployed instance opens outbound to the ARROW platform. In some countries that tunnel will not establish. The traffic may be blocked, throttled, or inspected at the national or carrier level; VPN use may be permitted only over a locally licensed provider; or the encryption itself may be restricted. The image deploys and runs, but it cannot phone home.

This is a connectivity and local-law problem, not a product defect, and it is foreseeable in a number of otherwise permitted destinations. Clients should assume it may happen and plan for it before the engagement window opens.

Where the ARROW tunnel cannot establish, the client is responsible for providing a lawful means of reaching the virtual machine so the engagement can proceed. Acceptable arrangements are ones the client already operates and controls, for example:

  • access through the client’s own corporate remote access or VPN infrastructure, where that infrastructure is lawfully operated in the destination;
  • a client-provided bastion or jump host that the operator can reach from a permitted location;
  • console or out-of-band access through the client’s hypervisor management interface or cloud provider console;
  • a client-nominated network path, address range, or egress allowance that permits the instance to reach the platform; or
  • operation of the instance by the client’s own personnel, with output exchanged through an agreed channel.

The client is responsible for the lawfulness, security, and availability of whatever path it provides, and for any consent or registration that path requires in the destination. VTEM Labs will support the integration but cannot warrant performance over a network it does not control, and engagement timelines should allow for it.

7.5.2 Where the technology itself is barred

Section titled “7.5.2 Where the technology itself is barred”

A blocked tunnel and a barred technology are different problems with different answers. If VPN use, the encryption in the product, or tooling of this class is prohibited or requires a license in the destination, that is a legal restriction and it is the client’s responsibility to resolve it lawfully before deployment, whether by using a licensed local provider, obtaining regulator approval, or narrowing the engagement. Clause 10 already places local law compliance on the client, and this is the most common place it bites.

VTEM Labs provisions the device or image, prepares the shipping documentation, and delivers it to the client. What this policy adds to that is a single question, asked before supply. Is the destination one this policy permits, and is the recipient a party VTEM Labs is permitted to supply. That question is about geography and identity. It is not about the client’s work.

  • VTEM Labs does not request, receive, review, audit, or retain any client statement of work, scope document, engagement letter, testing authorization, assessment methodology, finding, report, or any record of the work a client performs.
  • VTEM Labs is not a party to the client’s engagements, has no visibility into them, and holds no contractual right of access to that documentation.
  • VTEM Labs does not assess, approve, or second-guess the work its clients undertake. Clients are professional penetration testing and cybersecurity firms operating under their own commercial agreements, and the lawfulness and scoping of their engagements are matters for their own legal counsel.

ARROW is supplied to contracted professional customers under a commercial subscription. It is not available to the general public, is not sold over the counter, and is not provided on an unvetted or casual basis.

Releasing controlled technology or source code to a foreign person inside the United States is an export to that person’s most recent country of citizenship or permanent residency. VTEM Labs applies this rule to its own personnel and contractors, and customers must apply it to theirs. Giving a foreign national access to a controlled ARROW build, or to its controlled technology, may require a license even though nothing crosses a border, and no license exception is available for nationals of Country Group E:1 or E:2 destinations.

8. Client-arranged delivery and onward transit

Section titled “8. Client-arranged delivery and onward transit”

There is a middle case between a straightforward shipment and a virtual deployment. A client may have a legitimate operational need to put physical hardware somewhere that VTEM Labs will not ship to directly, because the customs, carrier, tariff, or seizure risk of that lane is one VTEM Labs is not willing to carry. Where the destination is otherwise lawful, that engagement does not have to be abandoned. It can proceed on the client’s own account.

VTEM Labs delivers the device to a permitted location the client nominates, typically a client office, freight forwarder, or agent in the United States or another permitted country. From the moment of delivery at that location, the client arranges, controls, and is responsible for all onward movement, to its own premises, to the engagement site, and back to VTEM Labs at the end of the term.

  • The client becomes the exporter. Any movement of the device out of the delivery country is the client’s export, made on the client’s own account and under the client’s own export authorizations. The client is the exporter of record and is responsible for classification, licensing, filing, and customs formalities for every leg it arranges.
  • The client carries the legal risk in full. The client assumes complete legal, regulatory, financial, and operational responsibility for the onward transit, including duty, tariff, penalty, delay, damage, loss, seizure, and forfeiture, and indemnifies VTEM Labs against any claim arising from it.
  • Written risk acceptance is required, not implied. This arrangement is available only where the client’s own legal counsel has reviewed it and confirmed in writing that the client accepts the risk, and where an authorized business representative of the client has done the same. VTEM Labs will not proceed on a verbal assurance or on an assurance from someone without authority to give it.
  • Custody and return are unchanged. The device remains the property of VTEM Labs throughout. The client remains fully responsible for it from delivery until confirmed return, and the return obligations in clause 11 apply in full. Choosing this route does not convert a rental into a sale and does not relieve the client of returning the device.
  • VTEM Labs may still decline. This is a concession, not an entitlement. VTEM Labs may refuse any request under this clause for any reason, and will refuse where the facts suggest the real destination is one this policy prohibits.

This clause exists so that lawful engagements in operationally difficult places can go ahead. It is not a mechanism for reaching places this policy closes, and it will never be treated as one.

Accordingly, the client must identify every country the device will enter before delivery is arranged, and must obtain written approval from VTEM Labs before moving it to any country not named in that request. Where a client cannot lawfully move a device to the place it needs to work, the answer is a virtual deployment under clause 7, not a quiet routing.

9. Customs, tariffs, and international shipping

Section titled “9. Customs, tariffs, and international shipping”

Due to evolving global trade regulations, tariffs, and carrier restrictions, international shipment and return of ARROW devices may be impacted by factors outside of the control of VTEM Labs. Because devices are rented and must come back, every engagement involves two customs movements, not one, and the return leg is usually the harder of the two.

  • Customs compliance. All shipments must comply with applicable U.S. export laws and destination country import regulations. VTEM Labs will not alter, misrepresent, or falsify customs declarations, product classifications, country of origin, or declared values under any circumstances or at any customer’s request.
  • Tariffs and duties. All import duties, VAT, tariffs, brokerage fees, and related charges are the sole responsibility of the receiving party unless otherwise explicitly agreed in writing. Both the rates and the basis on which they are assessed have changed materially during 2025 and 2026 and may change again during a subscription term. Landed cost should be confirmed with a customs broker in the destination before an engagement is scheduled.
  • Low-value shipments are no longer simple. The U.S. duty-free exemption for low-value commercial shipments has been suspended for all countries and is being withdrawn permanently. A returned device or a single spare part now requires a customs entry with full classification, and attracts brokerage and processing fees that can exceed the duty itself.
  • Temporary export documentation. Because ARROW devices are rented and returned, an ATA Carnet or equivalent temporary admission document is often the cleanest route for a short engagement. Where a Carnet is used, the customer is responsible for presenting the equipment for re-exportation within its validity period. A Carnet is a customs document only, so it does not authorize an export that export control law prohibits, and it does not make a restricted destination reachable.
  • Carrier limitations. Certain regions may be restricted or unsupported by carriers due to regulatory, geopolitical, or operational constraints. Shipping availability may change without notice.
  • Return shipping limitations. VTEM Labs will make commercially reasonable efforts to provide return shipping labels. However, due to international regulations, carrier restrictions, and tariff policies, this may not be possible in all regions.
  • Client-assisted returns. Where VTEM Labs is unable to generate compliant return shipping labels, the client is responsible for coordinating return shipment in accordance with applicable export laws, including carrier selection, customs documentation, and export declarations.
  • Use a broker or express carrier for returns, not the mail. The postal channel now carries the heaviest documentation burden for shipments returning to the United States and is not suitable for an ARROW device.
  • Export filing. Electronic export information must be filed for any shipment that requires an export license, regardless of its value. Value-based filing exemptions do not apply to licensed exports.
  • Refusal or inability to ship. If a client or end customer is unable or unwilling to comply with shipping, customs, or return requirements, VTEM Labs may require the use of a virtual appliance in place of physical device deployment.
  • Delays, holds, and seizures. VTEM Labs is not responsible for delays, customs holds, inspections, tariffs, or seizure of devices once transferred to a shipping carrier. Where a shipment is held or lost, VTEM Labs will offer a virtual deployment so the engagement can continue.

For the day-to-day mechanics of tracking, receiving, and returning a device, see Device Shipments.

The obligations below relate to export control, custody, and the movement of the device and image. They are deliberately confined to those subjects. Nothing in this policy governs how a client conducts its own engagements, and VTEM Labs does not require clients to account to it for that work.

  • No unauthorized resale or re-export. The device or VM may not be sold, sublicensed, transferred, or re-exported to any third party, and never to a party or destination in a restricted or embargoed jurisdiction. Devices are rented and remain VTEM Labs property, so a transfer to a third party is both a breach of contract and potentially an unlicensed re-export.
  • Compliance with local laws. The client is responsible for complying with all local laws regarding encryption, VPN use, import and export, wireless transmissions, computer misuse, and data protection at the deployment location.
  • Accurate destination information. The recipient entity, delivery location, and country of deployment given to VTEM Labs must be accurate and kept current, because those are the facts on which the export determination rests. Any change is reported before it takes effect.
  • Access control. Access is limited to identified individuals whose location and nationality are permitted under this policy.
  • No movement across borders. A device may not be carried or shipped to a country other than the one it was released to without prior written approval. Moving a device across a border is a re-export and requires its own analysis.

11. Device custody and return requirements

Section titled “11. Device custody and return requirements”

ARROW devices are rented for the duration of an engagement. The obligations below are the core of the commercial relationship, not boilerplate.

  • Custodial responsibility. ARROW physical devices remain the property of VTEM Labs at all times. The client assumes full responsibility for the device from the time of delivery until confirmed return, including physical security and protection against loss, theft, and unauthorized access.
  • Return timing. Physical devices must be returned upon expiration or termination of the applicable subscription term, or earlier upon request by VTEM Labs.
  • Return shipping. VTEM Labs will make commercially reasonable efforts to provide return shipping labels. However, due to international shipping restrictions, this may not be possible in all regions.
  • Client-managed returns. Where VTEM Labs cannot provide return shipping, the client is responsible for coordinating compliant return shipment, including carrier selection, customs documentation, and export declarations from the originating country.
  • Returned goods treatment. ARROW devices are U.S.-origin goods, so a device returned unaltered may normally re-enter the United States free of duty as American goods returned. That relief is fragile and the client must protect it. Do not open, service, repair, upgrade, reflash, or otherwise advance the device in value while it is abroad, and do not substitute a different unit. The exact device that was exported, by serial number, must be the device that returns. Work performed abroad or a substituted unit makes the return dutiable.
  • Return records. The client must keep, and provide on request, the shipping and export documentation for the outbound movement. Proof of export is required to claim returned-goods treatment, and the burden of proof sits with the importer of record.
  • Failure to return. Devices not returned within the agreed timeframe may be subject to replacement or recovery fees as defined in the commercial agreement, and platform access may be suspended.
  • Virtual deployments. On expiration or termination, the client must destroy or decommission all copies of the image and all instances derived from it, and confirm in writing on request.

VTEM Labs operates in strict compliance with U.S. export control laws and international trade regulations. The following actions are strictly prohibited.

  • Misrepresentation of shipment contents, value, origin, or classification.
  • Falsification or manipulation of customs, export, or import documentation.
  • Routing shipments, downloads, or cloud access through intermediaries to circumvent export restrictions.
  • Exporting, re-exporting, or transferring products to denied parties or restricted jurisdictions.
  • Splitting an order, or understating a value or quantity, to avoid a licensing or reporting threshold.
  • Use of ARROW in violation of applicable local, national, or international law.

VTEM Labs will not support or participate in any activity intended to bypass legal, regulatory, or customs requirements under any circumstances.

VTEM Labs may suspend platform access, halt a shipment, revoke a download, deactivate a deployed instance, and recall a device immediately, without prior notice and without liability, where it identifies a violation of this policy or a change in law or listing status that makes continued supply unlawful. Suspected violations are reported to the relevant U.S. authority where the law requires it.

Countries may be added to or removed from any list in this policy at any time, with or without notice, based on changes to U.S. export control laws or at the sole discretion of VTEM Labs in response to geopolitical events, compliance concerns, or risk assessments. The controlling version is the one published at vtemlabs.com.

If your organization is located in a country listed under the restricted category, if you are unsure of your compliance status, or if you need classification information for your own filings, contact VTEM Labs before scheduling an engagement. Requests should identify the legal entity, the recipient, and the country and site of deployment.

DestinationPhysical DeviceVirtual MachineBasis
CubaNot PermittedNot PermittedCountry Group E:2
IranNot PermittedNot PermittedCountry Group E:1
North KoreaNot PermittedNot PermittedCountry Group E:1
SyriaNot PermittedNot PermittedCountry Group E:1
Crimea, and the Donetsk, Luhansk, Kherson, and Zaporizhzhia regions of UkraineNot PermittedNot PermittedComprehensive sanctions
AfghanistanLicense RequiredLicense RequiredD:5 arms embargo
ArmeniaLicense RequiredLicense RequiredD:1 national security
AzerbaijanLicense RequiredLicense RequiredD:1 national security
BelarusLicense RequiredLicense RequiredD:1 and D:5; Russia-related controls
Burma (Myanmar)License RequiredLicense RequiredD:1 and D:5; military end user rule
CambodiaLicense RequiredLicense RequiredD:1; military end user rule
Central African RepublicLicense RequiredLicense RequiredD:5 arms embargo
ChinaLicense RequiredLicense RequiredD:1 and D:5; military end user rule
Congo (Democratic Republic of)License RequiredLicense RequiredD:5 arms embargo
EritreaLicense RequiredLicense RequiredD:5 arms embargo
GeorgiaLicense RequiredLicense RequiredD:1 national security
HaitiLicense RequiredLicense RequiredD:5 arms embargo
Hong KongLicense RequiredLicense RequiredNot a separate destination; treated as China
IraqLicense RequiredLicense RequiredD:1 and D:5; EAR 746.3
KazakhstanLicense RequiredLicense RequiredD:1 national security
KyrgyzstanLicense RequiredLicense RequiredD:1 national security
LaosLicense RequiredLicense RequiredD:1 national security
LebanonLicense RequiredLicense RequiredD:5 arms embargo
LibyaLicense RequiredLicense RequiredD:1 and D:5 arms embargo
MacauLicense RequiredLicense RequiredD:1; treated with China
MoldovaLicense RequiredLicense RequiredD:1 national security
MongoliaLicense RequiredLicense RequiredD:1 national security
NicaraguaLicense RequiredLicense RequiredD:1 and D:5; military end user rule
RussiaLicense RequiredLicense RequiredD:1 and D:5; EAR 746.8, policy of denial
SomaliaLicense RequiredLicense RequiredD:5 arms embargo
South SudanLicense RequiredLicense RequiredD:5 arms embargo
SudanLicense RequiredLicense RequiredD:5 arms embargo
TajikistanLicense RequiredLicense RequiredD:1 national security
TurkmenistanLicense RequiredLicense RequiredD:1 national security
UzbekistanLicense RequiredLicense RequiredD:1 national security
VenezuelaLicense RequiredLicense RequiredD:1 and D:5; military end user rule
VietnamLicense RequiredLicense RequiredD:1 national security
YemenLicense RequiredLicense RequiredD:1 national security
ZimbabweLicense RequiredLicense RequiredD:5 arms embargo
BahrainPermittedPermittedCountry Group D; government end users need a license
EgyptPermittedPermittedCountry Group D; government end users need a license
IsraelPermittedPermittedCountry Group D; government end users need a license
JordanPermittedPermittedCountry Group D; government end users need a license
KuwaitPermittedPermittedCountry Group D; government end users need a license
OmanPermittedPermittedCountry Group D; government end users need a license
PakistanPermittedPermittedCountry Group D; government end users need a license
QatarPermittedPermittedCountry Group D; government end users need a license
Saudi ArabiaPermittedPermittedCountry Group D; government end users need a license
TaiwanPermittedPermittedCountry Group D; government end users need a license
SingaporePermittedPermittedCountry Group A:6; transshipment diligence applies
TurkiyePermittedPermittedCountry Group A:5; transshipment diligence applies
United Arab EmiratesPermittedPermittedMoved to Country Group A:5 in July 2026
Australia, Canada, Japan, New Zealand, South KoreaPermittedPermittedCountry Group A:5; permitted with compliance
European Union member statesPermittedPermittedCountry Group A:5; permitted with compliance
Switzerland, United KingdomPermittedPermittedCountry Group A:5; permitted with compliance
Ukraine (government controlled)PermittedPermittedPermitted; occupied regions are prohibited
United StatesPermittedPermittedDeemed export rules apply to foreign persons
All other destinationsPermittedPermittedPermitted with compliance

Annex A. Destination determinations as of August 18, 2026.