Export Information on Sophos Products

General rules governing, and information relating to, the export of Sophos products.

Sophos is committed to complying with the laws and regulations relating to export controls. As part of this compliance effort, Sophos agreements contain provisions requiring Sophos customers and partners to ensure compliance with these laws and regulations. In order to assist our customers and partners, Sophos uses this portion of its web site to communicate export control information specific to its products to our customers and partners. This information may be required for shipping documentation, record keeping, or post-shipment reporting.

Customers and partners are encouraged to familiarize themselves with the import regulations of their country to ensure compliance with their specific regulations and to ensure timely delivery of Sophos products they may purchase.

NOTE: The contents on this website are not tailored to the needs of a specific entity or a particular export scenario. The information provided below is for general information purposes only. Exportation of restricted goods is a complex area and while Sophos will make reasonable efforts to maintain the information on this website, you are responsible for seeking your own legal advice and ensuring your compliance in relation to such matters.

United States Export Controls

Sophos products are subject to US export regulations. In the United States, a branch of the U.S. Department of Commerce known as the Bureau of Industry and Security regulates exports through the Export Administration Regulations (EAR). These regulations spell out the export restrictions on a wide variety of goods, software, and technologies. Sophos products may not be exported to Cuba, Iran, North Korea, Syria, or Sudan, but most products may be exported to other countries subject to the applicable import regulations of such country.

The US export classification control numbers for Sophos products are set out inTable 1 below.

Some Sophos products are subject to export restrictions because they include encryption technology. In the case of Sophos products containing encryption, a one-time government technical review is usually required prior to export. Once a review has been completed, products may become eligible for a particular license exception, such as ENC. This exception may then be used by other exporters, as provided by the U.S. EAR. 

Government End-Users: Restricted Encryption Products (UTM, Red, Access Points)

Certain government entities not located in the member countries of the EU, Australia, Canada, Japan, New Zealand, or the United States require a U.S. export license in order to obtain the noted Sophos restricted encryption products. 

All government end users in the Russia and Ukraine require a U.S. export license in order to obtain the noted Sophos restricted encryption products. 

With the exception of Russia and Ukraine, Sophos’s encryption licensing arrangement (ELA), Export License No. D528663, permits Local, State and Provincial government end users, as well as to National, Federal and Royal government end users that provide the civil government services listed below, to obtain the noted restricted encryption products:

  1. Census and Statistics Services;
  2. Civil Public Works Infrastructure Services (Construction, Maintenance, Repair, Regulation and Administration) as follows: Buildings, Public Transportation, Roads and Highways, Trucking;
  3. Civil Service Administration and Regulation, including Human Resources and Personnel/Labor Management;
  4. Clean Water Infrastructure Services (Treatment, Supply and Testing);
  5. Economic (Trade/Commerce/Investment), Business and Industrial Development, Promotion, Regulation and Administration; excluding the following end-users/end-uses:
    1. Agencies, Departments, Boards and Councils for Science and Technology,
    2. Research, Development and National Laboratories (other than as authorized in paragraphs (K) (Measurements and Standards) and (L) (Meteorology / Weather / Atmospheric Services) below)
    3. National Telecommunications and Information Technology Agencies, Boards, Councils and Development Authorities (including National Information Center, and Information Communications Technology (ICT) / Telecommunications Infrastructure / Spectrum Planning, Policy, Regulations and Testing);
  6. Elections, Balloting and Polling Services;
  7. Energy Regulation and Administration, including Oil, Gas and Mining Sectors;
  8. Environmental/ Natural Resources Regulation, Administration and Protection, including Wildlife, Fisheries and National Parks;
  9. Food/ Agriculture Regulation and Administration;
  10. Labor/Community/Social Services Planning, Regulation and Administration, including: Housing and Urban Development, Municipality And Rural Affairs;
  11. Measurements and Standards Services;
  12. Meteorology (Weather, Atmospheric) Services;
  13. National Archives/Museums;
  14. Patents;
  15. Pilgrimage and Religious Affairs;
  16. Postal Services;
  17. Public and Higher Education (Excluding Government Research Institutions and any agency, institution or affiliate engaged in the manufacture or distribution of items or services controlled on the Wassenaar Munitions List);
  18. Public Health and Medicine/Pharmaceutical Regulation and Administration;
  19. Public Libraries;
  20. Sports/Culture (Includes Film, Commercial Broadcasting and the Arts) Promotion, Regulation and Administration;
  21. Travel/Tourism Promotion, Regulation and Administration.

Note that the applicable definition of “government partner or end user” covers certain government organizations at the central, regional, and local levels, which are departments, agencies, or entities performing government functions, including governmental corporations that manufacture or distribute items or services controlled on the Wassenaar Munitions List, governmental research institutions and international governmental organizations. However, the definition of government end-users for US export purposes does not include:

  • Utility providers (such as providers of gas, electricity, telecommunications and internet service);
  • Transport agencies and entities (such as bus, train, and airport authorities);
  • Entertainment or broadcast entities (such as radio or television organizations);
  • Education organizations (such as schools, colleges and universities or other organizations that have direct contact with students);
  • Health and medical organizations (such as hospitals and clinics);
  • Retail & Manufacturing entities (such as retail or wholesale firms; and manufacturers or industrial entities that do not manufacture or distribute Wassenaar Munitions List items or services).

* The above restrictions do not apply to the following Sophos specific product versions: UTM 100, Red 10, Access Point (AP) 10, 30 & 50.

See the following URLs for more information on US export regulations:

http://www.bis.doc.gov; http://www.bis.doc.gov/index.php/regulations/export-administration-regulations-ear

UK Export Controls

Certain products have also been classified in accordance with UK export controls, as noted in Table 2 below, and may be exported in accordance with the Community General Export Authorization (CGEA) and Open Individual Export Licences (OIEL). Such restrictions apply when Sophos products are exported from the UK or by the Sophos UK entity. 

German Export Controls

The Sophos products listed in Table 3 below have also been classified in accordance with German export controls and may only be exported in accordance with the AGG16 and EU001 general licenses. The Table 3 products may not be exported to: Afghanistan, Angola, Armenia, Azerbaijan, Belarus, Burma (Myanmar), Burundi, Cote d'Ivoire, Cuba, Democratic Republic of Congo, Eritrea, Ethiopia, Guinea, Iraq, Iran, Lebanon, Liberia, Libya, Mozambique, Nigeria, North Korea, Pakistan, Somalia, Sudan, South Sudan, Syria, Tanzania, Uganda, Uzbekistan, Yemen & Zimbabwe. In addition, sales to Government end users and any Military, Para Military, Police, Secret Service (and related organizations) end users are only permitted if such end users are located in the following countries: Australia, Austria, Belgium, Bulgaria, Canada, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Japan, Latvia, Lithuania, Luxembourg, Malta, Netherlands, New Zealand, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey, United Kingdom. See the following URL for more information on German export controls: http://www.bafa.de/bafa/en/export_control/index.html

Military End-Users

Military and military-related organizations not located in the member countries of the EU, Australia, Canada, Japan, New Zealand, or the United States may require an export license in order to obtain Sophos products.

Sophos products may not be exported, in their entirety or in part, for (i) military purposes, or (ii) use in connection with the development, production, handling, operation, maintenance, storage, detection, identification or dissemination of chemical, biological or nuclear weapons, or other nuclear explosive devices, or the development, production, maintenance or storage of missiles capable of delivering such weapons.

Products Appearing in More Than One Table

If a product appears in multiple tables below, the applicable export controls of all such countries must be complied with in regards to the exportation of such product.

As noted above, exportation of restricted goods is a complex area and you are responsible for seeking your own legal advice and ensuring your compliance in relation to such matters in the context of your specific export scenario.

Bundled Products

From time-to-time, Sophos may rename or rebundle various products. If you are unsure which of the product names below reflect your purchase, please contact your Sophos Account Manager and they will review your purchase and, upon consultation with the Sophos Legal Department, provide you with the relevant information.


Table 1

Sophos Product ECCN1 License Exception2 CCATS3
Software
Sophos Anti-Spam Interface (SASI) 5D002 (C.1) ENC (unrestricted) G076251
Sophos Anti-Virus (SAV) for Mac 5D992 (C) N/A (mass market) G076252
Sophos Anti-Virus Interface (SAVI) 5D002 (C.1) ENC (unrestricted) G151143
Sophos Computer Security Scan 5D992 (C) N/A (mass market) G079727
Sophos Endpoint Security & Control 5D992 (C) N/A (mass market) G076250
Sophos Endpoint Security & Data Protection 5D992 (C) N/A (mass market) G076250
Sophos for Microsoft SharePoint 5D992 (C) N/A (mass market) G076094
Sophos Mobile Encryption 5D992 N/A (mass market) N/A
Sophos Mobile Security 5D992 N/A (NLR) N/A
Sophos NAC Advanced 5D002 (C) ENC (unrestricted) G076250
Sophos PureMessage for Exchange 5D992 (B) N/A (mass market) G079729
Sophos PureMessage for UNIX 5D992 (C) N/A (mass market) G076094
Sophos PureMessage for Lotus Domino 5D992 (C) N/A (mass market) G076094
Sophos SafeGuard CryptoServer CS and SE software 5D002 ENC (unrestricted) N/A
Sophos SafeGuard CryptoServer Software Development Kit (SDK) 5D002 ENC (unrestricted) N/A
Sophos SafeGuard Enterprise 5D992 (C) N/A (mass market) G077275
Sophos SafeGuard Easy 5D992 (C) N/A (mass market) G077275
Sophos SafeGuard LAN Crypt 5D992 N/A (mass market) N/A
Sophos SafeGuard MailGateway 5D992 N/A (mass market) N/A
Sophos SafeGuard PortProtector 5D992 N/A (NLR) N/A
Sophos SafeGuard PrivateCrypto 5D992 N/A (mass market) N/A
Sophos SafeGuard PrivateDisk 5D992 N/A (mass market) N/A
Sophos SafeGuard RemovableMedia 5D992 N/A (mass market) N/A
Sophos Security Monitor for iPhone EAR99 N/A N/A
Sophos Virtual Email Appliance 5D992 N/A (mass market) N/A
Sophos Virtual Web Appliance 5D992 N/A (mass market) N/A
Sophos UTM Appliance 5D002 (A.1) ENC (restricted) G146757
Sophos UTM100 Appliance 5D992 N/A (mass market) G146757
Appliances
Sophos Email Appliance ES100 5A002 (A.1) ENC (unrestricted) G078960
Sophos Email Appliance ES1000 5A002 (A.1) ENC (unrestricted) G050803
Sophos Email Appliance ES1100 5A002 (A.1) ENC (unrestricted) G073773
Sophos Email Appliance ES4000 5A002 (A.1) ENC (unrestricted) G043583
Sophos Email Appliance ES5000 5A002 (A.1) ENC (unrestricted) G068377
Sophos Email Appliance ES8000 5A002 (A.1) ENC (unrestricted) G068377
Sophos Management Appliance SM2000 5A002 (A.1) ENC (unrestricted) G068809
Sophos Management Appliance SM5000 5A002 (A.1) ENC (unrestricted) G070752
Sophos Web Appliance WS100 5A002 (A.1) ENC (unrestricted) G078960
Sophos Web Appliance WS500 5A002 (A.1) ENC (unrestricted) G068810
Sophos Web Appliance WS1000 5A002 (A.1) ENC (unrestricted) G051630
Sophos Web Appliance WS1100 5A002 (A.1) ENC (unrestricted) G068809
Sophos Web Appliance WS5000 5A002 (A.1) ENC (unrestricted) G138827
Sophos UTM Appliance 5A002 (A.1) ENC (restricted) G146757
Sophos UTM100 Appliance 5A992 N/A (mass market) G146757
Components
Astaro Mail Archiving (AMA) 5D992 N/A (mass market) N/A
PureMessage for Microsoft Exchange (includes Anti-Spam Interface) 5D992 N/A (mass market) N/A
Sophos Access Points 5A992 N/A (mass market) N/A
Sophos Anti Virus (SAV) (includes Windows 9x/NET, 2000+ versions) 5D992 N/A (mass market) G076252
Sophos Anti-Virus (SAV) for Linux/Unix 5D992 ENC (mass market) N/A
Sophos Anti-Virus (SAV) for Mac 5D992 N/A (mass market) G076252
Sophos Anti-Virus (SAV) for VMware vShield 5D002 ENC (unrestricted) N/A
Sophos AutoUpdate (SAU) 5D002 ENC (unrestricted) N/A
Sophos Cloud Agent 5D992 N/A (mass market) N/A
Sophos Cloud Web Agent 5D002 ENC (unrestricted) N/A
Sophos Data Leakage Protection (DLP) EAR99 N/A N/A
Sophos Diagnostic Utility (SDU) EAR99 N/A N/A
Sophos Endpoint Security & Control for Windows 5D992(C) N/A (mass market) G076252
Sophos Enterprise Console (SEC) 5D992 N/A (mass market) G152563
Sophos IPSec Client 5D992 N/A (mass market) N/A
Sophos LAN Crypt5 5D992 N/A (mass market) N/A
Sophos Management Communications System (MCS) 5D992 N/A (mass market) N/A
Sophos Mobile Control5 5D992 N/A (mass market) N/A
Sophos Mobile Encryption 5D992 N/A (mass market) N/A
Sophos Network Access Control (NAC) 5D002 ENC (unrestricted) G076250
Sophos Outlook Add-In 5D002 ENC (unrestricted) N/A
Sophos Patch Assessment (SPA) 5D002 ENC (unrestricted) N/A
Sophos RED 10 5A992 N/A (mass market) N/A
Sophos RED 50 5A002 ENC (restricted) G151089
Sophos SafeGuard Management Center (MC) 5D002 ENC (unrestricted) N/A
Sophos SafeGuard Device Encryption (DE) 5D002 ENC (unrestricted) N/A
Sophos SafeGuard Data Exchange (DX) 5D002 ENC (unrestricted) N/A
Sophos SafeGuard Cloud Storage (CS) 5D002 ENC (unrestricted) N/A
Sophos SafeGuard FileShare (FS) 5D002 ENC (unrestricted) N/A
Sophos SafeGuard Partner Connect 5D002 ENC (unrestricted) N/A
Sophos SafeGuard File Encryption for Mac 5D002 ENC (unrestricted) N/A
Sophos Smart Installer 5D992 N/A (mass market) vN/A
Sophos UTM Email Protection 5D002 ENC (unrestricted) N/A
Sophos UTM Endpoint Protection 5D992 N/A (mass market) N/A
Sophos UTM Essential Firewall 5D002 ENC (restricted) G152563
Sophos UTM Manager 5D992 N/A (mass market) N/A
Sophos UTM Network Protection 5D002 ENC (restricted) G152563
Sophos UTM Web Protection 5D992 N/A (mass market) N/A
Sophos UTM Web Server Protection 5D002 ENC (restricted) G152563
Sophos UTM Wireless Protection 5D002 ENC (unrestricted) N/A
Sophos Virus Removal Tool (SVRT) EAR99 N/A N/A



Table 2

Sophos Product Control Entry4 ECO Reference No.
Sophos Anti-Spam Interface (SASI) 5D002c1 ERE2009/003981
Sophos Anti-Virus (SAV) for Mac 5D002c1 ERE2009/003971
Sophos Anti-Virus (SAV) for UNIX 5D002c1 ERE2009/003971
Sophos Anti-Virus (SAV) for Linux 5D002c1 ERE2009/003971
Sophos Anti-Virus Interface (SAVI) 5D002c1 ERE2009/003981
Sophos Endpoint Security & Control 5D002c1 ERE2009/003966
Sophos Endpoint Security & Data Protection 5D002c1 ERE2009/003966
Sophos for Microsoft SharePoint NLR ERE2009/003881
Sophos NAC Advanced 5D002c1 ERE2009/003966
Sophos PureMessage for Exchange NLR ERE2009/003881
Sophos PureMessage for UNIX NLR ERE2009/003881
Sophos PureMessage for Lotus Domino NLR ERE2009/003881
Sophos SafeGuard Enterprise NLR ERE2009/002227
Sophos SafeGuard Easy NLR ERE2009/002227



Table 3

Sophos LAN Crypt5

  1. ECCN
    Export Control Classification Number assigned by the U.S. Department of Commerce, Bureau of Industry and Security (BIS) in the Commerce Control List (CCL). This is the fundamental designation indicating the level of control for an item.
    Please review the current Commerce Control List Overview and the Country Chart for up to date information on the current countries to which exports are restricted for the referenced ECCNs. Currently, unless otherwise restricted by another country's more restrictive controls, mass market items may be exported without a license to any destination, except to embargoed/sanctioned countries (Cuba, Iran, North Korea, Sudan, and Syria) or to prohibited end-users or for prohibited end-uses.

  2. License Exception ENC
    Sophos received a License Exception from the U.S. Department of Commerce for each of the appliance products after submitting each to a one-time significant technical review by the National Security Agency (NSA). See the following URL for further information on the ENC License Exception: http://www.bis.doc.gov/encryption/enc_faqs.htm#7

  3. CCATS (Commodity Classification Automated Tracking System)
    This is the code number assigned by BIS to products that it has classified against the CCL. If no CCATS number is provided, this indicates that the products have been classified under the Department of Commerce, Bureau of Industry and Security self-classification regulations.

  4. NLR
    This abbreviation indicates that UK Export Control Organization ("ECO") has indicated that the product does not require a license for export from the UK ("No License Required").

  5. Subject to German Export Control
    The LanCrypt products are subject to German export controls as 5A002 or 5D002 products and may only be exported in accordance with the AGG16 and EU001 general licenses as further detailed above.