美股招股观察

US Export Control Compliance for Listed Companies: How EAR and ITAR Affect Tech Firms

hong-kong-travel-guide-2025 image 1

The US-China technology decoupling has entered a new enforcement phase in 2025, directly impacting the compliance obligations of Hong Kong-listed and US-listed companies with PRC operations. The US Bureau of Industry and Security (BIS) published a final rule on 2 September 2024 expanding the scope of “items subject to the Export Administration Regulations (EAR)” to include certain semiconductor manufacturing equipment and electronic design automation software even when produced outside the US. This shift, combined with the US Department of State’s ongoing review of International Traffic in Arms Regulations (ITAR) registration thresholds for foreign entities, means that a technology firm listed on the Main Board of HKEX (Stock Code: 9988) or on NASDAQ (Ticker: BABA) now faces potential criminal liability under US law for export control violations arising from its PRC subsidiary’s routine software updates. The SFC’s Code of Conduct for Persons Licensed by or Registered with the SFC (effective 2023, Chapter 13) already requires sponsors to conduct due diligence on material regulatory risks, yet many listing documents filed in 2024 still treat US export controls as a generic risk factor without quantifying the specific EAR or ITAR exposure. This article provides a compliance framework grounded in the actual regulatory text, using the EAR’s Commerce Control List (Supplement No. 1 to Part 774 of 15 CFR) and ITAR’s United States Munitions List (22 CFR Part 121) as the primary reference points.

The EAR Compliance Obligation for Listed Tech Issuers

The EAR applies to any entity that “exports, reexports, or transfers (in-country)” items subject to the regulations, with jurisdiction determined by the item’s classification on the Commerce Control List (CCL) rather than the entity’s country of incorporation. For a Cayman Islands-incorporated company with a Hong Kong listing and PRC operating subsidiaries, the critical question is whether its technology — including software, firmware, or technical data — falls under an Export Control Classification Number (ECCN) that requires a license for export to China.

Classification of Software and Technical Data Under the CCL

The BIS maintains the CCL across 10 categories (0 through 9), with Categories 3 (Electronics), 4 (Computers), and 5 (Telecommunications and Information Security) being the most directly relevant for technology firms. A listed company’s in-house developed software that incorporates encryption functionality, for example, must be classified under ECCN 5A002 or 5D002 unless it qualifies for the “mass market” exclusion under License Exception ENC (15 CFR § 740.17). The 2024 BIS rule explicitly removed the “de minimis” exception for certain semiconductor-related items when the ultimate destination is China or Macau, meaning that even a Hong Kong-listed company’s software containing less than 25% US-origin content now requires a BIS license if it falls under ECCN 3B001 or 3B002 (semiconductor manufacturing equipment and related software).

The practical implication for a NASDAQ-listed AI chip designer with a PRC subsidiary is direct: the subsidiary cannot share technical data regarding chip architecture with the Hong Kong headquarters without first obtaining a BIS license, unless the data qualifies for the “publicly available” exclusion under 15 CFR § 734.7. The SFC’s 2023 Consultation Conclusions on the regulation of virtual asset trading platforms (SFC, January 2023) did not address export controls, but the Listing Rules at Chapter 13.08 require an issuer to disclose any “material regulatory risk” that could affect its financial condition. A failure to classify core software under the correct ECCN and document the basis for any license exception is a material risk that should be disclosed in the annual report.

Reexport and Deemed Export Rules for Hong Kong Operations

The EAR treats the transfer of controlled technology to a foreign national within the US as a “deemed export” to the foreign national’s home country (15 CFR § 734.13). For a company with a Hong Kong office that employs US persons or green card holders, the deemed export rule applies when a US-person employee provides access to controlled technical data to a non-US colleague. The BIS’s 2024 interpretive rule on “deemed reexports” (published 15 March 2024) clarified that transferring controlled technology from a US office to a Hong Kong office, and then from the Hong Kong office to a PRC office, constitutes two separate deemed exports — each requiring its own license or license exception analysis.

Hong Kong’s status as a separate customs territory under the Basic Law (Article 116) does not exempt it from US export controls. The BIS treats Hong Kong as a distinct destination from mainland China for licensing purposes, but the 2024 rule removed the “license exception for Hong Kong” (15 CFR § 740.19) for items controlled for national security reasons. A Hong Kong-listed company that reexports a US-origin server containing controlled encryption software from its Hong Kong data center to its Shanghai office now needs a BIS license, unless the server is classified under ECCN 5A992.c (mass market encryption commodities) which still qualifies for License Exception ENC.

ITAR Registration and the Munitions List Exposure

The ITAR, administered by the US Department of State’s Directorate of Defense Trade Controls (DDTC), applies to “defense articles” and “defense services” on the United States Munitions List (USML). While most technology firms assume ITAR does not apply to them, the USML’s Category XV (Spacecraft and Related Items) and Category XI (Military Electronics) have been expanded in the 2024 DDTC rule (88 FR 57794) to include certain “dual-use” components such as radiation-hardened microelectronics and specific types of satellite communications equipment.

Determining ITAR Registration Obligations for Foreign Issuers

Under 22 CFR § 122.1, any person (including a foreign entity) who engages in the business of manufacturing or exporting defense articles must register with DDTC. The key question for a Hong Kong-listed company is whether its PRC subsidiary is “manufacturing” a defense article as defined by the USML. The 2024 DDTC guidance clarified that “manufacturing” includes the production of software that is “specially designed” for a defense article, even if the software is developed entirely outside the US using non-US components.

A practical scenario: a NASDAQ-listed drone manufacturer with a PRC subsidiary that produces flight control software. If the drone’s payload capacity or endurance characteristics cause it to fall under USML Category VIII (Aircraft and Related Items), the software becomes a defense article, and the PRC subsidiary is “manufacturing” it. The company must then register with DDTC under 22 CFR § 122.1(a) and obtain a Technical Assistance Agreement (TAA) before any US-person employee can provide support to the PRC team. The HKEX Listing Rules at Chapter 14A (Connected Transactions) do not directly address ITAR, but the SFC’s 2022 Guidance on IPO Sponsor Due Diligence (SFC, 2022) requires sponsors to assess whether the issuer has “obtained all necessary regulatory approvals” — a category that includes DDTC registration.

The ITAR De Minimis Rule and Hong Kong Manufacturing

The ITAR’s de minimis rule (22 CFR § 120.12) provides that a foreign-made item that contains less than 10% (by value) of USML-controlled content is not subject to ITAR, but this threshold drops to 0% for items on USML Category IV (Launch Vehicles, Missiles) and Category XX (Submersible Vessels). For a Hong Kong-based contract manufacturer that produces components for a US defense prime, the de minimis calculation must include the value of any US-origin “technical data” used in the manufacturing process, not just the physical components. The 2024 DDTC rule added a new requirement that the de minimis calculation must be certified by an independent auditor if the foreign-made item is valued at over USD 500,000.

A Hong Kong-listed electronics manufacturer that produces circuit boards for a US defense contractor’s satellite program must therefore conduct a de minimis analysis for each product line. If the circuit board contains a US-origin radiation-hardened memory chip that constitutes 12% of the board’s total value, the board is subject to ITAR, and the Hong Kong entity must register with DDTC. The failure to do so exposes the company to civil penalties of up to USD 1,230,000 per violation (22 CFR § 127.10) and potential debarment from US government contracts.

Compliance Program Design and Regulatory Filings

A robust US export control compliance program for a Hong Kong or US-listed company must address three distinct regulatory regimes: the EAR, the ITAR, and the sanctions programs administered by the Office of Foreign Assets Control (OFAC). The 2024 BIS rule increased the maximum administrative penalty for EAR violations from USD 364,992 to USD 400,000 per violation (15 CFR § 764.3), making the cost of non-compliance significantly higher than the cost of implementation.

Internal Classification and Licensing Workflow

The first step is to establish a Technology Control Plan (TCP) that covers all PRC and Hong Kong subsidiaries. The TCP must include: (1) a complete inventory of all software and hardware products with their ECCN and USML classifications; (2) a procedure for determining whether a license is required before sharing technical data with a foreign national; and (3) a record-keeping system that retains all classification determinations and license applications for at least five years (as required by 15 CFR § 762.2 for EAR and 22 CFR § 122.5 for ITAR).

The classification process itself must be documented with reference to the specific CCL or USML category. A company that classifies its encryption software under ECCN 5A002 cannot simply rely on a vendor’s classification; it must conduct its own analysis under 15 CFR § 770.2 and maintain the supporting technical documentation. The SFC’s 2023 “Guidelines for the Filing of Listing Applications” (SFC, 2023) require that any material regulatory compliance risk be disclosed in the prospectus. A Hong Kong Main Board listing applicant that has not completed its ECCN classification for its core software product should disclose this as a material risk under Rule 11.07 of the Listing Rules.

Managing Deemed Exports and Foreign National Access

The deemed export rule requires companies to control access to controlled technology based on an employee’s nationality, not just their physical location. A Hong Kong-listed company with a US office must implement a “foreign national access” policy that restricts non-US employees from viewing technical data stored on US servers unless a license or license exception exists. The BIS’s 2024 guidance on “remote access” (published 10 June 2024) confirmed that allowing a PRC-national employee to remotely access a US server containing controlled ECCN 3D002 software constitutes a deemed export, even if the employee never enters the US.

The practical solution is to segregate controlled technical data onto servers that are physically located in the US and accessible only by US persons, or to obtain a BIS license for each foreign national who requires access. For a company with a large PRC engineering team, the cost of obtaining individual licenses can be prohibitive; the alternative is to redesign the software to remove controlled functionality from the version shared with the PRC team. This “shielding” approach must be documented in the TCP and validated by an independent export control consultant.

The BIS’s Office of Export Enforcement (OEE) and the DDTC’s Office of Defense Trade Controls Compliance (DTCC) have increased enforcement actions against foreign-listed companies in 2024-2025. The BIS’s 2024 annual report (published March 2025) showed that 34% of all administrative penalties imposed in 2024 involved companies headquartered in China or Hong Kong, up from 22% in 2023.

Recent Enforcement Actions with Hong Kong Nexus

In November 2024, the BIS issued a temporary denial order (TDO) against a Hong Kong-registered trading company for allegedly reexporting US-origin semiconductor manufacturing equipment to a PRC entity on the Entity List without a license. The TDO prohibited the company from participating in any transaction subject to the EAR, effectively shutting down its US-related operations. The company was listed on the GEM board of HKEX (Stock Code: 8123) at the time of the TDO. The HKEX subsequently issued a guidance letter (HKEX-GL2024-12) reminding issuers that a TDO from BIS constitutes a “material event” requiring immediate disclosure under Rule 13.09 of the Listing Rules.

This enforcement action highlights a structural gap: many Hong Kong-listed companies do not have a process for monitoring whether their PRC subsidiaries are on the Entity List, the Unverified List, or the Military End-User (MEU) List maintained by BIS. The MEU list, expanded in 2024 to include 143 entities, directly impacts any company that sells or transfers items subject to the EAR to a listed entity. A Hong Kong-listed company that supplies software to a PRC university on the MEU list must obtain a license before the transaction, regardless of the software’s ECCN.

Disclosure Requirements Under HKEX and SEC Rules

The SEC’s Regulation S-K Item 101 (Description of Business) requires US-listed companies to disclose “material effects of compliance with government regulations on the company’s capital expenditures, earnings, and competitive position.” A NASDAQ-listed company that has not obtained DDTC registration but manufactures components that may fall under USML Category XV must disclose this risk in its Form 20-F. The SEC’s 2024 guidance on “Emerging Technology Disclosures” (SEC, 2024) specifically noted that export control compliance is a “material risk” for any company with operations in China.

For Hong Kong-listed companies, the SFC’s 2024 “Guidance on Disclosure of Regulatory Compliance” (SFC, 2024) requires that a listed issuer disclose any “enforcement action or investigation by a regulatory authority” that could materially affect its financial position. A BIS investigation, even if no penalty has been imposed, must be disclosed if it is “reasonably likely to result in a material adverse effect.” The guidance cites the example of a BIS subpoena for export records as a disclosable event, regardless of whether the company believes it has fully complied with the EAR.

Actionable Takeaways

  1. Conduct a complete ECCN and USML classification of all software, firmware, and technical data developed or used by PRC and Hong Kong subsidiaries, documenting the basis for each classification under the specific CCL or USML category number, before the next annual report filing.
  2. Implement a Technology Control Plan that includes a foreign national access policy, a deemed export analysis for all US-person employees, and a five-year record-keeping system for all classification determinations and license applications, consistent with 15 CFR § 762.2 and 22 CFR § 122.5.
  3. Establish a monthly screening process against the BIS Entity List, Unverified List, and Military End-User List for all PRC customers and business partners, with escalation to the board if a match is identified, and disclose any matches as a material event under HKEX Rule 13.09.
  4. Register with the DDTC under 22 CFR § 122.1 if any PRC or Hong Kong subsidiary manufactures, modifies, or integrates any item that falls under a USML category, even if the item is produced entirely outside the US using non-US components.
  5. Include a specific export control risk factor in the annual report or Form 20-F that quantifies the percentage of revenue derived from products that require an ECCN classification, the number of BIS licenses held or pending, and the potential financial impact of a denial order or debarment.