Fabless design houses sit in a compliance blind spot. Because you don’t operate a fab floor, it’s easy to assume export control obligations are someone else’s problem — the foundry’s, the contract manufacturer’s, the distributor’s. That assumption has cost companies tens of millions of dollars in BIS penalties.
The Export Administration Regulations (EAR) apply to you regardless of whether you hold physical inventory. If you design chips that incorporate U.S.-origin technology and send design files, specifications, or software to an overseas foundry, you are exporting — and EAR requires you to manage it accordingly.
Here’s what most fabless teams miss.
1. The “No Physical Product” Misconception
Fabless companies frequently assume EAR only applies to physical goods crossing a border. It doesn’t.
EAR covers:
- Technical data transmitted electronically (design files, GDS-II layouts, simulation models)
- Software (EDA tools, firmware, embedded code) sent to overseas contractors
- “Deemed exports” — sharing controlled technology with a foreign national on U.S. soil
If your design team shares a GDS-II file with a TSMC or SMIC engineer via email or a shared design portal, that is an export under EAR. Whether it requires a license depends on the chip’s Export Control Classification Number (ECCN) and the destination country.
Action item: Classify every chip design you send offshore against the Commerce Control List (CCL). If you don’t have an ECCN for each product, start there.
2. Foundry Relationships and the “Foreign Direct Product Rule”
One of the most consequential and least understood EAR rules for fabless companies is the Foreign Direct Product (FDP) Rule.
Under FDP, products manufactured outside the U.S. using U.S.-origin technology, software, or equipment may still be subject to EAR — meaning your foundry’s output can be controlled even if you never touch a U.S. fab.
- Review your foundry agreements — do they address EAR obligations and FDP applicability?
- Identify U.S.-origin equipment in your foundry’s process — if TSMC uses Applied Materials or Lam Research equipment to make your chip, FDP may apply
- Document your FDP analysis — BIS auditors will ask for it; “we didn’t think it applied” is not a defense
The FDP Rule was significantly expanded in 2022 and again in 2024 in connection with China-related chip controls. If your foundry relationships include any Mainland China facilities or customers, treat this as a high-priority gap.
3. De Minimis Thresholds
EAR provides an exemption for products with a small percentage of U.S.-controlled content — the “de minimis” rule. Many fabless companies claim this exemption without doing the math.
- The standard threshold is 25% of the product’s fair market value — but for certain destinations (currently Cuba, Iran, North Korea, Syria, Russia, and others), the threshold drops to 10%
- De minimis calculations must be documented — you need a methodology, not an estimate
- Software and technology incorporated by reference counts toward de minimis — it’s not just the physical components
Common mistake: companies calculate de minimis based on bill-of-materials cost rather than fair market value, which understates the U.S.-controlled content percentage.
4. Deemed Export Risk in Design Teams
Fabless design houses typically employ significant numbers of foreign nationals — H-1B engineers, international student interns, overseas R&D teams. Every one of these relationships creates potential deemed export exposure.
- Confirm citizenship and visa status for all engineers with access to ECCN-controlled design files
- Review your technology control plan (TCP) — if you don’t have one, you need one before your next audit
- Audit your EDA tool access — Cadence, Synopsys, and Mentor Graphics suites used with controlled technology may require deemed export licenses for foreign national users
- Check foreign national access to foundry communications — process specifications, yield reports, and quality documentation can all contain controlled technical data
5. End-Use and End-User Certificates
When your chip ends up in a defense application — even one you didn’t design it for — your EAR obligations don’t end at the point of sale.
- Obtain end-use certificates for shipments to higher-risk regions or end-users
- Conduct red flag analysis — EAR’s “know your customer” requirement means you must investigate when transaction circumstances suggest diversion risk
- Screen all end-users against BIS Entity List, OFAC SDN List, and Denied Persons List before every transaction
- Document your red flag analysis — a written record that you looked and found nothing is far more defensible than silence
6. The Annual Compliance Review
Most fabless companies do export control compliance once — when they first encounter a controlled product — and then let it drift.
EAR compliance requires an annual review because:
- The CCL changes — products that weren’t controlled last year may be now
- Foundry relationships change — a new fab partner may trigger FDP obligations you didn’t have before
- The Entity List changes — customers and suppliers get added regularly
- Your product portfolio changes — new chips may have different ECCNs than the ones you classified before
Build a compliance calendar with annual ECCN reviews, entity list rescreens, and internal audit milestones. If that infrastructure doesn’t exist, it’s the first thing an auditor will ask about.
The Bottom Line
Fabless design houses aren’t exempt from EAR — they’re exposed to it in ways that are less obvious and harder to manage than traditional manufacturers. The combination of overseas foundries, multinational design teams, and rapidly evolving restriction lists creates a compliance environment that requires active, documented management.
AUDITPROOF’s semiconductor compliance module maps your design documentation, foundry relationships, and export filings against current EAR requirements — and flags gaps before BIS does.