DFM Platform

DFM Professional Packs · Guides · The Internal Compliance Programme (ICP) for dual-use exporters: what the EU actually expects

Guide

The Internal Compliance Programme (ICP) for dual-use exporters: what the EU actually expects

When an ICP is required, the Commission's seven core elements, cyber-surveillance due diligence and record-keeping — what Regulation (EU) 2021/821 and the official guidance actually say.

By Defence Finance Monitor · Published 2026-07-12

If your company exports dual-use items — goods, software or technology with both civil and military applications — EU law increasingly expects you to run a documented internal compliance programme (ICP). Not as a nice-to-have: for some authorisations it is a condition, and for a growing set of situations (non-listed items, cyber-surveillance capabilities, intangible transfers) it is the practical difference between a managed process and an improvised one.

This guide sets out what the EU framework actually says: when an ICP is expected, what the Commission's official guidance requires it to contain, and where the newer obligations — cyber-surveillance due diligence, record-keeping — fit in. It is general information, not legal advice; classification and authorisation decisions belong to specialists and competent authorities.

What an ICP is, in the regulation's own words

Regulation (EU) 2021/821 — the recast EU dual-use regime — defines an ICP in Article 2(21) as "ongoing effective, appropriate and proportionate policies and procedures adopted by exporters to facilitate compliance with the provisions and objectives of this Regulation and with the terms and conditions of the authorisations implemented under this Regulation, including, inter alia, due diligence measures assessing risks related to the export of the items to end-users and end-uses".

Three words in that definition do a lot of work: ongoing, proportionate, due diligence. An ICP is not a binder produced once for a licence application; it is a running process, scaled to the business, that assesses end-users and end-uses transaction by transaction.

When an ICP stops being optional

The clearest trigger is Article 12(4): exporters using global export authorisations shall implement an ICP, unless the competent authority considers it unnecessary on the basis of other information it has taken into account when processing the application. In other words: if you want the flexibility of a global authorisation, the ICP is the price of admission — and the burden of showing it is unnecessary sits with the process, not with you.

Beyond that trigger, the same machinery is what lets an exporter handle the regulation's other duties credibly: the catch-all conditions of Article 4 (non-listed items that may be intended for uses of concern), brokering (Article 6) and transit (Article 7) situations, and the Union General Export Authorisations of Annex II (EU001–EU008), each of which comes with conditions and exclusions that someone in the company must actually check.

The seven core elements (Commission Recommendation (EU) 2019/1318)

The Commission's ICP guidance — Recommendation (EU) 2019/1318, issued under the predecessor regulation and still the reference framework — structures an ICP around seven core elements:

  1. Top-level management commitment to compliance
  2. Organisation structure, responsibilities and resources
  3. Training and awareness raising
  4. Transaction screening process and procedures
  5. Performance review, audits, reporting and corrective actions
  6. Recordkeeping and documentation
  7. Physical and information security

Two features of the guidance deserve emphasis. First, proportionality is explicit: an ICP "needs to be tailored to the size, the structure and scope of the business" — the guidance was drafted with SMEs systematically in mind, and a five-person exporter is not expected to run a multinational's compliance department. Second, the guidance treats transaction screening (element 4) as the operational heart of the programme: items, end-use, parties and destinations, with a hold-and-escalate mechanism when red flags appear.

For research organisations — universities, research institutes, TTOs — the Commission adapted the same structure in Recommendation (EU) 2021/1700, which keeps the seven elements but reframes them for a research context (element 4 becomes "export screening process and procedures").

The 2024 layer: cyber-surveillance due diligence

Since October 2024 there is an additional, explicitly documented expectation. Recommendation (EU) 2024/2659 provides the guidelines foreseen by Articles 5(2) and 26(1) of the regulation for exporters of non-listed cyber-surveillance items. The guidelines expect exporters to carry out due diligence through transaction-screening measures in four steps: determine whether the non-listed item could be a cyber-surveillance item (as defined in Article 2(20)); review the item's capabilities for potential misuse in connection with internal repression or serious violations of human rights and international humanitarian law; review the stakeholders in the transaction (end-users, consignees, distributors, resellers); and use the findings to prevent and mitigate potential adverse impacts.

The guidelines also supply two lettered red-flag lists — one on item capabilities, one on stakeholders — that belong in any screening procedure touching surveillance-capable technology. If your product can observe, intercept or analyse the behaviour of natural persons, this layer applies to you even if nothing you sell appears in Annex I.

Record-keeping: the quiet obligation that decides audits

Article 27(1) requires exporters of dual-use items to keep detailed registers or records of their exports, including commercial documents such as invoices, manifests and transport and other dispatch documents. Retention periods are set by Article 27(3): at least five years from the end of the calendar year in which the export took place — with Article 27(4) setting at least three years for records of intra-Union transfers of Annex I items. When an authority asks, the question is rarely "do you have a policy?" and almost always "show me the records for this shipment".

Getting started, proportionately

A realistic first pass for an SME looks like this: map your trade flows (items, destinations, channels — including e-mail, cloud and remote access, because intangible transfers are exports too); record what you know about the Annex I status of your items, in its current version (Annex I was last updated by Delegated Regulation (EU) 2025/2003), and route open classification questions to a specialist; write down the transaction-screening steps you actually perform and who performs them; check each of the seven elements against what exists today and turn every gap into an action with an owner and a date; and put record-keeping and retention on a footing that would survive an authority request.

That gap-by-gap exercise — the seven elements as a structured assessment, the cyber-surveillance red flags, the authorisations map from individual to EU001–EU008, transaction screening and record-keeping templates — is exactly what the DFM Dual-Use Export Compliance (ICP) Pack packages into a workbook and editable documents. It produces preliminary flags and an action plan for internal preparation; it never classifies items and never concludes on authorisations — those decisions belong to specialists and competent authorities.


Article references confirmed against the official texts on EUR-Lex (source-check 2026-07-12): Regulation (EU) 2021/821 (CELEX 32021R0821); Commission Recommendation (EU) 2019/1318; Commission Recommendation (EU) 2021/1700; Commission Recommendation (EU) 2024/2659; Commission Delegated Regulation (EU) 2025/2003. This article is general information, not legal advice.

Related pack

Export compliance

Dual-Use Export Compliance (ICP) Pack 2026

Build and evidence your internal compliance programme: the Commission's seven ICP core elements, transaction and end-use screening, cyber-surveillance due diligence (Rec (EU) 2024/2659), authorisations map incl. EU001–EU008.

From €790

View pack & licences →