Export Control

Core Export Control Frequently Asked Questions

What is Export Control?

Export Controls are a complex set of federal laws and regulations designed to protect U.S. national security, economic interests, and foreign policy. They restrict the transfer of sensitive technologies, hardware, software, and data to foreign countries or to foreign nationals within the United States.

At NIU, these regulations primarily come from two federal agencies:

The Department of State

Manages the International Traffic in Arms Regulations (ITAR), which control military, defense, and space-related technologies.

The Department of Commerce

Manages the Export Administration Regulations (EAR), which control dual-use items—technologies designed for commercial purposes that also have potential military applications (e.g., advanced materials, lasers, or high-performance computers).
What is an Export?

An export is any transfer of controlled items, technology, software, or technical data out of the United States.

For university researchers, an export isn't just shipping a crate overseas. It happens when you:

  • Ship or mail physical samples, custom hardware, or specialized sensors to an international destination.
  • Travel internationally with university-owned laptops, encrypted hard drives, or proprietary project data.
  • Transmit digital data via email, cloud storage, or virtual presentations to an overseas recipient.
Does International Travel Require an Export Control Review?

Yes, international travel can raise export control considerations, even when no research equipment is being shipped. Traveling with university-owned laptops, mobile devices, specialized software, encrypted equipment, research data, or proprietary information may trigger export control requirements depending on your destination and the materials you are taking abroad.

Before international travel, review NIU's International Travel guidance to understand registration requirements, device recommendations, and export control considerations.

Visit International Travel to learn more.

What is a Deemed Export?

A deemed export occurs right here on campus. Under federal law, sharing controlled technical data or software source code with a foreign national inside the U.S. is legally treated as though you exported that information directly to their home country.

How It Happens

A deemed export can occur during lab tours, face-to-face conversations, shared access to research servers, or collaborative data analysis.

Why It Matters

If your research involves controlled technology, a federal export license may be required before allowing certain foreign nationals access to controlled technology or technical data.

What is Fundamental Research? Is My Research Restricted?

Fundamental research is basic or applied research in science and engineering where the resulting information is intended to be shared and published broadly within the scientific community.

  • The Exemption: Under the Fundamental Research Exclusion (FRE), the results of your research are entirely exempt from federal export controls, meaning you are free to publish and collaborate openly.
  • The Quick Rule: If your project has no publication restrictions and no restrictions on who can participate, your research results generally remain eligible for the Fundamental Research Exclusion.
  • How you lose it: This exemption may no longer apply if you accept publication approval requirements, dissemination restrictions, or limitations on who may participate in the research.
  • The Catch: This exemption only covers information - it does not exempt physical equipment, international shipping, or foreign travel from federal regulations. Principal Investigators (PIs) still need a review if they are shipping hardware, accessing proprietary background data, or traveling with NIU devices.

Foreign Countries of Concern (The CHIPS Act List)

What are "Countries of Concern"?

The federal government applies heightened security oversight, strict licensing requirements, and funding prohibitions to activities involving specific nations that pose a risk to U.S. national security. Because different federal agencies maintain distinct regulatory oversight lists based on their specific missions, countries of concern can vary depending on your project's funding source and technical scope.

Agency-Specific Risk and Sanctions Lists

If your research involves funding, data, or regulations from the following agencies, additional country-specific restrictions and licensing triggers apply:

  • Department of Energy (DOE): The DOE maintains a specific list of nations evaluated as high-risk under the National Counterintelligence Strategy. These include: China, Russia, Iran, North Korea, and Belarus.
  • National Institutes of Health (NIH): In alignment with Department of Justice data privacy directives (28 CFR § 202.601) and NIH genomic data sharing mandates, the NIH bars institutions located in specific countries from accessing NIH Controlled-Access Data Repositories. These targeted oversight nations include: China, Cuba, Iran, North Korea, Russia, and Venezuela.
  • United States Department of Agriculture (USDA): Managed by the Office of Research, Economic, and Science Security (ORESS), the USDA enforces heightened risk matrices regarding foreign investment, agricultural technology transfers, and genetic resources. The USDA utilizes the baseline federal standard for its stricter reporting mandates, focusing heavily on: China, Russia, Iran, and North Korea.
  • Department of Justice (DOJ): Under 28 CFR § 202.601, the DOJ formally defines its countries of concern as: China, Cuba, Iran, North Korea, Russia, and Venezuela.
  • Department of Commerce: The Bureau of Industry and Security (BIS) maintains strict export licensing requirements and restrictions (including the comprehensive "List E") that heavily target: Cuba, Iran, North Korea, Syria, Russia, Belarus, Iraq, and software/technology destinations like Hong Kong.
  • Department of State: Countries of Particular ConcernThe State Department designates nations with severe oversight risks, which currently include: Burma, China, Cuba, Eritrea, Iran, North Korea, Nicaragua, Pakistan, Russia, Saudi Arabia, Tajikistan, Turkmenistan, and Nigeria.
  • Office of Foreign Assets Control (OFAC): While OFAC does not maintain a single comprehensive list of banned countries, it administers comprehensive economic and trade sanctions that restrict U.S. persons from doing business with specific sanctioned regimes and geographic regions.

Note: These lists are dynamic and subject to frequent updates by federal oversight agencies. If your research involves international collaborations, personnel, or travel tied to any of the nations listed above or if you have any questions or concerns about how these lists might impact your project - please reach out to our office. You can contact the Office of Research Compliance, Integrity, and Safety at researchcompliance@niu.edu early in the proposal stage to ensure proper compliance and vetting.

Roles and Responsibilities of a Principal Investigator (PI)

What are my primary responsibilities as a PI regarding Export Controls?

Export control compliance is a shared partnership between the university administration and the research team. As the Principal Investigator, you have the closest view of your project's day-to-day operations. Your core responsibilities include:

  • Vetting Your Team: Ensuring all foreign national students, post-docs, and visiting scholars are cleared by our office via a Restricted Party Screening (RPS) before allowing them access to controlled equipment or data in your lab.
  • Monitoring Your Contracts: Reviewing your award terms and agency guidelines during proposal routing to ensure you don't inadvertently accept publication or citizenship restrictions without a Technology Control Plan (TCP) in place.
  • Securing Your Physical Shipments: Confirming that any equipment, custom hardware, or technical data is formally classified before it is shipped or hand-carried outside the United States.
  • Maintaining Academic Integrity: Disclosing all foreign affiliations, talent program invitations, and outside financial support accurately to both NIU and your federal sponsors.

Export Control Questions for Proposal Submissions

Are you completing NIU’s proposal routing form? Use the guide below to accurately answer the mandatory Export Control questions.

Do the agency guidelines or award terms explicitly reference restrictions in the area of Citizenship requirements?

What this means for your proposal: Federal agencies or private sponsors occasionally include clauses that limit who can work on a project based strictly on their country of citizenship.

  • Select Yes if: The Request for Proposal (RFP), funding announcement, or draft agreement states that only U.S. citizens can participate, or that foreign nationals require prior approval from the sponsor.
  • Select No if: The project is open to all qualified university personnel, students, and scholars regardless of their nationality.
  • Why it matters: Accepting citizenship restrictions automatically voids the Fundamental Research Exclusion (FRE). If you must answer Yes, contact Research Security immediately so we can evaluate if a Technology Control Plan (TCP) is required.
Do the agency guidelines or award terms explicitly reference restrictions in the area of Foreign Nationals?

What this means for your proposal: This is closely tied to citizenship but focuses on the participation of international scholars, students, or collaborators.

  • Select Yes if: The guidelines state that foreign nationals cannot have access to certain project data, laboratories, or software components, or if the sponsor requires a background check/vetting process specifically for non-U.S. persons.
  • Select No if: There are no clauses restricting international students or foreign faculty from participating in the research or accessing the results.
  • Why it matters: Just like citizenship restrictions, barring foreign nationals removes your project from the Fundamental Research safe harbor. We will need to review the specific contract language to protect your project.
Do the agency guidelines or award terms explicitly reference export control regulations?

What this means for your proposal: Sponsors will often include a standard clause notifying the university that the project may involve sensitive data regulated by federal export laws.

  • Select Yes if: You see explicit mentions of acronyms like ITAR (International Traffic in Arms Regulations), EAR (Export Administration Regulations), or statements like The contractor agrees to comply with all U.S. export control laws.
  • Select No if: There is no mention of export controls, ITAR, or EAR anywhere in the solicitation or award terms.
  • Why it matters: A Yes here is a helpful flag for our office. It doesn't mean your research is restricted, but it tells us we need to double-check the project's technical scope to ensure you don't inadvertently handle controlled hardware or software without a license.
Do the agency guidelines or terms and conditions reference Controlled Unclassified Information (CUI)?

What this means for your proposal: CUI is a specific federal security classification for sensitive data created or possessed by the government that requires safeguarding or dissemination controls. It is common in DoD, DoE, and NASA awards.

  • Select Yes if: The broad agency announcement or contract specifically mentions CUI, Controlled Unclassified Information, or federal data security clauses like DFARS 252.204-7012 or NIST SP 800-171.
  • Select No if: The project involves purely open, publishable academic research with no federal data safeguarding mandates.
  • Why it matters: Handling CUI requires NIU to implement strict cybersecurity and physical security measures. Flagging this Yes early ensures we can set up a secure digital environment for your data before the funds arrive.
Will project personnel send any materials, technology (hardware, software, etc.), or equipment purchased with award funds to a location outside the United States?

What this means for your proposal: This tracks the physical movement of items across U.S. borders, which constitutes a legal export regardless of whether the item is commercially available.

  • Select Yes if: You plan to ship lab equipment, custom sensors, biological samples, or specialized software to international collaborators, or if a team member will hand-carry NIU-purchased hardware abroad for field research.
  • Select No if: All equipment, materials, and technology purchased with the grant will remain within the United States.
  • Why it matters: Shipping items internationally is never exempt under the Fundamental Research Exclusion. If you check Yes, the Research Security team will perform a quick classification review to see if a federal export license is required before anything leaves the university.

Institutional Security and Oversight

When do I need a Technology Control Plan (TCP)?
A Technology Control Plan (TCP) is a customized security blueprint for your lab. It outlines the physical locks, IT safeguards, and personnel restrictions required to protect controlled data or hardware on campus. You need a TCP if you accept a project with publication restrictions, or if you are using proprietary, export-controlled background data from an industry sponsor.
What are Restricted Party Screenings (RPS)?
The U.S. government maintains strict lists of foreign individuals, companies, and universities that are banned from receiving American technology. Before NIU hires a foreign national scholar, hosts a visiting researcher, or enters into an international collaboration, our office performs a quick, digital Restricted Party Screening (RPS) to ensure the individual or institution is cleared for academic partnership.
What should I do if I suspect a compliance violation?
Export control violations carry heavy institutional and personal federal penalties, but self-reporting an accidental oversight early allows the university to assess the situation promptly and determine appropriate corrective actions. If you think controlled data was accidentally shared, a shipment left without a license, or a laptop was compromised abroad, contact the Research Security team at researchcompliance@niu.edu immediately so we can help mitigate the issue.

Quick Links and Compliance Resources

Questions or Contract Reviews?

Contact the Research Security team at researchcompliance@niu.edu.