On October 2, 2026, the U.S. Department of Commerce's Bureau of Industry and Security (BIS) published an administrative settlement with Lambda Research Corporation, a Massachusetts maker of optical and illumination design software (TracePro and OSLO), assessing a $2,000,000 civil penalty for 66 violations of the Export Administration Regulations (EAR). The Settlement Agreement holds that shipping software license dongles and pushing automatic updates to Entity List parties each count as an EAR export requiring a license.

Other U.S. providers of EAR99 technical software, and any exporter licensing software via dongles, access information, automatic updates or maintenance to Huawei-linked or China-based end-users through third-country distributors, must immediately screen every end-user, including the ultimate end-user behind distributor sales, against the Entity List and Unverified List and obtain BIS licenses before shipping, or face a civil penalty of up to $374,474 per violation, denial of export privileges, and a mandated compliance audit.

  • Authority : Bureau of Industry and Security (BIS), U.S. Department of Commerce
  • Entity : Lambda Research Corporation, Westford, Massachusetts (optical and illumination design software)
  • Measure and amount : $2,000,000 civil penalty, suspended one year and waived on compliance, plus mandated training and audit
  • Legal basis : 15 C.F.R. §§ 744.11, 744.15, 734.19, 764.2(a) and 764.2(e); settlement under § 766.18(a)
  • Decision date : October 2, 2026 (BIS press release and Order)
  • Official source : BIS Settlement Agreement and Proposed Charging Letter (PDF)

What happened

Between April 10, 2021 and August 12, 2025, Lambda sold and serviced EAR99 software for Entity List parties without a BIS license. It shipped CodeMeter dongles holding TracePro and OSLO licenses to Huawei Technologies Japan (Huawei Japan) through Japan distributor Noughts and Crosses, Ltd., and sold maintenance subscriptions that delivered automatic updates. After SiCarrier joined the Entity List on December 2, 2024, Lambda pushed seven automatic TracePro updates to it through ChinaSoft Technology (Shenzhen) and distributor Shanghai LightPaths. Lambda also exported a TracePro and RayViz license to the Sun Yat-Sen University marine lab (SMSEL), a Unverified List party, without the required UVL statement. The penalty is suspended for one year under Lambda's voluntary self-disclosure of October 31, 2025.

The breach

The Order applies three EAR doctrines. Under the access information rule, 15 C.F.R. § 734.19, a dongle that unlocks EAR99 software needs the same license as the software, because transferring access information knowing it will release the software is an export. The Order states that each automatic update of TracePro and OSLO constitutes an export under the EAR, so every update push to an Entity List party is a separate § 744.11 violation. Under § 744.15(b), a UVL statement is required before any transfer to a Unverified List party. Lambda committed 11 violations of § 764.2(e) and 55 of § 764.2(a), 66 in total, against a $374,474 per-violation maximum.

Who else is in the same regime

The doctrine is not Lambda-specific. Any U.S. software company licensing an EAR99 product by dongle or access information to entities in China or to Huawei affiliates is exposed, because EAR99 does not exempt an item from end-user controls. Exporters using third-country distributors in Japan or China carry the same ultimate-end-user risk: Lambda was charged for Huawei Japan and SiCarrier exports routed through Noughts and Crosses, Shanghai LightPaths and ChinaSoft. Companies pushing automatic updates or maintenance to listed parties face per-update violations, as the 47 updates to Huawei Japan and 7 to SiCarrier show. BIS singled out the SME with no written compliance program and no trained personnel.

What to check now

  • Screen the true end-user of every license, dongle, update and maintenance contract, including end-users behind distributors, against the Entity List and Unverified List.
  • Treat each automatic update and dongle shipment as a separate EAR export: stop unattended auto-updates to listed parties and obtain a § 744.11 license first.
  • Obtain a UVL statement under § 744.15(b) before any transfer to a Unverified List party, even for EAR99 items.
  • Review distributor and reseller contracts in China and Japan to confirm the ultimate end-user, and flag intermediary naming such as "ChinaSoft (Sicarrier)".
  • Stand up a written export compliance program with trained personnel, and self-disclose any historical updates or dongles that reached listed parties.

Continuous, per-jurisdiction monitoring surfaces Entity List and Unverified List changes the day BIS publishes them, before an update push becomes a violation.

Live
US export controls: BIS entity list, EAR rules and foreign direct product extensions
Monitor US export control rules for exporters and re-exporters of controlled items, software and technology with US content.
Email 10+ news

Sources