top of page

EU export controls explained: Catch-All

Is your supply chain ready for the catch-all provisions under EU Dual-Use Regulation 821/2021? This expert interview explores.


Catch-all deals with the control of non-listed items that may nonetheless be put to dangerous uses in the wrong hands. It creates compliance challenges because it demands subjective evaluation of items and users. Here we discuss how best to prepare for the 821/2021 catch-all requirements – and having the right systems in place.


World ECR editor Tom Blass is querying Export Control & Sanctions Expert Arne Mielken to discuss all matters REgulation 821-2021 - the EU Dual Use Regulation.


Here are the question he will ask Arne:

  • I hear a lot about ‘catch-all’. Remind me what it is again?

  • So, how is the new catch-all requirement different to what existed in the old regulation?

  • Is there anything I can do to prepare for catch-all? Does this mean I need to increase my due diligence?

  • Is some MS (Member State) more likely to apply catch-all than others?

  • I do business with ‘safe’ jurisdictions – e.g., the US, Canada, NZ, Switzerland, India etc. – does that mean that I don’t have to worry too much?


Tom Blass: I hear a lot about ‘catch-all’. Remind me what it is again?



Silhouetted person using phone beside colorful lights. EU flag with "Export Controls" text. "Customs Manager" on both sides. Dark blue overlay.

Arne Mielken: Catch me if you can”, indeed. The catch-all provisions under the EU Dual-Use Regulation grant national authorities the power to prohibit the export of dual-use items not listed in Annex I, particularly when they suspect those items may be intended for illicit or prohibited end-uses.

Let’s break this down clearly:

  • Listed items are controlled based on their technical characteristics as defined in Annex I.

  • Non-listed items, however, can become controlled based on their intended end-use — this is the essence of the catch-all concept.


For instance:


  • If a non-listed item is intended for use in connection with weapons of mass destruction (WMD), then an export licence is mandatory — although it’s highly unlikely such a licence would be granted.


  • Similarly, if the item is intended for military use in a country under an EU, UN or OSCE arms embargo, it would also fall under catch-all control and become licensable.

So, while listed items are controlled by what they are, non-listed items are controlled by what they might be used for. That’s why we often refer to catch-all as end-use controls.

Now, here’s an important point:The decision on whether a particular non-listed item requires a licence under catch-all provisions is made by the individual Member State. This decentralised approach has not changed with the introduction of the new EU Dual-Use Regulation (Regulation 821/2021).


🛑 Good in Theory, But Problematic in Practice

While the idea behind catch-all controls is sound — preventing misuse of sensitive items — the practical application is fraught with challenges:

  • An exporter might be obliged to apply for a licence for a non-listed item in Member State A, but face no such requirement in Member State B, for the same item and end-use.

  • The interpretation of whether an exporter has been “informed” or is “aware” of a potential end-use can vary significantly, creating legal uncertainty.

  • There’s substantial room for inconsistent application, even arbitrariness, between different Member States.


This inconsistent implementation weakens the harmonisation that the regulation aims to achieve and creates a compliance headache for exporters operating across the EU.

In summary:

The catch-all provisions are designed to close dangerous loopholes — but their effectiveness is often undermined by lack of clarity, inconsistent enforcement, and interpretive grey zones.

While the intentions behind the catch-all regime are commendable, its practical execution leaves much to be desired.


So, while the intentions were goods, the practical implementation was lacking somewhat.


Tom Blass: I see. So, how is the new catch-all requirement different to what existed in the old regulation?


The changes introduced under Regulation 821/2021 are subtle, almost hidden — and if you don’t examine the regulation carefully, you might easily miss them. But make no mistake: they are significant and complex. Let me walk you through them.

Let’s start with the foundation: the catch-all clause.


Under the previous Regulation 428/2009, Article 3(2) states:

“An authorisation may also be required for the export to all or certain destinations of certain dual-use items not listed in Annex I – pursuant to Article 4 or Article 8.”

So, there were two key articles under which a licence could be required for non-listed dual-use items:

  • Article 4 allowed Member States to impose licence requirements based on specific end-uses – for example:

    1. If the items are (or may be) intended for weapons of mass destruction (WMD) programmes;

    2. If intended for military end-use in countries subject to an EU, UN, or OSCE arms embargo;

    3. If destined as components of military items previously exported illegally.

If the competent authority has informed the exporter – or if the exporter knows or suspects – that the item may be used for one of these purposes, they must obtain a licence and report the situation.


  • Article 8 gave Member States the ability to impose controls for public security or human rights concerns, even if the items are not listed.


These core principles remain intact under Regulation 821/2021. However, here’s where the shift happens.

Now, under Article 3(2) of 821/2021, an authorisation may be required pursuant to four articles – not just two:

Articles 4, 5, 9, and 10

That’s right – the scope of the catch-all clause has expanded by 50%.


Let’s look at each one:


🔐 Article 5 – Cyber-Surveillance Controls

This is a new, targeted catch-all provision.It requires a licence for non-listed cyber-surveillance items if they are (or may be) intended for:

  • Internal repression, or

  • The commission of serious human rights violations or breaches of international humanitarian law.

This means that cyber-surveillance tools are now under tighter scrutiny, even if they’re not specifically listed.


🛡️ Article 9 – Public Security, Human Rights & Terrorism

Previously, Article 8 covered public security and human rights. Now, under Article 9, we also see the addition of “prevention of terrorism” as a basis for control.This broadens the justification Member States can use to require licences for non-listed items.


📋 Article 10 – The “Watch List”

This is arguably the most complex and ambiguous change.

To the best of my understanding, it introduces the idea that if an item appears on a national control list in one EU country (say, Malta), that item could become subject to licensing in another country (like Estonia).This could imply cross-border recognition of national controls, although I’m still waiting for clear confirmation on how this will be implemented in practice. If anyone can clarify this further, I’d genuinely welcome it.


Now, here’s perhaps the most subtle but impactful change — and it’s easy to overlook.

Let’s compare the original and new Article 4(1):

  • Under 428/2009, Article 4(1) applied only to WMD-related end-uses — specifically:

“Development, production, handling, operation, maintenance, storage, detection, identification or dissemination of chemical, biological or nuclear weapons or their delivery systems.”
  • But in 821/2021, while the wording seems similar, Article 4(1) is now referenced across multiple parts of the regulation:

    • Article 6 – Brokering

    • Article 7 – Transit

    • Article 8 – Technical Assistance


What’s the implication?

Previously, WMD-related controls applied only to exports. Now, those same controls apply to brokering, transit, and technical assistance as well.

Moreover, the military end-use and illicit export concerns previously limited to Article 4(2) and (3) are now part of this expanded scope. This is a huge shift.


⚠️ The Consequences?

This means:

  • More brokers will need to apply for licences.

  • More transit shipments might be held up or blocked.

  • Screening requirements are heavier, not only for exporters but for all parties involved in the transaction chain.

The scope of compliance has widened, and organisations must be vigilant, not just with listed items but increasingly with unlisted items and complex end-use scenarios.

In short:

More complexity. More responsibility. More risk.

The devil is, as always, in the details — and understanding them is essential for remaining compliant in this evolving landscape.


Tom Blass: Is there anything I can do to prepare for catch-all? Does this mean I need to increase my due diligence?


The first step in addressing the impact of the new regulation is to carefully review your supply chain. Here are a few key questions to consider:


  • Where do you use brokers or broker services?

  • Are there transit movements in your supply chain that could fall under catch-all controls?

  • Do you handle non-listed cyber-surveillance items that may now be subject to these regulations?


Having clarity on these aspects is essential because it allows businesses to exclude certain catch-all controls right away, which helps streamline compliance efforts.


If you work with a broker and deal with embargoed countries, your due diligence efforts will need to extend beyond just your direct transactions. End-use controls now apply to brokers and third-party intermediaries as well.


Let’s consider an example:Imagine you receive a notification from the authorities that your item, let’s call it “good X”, now requires a licence because of its military end-use. Last week, this item was exported without issue, but today, it has left the EU and is en route to Egypt, with plans to be transferred to Afghanistan next week. The transaction is facilitated by a broker in the EU. Under Regulation 428/2009, this broker could have executed the transaction without a licence. However, under Regulation 821/2021, the broker may now be required to obtain a licence before proceeding with the transaction.


What to Do Next?

If you're concerned about a specific item, you must thoroughly assess how the new regulation impacts its exportability. This may involve consulting with the authorities to clarify whether your product falls within scope and to confirm the necessary licensing requirements.


Next Steps for Businesses:

  1. Raise Awareness: Ensure that your team understands the new controls and their implications.

  2. Provide Training: Offer regular training to ensure everyone is up to date with the latest regulatory changes.

  3. Enhance Due Diligence: Extend your due diligence efforts to include screening for human rights abuses, terrorism concerns, and other red flags.

  4. Use Red Flags: Identify potential risks by applying indicators of suspicious activities — this can be a helpful tool for proactive compliance management.

By taking these steps, you can minimise the risk of inadvertently violating the new controls and ensure a smoother compliance process for your business.


Tom Blass: Is some MS more likely to apply catch-all than others?


Arne Mielken: Indeed, this was and is big concern. The current system leaves too much room for Member States to weigh national political interests over common interests when considering applying the Catch-all Clause. The EU hopes that the new mechanism will provide much-harmonised decision making. A good example of how national interests can influence


the application of catch-all controls was seen in their use by the Dutch authorities in relation to the Russia sanctions regime after the MH-17 crash. Because of the involvement of the Netherlands in this crash, the Dutch authorities applied for stricter controls over exports of non-listed items to Russia and for Russian end-use.

It can create an advantage for exporters operating in the Member States with more favourable policies and may encourage exporters with illicit intent to choose to have their products exported from the Member States with less risk of discovery and lower penalties for violations.


A solution that was suggested was a better way of information sharing between the Member States is recommended. This should result in the Member States increasing the amount of information being shared, as well as providing detailed information about their decisions to deny, issue or not require an export authorisation, all of which would benefit a common approach.


Under Article 9 of the new regulation, Member States must now notify the Commission and the other Member States of any measures adopted without delay and indicate the precise reasons for the measures.


The Commission will then publish the measures notified in the Official Journal of the European Union. A multilingual compilation of national control lists in force in the Member States will then be published, too.


And then Article 10 says that an authorisation is required for the export of dual-use items not listed in Annex I if another Member State imposes an authorisation requirement for the export of those items on the basis of a national control list where the procedure of Article 9 is followed. The Member State should also inform the other concerning the items and end-users concerned. The other Member States shall give “due consideration” and then inform customs authorities and others.


So, the hope is that unilateral decisions are then a thing from the past. Time will tell.


Tom Blass: I do business with ‘safe’ jurisdictions – e.g., the US, Canada, NZ, Switzerland, India etc. – does that mean that I don’t have to worry too much?


Arne Mielken: I would say that the chances of your exports being prohibited or not authorised are lower than when you export to a country of significant concern. Changes that most catch-all concerns are raised may be rare in these countries.

And don’t forget that even if a licence requirement is imposed, there are EU GEA’s that you can explore first.


Having said all of this, the catch-all provisions apply and are tied to end-uses, not necessarily to countries. And as you know, the world changes. What is a safe country today is no longer safe tomorrow. Terrorism is everywhere. Human rights abuses can and do occur even in the richest countries. And bad, rogue business partners also exist.

In Germany, we have a saying, „Unwissenheit schützt vor Strafe nicht“ (ignorance does not protect against punishment). So Due diligence is key, implement a red flag system and get an ICP! Strong take on procedures for any customer

Comments


Terms of Website Use

Cookie policy

Privacy policy

© 2025 by Customs Manager Ltd.

bottom of page