research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
EAR-specific compliance assessment for dual-use commercial items
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/ear-assessContext preview
What this command does when you run it.
EAR-specific compliance assessment for dual-use commercial items
description: EAR-specific compliance assessment for dual-use commercial items
> **Engineering guidance only. Not legal advice.** BIS determines EAR applicability, ECCNs, and license requirements, not this toolkit. Under [15 CFR 734.6](https://www.ecfr.gov/current/title-15/section-734.6), BIS is the authority; the country-specific sanctions rules live in [15 CFR 746](https://www.ecfr.gov/current/title-15/part-746) and change regularly (e.g. [Russia and Belarus under 746.8](https://www.ecfr.gov/current/title-15/section-746.8), Crimea/DNR/LNR under 746.6). Check the [BIS country guidance](https://www.bis.doc.gov/index.php/policy-guidance/country-guidance) for current sanctions text. Work with export-control counsel before relying on any posture below.
Deep dive assessment for Export Administration Regulations (EAR) compliance. Focuses on dual-use commercial items, encryption products, and technology under the Commerce Control List (CCL).
**Requirement**: Determine proper ECCN or EAR99 classification for all controlled items.
**Assessment Questions**:
**Common ECCNs**:
**Requirement**: Screen all customers and partners against BIS denied parties lists.
**Screening Lists**:
**Screening Frequency**:
**Assessment Questions**:
**Requirement**: Encryption items (Category 5 Part 2) must use FIPS 140-2/140-3 validated modules.
**Assessment Questions**:
**Self-Classification**:
**Requirement**: Block access from comprehensively embargoed countries.
**Embargoed Countries** (no exports without license):
**Partially Sanctioned** (check specific restrictions):
**Assessment Questions**:
**Requirement**: Control export of technical data and source code.
**Technical Data** (EAR 734.2):
**Assessment Questions**:
**Requirement**: Verify CSP provides EAR-compliant features.
**CSP Requirements**:
**Assessment Questions**:
**Requirement**: Determine if License Exception applies to avoid needing export license.
**Common License Exceptions**:
**ENC (Encryption)**:
**TSU (Technology and Software - Unrestricted)**:
**BAG (Baggage)**:
**TMP (Temporary)**:
**Assessment Questions**:
**Encryption Registration** (one-time):
**Annual Self-Classification** (if using ENC):
Is the item on the USML (US Munitions List)? ├─ YES → Use ITAR (not EAR) └─ NO → Continue to EAR Is the item on the CCL (Commerce Control List)? ├─ YES → Determine ECCN (e.g., 5D002 for encryption) │ ├─ High-level ECCN → May require BIS license │ └─ Check License Exceptions (ENC, TS
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.