TRAFEED

EU Export Rules 2026: Dual-Use, CRA, CBAM, and CE — What to Prioritize

Published2026-02-26Updated2026-07-21Ryuta Hamamoto

A July 2026 snapshot of the rules Japanese companies face when exporting to or placing products on the EU market.

EU Export Rules 2026: Dual-Use, CRA, CBAM, and CE — What to Prioritize
Share

This is Hamamoto from TIMEWELL. When Japanese companies try to sell into Europe, I still hear the same line: there are too many EU rules, and nobody knows where to start.

Export controls, product cybersecurity, personal data, CE marking, carbon border measures. Listing the names is exhausting. 2026 is the year several of them move at once. From 11 September, Cyber Resilience Act (CRA) reporting starts, and manufacturers that have not built a detection and support process are already short on time1.

This piece organises the main rules Japanese exporters face when shipping to or placing products on the EU market, as of 21 July 2026, using primary sources. First a priority table, then the detail by domain.

One table first: which EU rules matter most

Priority Domain Core rule 2026 operational anchor Why Japanese firms feel it
1 Product cyber CRA 11 September 2026: vulnerability and severe-incident reporting Smart devices, industrial IoT, software, embedded parts — early warning within 24 hours
2 Export control Dual-Use Regulation 2021/821 Continued use of the 2025 Annex I update Classification plus Articles 4 and 5 catch-alls
3 Carbon border CBAM 1 January 2026: definitive regime Steel, aluminium, and other covered imports; exporters supply emissions data
4 Product safety CE / Machinery Regulation New Machinery Regulation applies 20 January 2027 AI-enabled machinery and cyber risk enter CE conditions
5 Chemicals RoHS / REACH Ongoing exemption and SVHC updates Substance control and information duties at part level
6 Data and organisations GDPR / NIS2 GDPR procedure regulation in force from 2026; cross-border cases build from April 2027 Even out-of-scope firms feel customer requirements

Priority here is a mix of fine size and whether operations change inside 2026. Patchwork fixes cost more than designing compliance into the product lifecycle.

If you still lack a clean classification form for list and catch-all checks, start with the export classification template pack (2026). It is written for Japan’s FEFTA process, but the same discipline helps when you document EU Annex I decisions.

1. Export control — list controls and catch-alls

The EU controls dual-use goods, software, and technology that can serve civilian and military purposes. Japan has its own Foreign Exchange and Foreign Trade Act regime, but the EU framework is separate. Even when the first destination is the EU, re-exports and intra-EU transfers can create unexpected licence needs.

Dual-Use Regulation and the control list

The foundation is Regulation (EU) 2021/821. Controlled items sit in Annex I. Exports of listed goods, technology, and software generally require a licence2.

The 2025 control-list update refined and expanded coverage in areas such as quantum technology, semiconductor manufacturing equipment, advanced integrated circuits, advanced materials, and certain biosecurity-related equipment. The change tracks Wassenaar understandings and moves in the US and UK. Re-run classification if your catalogue sits near those edges.

Area Examples of tightened focus
Quantum Quantum computers, cryogenic electronics, parametric amplifiers, cryogenic cooling
Semiconductor manufacturing Atomic layer deposition, advanced lithography, EUV-related items, SEM, etch tools
Advanced electronics Specific high-end computing devices
Advanced materials High-temperature coatings; high-entropy alloy and refractory metal powders for metal 3D printing
Bio-related High-purity peptide synthesis equipment and similar items

Catch-all impact in practice

Not on the list does not mean free to ship. Unlisted items can still need a licence or a notification when end use or end user raises concern.

Two provisions matter most in day-to-day work:

  1. Article 4 military end-use catch-all — applies where there is a military end-use risk, including certain destinations subject to arms embargoes.
  2. Article 5 cyber-surveillance catch-all — can require notification when the exporter becomes aware that unlisted cyber-surveillance items may be used in connection with serious human rights abuses. Commission guidance has made due-diligence expectations more concrete since 2024.

If your product sits near face recognition or network inspection, do not treat Article 5 as someone else’s problem.

Japan-side classification and EU Annex I classification do not automatically match. Keep both paper trails. For the Japan side, see how METI classification works and list controls versus catch-all controls.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

2. Cybersecurity — CRA is the 2026 mountain

Cyber Resilience Act

The CRA, which entered into force in December 2024, requires cybersecurity measures across the lifecycle of products with digital elements sold in the EU. Scope is broad: smart appliances, industrial IoT, software, embedded components1.

Date What happens
Around 10 December 2024 CRA enters into force
11 June 2026 Chapter IV on notifying conformity assessment bodies applies
11 September 2026 Manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents apply
Through 2026 Harmonised standards continue to mature
11 December 2027 Main product obligations fully apply

From 11 September 2026, manufacturers must generally provide an early warning within 24 hours of awareness, a fuller notification within 72 hours, and follow-up reporting afterward, via the Single Reporting Platform operated with ENISA3. Legacy products already on the market can be in scope. Designing only for next-generation SKUs is not enough.

Fines can reach 2.5% of worldwide annual turnover or EUR 15 million, whichever is higher. This is a board-level risk.

NIS2 and supply-chain spillover

NIS2 tightens cybersecurity duties for essential and important entities across energy, transport, finance, health, digital infrastructure, and other sectors. Member State transposition has been uneven, and the Commission has pursued enforcement against late countries. Through 2026, national regimes keep coming online.

Direct duties fall on EU operators, but those operators must manage supply-chain security. Japanese suppliers increasingly see NIS2-level questionnaires and contract clauses from EU customers.

3. GDPR — enforcement plus procedure

Two practical points for 2026:

  1. Transparency as a coordinated enforcement theme — privacy notices that exist only on paper are not enough.
  2. The GDPR procedural regulation (in force from January 2026) streamlines cooperation among supervisory authorities. Broader application to new cross-border cases is expected from April 2027. Faster investigations mean shorter response windows.

If a product includes cloud services or apps, review CRA product security and GDPR data duties in the same design gate.

4. Product safety and environment — CE to carbon border

CE marking and the new Machinery Regulation

CE marking signals conformity with EU safety, health, and environmental requirements. Many products cannot be placed on the market without it.

A major shift is Machinery Regulation (EU) 2023/1230, which replaces the old Machinery Directive and applies from 20 January 2027. It brings AI-enabled machinery and cybersecurity risk assessment into the frame. Digital instructions may be allowed under conditions, while certain safety information can still require paper. From 2027 onward, CE and CRA will increasingly reinforce each other.

RoHS and REACH

RoHS (hazardous substances in electrical and electronic equipment) and REACH (chemicals) remain baseline European export controls.

Market surveillance still finds RoHS non-conformity. Complex supply chains make part-level substance control hard. Exemption changes, including lead-related rows, continue to move through 2026. REACH SVHC candidate lists also keep growing. Above 0.1% weight SVHC content, information duties to customers kick in. You need supplier data you can actually verify.

CBAM — the definitive regime has started

On 1 January 2026, CBAM left the transitional reporting-only phase and entered the definitive regime4.

In short, when covered goods are imported into the EU, authorised CBAM declarants must handle certificates linked to embedded emissions, priced with reference to the EU ETS. Current categories include steel, aluminium, cement, fertilisers, hydrogen, and electricity.

Item Content
Definitive regime start 1 January 2026
Main goods Steel, aluminium, cement, fertilisers, hydrogen, electricity, and related covered codes
Obligation holder EU authorised CBAM declarant (importer or indirect customs representative)
Japanese exporter role Provide embedded-emissions data and supplier information
De minimis Small annual volumes (for example under 50 tonnes) may be exempt
Scope expansion Downstream product expansion remains under discussion

Even if you do not import into the EU yourself, your goods may sit inside a CBAM product as material or parts. Confirm coverage early.

Timeline anchors for 2026–2027

When Rule What changes
2025 Dual-use control list Quantum, semiconductors, and related updates in force
1 January 2026 CBAM Definitive regime
January 2026 GDPR procedure regulation Entry into force; broader cross-border application later
11 June 2026 CRA Notifying authority / conformity assessment body framework
Mid-2026 RoHS and related Recheck exemptions and technical files
11 September 2026 CRA Vulnerability and incident reporting
20 January 2027 Machinery Regulation Mandatory application
11 December 2027 CRA Main product obligations

These rules interconnect. CRA security requirements overlap CE conditions under the new Machinery Regulation. CBAM emissions data links into sustainability reporting. Bundling requirements by SKU is cheaper than treating each statute as a separate project.

Five actions Japanese companies can take now

  1. Sort the portfolio — map each SKU to dual-use, CRA, chemicals, CBAM, and data.
  2. Stand up CRA reporting roles — detection, internal escalation, and external reporting with clear SLAs before 11 September.
  3. Document Japan and EU classifications separately — use the 2026 classification template pack for Japan-side records.
  4. Refresh supplier declarations — RoHS, REACH, emissions factors. Do not ship on stale SDS files.
  5. Prepare answers for EU customer security questionnaires — sales and engineering need a shared playbook under NIS2 and CRA pressure.

How TRAFEED reduces export-control load

Even for EU shipments, end-user screening and classification records break when they stay fully manual. TIMEWELL’s AI export-control agent TRAFEED (formerly ZEROCK ExCHECK) matches counterparties and items against sanctions lists, export-control lists, and risk information, and returns reasoned determinations. Multi-LLM cross-checks have shown classification accuracy of 95% or higher (joint validation with Okayama University and internal testing).

See the TRAFEED service catalogue (PDF) or contact us.

Key takeaways

  • For 2026 EU market access, CRA reporting on 11 September and the CBAM definitive regime are the hard operational anchors
  • Export control rests on Regulation (EU) 2021/821 Annex I plus Articles 4 and 5
  • CE tightens again on 20 January 2027 under the new Machinery Regulation
  • RoHS and REACH fail most often at part-level substance control
  • Rules interconnect — build one SKU requirements map and design compliance in early

Always verify against Commission pages and the Official Journal. This article is a snapshot as of 21 July 2026.

References

Footnotes

  1. European Commission, "Cyber Resilience Act" (accessed 21 July 2026). Main obligations apply from 11 December 2027; reporting obligations from 11 September 2026. https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act 2

  2. EUR-Lex, Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R0821

  3. European Commission, "Cyber Resilience Act - Reporting obligations". Early warning within 24 hours and notification within 72 hours for actively exploited vulnerabilities and severe incidents. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting

  4. European Commission, Taxation and Customs Union, "Carbon Border Adjustment Mechanism". Definitive period from 1 January 2026. https://taxation-customs.ec.europa.eu/carbon-border-adjustment-mechanism_en

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles