Let us imagine Tim. Tim is a computer science specialist who, while still at university, worked on secure communications, network security and encryption. After graduating, he teamed up with several more business-oriented co-founders and together they turned the technology into a startup. Their idea was to offer the solution as a SaaS product to companies that needed the secure transfer of sensitive information. Because the technology was resistant to cyberattacks and suitable for use in critical infrastructure, it quickly became clear that its potential extended beyond the conventional commercial market.
The company was acquiring customers but had not yet secured a truly significant contract. Then a potential foreign customer appeared with an opportunity substantially larger than anything the startup had handled before. Before signing the agreement, the customer wanted to assess the product’s technical capabilities and requested more detailed documentation. Tim prepared it, uploaded it to the cloud and gave the potential partner access. From a sales perspective, there was nothing unusual about this: the customer wanted to evaluate the technology, and the startup wanted to close the deal.
But with dual-use technologies, this is precisely the point at which a founder may face an unexpected question: did Tim simply share technical documentation, or did he potentially also transfer technology subject to export control rules?
This is not merely a theoretical issue. The European Regulation (EU) 2021/821 includes software and technology within the dual-use framework and establishes controls on exports, brokering, technical assistance, transit and transfers of dual-use items. Regulatory risk is therefore not necessarily limited to physically shipping a product across a border. Depending on the technology, source code, technical documentation, models, test data, software, know-how, technical assistance or electronic access to certain information may also be relevant.
Dual-use is no longer just a buzzword
For a deep-tech startup, moving from a civilian market into the defence or security sector can be a natural progression. Technology originally developed for logistics, energy, telecommunications, cybersecurity, space or industry may quickly become relevant to defence users, critical infrastructure or government institutions. This is why describing a company as a “civilian startup” says relatively little about the regulatory status of its technology.
What matters more is what the technology actually does, where it is transferred, who will use it and for what purpose. The assumption that “we are not a defence company, so this does not apply to us” can therefore be misleading. A better question is: does our product, software or technology have characteristics or potential applications that could make it subject to export controls, sanctions or other specific regulatory regimes?
Tim’s example also illustrates another point. Regulatory compliance in the dual-use sector is not merely an issue for the sales team immediately before an export. In practice, it can affect product development, recruitment, fundraising, cloud architecture, customer screening, technical cooperation and go-to-market strategy. A startup may open a virtual data room for a potential investor, send source code to an external technical partner or give a customer access to a test environment. None of these situations necessarily looks like a traditional export at first glance, but with sensitive technologies it is important to understand what is being shared, with whom and under what conditions.
The biggest regulatory risk is often a blind spot
A founder usually understands very well what their product does. What companies less often have is a documented answer to the question of how the same technology may be viewed by a regulator, major customer, investor or defence partner.
This is where regulatory risk mapping becomes useful. The point is not for an early-stage startup to immediately build the kind of regulatory compliance department found in a large defence corporation. The objective is more practical: to understand where regulatory risks arise within the business model and which decisions should trigger additional review.
For a company developing dual-use technology, the first step is to understand the technology itself. What does the product actually do? Which of its technical characteristics may be relevant from a regulatory perspective? What does the company share with customers and partners beyond the finished product? Then come target markets, destinations and end users. The structure of the transaction also matters, as a distributor, integrator, reseller or other intermediary can change the regulatory picture. For technology startups, access to information deserves particular attention: who can view the source code, who can access the development environment, who receives technical plans and from which countries can that information be accessed?
If Tim had already established this basic map before his first major international deal, several additional questions would probably have arisen before the documentation was uploaded. What exactly are we sending? Is any part of the product or related technology controlled? Who will receive the information and where is the recipient located? Who will actually use the technology? Before sharing it, do we need a licence, contractual restriction, internal approval or technical access limitation?
How does the law apply in practice?
There is no reliable answer to dual-use regulatory compliance questions without specific facts and proper classification. The first step is generally to determine whether the product, software or technology falls within an export control regime. The central European framework is Regulation (EU) 2021/821, while Annex I contains the common EU list of controlled dual-use items.
The control list is not static. In September 2026, the European Commission adopted a new update to the EU dual-use control list, which includes, among other things, new categories of advanced semiconductor, computing and manufacturing technologies.
The analysis does not end with the question of whether something appears on a control list. End use, end user, destination, sanctions restrictions and the way in which technology is transferred may also be relevant. In Slovenia, applications for individual and global export authorisations are submitted electronically through the eLicensing system, while official information is available through the SPOT portal for dual-use items.
Effective regulatory compliance is therefore not based on a single check. It is based on the relationship between technology classification, destination, recipient, end use and documentation showing how the company reached its assessment.
If a company does not yet have a clear answer as to how its product or technology is treated from a regulatory perspective, a logical first step is a regulatory qualification of the technology. We help determine how the product or technology should be treated from an export control perspective, identify relevant counterparties, destinations and end uses, assess potential sanctions exposure and determine whether specific licences or other regulatory steps may be required.
LEGAL EXPERT INSIGHT – Rok Bizjak, Lemur Legal
“For an early-stage dual-use company, it makes little sense to immediately build an extensive compliance system. The priority is to classify the technology correctly, understand which regulatory rules apply to it and document the key assessments. Only then can the company establish processes that are proportionate to the actual risks and practical enough to support its growth.”
Regulatory compliance as part of market access
In a startup environment, regulatory compliance is often treated as a cost or as something to address later, once required by a regulator or major customer. For dual-use companies, that sequence may be too late.
When a startup begins discussions with a defence integrator, public-sector customer, specialised investor or strategic partner, the other side is no longer assessing only whether the technology works. Supply chains, end users, export exposure, sanctions risks, access to sensitive information and internal decision-making processes also become relevant. The European Commission’s guidance on sanctions due diligence likewise emphasises risk-based screening of business partners, transactions and goods, as well as the identification of warning signs of potential sanctions circumvention.
Strong regulatory compliance does not guarantee a contract. It can, however, reduce uncertainty for a customer or partner and prevent the company from addressing key regulatory questions only after commercial terms have already been agreed, technical documentation has already been shared and deadlines are already running. The objective is not to create a process that slows the startup down. On the contrary, the company should know early enough what it can share, with whom, under what conditions and when additional approval is required.
NATO is not just another customer
The phrase “entering the NATO market” is useful, but simplified. NATO is not a single buyer with one tender and one procurement process. The broader defence ecosystem includes NATO bodies and agencies, national defence buyers in member states, major defence integrators, their supply chains, innovation programmes, testing environments and other routes to cooperation.
In July 2026, NATO launched the NATO Front Door for Industry, a platform designed to make it easier for companies to access information about procurement opportunities, innovation events and other ways of engaging with NATO.
The NATO DIANA Accelerator Programme is also particularly relevant to deep-tech and dual-use companies. The programme connects selected innovators with defence users, mentors, industry partners and investors, while providing access to a network of more than 200 test centres across the Alliance.
However, procurement readiness, technology readiness and regulatory readiness are not the same thing. A startup may have an excellent product and compelling technology but still be unprepared for the regulatory questions raised by a serious defence transaction. The reverse is also true: well-organised regulatory compliance does not guarantee a NATO contract, acceptance into DIANA or any other commercial outcome.
Once a company reaches the stage at which investors, acquirers, strategic partners or major defence customers begin conducting more detailed reviews, regulatory readiness becomes part of broader investment readiness. Through an investment readiness review, we help assess exposure to dual-use and export control rules, the maturity of internal compliance processes, foreign direct investment screening issues, procurement readiness and other regulatory and documentation risks before fundraising, M&A or a major strategic transaction.
This brings us back to Tim. His problem was not that he wanted to close a major deal quickly. That is the objective of every startup. The problem arises when the company has no process capable of raising a few additional questions before an important step without bringing the business to a halt.
Is your company regulatorily ready? Check in 5 minutes
This check is not legal advice and is not a substitute for formal classification. It is a quick way for a founder or management team to assess whether the company has a basic regulatory orientation.
Take five minutes and tick every statement you can answer YES to.
TECHNOLOGY
☐ We know whether our product has potential military, security or other strategic applications.
☐ We have assessed whether our product, software or technology may be subject to export controls.
DATA AND ACCESS
☐ We know which source code, technical documentation, models or other sensitive data may be shared with external parties.
☐ We know who has access to this information and from which countries.
MARKET AND END USER
☐ We have clearly identified the countries to which we intend to sell or transfer our technology.
☐ We know the end user and the intended end use.
PARTNERS AND PROCESSES
☐ We screen customers, distributors, integrators and other key business partners.
☐ It is clearly defined within the company who is responsible for triggering additional regulatory compliance review or legal assessment.
How should you read the result?
0–2 × YES: REGULATORY BLIND SPOT
Before the next major business step, it is advisable to carry out basic regulatory risk mapping.
3–5 × YES: THE FOUNDATIONS ARE IN PLACE
The company already manages some of the relevant risks, but questions may remain around classification, access to technology, partners or documentation.
6–8 × YES: GOOD BASIC READINESS
The next step is to verify whether the framework already in place actually fits the specific technology, market, customer and transaction.
The result is not a legal assessment and does not determine whether the company requires a licence. It does, however, indicate whether the company has basic processes in place to identify the questions that are likely to arise when seriously entering the defence or NATO market.
What should you do if the check reveals gaps?
The first step does not necessarily need to be hiring a regulatory compliance team or drafting dozens of internal policies. For an early-stage dual-use startup, it is generally more useful to establish a process proportionate to the actual risk. A company can begin by mapping its technology and sensitive data, setting clear access rules, introducing basic customer and partner screening, and defining the points at which an ordinary business process must trigger an additional review.
Once the company understands where its main regulatory pressure points are, individual decisions can be turned into a repeatable system. When establishing compliance frameworks, we help put in place clear responsibilities, internal approval procedures, export control processes, sanctions screening, escalation paths and documentation that the team can actually use in day-to-day operations.
Such a process should not exist to prevent the company from doing business. A well-designed system should achieve the opposite: people within the company know which decisions they can make independently, when internal approval is sufficient and when an additional regulatory or legal assessment is required.
Regulatory readiness is part of business readiness
Tim’s story is useful precisely because there is nothing particularly unusual about it. A customer wants to understand the product, the startup wants to demonstrate its quality, and the technical team prepares and shares documentation. It is an entirely ordinary business process. With dual-use technology, however, regulatory exposure can arise precisely in these everyday situations.
A dual-use startup therefore does not need the regulatory compliance system of a major defence corporation. It does, however, need sufficiently clear answers to several basic questions: what are we developing, what are we sharing, who can access it, where is the technology going, who will use it and who within the company recognises when additional review is required? The objective is not to build an extensive regulatory compliance infrastructure from day one, but to clearly understand where sensitive technology sits, who has access to it and what information may be shared externally.
For a dual-use startup, regulatory compliance is therefore not only a question of “are we allowed to do this?” Increasingly, it is also a question of “are we sufficiently prepared for an investor, strategic partner or defence customer to trust us?”
Strong regulatory compliance does not guarantee access to the defence market. It can, however, prevent regulatory unpreparedness from becoming the reason a company fails to reach it.