Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

US Entity List & NSO Group

In November 2021, the US Commerce Department's Bureau of Industry and Security (BIS) added NSO Group and Candiru to the Entity List, restricting the companies' access to US technology. This was one of the most significant regulatory actions against commercial spyware vendors.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01NSO Group was added to the US Entity List on November 3, 2021
  • 02The Entity List restricts access to US-origin technology without a license (which is presumed denied)
  • 03Candiru was added in July 2021; Cytrox/Intellexa was added in 2022
  • 04The designation cited NSO's tools being used to target government officials, journalists, and activists
  • 05The Entity List significantly impacted NSO Group's operations and supply chain

What Is the Entity List?

The Entity List is a trade restriction list maintained by the US Department of Commerce's Bureau of Industry and Security (BIS). It identifies foreign persons, companies, and organizations that are subject to specific license requirements for the export, re-export, or transfer of items subject to the Export Administration Regulations (EAR).

When a company is added to the Entity List:

  • A specific license is required for any export, re-export, or transfer of US-origin items to that company
  • The license application is subject to a policy of "presumption of denial" — meaning licenses are presumed to be denied unless the applicant can demonstrate a compelling case
  • The restriction applies to all items subject to the EAR, including software, hardware, and technology
  • Even items that do not normally require an export license become restricted when the recipient is on the Entity List

NSO Group's Addition to the Entity List

On November 3, 2021, the BIS added NSO Group and three other Israeli companies to the Entity List:

  • NSO Group Technologies — developer of Pegasus
  • Candiru — developer of another mercenary spyware product
  • Computer Security Initiative Consultancy LTD — a related entity
  • Positive SD — a related entity
Official Justification

The BIS stated that the companies were added to the Entity List because:

"The entities were involved in the development and supply of spyware and related tools that were used to target government officials, journalists, businesspeople, activists, academics, and embassy workers, and that these tools were used to conduct malicious cyber activities against these actors."

Subsequent Additions

Other spyware vendors have been added to the Entity List since 2021:

  • Candiru (July 2021): Added before NSO Group, also for developing spyware used against civil society
  • Cytrox (2022): North Macedonian spyware vendor, part of the Intellexa consortium, developer of Predator
  • Intellexa entities (2022–2023): Additional Intellexa consortium entities were added

Impact on NSO Group

The Entity List designation had significant practical impacts on NSO Group:

  • Technology access: NSO lost access to US-origin technology, including software development tools, cloud services, and hardware components
  • Supply chain disruption: NSO had to find alternative suppliers for technology that was previously sourced from US companies or contained US-origin components
  • Financial impact: The designation contributed to NSO's financial difficulties, including the loss of Novalpina Capital's backing
  • Reputational impact: The official US government designation reinforced the characterization of NSO as a company whose products harm civil society
  • Operational constraints: NSO had to adapt its development and operations to work without US technology, potentially slowing innovation and increasing costs

Limitations of the Entity List

What the Entity List Does NOT Do
  • Does not shut down the company: NSO Group continues to operate despite the Entity List designation
  • Does not prevent sales to non-US clients: NSO can still sell Pegasus to government clients outside the US
  • Does not criminalize the company's activities: It is a trade restriction, not a criminal sanction
  • Does not apply to the spyware itself: The restriction is on US technology access, not on the use of Pegasus
  • Can be circumvented: Companies may find alternative suppliers or route technology through third parties
  • Does not address the demand side: Government clients who misuse Pegasus are not directly affected

Relationship to Other Actions

The Entity List designation was part of a broader set of actions against NSO Group:

  • Lawsuits: WhatsApp v. NSO (2019) and Apple v. NSO (2021) were ongoing
  • Pegasus Project: The July 2021 investigation increased public and political pressure
  • Israel export controls: Israel's Defense Ministry tightened export oversight of NSO in 2022
  • EU PEGA Committee: The EU Parliament established an inquiry committee in 2022

The Broader Message

The Entity List designation sent a clear signal to the commercial spyware industry: the US government considers the targeting of civil society with mercenary spyware to be a malicious cyber activity that warrants trade restrictions. This has had a deterrent effect on the industry, though new vendors continue to emerge, often from jurisdictions with less regulatory oversight.

A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more