US Entity List & NSO Group
In November 2021, the US Commerce Department's Bureau of Industry and Security (BIS) added NSO Group and Candiru to the Entity List, restricting the companies' access to US technology. This was one of the most significant regulatory actions against commercial spyware vendors.
- 01NSO Group was added to the US Entity List on November 3, 2021
- 02The Entity List restricts access to US-origin technology without a license (which is presumed denied)
- 03Candiru was added in July 2021; Cytrox/Intellexa was added in 2022
- 04The designation cited NSO's tools being used to target government officials, journalists, and activists
- 05The Entity List significantly impacted NSO Group's operations and supply chain
What Is the Entity List?
The Entity List is a trade restriction list maintained by the US Department of Commerce's Bureau of Industry and Security (BIS). It identifies foreign persons, companies, and organizations that are subject to specific license requirements for the export, re-export, or transfer of items subject to the Export Administration Regulations (EAR).
When a company is added to the Entity List:
- A specific license is required for any export, re-export, or transfer of US-origin items to that company
- The license application is subject to a policy of "presumption of denial" — meaning licenses are presumed to be denied unless the applicant can demonstrate a compelling case
- The restriction applies to all items subject to the EAR, including software, hardware, and technology
- Even items that do not normally require an export license become restricted when the recipient is on the Entity List
NSO Group's Addition to the Entity List
On November 3, 2021, the BIS added NSO Group and three other Israeli companies to the Entity List:
- NSO Group Technologies — developer of Pegasus
- Candiru — developer of another mercenary spyware product
- Computer Security Initiative Consultancy LTD — a related entity
- Positive SD — a related entity
The BIS stated that the companies were added to the Entity List because:
"The entities were involved in the development and supply of spyware and related tools that were used to target government officials, journalists, businesspeople, activists, academics, and embassy workers, and that these tools were used to conduct malicious cyber activities against these actors."
Subsequent Additions
Other spyware vendors have been added to the Entity List since 2021:
- Candiru (July 2021): Added before NSO Group, also for developing spyware used against civil society
- Cytrox (2022): North Macedonian spyware vendor, part of the Intellexa consortium, developer of Predator
- Intellexa entities (2022–2023): Additional Intellexa consortium entities were added
Impact on NSO Group
The Entity List designation had significant practical impacts on NSO Group:
- Technology access: NSO lost access to US-origin technology, including software development tools, cloud services, and hardware components
- Supply chain disruption: NSO had to find alternative suppliers for technology that was previously sourced from US companies or contained US-origin components
- Financial impact: The designation contributed to NSO's financial difficulties, including the loss of Novalpina Capital's backing
- Reputational impact: The official US government designation reinforced the characterization of NSO as a company whose products harm civil society
- Operational constraints: NSO had to adapt its development and operations to work without US technology, potentially slowing innovation and increasing costs
Limitations of the Entity List
- Does not shut down the company: NSO Group continues to operate despite the Entity List designation
- Does not prevent sales to non-US clients: NSO can still sell Pegasus to government clients outside the US
- Does not criminalize the company's activities: It is a trade restriction, not a criminal sanction
- Does not apply to the spyware itself: The restriction is on US technology access, not on the use of Pegasus
- Can be circumvented: Companies may find alternative suppliers or route technology through third parties
- Does not address the demand side: Government clients who misuse Pegasus are not directly affected
Relationship to Other Actions
The Entity List designation was part of a broader set of actions against NSO Group:
- Lawsuits: WhatsApp v. NSO (2019) and Apple v. NSO (2021) were ongoing
- Pegasus Project: The July 2021 investigation increased public and political pressure
- Israel export controls: Israel's Defense Ministry tightened export oversight of NSO in 2022
- EU PEGA Committee: The EU Parliament established an inquiry committee in 2022
The Broader Message
The Entity List designation sent a clear signal to the commercial spyware industry: the US government considers the targeting of civil society with mercenary spyware to be a malicious cyber activity that warrants trade restrictions. This has had a deterrent effect on the industry, though new vendors continue to emerge, often from jurisdictions with less regulatory oversight.
