Export control used to be a shipping question. For quantum programs it is now a staffing question, and the shift is recent enough that most project plans have not caught up. On September 6, 2024, the U.S. Bureau of Industry and Security published an interim final rule that brought quantum computers, their cryogenic and control subsystems, and the software and technology used to develop them under U.S. export control. The rule added new entries to the Commerce Control List, each carrying an Export Control Classification Number, or ECCN, and it created a license exception for countries that had adopted equivalent controls. It also changed who may stand at the whiteboard.
That last consequence is the one that lands on the project manager. Three decisions that used to belong to legal and logistics now sit inside the staffing plan: how the team’s work is classified, who may access it, and how long any required authorization takes. Take them in the wrong order and you recruit someone you cannot onboard.
Controls reach the team, not just the shipment
Under the Export Administration Regulations, known as the EAR, releasing controlled technology or source code to a foreign national inside the United States counts as an export to that person’s country of nationality. This is the deemed export rule, and it long predates the quantum controls. No package crosses a border. The release happens when a foreign national reads the specification, joins the design review, watches the screen share, or walks the lab and sees the assembly.
Defense-related work sits under a separate regime, the International Traffic in Arms Regulations, or ITAR, where foreign person access to controlled technical data requires authorization and the standard is stricter. Most commercial quantum work will fall under the EAR rather than ITAR, but a project with a defense customer can carry both, sometimes in different work packages of the same program.
The practical effect is that nationality has become an access attribute in the same way a security clearance is. The restriction is a property of the work rather than a judgment about the person, and the work is what has to be sorted first.
Classify the work before you staff it
The common failure is to build the team, then ask compliance whether the team is allowed. Reverse it. Break the program into work packages and put each one through three questions.
Is the output controlled technology? Technology under the EAR means the specific information needed for development, production, or use of a controlled item. A theoretical result about pulse shaping is usually not. Firmware that implements a gate set on a controlled control stack usually is. Your export control officer makes this call, but the project manager supplies the work breakdown that makes the call possible.
Who has to see it to do the job? Not who is on the team. Who genuinely needs the file, the schematic, the repository, or the room. Access lists drawn from org charts are the reason licenses get requested for people who never needed one.
What authorization would a given person need, and how long does it take? This is a duration, and durations belong in the schedule.
A worked example makes the partition concrete. Consider a control-electronics workstream for a superconducting processor. The pulse-shaping theory is publishable and collaborative. The firmware that implements a specific gate calibration on a controlled device is likely controlled technology. Integration testing on the machine itself involves both the controlled item and the technology for its use. One workstream, three different access regimes. The firmware work needs a license conversation, and so does any integration testing that would release controlled technology to a foreign national.
The fundamental research exclusion, and where it stops
Universities and university-affiliated teams often rely on the fundamental research exclusion. Basic and applied research in science and engineering, performed at an accredited institution of higher education in the United States, where the resulting information is ordinarily published and shared broadly, is not subject to the EAR as technology. That exclusion is real and it does a great deal of work in academic quantum research.
It also stops in three places, and each of them shows up in industry projects.
It covers information, not items. The exclusion does not authorize a foreign national to use a controlled instrument, and it does not travel with the hardware.
It dies the moment publication is restricted. A sponsor’s right to review and remove proprietary content is generally tolerated. A contract clause giving the sponsor approval over whether results are published at all takes the project out of fundamental research.
It does not apply to proprietary industrial development. A corporate lab does not get the exclusion by hiring academics or by co-authoring papers.
Mixed university and industry consortia are where teams get this wrong. The same physicist may be inside the exclusion on Monday under a grant and outside it on Tuesday under a sponsored development agreement. Two projects, two access positions, one person. Somebody has to track that, and in practice it’s the project manager.
Partition the program: open science, protected engineering
The structural answer to all of this is to design the project so that the boundary between open and controlled work is a documented interface rather than a judgment call made in a corridor.
Where the boundary goes
Put fundamental results, general algorithms, materials characterization, benchmarking methodology, and tooling that has no device-specific content on the open side. Publish from there, collaborate internationally from there, and recruit globally into it. That side is where a quantum program stays connected to the field, and cutting it off to be safe is a real cost, not a free precaution.
Put device-specific engineering, calibration data tied to controlled hardware, integration with customer systems, and anything with a defense end use on the protected side. Access is by named individual, recorded, and reviewed when roles change.
How the two sides talk
The interface is a specification, not a conversation. The open team delivers a documented result, an algorithm, a model, a measured parameter set, and the protected team implements against it. That mirrors how a contractor delivers a component without seeing the full assembly drawing, and it is the reason the pattern scales.
Two operational details decide whether the partition survives contact with a real project. First, the IT boundary has to match the paper boundary. Shared drives, chat channels, ticketing systems, and CI pipelines all leak across partitions that exist only in a policy document. Second, there needs to be a route across. People acquire authorizations, projects mature, and a partition with no promotion path either freezes staff in place or gets ignored.
Smaller organizations often object that they cannot run two tracks. Most cannot, at full formality. The principle still applies at a smaller scale: one repository open, one closed, and a written rule about which artifacts go where.
Authorizations are schedule items, not risks
A license request is a task with a duration and a dependency. Treat it as a risk on a register and it will be reviewed monthly while the start date slips.
Ask your export control officer for the current processing time for the license type you need, and put that number in the plan. Add the internal time before the filing, which is frequently longer than the government’s, because it includes the technology classification, the access justification, and the attestation the employer signs about the applicant’s access. Then build the sequence backward from the date the person is supposed to be productive.
Recruitment timing compounds it. The people you want are mobile and are being courted. Canada opened an open work permit stream for U.S.-based H-1B holders in July 2023, and the cap was reached before the stream’s scheduled end date. A candidate who waits five months for an onboarding decision is a candidate someone else hires. If a role sits on the protected side, the honest options are to start the authorization before the offer where policy allows it, to scope the first three months onto the open side, or to fill the role from staff who already hold the access.
If federal research money is involved
Research security compliance is a separate obligation that arrives with federal funding, and it lands on program governance rather than on export control.
National Security Presidential Memorandum 33, issued in January 2021, set the disclosure and research security framework that agencies have been implementing since. Personnel on federally funded projects disclose foreign appointments, foreign funding, and participation in foreign talent recruitment programs. The CHIPS and Science Act went further and prohibits federally funded researchers from participating in what the statute calls malign foreign talent recruitment programs. Institutions above a federal research funding threshold are now expected to maintain a formal research security program covering training, cybersecurity, foreign travel reporting, and export control compliance.
The enforcement history is worth knowing, because it shapes how conservatively institutions behave. Harvard chemist Charles Lieber was convicted in December 2021 for concealing payments and an appointment connected to China’s Thousand Talents Plan. The Justice Department’s China Initiative, under which that case was brought, ended in February 2022 after sustained criticism that it swept in ordinary academic conduct and that its effects fell disproportionately on researchers of Chinese descent. In 2020, Presidential Proclamation 10043 barred entry to certain Chinese graduate students and researchers with ties to military-linked institutions.
Two things follow for a project manager. Disclosure failures are the most common finding by a wide margin, and they are almost always administrative rather than deliberate: an unreported guest appointment, an unlisted co-authorship arrangement, a travel reimbursement nobody logged. Build the disclosure step into onboarding and into the annual project review, and it stops being an incident. And where a policy pushes toward treating nationality as a proxy for risk, the cost is measurable and falls on the program: a narrower hiring pool, weaker collaboration, and researchers who leave for jurisdictions where they feel less suspected. Controls should attach to work packages. That’s what the regulations actually say.
What to write down before anyone starts
Six documents carry the weight, and a program that has them survives an audit and an onboarding surge:
- A technology control plan. The TCP is the master document. It lists the controlled items and technology, the physical and IT access controls, the personnel screening approach, the training requirement, and the record-keeping.
- A classification memo per work package, dated and signed, naming the ECCN or recording the determination that the work is not controlled.
- An access matrix, by named individual, mapping people to work packages rather than to teams.
- A visitor and collaborator procedure covering conference attendance, lab tours, and visiting researchers.
- A travel policy for staff carrying laptops and data to countries of concern, including clean-device provisions.
- An exit procedure covering repository access, notebooks, and the debrief.
None of this is exotic. Aerospace and semiconductor programs have run on it for decades. It is new to quantum teams, most of which grew out of academic groups where the default was to publish everything.
The bench you can staff from is the one you build
Every control described here narrows the pool for a specific role. The two responses available to a program are to widen the pool through authorizations, which is slow and partly outside your control, or to raise the capability of the people already inside the boundary, which is neither.
That second route is routinely underused. An organization typically holds cleared or unrestricted staff who understand its systems, its customers, and its safety culture, and who lack only the quantum-specific knowledge. Cryogenic engineers, RF and control engineers, security architects, and program managers can all reach working competence in quantum computing and post-quantum cryptography through structured training in a fraction of the time an authorization takes. Their access is already settled.
Sovereign capability is often discussed as a matter of hardware and funding. At the project level it is simpler than that: it’s the number of people who can do the protected work without a license conversation. That number is something an organization can raise deliberately, on a known schedule, with a budget line.
Quantum Academy’s certification programs are built for that route: structured, assessed training that takes engineers, architects, and program staff from adjacent disciplines to working quantum competence, with the assessment evidence to show a customer or an auditor. Browse the current portfolio at quantumacademy.com/. For the geopolitical background to the controls described here, Marin Ivezic’s analysis of quantum human capital and geopolitics sets out how national talent policy arrived at this point, and QuantumCareers.com maps the roles a quantum program needs to fill.