How Israel's Ministry of Defense Cut the Cyber Export List From 102 Countries to 37

The November 2021 policy shift that reshaped Israeli offensive-cyber overnight. Why the MOD sequenced its tightening to the BIS Entity List additions, what the 37-country list actually says, and how the Israeli cyber sector operates under both regimes.
In November 2021, days after the US Commerce Department added NSO Group and Candiru to the BIS Entity List, Israel's Ministry of Defense cut its approved-country list for cyber-offensive exports from 102 countries to 37. It was the sharpest single policy shift in Israeli export control in a decade. It was engineered as a response to Washington. And it reshaped the Israeli cyber sector from the inside out.
The 37-country list is not published in full by the MOD. Its outlines are known from press coverage, industry disclosure, and the pattern of licensing outcomes since. What is documented: democracies only, specified strategic partners retained, most Gulf states cut, most of Africa cut, most of Latin America cut, most of Southeast Asia cut. What is also documented: the Israeli offensive-cyber sector has never returned to its pre-November-2021 addressable market.
What Is Israel's Cyber Export Regime, and Who Runs It?
Cyber-offensive tools fall under Israel's dual-use export control architecture. The statutory basis is the Defense Export Control Law of 2007. The operational authority is the Defense Export Controls Agency (DECA), inside SIBAT, inside the Ministry of Defense.
Israel is not a member of the Wassenaar Arrangement — the 42-country multilateral export-control regime that in 2013 added intrusion software to its dual-use control list. But the Israeli MOD unilaterally applied the Wassenaar framework to Israeli cyber-offensive exports, aligning Israeli practice with the multilateral standard without acceding to it.
The result: Israeli cyber-offensive exports operate under a specifically Israeli licensing regime that mirrors Wassenaar substance but sets Israeli criteria. Since 2016, that regime has included a defined approved-country list, updated periodically by MOD policy without new legislation.
Why Did Israel's MOD Reduce the Approved-Country List From 102 to 37 in November 2021?
The trigger was Washington. On November 3, 2021, BIS added NSO Group, Candiru, Positive Technologies, and COSEINC to the Entity List for supplying spyware used to target journalists, activists, and government officials. The framing was human rights. The mechanism was export control.
The Israeli government protested through diplomatic channels. Washington did not reverse the listings. Within days, the MOD announced a substantive tightening of Israeli cyber-export licensing policy — reducing the approved-country list from 102 countries to 37.
Publicly, MOD leadership framed the reduction as a response to changing threat assessments and evolving human-rights considerations. Operationally, the sequencing to the BIS additions was unmistakable. Israel had two options: defend NSO and Candiru against Washington while continuing to license their sales, or acknowledge that the customer base needed narrowing. The MOD chose the second.
The cost to the Israeli cyber-offensive industry was immediate. Approved-country reduction from 102 to 37 is a reduction of roughly 64% in the licensed customer base. The revenue impact ran through every operating firm in the sector.
Which Countries Made the 37-Country List, and Which Got Cut?
The MOD does not publish the list in full. Reporting by Israeli press, industry disclosures, and licensing pattern analysis have documented the general contours:
Retained (approximate categories):
- NATO members
- Major EU democracies
- United States, Canada, United Kingdom, Australia, New Zealand, Japan, South Korea
- Select Latin American democracies (Chile, Uruguay, Costa Rica reported)
- Select Asia-Pacific democracies (Singapore, Taiwan reported)
- Specified Israeli strategic partners on case-by-case grounds
Cut (approximate categories):
- All Gulf states without bilateral exception (UAE and Bahrain later added via Abraham Accords framework)
- Most of Africa
- Most of Latin America outside the retained democracies
- Most of Southeast Asia outside the retained set
- India (reported as cut, then partially restored under bilateral discussions)
- Mexico (cut following Pegasus-related domestic controversies)
The list is periodically adjusted. Individual country additions or subtractions do not require new legislation — they operate under DECA licensing discretion within the statutory framework.
How Does the Cyber Export Regime Interact With the 2007 Defense Export Control Law?
The 2007 statute provides the framework. The cyber-export regime is an application of that framework to a specific technology category. Both track together in three principal ways:
- License types. Marketing licenses (pre-contract discussions), export licenses (specific transactions), and government-to-government program licenses apply to cyber-offensive exports as to conventional defense articles.
- Review criteria. End-use, end-user, regional security implications, US compatibility, and Israeli national-security considerations apply. Cyber-offensive exports face heightened scrutiny on end-use given the potential for targeting civilians.
- Penalties. Civil and criminal penalties under the 2007 law apply. Unauthorized cyber-offensive exports carry the same statutory exposure as unauthorized defense-article exports.
The 2007 law gave DECA the tools. The November 2021 policy shift was the sharpest single deployment of those tools since the statute's enactment.
What Happens to Israeli Cyber Firms Selling to Countries Off the Approved List?
An Israeli cyber-offensive firm cannot legally market, sell, or deliver its product to a customer in an unapproved country. Marketing licenses will not be granted; export licenses will not be granted; contracts cannot close. The 37-country list is the operational ceiling.
Firms that were mid-contract when the November 2021 tightening took effect faced structural questions. Pre-existing contracts to now-unapproved countries could not be renewed or expanded. Delivery obligations under existing licenses could be honored under grandfathering provisions, but new product releases could not ship. The Israeli offensive-cyber sector's forward-revenue pipeline compressed sharply.
Compliance workarounds — restructuring to a non-Israeli entity, moving operations offshore, spinning off product lines to acquirers in different jurisdictions — have been attempted. None of them fully escapes DECA reach where the underlying technology, IP, or personnel are Israeli. And the reputational and financial-sector consequences of appearing to circumvent MOD licensing are severe.
How Did the Tightening Affect NSO Group and Candiru Beyond BIS?
NSO and Candiru faced simultaneous US Entity List treatment and the Israeli MOD tightening. The compounding effect: no US-origin supply access (Entity List), narrower licensed customer base (37-country list), reputational overhang (both), banking constraints (both), talent-retention challenges (both).
NSO's pre-listing enterprise value in the $1 billion range compressed in the years that followed. Restructuring, layoffs, and distressed-position financing tracked through 2022–2025. Candiru's smaller scale meant less coverage; the same operational pattern applied.
Neither firm shut. Both operate under materially compressed conditions. The precedent for the sector — that BIS action can trigger DECA follow-on within the same month — is the durable consequence.
What Are the Broader Israeli Cyber Sector Consequences?
The 2021 tightening reshaped the sector's operating model:
- Product-line separation. Firms operating both defensive and offensive cyber lines increasingly separate them — defensive lines faced no restriction, offensive lines faced the 37-country ceiling and higher scrutiny across the board.
- Corporate restructuring. Multiple firms reincorporated abroad, spun off Israeli operations, or moved product ownership to non-Israeli entities. None of these moves fully escapes DECA reach on Israeli-developed IP.
- Fundraising shift. US venture capital participation in Israeli offensive-cyber has essentially disappeared. Where present, financing runs through European, Asian, and Gulf sources — with the corresponding governance implications.
- Talent flow. Israeli offensive-cyber engineering talent has increasingly moved into adjacent categories — enterprise cybersecurity, cloud security, AI security — where the regulatory ceiling is lower and the customer base is broader.
The sector still exists. It is materially smaller than the pre-2021 trajectory implied.
How Should Israeli Cyber Firms Plan Around the 37-Country Ceiling?
Four operational questions:
- Is my product on the offensive-cyber side of the line? The 37-country ceiling applies to offensive tools. Defensive cybersecurity products do not face the same restriction.
- What share of my addressable market is inside the 37-country list? Enterprise-planning purposes require concrete answers, not implicit assumptions.
- Are we exposed to a future BIS action that could compound the Israeli restrictions? Scenario planning for Entity List addition is now standard board-level review.
- What is our product architecture strategy if the ceiling narrows further? The 37-country number is not a floor. It has been adjusted downward for specific countries. It could compress further under future policy shifts.
The Israeli cyber-offensive sector operates today under a dual regulatory ceiling — American and Israeli — that did not exist before November 2021. The regulatory regime has become the sector's defining operational constraint.
Related in Olam:
- The BIS Entity List: NSO Group, Candiru, and What Listing Actually Does to an Israeli Company
- Israel's 2007 Defense Export Control Law: The SIBAT–DECA Licensing Architecture
- The US Export Administration Regulations: An Israeli Operator's Manual
- ITAR: The US Munitions Ceiling on Israeli Defense Exports
- The Foreign Direct Product Rule: How US Export Control Reaches Israeli Products Made Without US Parts
- DECA: How Israel Licensed $14.8B in Defense Exports in 2024

