On this page
One unnoticed legal risk costs more than it looks — a blocked export, a frozen payment, a leaked technology, or personal exposure for the director. In a defense business, legal security works not after an incident but before the contract, the technology transfer, the production run and the shipment. Below is a map of 13 risk categories, ordered by what can stop the business first.
| What it is | A map of 13 legal-risk categories for defense and dual-use manufacturers |
|---|---|
| Prioritization | STOP (5, critical) → SCALE (5, high) → SUPPORT (3, medium) |
| Three consequence zones | Stoppage · Liability · Loss of control |
| When it applies | Before the contract, the technology transfer, the production run and shipment |
| Who uses it | Founders (internal audit) and investors (due diligence) |
| Source | Juscutum’s defense-tech legal risk map |
Why legal risk stops a defense business
In an ordinary business, a legal mistake costs money. In a defense business, it stops the business itself. So legal security has to work as part of the production system — not as a reaction after an incident, but as a condition before the contract, the technology transfer, the production run and the shipment. The risk map splits the consequences into three zones.
Stoppage
An export, a payment, a permit or the production cycle is blocked.
Liability
Personal exposure for the director and the owners of critical functions.
Loss of control
A technology leak, disputes over IP or data, reputational damage.
- Dual-use goods
- Products with both civilian and military applications. They’re controlled under dedicated regimes (the EU’s Regulation 2021/821, the Wassenaar Arrangement, and for US-origin content the EAR), and a Ukrainian company’s international transfers run through the State Service of Export Control (SSECU). That’s why product identification comes before any contract.
Which risks to fix first: STOP → SCALE → SUPPORT
Not all risks are equal. You protect what can stop the business now first, and only then what slows scaling or dents reputation. The map splits the 13 categories into three tiers — and you start on the left.
| STOP · critical |
|---|
| Export control |
| Sanctions compliance |
| Criminal-law risk |
| Restricted access |
| Cybersecurity |
From Juscutum’s risk map · the STOP → SCALE → SUPPORT prioritization
The 5 risks that stop product, payment or team
These are the top five categories. Each has a specific trigger — the moment the risk fires and turns into a stoppage.
| 1. Export control | Uncontrolled transfer of goods, code, data or access |
|---|---|
| 2. Sanctions compliance | A counterparty or the chain routes the deal into a prohibited zone |
| 3. Criminal-law risk | An official’s decision lacks a proper procedure and evidence |
| 4. Restricted access | Specs, architecture, vulnerabilities or usage data are disclosed |
| 5. Cybersecurity | The network, cloud, channels or accounts are compromised |
Behind each trigger sits a concrete action before the deal. Export control requires product identification (military or dual-use), an SSECU permit and an end-use certificate; even transferring technical data or access to a foreign person (a deemed export) can fall under control. Sanctions compliancemeans screening beneficial owners (UBOs) and the whole chain of participants, not just the direct buyer. Criminal risk is removed not by seniority but by a documented procedure: a decision needs a basis and a record. Restricted access and cybersecurity close the same thing from two sides — who can see the specs and architecture, and who can reach the network, cloud and accounts.
All 13 categories, mapped
Here are all thirteen, by tier. Each category is a set of typical triggers; the key ones are listed.
🔴 Critical — STOP
- Regulatory & export-control. Product classification, international transfer of software and hardware, re-export without a permit, an unverified end-user.
- Sanctions & compliance. Contact with sanctioned persons, circumvention through intermediaries, blocked payments (AML), loss of international partnerships.
- Criminal-law. Unlawful transfer of dual-use items, corruption in certification, disclosure of restricted information, personal liability of the director or CTO.
- Restricted-information regime. Disclosure of technical specs, unprotected communication channels, no information classification, sensitive PR material.
- Cybersecurity & data protection. Unauthorized network access, attacks on cloud infrastructure, analytics leaks, no incident-response plan.
🟠 High — SCALE
- Intellectual property. Unassigned rights to code and algorithms, disputes with contractors, open-source without a licence audit, a partner copying the technology.
- International-scaling contracts. Unclear liability split, no end-use / no re-export, excessive performance guarantees, disputes over data ownership.
- Defense procurement & the state. Price and margin disputes, spec-compliance claims, post-contract audit risk, dependence on a single customer.
- People & management. Loss of critical engineers, missing NDAs and IP assignment, leaks via departed staff, founder disputes over product rights.
- Supply chain. Dependence on a narrow set of suppliers, components from sanctioned jurisdictions, shortages of critical parts, counterfeit risk.
🟡 Medium — SUPPORT
- Finance, tax, banking. Blocked payments (AML/sanctions), wrong customs classification, transfer-pricing risk, FX limits and international settlement.
- Technical regulation, certification, quality. No conformity assessment, non-compliance with jurisdiction standards, missing test protocols.
- Reputational & political. Accusations of entanglement in conflicts, information attacks, discredit through a technical incident, misuse by the end-user.
Run the risk-check on your company
A practical way to check yourself in two minutes. For each of the 13 categories, mark whether you hold both a procedure and documentary proof. Empty critical (STOP) categories are what stops the business first.
Critical gaps stop a business. Let's close them before a buyer, an investor or an audit finds them.
Close the risks5 readiness questions before you scale
Legal security is the ability to move fast without losing control. A company is ready to scale if it can answer five questions with confidence.
- 1What exactly do we produce and transfer?
- 2To whom, where and for what end-use?
- 3Who has access and who approved the decision?
- 4What contractual boundaries apply after transfer?
- 5What documents prove proper control?
What to do next
Start with an internal audit: run the 13 categories and mark which ones you already have a procedure and a document for, and which you don’t. That is your priority map: close the open STOP categories first, then SCALE, then SUPPORT.
Then comes what every careful counterparty checks. The same perimeter that protects you from a stoppage is the one an investor runs in due diligence and a buyer runs before a contract. A company with the 13 categories closed clears both without surprises — and that is what opens access to both capital and foreign contracts.
Legal risk in defense rarely arrives on its own — it arrives at the moment of the contract, the payment or the transfer, when it’s too late to stop. The companies that win close the perimeter in advance, in STOP → SCALE → SUPPORT order. That is the layer Wiseboard Defense builds for Ukrainian defense-tech companies: from product identification to a clean structure the buyer and the investor will later see.
Frequent questions
Produced in partnership with Juscutum. Petro Bilyk, Partner, AI & Technology practice. This article is informational and not legal advice. Regimes and lists (sanctions, critical goods, Defence City criteria) change — verify against the primary sources from SSECU, the Ministry of Defence and the NSDC, and get individual advice before acting.
- State Service of Export Control of Ukraine (SSECU) — permits, identification, country lists
- EU dual-use export control — Regulation (EU) 2021/821
- The Wassenaar Arrangement — conventional arms & dual-use export controls
- US EAR / Commerce Control List — Bureau of Industry and Security (BIS)
- US ITAR / US Munitions List — Directorate of Defense Trade Controls (DDTC)
- Ministry of Defence of Ukraine — Defence City resident status & benefits
- NSDC of Ukraine — sanctions decisions & the State Register of Sanctions
Published: 23 July 2026
