Skip to main content
  • IETF email infrastructure transition planned for 11 September

    A transition to a new modern, modular, and containerized infrastructure for email services provided for ietf.org, iab.org, irtf.org, rfc-editor.org (including email lists) is scheduled for 11 September 2026 starting at 2200UTC, with message delivery delayed up to 60 minutes. Further updates will be provided closer to the transition.

    28 Aug 2026
  • Post-Quantum Authentication: Up Next

    Post-quantum key establishment has moved from standards into deployment. Post-quantum authentication has not moved nearly as far, and specification work is no longer the only constraint. The IAB is holding a workshop in Prague on 11 and 12 October 2026 to bring deployment experience together with the people working on the relevant protocols and standards.

    27 Aug 2026
  • IETF 126 post-meeting survey: what we heard

    The IETF 126 Vienna meeting was held 18-24 July 2026 and the results of the post-meeting survey are now available.

    27 Aug 2026
  • Meet our new IETF NOC Lead

    Joe Clarke has been appointed as the new IETF NOC Lead and in this post Joe introduces himself and sets out his priorities for the IETF Network.

    10 Aug 2026
  • Secretariat restructuring and staffing update

    There have been a few changes in IETF Administration LLC staffing since January of this year (2026) including the recent insourcing of the Secretariat, which are summarised here to give an overall view of the staffing structure.

    30 Jul 2026

Filter by topic and date

Filter by topic and date

IETF LLC Statement on OFAC Compliance Questions

24 Mar 2021

IETF contributors recently asked the IETF LLC about the implications of complying with the US Treasury Department’s Office of Financial Asset Controls (OFAC).

See:

The sanctions rules managed by the US Treasury Department’s Office of Financial Asset Controls (OFAC) are nuanced and complex; broad statements about them are inevitably oversimplifications. That said, we think it unlikely that OFAC rules would meaningfully inhibit participation in IETF activities by individuals from sanctioned countries, or ever have in the past, as a general matter. OFAC rules focus on transactions and trade. Most IETF activity is fundamentally speech, excepted out from OFAC regulation either explicitly in the OFAC rules themselves or implicitly via U.S. constitutional safeguards.

We are not aware of any instance where OFAC rules have inhibited an individual from participating in the IETF. If such a situation were to arise in the future, we would work the affected individual to seek an appropriate accommodation to enable participation—for example, we could avoid problematic transactions while still engaging in communications, or seek a license from OFAC, or even escalate the issue as a legal matter if we thought that an individual’s right “to seek, receive and impart information and ideas through any media and regardless of frontiers” was being infringed (quoting the U.N. Declaration of Human Rights).

Properly complying with the OFAC regulations—as well as all other applicable laws and regulations—remains a critical task for IETF LLC. Our OFAC policy is designed to ensure our compliance. We do not anticipate that compliance will cause negative impacts on the IETF or its current or potential future new participants.

Recommendation of the IETF LLC to the General Area Dispatch working group and the Internet-Draft authors that asked the initial question.

We have no data to suggest OFAC rules have ever prevented any individual from participating in and contributing to the technical work of the IETF. We predict this will remain true in the future. OFAC rules thus do not appear to be a factor that will lead to a negative impact on the diversity and inclusiveness of the IETF. Further, OFAC regulations are a complex, nuanced topic that is difficult for non-experts to assess, and that defy simple summary treatment. Misstatements about compliance can have consequences. 

Accordingly, we recommend that any IETF groups or individuals focusing on issues of diversity and inclusiveness leave OFAC issues out of scope, given that (a) they are unlikely to negatively impact participation, (b) there is no evidence suggesting it has had an impact in the past, and (c) statements about IETF OFAC compliance are best managed by legal counsel.


Share this page