Instrument
Software and cloud-service denial
Software and cloud-service denial is the withdrawal or prohibition of software licences, updates, technical support, and cloud-hosted services to a target state or entity, degrading its digital infrastructure continuously rather than at a single stroke. It weaponises the subscription structure of modern software: because enterprise systems, design tools, and platforms are licensed and updated rather than owned, the supplier retains a standing capacity to switch the target off, or more precisely to let it decay.
Mechanism
The instrument operates through dependency over time. Denied updates may accumulate vulnerabilities and compatibility failures; denied support may make enterprise systems harder to maintain. Cloud delivery can create a sharper lever where specified functionality resides on a provider's infrastructure, but not every workload or service can be switched off instantly. The decision-maker matters. A government prohibition, export-control licence requirement, sanctions-compliance decision, provider contract term and voluntary market exit have different legal bases and exceptions. A private provider implementing a rule remains an intermediary, not the issuing authority.
Legal and institutional basis
Against Russia, the US Treasury issued a determination under Executive Order 14071 on 12 June 2024 covering IT consultancy and design services, IT support and cloud-based services for specified enterprise-management, design and manufacturing software. It took effect on 12 September 2024. OFAC FAQ 1184 defines covered categories and exceptions, including services to US-owned or controlled entities in Russia and services supporting authorised or licensed activity. The rule therefore does not prohibit every consumer application, update or cloud workload. Entity-based controls, sanctions programmes and other jurisdictions' rules must be analysed separately.
Employment history
Many Western software vendors suspended sales or services in Russia during 2022, often beyond then-operative legal requirements. The 2024 US determination created a defined prohibition, not a retrospective legal conversion of every earlier withdrawal. The separate BIS Kaspersky ICTS determination prohibited specified US transactions involving Kaspersky products on phased dates in 2024. It was not an OFAC Russia services measure. EU restrictions, provider terms and export controls likewise require their own authority, scope and wind-down analysis.
Effects and countermeasures
Effects are attritional where denied updates, support or hosted functions increase security, maintenance and compatibility risk. Their scale depends on the exact service, the customer's architecture and the availability of lawful substitutes. A target may continue using legacy installations, seek alternative vendors, redesign workflows or develop domestic capacity. Those adaptations can reduce immediate pressure and, over time, erode the supplier's chokepoint, the self-undermining arsenal problem in software form. The cited authorities do not establish the legality or prevalence of piracy, parallel imports or particular substitute ecosystems, so those claims require separate jurisdiction-specific evidence.
Effects also depend on architecture. On-premises perpetual software may continue without support, software-as-a-service may depend on continuous authentication, and a cloud workload may be portable or technically locked in. The date of contract termination, wind-down provision, data-export window and humanitarian or communications exception therefore matter to actual denial.
See also
Technology-embargo bundle · End-use and end-user controls · AI-chip and compute export control · Coalition sanctions and export controls against Russia after the full-scale invasion of Ukraine (2022-present) · Economic statecraft
Sources
- OFAC IT and software-services determination, accessed 30 July 2026.
- OFAC FAQ 1184, accessed 30 July 2026.
- BIS Kaspersky prohibition, accessed 30 July 2026.
- Council of the EU, Russia sanctions explained, accessed 30 July 2026.
Recommended citation
Cite this entry
Tennant, James J., ed. 'Software and cloud-service denial.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/software-and-cloud-service-denial/.
Suggest an edit