Secondary Sanctions
Secondary sanctions penalise non-US persons and entities for doing business with a sanctioned target, even where the transaction has no US nexus at all, no US person, no US dollars, no US territory involved. They work not through direct legal jurisdiction, which the US doesn’t have over a foreign company with no American footprint, but through the threat of cutting that company off from the US financial system entirely if it doesn’t comply.
Key takeaways
- Secondary sanctions penalise non-US firms for dealing with a sanctioned target, enforced through denial of US financial system access rather than direct legal jurisdiction.
- CAATSA (2017) made many secondary sanctions provisions mandatory rather than discretionary, a genuine structural shift from how sanctions previously operated.
- Turkey’s CAATSA-triggered sanctions over its S-400 purchase show mandatory secondary sanctions apply even to formal US treaty allies.
- Enforcement runs through three mechanisms: SDN designation, correspondent banking restrictions, and sectoral restrictions denying an entire industry US market access.
- Menu-based sanctions lists (the CAPTA List, Non-SDN Menu-Based Sanctions List) capture exposure that standard SDN List screening alone misses.
- The EU’s Blocking Regulation has been assessed as largely ineffective due to an “enforcement paradox”: EU authorities rarely penalise compliance with US secondary sanctions.
- Over 65% of OFAC secondary sanctions actions target corporate entities, and any firm dependent on US dollar clearing carries exposure regardless of US presence.
On this page
What secondary sanctions actually areThe mechanism: threat, not jurisdictionThe three enforcement mechanismsCAATSA: when secondary sanctions became mandatoryA real, documented example: Turkey and the S-400Menu-based sanctions: the technical screening layerThe EU’s counter-response: the Blocking RegulationWhy the Blocking Regulation hasn’t really workedWho secondary sanctions actually targetWhat this means for compliance outside the USBuilding secondary sanctions into a risk assessmentFAQsRead more
65%+
Of OFAC secondary sanctions actions directed at corporate entities rather than individuals
7 Aug 2018
Effective date of the EU’s updated Blocking Regulation (Council Regulation 2271/96)
Source: European Union
What secondary sanctions actually are
Secondary sanctions penalise non-US persons and entities for doing business with a sanctioned regime, sector, or party, even where the underlying transaction has no US nexus whatsoever. Ordinary US sanctions, primary sanctions, apply directly to US persons and anyone operating within US jurisdiction. Secondary sanctions extend consequences to a completely different population: foreign companies, foreign banks, foreign individuals, who have no US presence and would otherwise be entirely outside US legal reach.
The mechanism: threat, not jurisdiction
The US doesn’t have direct legal jurisdiction over a foreign bank with no American branches, no US dollar clearing relationship, and no US ownership. Secondary sanctions work around that limitation entirely differently: rather than asserting jurisdiction the US doesn’t have, they threaten to deny the foreign entity something it very much wants, access to the US financial system, US dollar clearing, US correspondent banking relationships, if it continues transacting with the sanctioned target. The foreign entity technically remains free to ignore US law; the practical cost of doing so is severe enough that most large financial institutions and multinational firms choose compliance instead. This is what makes secondary sanctions genuinely extraterritorial in effect while remaining, in a narrow legal sense, enforced through leverage rather than direct jurisdiction over the foreign firm itself.
The three enforcement mechanisms
Secondary sanctions enforcement generally falls into one of three categories. SDN designation adds the non-compliant foreign entity directly to OFAC’s own SDN List, triggering the full blocking consequences that apply to any Specially Designated National. Correspondent banking restrictions cut off a foreign financial institution’s access to US dollar correspondent accounts specifically, without necessarily designating the institution as an SDN outright, a narrower but still severe consequence given how central dollar clearing is to international trade. Sectoral restrictions deny an entire foreign industry, energy, defence, finance, access to US financing, technology transfers, or debt markets, targeting a sector broadly rather than a single named entity.
CAATSA: when secondary sanctions became mandatory
The Countering America’s Adversaries Through Sanctions Act, CAATSA, passed by Congress in 2017, marked a genuine structural shift most introductory content glosses over: it made many secondary sanctions provisions mandatory for the President to impose, rather than discretionary. Before CAATSA, secondary sanctions largely operated as an executive-branch tool the President could apply, ease, or withhold based on foreign policy judgement. CAATSA specifically required the US government to sanction foreign companies engaging in “significant transactions” with Russia’s defence and intelligence sectors, removing much of that discretion. This distinction, mandatory statutory sanctions versus discretionary executive sanctions, genuinely changes how predictable and durable a given secondary sanctions exposure is likely to be across different US political administrations.
A real, documented example: Turkey and the S-400
CAATSA’s mandatory framework was directly responsible for one of the clearest recent examples of secondary sanctions actually being applied against a NATO ally. Turkey’s 2019 purchase of Russia’s S-400 missile defence system triggered CAATSA Section 231, which required sanctions against Turkey’s defence procurement agency, cutting Turkish defence firms off from American components and technology partnerships, a consequence that persisted despite Turkey’s status as a formal US treaty ally. That outcome illustrates precisely how mandatory secondary sanctions differ from discretionary ones: political alliance didn’t create an automatic exemption once the statutory trigger was met.
Menu-based sanctions: the technical screening layer
For a compliance programme, secondary sanctions exposure isn’t fully captured by checking the standard SDN List alone. Several secondary sanctions authorities, including CAATSA, operate through what’s known as menu-based sanctions: a defined menu of possible penalty types that can be applied to a designated entity, tracked through separate reference lists such as the Non-SDN Menu-Based Sanctions List and the CAPTA List, a list of foreign financial institutions subject to correspondent account restrictions specifically. A screening programme built only around the SDN List, without incorporating these menu-based and sector-specific lists, misses a meaningful category of secondary sanctions exposure entirely.
The EU’s counter-response: the Blocking Regulation
The European Union’s primary legal response to US secondary sanctions is its Blocking Regulation, Council Regulation 2271/96, originally adopted in 1996 in response to earlier US extraterritorial sanctions on Cuba, and substantially updated with effect from 7 August 2018. The updated regulation operates through three mechanisms: it prohibits EU persons from complying with listed US secondary sanctions unless specifically authorised by the European Commission, it nullifies the legal effect within the EU of any foreign court judgment based on those sanctions, and it allows EU companies to recover damages caused by the sanctions’ application.
Why the Blocking Regulation hasn’t really worked
In practice, the EU’s Blocking Regulation has been widely regarded as largely ineffective. A 2021 European Commission public consultation concluded it had not succeeded in protecting European entities from US secondary sanctions pressure. The core problem researchers have identified is what’s been termed an “enforcement paradox”: European Commission and national authorities have generally been reluctant to actually penalise EU companies for quietly complying with American secondary sanctions, even though that compliance technically violates the Blocking Regulation itself, while companies that do try to follow the Blocking Regulation’s instructions and continue transacting with a US-sanctioned target face the very real US consequences the regulation can’t actually shield them from. Faced with a choice between a rarely-enforced EU rule and a routinely-enforced US one, most companies choose to comply with the US rule.
Who secondary sanctions actually target
Legal analysis of OFAC’s secondary sanctions actions has found that more than 65% are directed at corporate entities rather than individuals, reflecting the reality that most sanctions evasion and circumvention activity runs through business structures, banks, trading companies, shipping firms, rather than individual actors operating alone. Enforcement attention has increasingly concentrated on transshipment hubs and jurisdictions with weaker export control enforcement, the UAE, parts of Central Asia, and Eastern Europe among them, where goods and financial flows can be rerouted specifically to obscure their true origin or destination.
What this means for compliance outside the US
For a firm with no US ownership, no US operations, and no obvious US legal exposure, secondary sanctions still matter directly if that firm relies on US dollar clearing, correspondent banking relationships with US institutions, or US-origin technology and components anywhere in its supply chain, which describes the overwhelming majority of internationally active businesses. Treating secondary sanctions as a US-only compliance concern, relevant only to firms with genuine US nexus, misunderstands how the mechanism is actually designed to work: the entire point is to reach firms that have no US nexus at all.
Building secondary sanctions into a risk assessment
A risk assessment that properly accounts for secondary sanctions exposure looks beyond direct SDN screening to map dependency on US dollar clearing and correspondent banking, screen counterparties and their supply chains against menu-based and sectoral lists specifically, not just the SDN List, and assess exposure to the specific sectors, defence, energy, and jurisdictions, Russia, Iran, North Korea, most frequently targeted by mandatory secondary sanctions authorities like CAATSA. Firms operating supply chains through known transshipment risk jurisdictions need particular attention to end-user verification, since the entire purpose of routing goods through an intermediary jurisdiction is often to obscure the transaction’s true final destination.
Check counterparty exposure to secondary sanctions
Screen against menu-based and sectoral lists, not just the SDN List alone.
Frequently asked questions
What are secondary sanctions?
Secondary sanctions penalise non-US persons and entities for doing business with a sanctioned target, even where the transaction has no US nexus at all, enforced through the threat of losing access to the US financial system rather than direct legal jurisdiction.
How is this different from primary sanctions?
Primary sanctions restrict US persons and anyone within US jurisdiction directly. Secondary sanctions extend consequences to foreign persons and entities with no US presence, who would otherwise be entirely outside US legal reach.
What is CAATSA and why does it matter?
The Countering America’s Adversaries Through Sanctions Act (2017) made many secondary sanctions provisions mandatory for the President to impose, rather than discretionary, removing much of the executive branch’s prior flexibility on Russia, Iran, and North Korea sanctions specifically.
Can secondary sanctions apply to a NATO ally?
Yes. Turkey’s 2019 purchase of Russia’s S-400 missile system triggered mandatory sanctions under CAATSA Section 231 against Turkish defence procurement, despite Turkey’s status as a formal US treaty ally.
What is the EU’s Blocking Regulation?
Council Regulation 2271/96, updated with effect from 7 August 2018, prohibits EU persons from complying with listed US secondary sanctions and lets EU firms recover damages caused by them, though it has been widely assessed as largely ineffective in practice.
Why hasn’t the EU’s Blocking Regulation worked?
A 2021 European Commission consultation found it hadn’t succeeded, largely due to an “enforcement paradox”: EU authorities rarely penalise companies for quietly complying with US secondary sanctions, while the Blocking Regulation offers no real protection from the US consequences of not complying.
Who do secondary sanctions actually target?
More than 65% of OFAC secondary sanctions actions target corporate entities rather than individuals, reflecting that most evasion activity runs through business structures rather than individual actors.
Does a firm need any US connection to be exposed to secondary sanctions?
No. The entire mechanism is designed to reach firms with no US nexus at all. Any firm relying on US dollar clearing or correspondent banking relationships anywhere in its operations carries real exposure.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 12 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Secondary sanctions penalise non-US persons and entities for doing business with a sanctioned target, even where the transaction has no US nexus at all, no US person, no US dollars, no US territory involved. They work not through direct legal jurisdiction, which the US doesn’t have over a foreign company with no American footprint, but through the threat of cutting that company off from the US financial system entirely if it doesn’t comply.