If the requirement is for US Companies to provide encryption backdoors what about allowing someone to provide their own PGP (or other) certs -- would that side-step the requirement since the encryption is being performed by the user and not the company?