How to Determine if Your Product Is on the U.S. Munitions List?

Defense contractor reviewing U.S. Munitions List product classification

 The U.S. Munitions List is the classification system that determines whether a specific product or piece of technical data falls under the International Traffic in Arms Regulations (ITAR), and checking it is a separate question from anything your CMMC compliance work already covers.

One manufacturer we worked with found this out directly: well into solid CMMC Level 2 work, a completely separate conversation confirmed that a part they’d been producing for years was classified under the USML, triggering a registration requirement nobody had connected to their existing compliance project. 

Related Topic: Is Your Key Control Policy Actually Working?

How the USML Is Actually Organized?

The United States Munitions List isn’t a simple product catalog. It’s defined at 22 CFR § 121.1, part of the electronic Code of Federal Regulations, and organized into roughly two dozen numbered categories covering everything from Category I (firearms and related articles) and Category III (ammunition and ordnance) to Category IV (launch vehicles and guided missiles) and more specialized categories further down the list.

Each category comes with its own specific inclusion language, and often its own explicit exclusions too language stating a particular category does not control certain related items that might otherwise seem to fit. That’s exactly why classification isn’t as simple as matching a part to a category name. A component built for a military vehicle can be controlled under an entirely different category than the vehicle itself, and a part that looks similar to a controlled item can fall outside the category entirely depending on specific design details the category language spells out. 

This is also where the connection to the Commerce Control List, administered under a separate set of regulations at 15 CFR, matters again. Review specific category language carefully to determine ITAR or EAR jurisdiction and avoid relying on assumptions about product classification.

Related Topic: How to Run an Incident Response Tabletop Exercise?

How a Company Ends Up Not Knowing?

This isn’t a story about anyone being careless. The manufacturer had already invested real time and money into CMMC compliance, protecting Controlled Unclassified Information, CUI, the way the framework requires. CMMC work doesn’t ask the specific question that USML classification depends on, though: not “how are you protecting data,” but “does this specific product fall under a defense-article classification that triggers export control.” Those are genuinely different questions, evaluated under different frameworks, and answering one thoroughly says nothing about the other. 

In this case, the product was a torsion bar, a component used in military vehicle suspension systems. Nothing about a torsion bar looks exotic or obviously classified sitting on a shop floor. It’s a mechanical part, and plenty of non-defense torsion bars exist. What actually triggers USML classification isn’t how a part looks, it’s what it’s specifically designed for and what system it’s built into, and that context isn’t something a general compliance review is built to catch. Someone must directly verify each part’s classification instead of assuming a broad compliance program automatically covers every specific requirement.

Related Topic: What Is a System Security Plan? | Everything You Should Know

Confirming Eligibility Was the Easy Part 

Once the classification question came up, confirming basic ITAR eligibility was straightforward for this company: U.S.-based, free of foreign ownership. Domestically owned manufacturers usually complete this step quickly, making it one of the easiest confirmations in the entire process.

The harder, more consequential question was confirming that no non-U.S. persons had access to the technical data behind that part. Sharing technical data with a foreign person counts as an export under ITAR even if it happens entirely inside the United States, a rule known as a deemed export. Verifying this wasn’t a formality. Review everyone accessing technical data, including contractors and temporary staff, because information often travels beyond the core team unnoticed.

Related Topic: ITAR Compliance: Requirements & Cybersecurity

What Changed Once ITAR Applied?

Confirming the classification meant real, additional work layered on top of the CMMC compliance already underway, not a replacement for it. The company had to draft a dedicated ITAR policy specific to how they actually handled the classified part and its technical data, not a generic template adapted after the fact.

They assigned dedicated staff to manage ITAR compliance separately from CMMC, ensuring clear ownership of each framework’s distinct requirements internally.

Registration carried recurring costs: $3,000 initially and roughly $4,000 annually, though DDTC fees vary depending on each registration.

None of this replaced the CMMC work already in progress. Treat it as a separate compliance track requiring dedicated documentation, ownership, maintenance, and resources beyond the existing CMMC program.

Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals

A Different Shape: Needing Both From Day One

Not every company discovers this gap the way the torsion bar manufacturer did. A software and defense integration firm needed CMMC Level 2 and ITAR management because it handled CUI and USML data. There was no separate discovery moment. The team integrated both frameworks from onboarding, building one coordinated compliance program and preventing unexpected requirements from emerging later.

The contrast matters. Whether ITAR shows up as a day-one requirement or a mid-project discovery depends entirely on what your specific products and technical data actually are, not on how mature your CMMC compliance already is, and not on how long you’ve been operating as a defense contractor. A company can excel at CMMC yet overlook USML classification because CMMC requirements never directly prompt that critical question. The two compliance programs simply don’t check each other’s work. 

Related Topic: SOC 2 Requirements: What Your Business Needs to Know

How to Actually Check?

Check each product’s ITAR classification directly, including defense articles, temporary imports, and services, rather than relying on existing compliance. Submit a Commodity Jurisdiction request to DDTC when classification remains unclear, ensuring reliable answers instead of risky internal assumptions.

Waiting for that answer matters, too, not just asking the question. Keysight Technologies filed a commodity jurisdiction request after DDTC raised misclassification concerns about a piece of software the company had been treating as EAR99, meaning not ITAR-controlled at all. While that request was still pending, Keysight continued exporting the software under its original classification. DDTC ultimately determined the software was controlled under a specific USML category, and continuing to export under the old classification while the real answer was still pending became part of a consent agreement resulting in a $6.6 million penalty. The lesson isn’t just “check your classification.” It’s that once you’ve genuinely flagged uncertainty by filing for an official answer, treating the item as controlled until that answer comes back is the only defensible posture, not continuing business as usual in the meantime. 

The more sustainable version of this isn’t a one-time check. Build classification checks into routine product and contract reviews, just as teams assess CUI exposure before starting new work. Defense manufacturers should make USML classification standard during onboarding to proactively close compliance gaps for every product and customer.

If you want the fuller picture of what ITAR registration actually involves once classification is confirmed, including the eligibility requirements and the deemed export rule in more depth, our overview of what ITAR compliance actually requires covers that in full. 

Related Topic: What Is a POA&M? Complete Guide for Defense Contractors

What To Do With This?

If you’ve never specifically checked whether a product you manufacture is classified under the U.S. Munitions List, your CMMC compliance work almost certainly hasn’t answered that question for you, no matter how solid that work is. 

Schedule a free consultation with our CMMC-certified team to talk through whether ITAR applies to your specific products. If you’re already working through CMMC compliance services with us, this is exactly the kind of question worth raising directly rather than assuming your existing compliance work already covers it. 

FAQ 

Does having CMMC compliance mean I don’t need to worry about ITAR? 

No. CMMC and ITAR are triggered by different things and evaluated independently. Being fully compliant with CMMC says nothing about whether a specific product you manufacture is classified under the U.S. Munitions List, which is the question that actually determines whether ITAR applies. 

How do I know if my product is on the U.S. Munitions List? 

Classification depends on the item’s specific design and intended use, not just its general appearance, and can be genuinely difficult to determine with confidence internally. For products where classification is unclear, a commodity jurisdiction request to the State Department provides a formal, authoritative answer. 

Can a company need both CMMC and ITAR at the same time? 

Yes, and it’s common for companies whose work touches both Controlled Unclassified Information and USML-classified technical data. Some companies address both requirements immediately, while others discover ITAR obligations after they have already started their CMMC compliance journey.

Our Blog

What Is DFARS 252.204-7012? Requirements, Compliance & CMMC?

What Is DFARS 252.204-7012? Requirements, Compliance & CMMC?

A customer or prime contractor put DFARS 252.204-7012 in your contract. In plain terms,…

How to Determine if Your Product Is on the U.S. Munitions List?

How to Determine if Your Product Is on the U.S. Munitions List?

 The U.S. Munitions List is the classification system that determines whether a specific product or piece…

ITAR Compliance: Requirements & Cybersecurity

ITAR Compliance: Requirements & Cybersecurity

ITAR, the International Traffic in Arms Regulations, controls the export of defense-related articles, defense…