
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...


Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...


The U.S. Munitions List is the classification system that determines whether a specific product or piece of technical data falls under the International Traffic in Arms Regulations (ITAR), and checking it is a separate question from anything your CMMC compliance work already covers.
One manufacturer we worked with found this out directly: well into solid CMMC Level 2 work, a completely separate conversation confirmed that a part they’d been producing for years was classified under the USML, triggering a registration requirement nobody had connected to their existing compliance project.
Related Topic: Is Your Key Control Policy Actually Working?
The United States Munitions List isn’t a simple product catalog. It’s defined at 22 CFR § 121.1, part of the electronic Code of Federal Regulations, and organized into roughly two dozen numbered categories covering everything from Category I (firearms and related articles) and Category III (ammunition and ordnance) to Category IV (launch vehicles and guided missiles) and more specialized categories further down the list.
Each category comes with its own specific inclusion language, and often its own explicit exclusions too language stating a particular category does not control certain related items that might otherwise seem to fit. That’s exactly why classification isn’t as simple as matching a part to a category name. A component built for a military vehicle can be controlled under an entirely different category than the vehicle itself, and a part that looks similar to a controlled item can fall outside the category entirely depending on specific design details the category language spells out.
This is also where the connection to the Commerce Control List, administered under a separate set of regulations at 15 CFR, matters again. Review specific category language carefully to determine ITAR or EAR jurisdiction and avoid relying on assumptions about product classification.
Related Topic: How to Run an Incident Response Tabletop Exercise?
This isn’t a story about anyone being careless. The manufacturer had already invested real time and money into CMMC compliance, protecting Controlled Unclassified Information, CUI, the way the framework requires. CMMC work doesn’t ask the specific question that USML classification depends on, though: not “how are you protecting data,” but “does this specific product fall under a defense-article classification that triggers export control.” Those are genuinely different questions, evaluated under different frameworks, and answering one thoroughly says nothing about the other.
In this case, the product was a torsion bar, a component used in military vehicle suspension systems. Nothing about a torsion bar looks exotic or obviously classified sitting on a shop floor. It’s a mechanical part, and plenty of non-defense torsion bars exist. What actually triggers USML classification isn’t how a part looks, it’s what it’s specifically designed for and what system it’s built into, and that context isn’t something a general compliance review is built to catch. Someone must directly verify each part’s classification instead of assuming a broad compliance program automatically covers every specific requirement.
Related Topic: What Is a System Security Plan? | Everything You Should Know
Once the classification question came up, confirming basic ITAR eligibility was straightforward for this company: U.S.-based, free of foreign ownership. Domestically owned manufacturers usually complete this step quickly, making it one of the easiest confirmations in the entire process.
The harder, more consequential question was confirming that no non-U.S. persons had access to the technical data behind that part. Sharing technical data with a foreign person counts as an export under ITAR even if it happens entirely inside the United States, a rule known as a deemed export. Verifying this wasn’t a formality. Review everyone accessing technical data, including contractors and temporary staff, because information often travels beyond the core team unnoticed.
Related Topic: ITAR Compliance: Requirements & Cybersecurity
Confirming the classification meant real, additional work layered on top of the CMMC compliance already underway, not a replacement for it. The company had to draft a dedicated ITAR policy specific to how they actually handled the classified part and its technical data, not a generic template adapted after the fact.
They assigned dedicated staff to manage ITAR compliance separately from CMMC, ensuring clear ownership of each framework’s distinct requirements internally.
Registration carried recurring costs: $3,000 initially and roughly $4,000 annually, though DDTC fees vary depending on each registration.
None of this replaced the CMMC work already in progress. Treat it as a separate compliance track requiring dedicated documentation, ownership, maintenance, and resources beyond the existing CMMC program.
Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals
Not every company discovers this gap the way the torsion bar manufacturer did. A software and defense integration firm needed CMMC Level 2 and ITAR management because it handled CUI and USML data. There was no separate discovery moment. The team integrated both frameworks from onboarding, building one coordinated compliance program and preventing unexpected requirements from emerging later.
The contrast matters. Whether ITAR shows up as a day-one requirement or a mid-project discovery depends entirely on what your specific products and technical data actually are, not on how mature your CMMC compliance already is, and not on how long you’ve been operating as a defense contractor. A company can excel at CMMC yet overlook USML classification because CMMC requirements never directly prompt that critical question. The two compliance programs simply don’t check each other’s work.
Related Topic: SOC 2 Requirements: What Your Business Needs to Know
Check each product’s ITAR classification directly, including defense articles, temporary imports, and services, rather than relying on existing compliance. Submit a Commodity Jurisdiction request to DDTC when classification remains unclear, ensuring reliable answers instead of risky internal assumptions.
Waiting for that answer matters, too, not just asking the question. Keysight Technologies filed a commodity jurisdiction request after DDTC raised misclassification concerns about a piece of software the company had been treating as EAR99, meaning not ITAR-controlled at all. While that request was still pending, Keysight continued exporting the software under its original classification. DDTC ultimately determined the software was controlled under a specific USML category, and continuing to export under the old classification while the real answer was still pending became part of a consent agreement resulting in a $6.6 million penalty. The lesson isn’t just “check your classification.” It’s that once you’ve genuinely flagged uncertainty by filing for an official answer, treating the item as controlled until that answer comes back is the only defensible posture, not continuing business as usual in the meantime.
The more sustainable version of this isn’t a one-time check. Build classification checks into routine product and contract reviews, just as teams assess CUI exposure before starting new work. Defense manufacturers should make USML classification standard during onboarding to proactively close compliance gaps for every product and customer.
If you want the fuller picture of what ITAR registration actually involves once classification is confirmed, including the eligibility requirements and the deemed export rule in more depth, our overview of what ITAR compliance actually requires covers that in full.
Related Topic: What Is a POA&M? Complete Guide for Defense Contractors
If you’ve never specifically checked whether a product you manufacture is classified under the U.S. Munitions List, your CMMC compliance work almost certainly hasn’t answered that question for you, no matter how solid that work is.
Schedule a free consultation with our CMMC-certified team to talk through whether ITAR applies to your specific products. If you’re already working through CMMC compliance services with us, this is exactly the kind of question worth raising directly rather than assuming your existing compliance work already covers it.
No. CMMC and ITAR are triggered by different things and evaluated independently. Being fully compliant with CMMC says nothing about whether a specific product you manufacture is classified under the U.S. Munitions List, which is the question that actually determines whether ITAR applies.
Classification depends on the item’s specific design and intended use, not just its general appearance, and can be genuinely difficult to determine with confidence internally. For products where classification is unclear, a commodity jurisdiction request to the State Department provides a formal, authoritative answer.
Yes, and it’s common for companies whose work touches both Controlled Unclassified Information and USML-classified technical data. Some companies address both requirements immediately, while others discover ITAR obligations after they have already started their CMMC compliance journey.
A customer or prime contractor put DFARS 252.204-7012 in your contract. In plain terms,…
The U.S. Munitions List is the classification system that determines whether a specific product or piece…
ITAR, the International Traffic in Arms Regulations, controls the export of defense-related articles, defense…