Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
ITAR, the International Traffic in Arms Regulations, controls the export of defense-related articles, defense services, and technical data, administered by the Department of State’s Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA), with the specific regulations codified at 22 CFR Parts 120-130.
The underlying purpose is national security and foreign policy, not paperwork for its own sake: the government wants visibility and control over who has access to defense-relevant technology, wherever it ends up. Manufacturers must evaluate export controls separately from CMMC because their products can trigger requirements regardless of their contracting relationships.
Related Topic: SOC 2 Requirements: What Your Business Needs to Know
ITAR sits alongside the Export Administration Regulations (EAR), which covers dual-use items with both civilian and military applications under the Commerce Control List, administered separately by the Commerce Department rather than State.
The distinction matters because the two regimes carry different obligations, and a product can fall under one, the other, or occasionally require analysis under both before you know which set of rules actually applies. ITAR is generally the stricter of the two, and it’s the one this article focuses on, but it’s worth knowing EAR exists as a related but separate framework rather than assuming every export control question is automatically an ITAR question.
Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals
ITAR applies based on whether a specific product or piece of technical data falls under the United States Munitions List (USML), a detailed classification system covering defense articles and defense services. Defense services aren’t limited to physical products — training, technical assistance, or design help provided to a foreign person can itself be a controlled defense service, separate from any physical item involved. This is a product-based and activity-based trigger, not a company-based one.
A manufacturer can work defense contracts for years, already deep into CMMC compliance work protecting Controlled Unclassified Information, and still not have specifically checked whether an individual part they produce, or a service they provide, is classified under the USML.
That’s exactly what happened with one manufacturer we worked with. Well into their CMMC compliance work, a separate conversation confirmed that a specific part they’d been producing for years, a component used in military vehicle suspension systems, fell under U.S. Munitions List classification. Nobody had done anything wrong. Companies must evaluate CMMC and ITAR separately because each framework triggers different requirements despite careful compliance efforts under either.
Related Topic: Why Every Business Needs a Disaster Recovery Plan
Registering with DDTC is the entry requirement, not the finish line. Once registered, actually exporting a defense article, providing a defense service, or sharing technical data with a foreign person typically requires a specific export license or another form of DDTC authorization for that particular transaction.
A company can be fully registered and still need a separate license before a given shipment, technical data transfer, or foreign engagement is actually authorized. Treating registration as the end of the compliance obligation, rather than the beginning of an ongoing licensing relationship with DDTC, is a common and costly misunderstanding.
Related Topic: Full GDPR Consultant Guide for EU Businesses | Data Privacy Made Simple
ITAR violations carry real consequences, and they’re not limited to large defense primes. Penalties can include significant civil fines, criminal charges in serious cases, and debarment from future export privileges, which for a defense manufacturer can mean losing the ability to work on ITAR-controlled contracts at all.
Violations don’t require intent to be treated seriously; failing to register when required, or exporting a controlled item or sharing controlled technical data without proper authorization, can trigger enforcement even when nobody involved understood ITAR applied. That’s exactly why the classification question matters so much before a violation happens, not just as an abstract compliance exercise afterward.
These aren’t hypothetical numbers. FLIR Systems entered into a consent agreement with DDTC in 2018 covering a broad pattern of ITAR violations, resulting in a $30 million penalty, with $15 million suspended contingent on remedial compliance measures — a figure confirmed directly in the company’s own SEC filings. Smaller violations may cost less, but regulators assess penalties based on severity and patterns rather than company size alone.
Related Topic: Pennsylvania Insurance Data Security Act Guide
Beyond the product classification question, a company has to meet basic eligibility criteria to register with DDTC in the first place: being U.S.-based and free of foreign ownership or control. Domestic manufacturers should verify eligibility through a separate confirmation step rather than assume their ownership automatically satisfies applicable requirements.
Product classification itself can also be genuinely complex. The USML’s categories are detailed, and a component can be difficult to classify with confidence without real diligence. Evaluate each part’s intended use and system context to determine defense classification instead of relying solely on physical appearance.
Related Topic: Mastering CMMC Compliance: The Essential Guide to FIPS Encryption
ITAR treats sharing technical data with foreign persons as an export, even when the exchange occurs entirely within America. The regulation distinguishes US persons from everyone else and applies this distinction regardless of where organizations share information physically. This is often called a deemed export.
Foreign employees, contractors, or visitors accessing controlled documents can trigger obligations similar to physically exporting controlled items overseas.
Confirming that no non-U.S. persons have access to your technical data isn’t a formality. Verify and maintain access controls for employees, contractors, temporary staff, and anyone who handles technical data, regardless of duration.
Related Topic: Is Your Key Control Policy Actually Working?
Once eligibility and classification are confirmed, registration involves a real internal process, not just filling out a form. Companies must create tailored ITAR policies, establish compliance programs, and assign responsible personnel to manage daily compliance and enforcement. Tailor the policy to actual technical data practices so assessors can verify it accurately reflects your company’s operations.
Registration also isn’t free, and it isn’t one-time. In one real registration we supported, the initial registration fee was $3,000, with subsequent annual renewal starting around $4,000. DDTC registration creates recurring costs, and companies should verify current fees rather than relying on another organization’s specific figures.
Communicate ITAR applicability clearly to customers so they understand what information you can share and how you share it.
Related Topic: How to Run an Incident Response Tabletop Exercise?
Submit a commodity jurisdiction request to the State Department when context creates uncertainty about ITAR versus EAR product classification. Asking directly whether a specific item falls under ITAR or EAR. Use formal classification processes for ambiguous cases to get authoritative answers instead of risking costly mistakes during audits or exports.
Separate CMMC from ITAR: CMMC protects controlled information, while ITAR regulates defense exports through registration, classification, and licensing requirements.
Companies must evaluate CMMC and ITAR independently, even when both apply to the same products, operations, and technical data.
Some companies need both from the very start. One remote software and defense integration firm we worked with was flagged as needing both CMMC Level 2 and ITAR management from day one of onboarding, since their work touched both CUI and USML-classified technical data simultaneously. Other companies, like the manufacturer above, discover the ITAR piece separately, sometimes years into otherwise solid CMMC work. If you want a closer look at how that discovery actually happens and what it means for a company already deep into CMMC, we’ve written a full breakdown of what it means when a product turns out to be on the U.S. Munitions List.
Related Topic: Why GCC High Migration Costs Vary and How to Budget Smarter
If you’ve never specifically checked whether a product you manufacture falls under the U.S. Munitions List, that’s worth doing deliberately rather than assuming your CMMC compliance work already covers it, because it doesn’t.
Schedule a free consultation with our CMMC-certified team to talk through whether ITAR applies to your specific products, separate from whatever CMMC work is already underway. If you’re already working through CMMC compliance services with us, this is exactly the kind of question worth raising directly rather than assuming it’s already covered.
Related Topic: What Is a System Security Plan? | Everything You Should Know
CMMC protects Controlled Unclassified Information under a Department of Defense contracting requirement. ITAR controls the export of specific defense articles and technical data under a separate framework administered by the State Department. A company can need either, both, or discover it needs one well after already complying with the other.
US-based companies must follow ITAR when manufacturing, exporting, or brokering USML-controlled products or data, regardless of defense contracts.
Registration involves an initial fee followed by recurring annual renewal fees, and the exact amount can vary. Confirming current, exact figures directly with DDTC or a qualified advisor before budgeting is worth doing rather than relying on a fixed number, since fee schedules can change.
Regulators can impose fines, criminal charges, or debarment for ITAR violations, even when companies unknowingly fail compliance requirements.
ITAR, the International Traffic in Arms Regulations, controls the export of defense-related articles, defense…
A SOC 2 readiness assessment is the gap analysis work you do before the…
SOC 2 stands for System and Organization Controls 2, an attestation framework developed by…