ITAR Compliance: Requirements & Cybersecurity

ITAR compliance requirements for defense contractors and manufacturers

ITAR, the International Traffic in Arms Regulations, controls the export of defense-related articles, defense services, and technical data, administered by the Department of State’s Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA), with the specific regulations codified at 22 CFR Parts 120-130.

The underlying purpose is national security and foreign policy, not paperwork for its own sake: the government wants visibility and control over who has access to defense-relevant technology, wherever it ends up. Manufacturers must evaluate export controls separately from CMMC because their products can trigger requirements regardless of their contracting relationships.

Related Topic: SOC 2 Requirements: What Your Business Needs to Know

ITAR Isn’t the Only Export Control Regime, Just the Strictest 

ITAR sits alongside the Export Administration Regulations (EAR), which covers dual-use items with both civilian and military applications under the Commerce Control List, administered separately by the Commerce Department rather than State.

The distinction matters because the two regimes carry different obligations, and a product can fall under one, the other, or occasionally require analysis under both before you know which set of rules actually applies. ITAR is generally the stricter of the two, and it’s the one this article focuses on, but it’s worth knowing EAR exists as a related but separate framework rather than assuming every export control question is automatically an ITAR question. 

Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals

What Actually Triggers ITAR?

ITAR applies based on whether a specific product or piece of technical data falls under the United States Munitions List (USML), a detailed classification system covering defense articles and defense services. Defense services aren’t limited to physical products — training, technical assistance, or design help provided to a foreign person can itself be a controlled defense service, separate from any physical item involved. This is a product-based and activity-based trigger, not a company-based one.

A manufacturer can work defense contracts for years, already deep into CMMC compliance work protecting Controlled Unclassified Information, and still not have specifically checked whether an individual part they produce, or a service they provide, is classified under the USML. 

That’s exactly what happened with one manufacturer we worked with. Well into their CMMC compliance work, a separate conversation confirmed that a specific part they’d been producing for years, a component used in military vehicle suspension systems, fell under U.S. Munitions List classification. Nobody had done anything wrong. Companies must evaluate CMMC and ITAR separately because each framework triggers different requirements despite careful compliance efforts under either.

Related Topic: Why Every Business Needs a Disaster Recovery Plan

Registration Isn’t the Same as Having a License

Registering with DDTC is the entry requirement, not the finish line. Once registered, actually exporting a defense article, providing a defense service, or sharing technical data with a foreign person typically requires a specific export license or another form of DDTC authorization for that particular transaction. 

A company can be fully registered and still need a separate license before a given shipment, technical data transfer, or foreign engagement is actually authorized. Treating registration as the end of the compliance obligation, rather than the beginning of an ongoing licensing relationship with DDTC, is a common and costly misunderstanding. 

Related Topic: Full GDPR Consultant Guide for EU Businesses | Data Privacy Made Simple

What Happens If You Get This Wrong?

ITAR violations carry real consequences, and they’re not limited to large defense primes. Penalties can include significant civil fines, criminal charges in serious cases, and debarment from future export privileges, which for a defense manufacturer can mean losing the ability to work on ITAR-controlled contracts at all.

Violations don’t require intent to be treated seriously; failing to register when required, or exporting a controlled item or sharing controlled technical data without proper authorization, can trigger enforcement even when nobody involved understood ITAR applied. That’s exactly why the classification question matters so much before a violation happens, not just as an abstract compliance exercise afterward. 

These aren’t hypothetical numbers. FLIR Systems entered into a consent agreement with DDTC in 2018 covering a broad pattern of ITAR violations, resulting in a $30 million penalty, with $15 million suspended contingent on remedial compliance measures — a figure confirmed directly in the company’s own SEC filings. Smaller violations may cost less, but regulators assess penalties based on severity and patterns rather than company size alone.

Related Topic: Pennsylvania Insurance Data Security Act Guide

Who’s Actually Eligible to Register?

Beyond the product classification question, a company has to meet basic eligibility criteria to register with DDTC in the first place: being U.S.-based and free of foreign ownership or control. Domestic manufacturers should verify eligibility through a separate confirmation step rather than assume their ownership automatically satisfies applicable requirements.

Product classification itself can also be genuinely complex. The USML’s categories are detailed, and a component can be difficult to classify with confidence without real diligence. Evaluate each part’s intended use and system context to determine defense classification instead of relying solely on physical appearance.

Related Topic: Mastering CMMC Compliance: The Essential Guide to FIPS Encryption

The “Deemed Export” Rule That Catches People Off Guard

ITAR treats sharing technical data with foreign persons as an export, even when the exchange occurs entirely within America. The regulation distinguishes US persons from everyone else and applies this distinction regardless of where organizations share information physically. This is often called a deemed export.

Foreign employees, contractors, or visitors accessing controlled documents can trigger obligations similar to physically exporting controlled items overseas.

Confirming that no non-U.S. persons have access to your technical data isn’t a formality. Verify and maintain access controls for employees, contractors, temporary staff, and anyone who handles technical data, regardless of duration.

Related Topic: Is Your Key Control Policy Actually Working?

What Registration Actually Involves?

Once eligibility and classification are confirmed, registration involves a real internal process, not just filling out a form. Companies must create tailored ITAR policies, establish compliance programs, and assign responsible personnel to manage daily compliance and enforcement. Tailor the policy to actual technical data practices so assessors can verify it accurately reflects your company’s operations.

Registration also isn’t free, and it isn’t one-time. In one real registration we supported, the initial registration fee was $3,000, with subsequent annual renewal starting around $4,000. DDTC registration creates recurring costs, and companies should verify current fees rather than relying on another organization’s specific figures.

Communicate ITAR applicability clearly to customers so they understand what information you can share and how you share it.

Related Topic: How to Run an Incident Response Tabletop Exercise?

When You’re Genuinely Not Sure Which Applies

Submit a commodity jurisdiction request to the State Department when context creates uncertainty about ITAR versus EAR product classification. Asking directly whether a specific item falls under ITAR or EAR. Use formal classification processes for ambiguous cases to get authoritative answers instead of risking costly mistakes during audits or exports.

ITAR and CMMC Are Not the Same Requirement 

Separate CMMC from ITAR: CMMC protects controlled information, while ITAR regulates defense exports through registration, classification, and licensing requirements.

Companies must evaluate CMMC and ITAR independently, even when both apply to the same products, operations, and technical data.

Some companies need both from the very start. One remote software and defense integration firm we worked with was flagged as needing both CMMC Level 2 and ITAR management from day one of onboarding, since their work touched both CUI and USML-classified technical data simultaneously. Other companies, like the manufacturer above, discover the ITAR piece separately, sometimes years into otherwise solid CMMC work. If you want a closer look at how that discovery actually happens and what it means for a company already deep into CMMC, we’ve written a full breakdown of  what it means when a product turns out to be on the U.S. Munitions List. 

Related Topic: Why GCC High Migration Costs Vary and How to Budget Smarter

Final Thoughts: 

If you’ve never specifically checked whether a product you manufacture falls under the U.S. Munitions List, that’s worth doing deliberately rather than assuming your CMMC compliance work already covers it, because it doesn’t. 

Schedule a free consultation with our CMMC-certified team to talk through whether ITAR applies to your specific products, separate from whatever CMMC work is already underway. If you’re already working through CMMC compliance services with us, this is exactly the kind of question worth raising directly rather than assuming it’s already covered. 

Related Topic: What Is a System Security Plan? | Everything You Should Know

FAQ 

What’s the difference between ITAR and CMMC? 

CMMC protects Controlled Unclassified Information under a Department of Defense contracting requirement. ITAR controls the export of specific defense articles and technical data under a separate framework administered by the State Department. A company can need either, both, or discover it needs one well after already complying with the other. 

Who needs to register for ITAR?

US-based companies must follow ITAR when manufacturing, exporting, or brokering USML-controlled products or data, regardless of defense contracts.

How much does ITAR registration cost? 

Registration involves an initial fee followed by recurring annual renewal fees, and the exact amount can vary. Confirming current, exact figures directly with DDTC or a qualified advisor before budgeting is worth doing rather than relying on a fixed number, since fee schedules can change. 

What are the consequences of ITAR violations? 

Regulators can impose fines, criminal charges, or debarment for ITAR violations, even when companies unknowingly fail compliance requirements.

Our Blog

ITAR Compliance: Requirements & Cybersecurity

ITAR Compliance: Requirements & Cybersecurity

ITAR, the International Traffic in Arms Regulations, controls the export of defense-related articles, defense…

Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals

Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals

A SOC 2 readiness assessment is the gap analysis work you do before the…

SOC 2 Requirements: What Your Business Needs to Know

SOC 2 Requirements: What Your Business Needs to Know

 SOC 2 stands for System and Organization Controls 2, an attestation framework developed by…