ITAR vs EAR: Which Rules Apply to You?

ITAR vs EAR comparison showing export control regulations for defense manufacturers

 ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) are two separate export control regimes, administered by two different federal agencies, covering two different categories of items. Both exist for the same underlying reason protecting national security by controlling which sensitive technologies and defense capabilities leave the country and who can access them  but they do it through different lists, different agencies, and different licensing rules.

ITAR, administered by the Department of State’s Directorate of Defense Trade Controls (DDTC), covers defense articles and services on the United States Munitions List (USML). EAR, administered by the Department of Commerce’s Bureau of Industry and Security (BIS), covers dual-use and less-sensitive military items on the Commerce Control List plus a catch-all category called EAR99 for items subject to only baseline export controls. 

Here’s what actually determines which one applies to you, where the confusion tends to happen, and what’s genuinely at stake if you get it wrong. 

Related Topic: What Is DFARS 252.204-7012? Requirements, Compliance & CMMC?

What Is the Difference Between ITAR and EAR? 

The core distinction is which list your product sits on, and that comes down to what the item actually is. ITAR covers items specifically designed, developed, or modified for military applications — the U.S. Munitions List is organized into categories covering things like firearms, military electronics, and spacecraft. EAR covers items with both commercial and military applications — dual-use items — plus purely commercial items that still warrant some export oversight. 

The practical difference in compliance burden is real. ITAR registration and licensing is generally more restrictive, more expensive, and applies regardless of the item’s value or destination in many cases. EAR licensing requirements vary significantly based on the item’s Export Control Classification Number (ECCN), the destination country, and the end use — and a large share of items subject to EAR fall under EAR99, which requires no license for most destinations. 

Related Topic: ITAR Compliance: Requirements & Cybersecurity

What Determines Whether a Product Falls Under ITAR or EAR? 

This isn’t a judgment call you make casually — it’s a formal classification process, and getting it wrong in either direction creates risk. A product built specifically for military application, or that incorporates ITAR-controlled technical data, is generally subject to ITAR regardless of whether a commercial equivalent exists. A product with genuine dual-use application — something with both civilian and potential military use — is more likely to fall under EAR, classified by an ECCN or defaulted to EAR99 if it doesn’t meet any specific control criteria. 

We worked with a manufacturer recently that assumed none of their product line was ITAR-controlled, since most of their business was commercial. A registration review found that at least five of their products — parts built to specific military specifications for Navy and Army contracts — did in fact qualify. ITAR registration starts at a few thousand dollars and scales with contract volume, but the real cost isn’t the registration fee  it’s the compliance program built around it afterward. 

Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals

Can Something Be ITAR and Not CUI? 

Yes, and this is a genuinely common point of confusion for manufacturers already thinking in CMMC terms. ITAR and Controlled Unclassified Information (CUI) are separate frameworks that frequently overlap but aren’t identical. Technical data controlled under ITAR is generally also treated as CUI, but not everything marked CUI is ITAR-controlled  CUI is a broader category covering various types of sensitive government information, of which ITAR technical data is one subset. Treating “ITAR” and “CUI” as interchangeable labels is a mistake that shows up in real access-control and data-handling policies, not just in casual conversation. 

Related Topic: CUI Marking Requirements: How to Label Controlled Unclassified Information Correctly 

What Happens When ITAR and EAR Get Confused in Practice 

This isn’t a hypothetical risk. In one incident we responded to directly, ITAR-protected technical drawings were accidentally emailed to a non-U.S. person through an ordinary Microsoft 365 mailbox — the kind of mistake that happens when ITAR data gets treated the same as general business email rather than something requiring its own handling rules. After discovery, company reported within 60 days, identified recipients and nationalities, and purged data from systems and backups. The company’s ITAR Empowered Official led the response while legal counsel reviewed contract clauses governing vendor compliance obligations carefully.

Organizations must use FedRAMP-approved cloud services to store and transmit ITAR data across both sending and receiving endpoints. A file sitting in a compliant system on your end doesn’t protect you if it lands in an ordinary commercial inbox on the other end. 

Related Topic: SOC 2 Requirements: What Your Business Needs to Know

Who Needs to Comply With ITAR or EAR? 

Manufacturers must follow applicable export regulations when making, exporting, importing, or sharing controlled technical data with foreign persons. Foreign national employees accessing ITAR-controlled technical data domestically may trigger deemed-export rules, creating compliance obligations organizations must understand.

Related Topic: Why Every Business Needs a Disaster Recovery Plan

What Are the Penalties for ITAR and EAR Violations? 

Enforcement has intensified significantly. BIS imposed approximately $324 million in penalties during 2025, marking an 18-fold increase from roughly $16 million in 2024. The Department of State enforces ITAR separately, imposing significant fines and potentially denying export privileges for compliance violations. Neither regulation treats “we didn’t realize this applied to us” as a meaningful defense. 

Clarify whether ITAR, EAR, or both apply to your products and data before customer compliance questionnaires force decisions. Our team works with manufacturers in the DoD and aerospace supply chain navigating exactly this kind of classification and data-handling complexity, backed by managed IT services built for compliance-heavy environments. For more on the broader ITAR compliance picture, see our guide to ITAR requirements and cybersecurity. 

👉 Schedule a free consultation with our team to talk through how ITAR and EAR actually apply to your business. 

Related Topic: Full GDPR Consultant Guide for EU Businesses | Data Privacy Made Simple

FAQs

What is EAR99?

EAR99 classifies items under EAR that lack ECCNs, but destinations, end users, or end uses may require licenses.

Which agency administers ITAR, and which administers EAR?

DDTC administers ITAR, while BIS administers EAR; companies handling both categories must follow each agency’s separate compliance requirements.

What’s the difference between the U.S. Munitions List and the Commerce Control List?

USML lists ITAR-controlled defense articles and services, while CCL classifies EAR-controlled dual-use items using Export Control Classification Numbers.

How much does ITAR registration cost?

DDTC charges several thousand dollars for ITAR registration, while compliance programs, documentation, and access controls create larger costs.

Our Blog

ITAR vs EAR: Which Rules Apply to You?

ITAR vs EAR: Which Rules Apply to You?

 ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) are two separate…

How Manufacturers Can Strengthen Operational Technology Security

How Manufacturers Can Strengthen Operational Technology Security

Operational technology (OT) security means protecting the systems that actually run your production floor…

AS9100 Certification Guide for Manufacturers

AS9100 Certification Guide for Manufacturers

AS9100 builds on ISO 9001, adding aerospace, space, and defense requirements for risk management…