Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) are two separate export control regimes, administered by two different federal agencies, covering two different categories of items. Both exist for the same underlying reason protecting national security by controlling which sensitive technologies and defense capabilities leave the country and who can access them but they do it through different lists, different agencies, and different licensing rules.
ITAR, administered by the Department of State’s Directorate of Defense Trade Controls (DDTC), covers defense articles and services on the United States Munitions List (USML). EAR, administered by the Department of Commerce’s Bureau of Industry and Security (BIS), covers dual-use and less-sensitive military items on the Commerce Control List plus a catch-all category called EAR99 for items subject to only baseline export controls.
Here’s what actually determines which one applies to you, where the confusion tends to happen, and what’s genuinely at stake if you get it wrong.
Related Topic: What Is DFARS 252.204-7012? Requirements, Compliance & CMMC?
The core distinction is which list your product sits on, and that comes down to what the item actually is. ITAR covers items specifically designed, developed, or modified for military applications — the U.S. Munitions List is organized into categories covering things like firearms, military electronics, and spacecraft. EAR covers items with both commercial and military applications — dual-use items — plus purely commercial items that still warrant some export oversight.
The practical difference in compliance burden is real. ITAR registration and licensing is generally more restrictive, more expensive, and applies regardless of the item’s value or destination in many cases. EAR licensing requirements vary significantly based on the item’s Export Control Classification Number (ECCN), the destination country, and the end use — and a large share of items subject to EAR fall under EAR99, which requires no license for most destinations.
Related Topic: ITAR Compliance: Requirements & Cybersecurity
This isn’t a judgment call you make casually — it’s a formal classification process, and getting it wrong in either direction creates risk. A product built specifically for military application, or that incorporates ITAR-controlled technical data, is generally subject to ITAR regardless of whether a commercial equivalent exists. A product with genuine dual-use application — something with both civilian and potential military use — is more likely to fall under EAR, classified by an ECCN or defaulted to EAR99 if it doesn’t meet any specific control criteria.
We worked with a manufacturer recently that assumed none of their product line was ITAR-controlled, since most of their business was commercial. A registration review found that at least five of their products — parts built to specific military specifications for Navy and Army contracts — did in fact qualify. ITAR registration starts at a few thousand dollars and scales with contract volume, but the real cost isn’t the registration fee it’s the compliance program built around it afterward.
Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals
Yes, and this is a genuinely common point of confusion for manufacturers already thinking in CMMC terms. ITAR and Controlled Unclassified Information (CUI) are separate frameworks that frequently overlap but aren’t identical. Technical data controlled under ITAR is generally also treated as CUI, but not everything marked CUI is ITAR-controlled CUI is a broader category covering various types of sensitive government information, of which ITAR technical data is one subset. Treating “ITAR” and “CUI” as interchangeable labels is a mistake that shows up in real access-control and data-handling policies, not just in casual conversation.
Related Topic: CUI Marking Requirements: How to Label Controlled Unclassified Information Correctly
This isn’t a hypothetical risk. In one incident we responded to directly, ITAR-protected technical drawings were accidentally emailed to a non-U.S. person through an ordinary Microsoft 365 mailbox — the kind of mistake that happens when ITAR data gets treated the same as general business email rather than something requiring its own handling rules. After discovery, company reported within 60 days, identified recipients and nationalities, and purged data from systems and backups. The company’s ITAR Empowered Official led the response while legal counsel reviewed contract clauses governing vendor compliance obligations carefully.
Organizations must use FedRAMP-approved cloud services to store and transmit ITAR data across both sending and receiving endpoints. A file sitting in a compliant system on your end doesn’t protect you if it lands in an ordinary commercial inbox on the other end.
Related Topic: SOC 2 Requirements: What Your Business Needs to Know
Manufacturers must follow applicable export regulations when making, exporting, importing, or sharing controlled technical data with foreign persons. Foreign national employees accessing ITAR-controlled technical data domestically may trigger deemed-export rules, creating compliance obligations organizations must understand.
Related Topic: Why Every Business Needs a Disaster Recovery Plan
Enforcement has intensified significantly. BIS imposed approximately $324 million in penalties during 2025, marking an 18-fold increase from roughly $16 million in 2024. The Department of State enforces ITAR separately, imposing significant fines and potentially denying export privileges for compliance violations. Neither regulation treats “we didn’t realize this applied to us” as a meaningful defense.
Clarify whether ITAR, EAR, or both apply to your products and data before customer compliance questionnaires force decisions. Our team works with manufacturers in the DoD and aerospace supply chain navigating exactly this kind of classification and data-handling complexity, backed by managed IT services built for compliance-heavy environments. For more on the broader ITAR compliance picture, see our guide to ITAR requirements and cybersecurity.
👉 Schedule a free consultation with our team to talk through how ITAR and EAR actually apply to your business.
Related Topic: Full GDPR Consultant Guide for EU Businesses | Data Privacy Made Simple
EAR99 classifies items under EAR that lack ECCNs, but destinations, end users, or end uses may require licenses.
DDTC administers ITAR, while BIS administers EAR; companies handling both categories must follow each agency’s separate compliance requirements.
USML lists ITAR-controlled defense articles and services, while CCL classifies EAR-controlled dual-use items using Export Control Classification Numbers.
DDTC charges several thousand dollars for ITAR registration, while compliance programs, documentation, and access controls create larger costs.
ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) are two separate…
Operational technology (OT) security means protecting the systems that actually run your production floor…
AS9100 builds on ISO 9001, adding aerospace, space, and defense requirements for risk management…