- ITAR compliance refers to an organization following U.S. State Department rules that control the export, transfer, and disclosure of defense articles, defense services, and related technical data.
- Access to ITAR-controlled technical data is restricted to U.S. persons, a legal category broader than U.S. citizens, and is distinct from a personnel security clearance, which is a separate government determination.
- Civil penalties can reach $1,271,078 per violation or twice the transaction value, whichever is greater; criminal penalties can reach $1 million and 20 years imprisonment per violation; and a conviction triggers a mandatory three-year statutory debarment.
- ITAR-controlled technical data created or held for the government is also Controlled Unclassified Information (CUI) in the Export Control category, so both frameworks' requirements apply at once.
- Some parts and components sit at the boundary between ITAR and the Commerce Department's dual-use export regime, and getting that jurisdiction call wrong is one of the most common ITAR compliance mistakes.
What Is ITAR Compliance?
ITAR compliance is the practice of following the International Traffic in Arms Regulations (ITAR), a U.S. Department of State regulation administered by the Directorate of Defense Trade Controls (DDTC), which controls the manufacture, export, temporary import, and transfer of defense articles, defense services, and related technical data.
Technical data, in ITAR terms, means the information, such as blueprints, source code, and specifications, needed to design, produce, or use a defense article. The rule exists to keep sensitive military and defense technology out of the hands of unauthorized foreign governments and individuals.
ITAR traces back to the Arms Export Control Act (AECA) of 1976, part of a broader Cold War era effort to control the flow of military technology out of the United States. Any organization that manufactures, exports, brokers, or handles technical data tied to a defense article falls under its scope, from prime contractors down to small parts suppliers and engineering firms. Because ITAR applies to information as well as physical hardware, software companies, cloud providers, universities, and any business that touches a defense-related engineering drawing, source code file, or technical specification can fall under its scope.
How ITAR Compliance Works
ITAR compliance rests on a small number of mechanisms that apply together, not in isolation.
- Classification against the U.S. Munitions List (USML): Determine whether products, services, or technical data fall under a category listed at 22 CFR part 121.
- Registration with the DDTC: Under 22 CFR 122.1, any organization engaged in manufacturing, exporting, or temporarily importing a defense article, or furnishing a defense service, must register annually and pay a fee, regardless of whether it currently holds an export license.
- Restriction to U.S. persons: Access to controlled technical data must be limited to U.S. persons unless a specific license or exemption authorizes disclosure to a foreign person.
- Licensing of exports and transfers: Sending a controlled item or piece of technical data outside the United States, or disclosing it to a foreign person anywhere, requires a State Department license or an applicable exemption.
- Recordkeeping and audit: Organizations must document registration, licensing, and technical data handling, and retain those records for government review.
Supply chain liability extends this further: a company can still be found in violation if a downstream buyer, not the company itself, makes the unauthorized transfer.
What ITAR Covers: The U.S. Munitions List
The USML, codified at 22 CFR 121.1, organizes controlled defense articles, services, and technical data into 21 categories, running from Category I through Category XXI.
| Category group | Representative examples |
|---|---|
| Weapons and ammunition | Firearms, artillery, ordnance, and related components |
| Vehicles and vessels | Military ground vehicles, armored equipment, and naval vessels |
| Aircraft and spacecraft | Military aircraft, spacecraft, satellites, and associated systems |
| Electronics and sensors | Fire control, night vision, and military communications equipment |
| Technical data and services | Engineering drawings, source code, and technical documentation tied to a listed article, plus training or technical assistance |
A defense article is a physical commodity plus its technical data. A defense service is the furnishing of assistance or training to a foreign person regarding a defense article. Both require the same export license.
Is ITAR-Controlled Technical Data Considered CUI?
ITAR-controlled technical data is Controlled Unclassified Information (CUI) when it is created or possessed by, or on behalf of, the U.S. government, most commonly under a Department of Defense contract. The National Archives and Records Administration (NARA), which administers the CUI program, lists export-controlled information, including ITAR-regulated technical data, in its CUI Registry under the Export Control category, marked CUI//SP-EXPT.
The two frameworks answer different questions. CUI governs how information must be labeled and safeguarded inside federal information systems. ITAR governs who is legally permitted to view or receive the information, regardless of marking. A single engineering drawing produced under a defense contract can carry a CUI marking for handling purposes while remaining separately subject to ITAR's U.S. person access restriction, and satisfying one framework's requirements does not automatically satisfy the other's.
Who Counts as a "U.S. Person" Under ITAR?
A U.S. person under ITAR is a legal category, not a security clearance or job title, and it is broader than "U.S. citizen." The definition covers U.S. citizens, certain lawful permanent residents, asylees and refugees under specific immigration provisions, and entities incorporated to do business in the United States. Anyone who does not meet this definition, including a foreign national physically present in the United States, is a foreign person under the regulation.
ITAR citizenship requirements are often confused with a security clearance, but the two are unrelated. A clearance is a separate government determination for access to classified information and is not required to view unclassified ITAR-controlled technical data. An employee can be fully authorized as a U.S. person without holding any clearance, and a cleared employee who does not meet the U.S. person definition is still barred from unauthorized access. This confusion commonly leads organizations to under-restrict access on the mistaken assumption that a background check alone qualifies someone.
ITAR vs. EAR: Understanding the Difference
ITAR is frequently confused with the Export Administration Regulations (EAR), administered by the Commerce Department's Bureau of Industry and Security (BIS). The two regimes cover different items, sit under different agencies, and carry different levels of restriction.
| Aspect | ITAR | EAR |
|---|---|---|
| Administering agency | U.S. Department of State (DDTC) | U.S. Department of Commerce (BIS) |
| Controlled items | Defense articles, defense services, and technical data on the USML | Commercial and dual-use items on the Commerce Control List (CCL) |
| Access restriction | Limited to U.S. persons unless licensed | Varies by item, destination, and end use |
| Typical severity | Generally the more restrictive regime | Often less restrictive, though still enforceable |
Some items sit at the boundary between the two regimes and require a dual-jurisdiction analysis. Under 22 CFR 120.41, a part or component is "specially designed" for a defense article, and therefore ITAR-controlled, if it results from development work aimed at USML performance characteristics, with release provisions carving out items like fasteners or parts that share the same form, fit, and function as a commercial equivalent. Items formerly on the USML but since moved to Commerce control appear on the CCL as 500 series or 600 series Export Control Classification Numbers rather than being dropped from control entirely, as happened with commercial satellites between 1999 and 2014. Because classification can turn on design history as much as current function, organizations integrating parts from multiple suppliers into a defense-related system can submit a Commodity Jurisdiction request to the DDTC for a binding determination rather than assume EAR coverage by default.
Why ITAR Compliance Matters for Data Security
ITAR turns technical data protection into a direct legal obligation, not just a good security practice.
- Civil penalties can reach $1,271,078 per violation, or twice the value of the underlying transaction, whichever is greater, under 22 CFR 127.10.
- Criminal penalties for willful violations can include fines up to $1 million and imprisonment of up to 20 years per violation, under 22 CFR 127.3 and 22 U.S.C. 2778(c).
- Statutory debarment bars a convicted party from defense trade for a mandatory three-year period, under 22 CFR 127.7.
- Loss of government contracting eligibility and reputational damage can follow, independent of any fine.
These are not hypothetical risks, and that risk now extends to newer channels: pasting a controlled drawing into a popular AI assistant can create the same disclosure risk as emailing it to an unauthorized recipient.
Common ITAR Compliance Challenges
- Locating controlled data at scale
Technical data is often scattered across file servers, collaboration platforms, and cloud storage, with no consistent tagging. - Misunderstanding who counts as a U.S. person
Guidance that oversimplifies this to "U.S. citizens only" misses lawful permanent residents, asylees, and U.S. incorporated entities. - Assuming general-purpose file sharing is sufficient
Most collaboration tools default to easily generated sharing links; without a control that restricts a specific file to verified U.S. persons, an overshared link can itself be an unauthorized export. - Treating "ITAR-compliant enclave" as a product label rather than an outcome
The requirement is always the same, data and support personnel restricted to screened U.S. persons, and a cloud tier on shared, unscreened infrastructure does not meet it regardless of marketing name. - Confusing "deemed export" with ITAR terminology
That term comes from the Commerce Department's regime; the underlying risk it describes, unauthorized release to a foreign person physically present in the United States, is still real under ITAR either way.
ITAR Restricted Countries
Restricted destinations are identified under 22 CFR 126.1, which prohibits exports to countries or parties subject to United Nations Security Council sanctions covering defense articles, to countries the Secretary of State has designated a state sponsor of terrorism, and to individuals or entities separately subject to UN sanctions regardless of location. Because this list derives from active sanctions determinations rather than a single fixed roster, organizations should treat 22 CFR 126.1 and current DDTC guidance as the source of record rather than a prior year's training deck.
Building an ITAR Compliance Program: A Checklist
- Determine applicability against the USML.
- Register with the DDTC under 22 CFR 122.1 and renew annually; registration and facility-level access controls (physical and digital) apply together, since wherever technical data is stored or displayed, access must be limited to authorized U.S. persons.
- Discover and classify technical data across file servers, cloud storage, and collaboration tools, noting where it also qualifies as CUI.
- Restrict access to U.S. persons, independent of any security clearance, with least-privilege controls.
- Choose an appropriate technical environment. Since March 2020, unclassified technical data secured with end-to-end encryption meeting FIPS 140-2 (or comparable 128-bit AES strength) and not sent to a 22 CFR 126.1 country is not considered an export under the ITAR Encryption Rule (22 CFR 120.54), though access to the decrypted data by a foreign person remains one.
- License exports and transfers, checking the destination against 22 CFR 126.1.
- Train employees to recognize controlled technical data and required authorization.
- Screen partners and monitor activity for unauthorized disclosure.
- Maintain records and disclose voluntarily; voluntary disclosure can mitigate penalties.
How Cyberhaven Addresses ITAR Compliance
Cyberhaven addresses ITAR compliance through a unified data security platform that combines DSPM, DLP, and AI Security to keep controlled technical data visible, classified, and restricted to authorized users. The platform continuously discovers where technical data lives across cloud storage, endpoints, and SaaS applications, and tracks it as it moves, so a controlled drawing stays classified even after it is copied, renamed, or shared through a file-sharing link.
Data Lineage traces technical data from its point of origin through every copy and transformation, helping answer the question every ITAR audit eventually asks: where did this file go, and who touched it?
Frequently Asked Questions
What Does Being ITAR Compliant Mean?
Being ITAR compliant means an organization has registered where required, classified its controlled technical data, restricted access to U.S. persons, obtained licenses for exports or foreign disclosure, and maintains records of that activity. No single certificate confirms this status; it is an ongoing operational responsibility.
What Are ITAR Requirements for Employees?
Employees who may access ITAR-controlled technical data must generally qualify as U.S. persons, a status separate from any security clearance, complete training on what counts as controlled information, and follow procedures that prevent controlled data from reaching unauthorized foreign persons, including foreign national coworkers physically present in the United States.
Is ITAR Access Restricted to U.S. Citizens Only?
Not exactly. ITAR restricts access to U.S. persons, a category broader than citizenship that also includes certain lawful permanent residents, asylees, and organizations incorporated to do business in the United States. Anyone who does not meet this definition is a foreign person under the regulation.
What Is an ITAR-Compliant Enclave?
An ITAR-compliant enclave is a technical environment where access to controlled technical data is restricted to screened U.S. persons at both the data layer and the support layer. There is no certified enclave standard; an environment qualifies by meeting the same access, encryption, and destination restrictions found in 22 CFR 120.54 and 126.1, not by carrying a particular vendor label.
Does ITAR Require Special File-Sharing Tools?
ITAR does not name specific file-sharing products, but it does require that any tool sharing controlled technical data enforce the U.S. person restriction on that specific file, regardless of how a link is generated or forwarded. A general-purpose tool can be used only if configured, or paired with a control, to block access by anyone who does not qualify as a U.S. person.
Is There an Official ITAR Compliance Certification?
No. Neither the State Department nor any cloud provider or software vendor issues an ITAR compliance certification. Cloud environments can support compliance through features and contractual commitments, but the organization itself remains responsible for meeting and demonstrating ITAR requirements.



.avif)
.avif)
