ITAR Compliance and Technical Data Controls
In 2023, a mid-size aerospace manufacturer paid $20 million in civil penalties after the State Department discovered its Romanian subsidiary had been accessing USML-controlled CAD files through a shared engineering drive for three years. Nobody exported anything physically — the files never left the server — but a non-U.S. person clicked "open," and that constituted a deemed export. The company's IT team had no idea citizenship-based access controls were even a requirement.
That case is not exceptional. The Directorate of Defense Trade Controls (DDTC) has settled enforcement actions exceeding $100 million in the past decade, and the common thread is not malicious intent — it is ignorance of what constitutes an "export" under ITAR.
Why Now: The Cloud Makes Deemed Exports Trivial
The International Traffic in Arms Regulations (ITAR) were written when technical data lived in locked filing cabinets. Today, it lives in Confluence, SharePoint, and S3 buckets accessible by globally distributed engineering teams. Every cloud collaboration tool that does not enforce citizenship-based access is a potential ITAR violation in progress.
Three forces are converging to make ITAR enforcement more aggressive:
- DoD supply chain scrutiny is rising. CMMC assessors are now cross-referencing ITAR registration with CUI boundary documentation. If you claim a CUI boundary but your DDTC registration is lapsed, expect findings.
- Cloud-native development defaults to global access. Default IAM policies in major cloud providers do not distinguish between U.S. persons and foreign nationals. You must opt in to ITAR-compliant regions explicitly.
- Voluntary disclosures are increasing. Companies discovering violations during CMMC prep are self-reporting at record rates — which means DDTC visibility into the defense industrial base has never been broader.
Who Actually Needs ITAR Compliance
ITAR applies to any organization that manufactures, exports, brokers, or possesses defense articles or technical data listed on the United States Munitions List (USML). That includes:
- Prime contractors manufacturing USML items
- Subcontractors receiving technical data packages for USML components
- Cloud service providers storing or processing ITAR-controlled data
- Engineering firms with access to USML-related designs, test data, or manufacturing processes
- Universities conducting USML-related research outside fundamental research exclusions
The misconception that kills companies: "We do not export anything, so ITAR does not apply." ITAR applies the moment you possess USML-related technical data — even if it never leaves your building. One foreign national employee opening one controlled file is a violation.
DDTC Registration
Organizations engaged in manufacturing or exporting defense articles must register with DDTC before applying for any export licenses or agreements.
The process:
- Complete form DS-2032 (Statement of Registration)
- Pay the registration fee ($2,250/year as of 2026)
- Disclose organizational structure, officers, and any debarments, indictments, or convictions
- Renew annually — lapsed registration does not relieve you of ITAR obligations
Registration does not grant permission to export. It establishes your organization as a known participant in the defense trade. Think of it as the prerequisite for everything else.
Defining and Controlling Technical Data
What Qualifies as ITAR-Controlled Technical Data
ITAR-controlled technical data includes blueprints, drawings, design documentation, manufacturing processes, software source code directly related to USML items, test results, engineering analyses, and training materials specific to USML articles.
Technical data does NOT include information in the public domain, general scientific or engineering principles, basic marketing materials, or telemetry data (with specific exceptions).
The U.S. Person Requirement
Only U.S. persons may access ITAR-controlled technical data without an export license. A "U.S. person" is a U.S. citizen, a U.S. permanent resident (green card holder), or a U.S. entity not foreign-owned, controlled, or influenced.
This has operational implications that most organizations underestimate:
- Hiring: Foreign national employees cannot access ITAR data without a license — even if they have a security clearance from another Five Eyes nation
- Cloud infrastructure: ITAR data must reside on infrastructure administered exclusively by U.S. persons, in U.S. data centers
- Collaboration tools: Sharing a Slack channel, a Git repo, or a Teams folder with a foreign person who can see ITAR data is a violation
- Travel: A laptop crossing an international border with ITAR data on the hard drive constitutes an export
Physical and Digital Controls
| Control Area | Requirement |
|---|---|
| Storage | Access-controlled areas (physical and digital), U.S. persons only |
| Network | Segmented networks accessible only to authorized U.S. persons |
| Never transmit ITAR data via unencrypted email; even encrypted email to a foreign person requires a license | |
| Cloud | ITAR-compliant regions only (U.S. person administration, U.S. data residency) |
| Devices | Encrypted laptops and removable media with access logging |
| Destruction | Approved sanitization methods when data is no longer needed |
| Marking | All ITAR-controlled documents labeled with distribution statements |
ITAR and CMMC: The Overlap That Trips People Up
Here is the contrarian opinion most consultants will not tell you: being fully CMMC Level 2 compliant does not make you ITAR compliant, and the gap is not small.
ITAR-controlled technical data is a category of CUI, so organizations handling it for DoD contracts must comply with both ITAR (State Department export control) and DFARS 252.204-7012 / CMMC (DoD cybersecurity). The requirements overlap significantly — encryption, access control, audit logging — but they diverge on one fundamental axis: ITAR controls access by nationality, while NIST 800-171 / CMMC controls access by authorization level.
You can have a perfectly segmented CUI enclave with full MFA, FIPS-validated encryption, and continuous monitoring — and still violate ITAR if one dual-national engineer on the team has access without a license. CMMC assessors are not checking citizenship status. DDTC is.
Common ITAR Violations
Deemed Exports
The most frequent violation. A foreign national employee accesses ITAR data without a license. The data never leaves the building, but a deemed export occurred. Organizations must implement access controls that gate on citizenship status — not just role or clearance level.
Cloud Provider Assumptions
Not all cloud services are ITAR-compliant by default. Major providers offer ITAR-compliant regions (AWS GovCloud, Azure Government), but the default commercial offering does not qualify. If your ITAR data is in a standard commercial tenant, you are in violation regardless of encryption state.
Email and Collaboration Tools
Emailing ITAR-controlled technical data to a foreign person is an unlicensed export — full stop. But so is sending ITAR data via a service that routes through foreign servers, or granting access to a collaboration workspace where a foreign national can see the data. The intent does not matter; the access does.
Failure to Mark
Unmarked ITAR data is mishandled ITAR data. Distribution statements and handling instructions must be applied consistently across all controlled documents. The marking requirement is how downstream recipients know to apply controls — without it, violations cascade through the supply chain.
Voluntary Disclosure: The Smart Path When You Find a Problem
Most ITAR violations are discovered internally — typically during CMMC preparation, cloud migration projects, or M&A due diligence. When you discover a potential violation, you face a choice: disclose to DDTC proactively or wait and hope nobody notices.
The data overwhelmingly favors disclosure. DDTC published guidance stating that voluntary disclosures are treated as mitigating factors in penalty determination. Organizations that self-disclose, remediate, and implement compliance programs consistently receive substantially lower penalties than those caught by enforcement actions. More importantly, voluntary disclosure dramatically reduces the likelihood of debarment — the penalty that ends companies.
The disclosure process:
- Lock down the violation immediately — revoke access, preserve evidence
- Conduct an internal investigation — determine scope, duration, and data exposed
- File initial notification with DDTC within 60 days of discovery
- Submit full disclosure with investigation results and remediation plan
- Implement corrective actions — the remediation plan becomes your compliance roadmap
Waiting is not a strategy. DCMA audits, CMMC assessments, whistleblower complaints, and foreign government notifications all surface violations independently. Being caught is categorically worse than self-reporting.
Penalties
ITAR violations carry severe consequences:
- Civil penalties: Over $1 million per violation as inflation-adjusted (statutory base $500,000; per individual transfer, not per incident)
- Criminal penalties: Up to $1 million and 20 years imprisonment per willful violation
- Debarment: Permanent prohibition from defense trade
- Consent agreements: Multi-year monitored compliance programs with independent oversight
These are not theoretical. RTX (Raytheon) entered a $200 million consent agreement in 2024. Boeing agreed to a $51 million settlement in 2024. L3Harris paid $13 million in 2019. Smaller companies have been debarred entirely — their contracts, their workforce, and their revenue gone permanently.
Key Takeaways
- ITAR applies the moment you possess USML-related technical data — physical export is not required
- "Deemed export" means any access by a non-U.S. person, even on domestic soil
- CMMC compliance does not equal ITAR compliance — nationality-based access is the gap
- Default cloud configurations are not ITAR-compliant; you must opt into GovCloud or equivalent
- Civil penalties can exceed $1M per violation and scale to debarment
- Self-disclosure to DDTC before they find you dramatically reduces penalty exposure
Frequently Asked Questions
Does ITAR apply if we only perform domestic work and never ship anything overseas?
Yes. ITAR governs access to technical data, not just physical shipment. If you possess USML-related technical data and a non-U.S. person on your team, in your cloud environment, or at a partner organization can access it, you are subject to ITAR regardless of whether anything crosses a border.
How does ITAR interact with CMMC assessments?
CMMC assessors evaluate your cybersecurity controls against NIST 800-171. They do not assess ITAR compliance directly. However, assessors will note if your CUI boundary documentation is inconsistent with your DDTC registration or if access controls do not account for export-controlled data categories. A CMMC certification does not satisfy ITAR obligations.
What cloud providers are ITAR-compliant?
AWS GovCloud, Microsoft Azure Government, and Google Cloud Assured Workloads offer ITAR-compliant regions. Standard commercial tenants — even with encryption enabled — do not meet ITAR requirements because they cannot guarantee U.S.-person-only administration. You must explicitly provision into the compliant region and verify the access controls.
Can foreign national employees ever access ITAR data?
Yes, with an approved Technical Assistance Agreement (TAA) or Manufacturing License Agreement (MLA) from DDTC. The license application process typically takes 30-60 days and must specify the individual, the data, and the purpose. Blanket approvals are not available for ITAR.
What should we do if we discover a potential ITAR violation?
File a voluntary disclosure with DDTC within 60 days of discovery. Lock down the violation immediately (revoke access, preserve evidence), conduct an internal investigation to determine scope, and submit a full disclosure with remediation plan. Self-reporting consistently results in substantially lower penalties compared to enforcement-discovered violations and reduces debarment risk.
How Advisedly Helps
Advisedly tracks ITAR technical data controls alongside your broader compliance obligations across 500+ frameworks. The platform maps ITAR requirements to your information systems, enforces citizenship-based access policies within your CUI boundary documentation, and maintains audit trails for technical data access events. For organizations managing ITAR alongside CMMC, FedRAMP, and other frameworks, the unified compliance view ensures export control requirements are addressed without duplicating work across standards — the evidence collection module captures access control configurations, data handling records, and marking compliance evidence that DDTC expects during reviews. Contact begin@advisedly.ai
<!-- LI hook: One click by one foreign engineer cost $20M in ITAR fines -->