What It Is

ITAR controls three things: defense articles (the physical items), defense services (assistance and training related to them), and technical data (the information required to develop, produce, or maintain them). All three are keyed to the United States Munitions List.

Two mechanics define how ITAR actually works in practice.

Registration is mandatory, not implied. 22 CFR Part 122 requires any person who engages in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, to register with DDTC. Section 122.1 is explicit: a manufacturer who does not engage in exporting must nevertheless register. If you machine parts on the Munitions List and never ship overseas, ITAR still applies - and registration is still owed.

Access is an export. Releasing technical data to a foreign person, even inside the United States, is a deemed export under 22 CFR 120.50. That is why IT system design and access control sit at the center of ITAR compliance.

What Information Is Regulated

ITAR protects defense articles, defense services, and technical data listed on the United States Munitions List (USML), codified at 22 CFR Part 121. (Not the "U.S. Munitions Import List" - that is a separate import-control list administered by ATF under 27 CFR Part 447, and it is not what ITAR export controls are keyed to.)

From an IT perspective, the most critical category is ITAR-controlled technical data:

  • Engineering drawings and schematics: the classic case.
  • CAD files and models: controlled the moment they describe a controlled article.
  • Source code: where it relates to defense articles.
  • Specifications and test data: including qualification and acceptance results.
  • Manufacturing processes and R&D materials: know-how counts.

This data typically lives in file servers, cloud storage, email, collaboration tools, and development environments - which is exactly where ITAR compliance is won or lost.

The encryption carve-out qualifies the cloud rule. Storing unclassified technical data abroad is not automatically an export. Under 22 CFR 120.54(a)(5), unclassified technical data secured with end-to-end encryption of adequate strength (at minimum 128-bit security), and not intentionally sent to or stored in proscribed countries, is not an export. Under 120.54(c), mere access to properly encrypted data does not constitute a release. Unencrypted or misconfigured cloud storage outside the U.S. remains a serious violation risk - the carve-out rewards disciplined encryption; it does not forgive sloppy configuration.

IT Requirements

ITAR does not prescribe specific technologies. It requires strict control over access, storage, and transmission of technical data - which lands squarely on IT:

  • Access control and identity: access limited to U.S. persons (defined at 22 CFR 120.62) or foreign persons specifically authorized by the State Department through a license, exemption, or agreement such as a Technical Assistance Agreement. "U.S. persons only" is not the legal standard - authorization is. Role-based access, least privilege, and immediate revocation when authorization ends.
  • Data location and storage: ITAR data stored in compliant environments, protected from unauthorized foreign-person access, with cloud services evaluated against the 120.54 encryption carve-out rather than assumed compliant or assumed forbidden.
  • Network and system segmentation: ITAR data segregated from non-ITAR systems, lateral access prevented, and movement between environments restricted.
  • Encryption and secure transmission: end-to-end encryption at rest and in transit. Under 120.54 it is more than good practice - properly implemented, it changes the legal analysis of where data may travel.
  • Logging, monitoring, and auditability: track access to controlled data, detect unauthorized attempts, investigate potential violations, and produce evidence of controls.
  • Vendor and third-party risk: you remain responsible for vendors, MSPs, cloud providers, and consultants with system or data access. Third-party access is one of the most common ITAR failure points.

How It Fits Into Cyber Risk Management

ITAR aligns with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and CMMC requirements.

Organizations with strong identity, access, and data governance controls are far better positioned to meet ITAR obligations. The disciplines overlap almost completely; ITAR just raises the stakes on getting them wrong.

How We Help With ITAR Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment traces where ITAR technical data lives, who can reach it, and whether your cloud and vendor configuration would survive a DDTC question.

How to Prepare

  1. Confirm registration and jurisdiction

    Determine what you make or handle that sits on the United States Munitions List (22 CFR Part 121), and confirm DDTC registration under 22 CFR Part 122. Manufacturers who never export are still required to register - this is the most commonly missed obligation.

  2. Identify ITAR-controlled data

    Document what data is ITAR-controlled, where it is stored, how it moves, and who can access it. You cannot control access to data you have not located.

  3. Restrict and validate access

    Limit access to U.S. persons or foreign persons operating under a DDTC authorization. Match permissions to job roles, review access regularly, and revoke it the day authorization ends.

  4. Secure storage and systems

    Implement segmented storage environments, secure cloud configurations evaluated against 22 CFR 120.54, end-to-end encryption, monitoring, and endpoint and email security.

  5. Review vendors and cloud providers

    Confirm vendors meet ITAR requirements, data residency and encryption are appropriate, access controls are enforced, and contracts reflect who is responsible for what.

  6. Document controls and processes

    Prepare access control policies, system diagrams, incident response procedures, and audit and investigation workflows. If DDTC asks, the answer needs to exist on paper.

Official source

Official source: State Department Directorate of Defense Trade Controls

Secondary source: eCFR, 22 CFR Subchapter M

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25