What Is ITAR and Why It Matters

ITAR (International Traffic in Arms Regulations) is the U.S. State Department regulation that controls the export, access, and handling of defense articles, defense services, and related technical data. It is administered by the Directorate of Defense Trade Controls (DDTC) and codified at 22 CFR Subchapter M.

ITAR applies not only to physical exports but to digital access, electronic storage, cloud systems, and internal IT environments.

From a cybersecurity and IT standpoint, ITAR is about who can access controlled data, where it is stored, and how it is protected - even if nothing ever leaves the country.

What It Is

ITAR controls three things: defense articles (the physical items), defense services (assistance and training related to them), and technical data (the information required to develop, produce, or maintain them). All three are keyed to the United States Munitions List.

Two mechanics define how ITAR actually works in practice.

Registration is mandatory, not implied. 22 CFR Part 122 requires any person who engages in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, to register with DDTC. Section 122.1 is explicit: a manufacturer who does not engage in exporting must nevertheless register. If you machine parts on the Munitions List and never ship overseas, ITAR still applies - and registration is still owed.

Access is an export. Releasing technical data to a foreign person, even inside the United States, is a deemed export under 22 CFR 120.50. That is why IT system design and access control sit at the center of ITAR compliance.

Who It Applies To

ITAR applies to organizations that manufacture defense articles, develop or handle defense-related technical data, provide defense services, or support defense contractors and programs. That includes:

  • Defense contractors and subcontractors: the direct holders of controlled programs.
  • Manufacturers and engineering firms: including those who never export - registration under 22 CFR Part 122 applies regardless.
  • Aerospace and aviation companies: aircraft, spacecraft, and related components are heavily represented on the Munitions List.
  • Software and technology providers: source code and algorithms can be technical data.
  • IT, MSP, and cloud service providers: administering systems that hold ITAR data puts you in the compliance picture.
  • Research institutions and labs: defense-related R&D generates controlled technical data.

If your organization touches ITAR-controlled technical data, ITAR applies - even if you never ship a physical product.

What Information Is Regulated

ITAR protects defense articles, defense services, and technical data listed on the United States Munitions List (USML), codified at 22 CFR Part 121. (Not the "U.S. Munitions Import List" - that is a separate import-control list administered by ATF under 27 CFR Part 447, and it is not what ITAR export controls are keyed to.)

From an IT perspective, the most critical category is ITAR-controlled technical data:

  • Engineering drawings and schematics: the classic case.
  • CAD files and models: controlled the moment they describe a controlled article.
  • Source code: where it relates to defense articles.
  • Specifications and test data: including qualification and acceptance results.
  • Manufacturing processes and R&D materials: know-how counts.

This data typically lives in file servers, cloud storage, email, collaboration tools, and development environments - which is exactly where ITAR compliance is won or lost.

The encryption carve-out qualifies the cloud rule. Storing unclassified technical data abroad is not automatically an export. Under 22 CFR 120.54(a)(5), unclassified technical data secured with end-to-end encryption of adequate strength (at minimum 128-bit security), and not intentionally sent to or stored in proscribed countries, is not an export. Under 120.54(c), mere access to properly encrypted data does not constitute a release. Unencrypted or misconfigured cloud storage outside the U.S. remains a serious violation risk - the carve-out rewards disciplined encryption; it does not forgive sloppy configuration.

Relation to Other Frameworks

These are often confused, and the distinction is structural:

  • ITAR: export control - who may access controlled data and where it may go.
  • **DFARS:** contractual cybersecurity requirements for protecting CUI.
  • **CMMC:** the program verifying DFARS and NIST controls.

The defense chain - CUI Program, NIST SP 800-171, DFARS, CMMC - governs how covered data is protected. ITAR runs parallel to that chain and governs who may access it. Export-controlled technical data is itself a category of CUI, so many organizations are subject to all of these simultaneously and need coordinated compliance across IT, security, and operations.

IT Requirements

ITAR does not prescribe specific technologies. It requires strict control over access, storage, and transmission of technical data - which lands squarely on IT:

  • Access control and identity: access limited to U.S. persons (defined at 22 CFR 120.62) or foreign persons specifically authorized by the State Department through a license, exemption, or agreement such as a Technical Assistance Agreement. "U.S. persons only" is not the legal standard - authorization is. Role-based access, least privilege, and immediate revocation when authorization ends.
  • Data location and storage: ITAR data stored in compliant environments, protected from unauthorized foreign-person access, with cloud services evaluated against the 120.54 encryption carve-out rather than assumed compliant or assumed forbidden.
  • Network and system segmentation: ITAR data segregated from non-ITAR systems, lateral access prevented, and movement between environments restricted.
  • Encryption and secure transmission: end-to-end encryption at rest and in transit. Under 120.54 it is more than good practice - properly implemented, it changes the legal analysis of where data may travel.
  • Logging, monitoring, and auditability: track access to controlled data, detect unauthorized attempts, investigate potential violations, and produce evidence of controls.
  • Vendor and third-party risk: you remain responsible for vendors, MSPs, cloud providers, and consultants with system or data access. Third-party access is one of the most common ITAR failure points.

Why It Matters

ITAR violations carry severe civil and criminal exposure:

  • Civil penalties: 22 CFR 127.10 currently caps civil penalties at the greater of $1,271,078 per violation or twice the value of the transaction, adjusted annually for inflation. Multiple violations stack. /* ⚖️ COUNSEL - figure verified against 22 CFR 127.10 on 2026-07-24; re-verify at each annual inflation adjustment */
  • Criminal penalties: willful violations are prosecuted under 22 U.S.C. 2778(c) and can include substantial fines and imprisonment. /* FLAG: specific criminal amounts (commonly cited as up to $1M / 20 years per violation) NOT verified against uscode.house.gov this session - kept qualitative per fact-check; verify before adding figures */
  • Loss of export privileges and debarment: including three-year administrative debarment under 22 CFR 127.7.
  • Contract termination and reputational damage: primes and agencies exit fast.
  • Personal exposure for executives: enforcement can reach individuals, not just companies. /* ⚖️ COUNSEL */

Most violations are unintentional: misconfigured access controls, improper cloud usage, shared file systems, unvetted vendor access, and no visibility into who can reach the data.

How It Fits Into Cyber Risk Management

ITAR aligns with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and CMMC requirements.

Organizations with strong identity, access, and data governance controls are far better positioned to meet ITAR obligations. The disciplines overlap almost completely; ITAR just raises the stakes on getting them wrong.

How We Help With ITAR Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment traces where ITAR technical data lives, who can reach it, and whether your cloud and vendor configuration would survive a DDTC question.

How to Prepare

  1. 01Confirm registration and jurisdiction

    Determine what you make or handle that sits on the United States Munitions List (22 CFR Part 121), and confirm DDTC registration under 22 CFR Part 122. Manufacturers who never export are still required to register - this is the most commonly missed obligation.

  2. 02Identify ITAR-controlled data

    Document what data is ITAR-controlled, where it is stored, how it moves, and who can access it. You cannot control access to data you have not located.

  3. 03Restrict and validate access

    Limit access to U.S. persons or foreign persons operating under a DDTC authorization. Match permissions to job roles, review access regularly, and revoke it the day authorization ends.

  4. 04Secure storage and systems

    Implement segmented storage environments, secure cloud configurations evaluated against 22 CFR 120.54, end-to-end encryption, monitoring, and endpoint and email security.

  5. 05Review vendors and cloud providers

    Confirm vendors meet ITAR requirements, data residency and encryption are appropriate, access controls are enforced, and contracts reflect who is responsible for what.

  6. 06Document controls and processes

    Prepare access control policies, system diagrams, incident response procedures, and audit and investigation workflows. If DDTC asks, the answer needs to exist on paper.

Frequently Asked Questions

We never export anything. Does ITAR still apply to us?

Very possibly, twice over. First, 22 CFR 122.1 requires manufacturers of defense articles to register with DDTC even if they never export. Second, releasing technical data to a foreign person inside the U.S. is a deemed export under 22 CFR 120.50 - no shipment required. Domestic-only operations do not put you outside ITAR.

Do we have to register with DDTC?

If you engage in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, yes - 22 CFR Part 122 requires it. Registration is an obligation on its own, separate from licensing. Not exporting does not exempt a manufacturer.

Can we use cloud services for ITAR data?

Yes, carefully. Under 22 CFR 120.54(a)(5), unclassified technical data secured with compliant end-to-end encryption (at minimum 128-bit security) and not intentionally sent to or stored in proscribed countries is not an export - and mere access to properly encrypted data is not a release. The configuration has to actually meet the carve-out. Unencrypted data in foreign-hosted storage is a violation risk, not a gray area.

Can foreign employees ever access ITAR data?

Yes, with authorization. ITAR does not ban all foreign-person access - it requires a State Department license, exemption, or agreement such as a Technical Assistance Agreement before release. Unauthorized access is the violation. "U.S. persons only" is a common simplification, but authorization is the actual legal standard.

What is the difference between ITAR and DFARS or CMMC?

ITAR is export control: who may access defense technical data and where it may go. DFARS is contract law: how covered defense information must be protected. CMMC verifies the DFARS-required controls. Many defense manufacturers are subject to all three at once, and the same access-control work serves each.

What are the penalties for an ITAR violation?

Civil penalties currently reach $1,271,078 per violation or twice the transaction value, whichever is greater (22 CFR 127.10, adjusted annually). Willful violations can also bring criminal prosecution, plus loss of export privileges and debarment. Most enforcement starts with unintentional failures - misconfigured access, not espionage.

What does ITAR compliance cost?

It depends on how much controlled data you hold and how contained it is. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. Segmenting ITAR data early usually costs far less than retrofitting controls across everything.

Where do we start?

Start with two questions: are we registered with DDTC, and where does our controlled technical data actually live? Most organizations can answer neither precisely. Our Cyber Risk & Compliance Gap Assessment maps the data, the access, and the gaps before a violation forces the exercise.

Official source

Official source: State Department Directorate of Defense Trade Controls

Secondary source: eCFR, 22 CFR Subchapter M

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25