Compliance 10 min read

ITAR Compliance: What Defense Contractors Need to Know

J

Jared Clark

July 20, 2026

If your company touches defense hardware, technical data, or defense services — even as a domestic supplier — ITAR may already apply to you. The International Traffic in Arms Regulations govern not just physical exports but the sharing of controlled information with foreign nationals on US soil. Most companies I work with discover their ITAR exposure not through a regulatory audit but through a close call: a foreign-national engineer reviewing a controlled drawing, a proposal sent to a Canadian subsidiary without a license, or a shared cloud environment that nobody had mapped against the technical data rules.

Understanding what ITAR requires — and where companies consistently fall short — is the work Certify Consulting does every day.

What ITAR Is and Why It Exists

ITAR, codified at 22 CFR Parts 120–130, implements the Arms Export Control Act (AECA). Its purpose is to protect US national security by controlling the export of defense articles, technical data, and defense services listed on the United States Munitions List (USML). The Directorate of Defense Trade Controls (DDTC), housed within the State Department, administers and enforces the regulations.

The regulation reaches further than most people expect. Any company that manufactures, exports, imports, brokers, or furnishes defense services related to USML items must register with DDTC — regardless of whether they ever execute an actual export. Registration is mandatory for manufacturers even if all sales are domestic.

The USML contains 21 categories, from Category I (Firearms) through Category XXI (Miscellaneous Articles). If your product, component, or technical data falls within any of those categories, you are operating in ITAR territory. Common areas of surprise include night vision optics (Category XII), GPS and navigation equipment (Category XI), and certain unmanned aerial systems (Category VIII). The first question every new ITAR engagement starts with is product classification — and the answer shapes everything that comes after.

ITAR vs. EAR: Understanding the Jurisdictional Split

One of the most common points of confusion I see — and one that creates real compliance risk — is the boundary between ITAR and the Export Administration Regulations (EAR), which govern dual-use items. The two frameworks operate under different federal agencies, different control lists, and different penalty structures.

Feature ITAR (22 CFR 120–130) EAR (15 CFR 730–774)
Governing authority State Department / DDTC Commerce Department / BIS
Control list USML (21 categories) Commerce Control List (CCL)
Primary focus Defense articles & services Dual-use items, commercial technology
Registration required Yes — all USML manufacturers No general registration requirement
License authority DDTC (State) BIS (Commerce)
Default for unlisted items No — item must appear on USML Yes — catch-all EAR99 classification
Civil penalties Up to $1.3 million per violation Up to $353,534 per violation
Criminal penalties Up to $1M + 20 years imprisonment Up to $1M + 20 years imprisonment

In practice, the jurisdictional question — is this item ITAR or EAR? — is itself a compliance step you cannot skip. You cannot self-classify a product as EAR without first confirming it does not fall under the USML. Where jurisdiction is genuinely uncertain, a commodity jurisdiction (CJ) request to DDTC is the formal mechanism for resolving it. Many companies skip this step and assume EAR, which is a mistake I've seen create significant enforcement exposure.

The Registration Requirement Most Small Contractors Miss

Any US person who manufactures or exports defense articles, or furnishes defense services related to USML items, must register with DDTC. "Manufacture" is defined broadly — it includes production, fabrication, modification, and in some cases the development of controlled technical data.

Registration is annual and currently costs $2,250 for a single-tier one-year registration. The DS-2032 form must be complete and accurate; incomplete applications are returned and the clock resets. What most small contractors fail to understand is that registration is triggered by the activity of manufacturing, not by an actual export. The DDTC currently maintains registrations for approximately 11,000 entities, and many more companies arguably qualify but are unregistered — which itself constitutes a violation.

ITAR enforcement data from the State Department consistently identifies registration failures as one of the most common predicate violations in civil penalty cases. If you're making something that appears on the USML and you haven't registered, that's the first thing to fix.

What Counts as Technical Data Under ITAR

This is the area where I spend the most time with clients, because the definition is genuinely broad. Under 22 CFR 120.33, technical data includes information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles, as well as classified defense information and certain invention secrecy materials.

What surprises most clients is that technical data does not have to be a formal document. A conversation between a US engineer and a foreign national that transmits controlled information is a "deemed export" under ITAR — legally equivalent to physically sending that data overseas. Cloud platforms accessible from foreign IP addresses, collaboration tools used by international teams, and even international travel with a company laptop loaded with controlled data all create deemed export exposure.

Jared Clark, Principal Consultant at Certify Consulting, identifies technical data control as the single highest-risk area for mid-sized defense subcontractors: "Most ITAR violations I see aren't intentional — they come from companies that genuinely didn't know their engineering drawings or test procedures fell under ITAR. By the time we map the technical data environment, we almost always find at least one uncontrolled pathway." That pathway — whether it's a foreign-national contractor, a shared Dropbox folder, or a legacy FTP server — is where enforcement exposure lives.

The Five Elements of a Defensible ITAR Compliance Program

Registration alone does not constitute ITAR compliance. Companies with ITAR exposure need a documented compliance program. Based on Certify Consulting's work with defense manufacturers and subcontractors, a defensible program includes five elements.

Product and Technology Classification. Every product line, component, and category of technical data should be classified against the current USML text. This is not a one-time exercise — it should repeat whenever a product is modified, a new product is introduced, or regulatory updates revise the USML. Document the classification rationale in writing so it survives scrutiny.

Export License Management. For any transfer to a foreign person — whether an export, re-export, or deemed export — companies need a written process for determining whether a license is required and obtaining one before the transfer occurs. The DDTC receives approximately 35,000 license applications per year and reviews the majority within 30 days for routine transactions. License turnaround time should be built into project timelines rather than treated as an afterthought.

Foreign National Screening. Employees, contractors, visitors, and anyone with access to controlled technical data need to be screened before access is granted — not after. ITAR defines foreign nationals by citizenship and permanent residency status, not by where someone was born or how long they've lived in the US. A written foreign-national access policy is not optional; it's a core program document.

Employee Training. Every employee who could conceivably touch controlled articles or data should receive role-appropriate training at hire and annually thereafter. Training records should be documented, and the content should reflect the actual risk profile of each role — engineers, purchasing staff, IT administrators, and international business development personnel all face different exposures and need different instruction.

Recordkeeping and Internal Audit. ITAR requires that records of exports, licenses, and related transactions be maintained for five years. A compliance program without an internal audit function will not hold up under DDTC scrutiny. Internal audits should test whether written procedures are actually being followed — because the gap between policy and practice is exactly where enforcement actions originate.

ITAR Penalties and the Cost of Getting It Wrong

ITAR enforcement has real teeth. Civil penalties under Section 38(e) of the AECA can reach $1.3 million per violation. Criminal penalties can reach $1 million per violation and 20 years in federal prison. The DDTC also has authority to debar companies from ITAR-controlled exports, which for a defense contractor can be an existential business consequence — not a regulatory fine you absorb and move past.

Beyond the headline numbers, ITAR enforcement creates cascading costs: legal fees, remediation expenses, the administrative burden of a monitored compliance agreement, and the reputational damage of a public penalty order. Notable ITAR enforcement actions in recent years have involved companies with revenues in the hundreds of millions — companies with dedicated compliance departments — which reinforces that organizational scale does not substitute for a deliberately designed program.

The voluntary disclosure process under 22 CFR 127.12 is worth knowing. If a company discovers a potential violation and self-discloses to DDTC before the government discovers it independently, DDTC generally treats the disclosure as a significant mitigating factor in penalty calculations. I always recommend that clients with a potential ITAR issue engage legal counsel before taking any action — including disclosure. The decision to voluntarily disclose requires careful legal analysis, not a reflexive assumption that faster is always better.

ITAR Brokering: The Rules That Catch Companies Off Guard

One dimension of ITAR that frequently surprises non-traditional defense suppliers is the brokering framework under 22 CFR Part 129. Any person who acts as a broker — meaning they arrange, finance, or otherwise facilitate the sale, purchase, transfer, loan, lease, import, export, or transportation of defense articles or defense services — must register with DDTC and in many cases obtain advance approval before executing a transaction.

"Brokering" is defined broadly enough to capture market research firms, trade advisors, and logistics providers who facilitate USML transactions without ever taking title to the articles. If your business model involves connecting buyers and sellers of defense items in any capacity, Part 129 likely applies and should be reviewed.

How Certify Consulting Structures ITAR Engagements

Certify Consulting's ITAR compliance practice, led by Jared Clark, JD, MBA, focuses on three deliverables before a client's first DDTC registration: a product classification review, a technical data audit, and a written compliance plan. These three outputs define the scope of what a client actually needs to control before any license application or registration filing proceeds.

The classification review maps every product, component, and data category against the current USML text, identifies ambiguous items that warrant a CJ request, and documents the classification rationale in a form that survives regulatory scrutiny. The technical data audit traces every pathway through which controlled information could reach a foreign person — employees, contractors, cloud systems, international partners, shared drives — and identifies gaps in the current control environment. The compliance plan translates findings into a documented, role-specific program the client can implement and maintain.

Across more than 200 client engagements, Certify Consulting has maintained a 100% first-time audit pass rate. That record comes from a consistent methodology: get the classification right first, build the controls around what the classification actually requires, and train the people who own the operational risk.

Common ITAR Compliance Mistakes

The most common ITAR mistakes I see follow a predictable pattern, which means they're also predictable to prevent.

Assuming domestic sales eliminate ITAR obligations. Manufacturing a USML item creates registration and compliance obligations regardless of whether any export ever occurs. The activity triggers the requirement, not the transaction.

Treating technical data as less regulated than hardware. The regulations apply equally. A controlled CAD file carries the same ITAR weight as the physical part it describes.

Failing to screen foreign-national employees before granting systems access. Many companies screen at hire but do not separately screen before systems access is provisioned, creating a window of uncontrolled deemed export exposure that can span weeks or months.

Letting export licenses expire before renewals are filed. ITAR licenses have defined validity periods. Operating under an expired license is a violation, and the administrative disruption of an expired license during an active program can be substantial.

Assuming a prime contractor's compliance flows downstream. Each entity in the supply chain must maintain its own compliant program. Subcontractors cannot borrow ITAR compliance from the prime.

For organizations navigating regulated industries beyond defense, Certify Consulting's FDA regulatory compliance services and ISO certification consulting practice apply the same methodology: classification first, controls second, documentation third.


Last updated: 2026-07-20

Jared Clark is the Principal Consultant at Certify Consulting (https://certify.consulting), where he leads ITAR, GMP, ISO, and FDA compliance engagements. Credentials: JD, MBA, PMP, CMQ-OE, CQA, CPGP, RAC. Certify Consulting has served 200+ clients and maintained a 100% first-time audit pass rate over 8+ years of practice.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.