Compliance 12 min read

What to Look for When Hiring an ITAR Consultant

J

Jared Clark

August 10, 2026

I get some version of this call every few months: a defense contractor, a small aerospace machine shop, a software company that just realized its encryption module touches a controlled technical data package, and they need an export control specialist yesterday. The problem is that "ITAR consultant" is not a licensed title. Anyone can put it on a LinkedIn profile. There is no bar exam for it, no single certifying body, and the gap between someone who has actually filed a Commodity Jurisdiction request with the Directorate of Defense Trade Controls and someone who read the regulation once is wide enough to sink a company.

So this is the guide I wish more companies read before they signed an engagement letter. It walks through what the International Traffic in Arms Regulations actually require, what a competent consultant needs to know cold, and the specific questions that separate a real practitioner from someone charging by the hour to Google alongside you.

What Is ITAR, and Why Does the Consultant You Hire Matter So Much?

ITAR is the set of regulations at 22 CFR Parts 120–130 that implement the Arms Export Control Act, and it is administered by the Directorate of Defense Trade Controls, a division of the State Department, not Commerce. That distinction trips people up constantly, because most general export questions default to Commerce's Export Administration Regulations. If your product, technical data, or even a conversation with a foreign national touches something on the United States Munitions List, you are in DDTC's world, and the penalties for getting it wrong are criminal, not just civil.

Here is the sentence that should focus attention: willful ITAR violations carry criminal exposure of up to 20 years imprisonment and fines that can reach into seven figures per violation under the Arms Export Control Act, and the civil penalty ceiling under 22 CFR 127.10 is adjusted for inflation most years, so a consultant who quotes you last decade's penalty numbers is telling you they haven't kept current. That is not a hypothetical. DDTC's consent agreements with companies like Honeywell, ITT, and BAE Systems ran into the hundreds of millions of dollars, and small and mid-size manufacturers get debarred every year for far less sophisticated violations than the ones that make headlines.

The person you hire to navigate this needs to be someone who reads the Federal Register the way other people read the news. In my experience, the biggest driver of bad outcomes is not malice. It's a well-meaning engineer or contracts manager making a classification call on a Friday afternoon without knowing the difference between a "defense article" and a "defense service," and nobody catching it until an audit two years later.

What Does an ITAR Consultant Actually Do?

A competent export control specialist is doing several distinct jobs at once, and it's worth naming them separately because most consultants are strong in one or two and weak in the rest.

Jurisdictional and classification analysis. Before anything else, someone has to determine whether an item, technology, or service is even covered by ITAR versus the EAR versus neither. This means working through the USML's 21 categories, understanding the "specially designed" catch-all language that pulls in components you'd never guess, and knowing when to file a Commodity Jurisdiction request under 22 CFR 120.4 rather than guessing.

Registration and licensing. Manufacturers, exporters, and brokers of defense articles or services must register with DDTC annually under 22 CFR 122.1, on a tiered fee schedule that runs roughly $2,250 to nearly $4,000 depending on license activity in the prior year. Registration alone doesn't authorize an export — it's a prerequisite for applying for the license, Technical Assistance Agreement, or Manufacturing License Agreement that actually does.

Technology control plans and physical/IT security. ITAR requires that controlled technical data be walled off from unauthorized foreign persons, including foreign nationals employed by the same U.S. company. A real consultant designs technology control plans that account for badge access, network segmentation, and deemed export risk — not just paperwork.

Voluntary self-disclosure. When a violation is found, 22 CFR 127.12 gives companies a path to disclose it voluntarily, and DDTC has historically treated voluntary disclosures far more leniently than violations discovered through enforcement. Knowing when and how to file a VSD, and how to scope the internal investigation that has to precede it, is a specialized skill most general compliance consultants have never actually exercised.

Training and culture. The best engagement I've seen isn't a binder that sits on a shelf. It's recurring, role-specific training for engineers, shipping staff, and sales — the people actually making day-to-day calls about what can go in an email attachment to a foreign customer.

If the consultant you're evaluating can only speak fluently to one of these five, ask who covers the rest.

Credentials and Background: What Actually Signals Competence

There's no single credential that guarantees export control competence, which is exactly why this space attracts people who oversell. Here's what I'd actually weigh, in rough order of signal strength.

A legal background in export control specifically — not general corporate law. Jurisdictional determinations under ITAR are legal interpretations with criminal consequences, and a consultant with a JD who has actually practiced in this area brings a different rigor to a classification memo than someone approaching it purely as a process exercise. I say this as someone who holds a JD myself: the discipline of building a record that would survive a DDTC compliance review, not just satisfy an internal checklist, is a legal skill.

Direct experience with DDTC, not just the regulation. Has this person actually filed a Commodity Jurisdiction request and gotten a determination back? Prepared a Technical Assistance Agreement that DDTC approved without a request for additional information? Filed or advised on a voluntary self-disclosure? These are specific, verifiable actions — ask for the count and the outcome, not just "yes, I've done that."

Industry-recognized compliance credentials as a supplement, not a substitute. Certifications like Certified U.S. Export Compliance Officer (CUSECO) or a background in quality and regulatory affairs (RAC, CQA-type credentials) show someone understands compliance program architecture — audits, corrective action, document control — which matters because ITAR compliance doesn't live in a vacuum. It has to integrate with your quality management system and your existing SOPs, not sit next to them as a separate binder nobody opens.

Familiarity with adjacent regimes. Most companies with ITAR exposure also have EAR exposure, and many have OFAC sanctions exposure layered on top. A consultant who only knows ITAR in isolation will miss the cases where a transaction is fine under one regime and prohibited under another.

ITAR Consultant vs. Export Control Attorney vs. In-House Compliance Officer

Companies often ask which of these three they actually need. The honest answer is usually some combination, but the roles are genuinely different, and confusing them is how gaps happen.

Factor ITAR Consultant Export Control Attorney In-House Compliance Officer
Best for Program build-out, classification analysis, TCP design, training Privileged legal opinions, VSD strategy, enforcement defense Day-to-day monitoring, screening, license tracking
Typical engagement Project-based, 3–12 months Hourly, matter-specific Permanent headcount
Attorney-client privilege No, unless engaged through counsel Yes No
DDTC filing authority Prepares filings, often can't sign as Empowered Official Can advise on filing strategy Often serves as the Empowered Official
Cost profile Mid-range, scoped Highest hourly rate Lowest marginal cost, highest fixed cost
Ongoing coverage Limited to engagement term Reactive, as-needed Continuous
Risk if used alone May lack privilege on sensitive findings Expensive for routine operational work May lack breadth across changing regs

Notice the privilege row. If you suspect a violation and want the resulting investigation protected by attorney-client privilege, engaging a standalone consultant directly won't get you there — the engagement typically needs to run through outside counsel, with the consultant retained as counsel's agent. A consultant worth hiring will tell you this unprompted, before you've disclosed anything sensitive, rather than let you find out the hard way that your internal investigation memo is discoverable.

Questions to Ask Before You Sign an Engagement Letter

Ask these directly, and pay attention to how specifically they're answered.

  1. "Walk me through a classification you got wrong, and how you found out." Everyone who has done this work long enough has a story. Someone with no story either hasn't done enough of this work or won't tell you the truth.
  2. "How do you handle a 'specially designed' analysis?" This is the single most litigated, most misunderstood phrase in the USML. A vague answer here is a real red flag.
  3. "What's your process for a voluntary self-disclosure, from discovery to filing?" Listen for a defined sequence: scope the investigation, quantify the exposure, decide on disclosure timing, draft under privilege where appropriate, file under 127.12, and manage the follow-up.
  4. "Can you serve as our Empowered Official, or only advise one?" DDTC requires registrants to designate an Empowered Official who can bind the company on license applications — usually a senior employee, not an outside consultant, though the consultant should know exactly how that role is supposed to function.
  5. "What does your deliverable actually look like — a report, or a working program?" A technology control plan that isn't operationalized into badge access lists and IT permissions is a document, not a control.
  6. "How do you keep current?" DDTC issues Federal Register notices, guidance updates, and enforcement actions continuously. Someone who can't name what changed in the last twelve months is behind.

Red Flags That Should End the Conversation

A few patterns are close to disqualifying on their own. Anyone who tells you ITAR classification is "just common sense" hasn't done the work — the "specially designed" catch-all exists precisely because common sense fails constantly in this area. Anyone who promises a guaranteed outcome on a Commodity Jurisdiction request is either inexperienced or misleading you, because DDTC's determinations are genuinely unpredictable case by case. And anyone who wants to skip a gap assessment and go straight to writing policy documents is optimizing for a fast invoice, not a working compliance program — you cannot write an accurate technology control plan for a company whose actual technical data flows you haven't mapped.

What a Well-Scoped Engagement Actually Looks Like

The engagements that hold up under audit tend to follow a similar shape, even when the company and product line differ wildly. It starts with a jurisdictional and classification review across the current product and technology portfolio, not just the flagship product line — shadow IT and legacy programs are where surprises live. That feeds a documented gap assessment against the existing registration status, licenses, and technology control plan, if one exists. From there, the consultant should produce or revise the actual TCP, tied to specific access controls rather than generic language, and build role-based training that matches what each function actually touches — engineering's exposure is not sales' exposure. Finally, there should be a defined cadence for reassessment, because a static compliance program built for last year's product line is a liability for this year's.

None of that has to take a year. A focused gap assessment for a single-product small manufacturer might run a matter of weeks. But it should always run in that order. Skipping the assessment to jump straight to documentation is the single most common shortcut I see, and it's the one that produces policies nobody can actually follow because they were written for a company that doesn't quite match reality.

If your team needs a structured starting point, our ITAR and export control compliance services walk through exactly this sequence, and you're welcome to reach out directly if you want a second opinion on a classification call before you make it official.

Frequently Asked Questions

Do I need an ITAR consultant if my company only exports a small volume of controlled items? Volume doesn't reduce your obligation. Registration under 22 CFR 122.1 and correct classification are required regardless of how many units you ship, and DDTC has pursued enforcement against companies with modest export volumes when the violation involved unauthorized technical data transfers or unlicensed defense services.

What's the difference between ITAR and EAR, and how do I know which applies? ITAR covers defense articles and services on the United States Munitions List and is administered by the State Department's DDTC. The Export Administration Regulations cover dual-use and commercial items administered by Commerce's Bureau of Industry and Security. Many products require a Commodity Jurisdiction determination specifically because the line between the two isn't obvious from the product description alone.

How much should an ITAR compliance engagement cost? It varies with company size and the state of your existing controls, but a scoped gap assessment is typically the right first purchase before committing to a larger program build, since it tells you honestly how much work remains.

Can my regular corporate attorney handle ITAR issues? Usually not well. Export control law is dense enough, and DDTC's enforcement posture specific enough, that general corporate counsel without dedicated export control experience will often miss classification nuances that a specialist catches immediately.

What happens if we find a past violation during a compliance review? You have the option to file a voluntary self-disclosure under 22 CFR 127.12. DDTC has historically extended more favorable treatment to companies that self-report and remediate promptly than to those whose violations surface through enforcement or a third-party complaint, which is why the investigation should typically be scoped under privilege before you decide how and when to disclose.

Is a background in quality systems relevant to export control consulting? Yes, more than people expect. ITAR compliance ultimately depends on document control, training records, and corrective action processes that look a great deal like a quality management system, and a consultant who understands both worlds tends to build controls that survive an actual audit rather than controls that only look good in a slide deck.

Last updated: 2026-08-10

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.