ITAR (International Traffic in Arms Regulations)
ITAR controls the export and import of defense articles, services, and technical data on the U.S. Munitions List (USML). Codified in 22 CFR Parts 120-130. Administered by the Directorate of Defense Trade Controls (DDTC) in the State Department. If you manufacture defense articles, provide defense services, or hold ITAR technical data, you need to register with DDTC and apply export controls (including controls on foreign-person access to technical data).
- glossary
- ITAR vs EAR
ITAR vs EAR
U.S. export controls split into two regimes. ITAR covers defense articles (weapons, defense systems, related technical data) on the USML, administered by State's DDTC. EAR (Export Administration Regulations) covers dual-use items on the Commerce Control List, administered by Commerce's Bureau of Industry and Security. ITAR is generally stricter. ITAR technical data cannot be shared with any foreign person anywhere, including foreign persons inside the United States, without a license or exemption. EAR controls vary by country and end-use.
What Gets Classified as ITAR
The USML has 21 categories covering everything from firearms (Category I) to classified articles (Category XVII) to spacecraft (Category XV). If your product or technical data fits a USML category description, you are subject to ITAR. When classification is uncertain, DDTC provides Commodity Jurisdiction determinations.
Registration and Basic Compliance
- Register with DDTC (22 CFR 122) if you manufacture, export, or broker defense articles or services. Registration fees start around $3,000 annually.
- Implement a Technology Control Plan (TCP) to prevent unauthorized foreign-person access to ITAR technical data.
- Screen employees and visitors for foreign-person status. U.S. person is defined narrowly: U.S. citizens, lawful permanent residents, and certain protected individuals.
- Obtain export licenses (DSP-5, DSP-73, etc.) before sharing ITAR articles or technical data with any foreign person.
- Know and apply exemptions where they apply (e.g., 22 CFR 126.4 for U.S. government use, 125.4 for specific technical data transfers).
The Cloud Angle
ITAR treats any foreign-person access as an export. If ITAR technical data sits on a server that non-U.S.-person staff administer, that is an export without a license. This is why defense contractors with ITAR data run in environments like Microsoft GCC High or AWS GovCloud, which guarantee U.S.-person or U.S.-citizen staffing, U.S.-only data residency, and limited visibility for operations and support staff.
Penalties
Civil penalties reach $1,271,078 per violation (22 CFR 127.10, adjusted for inflation January 2025) or twice the transaction value, whichever is greater. Criminal penalties under 22 U.S.C. 2778(c) can reach $1 million per willful violation and 20 years imprisonment. DDTC can also debar the organization from future defense trade. Recent cases (e.g., Honeywell, Bright Lights USA, ITT) have produced multi-million-dollar civil settlements.
ITAR and CMMC
ITAR and CMMC are separate regimes run by different agencies. But they often apply to the same organizations. If your ITAR technical data is also CUI (usually the case for military applications), you are implementing NIST 800-171 for CMMC and ITAR safeguarding rules at the same time. The controls overlap heavily. The ITAR-specific layer is foreign-person access control and Technology Control Plans.