If you work with International Traffic in Arms Regulations (ITAR)-controlled technical data, you already know it's sensitive information. Your team has probably been careful about it for years: checking contract requirements, limiting access, watching who's in the room, thinking twice before an email goes out.
What a lot of contractors don't realize is that this same data is also considered Controlled Unclassified Information (CUI). This means the Cybersecurity Maturity Model Certification (CMMC) requirements apply to that data too, with its own set of safeguarding requirements layered on top of whatever export control discipline you've already built.
Understanding the relationship between ITAR data and CUI has direct implications for your compliance obligations and ability to bid on DoD contracts. Below, we’ll walk through each type of sensitive data, explain how they relate to each other, and overview your security and compliance obligations for each.
ITAR data vs CUI
CUI is government information that's sensitive enough to require safeguarding or dissemination controls under federal law, regulation, or government-wide policy, even though it isn't classified. It covers everything from technical data to personnel records to procurement documents, organized into categories by the CUI Registry.
The International Traffic in Arms Regulations (ITAR) is a set of US State Department regulations controlling the export of defense articles, services, and related technical data on the US Munitions List. It exists to keep sensitive military technology out of the hands of foreign adversaries, and it applies whether you're shipping a physical item overseas or simply sharing technical data domestically with someone who isn't a US person.
ITAR data and CUI aren’t separate things: ITAR data is a type of CUI.

Technical data controlled under ITAR meets the CUI definition: it's unclassified, but a specific federal regulation (ITAR itself, 22 CFR Parts 120-130) requires safeguarding and dissemination controls. That makes it CUI Specified under the Export Control organizational index, since the additional restrictions come directly from export control law, not from the CUI Program's standard baseline.
This means ITAR-controlled technical data carries:
- The standard CUI safeguarding requirements (NIST SP 800-171, currently Revision 2) that apply to all CUI
- Additional, ITAR-specific restrictions on top, including who can access the data and whether sharing it (even domestically) requires a license
It’s important to note that under ITAR, an export isn't limited to physically shipping something overseas. Disclosing, releasing, or transferring controlled technical data to a foreign person, even verbally, in an email, or by letting them view a document while standing in a US office, counts as an export to that person's home country. This is the "deemed export" rule, and it applies under both ITAR (22 CFR 120.17) and its EAR counterpart (15 CFR 734.13).
For a defense contractor, this means a foreign national employee viewing ITAR-controlled engineering drawings at your US facility can trigger an export control violation, with no shipment, no border crossing, and no intent to export anything internationally. Many organizations only think about export control when physically moving goods abroad and miss this type of exposure entirely.
There's a narrow exception for information that qualifies as "fundamental research" or is already publicly available, but that exception is specific and shouldn't be assumed without confirming it actually applies to your situation.
If your organization works with any ITAR-controlled data, your CUI boundary needs to explicitly account for who has access to it, including double-checking the citizenship and residency status of anyone who might encounter it, not just where it's physically stored.
How ITAR technical data gets marked
CUI Basic follows the CUI Program's standard safeguarding rules, the baseline that applies to all CUI. CUI Specified carries additional requirements layered on top, imposed by whatever specific law or regulation makes that category sensitive enough to need extra protection. ITAR is exactly that kind of additional authority, which is why ITAR-controlled technical data typically lands in the Specified category.
The actual technical data and defense articles transferred under an ITAR agreement, governed by provisions like 22 CFR 120.21 (which defines Manufacturing License Agreements), are CUI Specified, carrying the banner marking CUI//SP-EXPT.
But not everything tied to an ITAR agreement is CUI Specified. Certain administrative or contractual requirements that accompany those same agreements, like the annual sales reporting clause required under 22 CFR 124.9(a)(5), are CUI Basic. The distinction comes down to what kind of information you're actually looking at: the sensitive technical data and defense articles themselves are Specified, while administrative recordkeeping about the agreement (like quantities sold or transferred) is Basic.
Don't assume "this document relates to an ITAR agreement" automatically means Specified-level handling. Check what the specific document actually contains, the underlying technical data, or administrative paperwork about it, since that's what determines the marking and the controls that apply.
Recommended reading
How ITAR Cybersecurity Requirements Apply to Contractors in the Federal Supply Chain
Read MoreWhat this means for your cybersecurity and compliance program
Since ITAR-controlled technical data is CUI, handling it means you’ll likely be required to achieve at least CMMC Level 2 certification to be awarded DoD contracts. That means implementing 110 NIST SP 800-171 controls, creating SSP and POA&M documentation, completing a formal self-assessment, and submitting annual affirmations, in addition to the ITAR-specific access and dissemination restrictions.
FAQs
Is all ITAR data CUI?
Yes, but not all of it is CUI Specified. The actual technical data and defense articles ITAR controls are CUI Specified. Administrative paperwork tied to an ITAR agreement, like required sales reporting, can be CUI Basic instead. Both qualify as CUI: which type depends on what the specific document actually contains.
Is all CUI ITAR?
No. CUI is a much broader category than ITAR. Most CUI (personnel records, procurement documents, general technical data) has nothing to do with export control. ITAR only covers a specific subset: technical data and defense articles on the US Munitions List.
Does CMMC cover ITAR requirements?
Not directly. CMMC verifies your implementation of NIST SP 800-171 controls for CUI generally. ITAR's specific export licensing and foreign person access restrictions are separate legal requirements you need to meet independently, even if your CMMC program also covers the same data as CUI Specified.