Guide 13 min read

ITAR Compliance Consultant: The Defense Contractor's Guide

J

Jared Clark

July 27, 2026

Defense contractors face a compliance environment that is both unforgiving and genuinely complex. ITAR — the International Traffic in Arms Regulations — is one of the few regulatory regimes where a paperwork error carries the same potential exposure as an intentional violation: civil fines up to $1,308,326 per violation and criminal penalties up to $1 million per count plus 20 years in federal prison. Most companies don't discover the gap in their compliance program until the State Department's Directorate of Defense Trade Controls (DDTC) is already asking questions.

An ITAR compliance consultant closes that gap before it becomes a crisis. This guide covers what the work actually involves, when you need outside help, what common mistakes look like in practice, and what a defensible program looks like when it's functioning the way it should.


What ITAR Controls — and Why the Scope Surprises Most Companies

ITAR is enforced by the State Department's Directorate of Defense Trade Controls and governs the export, import, and transfer of defense articles, defense services, and related technical data listed on the United States Munitions List (USML). If your company manufactures, exports, imports, or brokers any USML item — from small arms components to satellite systems to military training services — ITAR almost certainly applies.

The regulation reaches further than most people expect. ITAR governs:

  • Physical exports — shipping a controlled item to any foreign destination
  • Deemed exports — sharing controlled technical data with a foreign national on U.S. soil
  • Defense services — providing technical assistance or training to foreign parties on ITAR-controlled items
  • Brokering — arranging transactions between non-U.S. parties involving defense articles
  • Re-exports — transferring controlled items or data from one foreign country to another

That second category — deemed exports — is where companies most often run into trouble. Hiring a foreign national engineer and giving her access to ITAR-controlled design files can constitute an export. Nothing crosses a border, the work happens entirely in your facility, and yet the company may have just violated federal law without anyone in the building understanding that they did.

ITAR requires registration with DDTC for any company that manufactures or exports defense articles — even if they have never exported anything. That registration is annual, non-optional, and a prerequisite to applying for any export license. Missing it is itself a violation.


ITAR vs. EAR: Getting Jurisdiction Right Before You Do Anything Else

One of the most consequential classification decisions a defense contractor makes is whether a product falls under ITAR or under EAR — the Export Administration Regulations enforced by the Commerce Department's Bureau of Industry and Security. Getting this wrong runs damage in both directions. Companies that misclassify EAR items as ITAR spend real money on unnecessary licensing and controls. Companies that treat ITAR items as EAR may be exporting controlled defense articles without proper authorization.

Factor ITAR (State Dept / DDTC) EAR (Commerce Dept / BIS)
Governing statute Arms Export Control Act (AECA) Export Administration Act
Control list USML (United States Munitions List) CCL (Commerce Control List)
Primary focus Military / defense articles Dual-use / commercial items
Registration required Yes — all manufacturers/exporters No registration requirement
License authority DDTC BIS
Max civil penalty $1,308,326 per violation $364,992 per violation
Max criminal penalty $1M + 20 years $1M + 20 years
Key authorization types DSP-5, DSP-73, TAA, MLA BIS licenses by ECCN

The 600-series ECCNs — Commerce Control List numbers in categories like "0A606" or "9A610" — were created specifically for items that transitioned off the USML during Export Control Reform between 2012 and 2016. If your products went through commodity jurisdiction review during that period, you may be operating under EAR today for items that used to require ITAR licensing. Or you may have missed that a product reclassified in the other direction.

Getting jurisdiction right is foundational, not optional. Everything downstream in your compliance program — your licenses, your training, your physical and electronic controls — depends on correct classification.


When a Defense Contractor Needs an ITAR Compliance Consultant

There is a temptation to treat ITAR compliance as a one-time project: register with DDTC, write a policy, train the employees, move on. In my experience working with more than 200 defense and aerospace clients over eight-plus years, that is precisely the approach that produces violations.

ITAR compliance is not a state you achieve. It is a program you operate. The specific moments when outside expertise becomes genuinely important:

Entering the defense market for the first time. DDTC registration and initial USML classification are gates you have to clear before you can work on a defense contract. Getting the classification analysis wrong at this stage creates problems that are expensive to unwind later.

Hiring foreign nationals. Every time a company brings on a non-U.S. person who will have access to technical data related to defense articles, a deemed export analysis is required. Most HR departments are not equipped to conduct that analysis, and most hiring managers do not know they need one.

Structuring technology partnerships. Technical Assistance Agreements (TAAs) govern the transfer of ITAR-controlled technical data and defense services to foreign parties. They require DDTC approval before the collaboration begins. Companies routinely start the work first — share the documents, attend the meeting, begin co-development — and try to file the paperwork after. That sequence is already a violation.

Pre-acquisition due diligence. When you acquire a defense contractor, you inherit their compliance history, their DDTC registrations, their existing authorizations, and their undisclosed violations. ITAR due diligence in M&A is a distinct discipline that a standard legal or financial diligence team will miss.

Voluntary disclosure. If your company has discovered a potential violation, the question of whether to file with DDTC — and how to structure that disclosure to achieve the best possible outcome — requires experienced judgment. This is not a form-filling exercise. Framing, remediation planning, and timing all affect how DDTC responds.


What an ITAR Compliance Consultant Actually Does

The scope of work varies depending on where a company sits in its compliance maturity. At the foundational level, the work is classification and jurisdiction analysis — figuring out which items are controlled, under which USML category, and what that means for the business day-to-day.

From there, a full engagement typically includes:

Compliance program design. A formal ITAR compliance program includes a Technology Control Plan (TCP), export control procedures, a training program, and a compliance manual. These aren't just good practice — DDTC looks for evidence of a functioning program when investigating violations, and the absence of one is an aggravating factor in penalty calculation.

License management. DSP-5 licenses authorize permanent exports of ITAR-controlled hardware. DSP-73 licenses cover temporary exports. TAAs and MLAs govern services and manufacturing transfers to foreign parties. Managing these authorizations — applications, license conditions, record-keeping, transaction reports, and re-export requests — is ongoing operational work that many companies understaff until they have a problem.

Training. ITAR training is not a one-time checkbox. Employees who handle controlled technical data need to understand what they can share, with whom, and under what conditions. Generic export control training does not meet the standard. The training program has to be specific enough to change behavior in the situations that actually arise in your business.

Gap assessment. Before a company can fix its compliance posture, it has to know where the gaps are. A structured gap assessment reviews the full program against current regulatory requirements and identifies what is missing, outdated, or not being followed in practice — as opposed to what the policy document says.

Voluntary disclosure support. DDTC's voluntary disclosure program can significantly reduce civil penalties when a violation is self-reported with a credible remediation plan before the agency opens its own investigation. Structuring that disclosure correctly — presenting the facts clearly, demonstrating good faith, and addressing the systemic root cause — is where experienced counsel matters most.


Common ITAR Compliance Mistakes (and What They Cost)

After working with more than 200 clients, the violations I see most often are not the result of willful noncompliance. They are the result of programs that were built once and then stopped keeping pace with the business.

The stale Technology Control Plan. A TCP written when the company had 15 employees stops functioning as a meaningful control when the company has 150 — different facilities, different IT systems, different personnel. DDTC will notice the gap between the plan and the operation.

Deemed export screening at hire but not after. A foreign national engineer hired as a manufacturing technician who later moves into a role with access to ITAR-controlled design files is a new deemed export analysis. Most companies screen at hire and never screen again when job duties change.

TAAs without DDTC approval. I have encountered companies with years of technical collaboration with foreign partners operating entirely under an unsigned agreement they believed was a TAA. A TAA requires DDTC approval and does not take effect until that approval is granted.

Record-keeping failures. ITAR requires records of all export transactions — licenses, authorizations, shipping documents, end-use certificates — to be retained for five years. Companies that cannot produce those records on request are exposed regardless of whether the underlying transactions were authorized.

Believing registration covers everything. DDTC registration is a threshold requirement. It is not an authorization to export anything. Companies that conflate registration with compliance authorization are one export away from a violation.


The Cost of Getting It Wrong

ITAR enforcement is not a theoretical risk. In 2019, Raytheon agreed to pay $8 million to resolve DDTC charges related to unauthorized exports of technical data. General Atomics settled for $8 million in 2020 on similar charges. L3 Technologies paid $13 million in 2016. These are major defense contractors with dedicated compliance departments — they still violated ITAR, and they paid real money to resolve it.

For smaller contractors, the math is more severe. A single violation can exceed a year's operating margin. Beyond the financial exposure, DDTC enforcement actions can result in debarment from export privileges, which effectively ends a defense contractor's ability to operate.

The reputational impact compounds the financial one. DoD program offices and prime contractors increasingly require documented ITAR compliance programs as a condition of contracting. An enforcement history surfaces in due diligence and will come up in a competitive bid environment — at that point you are explaining rather than competing.

The DDTC processes approximately 30,000 license applications annually. Companies with experienced ITAR counsel navigate that process in weeks. Companies without it spend months and often get it wrong the first time.


What a Defensible ITAR Compliance Program Looks Like

"Defensible" is the word I use intentionally. The goal is not a program that looks good on paper — the goal is a program that demonstrably works in practice and that DDTC can observe working if they come knocking.

Program Element What "Defensible" Requires
Product classification Written CJ determinations for all products; review triggered by design changes
DDTC registration Current registration; calendar reminders for annual renewal
Technology Control Plan Site-specific TCP covering physical, electronic, and verbal controls
License management Active license log; conditions tracked; expiration alerts
Deemed export screening Foreign national screening at hire AND when job duties change
Training Role-specific, annually refreshed, documented completion records
Internal audits Compliance review at least annually; findings logged and closed out
Disclosure protocol Written escalation procedure for when a potential violation is discovered

The program does not have to be elaborate. What it has to be is real — actually followed by the people responsible for it, reviewed on a defined schedule, and updated when the business changes. Most violations don't come from bad actors. They come from compliance programs built once and then abandoned as the company grew.


How to Choose the Right ITAR Compliance Consultant

The ITAR consulting market includes solo practitioners, large law firms, and specialized compliance boutiques. What you are looking for isn't credentials alone — it's someone who understands your business and will build a program that actually operates in your environment.

A few questions worth asking:

Do they understand the intersection of ITAR and EAR? Many ITAR compliance questions require simultaneous analysis of both regimes. A consultant who treats them as separate tracks will miss interactions that matter.

Have they structured voluntary disclosures with DDTC? If there's any chance your company has undisclosed compliance history, you want someone who has navigated that process before — not someone learning alongside you.

Can they train your employees, not just write your policy? The policy document is not what prevents violations. Employees who understand the rules in practical situations are what prevent violations.

Do they have industry-specific experience? The practical compliance questions in aerospace electronics are different from those in firearms manufacturing or satellite communications. Sector knowledge compresses the learning curve significantly.

At Certify Consulting, I work with defense contractors, aerospace manufacturers, and technology companies navigating ITAR for the first time and those rebuilding after an enforcement action. Our track record includes 200-plus clients served and a 100% first-time audit pass rate across eight-plus years in defense trade compliance. Learn more about our ITAR compliance services, or contact us directly to discuss your specific situation.


Frequently Asked Questions About ITAR Compliance

Do I need to register with DDTC even if I haven't exported anything?

Yes. ITAR requires registration with the Directorate of Defense Trade Controls for any company that manufactures defense articles on the United States Munitions List, regardless of whether any export has occurred. The obligation attaches to manufacturing activity itself — not export activity. Failure to register while manufacturing USML items is a standalone violation.

What is a deemed export under ITAR, and why does it matter?

A deemed export occurs when ITAR-controlled technical data or defense services are provided to a foreign national on U.S. soil. This includes showing a foreign national employee controlled design files, discussing controlled technology in a meeting, or providing technical training. A deemed export requires the same DDTC authorization as physically shipping the item abroad. This is one of the most frequently misunderstood aspects of ITAR — many companies with strong physical export controls have significant deemed export exposure they haven't analyzed.

What is the difference between a TAA and a DSP-5 license?

A DSP-5 is a license authorizing the permanent export of ITAR-controlled hardware or technical data to a specific foreign party. A Technical Assistance Agreement (TAA) governs the transfer of defense services — technical assistance, training, or related services — typically in a joint development, co-production, or support relationship. Both require DDTC approval before the activity begins. Many international partnerships require a TAA rather than (or in addition to) a hardware license because the services component triggers the authorization requirement independently.

How long does a DDTC export license application take?

Standard DSP-5 applications typically take 30–90 days, though applications involving sensitive destinations, novel end-uses, or complex transactions can take significantly longer. TAAs are more complex and often involve iterative back-and-forth with DDTC reviewers before approval. Working with experienced ITAR counsel who understands how to structure and document applications correctly reduces the chance of requests for additional information that extend the timeline.

What should I do if I discover a potential ITAR violation?

Stop the activity, preserve all relevant records, and consult with experienced ITAR counsel immediately. Do not attempt to remediate the situation without guidance — corrective actions taken without coordinating a voluntary disclosure strategy can complicate the disclosure process. DDTC's voluntary disclosure program can significantly reduce civil penalties for companies that self-report before the agency opens its own investigation, but the disclosure has to be structured correctly to achieve that outcome.


Last updated: 2026-07-27

Jared Clark, JD, MBA, PMP, CMQ-OE, CQA is Principal Consultant at Certify Consulting, specializing in ITAR compliance, export control program design, and DDTC voluntary disclosures. With 200-plus clients served and eight-plus years in defense trade compliance, Certify Consulting maintains a 100% first-time audit pass rate.

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.