If you manufacture, export, or broker defense articles — or if you're not sure whether you do — ITAR is not something you learn about after the fact. The International Traffic in Arms Regulations (22 CFR Parts 120–130) carry civil penalties up to $1,308,333 per violation and criminal exposure up to 20 years in federal prison. The Directorate of Defense Trade Controls (DDTC) has collected those penalties from companies with compliance programs on paper. The difference between a company that survives a DDTC audit and one that doesn't is almost never a question of intent. It's a question of documentation, training, and operational discipline.
Over the past eight-plus years, I've helped 200+ clients work through export control requirements — and I've seen a fairly predictable set of failure points. They're almost never the dramatic ones. Most ITAR problems are quiet: an unlicensed technical data disclosure to a foreign national on the shop floor, an improperly classified item that slips into a commercial sale, a Technology Control Plan that nobody updated after a facility expansion. This guide covers what actually matters when you're building or auditing an ITAR compliance program.
What ITAR Covers — and Who It Applies To
ITAR governs the export and temporary import of defense articles, defense services, and technical data as defined in 22 CFR Parts 120–121. The scope is broader than most people expect.
ITAR applies to any company that:
- Manufactures items listed on the United States Munitions List (USML) under 22 CFR Part 121
- Exports or re-exports ITAR-controlled hardware, software, or technical data
- Provides defense services to a foreign person or entity
- Brokers transfers of USML items between third parties
One point that consistently surprises first-time compliance clients: even a purely domestic manufacturer can trigger ITAR obligations if foreign nationals have access to manufacturing processes, technical drawings, or specifications for USML items. That access — regardless of where it occurs — qualifies as a "deemed export" under DDTC guidance. You don't need a shipping label to have an export problem.
ITAR Registration Under 22 CFR Part 122
Registration with DDTC is required before any manufacturing, exporting, or brokering of defense articles. This is not optional, and it is not contingent on whether you plan to export. If you make a USML item domestically and decide later to sell it internationally, you cannot retroactively register on the way out the door.
Registration is completed through the DDTC D-Trade portal and must be renewed annually. A lapsed registration is itself a compliance violation — even if you hold active licenses for specific exports. Current annual registration fees are set by DDTC and reflect your activity tier.
The registration process also requires designating an Empowered Official. That requirement gets its own section below, because the mistakes I see around it are both common and fixable.
Classifying Your Items: The USML Judgment Call
The United States Munitions List (22 CFR Part 121) is organized into 21 categories, ranging from firearms and ammunition (Category I) to military electronics (Category XI) to space launch vehicles (Category XV). Classification is not a clerical exercise. The USML uses performance parameters, design features, and end-use characteristics — and many items sit at the boundary between ITAR and the Export Administration Regulations (EAR).
Since the Export Control Reform Act (ECRA) of 2018 and the accompanying USML-to-CCL realignment, there have been significant category-by-category revisions. Items that were once clearly ITAR may now fall under EAR jurisdiction, and vice versa for some dual-use items that were militarized. If your classification decisions were made before 2015 and haven't been formally reviewed since, I'd call them stale.
When an item sits in a genuinely gray zone, you can submit a Commodity Jurisdiction (CJ) request to DDTC under 22 CFR § 120.4. A CJ determination gives you a documented, defensible basis for your classification — and in an enforcement scenario, documented reasoning matters enormously.
ITAR vs. EAR: Which Regime Applies?
This is the first question I get from most new clients, and it deserves a direct comparison. ITAR civil penalties reach $1,308,333 per violation under 22 U.S.C. § 2778(e), while EAR civil penalties max out at $364,992 per violation — but both regimes impose criminal exposure up to 20 years, and both count violations per shipment or per disclosure.
| Factor | ITAR (22 CFR 120–130) | EAR (15 CFR 730–774) |
|---|---|---|
| Governing agency | State Dept. / DDTC | Commerce Dept. / BIS |
| Covered items | USML (defense articles) | CCL (dual-use items) |
| Registration required? | Yes — before any covered activity | No universal registration |
| License authority | State Dept. export licenses | Commerce licenses or No License Required |
| Deemed export rule | Yes — foreign national access | Yes — different thresholds |
| Civil penalty max | $1,308,333 per violation | $364,992 per violation |
| Criminal penalty max | 20 years / $1M per count | 20 years / $1M per count |
| Voluntary disclosure | Strongly recommended; mitigates | Strongly recommended; mitigates |
| Self-reporting benefit | Significant penalty reduction | Significant penalty reduction |
The practical test: if your item was designed, modified, or configured for a military purpose, start with the USML. If it's genuinely commercial with incidental military applications, look at the CCL first. Getting this classification wrong in either direction carries consequences — over-classification generates unnecessary license burden, and under-classification generates enforcement risk.
Deemed Exports and Foreign National Management
This is where most mid-size defense contractors have gaps they don't know about. A "deemed export" occurs when ITAR-controlled technical data is released to a foreign national inside the United States. The release — whether it's a conversation on the factory floor, access to a CAD file on a shared drive, or a visitor tour of a manufacturing line — is treated as an export to that person's country of origin.
Managing deemed export risk requires knowing:
- Which of your employees, contractors, and regular visitors are foreign nationals
- What USML technical data they have access to, in what systems, and under what controls
- Whether your authorized licenses cover the relevant countries of origin
- How remote access policies interact with your ITAR data environment
The challenge post-2020 is that remote work arrangements dramatically expanded the attack surface. Engineers connecting from home, contractors dialing into design reviews, vendors accessing drawings through cloud platforms — all of these create deemed export scenarios that weren't in most companies' Technology Control Plans as of 2019. In my experience, that gap is still open at a lot of facilities.
Under 22 CFR Part 122, ITAR registration with DDTC is required before manufacturing, exporting, or brokering any defense article — regardless of whether the company currently has export plans — and that obligation extends to managing all deemed export exposures created by foreign national access.
What an ITAR Compliance Program Actually Needs
An ITAR compliance program is not a binder. I've audited companies with 200-page compliance manuals that had never trained a production supervisor and couldn't identify their Empowered Official. The binder did not help them. What actually holds up to DDTC scrutiny has four non-negotiable elements:
1. ITAR Compliance Manual — 22 CFR Part 128 basis
Must be tailored to your operations, not a template. Cover: scope of USML items you handle, registration status, license procedures, deemed export policy, training requirements, and violation reporting procedures. Generic documents get companies into trouble because they describe procedures that don't match what actually happens.
2. Empowered Official (EO)
Your Empowered Official is a U.S. person with authority to bind the company contractually on export matters and responsibility for signing license applications. The EO cannot be a foreign national. Many companies assign the EO designation to legal or HR without giving that person real operational authority — this is a gap DDTC auditors find quickly.
3. Technology Control Plan (TCP)
Required if foreign nationals have or could have access to ITAR-controlled technical data or hardware. The TCP must address physical security (facility access controls, visitor escort procedures), cyber security (network access, data controls, cloud environment policies), and subcontractor/vendor access. A TCP written at onboarding and never updated is the single most common compliance gap I find on assessments.
4. Role-Specific Training Program
Training must be documented, dated, and role-specific. A shipping clerk's ITAR training should look different from an engineer's. The USML category revisions post-2018 required training updates that a significant number of companies never completed.
The Empowered Official: Where Mid-Size Contractors Slip Up
ITAR requires that the person signing export license applications be a "senior officer of the company" with full authority to bind the company on export matters (22 CFR § 120.68, formerly § 120.25). That person must be a U.S. citizen or lawful permanent resident.
The problem I see frequently: the EO is listed on the DDTC registration as the VP of Compliance, but the actual authority sits informally with an operations manager who isn't designated. When a license needs to be signed and the VP is unavailable, someone signs who isn't authorized — and that's a violation regardless of whether the underlying export was legitimate.
The fix is simple: designate a primary EO and a backup EO, make sure both are properly authorized in your compliance program documentation, and test the chain of authority at least annually. Document the test. DDTC doesn't take your word for it.
Technology Control Plans — The Operational Gap
If your facility employs or hosts foreign nationals who work anywhere near ITAR-controlled technical data, you need a TCP. This includes foreign national employees, contract workers, vendors visiting the facility, customers on plant tours, and — critically in 2026 — foreign nationals connecting to your systems remotely.
A defensible TCP today has to address:
- Physical access: badge access logs, visitor escort procedures, restricted area designations
- IT system access: who can reach which file servers, CAD systems, design databases, and ERP modules
- Cloud and remote access: ITAR-compliant hosting environments, VPN policies, contractor remote access
- Subcontractor controls: flow-down requirements, access agreements, audit rights
- Incident response: what happens when unauthorized access is discovered
The cloud issue deserves particular attention. Many companies adopted cloud platforms during 2020–2021 without considering whether foreign national employees of the cloud provider could access their data under the provider's standard terms. Under ITAR, that access — even if inadvertent — is a deemed export. Major cloud providers now offer ITAR-compliant hosting configurations, but they require specific contracting and configuration, not just a checkbox during sign-up.
ITAR Penalties and Enforcement: What the Numbers Actually Mean
DDTC's civil penalty authority allows fines up to $1,308,333 per violation. In significant enforcement actions, violations are counted per shipment, per disclosure, or per license application — meaning a pattern of conduct compounds into eight-figure exposure quickly. Several recent consent agreements give a realistic picture:
- BAE Systems: $79 million (2011) — inadequate compliance program across multiple USML categories
- United Technologies: $75 million (2012) — unauthorized exports of military helicopter technical data
- Esterline Technologies: $30 million (2017) — EAR/ITAR misclassification and licensing failures
- L3 Technologies: $13 million (2021) — unauthorized re-exports through foreign subsidiaries
The common thread: these were systemic failures, not isolated incidents. A company that makes one inadvertent disclosure, catches it internally, and self-reports under 22 CFR Part 127 is in a fundamentally different enforcement posture than a company with a pattern of avoidance. DDTC's Voluntary Disclosure program genuinely matters — self-reporting typically results in significantly reduced penalties and avoids criminal referral to the Department of Justice.
If you discover a potential violation, the first 48–72 hours matter. Preserve documentation, halt the activity if it's ongoing, and get ITAR counsel on the phone before you decide how to respond.
How to Choose an ITAR Compliance Consultant
I'll be direct: what differentiates capable consultants in this space is operational experience, not just regulatory knowledge.
Look for: - Documented experience working with DDTC directly — navigating CJ requests, voluntary disclosures, and license applications, not just teaching a seminar about them - Familiarity with your specific USML categories and the technical environment around them - The ability to produce actual compliance documents tailored to your operations, not templates with your logo pasted in - A track record that includes audit-facing work, not just pre-audit consulting
Be skeptical of: - Consultants who deliver a compliance manual without auditing your actual operations first - Any promise of a clean bill of health that didn't require an operational review to earn - Firms without experience inside manufacturing or engineering environments — ITAR compliance is an operational discipline, and you can't assess operations from a conference room
In my view, the companies that maintain clean ITAR records are almost never the ones with the thickest binders. They're the ones whose operations supervisors can answer a basic compliance question without looking anything up, whose IT security policies genuinely reflect ITAR requirements, and whose training records are current. That takes operational integration — working inside the company's actual processes, not just documenting what should happen.
If you're not sure where your program stands, a structured gap assessment is the right starting point. You need to know exactly what you have and what you don't before DDTC does.
For more on how we structure ITAR compliance assessments for defense manufacturers, see our ITAR Compliance Services page on ITARconsultant.us. If you're evaluating your overall export control posture, our Export Control Program Development guide covers both ITAR and EAR requirements in depth.
Last updated: 2026-07-20
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.