Most companies discover their ITAR gaps the hard way: a customer audit turns up an unscreened foreign national in the engineering group, or a proposal manager attaches a drawing with export-controlled dimensional data to an email that goes to a distributor in a country nobody checked. By the time that happens, you're no longer doing a self-assessment. You're doing damage control.
An ITAR readiness self-assessment is the difference between finding that problem on a Tuesday afternoon with a checklist, and finding it during a government inquiry. It's not a substitute for a full compliance program, and it's not the same thing as a third-party audit. It's the recurring, internal gut-check that tells you whether the program you built two years ago still matches the business you're running today.
I've walked companies through this process enough times to know where it breaks down. It's rarely the big, obvious stuff — everyone remembers to register with the Directorate of Defense Trade Controls (DDTC). It's the quiet drift: a technology control plan that was accurate when it was written and hasn't been touched since a reorg, or an empowered official who was trained once, in 2021, and has since inherited three new product lines they've never been briefed on.
What an ITAR Readiness Self-Assessment Actually Covers
A real self-assessment isn't a single yes/no question ("are we ITAR compliant?"). It's a structured walk through the specific obligations that create liability if they slip, organized around where DDTC and the Directorate itself have said they look first.
Jurisdiction and Classification
Before anything else, you need to know whether your hardware, software, and technical data are even subject to ITAR, and if so, which category of the U.S. Munitions List (USML) they fall under. The USML spans 21 categories under 22 CFR 121.1, and a single misclassified line item can put an entire product line out of compliance without anyone noticing for years. Classification isn't a one-time exercise — a design change, a new customer requirement, or a supplier substitution can shift an item's jurisdiction or category, so the self-assessment needs to ask not just "did we classify this" but "when did we last re-check it."
Registration Status
Registration with DDTC under 22 CFR 122.1 must be renewed annually regardless of whether you currently hold or need an active export license, and a lapsed registration is itself a violation, independent of whether any actual export occurred. I still run into companies that let registration lapse during a slow year because "we're not exporting anything right now." That logic doesn't hold up if the registration requirement is triggered by manufacturing or brokering activity, not by shipment volume.
Technology Control Plan (TCP) Accuracy
Your TCP is supposed to describe, in specific and current terms, how controlled technical data is segregated, who has access, and how foreign-person access is managed. In practice, TCPs are often written once for an audit or a customer flow-down requirement and then left untouched while the org chart, IT systems, and physical facility all change around them. A self-assessment should physically walk the floor and compare what the TCP says against what's actually happening at the workstations.
Deemed Export Exposure
A "deemed export" happens when controlled technical data is released to a foreign person inside the United States — in a meeting, on a shared drive, in a code repository, or in casual hallway conversation. This is consistently the area where I find the widest gap between what companies believe their exposure is and what it actually is, because deemed exports don't involve a shipment, a customs form, or anything that feels like "exporting." If your engineering, IT, and HR systems aren't talking to each other about who's a foreign person and what they can access, you have a deemed export problem you don't know about yet.
Screening and Denied Party Checks
Are you checking counterparties — customers, freight forwarders, distributors, even job candidates for controlled roles — against the Consolidated Screening List before onboarding, and are you re-screening on a defined cadence rather than just at intake? A one-time screen at contract signing misses the case where a previously clean counterparty gets added to a denied or restricted party list eighteen months into the relationship.
Recordkeeping
22 CFR 122.5 requires exporters to maintain records related to ITAR-controlled activities for a minimum of five years from the date of export, license expiration, or termination of the agreement, whichever is later. The self-assessment question isn't "do we keep records" — it's "can we retrieve them, complete, within the timeframe a government request would demand."
Empowered Official Function
Your empowered official has to have the authority, the training, and the current product knowledge to make licensing determinations and stop a shipment that doesn't have proper authorization. An empowered official in name only — someone with the title but no real visibility into what's shipping — is a paper compliance program, and DDTC's own Compliance Program Guidelines treat management commitment and real authority as a distinct line item, not a formality.
Training Currency
Training that happened once at onboarding, with no refresh, is functionally equivalent to no training for anyone who's been in their role more than a year. People forget, roles change, and regulations get amended. A self-assessment should check training records against actual role changes, not just against a completion checkbox from three years ago.
Flow-Down and Subcontractor Controls
If you're a prime or a mid-tier supplier, your ITAR obligations don't stop at your own four walls. Flow-down clauses in subcontracts, and verification that your subcontractors actually understand and follow them, are a recurring finding in government audits of larger primes' supply chains.
Self-Assessment vs. Third-Party Audit vs. Consent Agreement Monitorship
These three activities get conflated constantly, and the differences matter for how much weight to put on the result.
| Feature | Internal Self-Assessment | Third-Party Compliance Audit | DDTC Consent Agreement Monitorship |
|---|---|---|---|
| Who conducts it | Internal compliance team | Outside ITAR consultant or law firm | External special compliance officer, government-approved |
| Trigger | Scheduled, recurring (quarterly/annual) | Scheduled, or pre-M&A due diligence | Imposed as part of an enforcement settlement |
| Independence | Low — self-reported | Moderate to high | Highest — reports to DDTC |
| Typical cost | Internal labor only | Fixed-fee or hourly engagement | Multi-year, often six or seven figures |
| Consequence of findings | Internal remediation, no disclosure obligation by itself | May trigger voluntary self-disclosure | Findings go directly to the government |
| Best used for | Ongoing hygiene, early warning | Independent validation, M&A diligence | Not optional — imposed after a violation |
The self-assessment is the cheapest and most frequent of the three, which is exactly why it should catch problems before they ever require the other two. Companies that skip it and wait for an outside audit to find their gaps are choosing to find out the hard way, on someone else's schedule.
How to Run an ITAR Readiness Self-Assessment: A Step-by-Step Framework
1. Pull your registration and license history first. Before you look at anything else, confirm your DDTC registration is current, and pull every active license, agreement, and exemption you're relying on. You can't assess your program against activity you haven't inventoried.
2. Re-verify classification on anything that's changed. Any product with a design revision, new component sourcing, or new end use in the last twelve months goes back through classification review. Don't assume last year's answer still holds.
3. Walk the TCP against reality. Compare the written technology control plan line by line against actual access controls, badge logs, IT permissions, and physical layout. Note every discrepancy, no matter how small it seems.
4. Map foreign-person access across every system that touches technical data. This includes engineering drives, PLM systems, source code repositories, and physical prototype access — not just personnel files. Cross-reference against your current foreign national roster, including contractors and interns.
5. Re-run screening on your active counterparty list. Don't just screen new counterparties — re-screen your existing customer, distributor, and vendor list against the current Consolidated Screening List.
6. Test recordkeeping retrieval, don't just confirm records exist. Pick three transactions from the past two years at random and time how long it takes to produce a complete file. If it takes days instead of hours, that's a finding.
7. Interview the empowered official. Ask them to walk through the last licensing decision they made or should have made. If they can't speak specifically to recent product or program changes, their authority is theoretical rather than operational.
8. Check training records against org changes. Cross-reference your training completion log against promotions, transfers, and new hires in controlled roles over the past 18 months.
9. Sample your subcontract flow-down language. Pull a handful of active subcontracts and confirm the ITAR flow-down clauses are present, current, and actually referenced in supplier onboarding.
10. Document findings with severity and owner, not just a list. Every gap gets a named owner and a remediation deadline. An assessment that produces a list nobody is accountable for fixing isn't a self-assessment — it's a memo.
Common Gaps I Find Doing This Work
In my experience, the same handful of issues show up across companies that would otherwise describe themselves as compliant. Deemed export exposure through IT systems is the single most underestimated risk, because it doesn't look like an export to the people creating it. Stale technology control plans are a close second — written to pass one audit, then frozen in time while the business moves on. Empowered officials with the title but not the operational visibility to actually use it come in third. None of these show up on a simple compliance checklist that only asks whether policies exist. They show up when you test whether the policies match what's actually happening on the ground.
When to Bring in Outside Help
A self-assessment run entirely in-house has a structural limitation: the people doing the assessing are often the same people who built the program, and it's hard to see your own blind spots. In my view, that's not a reason to skip the internal self-assessment — it's a reason to pair it with periodic outside validation, particularly before a merger or acquisition, after a significant product line change, or any time your government customer base expands into new agencies with different flow-down expectations. If your internal self-assessment turns up findings you're not confident you can remediate correctly on your own, that's the moment to bring in outside expertise rather than waiting for an outside party to bring it to you. Our team at Certify Consulting works through exactly this kind of gap analysis with manufacturers and exporters, and it pairs naturally with the ITAR compliance program development services we offer for companies building or repairing a program from the findings up.
For companies specifically worried about the technical data side of this, it's worth reading through our breakdown of technology control plan requirements alongside the self-assessment framework above — the two exercises reinforce each other.
Frequently Asked Questions
How often should we run an ITAR readiness self-assessment?
At minimum, annually, timed to coincide with your DDTC registration renewal. Companies with active foreign-person hiring, frequent product changes, or growing subcontractor networks should run a lighter-weight version quarterly, focused specifically on deemed export exposure and screening currency, since those two areas change the fastest.
Is a self-assessment the same thing as a voluntary self-disclosure?
No. A self-assessment is an internal review that may or may not surface something worth disclosing. A voluntary self-disclosure under 22 CFR 127.12 is a formal notification to DDTC about a specific violation you've already identified. Running a good self-assessment is often what leads a company to the voluntary disclosure decision, but the two are distinct steps with different audiences and different consequences.
What's the difference between an ITAR self-assessment and an EAR self-assessment?
ITAR covers defense articles and services on the U.S. Munitions List, administered by the State Department's DDTC under the Arms Export Control Act. The Export Administration Regulations (EAR) cover dual-use and commercial items administered by the Commerce Department's Bureau of Industry and Security. A company dealing in both regimes needs separate classification logic for each, though the underlying self-assessment discipline — jurisdiction, screening, recordkeeping, training — overlaps considerably.
Can a small company with no dedicated compliance staff realistically run this internally?
Yes, with the caveat that the framework above assumes someone has clear ownership of the process even if it's a part-time responsibility layered onto another role. Smaller exporters often do the internal walk-through using this kind of checklist and then bring in outside expertise specifically to validate classification calls and TCP language, which are the two areas where getting it wrong is most consequential.
What happens if a self-assessment finds a violation that already occurred?
Stop, document what you found and when, and get guidance on whether it rises to the level of a voluntary self-disclosure before doing anything else. Penalties for ITAR violations can be severe: DDTC's 2024 inflation adjustment set the maximum civil penalty at $1,197,728 per violation, and criminal violations of the Arms Export Control Act can carry penalties of up to $1 million and 20 years in prison per violation. That severity is exactly why voluntary disclosure, made correctly and promptly, is treated by DDTC as a significant mitigating factor.
Last updated: 2026-08-10
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.