A defensible ITAR compliance program covers twelve areas: (1) jurisdiction and USML classification, (2) DDTC registration, (3) empowered official designation, (4) a written compliance program, (5) technical data controls including IT security, (6) deemed-export screening, (7) license determination workflows, (8) subcontractor flow-downs, (9) training, (10) recordkeeping with five-year retention under 22 CFR 122.5, (11) audits and monitoring, and (12) violation response and voluntary disclosure readiness. "Defensible" means one thing: if DDTC examined your program tomorrow, you could produce documented evidence for every step — not intentions, not awareness, but records.
How to Use This Checklist
This checklist is a working self-assessment, not a reading exercise. For each of the twelve steps, score your company honestly: in place and documented, partially in place, or missing. The "what good looks like" criteria under each step describe the evidence a regulator, a prime contractor, or an acquirer would ask to see — if you cannot produce the document, the honest score is not "in place."
Work the steps in order. The sequence is deliberate: you cannot make license determinations for items you haven't classified, and you cannot designate an empowered official for a company that isn't registered. Steps 1–3 are legal prerequisites, steps 4–8 are the operating controls, and steps 9–12 are what keep the program alive and defensible year after year. If you are new to the regulations entirely, read our definitive guide to what ITAR is first — this checklist assumes you know you are, or may be, subject to 22 CFR Parts 120–130.
One warning before you begin: the stakes for getting this wrong are civil penalties up to $1,267,619 per violation and criminal exposure of up to $1,000,000 in fines and 20 years' imprisonment per violation. Treat gaps you find as priorities, not observations.
Steps 1–3: The Legal Foundation
Jurisdiction & Classification
Everything starts here: determine, item by item, whether your products and technical data are ITAR-controlled (on the U.S. Munitions List, 22 CFR 121.1) or EAR-controlled (Commerce Control List). Get this wrong and every downstream decision — registration, licensing, data handling — is built on sand; treating an ITAR item as EAR is itself a violation. Document a written classification rationale for each product family, and where the USML/CCL boundary is genuinely ambiguous, submit a Commodity Jurisdiction request to DDTC under 22 CFR 120.4 for a legally binding answer. Note that the September 2025 USML revisions changed 15 of 21 categories — classifications made before then need re-review against the current category text.
What good looks like
- A classification matrix covering every product, component, and data family — with the USML category/paragraph or ECCN and a written rationale
- CJ determinations on file for boundary items
- A documented re-review completed against the September 2025 USML revisions
DDTC Registration
If you manufacture, export, or temporarily import defense articles, or furnish defense services, you must register with DDTC under 22 CFR 122.1 — and manufacturers must register even if they never export. Registration runs through the DECCS portal via the DS-2032 Statement of Registration, with Tier 1 fees at $3,000/year under the January 2025 fee schedule and typical processing of 45–60 days. Registration is not a one-time event: it renews annually, and material changes to the business must be reported to DDTC under 22 CFR 122.4. Our step-by-step DDTC registration guide walks the full process.
What good looks like
- A current registration letter, with the correct fee tier
- Renewal calendared well before expiration, with an owner assigned
- Registration details that match the business as it exists today — entities, locations, and activities
Empowered Official Designation
Every registered company must designate an empowered official under 22 CFR 120.67 — a U.S.-person employee with the independent authority to inquire into any aspect of a proposed export, verify the legality of transactions, and refuse to sign a license application without fear of being overruled by sales pressure. The most common failure here is a paper designation: someone holds the title but lacks the seniority, training, or actual authority the regulation requires. The second most common failure is having no backup, so the program stalls whenever one person is on vacation.
What good looks like
- A formal, signed designation identifying the empowered official and their authority
- Documented empowered-official training beyond general awareness
- A trained backup, and organizational evidence the EO can actually halt a transaction
Steps 4–8: Build the Operating Controls
Written Compliance Program & Manual
"ITAR awareness" is not a compliance program. A defensible program is written down: a management commitment signed by leadership, an organizational chart showing who owns what, procedures for classification, licensing, data handling, screening, shipping, and violation response, and a schedule for reviewing the manual itself. The test is not elegance — it is whether the manual describes what your company actually does. A beautiful manual that doesn't match floor practice is worse than useless in an enforcement context, because it proves you knew the rules. See our compliance program development service for how we build these.
What good looks like
- A version-controlled compliance manual with a signed management commitment
- Procedures that match observed practice on the floor
- A documented risk assessment and a periodic review schedule that is actually followed
Technical Data Controls — Including IT
Technical data (22 CFR 120.33) is where modern ITAR violations actually happen — not at the border, but in file shares, email, and cloud tools. Controls need two layers. Physical and procedural: marking controlled documents, inventorying where technical data lives, and restricting access to authorized U.S. persons. And IT: access control lists, encryption of ITAR data in transit and at rest, audit logging, and cloud services that meet export-control requirements — mapped against NIST 800-171. The question that exposes most gaps: "Could a foreign-person employee or IT administrator open your engineering file share right now?" If you don't know, that is a finding.
What good looks like
- A technical data inventory: what exists, where it lives, who can access it
- Marking conventions applied consistently; encrypted transmission as the default
- Access reviews on a schedule, and no ITAR data in unapproved consumer cloud or personal email
Deemed-Export Screening
Under 22 CFR 120.17, disclosing technical data to a foreign person inside the United States is an export to that person's country of nationality. That makes personnel screening a compliance control, not an HR formality: you must know the U.S.-person status of everyone with potential access to controlled data — employees, contractors, interns, and visiting suppliers — before access is granted, and re-check when roles change. Facilities with foreign persons on site need a Technology Control Plan and visitor procedures (screening, logging, escorts, and controlled sight lines). Our deemed exports guide covers this risk in depth.
What good looks like
- Documented, lawful export-control screening at hire and at role change
- A written Technology Control Plan where foreign persons are present
- Visitor logs, escort rules, and authorization obtained before any foreign person accesses controlled data
License Determination Workflows
Every cross-border transfer — and every disclosure to a foreign person — needs a documented authorization decision before it happens: a license (such as a DSP-5), an agreement (TAA or MLA for defense services and technical data), or a specific, cited exemption under the regulations. A defensible program routes these decisions through a defined workflow ending at the empowered official, rather than leaving them to whoever is closest to the shipment. Exemption use is the quiet failure mode here: exemptions must be evaluated and documented per transaction, not assumed because "we used it last time." See our export licensing service for the license types and process.
What good looks like
- A written determination workflow every export request must pass through
- Shipments hold automatically until authorization is confirmed and provisos checked
- Per-transaction documentation of the license, agreement, or exemption relied upon
Subcontractor & Supply Chain Flow-Downs
ITAR responsibility does not stop at your shipping dock. If you pass controlled technical data or ITAR components to subcontractors, you must flow the obligations down — contractually (including DFARS 252.225-7048 where applicable) and practically: confirming subs are DDTC-registered when their work requires it, controlling how technical data transfers between you, and knowing whether your sub's workforce includes foreign persons. If you are the subcontractor, the mirror obligation applies: "the prime handles ITAR" is a myth — each entity in the chain carries independent legal responsibility for its own compliance.
What good looks like
- Export-control flow-down clauses in POs and subcontracts involving controlled items or data
- Verification of subcontractor registration and compliance posture before data transfers
- Controlled, documented channels for technical data exchange with the supply chain
Steps 9–12: Sustain and Defend the Program
Training Program
A program only the compliance officer understands is a program of one. Training must reach every function that can touch controlled articles or data — engineering, sales, HR, IT, shipping, and leadership — because deemed exports happen in design reviews and plant tours, not just at the border. A defensible training program is role-based, delivered at new hire before access is granted, refreshed on a regular cadence, and documented with rosters, agendas, and assessments. DDTC consent agreements routinely mandate training after violations; building it beforehand is both cheaper and evidence of good faith. Our ITAR training services page details modules, tracks, and formats.
What good looks like
- All-hands awareness training plus role-based deep-dives for high-exposure functions
- New-hire training completed before access to controlled data
- Rosters, versioned content, and assessment records retained with your compliance records
Recordkeeping — Five-Year Retention
ITAR requires records to be maintained for five years under 22 CFR 122.5 — covering the manufacture, acquisition, and disposition of defense articles and technical data, export authorizations, and DDTC correspondence. In practice, a defensible program applies that discipline to everything the other eleven steps generate: classification rationales, licenses and exemption citations, shipping documents, screening records, TCPs, training rosters, and audit reports. Retention is only half the requirement; the other half is retrieval. When a prime, an acquirer, or DDTC asks for the authorization behind a 2023 shipment, "we have it somewhere" is not an answer.
What good looks like
- A written retention schedule mapping each record type to the five-year rule
- Records organized for retrieval — any transaction reconstructible in hours, not weeks
- Electronic records managed with the same access controls as the technical data itself
Audits & Ongoing Monitoring
A compliance program that is never tested degrades silently: classifications drift out of date, screening lapses for contractors, exemptions get reused past their facts. Internal audits find these failures while they are still correctable — before a regulator, a prime's supplier audit, or an acquirer's due diligence finds them for you. Effective monitoring combines scheduled audits against this checklist, transaction sampling (pull ten shipments and trace each to its authorization), and corrective actions tracked to closure. Periodically, have someone independent of daily operations run the review — the person who built the process should not be its only examiner.
What good looks like
- An audit schedule with defined scope, and completed audit reports on file
- Findings logged with owners and deadlines, tracked to verified closure
- Periodic independent review — internal audit function or external consultant
Violation Response & Voluntary Disclosure Readiness
The final test of a program is what happens on a bad day. Employees need a clear, blame-tolerant channel to report a suspected violation internally — a workforce afraid to report converts small problems into buried ones. Leadership needs a pre-built response plan: freeze the transaction, preserve evidence, engage counsel, and assess scope before anyone "fixes" anything. And the company needs to understand the voluntary disclosure mechanism of 22 CFR 127.12 before it ever needs it: self-reporting is treated as a significant mitigating factor, while violations DDTC discovers on its own are penalized far more severely. Deciding your disclosure philosophy during a crisis is too late.
What good looks like
- A written incident response procedure naming roles, first calls, and evidence-preservation steps
- An internal reporting channel employees know about and trust
- Outside counsel and an ITAR consultant identified in advance — not searched for mid-crisis
What "Defensible" Actually Means
Run down the twelve steps and count the ones you scored "in place and documented." A program is defensible when every step passes a simple test: could you hand a regulator the evidence today? Not describe the practice — produce the document. The classification matrix, the registration letter, the EO designation, the manual, the data inventory, the screening records, the license file, the flow-down clauses, the training rosters, the retention schedule, the audit reports, the response plan. Enforcement outcomes turn on this distinction: DDTC treats a documented, genuinely operated program as evidence of good faith, and its absence as an aggravating fact.
Most companies that work through this checklist honestly find they are strong in two or three areas and exposed in the rest — typically technical data IT controls, deemed-export screening, and audit cadence. That is normal, and it is fixable in priority order. What is not fixable retroactively is doing nothing until a prime's audit, an acquisition, or a DDTC inquiry forces the question.
A self-assessment tells you where you think you stand. A professional gap analysis tells you where you actually stand — step by step, against your real transactions, data flows, and records, with findings prioritized by risk. Jared Clark, JD, has run this review across 200+ client engagements, and his clients maintain a 100% first-time audit pass rate.
ITAR Compliance Checklist FAQ
About the Author
Jared Clark, JD, MBA, PMP, CMQ-OE
Jared Clark is an ITAR compliance consultant and export control expert with hands-on experience guiding 200+ clients through DDTC registration, compliance program development, USML classification, export licensing, and voluntary disclosure. Holding a Juris Doctor (JD), MBA, Project Management Professional (PMP) certification from PMI, and Certified Manager of Quality/Organizational Excellence (CMQ-OE) designation from ASQ, Jared brings legal, business, project management, and quality systems expertise to every engagement. His clients maintain a 100% first-time audit pass rate.
For broader certification consulting across ISO, GMP, and other regulatory frameworks, visit our parent practice at certify.consulting.