Compliance Self-Assessment

ITAR Compliance Checklist:
12 Steps to a Defensible Program

By Jared Clark, JD, MBA, PMP, CMQ-OE · Updated July 2026 · ~14 min read

200+
Clients Served
100%
Audit Pass Rate
JD, CMQ-OE
Expert Credentials

A defensible ITAR compliance program covers twelve areas: (1) jurisdiction and USML classification, (2) DDTC registration, (3) empowered official designation, (4) a written compliance program, (5) technical data controls including IT security, (6) deemed-export screening, (7) license determination workflows, (8) subcontractor flow-downs, (9) training, (10) recordkeeping with five-year retention under 22 CFR 122.5, (11) audits and monitoring, and (12) violation response and voluntary disclosure readiness. "Defensible" means one thing: if DDTC examined your program tomorrow, you could produce documented evidence for every step — not intentions, not awareness, but records.

How to Use This Checklist

This checklist is a working self-assessment, not a reading exercise. For each of the twelve steps, score your company honestly: in place and documented, partially in place, or missing. The "what good looks like" criteria under each step describe the evidence a regulator, a prime contractor, or an acquirer would ask to see — if you cannot produce the document, the honest score is not "in place."

Work the steps in order. The sequence is deliberate: you cannot make license determinations for items you haven't classified, and you cannot designate an empowered official for a company that isn't registered. Steps 1–3 are legal prerequisites, steps 4–8 are the operating controls, and steps 9–12 are what keep the program alive and defensible year after year. If you are new to the regulations entirely, read our definitive guide to what ITAR is first — this checklist assumes you know you are, or may be, subject to 22 CFR Parts 120–130.

One warning before you begin: the stakes for getting this wrong are civil penalties up to $1,267,619 per violation and criminal exposure of up to $1,000,000 in fines and 20 years' imprisonment per violation. Treat gaps you find as priorities, not observations.

Steps 1–3: The Legal Foundation

1

Jurisdiction & Classification

Everything starts here: determine, item by item, whether your products and technical data are ITAR-controlled (on the U.S. Munitions List, 22 CFR 121.1) or EAR-controlled (Commerce Control List). Get this wrong and every downstream decision — registration, licensing, data handling — is built on sand; treating an ITAR item as EAR is itself a violation. Document a written classification rationale for each product family, and where the USML/CCL boundary is genuinely ambiguous, submit a Commodity Jurisdiction request to DDTC under 22 CFR 120.4 for a legally binding answer. Note that the September 2025 USML revisions changed 15 of 21 categories — classifications made before then need re-review against the current category text.

What good looks like

  • A classification matrix covering every product, component, and data family — with the USML category/paragraph or ECCN and a written rationale
  • CJ determinations on file for boundary items
  • A documented re-review completed against the September 2025 USML revisions
2

DDTC Registration

If you manufacture, export, or temporarily import defense articles, or furnish defense services, you must register with DDTC under 22 CFR 122.1 — and manufacturers must register even if they never export. Registration runs through the DECCS portal via the DS-2032 Statement of Registration, with Tier 1 fees at $3,000/year under the January 2025 fee schedule and typical processing of 45–60 days. Registration is not a one-time event: it renews annually, and material changes to the business must be reported to DDTC under 22 CFR 122.4. Our step-by-step DDTC registration guide walks the full process.

What good looks like

  • A current registration letter, with the correct fee tier
  • Renewal calendared well before expiration, with an owner assigned
  • Registration details that match the business as it exists today — entities, locations, and activities
3

Empowered Official Designation

Every registered company must designate an empowered official under 22 CFR 120.67 — a U.S.-person employee with the independent authority to inquire into any aspect of a proposed export, verify the legality of transactions, and refuse to sign a license application without fear of being overruled by sales pressure. The most common failure here is a paper designation: someone holds the title but lacks the seniority, training, or actual authority the regulation requires. The second most common failure is having no backup, so the program stalls whenever one person is on vacation.

What good looks like

  • A formal, signed designation identifying the empowered official and their authority
  • Documented empowered-official training beyond general awareness
  • A trained backup, and organizational evidence the EO can actually halt a transaction

Steps 4–8: Build the Operating Controls

4

Written Compliance Program & Manual

"ITAR awareness" is not a compliance program. A defensible program is written down: a management commitment signed by leadership, an organizational chart showing who owns what, procedures for classification, licensing, data handling, screening, shipping, and violation response, and a schedule for reviewing the manual itself. The test is not elegance — it is whether the manual describes what your company actually does. A beautiful manual that doesn't match floor practice is worse than useless in an enforcement context, because it proves you knew the rules. See our compliance program development service for how we build these.

What good looks like

  • A version-controlled compliance manual with a signed management commitment
  • Procedures that match observed practice on the floor
  • A documented risk assessment and a periodic review schedule that is actually followed
5

Technical Data Controls — Including IT

Technical data (22 CFR 120.33) is where modern ITAR violations actually happen — not at the border, but in file shares, email, and cloud tools. Controls need two layers. Physical and procedural: marking controlled documents, inventorying where technical data lives, and restricting access to authorized U.S. persons. And IT: access control lists, encryption of ITAR data in transit and at rest, audit logging, and cloud services that meet export-control requirements — mapped against NIST 800-171. The question that exposes most gaps: "Could a foreign-person employee or IT administrator open your engineering file share right now?" If you don't know, that is a finding.

What good looks like

  • A technical data inventory: what exists, where it lives, who can access it
  • Marking conventions applied consistently; encrypted transmission as the default
  • Access reviews on a schedule, and no ITAR data in unapproved consumer cloud or personal email
6

Deemed-Export Screening

Under 22 CFR 120.17, disclosing technical data to a foreign person inside the United States is an export to that person's country of nationality. That makes personnel screening a compliance control, not an HR formality: you must know the U.S.-person status of everyone with potential access to controlled data — employees, contractors, interns, and visiting suppliers — before access is granted, and re-check when roles change. Facilities with foreign persons on site need a Technology Control Plan and visitor procedures (screening, logging, escorts, and controlled sight lines). Our deemed exports guide covers this risk in depth.

What good looks like

  • Documented, lawful export-control screening at hire and at role change
  • A written Technology Control Plan where foreign persons are present
  • Visitor logs, escort rules, and authorization obtained before any foreign person accesses controlled data
7

License Determination Workflows

Every cross-border transfer — and every disclosure to a foreign person — needs a documented authorization decision before it happens: a license (such as a DSP-5), an agreement (TAA or MLA for defense services and technical data), or a specific, cited exemption under the regulations. A defensible program routes these decisions through a defined workflow ending at the empowered official, rather than leaving them to whoever is closest to the shipment. Exemption use is the quiet failure mode here: exemptions must be evaluated and documented per transaction, not assumed because "we used it last time." See our export licensing service for the license types and process.

What good looks like

  • A written determination workflow every export request must pass through
  • Shipments hold automatically until authorization is confirmed and provisos checked
  • Per-transaction documentation of the license, agreement, or exemption relied upon
8

Subcontractor & Supply Chain Flow-Downs

ITAR responsibility does not stop at your shipping dock. If you pass controlled technical data or ITAR components to subcontractors, you must flow the obligations down — contractually (including DFARS 252.225-7048 where applicable) and practically: confirming subs are DDTC-registered when their work requires it, controlling how technical data transfers between you, and knowing whether your sub's workforce includes foreign persons. If you are the subcontractor, the mirror obligation applies: "the prime handles ITAR" is a myth — each entity in the chain carries independent legal responsibility for its own compliance.

What good looks like

  • Export-control flow-down clauses in POs and subcontracts involving controlled items or data
  • Verification of subcontractor registration and compliance posture before data transfers
  • Controlled, documented channels for technical data exchange with the supply chain

Steps 9–12: Sustain and Defend the Program

9

Training Program

A program only the compliance officer understands is a program of one. Training must reach every function that can touch controlled articles or data — engineering, sales, HR, IT, shipping, and leadership — because deemed exports happen in design reviews and plant tours, not just at the border. A defensible training program is role-based, delivered at new hire before access is granted, refreshed on a regular cadence, and documented with rosters, agendas, and assessments. DDTC consent agreements routinely mandate training after violations; building it beforehand is both cheaper and evidence of good faith. Our ITAR training services page details modules, tracks, and formats.

What good looks like

  • All-hands awareness training plus role-based deep-dives for high-exposure functions
  • New-hire training completed before access to controlled data
  • Rosters, versioned content, and assessment records retained with your compliance records
10

Recordkeeping — Five-Year Retention

ITAR requires records to be maintained for five years under 22 CFR 122.5 — covering the manufacture, acquisition, and disposition of defense articles and technical data, export authorizations, and DDTC correspondence. In practice, a defensible program applies that discipline to everything the other eleven steps generate: classification rationales, licenses and exemption citations, shipping documents, screening records, TCPs, training rosters, and audit reports. Retention is only half the requirement; the other half is retrieval. When a prime, an acquirer, or DDTC asks for the authorization behind a 2023 shipment, "we have it somewhere" is not an answer.

What good looks like

  • A written retention schedule mapping each record type to the five-year rule
  • Records organized for retrieval — any transaction reconstructible in hours, not weeks
  • Electronic records managed with the same access controls as the technical data itself
11

Audits & Ongoing Monitoring

A compliance program that is never tested degrades silently: classifications drift out of date, screening lapses for contractors, exemptions get reused past their facts. Internal audits find these failures while they are still correctable — before a regulator, a prime's supplier audit, or an acquirer's due diligence finds them for you. Effective monitoring combines scheduled audits against this checklist, transaction sampling (pull ten shipments and trace each to its authorization), and corrective actions tracked to closure. Periodically, have someone independent of daily operations run the review — the person who built the process should not be its only examiner.

What good looks like

  • An audit schedule with defined scope, and completed audit reports on file
  • Findings logged with owners and deadlines, tracked to verified closure
  • Periodic independent review — internal audit function or external consultant
12

Violation Response & Voluntary Disclosure Readiness

The final test of a program is what happens on a bad day. Employees need a clear, blame-tolerant channel to report a suspected violation internally — a workforce afraid to report converts small problems into buried ones. Leadership needs a pre-built response plan: freeze the transaction, preserve evidence, engage counsel, and assess scope before anyone "fixes" anything. And the company needs to understand the voluntary disclosure mechanism of 22 CFR 127.12 before it ever needs it: self-reporting is treated as a significant mitigating factor, while violations DDTC discovers on its own are penalized far more severely. Deciding your disclosure philosophy during a crisis is too late.

What good looks like

  • A written incident response procedure naming roles, first calls, and evidence-preservation steps
  • An internal reporting channel employees know about and trust
  • Outside counsel and an ITAR consultant identified in advance — not searched for mid-crisis

What "Defensible" Actually Means

Run down the twelve steps and count the ones you scored "in place and documented." A program is defensible when every step passes a simple test: could you hand a regulator the evidence today? Not describe the practice — produce the document. The classification matrix, the registration letter, the EO designation, the manual, the data inventory, the screening records, the license file, the flow-down clauses, the training rosters, the retention schedule, the audit reports, the response plan. Enforcement outcomes turn on this distinction: DDTC treats a documented, genuinely operated program as evidence of good faith, and its absence as an aggravating fact.

Most companies that work through this checklist honestly find they are strong in two or three areas and exposed in the rest — typically technical data IT controls, deemed-export screening, and audit cadence. That is normal, and it is fixable in priority order. What is not fixable retroactively is doing nothing until a prime's audit, an acquisition, or a DDTC inquiry forces the question.

Want This Reviewed Against Your Operations?

A self-assessment tells you where you think you stand. A professional gap analysis tells you where you actually stand — step by step, against your real transactions, data flows, and records, with findings prioritized by risk. Jared Clark, JD, has run this review across 200+ client engagements, and his clients maintain a 100% first-time audit pass rate.

ITAR Compliance Checklist FAQ

Work the steps in the order presented — the sequence is deliberate. Jurisdiction and classification come first because every other obligation depends on whether your items are ITAR-controlled at all. DDTC registration and empowered official designation come next because they are legal prerequisites to defense trade activity. The written program and operational controls (technical data, deemed exports, licensing, flow-downs) build on that foundation, and training, recordkeeping, audits, and violation response sustain the program over time. Skipping ahead — for example, filing license applications before classification is nailed down — is how companies build programs on sand.
No. There is no government-issued ITAR certification. Companies register with DDTC under 22 CFR 122.1 — registration is a legal obligation, not a certification — and then remain responsible for their own ongoing compliance. When a prime contractor asks whether you are "ITAR compliant," what they actually want is evidence of the elements in this checklist: active registration, an empowered official, a written compliance program, technical data controls, screening, training, and records. A completed, documented checklist is the honest answer to that question.
ITAR records must be maintained for five years under 22 CFR 122.5. That retention obligation covers records related to the manufacture, acquisition, and disposition of defense articles, defense services, and technical data — including export authorizations and correspondence with DDTC. In practice, a defensible program applies the five-year discipline across licenses and exemption citations, shipping documentation, screening records, training rosters, and audit reports, and can retrieve any of them quickly when a prime, an auditor, or DDTC asks.
Stop, preserve the evidence, and escalate — do not quietly fix the process and move on. ITAR provides a voluntary disclosure mechanism under 22 CFR 127.12, and voluntary disclosure is treated as a strong mitigating factor in DDTC enforcement decisions; violations discovered by the government rather than self-reported are penalized far more severely. Engage legal counsel and an experienced ITAR consultant immediately to assess whether what you found is actually a violation, scope it accurately, and manage the disclosure decision deliberately.
Yes — every step, scaled to your size. A 15-person machine shop does not need the compliance infrastructure of a defense prime, but it does need every element on this checklist in some proportionate form: its items classified, its DDTC registration active if it manufactures defense articles (required under 22 CFR 122.1 even with no exports), an empowered official, written procedures, controlled technical data, screening, license discipline, flow-down awareness, training, five-year records, periodic self-review, and a plan for handling potential violations. ITAR's penalties do not scale down for company size, so the program cannot be skipped — only right-sized.
JC

About the Author

Jared Clark, JD, MBA, PMP, CMQ-OE

Jared Clark is an ITAR compliance consultant and export control expert with hands-on experience guiding 200+ clients through DDTC registration, compliance program development, USML classification, export licensing, and voluntary disclosure. Holding a Juris Doctor (JD), MBA, Project Management Professional (PMP) certification from PMI, and Certified Manager of Quality/Organizational Excellence (CMQ-OE) designation from ASQ, Jared brings legal, business, project management, and quality systems expertise to every engagement. His clients maintain a 100% first-time audit pass rate.

For broader certification consulting across ISO, GMP, and other regulatory frameworks, visit our parent practice at certify.consulting.

JD MBA PMP CMQ-OE

Want This Checklist Reviewed Against Your Operations?

Schedule a free 30-minute consultation. We will walk the twelve steps against your actual program, flag the gaps that matter most, and outline a prioritized path to a defensible program — no obligation, no pressure.

Or email us at [email protected]