ITAR Training Services

ITAR Compliance Training
for Your Team

By Jared Clark, JD, MBA, PMP, CMQ-OE · Updated July 2026 · ~12 min read

200+
Clients Served
100%
Audit Pass Rate
JD, CMQ-OE
Expert Credentials

ITAR compliance training is a required pillar of any defensible export compliance program. Companies subject to the International Traffic in Arms Regulations (22 CFR Parts 120–130) must ensure that every employee who touches defense articles or ITAR-controlled technical data — engineering, sales, HR, IT, and shipping, not just the export desk — understands their obligations. DDTC consent agreements routinely mandate formal training as a remedial condition after violations; building the program before enforcement is dramatically cheaper than building it under a consent agreement. We deliver ITAR training as an on-site workshop, live virtual session, or fully custom program — designed and taught by Jared Clark, JD, a practicing ITAR compliance consultant.

Why Training Is a Pillar of an ITAR Compliance Program

An ITAR compliance program lives or dies on the judgment of individual employees. Your DDTC registration is a legal prerequisite and your written compliance manual defines the rules — but neither one stops an engineer from emailing a drawing to an overseas supplier, or a salesperson from walking a foreign visitor past an open CAD screen. Documents don't prevent violations. Trained people do.

That is why training appears in every serious articulation of what an export compliance program must contain. When DDTC evaluates a company's compliance posture — whether in a voluntary disclosure review, a compliance program assessment, or an enforcement proceeding — a documented training program is one of the elements it expects to find. And when DDTC resolves enforcement actions through consent agreements, those agreements routinely mandate formal, recurring ITAR training as a condition of settlement, often under the eye of an external compliance monitor. In other words: if you don't build a training program voluntarily, a consent agreement may eventually build one for you — on the government's terms, on the government's schedule, and at far greater cost.

Training also functions as evidence. In an enforcement context, the question is rarely just "did a violation occur?" but "what kind of company allowed it to occur?" A company that can produce rosters, dated agendas, and assessment records demonstrating a genuine effort to educate its workforce is in a fundamentally different negotiating position than a company whose employees were never told what technical data is. The stakes justify the effort: civil penalties reach $1,267,619 per violation, and criminal violations carry fines up to $1,000,000 and imprisonment up to 20 years. Against numbers like those, training is the cheapest risk control you will ever buy.

The Untrained-Employee Problem

Across 200+ client engagements, the compliance gaps we find most often do not come from bad intent — they come from employees who never learned that the thing they handle every day is ITAR-controlled. An engineer who doesn't know a test report is technical data cannot protect it. Training closes the gap between the compliance manual on the shelf and the decisions made on the floor.

If you are still building the foundational elements of your program — classification, registration, written procedures — start with our ITAR compliance checklist and our guide to what ITAR is and who must comply. Training is most effective when it teaches employees to operate procedures that actually exist.

Who Needs ITAR Training (Hint: Not Just Your Export Staff)

The single most common training mistake is scoping it to the "export people" — the shipping manager and the compliance coordinator — while the rest of the company operates untrained. That scoping fails because of one concept: the deemed export. Under 22 CFR 120.17, releasing ITAR-controlled technical data to a foreign person inside the United States is an export to that person's country of nationality. Deemed exports don't happen at the loading dock. They happen in engineering meetings, in shared file systems, on factory tours, and in job interviews. Every function that can disclose technical data can commit a violation, and every function that can commit a violation needs training.

Engineering and Product Development

Engineers carry the heaviest technical data exposure in the company. Design reviews, CAD models, test reports, supplier technical calls, and collaboration platforms are all potential release points. An engineering team that includes or interacts with foreign persons — employees, contractors, interns, or joint-venture counterparts — is one unguarded screen-share away from a deemed export. Engineering training focuses on recognizing technical data under 22 CFR 120.33, handling it inside approved systems, and knowing when a conversation must stop until authorization is confirmed.

Sales and Business Development

Sales teams generate export risk before a product ever ships: proposals that include controlled specifications, trade show conversations with foreign buyers, demo requests, and technical Q&A during pre-sales. Sales training covers the line between permissible marketing information and controlled technical data, red flags in customer inquiries, and why "the customer is in a hurry" is never a reason to skip a license determination.

Human Resources and Recruiting

HR sits at the gate of the deemed-export problem. Hiring a foreign person into a role with access to ITAR technical data creates licensing obligations before that employee's first day. HR training covers lawful export-control screening during hiring, coordinating role assignments with the empowered official, onboarding and offboarding controls, and maintaining screening records — all while staying inside anti-discrimination boundaries, which is exactly the kind of legal seam where JD-level guidance matters.

Information Technology

IT administrators control where technical data lives and who can reach it. Their training covers access control lists, encryption of ITAR data in transit and at rest, cloud storage rules, mapping to NIST 800-171 controls, and the frequently missed risk of foreign-person system administrators — a person who can read the file server can receive a deemed export, whether or not they ever open a drawing.

Shipping, Logistics, and Receiving

The traditional export function still matters. Shipping training covers verifying that an export authorization exists before anything moves, matching shipments to license provisos, export documentation, and holding shipments when paperwork doesn't line up. Receiving matters too: temporary imports of defense articles are ITAR-regulated activity.

Executives and the Empowered Official

Leadership sets the compliance culture, signs the management commitment, and owns the budget. The empowered official (22 CFR 120.67) carries personal responsibilities — signing license applications, verifying compliance, attesting to DDTC submissions — that demand training well beyond general awareness. Executive training focuses on enforcement exposure, resourcing decisions, and what the empowered official's independent authority means in practice.

Core Training Modules

Our curriculum is built from six core modules. Every engagement assembles these modules — adjusted to your products, your USML categories, and your data flows — rather than delivering a generic slide deck that could apply to any company.

Module 1 — ITAR Fundamentals
The regulatory architecture of 22 CFR Parts 120–130: what a defense article, defense service, and technical data are; how the USML's 21 categories work; why DDTC registration exists; and the civil and criminal penalty landscape. This module gives every employee the shared vocabulary the rest of the program depends on.
Module 2 — Technical Data Handling
What is and is not technical data under 22 CFR 120.33 — drawings, specifications, test results, source code, and manuals versus general marketing material and public-domain science. Marking conventions, approved storage locations, transmission rules (including encryption expectations), and what to do when data arrives unmarked.
Module 3 — Deemed Exports
The rule that surprises every new hire: disclosure to a foreign person in the U.S. is an export (22 CFR 120.17). Who counts as a U.S. person, how Technology Control Plans work, and the everyday situations — meetings, screen-shares, shared drives — where deemed exports actually occur. See our dedicated deemed exports guide for the full treatment.
Module 4 — ITAR and Visitors / Foreign Persons On-Site
Facility-level controls: visitor screening and logging, escort requirements, what a foreign visitor may and may not see on a plant tour, conference and supplier-visit protocols, and how to decline a disclosure politely but firmly. This module is scenario-heavy because visitor incidents are judgment calls made in real time.
Module 5 — Recordkeeping
What ITAR requires you to keep and for how long — including the five-year retention requirement of 22 CFR 122.5 — which records each role generates (screening logs, shipping documents, license correspondence, training rosters), and how retention failures turn small problems into enforcement findings.
Module 6 — Red Flags and Escalation
Recognizing diversion indicators and suspicious inquiries: buyers indifferent to specifications, unusual routing or payment, requests to omit documentation, pressure to bypass process. Most importantly: exactly who to call and how to freeze a transaction. A trained employee's most valuable skill is knowing when to stop.

Role-Based Training Tracks

Not everyone needs the same depth. A receptionist who signs in visitors needs awareness; an engineer exchanging data with a foreign supplier needs working proficiency; your empowered official needs command of the regulations. We structure engagements into three tracks so each audience gets the depth its risk exposure demands — and no one sits through material irrelevant to their job.

Track Audience Content Focus
All-Hands Awareness Every employee at an ITAR-registered company Modules 1 and 3 in condensed form: what ITAR is, what technical data looks like, the deemed-export rule, and how to escalate. Establishes the baseline DDTC expects across the workforce.
Practitioner Deep-Dive Engineering, sales, HR, IT, shipping Full modules relevant to the function, taught with the department's actual workflows and scenario exercises drawn from their day-to-day work. Engineering gets technical data handling in depth; HR gets screening; IT gets systems controls; shipping gets authorization verification.
Leadership & Empowered Official Executives, empowered officials, compliance owners Regulatory obligations of the empowered official under 22 CFR 120.67, enforcement landscape and penalty exposure, voluntary disclosure decision-making, resourcing the program, and governance of the training program itself.

Role-based structure is not just pedagogy — it is what a mature program looks like from the outside. When DDTC reviews training records that show differentiated content by role, it sees a company that understood its own risk map rather than one that bought a video and pressed play.

Delivery Formats: On-Site, Live Virtual, or Custom Program

On-Site Workshop

We come to your facility and teach in the environment where the risks actually live. On-site delivery allows a walkthrough of your floor — where visitors enter, where controlled drawings sit, where the shipping desk verifies licenses — and turns abstract rules into concrete, local practice. Scenario exercises use your products and your data flows. On-site works best for single-site manufacturers and for companies launching their first formal training cycle, where face-to-face Q&A surfaces the compliance questions employees have been sitting on.

Live Virtual Training

Live virtual sessions deliver the same modules, the same scenario exercises, and the same open Q&A over video conference — taught live by the instructor, never pre-recorded. Virtual delivery suits distributed teams, multi-site companies, and annual refresher cycles where travel cost isn't justified. Attendance and assessments are captured identically to on-site sessions, so your documentation is just as defensible.

Custom Training Program

For companies that want a durable internal capability, we build a complete program around your operation: curriculum mapped to your USML categories and license portfolio, role-track definitions, assessment questions, acknowledgment forms, a new-hire and refresher schedule, and train-the-trainer support so your compliance staff can sustain the cycle internally. The deliverable is not a training event — it is a training system your program can run for years.

Pricing: every training engagement is scoped to your program — headcount, role tracks, format, and documentation deliverables. Request a quote or call 858-240-4353 and we will scope it in one conversation.

Documenting Training the Way DDTC Expects

From a regulator's perspective, undocumented training never happened. If DDTC reviews your program — in a disclosure, an audit, or a compliance assessment — the training pillar is evaluated through its records. Every engagement we deliver produces the documentation set that review will ask for:

  • Attendance rosters — who attended each session, with dates and delivery format
  • Content records — versioned agendas and materials showing exactly what was taught and when the curriculum was last updated for regulatory change
  • Assessments — evidence that understanding was verified, not just that attendance occurred
  • Acknowledgments — signed employee acknowledgments of ITAR obligations
  • Schedule and coverage tracking — new-hire training completed before access to controlled data, refreshers on cadence, and no coverage gaps as people change roles

Retain training records within your ITAR recordkeeping system alongside your other compliance records — the same discipline that governs licenses and shipping documents under 22 CFR 122.5 should govern the records that prove your people were trained. Step 9 of our 12-step ITAR compliance checklist covers where training sits in the overall program.

Your Instructor: A JD Who Practices ITAR Compliance Daily

ITAR is not a best-practice framework — it is federal law, administered by the State Department under the Arms Export Control Act, with criminal prosecution exposure. That is why it matters that your instructor reads the regulations the way counsel reads them. Jared Clark holds a Juris Doctor (JD) alongside an MBA, PMP, and CMQ-OE, and teaches ITAR as what it is: a legal regime where the words of 22 CFR carry consequences, not a checkbox exercise.

Just as important: this is training delivered by a practicing ITAR consultant, not a professional lecturer. The scenarios in class come from active consulting work — registrations, classification reviews, technology control plans, and disclosure engagements across 200+ client relationships. When an engineer asks "what about the situation where our supplier's engineer joins the call?", the answer comes from someone who has handled that exact situation, under the current regulations, including the September 2025 USML revisions that reshaped 15 of 21 categories. Your team gets answers, not "let me check on that."

Training is also where compliance programs reveal their other gaps. Because your instructor is the same consultant who builds full ITAR compliance programs, the questions your team asks in session often surface issues — an unscreened contractor population, an unmarked drawing library — that can be fixed before they become disclosure material.

ITAR Training FAQ

Every employee who can access defense articles or ITAR-controlled technical data needs training — not just the export compliance staff. In practice that means engineering and product development (the heaviest technical data exposure), sales and business development, HR and recruiting, IT administrators, shipping and logistics, and executives. Deemed exports under 22 CFR 120.17 occur wherever technical data is disclosed to a foreign person, which is why an engineer in a design review needs ITAR awareness just as much as the person filing the export paperwork.
ITAR does not prescribe a statutory training interval, but annual refresher training is the accepted industry standard and the cadence DDTC expects to see documented in a mature compliance program. Beyond the annual cycle, training should be delivered at new hire (before access to controlled data is granted), when an employee changes roles, and whenever the regulations change materially — for example, the September 2025 USML revisions that affected 15 of 21 categories warranted an update to classification-related training content.
No. There is no government-issued ITAR certification for individuals or companies. DDTC registration under 22 CFR 122.1 is a legal requirement, not a certification, and no training provider can make your company "ITAR certified." What matters to DDTC is evidence: a documented training program showing who was trained, on what content, when, and how understanding was verified. Be cautious of vendors selling "ITAR certification" — the credential that protects you in an enforcement context is your own training records, not a certificate.
Training engagements are scoped to your program — headcount, number of role-based tracks, delivery format (on-site workshop, live virtual, or custom program), and whether you need supporting materials such as assessment questions and acknowledgment forms. Request a quote and we will scope a program to your operations. Every engagement includes documentation deliverables — rosters, agendas, and assessment records — so the training is defensible, not just delivered.
Yes. Live virtual training delivers the same modules, scenario exercises, and Q&A as an on-site workshop, and works well for distributed teams and multi-site companies. Sessions are led live by the instructor — not pre-recorded videos — so employees can ask questions about their actual work situations. Attendance and assessment records are captured the same way as on-site sessions, so your documentation for DDTC purposes is identical.
JC

About the Author

Jared Clark, JD, MBA, PMP, CMQ-OE

Jared Clark is an ITAR compliance consultant and export control expert with hands-on experience guiding 200+ clients through DDTC registration, compliance program development, USML classification, export licensing, and voluntary disclosure. Holding a Juris Doctor (JD), MBA, Project Management Professional (PMP) certification from PMI, and Certified Manager of Quality/Organizational Excellence (CMQ-OE) designation from ASQ, Jared brings legal, business, project management, and quality systems expertise to every engagement. His clients maintain a 100% first-time audit pass rate.

For broader certification consulting across ISO, GMP, and other regulatory frameworks, visit our parent practice at certify.consulting.

JD MBA PMP CMQ-OE

Ready to Train Your Team on ITAR?

Schedule a free 30-minute consultation. We will map your roles and risk exposure, recommend the right tracks and format, and scope a training program for your operation — no obligation, no pressure.

Or email us at [email protected]