Why Training Is a Pillar of an ITAR Compliance Program
An ITAR compliance program lives or dies on the judgment of individual employees. Your DDTC registration is a legal prerequisite and your written compliance manual defines the rules — but neither one stops an engineer from emailing a drawing to an overseas supplier, or a salesperson from walking a foreign visitor past an open CAD screen. Documents don't prevent violations. Trained people do.
That is why training appears in every serious articulation of what an export compliance program must contain. When DDTC evaluates a company's compliance posture — whether in a voluntary disclosure review, a compliance program assessment, or an enforcement proceeding — a documented training program is one of the elements it expects to find. And when DDTC resolves enforcement actions through consent agreements, those agreements routinely mandate formal, recurring ITAR training as a condition of settlement, often under the eye of an external compliance monitor. In other words: if you don't build a training program voluntarily, a consent agreement may eventually build one for you — on the government's terms, on the government's schedule, and at far greater cost.
Training also functions as evidence. In an enforcement context, the question is rarely just "did a violation occur?" but "what kind of company allowed it to occur?" A company that can produce rosters, dated agendas, and assessment records demonstrating a genuine effort to educate its workforce is in a fundamentally different negotiating position than a company whose employees were never told what technical data is. The stakes justify the effort: civil penalties reach $1,267,619 per violation, and criminal violations carry fines up to $1,000,000 and imprisonment up to 20 years. Against numbers like those, training is the cheapest risk control you will ever buy.
If you are still building the foundational elements of your program — classification, registration, written procedures — start with our ITAR compliance checklist and our guide to what ITAR is and who must comply. Training is most effective when it teaches employees to operate procedures that actually exist.
Who Needs ITAR Training (Hint: Not Just Your Export Staff)
The single most common training mistake is scoping it to the "export people" — the shipping manager and the compliance coordinator — while the rest of the company operates untrained. That scoping fails because of one concept: the deemed export. Under 22 CFR 120.17, releasing ITAR-controlled technical data to a foreign person inside the United States is an export to that person's country of nationality. Deemed exports don't happen at the loading dock. They happen in engineering meetings, in shared file systems, on factory tours, and in job interviews. Every function that can disclose technical data can commit a violation, and every function that can commit a violation needs training.
Engineering and Product Development
Engineers carry the heaviest technical data exposure in the company. Design reviews, CAD models, test reports, supplier technical calls, and collaboration platforms are all potential release points. An engineering team that includes or interacts with foreign persons — employees, contractors, interns, or joint-venture counterparts — is one unguarded screen-share away from a deemed export. Engineering training focuses on recognizing technical data under 22 CFR 120.33, handling it inside approved systems, and knowing when a conversation must stop until authorization is confirmed.
Sales and Business Development
Sales teams generate export risk before a product ever ships: proposals that include controlled specifications, trade show conversations with foreign buyers, demo requests, and technical Q&A during pre-sales. Sales training covers the line between permissible marketing information and controlled technical data, red flags in customer inquiries, and why "the customer is in a hurry" is never a reason to skip a license determination.
Human Resources and Recruiting
HR sits at the gate of the deemed-export problem. Hiring a foreign person into a role with access to ITAR technical data creates licensing obligations before that employee's first day. HR training covers lawful export-control screening during hiring, coordinating role assignments with the empowered official, onboarding and offboarding controls, and maintaining screening records — all while staying inside anti-discrimination boundaries, which is exactly the kind of legal seam where JD-level guidance matters.
Information Technology
IT administrators control where technical data lives and who can reach it. Their training covers access control lists, encryption of ITAR data in transit and at rest, cloud storage rules, mapping to NIST 800-171 controls, and the frequently missed risk of foreign-person system administrators — a person who can read the file server can receive a deemed export, whether or not they ever open a drawing.
Shipping, Logistics, and Receiving
The traditional export function still matters. Shipping training covers verifying that an export authorization exists before anything moves, matching shipments to license provisos, export documentation, and holding shipments when paperwork doesn't line up. Receiving matters too: temporary imports of defense articles are ITAR-regulated activity.
Executives and the Empowered Official
Leadership sets the compliance culture, signs the management commitment, and owns the budget. The empowered official (22 CFR 120.67) carries personal responsibilities — signing license applications, verifying compliance, attesting to DDTC submissions — that demand training well beyond general awareness. Executive training focuses on enforcement exposure, resourcing decisions, and what the empowered official's independent authority means in practice.
Core Training Modules
Our curriculum is built from six core modules. Every engagement assembles these modules — adjusted to your products, your USML categories, and your data flows — rather than delivering a generic slide deck that could apply to any company.
Role-Based Training Tracks
Not everyone needs the same depth. A receptionist who signs in visitors needs awareness; an engineer exchanging data with a foreign supplier needs working proficiency; your empowered official needs command of the regulations. We structure engagements into three tracks so each audience gets the depth its risk exposure demands — and no one sits through material irrelevant to their job.
| Track | Audience | Content Focus |
|---|---|---|
| All-Hands Awareness | Every employee at an ITAR-registered company | Modules 1 and 3 in condensed form: what ITAR is, what technical data looks like, the deemed-export rule, and how to escalate. Establishes the baseline DDTC expects across the workforce. |
| Practitioner Deep-Dive | Engineering, sales, HR, IT, shipping | Full modules relevant to the function, taught with the department's actual workflows and scenario exercises drawn from their day-to-day work. Engineering gets technical data handling in depth; HR gets screening; IT gets systems controls; shipping gets authorization verification. |
| Leadership & Empowered Official | Executives, empowered officials, compliance owners | Regulatory obligations of the empowered official under 22 CFR 120.67, enforcement landscape and penalty exposure, voluntary disclosure decision-making, resourcing the program, and governance of the training program itself. |
Role-based structure is not just pedagogy — it is what a mature program looks like from the outside. When DDTC reviews training records that show differentiated content by role, it sees a company that understood its own risk map rather than one that bought a video and pressed play.
Delivery Formats: On-Site, Live Virtual, or Custom Program
On-Site Workshop
We come to your facility and teach in the environment where the risks actually live. On-site delivery allows a walkthrough of your floor — where visitors enter, where controlled drawings sit, where the shipping desk verifies licenses — and turns abstract rules into concrete, local practice. Scenario exercises use your products and your data flows. On-site works best for single-site manufacturers and for companies launching their first formal training cycle, where face-to-face Q&A surfaces the compliance questions employees have been sitting on.
Live Virtual Training
Live virtual sessions deliver the same modules, the same scenario exercises, and the same open Q&A over video conference — taught live by the instructor, never pre-recorded. Virtual delivery suits distributed teams, multi-site companies, and annual refresher cycles where travel cost isn't justified. Attendance and assessments are captured identically to on-site sessions, so your documentation is just as defensible.
Custom Training Program
For companies that want a durable internal capability, we build a complete program around your operation: curriculum mapped to your USML categories and license portfolio, role-track definitions, assessment questions, acknowledgment forms, a new-hire and refresher schedule, and train-the-trainer support so your compliance staff can sustain the cycle internally. The deliverable is not a training event — it is a training system your program can run for years.
Pricing: every training engagement is scoped to your program — headcount, role tracks, format, and documentation deliverables. Request a quote or call 858-240-4353 and we will scope it in one conversation.
Documenting Training the Way DDTC Expects
From a regulator's perspective, undocumented training never happened. If DDTC reviews your program — in a disclosure, an audit, or a compliance assessment — the training pillar is evaluated through its records. Every engagement we deliver produces the documentation set that review will ask for:
- Attendance rosters — who attended each session, with dates and delivery format
- Content records — versioned agendas and materials showing exactly what was taught and when the curriculum was last updated for regulatory change
- Assessments — evidence that understanding was verified, not just that attendance occurred
- Acknowledgments — signed employee acknowledgments of ITAR obligations
- Schedule and coverage tracking — new-hire training completed before access to controlled data, refreshers on cadence, and no coverage gaps as people change roles
Retain training records within your ITAR recordkeeping system alongside your other compliance records — the same discipline that governs licenses and shipping documents under 22 CFR 122.5 should govern the records that prove your people were trained. Step 9 of our 12-step ITAR compliance checklist covers where training sits in the overall program.
Your Instructor: A JD Who Practices ITAR Compliance Daily
ITAR is not a best-practice framework — it is federal law, administered by the State Department under the Arms Export Control Act, with criminal prosecution exposure. That is why it matters that your instructor reads the regulations the way counsel reads them. Jared Clark holds a Juris Doctor (JD) alongside an MBA, PMP, and CMQ-OE, and teaches ITAR as what it is: a legal regime where the words of 22 CFR carry consequences, not a checkbox exercise.
Just as important: this is training delivered by a practicing ITAR consultant, not a professional lecturer. The scenarios in class come from active consulting work — registrations, classification reviews, technology control plans, and disclosure engagements across 200+ client relationships. When an engineer asks "what about the situation where our supplier's engineer joins the call?", the answer comes from someone who has handled that exact situation, under the current regulations, including the September 2025 USML revisions that reshaped 15 of 21 categories. Your team gets answers, not "let me check on that."
Training is also where compliance programs reveal their other gaps. Because your instructor is the same consultant who builds full ITAR compliance programs, the questions your team asks in session often surface issues — an unscreened contractor population, an unmarked drawing library — that can be fixed before they become disclosure material.