Dual Compliance Guide

ITAR vs CMMC: How the Two
Compliance Regimes Fit Together

By Jared Clark, JD, MBA, PMP, CMQ-OE · Updated July 2026 · ~14 min read

200+
Clients Served
100%
Audit Pass Rate
JD, CMQ-OE
Expert Credentials

ITAR and CMMC are two different compliance regimes that frequently apply to the same defense contractor. ITAR (International Traffic in Arms Regulations, 22 CFR Parts 120–130) is federal export control law administered by the State Department's Directorate of Defense Trade Controls (DDTC) — it governs who may manufacture, export, and share defense articles, defense services, and technical data. CMMC (Cybersecurity Maturity Model Certification) is a Department of Defense contractual cybersecurity program, imposed through DFARS clause 252.204-7021, that verifies contractors protect Controlled Unclassified Information (CUI) on their information systems using the NIST SP 800-171 (and, at the highest level, SP 800-172) security requirements. They overlap because ITAR-controlled technical data held on contractor systems is a category of CUI — but neither regime substitutes for the other. CMMC certification does not authorize a single export, and DDTC registration does not satisfy a single CMMC control.

Two Regimes, Two Missions

Confusion between ITAR and CMMC is understandable: both apply to defense contractors, both involve protecting sensitive defense-related information, and both can disqualify you from defense work if you fail. But they were built by different agencies to solve different problems, and the differences matter for how you build your compliance program — and for what can go wrong if you conflate them.

ITAR: Export Control Law Enforced by the State Department

ITAR exists to keep defense articles, defense services, and related technical data out of the hands of foreign adversaries and unauthorized end users. It is law — regulations issued under the Arms Export Control Act and codified at 22 CFR Parts 120–130 — administered by the State Department's Directorate of Defense Trade Controls (DDTC). If you manufacture, export, temporarily import, or broker items on the United States Munitions List (USML), ITAR applies to you whether or not you hold a single government contract. Violations carry civil penalties up to $1,267,619 per violation and criminal penalties up to $1,000,000 and 20 years imprisonment. For the full regulatory picture, see our guide to what ITAR is and who must comply.

ITAR's core mechanics are about people and transfers: who is a U.S. person, who is a foreign person, what counts as an export (including a "deemed export" to a foreign national inside your own facility), and what authorization is required before a controlled item or piece of technical data changes hands. Its compliance apparatus includes DDTC registration, USML classification, export licenses and agreements, an empowered official, and recordkeeping.

CMMC: A DoD Contractual Cybersecurity Program

CMMC exists to solve a different problem: sensitive but unclassified DoD information leaking out of contractor networks through weak cybersecurity. It is not a statute or an export regulation — it is a contractual requirement the Department of Defense places on its contractors and flows down through the supply chain, implemented through DFARS clause 252.204-7021. CMMC verifies, through assessment, that a contractor's information systems actually implement the security requirements of NIST SP 800-171 (for Controlled Unclassified Information) and, for the most sensitive programs, a subset of NIST SP 800-172.

CMMC's core mechanics are about systems and controls: access control, encryption, audit logging, incident response, configuration management, and the rest of the 800-171 control families — assessed against a defined scope of systems that store, process, or transmit CUI. Under CMMC 2.0, the program's assessment requirements are phasing into DoD contracts over the 2025–2028 period, which is why so many subcontractors are confronting CMMC and ITAR obligations at the same time.

The One-Sentence Version

ITAR controls who may receive defense articles and technical data; CMMC verifies that the computer systems holding DoD's sensitive information are actually secure. One is about authorization of transfers; the other is about the condition of your network. A defense contractor facing both should think of ITAR as the "who can see it" regime and CMMC as the "how it's protected on your systems" regime.

ITAR vs CMMC: Side-by-Side Comparison

The table below summarizes the structural differences. Note how few rows actually overlap — the regimes intersect at exactly one point: the safeguarding of export-controlled technical data on information systems.

Attribute ITAR CMMC
What it is Federal export control regulations (22 CFR Parts 120–130) DoD contractual cybersecurity certification program
Administering body State Department — Directorate of Defense Trade Controls (DDTC) Department of Defense, via DFARS 252.204-7021; assessments by authorized third-party assessors
Legal basis Arms Export Control Act; binding law regardless of contracts Contract clause — applies only through DoD contracts and flow-downs
What it protects Defense articles, defense services, and technical data on the USML — against transfer to unauthorized foreign persons Federal Contract Information and Controlled Unclassified Information (CUI) residing on contractor information systems
Underlying standard USML classification + licensing rules; no single security standard NIST SP 800-171 (Level 2); subset of NIST SP 800-172 (Level 3)
Trigger Manufacturing, exporting, brokering, or furnishing USML items/data/services — contracts irrelevant Holding DoD contracts (or subcontracts) that include the CMMC clause
Registration / certification Annual DDTC registration (mandatory for manufacturers and exporters) Assessment/certification at the level specified in the contract
Key personnel concept Empowered official; foreign person screening Assessment scope owner; no export-control personnel roles
Consequences of failure Civil penalties up to $1,267,619 per violation; criminal fines and imprisonment; debarment Ineligibility for covered DoD contracts; contractual remedies; False Claims Act exposure for misrepresentation
Does it authorize exports? Yes — via licenses and agreements issued by DDTC No — never

The Row That Causes the Most Damage

The last row is where companies get hurt. A CMMC certificate is a statement about your network security — it says nothing about whether a given person may lawfully see a given drawing. We have seen contractors assume that because their environment was "CMMC ready," their foreign national engineers could access controlled technical data. That is a deemed export violation under ITAR, and CMMC provides zero defense.

When a Company Needs ITAR, CMMC, or Both

Because the two regimes have independent triggers, you should evaluate them separately. Four scenarios cover most of the defense industrial base:

ITAR Only

You manufacture or export USML-listed items but hold no DoD contracts containing the CMMC clause. Example: a firearms components manufacturer selling commercially and exporting under DDTC licenses. You must register with DDTC and run an ITAR compliance program — but no contract obligates you to a CMMC assessment. (You still have ITAR technical-data safeguarding obligations; see the overlap section below.)

CMMC Only

You hold DoD contracts involving Federal Contract Information or CUI, but nothing you handle is USML-controlled. Example: a logistics software provider processing DoD CUI that contains no export-controlled technical data. You need certification at the level your contracts specify, but you have no DDTC registration or licensing obligations.

Both — the Common Case for Defense Manufacturers

You manufacture defense articles or handle ITAR technical data and you perform on DoD contracts (directly or as a subcontractor). This is the majority of small and mid-size defense suppliers. ITAR obligates you to register, classify, and control transfers; your contracts obligate you to a CMMC Level 2 assessment because the ITAR technical data on your systems is CUI. If this is you, the sequencing guidance below is the most important part of this page.

Neither — But Verify Before You Assume

Companies outside the defense supply chain that touch neither USML items nor DoD information need neither regime. But "we're just a machine shop" is not a classification analysis. If a prime sends you drawings marked as export-controlled, or your purchase orders start carrying DFARS flow-down clauses, your status has changed — whether or not anyone told you. Our 50-point ITAR compliance checklist is a fast way to test whether you have obligations you have not addressed.

Where the Two Regimes Overlap

The overlap is real and exploitable — done right, one body of security work serves both masters. Three connection points matter:

1. Export-Controlled Technical Data Is a Category of CUI

The federal CUI framework designates export-controlled information as a CUI category. That means the same ITAR technical data — drawings, specifications, source code, process documentation for defense articles — is simultaneously (a) ITAR-controlled under 22 CFR Part 120 and (b) CUI that DoD contracts require you to protect. One dataset, two regimes. This is the single fact that pulls most ITAR contractors into CMMC Level 2: if your DoD work involves ITAR technical data on your systems, your contracts will require you to protect it to NIST SP 800-171 and, increasingly, to prove it through a CMMC assessment.

2. NIST SP 800-171 Controls Help Satisfy ITAR Safeguarding

ITAR requires you to prevent unauthorized disclosure of technical data to foreign persons, and 22 CFR 120.54 recognizes properly secured end-to-end encrypted transmission of technical data as falling outside the definition of a controlled export event. The access controls, encryption, audit logging, and incident response that NIST SP 800-171 mandates are exactly the mechanisms a well-run ITAR program uses to control technical data: restricting access to authorized U.S. persons, encrypting data in transit and at rest, logging who touched what, and detecting incidents. A contractor that implements 800-171 honestly has built most of the technical half of its ITAR technical-data controls — what remains is the ITAR-specific layer: foreign person screening, deemed export analysis, license determinations, and marking.

3. One Incident Can Trigger Both Regimes

A breach of a system holding ITAR technical data is not just a cybersecurity incident with contractual reporting obligations — if controlled technical data was accessed by foreign persons, it may also be an unauthorized export requiring analysis and potentially a voluntary disclosure to DDTC under 22 CFR 127.12. Your incident response plan should be written with both regimes in mind, with the empowered official in the notification chain. Companies that treat these as separate programs routinely handle the cyber side well and miss the export-control disclosure entirely.

The Practical Consequence
Build one protected environment for controlled data — a defined enclave where ITAR technical data and other CUI live — and satisfy both regimes inside it. Two parallel programs run by two different managers who never talk is how contractors end up paying twice and still failing both.

Common Misconceptions That Get Contractors in Trouble

"We're CMMC certified, so we can share the data"

False. CMMC certification does not authorize any export — not a shipment, not an email to a foreign partner, not access by a foreign national employee. Export authorization comes only from DDTC in the form of licenses, agreements, or applicable exemptions. Your CMMC status is irrelevant to whether a transfer is lawful under ITAR.

"We're ITAR registered, so the cybersecurity requirement is covered"

False. DDTC registration is a notification and eligibility step — it does not assess your systems, and it does not satisfy any NIST SP 800-171 requirement or CMMC assessment obligation. "ITAR registered" appearing in a capability statement tells a prime nothing about whether your network can hold their CUI.

"There's no such thing as being 'ITAR certified'"

True — and worth internalizing. Unlike CMMC, ITAR has no certification. No third party can issue you an "ITAR certificate." Companies are registered with DDTC and are compliant (or not) in their conduct. Vendors selling "ITAR certification" are selling something that does not exist in the regulations.

"The prime's CMMC and ITAR programs cover us"

False. Both regimes reach you independently. ITAR obligations attach to your own manufacturing and your own handling of technical data, and CMMC requirements flow down through your subcontracts. A prime's certificate covers the prime's systems; a prime's registration covers the prime's activities. Yours are yours. Small subcontractors should read our right-sized ITAR roadmap for small businesses on exactly this point.

"CMMC replaced the ITAR cybersecurity rules"

False. There were never ITAR rules that CMMC replaced — the regimes evolved separately. ITAR's safeguarding expectations (and the 22 CFR 120.54 encryption provisions) remain in force alongside CMMC. Meeting one without the other leaves you exposed on the side you skipped.

Sequencing: How to Tackle Both Without Doing the Work Twice

For a contractor facing both regimes at once — the common case since CMMC 2.0 assessment requirements began phasing into contracts — order of operations determines cost. The wrong order is to "do CMMC" across your entire network first and bolt export control on later. The right order uses ITAR analysis to shrink and define the CMMC problem:

  1. Classify first. Determine what in your business is actually ITAR-controlled — which products fall on the USML, which drawings and files are technical data. This is an ITAR exercise, but it produces the map of where your most sensitive CUI lives.
  2. Register and appoint. If you manufacture or export defense articles, complete DDTC registration and designate an empowered official. These are legal prerequisites with no CMMC equivalent, and they gate everything else.
  3. Scope an enclave. Use the classification map to define a bounded environment — specific systems, shares, and tools — where ITAR technical data and other CUI will live. A scoped enclave is dramatically cheaper to secure and assess than a whole corporate network, and it simultaneously narrows your deemed-export exposure.
  4. Implement NIST SP 800-171 once, for both. Build the 800-171 controls in the enclave, and layer the ITAR-specific controls on top: U.S.-person access restrictions, foreign national screening, technical data marking, and visitor and transmission procedures. One control set, two compliance outcomes.
  5. Write the paper to match. Your ITAR manual, Technology Control Plan, and CMMC system security documentation should describe the same environment consistently. Assessors and DDTC both respond badly to documentation that contradicts reality — or each other.
  6. Unify training and incident response. Train employees once on a combined curriculum — what CUI and technical data are, who may access them, how to report an incident — and make sure incident response includes the ITAR voluntary disclosure decision path.

Sequenced this way, the overlap works for you: the expensive middle (the secured enclave and its controls) is shared, and each regime adds only its unique edges — licensing and people-screening for ITAR, assessment and certification for CMMC. In our client engagements, the integrated build is consistently faster and cheaper than two independent programs, and it produces one coherent story to tell primes, assessors, and regulators. If you want a structured starting point before engaging anyone, work through our ITAR compliance checklist, then talk to us about how your CMMC obligations map onto the gaps it reveals.

Frequently Asked Questions About ITAR and CMMC

No. CMMC certification verifies that your information systems meet DoD cybersecurity requirements — it has no export control effect whatsoever. Exporting a defense article, sharing ITAR technical data with a foreign person, or furnishing a defense service still requires DDTC registration and, in most cases, a State Department export authorization under 22 CFR Parts 120–130. A CMMC Level 2 certificate does not substitute for any of these. Companies that treat CMMC as evidence of export compliance are exposed to civil penalties of up to $1,267,619 per ITAR violation.
Not directly. ITAR requires you to safeguard technical data against unauthorized disclosure to foreign persons, but it does not mandate CMMC certification. CMMC is a contractual requirement imposed by DoD through DFARS clause 252.204-7021. The two connect in practice: ITAR-controlled technical data on contractor systems is a category of Controlled Unclassified Information (CUI), and contracts involving CUI typically require CMMC Level 2, which is built on the NIST SP 800-171 security requirements. So most contractors handling ITAR technical data under DoD contracts will face a CMMC requirement — through their contracts, not through ITAR itself.
No. CMMC Level 2 addresses only the cybersecurity dimension of protecting CUI on your systems. ITAR compliance additionally requires DDTC registration (22 CFR 122.1), accurate USML classification, export licenses or agreements before any transfer to foreign persons, deemed export controls for foreign national employees, an empowered official, recordkeeping, and voluntary disclosure of violations. A company can hold a clean CMMC certificate and still commit an ITAR violation the same day — for example, by hiring a foreign national engineer and giving them access to controlled drawings without a license. See our complete ITAR guide →
Start with ITAR fundamentals: determine whether your items or data are USML-controlled, register with DDTC if you manufacture or export defense articles, and identify exactly where ITAR technical data lives in your business. That data-scoping exercise defines your CUI boundary — which is the foundation of your CMMC assessment scope. Doing ITAR classification first means you build your NIST SP 800-171 environment around the right data, often a smaller enclave rather than your whole network, which reduces CMMC cost and effort. Then implement the 800-171 controls once, so they satisfy both your CMMC assessment and your ITAR technical-data safeguarding obligations.
No — the regimes have different triggers. ITAR applies if you manufacture, export, or broker defense articles, defense services, or related technical data on the USML, even with no DoD contract at all. CMMC applies if you hold DoD contracts with the applicable DFARS clauses, even if nothing you touch is ITAR-controlled — for example, a contractor handling only non-export-controlled CUI. Many defense manufacturers sit in the overlap and need both; a commercial exporter of USML items with no DoD contracts may need only ITAR, and an IT services contractor to DoD may need only CMMC.
JC

About the Author

Jared Clark, JD, MBA, PMP, CMQ-OE

Jared Clark is an ITAR compliance consultant and export control expert with hands-on experience guiding 200+ clients through DDTC registration, compliance program development, USML classification, export licensing, and voluntary disclosure. Holding a Juris Doctor (JD), MBA, Project Management Professional (PMP) certification from PMI, and Certified Manager of Quality/Organizational Excellence (CMQ-OE) designation from ASQ, Jared brings legal, business, project management, and quality systems expertise to every engagement. His clients maintain a 100% first-time audit pass rate.

For broader certification consulting across ISO, GMP, and other regulatory frameworks, visit our parent practice at certify.consulting.

JD MBA PMP CMQ-OE

Facing ITAR and CMMC at the Same Time?

Schedule a free 30-minute consultation. We will map where your ITAR obligations and CMMC requirements overlap, identify gaps, and outline one integrated compliance path — no obligation, no pressure.

Or email us at [email protected]