Small Business Guide

ITAR Compliance for Small Business:
A Right-Sized Roadmap

By Jared Clark, JD, MBA, PMP, CMQ-OE · Updated July 2026 · ~13 min read

200+
Clients Served
100%
Audit Pass Rate
JD, CMQ-OE
Expert Credentials

Small businesses are fully subject to ITAR (International Traffic in Arms Regulations, 22 CFR Parts 120–130) — there is no small-company exemption. A 10–50 person shop that manufactures defense articles or handles ITAR-controlled technical data needs five things: DDTC registration, a designated empowered official (an existing employee wearing an additional hat), a right-sized written compliance manual, practical technical-data controls, and basic training plus recordkeeping. What it does not need is an enterprise compliance department. ITAR obligations are independent per company — your prime contractor's compliance program does not cover you, which is exactly why primes flow ITAR requirements down to second- and third-tier subcontractors. Done in the right order, a small shop can stand up a defensible core program in roughly 90 days.

Why ITAR Keeps Landing on Small Shops

If you run a machine shop, electronics house, coating line, or software team and a defense prime just asked for proof of your "ITAR compliance," you are experiencing a structural feature of the defense supply chain, not a bureaucratic accident. Three forces are at work:

1. Liability Does Not Stop at the Prime

Every company in the chain bears its own legal responsibility under ITAR. If your shop machines a component specifically designed for a USML-listed system, you are a manufacturer of a defense article under 22 CFR 122.1 — with your own registration obligation — even if you never export anything and the prime handles every shipment. If the prime emails you a controlled drawing, you are now holding ITAR technical data and are responsible for who sees it. The prime cannot absorb your obligations, so instead it verifies them: questionnaires, flow-down clauses (including DFARS 252.225-7048 for export-controlled items), and audits. New to the terminology? Start with our plain-language guide to what ITAR is and who must comply.

2. Primes Are Under Pressure Themselves

Enforcement has intensified — the $950M RTX/Raytheon settlement in 2024 was the largest ITAR enforcement action in history, and DDTC has pursued actions against companies with as few as 10 employees. Primes responded by tightening supplier requirements: a subcontractor that cannot demonstrate registration and basic controls is a supply-chain risk they will engineer out. Increasingly, the suppliers who can produce a registration letter and a credible compliance manual win the work; the ones who cannot get quietly dropped from the bid list.

3. The Data Follows the Work

You cannot quote, tool, or machine a defense component without drawings and specifications — and those are usually ITAR technical data. The moment they hit your email server, your obligations are live: controlling access to U.S. persons, preventing deemed exports to any foreign national employees, and safeguarding the files. This is why "we just make parts" is not a defense. The regulation follows the data and the design intent, not your self-image as a commercial shop.

The Most Expensive Sentence in the Supply Chain

"The prime handles ITAR for us." In our work with 200+ clients, this assumption is the single most common root cause we find when a small manufacturer discovers it has been out of compliance for years — unregistered while manufacturing defense articles, or sharing controlled drawings with an uncleared workforce. Each instance is a separate violation with civil exposure up to $1,267,619. If you supply a defense prime and have never made your own ITAR determination, make one now.

What a 10–50 Person Shop Actually Needs

Here is the honest scope. Five components, each sized to a small organization:

1. DDTC Registration

If you manufacture defense articles or export them, register with DDTC through the DECCS portal using the DS-2032 Statement of Registration. Registration is a notification and eligibility step, not a license — but it is mandatory, renews annually, and manufacturing USML items without it is itself a violation. Processing typically runs 45–60 days, so start early. Our DDTC registration guide walks through the process, documentation, and common rejection reasons step by step.

2. An Empowered Official Who Wears Other Hats

Every registrant must designate an empowered official (22 CFR 120.67) — a U.S. person who is a direct employee, officer, or director with authority to verify compliance, sign submissions to DDTC, and refuse improper transactions. In a small shop this is not a new hire: it is your president, operations manager, or quality manager with additional training and genuine authority. Two things matter more than the title: the person must actually be able to say "no" to a shipment or disclosure without being overruled by sales, and there should be a trained backup so a vacation does not halt your defense work.

3. A Right-Sized Compliance Manual

You need written procedures — DDTC expects them, primes ask for them, and they are what turns compliance from tribal knowledge into a system that survives employee turnover. For a small shop, a focused manual covering your actual activities beats a 200-page template every time: how you classify items, who may access technical data, how visitors are handled, how shipments are authorized, how records are kept, and what happens when something goes wrong. A manual describing procedures you do not actually follow is worse than a shorter one you do — in an enforcement context, it documents that you knew better.

4. Practical Technical-Data Controls

The heart of small-business ITAR compliance is controlling who can see controlled drawings and files. Practically, that means: a defined place where ITAR data lives (a restricted server share or a small secured cloud enclave rather than your whole network), access limited to authorized U.S. persons, marking so employees can recognize controlled documents, encrypted transmission, screening before any foreign national is given access to anything (that is the deemed export rule), and basic visitor controls on the shop floor. If your DoD subcontracts also carry cybersecurity clauses, this same enclave becomes the scope of your CMMC obligations — see our companion guide on how ITAR and CMMC fit together before you build anything twice.

5. Training and Recordkeeping

Everyone who touches controlled items or data needs to know what ITAR is, what your company controls, and who to ask before sharing anything — a focused session at hire and an annual refresher is a defensible baseline for a small shop. Keep records: registration and renewal documents, training logs, access lists, license or exemption documentation, and shipment records, retained for five years. Records are what convert "we are compliant" from an assertion into evidence — for a prime's questionnaire and for DDTC alike.

What You Can Skip: Enterprise Theater vs. Real Compliance

Small businesses over-buy ITAR compliance nearly as often as they under-buy it, usually after a scary sales pitch. The regulation requires controls proportionate to your activities — not a scaled-down replica of a prime's compliance department. Distinguish the substance from the theater:

Compliance Area What a Small Shop Needs Enterprise Theater You Can Skip
People A trained empowered official who wears other hats, plus a backup A dedicated trade-compliance department and full-time export counsel on staff
Documentation A focused manual describing what you actually do Hundreds of pages of unread boilerplate policies
IT controls A small secured enclave where controlled data lives Re-architecting the entire corporate network to the highest standard "just in case"
Training Role-based sessions at hire + annual refresher, documented Enterprise learning-management platforms and week-long seminars for machinists
Licensing License determinations when a transfer to a foreign person is actually contemplated Pre-emptive license applications for exports you have no plans to make
"Certification" DDTC registration + demonstrable controls (there is no such thing as an "ITAR certificate") Paying a vendor for an "ITAR certified" badge — a credential that does not exist in the regulations

One caution cuts the other way: right-sizing means scaling the machinery, never the obligations. A small shop's deemed-export exposure is identical to Lockheed's. The five components above are the floor — everything beyond them should be justified by your actual risk profile, not by a vendor's template.

What Actually Drives the Cost

We will not quote you a fake all-in number — the honest answer is that cost depends on a handful of identifiable drivers. Know them, and you can budget intelligently and interrogate any proposal you receive:

  • The registration fee — the one fixed, citable cost. Under the DDTC fee schedule effective January 2025, Tier 1 registration (few or no active approvals — where most small businesses start) is $3,000 per year, with qualifying small businesses paying $2,500. It renews annually.
  • Classification complexity. One product family clearly on the USML is a short exercise; a mixed commercial/defense catalog near the USML/CCL boundary can require commodity jurisdiction analysis — the single biggest variable in up-front effort. The September 2025 USML revisions (15 of 21 categories updated) mean even previously classified items may need a fresh look.
  • Where your technical data currently lives. If controlled drawings are scattered across personal email, shared drives, and phones, consolidation into an enclave is the largest IT line item. If your data is already reasonably contained, this shrinks dramatically.
  • Your workforce composition. No foreign national employees means deemed-export controls are mostly procedural. Foreign nationals in engineering or production roles mean screening, access segregation, and possibly license applications — real money and real lead time.
  • Whether you export. A domestic-only manufacturer selling to U.S. primes may need no licenses at all. Actual exports add license preparation and ongoing proviso management per authorization.
  • Overlapping requirements. If your subcontracts also carry cybersecurity clauses, building the ITAR enclave and the CMMC-scoped environment as one project costs meaningfully less than two sequential ones.

The comparison that matters for budgeting: every one of these drivers is priced in the thousands or tens of thousands, while a single civil violation is priced at up to $1,267,619 — and the practical penalty that kills small companies is losing prime-contract eligibility altogether.

A Phased 90-Day Roadmap

Standing up a core program is a project, and sequencing beats intensity. Here is the order of operations we use with small clients:

Days 1–30: Determine and Register

  1. Classify. Determine whether your products, components, or data are USML-controlled. Request written determinations from your primes for the items and drawings they send you — and document your own analysis.
  2. Inventory the data. Find every place ITAR technical data currently lives: email, shares, laptops, quoting systems, the shop-floor computer.
  3. Begin DDTC registration through DECCS if you manufacture or export defense articles — start now, because processing takes 45–60 days and everything else can proceed in parallel.
  4. Designate the empowered official (and backup) and get them trained.

Days 31–60: Contain and Document

  1. Build the enclave. Consolidate controlled data into one restricted location; set access lists to authorized U.S. persons; enable encryption for storage and transmission.
  2. Screen personnel. Confirm the U.S.-person status of everyone with access; where foreign national employees need access, stop and get a license determination first.
  3. Write the manual — procedures matching what you actually built: classification, access, visitors, shipping authorization, records, and incident/violation response.
  4. Start marking controlled documents so employees can recognize them on sight.

Days 61–90: Train, Prove, and Maintain

  1. Train everyone who touches controlled items or data; document attendance.
  2. Set the recordkeeping system — registration, training logs, access lists, shipment records — with five-year retention.
  3. Self-audit against a structured baseline — our 50-point ITAR compliance checklist exists for exactly this step — and fix what it surfaces.
  4. Put maintenance on the calendar: annual registration renewal, annual refresher training, access review, and a standing agenda item for regulatory changes.

At the end of 90 days you will not have an enterprise program — you will have something better for your size: a registration certificate, a named accountable person, contained data, written procedures you actually follow, trained people, and records that prove all of it. That package answers a prime's questionnaire, and it is the posture DDTC expects of a company your size.

When DIY Works — and When to Get Help

Not every small business needs a consultant, and you should be skeptical of anyone who says otherwise. An honest split:

DIY Is Reasonable When…

  • Your classification is unambiguous — the prime has told you in writing that the items and drawings are ITAR-controlled, and you make nothing else that is close to the line;
  • You have no foreign national employees and no export transactions — domestic manufacturing for U.S. primes only;
  • Someone on staff has the bandwidth and diligence to own the project, work the DECCS registration, and write procedures that match reality;
  • You are starting clean, with no history of handling controlled data outside any controls.

Get Professional Help When…

  • Classification is uncertain — dual-use products, commercial derivatives, or items near the USML/CCL boundary. A wrong self-classification is not a paperwork error; it is the seed of every downstream violation.
  • Foreign nationals are in the workforce — deemed export analysis and license strategy carry real legal consequences and are unforgiving of improvisation.
  • You suspect past violations — if controlled data has already been shared without authorization, the voluntary disclosure decision (22 CFR 127.12) has deadlines and strategy implications. Get counsel and a compliance professional involved before you write anything to DDTC.
  • A prime audit or contract deadline is bearing down — compressing the 90-day roadmap into 30 days is possible, but not while learning the regulations from scratch.
  • ITAR and CMMC arrive together — scoping one environment to satisfy both regimes is where an experienced integrator saves more than their fee.

Either way, start the same place: work through the compliance checklist to see your actual gap profile. If the gaps are procedural, close them yourself. If they are legal or structural, contact us for a free consultation — we will tell you plainly which category you are in, including when the honest answer is that you can do this without us.

FAQs Small-Shop Owners Actually Ask

No. ITAR obligations attach to each company independently. If your shop manufactures defense articles or receives ITAR-controlled technical data, you carry your own registration, safeguarding, and licensing obligations under 22 CFR Parts 120–130 — regardless of what the prime does. The prime's registration covers the prime's activities, not yours. Primes flow ITAR requirements down precisely because each tier of the supply chain bears its own legal responsibility, and DDTC has pursued enforcement against small companies, not just large primes.
If you manufacture defense articles — including components specifically designed for USML-listed items — yes. Under 22 CFR 122.1, manufacturers of defense articles must register with DDTC even if they never export and sell only to U.S. primes. Registration is a notification requirement, not an export authorization; failing to register while manufacturing USML items is itself a violation. If you only distribute or handle items you did not manufacture and do not export, the analysis differs — that is worth a professional determination. See our DDTC Registration guide →
A small business does not need a dedicated compliance hire. The empowered official must be a U.S. person and a direct employee, officer, or director with real authority to inquire into compliance and refuse improper transactions — a consultant cannot hold the role. In a 10–50 person shop, the empowered official is typically the president, operations manager, or quality manager wearing an additional hat. What matters is that they are trained, genuinely empowered to say no, and have a designated backup.
Under the fee schedule effective January 2025, Tier 1 registration (registrants with few or no active approvals — where most small businesses start) is $3,000 per year, with qualifying small businesses paying $2,500. Registration renews annually. Registration is only one cost component: expect additional investment in written procedures, training, and technical data controls — but for a small shop these should be right-sized, not enterprise-scale.
Often, yes — through your subcontract rather than through ITAR itself. ITAR-controlled technical data on your systems is a category of Controlled Unclassified Information (CUI), and DoD contracts involving CUI increasingly require CMMC Level 2, built on NIST SP 800-171. ITAR and CMMC are separate regimes with separate triggers: CMMC certification never authorizes an export, and DDTC registration never satisfies a CMMC assessment. Sequencing them together — classify ITAR data first, then scope a small secured enclave — is significantly cheaper than treating them as two unrelated projects. See our ITAR vs CMMC guide →
JC

About the Author

Jared Clark, JD, MBA, PMP, CMQ-OE

Jared Clark is an ITAR compliance consultant and export control expert with hands-on experience guiding 200+ clients through DDTC registration, compliance program development, USML classification, export licensing, and voluntary disclosure. Holding a Juris Doctor (JD), MBA, Project Management Professional (PMP) certification from PMI, and Certified Manager of Quality/Organizational Excellence (CMQ-OE) designation from ASQ, Jared brings legal, business, project management, and quality systems expertise to every engagement. His clients maintain a 100% first-time audit pass rate.

For broader certification consulting across ISO, GMP, and other regulatory frameworks, visit our parent practice at certify.consulting.

JD MBA PMP CMQ-OE

Building ITAR Compliance on a Small-Business Budget?

Schedule a free 30-minute consultation. We will assess where your shop stands, tell you honestly what you can do yourself, and scope only the help you actually need — no obligation, no pressure.

Or email us at [email protected]