Why ITAR Keeps Landing on Small Shops
If you run a machine shop, electronics house, coating line, or software team and a defense prime just asked for proof of your "ITAR compliance," you are experiencing a structural feature of the defense supply chain, not a bureaucratic accident. Three forces are at work:
1. Liability Does Not Stop at the Prime
Every company in the chain bears its own legal responsibility under ITAR. If your shop machines a component specifically designed for a USML-listed system, you are a manufacturer of a defense article under 22 CFR 122.1 — with your own registration obligation — even if you never export anything and the prime handles every shipment. If the prime emails you a controlled drawing, you are now holding ITAR technical data and are responsible for who sees it. The prime cannot absorb your obligations, so instead it verifies them: questionnaires, flow-down clauses (including DFARS 252.225-7048 for export-controlled items), and audits. New to the terminology? Start with our plain-language guide to what ITAR is and who must comply.
2. Primes Are Under Pressure Themselves
Enforcement has intensified — the $950M RTX/Raytheon settlement in 2024 was the largest ITAR enforcement action in history, and DDTC has pursued actions against companies with as few as 10 employees. Primes responded by tightening supplier requirements: a subcontractor that cannot demonstrate registration and basic controls is a supply-chain risk they will engineer out. Increasingly, the suppliers who can produce a registration letter and a credible compliance manual win the work; the ones who cannot get quietly dropped from the bid list.
3. The Data Follows the Work
You cannot quote, tool, or machine a defense component without drawings and specifications — and those are usually ITAR technical data. The moment they hit your email server, your obligations are live: controlling access to U.S. persons, preventing deemed exports to any foreign national employees, and safeguarding the files. This is why "we just make parts" is not a defense. The regulation follows the data and the design intent, not your self-image as a commercial shop.
What a 10–50 Person Shop Actually Needs
Here is the honest scope. Five components, each sized to a small organization:
1. DDTC Registration
If you manufacture defense articles or export them, register with DDTC through the DECCS portal using the DS-2032 Statement of Registration. Registration is a notification and eligibility step, not a license — but it is mandatory, renews annually, and manufacturing USML items without it is itself a violation. Processing typically runs 45–60 days, so start early. Our DDTC registration guide walks through the process, documentation, and common rejection reasons step by step.
2. An Empowered Official Who Wears Other Hats
Every registrant must designate an empowered official (22 CFR 120.67) — a U.S. person who is a direct employee, officer, or director with authority to verify compliance, sign submissions to DDTC, and refuse improper transactions. In a small shop this is not a new hire: it is your president, operations manager, or quality manager with additional training and genuine authority. Two things matter more than the title: the person must actually be able to say "no" to a shipment or disclosure without being overruled by sales, and there should be a trained backup so a vacation does not halt your defense work.
3. A Right-Sized Compliance Manual
You need written procedures — DDTC expects them, primes ask for them, and they are what turns compliance from tribal knowledge into a system that survives employee turnover. For a small shop, a focused manual covering your actual activities beats a 200-page template every time: how you classify items, who may access technical data, how visitors are handled, how shipments are authorized, how records are kept, and what happens when something goes wrong. A manual describing procedures you do not actually follow is worse than a shorter one you do — in an enforcement context, it documents that you knew better.
4. Practical Technical-Data Controls
The heart of small-business ITAR compliance is controlling who can see controlled drawings and files. Practically, that means: a defined place where ITAR data lives (a restricted server share or a small secured cloud enclave rather than your whole network), access limited to authorized U.S. persons, marking so employees can recognize controlled documents, encrypted transmission, screening before any foreign national is given access to anything (that is the deemed export rule), and basic visitor controls on the shop floor. If your DoD subcontracts also carry cybersecurity clauses, this same enclave becomes the scope of your CMMC obligations — see our companion guide on how ITAR and CMMC fit together before you build anything twice.
5. Training and Recordkeeping
Everyone who touches controlled items or data needs to know what ITAR is, what your company controls, and who to ask before sharing anything — a focused session at hire and an annual refresher is a defensible baseline for a small shop. Keep records: registration and renewal documents, training logs, access lists, license or exemption documentation, and shipment records, retained for five years. Records are what convert "we are compliant" from an assertion into evidence — for a prime's questionnaire and for DDTC alike.
What You Can Skip: Enterprise Theater vs. Real Compliance
Small businesses over-buy ITAR compliance nearly as often as they under-buy it, usually after a scary sales pitch. The regulation requires controls proportionate to your activities — not a scaled-down replica of a prime's compliance department. Distinguish the substance from the theater:
| Compliance Area | What a Small Shop Needs | Enterprise Theater You Can Skip |
|---|---|---|
| People | A trained empowered official who wears other hats, plus a backup | A dedicated trade-compliance department and full-time export counsel on staff |
| Documentation | A focused manual describing what you actually do | Hundreds of pages of unread boilerplate policies |
| IT controls | A small secured enclave where controlled data lives | Re-architecting the entire corporate network to the highest standard "just in case" |
| Training | Role-based sessions at hire + annual refresher, documented | Enterprise learning-management platforms and week-long seminars for machinists |
| Licensing | License determinations when a transfer to a foreign person is actually contemplated | Pre-emptive license applications for exports you have no plans to make |
| "Certification" | DDTC registration + demonstrable controls (there is no such thing as an "ITAR certificate") | Paying a vendor for an "ITAR certified" badge — a credential that does not exist in the regulations |
One caution cuts the other way: right-sizing means scaling the machinery, never the obligations. A small shop's deemed-export exposure is identical to Lockheed's. The five components above are the floor — everything beyond them should be justified by your actual risk profile, not by a vendor's template.
What Actually Drives the Cost
We will not quote you a fake all-in number — the honest answer is that cost depends on a handful of identifiable drivers. Know them, and you can budget intelligently and interrogate any proposal you receive:
- The registration fee — the one fixed, citable cost. Under the DDTC fee schedule effective January 2025, Tier 1 registration (few or no active approvals — where most small businesses start) is $3,000 per year, with qualifying small businesses paying $2,500. It renews annually.
- Classification complexity. One product family clearly on the USML is a short exercise; a mixed commercial/defense catalog near the USML/CCL boundary can require commodity jurisdiction analysis — the single biggest variable in up-front effort. The September 2025 USML revisions (15 of 21 categories updated) mean even previously classified items may need a fresh look.
- Where your technical data currently lives. If controlled drawings are scattered across personal email, shared drives, and phones, consolidation into an enclave is the largest IT line item. If your data is already reasonably contained, this shrinks dramatically.
- Your workforce composition. No foreign national employees means deemed-export controls are mostly procedural. Foreign nationals in engineering or production roles mean screening, access segregation, and possibly license applications — real money and real lead time.
- Whether you export. A domestic-only manufacturer selling to U.S. primes may need no licenses at all. Actual exports add license preparation and ongoing proviso management per authorization.
- Overlapping requirements. If your subcontracts also carry cybersecurity clauses, building the ITAR enclave and the CMMC-scoped environment as one project costs meaningfully less than two sequential ones.
The comparison that matters for budgeting: every one of these drivers is priced in the thousands or tens of thousands, while a single civil violation is priced at up to $1,267,619 — and the practical penalty that kills small companies is losing prime-contract eligibility altogether.
A Phased 90-Day Roadmap
Standing up a core program is a project, and sequencing beats intensity. Here is the order of operations we use with small clients:
Days 1–30: Determine and Register
- Classify. Determine whether your products, components, or data are USML-controlled. Request written determinations from your primes for the items and drawings they send you — and document your own analysis.
- Inventory the data. Find every place ITAR technical data currently lives: email, shares, laptops, quoting systems, the shop-floor computer.
- Begin DDTC registration through DECCS if you manufacture or export defense articles — start now, because processing takes 45–60 days and everything else can proceed in parallel.
- Designate the empowered official (and backup) and get them trained.
Days 31–60: Contain and Document
- Build the enclave. Consolidate controlled data into one restricted location; set access lists to authorized U.S. persons; enable encryption for storage and transmission.
- Screen personnel. Confirm the U.S.-person status of everyone with access; where foreign national employees need access, stop and get a license determination first.
- Write the manual — procedures matching what you actually built: classification, access, visitors, shipping authorization, records, and incident/violation response.
- Start marking controlled documents so employees can recognize them on sight.
Days 61–90: Train, Prove, and Maintain
- Train everyone who touches controlled items or data; document attendance.
- Set the recordkeeping system — registration, training logs, access lists, shipment records — with five-year retention.
- Self-audit against a structured baseline — our 50-point ITAR compliance checklist exists for exactly this step — and fix what it surfaces.
- Put maintenance on the calendar: annual registration renewal, annual refresher training, access review, and a standing agenda item for regulatory changes.
At the end of 90 days you will not have an enterprise program — you will have something better for your size: a registration certificate, a named accountable person, contained data, written procedures you actually follow, trained people, and records that prove all of it. That package answers a prime's questionnaire, and it is the posture DDTC expects of a company your size.
When DIY Works — and When to Get Help
Not every small business needs a consultant, and you should be skeptical of anyone who says otherwise. An honest split:
DIY Is Reasonable When…
- Your classification is unambiguous — the prime has told you in writing that the items and drawings are ITAR-controlled, and you make nothing else that is close to the line;
- You have no foreign national employees and no export transactions — domestic manufacturing for U.S. primes only;
- Someone on staff has the bandwidth and diligence to own the project, work the DECCS registration, and write procedures that match reality;
- You are starting clean, with no history of handling controlled data outside any controls.
Get Professional Help When…
- Classification is uncertain — dual-use products, commercial derivatives, or items near the USML/CCL boundary. A wrong self-classification is not a paperwork error; it is the seed of every downstream violation.
- Foreign nationals are in the workforce — deemed export analysis and license strategy carry real legal consequences and are unforgiving of improvisation.
- You suspect past violations — if controlled data has already been shared without authorization, the voluntary disclosure decision (22 CFR 127.12) has deadlines and strategy implications. Get counsel and a compliance professional involved before you write anything to DDTC.
- A prime audit or contract deadline is bearing down — compressing the 90-day roadmap into 30 days is possible, but not while learning the regulations from scratch.
- ITAR and CMMC arrive together — scoping one environment to satisfy both regimes is where an experienced integrator saves more than their fee.
Either way, start the same place: work through the compliance checklist to see your actual gap profile. If the gaps are procedural, close them yourself. If they are legal or structural, contact us for a free consultation — we will tell you plainly which category you are in, including when the honest answer is that you can do this without us.