Compliance with the International Traffic in Arms Regulations (ITAR) is mandatory for companies that work with the U.S. defense sector, and the stakes are high: civil penalties now exceed $1.27 million per violation, alongside criminal charges and loss of export privileges. ITAR is not only a legal and paperwork obligation. Because it controls defense-related technical data, it is also an IT and data-security obligation.
IT Solutions Technology Partners helps defense contractors and manufacturers implement the IT side of ITAR, including U.S.-person access controls, compliant cloud environments, and encryption, work that overlaps heavily with CMMC and NIST SP 800-171. As a Microsoft Solutions Partner and a SOC 2 Type II compliant provider, ITS focuses on the systems that protect controlled technical data.
What is ITAR compliance?
ITAR compliance means following the U.S. State Department regulations that control the export and import of defense articles, defense services, and related technical data listed on the United States Munitions List (USML). Administered by the Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA), ITAR is designed to keep sensitive military technology from reaching unauthorized foreign persons. Compliance is mandatory for manufacturers, exporters, and brokers of defense articles and technical data.
A key point that surprises many companies: under ITAR, an “export” is not only shipping a physical part overseas. Giving a foreign person access to controlled technical data, even a foreign national employee inside the United States or an offshore IT administrator, counts as an export (a “deemed export”). That is why ITAR reaches directly into how you store, transmit, and control access to data.
Who needs to be ITAR compliant?
Any company that manufactures, exports, brokers, or handles defense articles, defense services, or ITAR-controlled technical data must comply. This extends well beyond obvious weapons makers. It includes subcontractors and suppliers in the defense supply chain, engineering and software firms that touch technical data, and any IT, SaaS, or cloud provider that stores, processes, or grants access to that data. If your systems hold ITAR technical data, ITAR applies to you.
The USML spans a broad range of categories, from firearms and ammunition to military electronics, aircraft, and spacecraft, and it covers defense services such as training foreign units or modifying defense articles. Companies often discover they are in scope not because they build weapons, but because they hold controlled drawings, specifications, or source code on behalf of a prime contractor.
What are the penalties for ITAR violations?
ITAR penalties are severe and are adjusted for inflation each year. As of 2025, the civil penalty is $1,271,078 per violation, or twice the value of the transaction, whichever is greater. Criminal penalties for willful violations reach up to $1 million in fines and up to 20 years of imprisonment per violation. Companies can also face debarment, loss of export privileges, and seizure of goods.
| Penalty type | Maximum exposure |
|---|---|
| Civil (per violation) | $1,271,078 (2025), or twice the transaction value, whichever is greater |
| Criminal (per willful violation) | Up to $1,000,000 in fines and up to 20 years imprisonment |
| Additional consequences | Statutory debarment, loss of export privileges, seizure or forfeiture of goods, mandatory consent agreements |
Enforcement is active and the amounts are large. In 2024, defense manufacturer RTX (Raytheon) agreed to federal settlements totaling roughly $950 million to resolve multiple enforcement matters, including ITAR violations, one of the largest export-control-related actions on record. Earlier cases, such as a 2023 settlement of up to $27 million against a U.S. manufacturer for unauthorized transfers of technical data, show that mid-sized companies are targets too. The trend across recent years is toward higher penalties and more aggressive enforcement.
How does ITAR affect your IT and data security?
ITAR directly governs your IT because controlled technical data must be protected from foreign-person access at every point: storage, transmission, and administration. Making that data available to a foreign person, including an unauthorized employee or an offshore cloud administrator, is treated as an export. In practice, that means U.S.-person access controls, encryption, careful cloud choices, and audit logging are not optional extras. They are how you stay compliant.
Four IT and data-security rules matter most:
- U.S.-person access control: Only U.S. persons (or those with specific DDTC authorization) may access ITAR technical data. This requires enforced access controls, personnel screening, and usually a documented Technology Control Plan (TCP).
- The encryption carve-out (22 CFR § 120.54): Since 2020, storing or sending unclassified ITAR technical data over the internet or in the cloud is not treated as an export if four conditions are met: the data is unclassified, it is end-to-end encrypted, the encryption uses FIPS 140-2 (or a validated successor) modules, and the decryption keys are never provided to any foreign person or held in a proscribed country. The carve-out protects the encrypted data in transit and at rest; a foreign person accessing the decrypted data is still an export.
- Data residency and compliant cloud: ITAR does not strictly require U.S.-only storage, but keeping data in the United States with U.S.-person access is the standard mitigation. Microsoft 365 GCC High and Azure Government are the environments most defense contractors use, because they keep data in the continental U.S., limit access to U.S. persons, and carry contractual ITAR commitments that standard commercial Microsoft 365 does not.
- Audit and evidence: DDTC reviews expect proof, not policies: access logs showing that only U.S. persons reached the data, and evidence that encryption met FIPS standards.
This is the part of ITAR that lives in your IT environment, and it is where an experienced managed IT and compliance partner adds the most value.
ITAR vs EAR: what is the difference?
ITAR and the Export Administration Regulations (EAR) are two separate U.S. export-control regimes. ITAR, administered by the State Department’s DDTC, controls defense articles and services on the USML. The EAR, administered by the Commerce Department’s Bureau of Industry and Security (BIS), controls “dual-use” items (commercial goods with possible military applications) on the Commerce Control List (CCL). Knowing which regime governs your product is the first compliance decision.
| ITAR | EAR | |
|---|---|---|
| Administered by | State Department (DDTC) | Commerce Department (BIS) |
| Governs | Defense articles, services, and technical data | Dual-use and commercial items |
| Control list | U.S. Munitions List (USML) | Commerce Control List (CCL) |
| Registration | Required with DDTC | Not generally required |
| Civil penalty (2025) | $1,271,078 per violation | $374,474 per violation |
Some items have moved from the USML to the CCL over the years, so classification should be confirmed rather than assumed. Many defense contractors are subject to both regimes.
How does ITAR relate to CMMC, CUI, and NIST SP 800-171?
ITAR overlaps heavily with the Department of Defense’s cybersecurity requirements. ITAR-controlled technical data is almost always also Controlled Unclassified Information (CUI), which brings it under DFARS 252.204-7012, NIST SP 800-171, and CMMC. In other words, the same data that ITAR says must be protected from foreign-person access is the data CMMC says must be protected with specific security controls. Treating them as one program, rather than three silos, is far more efficient.
For most defense contractors, this convergence is the practical reason to build a single controlled environment (for example, Microsoft 365 GCC High) that satisfies ITAR’s U.S.-person and encryption requirements and the NIST SP 800-171 controls behind CMMC at the same time. IT Solutions Technology Partners helps defense and manufacturing clients design that shared foundation so one investment covers overlapping obligations.
How do you achieve and maintain ITAR compliance?
Achieving ITAR compliance follows a clear sequence: register, classify your data, control access, secure your systems, train your people, and audit continuously. The legal and IT sides run in parallel, because registration and licensing mean little if your systems let an unauthorized person reach the data.
- Register with the DDTC. Manufacturers, exporters, and brokers of defense articles and technical data must register with the Directorate of Defense Trade Controls and obtain the appropriate licenses for what they plan to export.
- Classify your data and map its flow. Determine which data is ITAR-controlled by checking it against the USML, then map where it lives and who can reach it.
- Control access to U.S. persons. Enforce U.S.-person-only access with identity and access controls, personnel screening, and a documented Technology Control Plan.
- Secure your systems. Use a compliant environment (commonly Microsoft 365 GCC High or Azure Government), apply FIPS-validated end-to-end encryption per the 22 CFR § 120.54 carve-out, and enable audit logging.
- Train your people. Provide ongoing ITAR awareness training for all relevant personnel, since human error is a leading cause of violations.
- Audit and update. Perform regular internal and external audits, keep evidence of controls and access, and update procedures as regulations and your business change.
How does IT Solutions Technology Partners help with ITAR compliance?
IT Solutions Technology Partners helps defense contractors and manufacturers build and run the IT environment that ITAR requires. That includes designing U.S.-person access controls, deploying and managing compliant cloud environments such as Microsoft 365 GCC High and Azure Government, implementing FIPS-validated encryption, and producing the access and audit evidence DDTC reviews expect. Because ITAR data is almost always also CUI, ITS aligns this work with NIST SP 800-171 and CMMC so a single program covers overlapping requirements.
Founded in 1994 and supporting clients from 14 offices with a team of roughly 450 to 500 professionals, ITS pairs this compliance work with the managed IT and cybersecurity foundation defense and manufacturing organizations depend on. ITS supports the technology side of export-control compliance; it does not replace qualified export-control counsel, and the two work best together.
Frequently Asked Questions
Is ITAR the same as EAR? No. ITAR, administered by the State Department’s DDTC, controls defense articles and technical data on the U.S. Munitions List. The EAR, administered by the Commerce Department’s BIS, controls dual-use and commercial items on the Commerce Control List. Many defense contractors are subject to both, so each product should be classified to determine which applies.
Can ITAR-controlled technical data be stored in the cloud? Yes, within limits. Since 2020, the 22 CFR § 120.54 encryption carve-out allows unclassified ITAR technical data to be stored and transmitted in the cloud without it counting as an export, provided the data is end-to-end encrypted with FIPS 140-2 validated encryption and the decryption keys are never accessible to a foreign person. Most contractors use Microsoft 365 GCC High or Azure Government for this.
Does ITAR require data to be stored in the United States? Not strictly, but keeping data in the U.S. with access limited to U.S. persons is the widely adopted way to meet ITAR’s requirements. Standard commercial cloud regions do not guarantee U.S. data residency or U.S.-person-only access, which is why defense contractors typically choose government cloud environments.
Is ITAR-controlled data also considered CUI? Almost always. ITAR technical data typically qualifies as Controlled Unclassified Information, which brings it under DFARS 252.204-7012, NIST SP 800-171, and CMMC. Building one controlled environment to satisfy both ITAR and CMMC is usually more efficient than running separate programs.
Who enforces ITAR? ITAR is administered and enforced by the U.S. State Department’s Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act. Civil penalties are set by the State Department and adjusted for inflation each year; criminal cases can be referred for prosecution.
What is a Technology Control Plan (TCP)? A Technology Control Plan is a documented set of procedures that restricts access to ITAR-controlled data and articles to authorized U.S. persons. It covers personnel screening, physical and logical access controls, and handling procedures, and it is a common expectation for demonstrating ITAR compliance.
Useful Links for More Information
- U.S. State Department’s Directorate of Defense Trade Controls (DDTC):
- DDTC Registration Page: Direct link for companies to start the registration process which is mandatory for ITAR compliance.
- DDTC ITAR Regulations Page: Detailed information on ITAR regulations, updates, and guidelines.
- United States Munitions List (USML):
- USML Categories: Link to the electronic Code of Federal Regulations (eCFR) where the USML is outlined, detailing the specific articles and services covered under ITAR.
- ITAR Compliance Training Resources:
- Export Compliance Training Institute (ECTI): Offers courses and seminars on ITAR compliance and other export control topics.
- Society for International Affairs (SIA): Provides training and conferences focused on defense trade and related compliance issues.
- ITAR Compliance Checklist and Guides:
- Bureau of Industry and Security (BIS) Compliance Guidelines: Although focused on the BIS, many of the compliance principles are similar and this resource provides valuable compliance checklists and management practices.
- Getting Started with Defense Trade: Direct link to the DDTC resource that helps businesses understand how to start with defense trade, useful for new entrants needing ITAR guidance.
- Government Publications and Updates:
-
-
- Federal Register: For updates on ITAR and related federal regulations. Useful for tracking changes to ITAR regulations and associated public commentary periods.
-
Updated 9/3/26