Navigating ITAR Compliance: What You Need to Know

Compliance with the International Traffic in Arms Regulations (ITAR) is mandatory for companies that work with the U.S. defense sector, and the stakes are high: civil penalties now exceed $1.27 million per violation, alongside criminal charges and loss of export privileges. ITAR is not only a legal and paperwork obligation. Because it controls defense-related technical data, it is also an IT and data-security obligation. 

IT Solutions Technology Partners helps defense contractors and manufacturers implement the IT side of ITAR, including U.S.-person access controls, compliant cloud environments, and encryption, work that overlaps heavily with CMMC and NIST SP 800-171. As a Microsoft Solutions Partner and a SOC 2 Type II compliant provider, ITS focuses on the systems that protect controlled technical data.

What is ITAR compliance?

ITAR compliance means following the U.S. State Department regulations that control the export and import of defense articles, defense services, and related technical data listed on the United States Munitions List (USML). Administered by the Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA), ITAR is designed to keep sensitive military technology from reaching unauthorized foreign persons. Compliance is mandatory for manufacturers, exporters, and brokers of defense articles and technical data.

A key point that surprises many companies: under ITAR, an “export” is not only shipping a physical part overseas. Giving a foreign person access to controlled technical data, even a foreign national employee inside the United States or an offshore IT administrator, counts as an export (a “deemed export”). That is why ITAR reaches directly into how you store, transmit, and control access to data.

Who needs to be ITAR compliant?

Any company that manufactures, exports, brokers, or handles defense articles, defense services, or ITAR-controlled technical data must comply. This extends well beyond obvious weapons makers. It includes subcontractors and suppliers in the defense supply chain, engineering and software firms that touch technical data, and any IT, SaaS, or cloud provider that stores, processes, or grants access to that data. If your systems hold ITAR technical data, ITAR applies to you.

The USML spans a broad range of categories, from firearms and ammunition to military electronics, aircraft, and spacecraft, and it covers defense services such as training foreign units or modifying defense articles. Companies often discover they are in scope not because they build weapons, but because they hold controlled drawings, specifications, or source code on behalf of a prime contractor.

What are the penalties for ITAR violations?

ITAR penalties are severe and are adjusted for inflation each year. As of 2025, the civil penalty is $1,271,078 per violation, or twice the value of the transaction, whichever is greater. Criminal penalties for willful violations reach up to $1 million in fines and up to 20 years of imprisonment per violation. Companies can also face debarment, loss of export privileges, and seizure of goods.

Penalty type Maximum exposure
Civil (per violation) $1,271,078 (2025), or twice the transaction value, whichever is greater
Criminal (per willful violation) Up to $1,000,000 in fines and up to 20 years imprisonment
Additional consequences Statutory debarment, loss of export privileges, seizure or forfeiture of goods, mandatory consent agreements

 

Enforcement is active and the amounts are large. In 2024, defense manufacturer RTX (Raytheon) agreed to federal settlements totaling roughly $950 million to resolve multiple enforcement matters, including ITAR violations, one of the largest export-control-related actions on record. Earlier cases, such as a 2023 settlement of up to $27 million against a U.S. manufacturer for unauthorized transfers of technical data, show that mid-sized companies are targets too. The trend across recent years is toward higher penalties and more aggressive enforcement.

How does ITAR affect your IT and data security?

ITAR directly governs your IT because controlled technical data must be protected from foreign-person access at every point: storage, transmission, and administration. Making that data available to a foreign person, including an unauthorized employee or an offshore cloud administrator, is treated as an export. In practice, that means U.S.-person access controls, encryption, careful cloud choices, and audit logging are not optional extras. They are how you stay compliant.

Four IT and data-security rules matter most:

  • U.S.-person access control: Only U.S. persons (or those with specific DDTC authorization) may access ITAR technical data. This requires enforced access controls, personnel screening, and usually a documented Technology Control Plan (TCP).
  • The encryption carve-out (22 CFR § 120.54): Since 2020, storing or sending unclassified ITAR technical data over the internet or in the cloud is not treated as an export if four conditions are met: the data is unclassified, it is end-to-end encrypted, the encryption uses FIPS 140-2 (or a validated successor) modules, and the decryption keys are never provided to any foreign person or held in a proscribed country. The carve-out protects the encrypted data in transit and at rest; a foreign person accessing the decrypted data is still an export.
  • Data residency and compliant cloud: ITAR does not strictly require U.S.-only storage, but keeping data in the United States with U.S.-person access is the standard mitigation. Microsoft 365 GCC High and Azure Government are the environments most defense contractors use, because they keep data in the continental U.S., limit access to U.S. persons, and carry contractual ITAR commitments that standard commercial Microsoft 365 does not.
  • Audit and evidence: DDTC reviews expect proof, not policies: access logs showing that only U.S. persons reached the data, and evidence that encryption met FIPS standards.

This is the part of ITAR that lives in your IT environment, and it is where an experienced managed IT and compliance partner adds the most value.

ITAR vs EAR: what is the difference?

ITAR and the Export Administration Regulations (EAR) are two separate U.S. export-control regimes. ITAR, administered by the State Department’s DDTC, controls defense articles and services on the USML. The EAR, administered by the Commerce Department’s Bureau of Industry and Security (BIS), controls “dual-use” items (commercial goods with possible military applications) on the Commerce Control List (CCL). Knowing which regime governs your product is the first compliance decision.

ITAR EAR
Administered by State Department (DDTC) Commerce Department (BIS)
Governs Defense articles, services, and technical data Dual-use and commercial items
Control list U.S. Munitions List (USML) Commerce Control List (CCL)
Registration Required with DDTC Not generally required
Civil penalty (2025) $1,271,078 per violation $374,474 per violation

 

Some items have moved from the USML to the CCL over the years, so classification should be confirmed rather than assumed. Many defense contractors are subject to both regimes.

How does ITAR relate to CMMC, CUI, and NIST SP 800-171?

ITAR overlaps heavily with the Department of Defense’s cybersecurity requirements. ITAR-controlled technical data is almost always also Controlled Unclassified Information (CUI), which brings it under DFARS 252.204-7012, NIST SP 800-171, and CMMC. In other words, the same data that ITAR says must be protected from foreign-person access is the data CMMC says must be protected with specific security controls. Treating them as one program, rather than three silos, is far more efficient.

For most defense contractors, this convergence is the practical reason to build a single controlled environment (for example, Microsoft 365 GCC High) that satisfies ITAR’s U.S.-person and encryption requirements and the NIST SP 800-171 controls behind CMMC at the same time. IT Solutions Technology Partners helps defense and manufacturing clients design that shared foundation so one investment covers overlapping obligations.

How do you achieve and maintain ITAR compliance?

Achieving ITAR compliance follows a clear sequence: register, classify your data, control access, secure your systems, train your people, and audit continuously. The legal and IT sides run in parallel, because registration and licensing mean little if your systems let an unauthorized person reach the data.

  1. Register with the DDTC. Manufacturers, exporters, and brokers of defense articles and technical data must register with the Directorate of Defense Trade Controls and obtain the appropriate licenses for what they plan to export.
  2. Classify your data and map its flow. Determine which data is ITAR-controlled by checking it against the USML, then map where it lives and who can reach it.
  3. Control access to U.S. persons. Enforce U.S.-person-only access with identity and access controls, personnel screening, and a documented Technology Control Plan.
  4. Secure your systems. Use a compliant environment (commonly Microsoft 365 GCC High or Azure Government), apply FIPS-validated end-to-end encryption per the 22 CFR § 120.54 carve-out, and enable audit logging.
  5. Train your people. Provide ongoing ITAR awareness training for all relevant personnel, since human error is a leading cause of violations.
  6. Audit and update. Perform regular internal and external audits, keep evidence of controls and access, and update procedures as regulations and your business change.

How does IT Solutions Technology Partners help with ITAR compliance?

IT Solutions Technology Partners helps defense contractors and manufacturers build and run the IT environment that ITAR requires. That includes designing U.S.-person access controls, deploying and managing compliant cloud environments such as Microsoft 365 GCC High and Azure Government, implementing FIPS-validated encryption, and producing the access and audit evidence DDTC reviews expect. Because ITAR data is almost always also CUI, ITS aligns this work with NIST SP 800-171 and CMMC so a single program covers overlapping requirements.

Founded in 1994 and supporting clients from 14 offices with a team of roughly 450 to 500 professionals, ITS pairs this compliance work with the managed IT and cybersecurity foundation defense and manufacturing organizations depend on. ITS supports the technology side of export-control compliance; it does not replace qualified export-control counsel, and the two work best together.

Frequently Asked Questions

Is ITAR the same as EAR? No. ITAR, administered by the State Department’s DDTC, controls defense articles and technical data on the U.S. Munitions List. The EAR, administered by the Commerce Department’s BIS, controls dual-use and commercial items on the Commerce Control List. Many defense contractors are subject to both, so each product should be classified to determine which applies.

Can ITAR-controlled technical data be stored in the cloud? Yes, within limits. Since 2020, the 22 CFR § 120.54 encryption carve-out allows unclassified ITAR technical data to be stored and transmitted in the cloud without it counting as an export, provided the data is end-to-end encrypted with FIPS 140-2 validated encryption and the decryption keys are never accessible to a foreign person. Most contractors use Microsoft 365 GCC High or Azure Government for this.

Does ITAR require data to be stored in the United States? Not strictly, but keeping data in the U.S. with access limited to U.S. persons is the widely adopted way to meet ITAR’s requirements. Standard commercial cloud regions do not guarantee U.S. data residency or U.S.-person-only access, which is why defense contractors typically choose government cloud environments.

Is ITAR-controlled data also considered CUI? Almost always. ITAR technical data typically qualifies as Controlled Unclassified Information, which brings it under DFARS 252.204-7012, NIST SP 800-171, and CMMC. Building one controlled environment to satisfy both ITAR and CMMC is usually more efficient than running separate programs.

Who enforces ITAR? ITAR is administered and enforced by the U.S. State Department’s Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act. Civil penalties are set by the State Department and adjusted for inflation each year; criminal cases can be referred for prosecution.

What is a Technology Control Plan (TCP)? A Technology Control Plan is a documented set of procedures that restricts access to ITAR-controlled data and articles to authorized U.S. persons. It covers personnel screening, physical and logical access controls, and handling procedures, and it is a common expectation for demonstrating ITAR compliance.


Useful Links for More Information

  1. U.S. State Department’s Directorate of Defense Trade Controls (DDTC):
  2. United States Munitions List (USML):
    • USML Categories: Link to the electronic Code of Federal Regulations (eCFR) where the USML is outlined, detailing the specific articles and services covered under ITAR.
  3. ITAR Compliance Training Resources:
  4. ITAR Compliance Checklist and Guides:
  5. Government Publications and Updates:
      • Federal Register: For updates on ITAR and related federal regulations. Useful for tracking changes to ITAR regulations and associated public commentary periods.

Updated 9/3/26

What CMMC Level Does Your Business Need?

If you’re a defense contractor or subcontractor, chances are you’ve been hearing more and more about the Cybersecurity Maturity Model Certification, or CMMC. It’s the Department of Defense’s (DoD) framework for making sure every company in the Defense Industrial Base (DIB) protects government data at the level it deserves.

Here’s the problem: between acronyms like FCI, CUI, NIST 800-171, and C3PAO assessments, it’s easy to get lost in the jargon. The question we hear most often from clients sums it up perfectly:

“What CMMC level do we actually need?”

The answer isn’t one-size-fits-all. It depends on two things—the type of information you handle and what your contract says. Let’s walk through how to figure that out.

Step One: Know What Kind of Data You Handle

CMMC requirements start with two categories of data: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

FCI is information that’s provided by or generated for the government under a contract but isn’t meant for public release. Think of it as the everyday details of doing business with the DoD—project timelines, internal correspondence, schedules, and so on. The handling of FCI is covered under FAR 52.204-21.

CUI, on the other hand, involves more sensitive material. Laws, regulations, or government-wide policies require it to be protected with added safeguards. That might include technical drawings, specifications, or export-controlled data. You can find the official definition in 32 CFR § 2002.4(h) and the DoD’s CUI guidance.

If your organization works only with FCI, you’ll most likely fall under CMMC Level 1. Handling CUI? That moves you into Level 2, or for the rare, highly sensitive programs, Level 3.

Keep in mind: CMMC requirements flow down to subcontractors. If your prime contractor shares CUI with you, you have to meet the same level they do. It’s not optional.

The Current CMMC Framework: Three Levels

When CMMC first rolled out, it included five levels. The current version, CMMC 2.0, streamlined that to three, making the model easier to understand and apply.

Level What It Covers Assessment Type Core Standard Typical Use Case
Level 1 – Foundational Basic safeguarding of FCI Annual self-assessment and affirmation FAR 52.204-21 Contractors handling only FCI
Level 2 – Advanced Protection of CUI Self-assessment or third-party certification by a C3PAO, depending on the contract NIST SP 800-171 Most defense contractors and subcontractors
Level 3 – Expert Enhanced protection for critical programs DoD-led DIBCAC assessment NIST SP 800-172 Select, high-sensitivity contracts

Level 1 covers 17 basic practices. Level 2 expands to all 110 controls in NIST SP 800-171. Level 3 adds a handful of the more advanced requirements from NIST SP 800-172. (DoD CIO, CMMC Model Overview v2.0, Dec 2021)

How to Match Your Situation to a Level

A practical way to think about CMMC levels is by asking what kind of data lives in your systems:

  • Level 1: You deal with FCI only. You’ll perform an annual self-assessment, upload the score to the Supplier Performance Risk System (SPRS), and affirm compliance each year.
  • Level 2: You handle CUI. Your contract will say whether you can self-assess or need a C3PAO (CMMC Third-Party Assessment Organization) certification. Assessments typically recur every three years.
  • Level 3: You’re supporting a critical national security program, so the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) will perform the assessment directly.

When in doubt, read your clauses.

Before You Bid: A Quick Readiness Check

Before spending time and money preparing a proposal, take an honest look at your current posture:

  • Does the solicitation include DFARS 252.204-7021? If so, CMMC applies.
  • Does it reference CUI or “covered defense information”? That points to Level 2 or higher.
  • Have you already submitted a NIST SP 800-171 score in SPRS? (That’s now required for most DoD contracts.)
  • Does the solicitation specify Level 2 (self) or Level 2 (C3PAO required)?
  • Do your subcontractors handle FCI or CUI? Their systems must meet the same standard.
  • Can you clearly define where CUI resides? Sometimes setting up a separate, secure enclave is more practical than locking down your entire enterprise network.

Getting this clarity early helps avoid compliance gaps that can derail a bid. DoD contracting officers increasingly check SPRS scores and CMMC status before awarding or extending contracts.

Building a Realistic Roadmap

Once you’ve identified your level, you can start mapping out next steps.

  1. Classify your data. Confirm whether you handle FCI, CUI, or both.
  2. Confirm the required level and assessment type. The solicitation will tell you.
  3. Run a gap assessment. Compare your systems to the controls in NIST SP 800-171 or FAR 52.204-21.
  4. Document your findings. Develop a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) for anything not yet complete.
  5. Post your score. Level 2 organizations must submit their SPRS score before award.
  6. Close the gaps. If you’ve received conditional approval, you usually have 180 days to resolve remaining items.
  7. Plan for recurring assessments. Expect annual affirmations and triennial reassessments depending on your level.

Treating CMMC like a phased project with owners, milestones, and documentation keeps it manageable and prevents last-minute scrambles.

When It’s Time to Ask for Help

Many contractors eventually realize they need outside support. Bringing in a CMMC consultant can make a world of difference if:

  • You’re not sure whether specific data counts as CUI.
  • Your SPRS score is low and you need to prioritize fixes.
  • You’re facing a C3PAO audit or preparing for DIBCAC review.
  • You’d rather build a secure enclave than harden every system.
  • You rely on multiple subcontractors or cloud providers that also handle CUI.

A qualified cybersecurity partner will start with a gap review, outline a readiness plan, and guide you through remediation so you can focus on running your business instead of deciphering compliance jargon.

Final Thoughts

CMMC isn’t just another government checkbox. It’s about keeping the information that supports our national defense safe and keeping your organization eligible to compete.

By understanding the kind of data you manage, reading your contracts carefully, and building a realistic action plan, you can move through CMMC confidently and position your company for long-term success in the DoD supply chain.

🟢 Need help figuring out which level applies to your business or how to get ready for your assessment? Book a consult to map your scope, score your readiness, and plan your next steps.

FAQs

  • Does my industry determine my CMMC level?
    • No. Your contract language and the type of data you handle determine your level—not your industry category.
  • How often do we need to reassess?
    • Level 1 requires an annual self-attestation.
    • Level 2 requires a triennial assessment (self or C3PAO) with yearly affirmations.
    • Level 3 involves a DoD-led review every three years.
  • What if we’re almost compliant but not quite there?
    • The DoD may allow a temporary or “conditional” status with an approved POA&M, but all open items must be closed within 180 days to maintain eligibility.

🟢 For more detail on CMMC preparation, visit our CMMC Compliance Services page.