ITAR (International Traffic in Arms Regulations) is the U.S. State Department regulation that controls the export, access, and handling of defense articles, defense services, and related technical data. It is administered by the Directorate of Defense Trade Controls (DDTC) and codified at 22 CFR Subchapter M.
ITAR applies not only to physical exports but to digital access, electronic storage, cloud systems, and internal IT environments.
From a cybersecurity and IT standpoint, ITAR is about who can access controlled data, where it is stored, and how it is protected - even if nothing ever leaves the country.
ITAR controls three things: defense articles (the physical items), defense services (assistance and training related to them), and technical data (the information required to develop, produce, or maintain them). All three are keyed to the United States Munitions List.
Two mechanics define how ITAR actually works in practice.
Registration is mandatory, not implied. 22 CFR Part 122 requires any person who engages in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, to register with DDTC. Section 122.1 is explicit: a manufacturer who does not engage in exporting must nevertheless register. If you machine parts on the Munitions List and never ship overseas, ITAR still applies - and registration is still owed.
Access is an export. Releasing technical data to a foreign person, even inside the United States, is a deemed export under 22 CFR 120.50. That is why IT system design and access control sit at the center of ITAR compliance.
ITAR applies to organizations that manufacture defense articles, develop or handle defense-related technical data, provide defense services, or support defense contractors and programs. That includes:
If your organization touches ITAR-controlled technical data, ITAR applies - even if you never ship a physical product.
ITAR protects defense articles, defense services, and technical data listed on the United States Munitions List (USML), codified at 22 CFR Part 121. (Not the "U.S. Munitions Import List" - that is a separate import-control list administered by ATF under 27 CFR Part 447, and it is not what ITAR export controls are keyed to.)
From an IT perspective, the most critical category is ITAR-controlled technical data:
This data typically lives in file servers, cloud storage, email, collaboration tools, and development environments - which is exactly where ITAR compliance is won or lost.
The encryption carve-out qualifies the cloud rule. Storing unclassified technical data abroad is not automatically an export. Under 22 CFR 120.54(a)(5), unclassified technical data secured with end-to-end encryption of adequate strength (at minimum 128-bit security), and not intentionally sent to or stored in proscribed countries, is not an export. Under 120.54(c), mere access to properly encrypted data does not constitute a release. Unencrypted or misconfigured cloud storage outside the U.S. remains a serious violation risk - the carve-out rewards disciplined encryption; it does not forgive sloppy configuration.
These are often confused, and the distinction is structural:
The defense chain - CUI Program, NIST SP 800-171, DFARS, CMMC - governs how covered data is protected. ITAR runs parallel to that chain and governs who may access it. Export-controlled technical data is itself a category of CUI, so many organizations are subject to all of these simultaneously and need coordinated compliance across IT, security, and operations.
ITAR does not prescribe specific technologies. It requires strict control over access, storage, and transmission of technical data - which lands squarely on IT:
ITAR violations carry severe civil and criminal exposure:
Most violations are unintentional: misconfigured access controls, improper cloud usage, shared file systems, unvetted vendor access, and no visibility into who can reach the data.
ITAR aligns with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and CMMC requirements.
Organizations with strong identity, access, and data governance controls are far better positioned to meet ITAR obligations. The disciplines overlap almost completely; ITAR just raises the stakes on getting them wrong.
Here is the key takeaway: ITAR compliance is about authorized access, not geography alone.
Most violations happen because organizations do not know where ITAR data lives, do not know who can access it, or assume cloud and IT vendors handle compliance. Strong visibility and disciplined access management prevent most issues - and under the 120.54 carve-out, disciplined encryption buys real legal room that sloppy environments never get.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment traces where ITAR technical data lives, who can reach it, and whether your cloud and vendor configuration would survive a DDTC question.
Determine what you make or handle that sits on the United States Munitions List (22 CFR Part 121), and confirm DDTC registration under 22 CFR Part 122. Manufacturers who never export are still required to register - this is the most commonly missed obligation.
Document what data is ITAR-controlled, where it is stored, how it moves, and who can access it. You cannot control access to data you have not located.
Limit access to U.S. persons or foreign persons operating under a DDTC authorization. Match permissions to job roles, review access regularly, and revoke it the day authorization ends.
Implement segmented storage environments, secure cloud configurations evaluated against 22 CFR 120.54, end-to-end encryption, monitoring, and endpoint and email security.
Confirm vendors meet ITAR requirements, data residency and encryption are appropriate, access controls are enforced, and contracts reflect who is responsible for what.
Prepare access control policies, system diagrams, incident response procedures, and audit and investigation workflows. If DDTC asks, the answer needs to exist on paper.
Very possibly, twice over. First, 22 CFR 122.1 requires manufacturers of defense articles to register with DDTC even if they never export. Second, releasing technical data to a foreign person inside the U.S. is a deemed export under 22 CFR 120.50 - no shipment required. Domestic-only operations do not put you outside ITAR.
If you engage in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, yes - 22 CFR Part 122 requires it. Registration is an obligation on its own, separate from licensing. Not exporting does not exempt a manufacturer.
Yes, carefully. Under 22 CFR 120.54(a)(5), unclassified technical data secured with compliant end-to-end encryption (at minimum 128-bit security) and not intentionally sent to or stored in proscribed countries is not an export - and mere access to properly encrypted data is not a release. The configuration has to actually meet the carve-out. Unencrypted data in foreign-hosted storage is a violation risk, not a gray area.
Yes, with authorization. ITAR does not ban all foreign-person access - it requires a State Department license, exemption, or agreement such as a Technical Assistance Agreement before release. Unauthorized access is the violation. "U.S. persons only" is a common simplification, but authorization is the actual legal standard.
ITAR is export control: who may access defense technical data and where it may go. DFARS is contract law: how covered defense information must be protected. CMMC verifies the DFARS-required controls. Many defense manufacturers are subject to all three at once, and the same access-control work serves each.
Civil penalties currently reach $1,271,078 per violation or twice the transaction value, whichever is greater (22 CFR 127.10, adjusted annually). Willful violations can also bring criminal prosecution, plus loss of export privileges and debarment. Most enforcement starts with unintentional failures - misconfigured access, not espionage.
It depends on how much controlled data you hold and how contained it is. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. Segmenting ITAR data early usually costs far less than retrofitting controls across everything.
Start with two questions: are we registered with DDTC, and where does our controlled technical data actually live? Most organizations can answer neither precisely. Our Cyber Risk & Compliance Gap Assessment maps the data, the access, and the gaps before a violation forces the exercise.
Official source: State Department Directorate of Defense Trade Controls
Secondary source: eCFR, 22 CFR Subchapter M
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25