What is ITAR?

ITAR — the International Traffic in Arms Regulations — is the US export-control regime governing defense articles, defense services and related technical data. It is administered by the Directorate of Defense Trade Controls (DDTC) at the Department of State, and it implements the Arms Export Control Act.

What ITAR controls is defined by the United States Munitions List (USML) — 21 categories covering firearms, ammunition, launch vehicles, missiles, military electronics, aircraft, spacecraft, military training equipment, protective personnel equipment and more. If your product, component or the technical data describing it falls in a USML category, you are in ITAR territory.

ITAR is frequently confused with the EAR (Export Administration Regulations), administered by the Commerce Department and covering dual-use items on the Commerce Control List. The distinction matters enormously, because the two regimes have different licensing, different registration duties and very different penalty exposure. Determining which regime your item falls under — and the specific classification within it — is the foundational step, and getting it wrong invalidates everything built on top.

Who needs an ITAR compliance program

ITAR obligations attach to:

  • Manufacturers of defense articles, whether or not they export
  • Exporters of defense articles, services or technical data
  • Brokers arranging transactions in defense articles
  • Aerospace and defense suppliers at any tier, including machine shops working from controlled drawings
  • Engineering and design firms that generate or receive controlled technical data
  • Universities and research organizations conducting controlled research
  • Companies with foreign-national employees, foreign parent companies, or offshore engineering support

Note the first item: manufacturers of defense articles must register with DDTC even if they never export anything. That single requirement catches a great many companies unaware.

The concept that surprises people most is the deemed export. Releasing controlled technical data to a foreign national — even one lawfully employed at your own facility in the United States — is treated as an export to that person's country of nationality, and may require a licence. An email, a drawing on a screen, a plant tour, or a shared engineering folder can all constitute an export. There is no physical border crossing involved.

What an ITAR program requires

ITAR compliance is not a certification. It is a regulatory obligation, and what you build is a documented compliance program:

  • Jurisdiction and classification — determining whether items fall under ITAR or the EAR, and their specific USML category or ECCN, with a documented rationale. Commodity jurisdiction requests to DDTC where genuinely unclear.
  • DDTC registration — required annually for manufacturers, exporters and brokers
  • An Empowered Official — a named, qualified person with the authority to sign licence applications and the responsibility that comes with it
  • A Technology Control Plan (TCP) — how controlled technical data is physically and electronically segregated, and access restricted by nationality
  • Licensing — DSP-5, DSP-73, agreements such as TAAs and MLAs, and correct use of exemptions
  • Screening — employees, visitors, customers and partners against debarred and denied-party lists
  • IT controls — access control, encryption, and careful handling of cloud storage and offshore IT support, which is a frequent inadvertent violation
  • Training — role-specific, for engineering, sales, shipping, HR and IT
  • Recordkeeping — generally five years, and rigorous
  • Voluntary disclosure procedures — because self-reporting a violation materially affects the outcome

Why this one deserves real attention

We are direct with clients about ITAR because the consequences sit at the top end of regulatory compliance. Civil penalties run to substantial sums per violation, and criminal penalties include imprisonment. Debarment — losing the right to export at all — is an existential outcome for a defense supplier. Enforcement is active, and it reaches individuals, not only companies.

The uncomfortable part is that the most common violations are not deliberate arms trafficking. They are ordinary business behaviour by people who did not know the rules applied: an engineer emailing a drawing to a colleague overseas, a foreign-national employee given routine access to a controlled folder, technical data placed in a cloud service with offshore administration, or a supplier sent a specification without an export review.

On the positive side, an ITAR program is also a market qualifier. Primes increasingly require evidence of one before flowing controlled work down, and being able to demonstrate a real program — Empowered Official, TCP, training records, screening — is what gets you onto the bid list.

How QSE builds your program

We bring 30+ years of building compliance systems and 900+ organizations certified, much of it in aerospace and defense where ITAR sits alongside AS9100 and, increasingly, CMMC.

One clarification first: ITAR is not something you get certified in, and no consultant can grant you compliance. There is no registrar and no certificate. What exists is a documented program, and its test is whether it holds up to a DDTC review, a prime's audit, or the day something goes wrong. We should also say plainly that classification and licensing questions at the boundaries are legal determinations — we build the program and will tell you when you need export counsel rather than a consultant.

We start with jurisdiction and classification, because everything downstream depends on it. Then we handle registration, appoint and train your Empowered Official, build the Technology Control Plan with your IT and facilities teams, put screening and licensing procedures in place, and deliver role-specific training to the functions that actually create exposure — engineering, sales, shipping, HR and IT. We integrate it with your AS9100 system rather than running a separate binder.

Then we audit you against it. Most organizations have a working program in about 4 to 8 months.

Common pitfalls we help you avoid

  • Deemed exports — giving foreign-national employees, contractors or visitors access to controlled technical data without a licence
  • Assuming ITAR does not apply because you do not export — manufacturers of defense articles must still register with DDTC
  • Confusing ITAR and the EAR, and applying the wrong regime's rules
  • Storing controlled technical data in cloud services with offshore administration, or using offshore IT support with access to it
  • An Empowered Official in name only, without the knowledge or authority the role requires
  • No Technology Control Plan, or one that exists on paper while the shared drive stays open to everyone
  • Relying on exemptions without documenting eligibility
  • Sending drawings or specifications to suppliers without an export review
  • Training only the export team, when the real exposure sits in engineering, HR and IT
  • Discovering a violation and saying nothing — voluntary disclosure materially improves the outcome