AnalysisManufacturing

ITAR Compliance for Defense Suppliers

Determine when ITAR applies, separate registration from export authority, and connect supplier handoffs to the controls and records they require.

ByMilitary Contractor Editorial
PublishedSeptember 7, 2026
Last checkedSeptember 7, 2026
Reading time10 minutes
Cutting tool machining a clamped metal workpiece, with metal chips scattered across the machine bed
A CNC machine aboard USS George Washington, June 3, 2025. Manufacturing context only; the photograph does not establish the export classification of the depicted equipment or workpiece.

For a supplier, the practical sequence is to establish what is controlled, identify who will receive it, confirm the authority for each controlled activity, and preserve the supporting records. Apply that sequence to drawings and engineering support as well as finished hardware.

On This Page

Establish what is subject to ITAR

A military customer does not make every purchased item ITAR-controlled. Start with the relevant U.S. Munitions List (USML) entry and the item's actual characteristics. Under section 120.3, intended military or civilian use after export is not, by itself, the jurisdiction test. A component's classification needs its own analysis; the customer's industry is insufficient.

ITAR also reaches information. Section 120.33 includes information needed to produce, operate, repair, or modify defense articles, including certain drawings, photographs, instructions, and documentation. It excludes, among other things, general scientific or engineering principles commonly taught in schools, qualifying public-domain information, and basic marketing descriptions. An unclassified drawing can still be controlled technical data.

Ask the customer for the export jurisdiction, applicable classification, drawing revision, and supporting determination. Identify the exact USML category and paragraph when ITAR applies. Keep that information with the job and resolve conflicting markings before distributing the file. A label is useful evidence of how the sender treats information, but it cannot replace the underlying determination.

When doubt remains about USML coverage, section 120.4 provides the commodity jurisdiction procedure. DDTC, the State Department's Directorate of Defense Trade Controls, can determine jurisdiction. Do not interpret an unresolved request as permission to export.

The Commerce Department's Defense Export Handbook explains the separate ITAR and Export Administration Regulations (EAR) systems. A determination that an item falls under the EAR starts a different compliance analysis; it does not establish unrestricted trade. Likewise, a customer's cybersecurity or quality approval does not supply ITAR export authorization.

Separate registration from transaction authority

Section 122.1 generally requires registration for a person engaged in the United States in manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services. One occasion can satisfy the business-activity trigger. There are specific exceptions, including activity confined to producing unclassified technical data and fabrication solely for experimental or scientific purposes. Those two exceptions do not eliminate applicable export-approval requirements; a person relying on them must register before receiving an export license or approval.

Keep three questions separate: Does this entity need registration? Does this activity require authorization? Does the authorization cover the proposed work?

For defense articles, section 123.1 requires DDTC approval before export or temporary import unless an exemption applies. For defense services, Part 124 governs agreements and exceptions. An overseas production-support arrangement may need a technical assistance agreement or manufacturing license agreement. A hardware license should not be assumed to cover accompanying engineering assistance.

Read the approved scope, parties, end use, duration, and conditions, often called provisos. If a prime says its authorization covers your company, obtain the applicable terms and establish how your entity and activity are covered. A purchase order or nondisclosure agreement is not a substitute for that review. Changes to an agreement's substantive scope require approval before they take effect under section 124.1(c).

Exemptions also require analysis. Record the exact provision and why every relevant condition is met. Check destination restrictions under section 126.1, which limits exemption use and contains country-specific rules. A familiar trading partner or government customer is not enough to establish eligibility.

For continuing registration, section 122.2 requires annual renewal and fee payment. Submit renewal at least 30 days, but no earlier than 60 days, before expiration. Assign a responsible person and a backup so the deadline does not depend on one inbox.

Control technical-data access

An export can occur without an international shipment. Section 120.50 includes releasing technical data to a foreign person inside the United States and performing a defense service for a foreign person domestically or abroad. Review design meetings, visitor access, remote support, shared folders, and subcontractor communications accordingly.

Use the actual legal definition when assessing access. U.S. person includes lawful permanent residents and protected individuals under the referenced immigration statute. It is broader than U.S. citizenship. Employment, a U.S. office address, or an NDA alone does not settle whether a particular person may receive controlled data. Have export-compliance and employment specialists coordinate the process instead of turning ITAR into a blanket citizens-only hiring rule.

Cloud storage needs a precise assessment. Section 120.54(a)(5) excludes certain sending, taking, or storing of unclassified technical data from export treatment when its encryption and geographic conditions are met. It requires qualifying end-to-end encryption, the specified cryptographic strength or modules and supporting controls, and compliance with restrictions on where data originates, is intentionally sent, or is stored.

The rule's end-to-end definition also requires that third parties not receive the means of decryption. The intended recipient must qualify under paragraph (b)(2). A provider's claim that a service is encrypted therefore does not establish that the exception applies. Document the actual key access, support access, recipient authorization, and storage arrangement. An encrypted-storage exception does not authorize an otherwise prohibited recipient to read the data.

Put controls at supplier handoffs

DDTC's ITAR Compliance Risk Matrix identifies weaknesses in classification, authorization management, visitor access, training, records, and management support. It is guidance for assessing a company's risks, not a certification or a substitute for the regulations.

The following table translates the cited rules into suggested supplier procedures. The roles and filing methods are practical implementation choices, not government-mandated job titles or forms.

HandoffDecision before work proceedsWorking record to retain
Customer sends a drawing for quotationEstablish jurisdiction and permitted access before wider circulationClassification basis, revision, sender's instructions, and access decision
Buyer selects a machining or finishing subcontractorConfirm the receiving entity, site, people, and applicable authorizationSupplier review, transfer terms, and approved scope
Engineer adds an outside specialist to a meetingCheck whether controlled data or a defense service will be providedRecipient review and the applicable approval or exception analysis
IT enables a support tool or new storage serviceReview data access, decryption capability, location, and recipient eligibilityService configuration and documented export-control assessment
Shipping releases an articleMatch the shipment to authority, parties, destination, and conditionsRelease review, shipment documentation, and authorization reference

Source basis: sections 120.3, 120.33, 120.50, 120.54, 123.1, Parts 124 and 127, and DDTC's risk matrix, checked September 7, 2026. The handoff sequence is editorial synthesis.

Consider an illustrative job: a domestic machine shop receives a controlled drawing, then wants an overseas specialist to advise on a manufacturing problem. The access and service questions arise before the specialist joins a video call. Keeping the finished part in the United States does not answer them. The supplier needs a reviewed path for the proposed disclosure and assistance, or it must keep that work within the authorized scope.

Make the process usable under schedule pressure. Name who can hold a transfer, who resolves questions, and where employees find the current instructions. Train purchasing, engineering, shipping, IT, and reception for the decisions they actually make. Revisit access when a supplier, employee role, system, or project changes.

Keep records that survive personnel changes

For persons required to register, section 122.5 requires records covering relevant manufacture, acquisition, disposition, technical data, defense services, and other specified activities. This includes licensing documentation and documentation of exports using exemptions.

Electronic records must remain readable, reproducible on paper, and accessible. Changes must be recorded with who made them and when. A shared folder that silently overwrites earlier decisions does not meet that change-history requirement.

The retention period is generally five years from expiration of the license or other approval, or from the transaction date as applicable, including the rule's treatment of exemption transactions. Do not apply a universal “five years after shipment” deletion rule. Identify the correct trigger, account for any individually prescribed period, and make records available for authorized government inspection and copying.

A useful job file connects the article or data revision, classification basis, parties, authorization or exemption analysis, transfers, and retention trigger. Keep program records, such as training and access reviews, in a linked location. Test retrieval with a real completed job: a colleague should be able to reconstruct the decision without asking the original employee to remember it.

Corporate changes need their own calendar. Section 122.4 requires notice within five days for specified changes, including listed changes in ownership, control, legal structure, and senior personnel. Intended transfers of ownership or control to a foreign person have an advance-notice requirement of at least 60 days. That notice does not authorize disclosure of technical data during due diligence. Bring export compliance into transaction planning before opening a data room.

Respond when a control fails

The failure points are often ordinary handoffs: an uncontrolled quotation attachment, a new subcontractor outside the approved scope, an overseas support session, a missed renewal, or an authorization stored without its provisos. These are illustrative failure scenarios, not claims about their frequency across the industry.

When a suspected unauthorized release is discovered, stop further dissemination, preserve the relevant records, and bring in the responsible compliance lead and counsel promptly. Establish what was shared, with whom, when, under which authority, and whether related transfers are affected. Do not delete the trail while trying to contain the incident.

Section 127.12 describes voluntary disclosure: initial notification immediately after discovery, followed by a full disclosure within 60 calendar days when the initial notice is incomplete, unless an extension is approved. Voluntary disclosure can be considered in mitigation; it does not guarantee immunity. The provision also preserves specified affirmative reporting duties, so do not assume every report is optional.

Before accepting affected work, resolve three operational questions: who owns classification, who can authorize each transfer, and who can retrieve the record supporting it. Then walk one drawing and one physical article through the proposed job. Any handoff that lacks an answer belongs in the work plan before production commitments make it harder to correct.

Source notes

The cited eCFR pages displayed Title 22 current through September 3, 2026. Recheck the applicable text and effective dates before a transaction.

Last checked: September 7, 2026.

Sources

These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.

  1. 22 CFR 120.3eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  2. 22 CFR 120.33eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  3. 22 CFR 120.4eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  4. 2025 Defense Export HandbookU.S. Department of Commerce · Publication date not recorded · checked September 7, 2026
  5. 22 CFR 122.1eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  6. 22 CFR 122.2eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  7. 22 CFR 123.1eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  8. 22 CFR Part 124eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  9. 22 CFR 126.1eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  10. 22 CFR 120.50eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  11. 22 CFR 120.62eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  12. 22 CFR 120.54eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  13. DDTC ITAR Compliance Risk MatrixDirectorate of Defense Trade Controls · Publication date not recorded · checked September 7, 2026
  14. 22 CFR 122.5eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  15. 22 CFR 122.4eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
  16. 22 CFR Part 127eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026