ITAR Compliance for Defense Suppliers
Determine when ITAR applies, separate registration from export authority, and connect supplier handoffs to the controls and records they require.

For a supplier, the practical sequence is to establish what is controlled, identify who will receive it, confirm the authority for each controlled activity, and preserve the supporting records. Apply that sequence to drawings and engineering support as well as finished hardware.
On This Page
- Establish what is subject to ITAR
- Separate registration from transaction authority
- Control technical-data access
- Put controls at supplier handoffs
- Keep records that survive personnel changes
- Respond when a control fails
Establish what is subject to ITAR
A military customer does not make every purchased item ITAR-controlled. Start with the relevant U.S. Munitions List (USML) entry and the item's actual characteristics. Under section 120.3, intended military or civilian use after export is not, by itself, the jurisdiction test. A component's classification needs its own analysis; the customer's industry is insufficient.
ITAR also reaches information. Section 120.33 includes information needed to produce, operate, repair, or modify defense articles, including certain drawings, photographs, instructions, and documentation. It excludes, among other things, general scientific or engineering principles commonly taught in schools, qualifying public-domain information, and basic marketing descriptions. An unclassified drawing can still be controlled technical data.
Ask the customer for the export jurisdiction, applicable classification, drawing revision, and supporting determination. Identify the exact USML category and paragraph when ITAR applies. Keep that information with the job and resolve conflicting markings before distributing the file. A label is useful evidence of how the sender treats information, but it cannot replace the underlying determination.
When doubt remains about USML coverage, section 120.4 provides the commodity jurisdiction procedure. DDTC, the State Department's Directorate of Defense Trade Controls, can determine jurisdiction. Do not interpret an unresolved request as permission to export.
The Commerce Department's Defense Export Handbook explains the separate ITAR and Export Administration Regulations (EAR) systems. A determination that an item falls under the EAR starts a different compliance analysis; it does not establish unrestricted trade. Likewise, a customer's cybersecurity or quality approval does not supply ITAR export authorization.
Separate registration from transaction authority
Section 122.1 generally requires registration for a person engaged in the United States in manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services. One occasion can satisfy the business-activity trigger. There are specific exceptions, including activity confined to producing unclassified technical data and fabrication solely for experimental or scientific purposes. Those two exceptions do not eliminate applicable export-approval requirements; a person relying on them must register before receiving an export license or approval.
Keep three questions separate: Does this entity need registration? Does this activity require authorization? Does the authorization cover the proposed work?
For defense articles, section 123.1 requires DDTC approval before export or temporary import unless an exemption applies. For defense services, Part 124 governs agreements and exceptions. An overseas production-support arrangement may need a technical assistance agreement or manufacturing license agreement. A hardware license should not be assumed to cover accompanying engineering assistance.
Read the approved scope, parties, end use, duration, and conditions, often called provisos. If a prime says its authorization covers your company, obtain the applicable terms and establish how your entity and activity are covered. A purchase order or nondisclosure agreement is not a substitute for that review. Changes to an agreement's substantive scope require approval before they take effect under section 124.1(c).
Exemptions also require analysis. Record the exact provision and why every relevant condition is met. Check destination restrictions under section 126.1, which limits exemption use and contains country-specific rules. A familiar trading partner or government customer is not enough to establish eligibility.
For continuing registration, section 122.2 requires annual renewal and fee payment. Submit renewal at least 30 days, but no earlier than 60 days, before expiration. Assign a responsible person and a backup so the deadline does not depend on one inbox.
Control technical-data access
An export can occur without an international shipment. Section 120.50 includes releasing technical data to a foreign person inside the United States and performing a defense service for a foreign person domestically or abroad. Review design meetings, visitor access, remote support, shared folders, and subcontractor communications accordingly.
Use the actual legal definition when assessing access. U.S. person includes lawful permanent residents and protected individuals under the referenced immigration statute. It is broader than U.S. citizenship. Employment, a U.S. office address, or an NDA alone does not settle whether a particular person may receive controlled data. Have export-compliance and employment specialists coordinate the process instead of turning ITAR into a blanket citizens-only hiring rule.
Cloud storage needs a precise assessment. Section 120.54(a)(5) excludes certain sending, taking, or storing of unclassified technical data from export treatment when its encryption and geographic conditions are met. It requires qualifying end-to-end encryption, the specified cryptographic strength or modules and supporting controls, and compliance with restrictions on where data originates, is intentionally sent, or is stored.
The rule's end-to-end definition also requires that third parties not receive the means of decryption. The intended recipient must qualify under paragraph (b)(2). A provider's claim that a service is encrypted therefore does not establish that the exception applies. Document the actual key access, support access, recipient authorization, and storage arrangement. An encrypted-storage exception does not authorize an otherwise prohibited recipient to read the data.
Put controls at supplier handoffs
DDTC's ITAR Compliance Risk Matrix identifies weaknesses in classification, authorization management, visitor access, training, records, and management support. It is guidance for assessing a company's risks, not a certification or a substitute for the regulations.
The following table translates the cited rules into suggested supplier procedures. The roles and filing methods are practical implementation choices, not government-mandated job titles or forms.
| Handoff | Decision before work proceeds | Working record to retain |
|---|---|---|
| Customer sends a drawing for quotation | Establish jurisdiction and permitted access before wider circulation | Classification basis, revision, sender's instructions, and access decision |
| Buyer selects a machining or finishing subcontractor | Confirm the receiving entity, site, people, and applicable authorization | Supplier review, transfer terms, and approved scope |
| Engineer adds an outside specialist to a meeting | Check whether controlled data or a defense service will be provided | Recipient review and the applicable approval or exception analysis |
| IT enables a support tool or new storage service | Review data access, decryption capability, location, and recipient eligibility | Service configuration and documented export-control assessment |
| Shipping releases an article | Match the shipment to authority, parties, destination, and conditions | Release review, shipment documentation, and authorization reference |
Source basis: sections 120.3, 120.33, 120.50, 120.54, 123.1, Parts 124 and 127, and DDTC's risk matrix, checked September 7, 2026. The handoff sequence is editorial synthesis.
Consider an illustrative job: a domestic machine shop receives a controlled drawing, then wants an overseas specialist to advise on a manufacturing problem. The access and service questions arise before the specialist joins a video call. Keeping the finished part in the United States does not answer them. The supplier needs a reviewed path for the proposed disclosure and assistance, or it must keep that work within the authorized scope.
Make the process usable under schedule pressure. Name who can hold a transfer, who resolves questions, and where employees find the current instructions. Train purchasing, engineering, shipping, IT, and reception for the decisions they actually make. Revisit access when a supplier, employee role, system, or project changes.
Keep records that survive personnel changes
For persons required to register, section 122.5 requires records covering relevant manufacture, acquisition, disposition, technical data, defense services, and other specified activities. This includes licensing documentation and documentation of exports using exemptions.
Electronic records must remain readable, reproducible on paper, and accessible. Changes must be recorded with who made them and when. A shared folder that silently overwrites earlier decisions does not meet that change-history requirement.
The retention period is generally five years from expiration of the license or other approval, or from the transaction date as applicable, including the rule's treatment of exemption transactions. Do not apply a universal “five years after shipment” deletion rule. Identify the correct trigger, account for any individually prescribed period, and make records available for authorized government inspection and copying.
A useful job file connects the article or data revision, classification basis, parties, authorization or exemption analysis, transfers, and retention trigger. Keep program records, such as training and access reviews, in a linked location. Test retrieval with a real completed job: a colleague should be able to reconstruct the decision without asking the original employee to remember it.
Corporate changes need their own calendar. Section 122.4 requires notice within five days for specified changes, including listed changes in ownership, control, legal structure, and senior personnel. Intended transfers of ownership or control to a foreign person have an advance-notice requirement of at least 60 days. That notice does not authorize disclosure of technical data during due diligence. Bring export compliance into transaction planning before opening a data room.
Respond when a control fails
The failure points are often ordinary handoffs: an uncontrolled quotation attachment, a new subcontractor outside the approved scope, an overseas support session, a missed renewal, or an authorization stored without its provisos. These are illustrative failure scenarios, not claims about their frequency across the industry.
When a suspected unauthorized release is discovered, stop further dissemination, preserve the relevant records, and bring in the responsible compliance lead and counsel promptly. Establish what was shared, with whom, when, under which authority, and whether related transfers are affected. Do not delete the trail while trying to contain the incident.
Section 127.12 describes voluntary disclosure: initial notification immediately after discovery, followed by a full disclosure within 60 calendar days when the initial notice is incomplete, unless an extension is approved. Voluntary disclosure can be considered in mitigation; it does not guarantee immunity. The provision also preserves specified affirmative reporting duties, so do not assume every report is optional.
Before accepting affected work, resolve three operational questions: who owns classification, who can authorize each transfer, and who can retrieve the record supporting it. Then walk one drawing and one physical article through the proposed job. Any handoff that lacks an answer belongs in the work plan before production commitments make it harder to correct.
Source notes
- 22 CFR 120.3: regulatory criteria for defense-article and defense-service jurisdiction.
- 22 CFR 120.33: technical-data definition and exclusions.
- 22 CFR 120.4: commodity jurisdiction procedure.
- 2025 Defense Export Handbook: Commerce Department guidance explaining export-control jurisdiction and authorization routes.
- 22 CFR 122.1 and 122.2: registration applicability, limits, and renewal.
- 22 CFR 123.1 and Part 124: license and agreement requirements.
- 22 CFR 126.1: destination restrictions and limits on exemptions.
- 22 CFR 120.50 and 120.62: export and U.S.-person definitions.
- 22 CFR 120.54: conditions for activities excluded from export treatment, including encrypted technical-data handling.
- DDTC ITAR Compliance Risk Matrix: agency guidance on business functions and compliance vulnerabilities.
- 22 CFR 122.5 and 122.4: records, retention, and registration-change notifications.
- 22 CFR Part 127: violations and voluntary-disclosure procedures.
The cited eCFR pages displayed Title 22 current through September 3, 2026. Recheck the applicable text and effective dates before a transaction.
Last checked: September 7, 2026.
Documentation
Sources
These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.
- 22 CFR 120.3eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 120.33eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 120.4eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 2025 Defense Export HandbookU.S. Department of Commerce · Publication date not recorded · checked September 7, 2026
- 22 CFR 122.1eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 122.2eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 123.1eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR Part 124eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 126.1eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 120.50eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 120.62eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 120.54eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- DDTC ITAR Compliance Risk MatrixDirectorate of Defense Trade Controls · Publication date not recorded · checked September 7, 2026
- 22 CFR 122.5eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR 122.4eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026
- 22 CFR Part 127eCFR / U.S. Department of State · Publication date not recorded · checked September 7, 2026