The International Traffic in Arms Regulations (ITAR) are US rules, administered by the State Department, that control the export and temporary import of defense articles, defense services and the technical data behind them. Items in scope are listed on the US Munitions List (USML). For an IT buyer, ITAR matters because technical data, such as drawings, specifications and manufacturing know-how, often lives in email, file shares, cloud storage and backups, and letting a foreign person access it can count as an export. This entry is general information, not legal advice; confirm your obligations with export counsel.
At a glance
- ITAR is administered by the State Department’s Directorate of Defense Trade Controls (DDTC) and covers items on the US Munitions List.
- “Export” includes releasing technical data to a foreign person, including one working inside the US, which is why system access matters.
- There is no official ITAR certification for cloud, email or IT providers; providers can only support your compliance.
- Many companies that make USML items must register with DDTC, and most exports need a license unless an exemption applies.
- ITAR often sits alongside CMMC and NIST SP 800-171 in defense supply chains.
What problem it solves
ITAR exists to keep sensitive military technology out of the wrong hands. For a company in a defense supply chain, it turns that goal into concrete duties: know which items and data are controlled, decide who may receive them, and get government approval before they leave the US or reach a foreign person.
In IT terms, the problem is access. A mid-sized machine shop, electronics maker or engineering firm may keep controlled drawings in the same Microsoft 365 tenant, file server or backup service as everything else. If a provider’s support staff abroad can read that data, or it is replicated to an overseas region, the company may have made an unlicensed export without shipping anything. ITAR forces buyers to ask where data sits and who can touch it.
How it works
Jurisdiction and classification. The first question is whether an item or piece of data is on the USML (ITAR) or instead falls under the Commerce Department’s Export Administration Regulations (EAR). When it is unclear, a company can ask DDTC for a commodity jurisdiction determination.
Exports and deemed exports. Sending controlled technical data abroad, or releasing it to a foreign person in the US, generally needs authorization. Release can be as simple as granting a login.
Registration, licenses and exemptions. Registered companies apply for licenses or agreements for specific exports, or use an exemption where one fits.
Encryption. The rules include conditions under which data secured with qualifying end-to-end encryption is not treated as exported. They are narrow, and how they apply to a given cloud setup is a question for counsel.
Compliance program. Companies typically keep a written program covering classification, access controls, screening, training and recordkeeping.
Registration, licenses and exemptions
ITAR has no tiers. Its structure is a set of government approvals, shown below in general terms; which apply to you depends on your products and activities.
| Approval | What triggers it | How it is obtained | What a company typically shows |
|---|---|---|---|
| DDTC registration | Manufacturing, exporting or brokering USML items, generally even without exporting | Filed with DDTC and renewed periodically | Current registration |
| Export license or agreement | Exporting a defense article, technical data or defense service, including release to a foreign person | Application to DDTC, approved case by case | License or agreement number and its conditions |
| Exemption | A specific situation the regulations exempt | Self-determined, with records kept | Documented basis for using the exemption |
| Commodity jurisdiction | Unclear whether an item is ITAR or EAR | Request to DDTC | DDTC’s written determination |
When it matters for buyers
- When a customer flows down ITAR data. Your IT environment must keep that data away from unauthorized foreign persons.
- When choosing cloud, email or collaboration services. Ask whether data stays in the US and whether only US persons provide support. Government-focused cloud offerings often exist for this reason.
- When hiring an MSP or help desk. Offshore technicians with admin rights can be a problem.
- When setting up backups and disaster recovery. Replicas and backups count too.
- When preparing for CMMC. The same environment often has to meet both.
Our governance, risk and compliance overview covers advisors who help scope controlled data and environments.
Questions to ask vendors
- Where is our data stored, including backups, logs and disaster recovery copies?
- Are support and administrative staff with access to our data US persons, and how do you verify that?
- Do you offer a separate environment or service tier for export-controlled data, and what does the contract commit to?
- How is our data encrypted, who holds the keys, and can your staff decrypt it?
- Will you sign contract terms covering export-controlled data, and what happens if you breach them?
- Is your offering scoped to the specific service we would buy, or only to other products?
How it differs from EAR
ITAR and the EAR are both US export control regimes, but they cover different items and are run by different departments. ITAR covers defense articles and services on the USML and is administered by the State Department. The EAR covers commercial and dual-use items on the Commerce Control List, plus many everyday items, and is administered by the Commerce Department. ITAR is generally stricter, with fewer exceptions, and an item covered by the USML falls under ITAR rather than the EAR. Defense contractors often handle both kinds of data, along with the CMMC and NIST Special Publication 800-171 requirements that protect it.
