Adam Kangiser, Iviry’s Compliance Analyst

As scrutiny of the Defense Industrial Base grows, manufacturers and defense contractors can’t treat export control compliance as a back-office formality anymore. On July 21, Iviry hosted a live webinar, ITAR Data in Manufacturing, where our Chief Growth Officer Randy Delarm and GRC Manager Sarah Lane walked through what’s at stake and where manufacturers get exposed. This post is the first in a four-part series breaking that session down.

ITAR vs. EAR: two regulations, two agencies

These two frameworks get confused a lot, but they come from different agencies and cover different things.

  • ITAR (International Traffic in Arms Regulations): enforced by the U.S. Department of State. It controls the export of defense articles, defense services, and related technical data listed on the United States Munitions List (USML), which covers 21 categories of items designed for military use. Governed by 22 CFR Parts 120 to 130.
  • EAR (Export Administration Regulations): enforced by the U.S. Department of Commerce. It applies to commercial and dual-use items, meaning goods with both commercial and potential military applications, listed on the Commerce Control List (CCL), which covers 9 categories. Governed by 15 CFR Parts 730 to 774.

This series focuses on ITAR and EAR compliance as it relates to IT systems and Controlled Technical Information (CTI), not on registration or the export process itself.

You don’t have to ship anything to violate ITAR

This is the part that catches a lot of manufacturers off guard: under ITAR, you don’t have to ship anything to break the law. Simply letting a foreign national access controlled technical data, even inside the United States, can count as an export. That’s called a deemed export.

A deemed export happens the moment ITAR-controlled technical data is released to a foreign person, no matter where that person is physically located. ITAR regulates access, not just shipment. Under ITAR, a foreign person includes:

  • Non-U.S. citizens
  • Lawful permanent residents who are not U.S. persons
  • Dual nationals
  • Foreign contractors
  • International visitors
  • Temporary visa holders

A foreign national reading a drawing inside your building counts as a deemed export. No border crossing required.

What counts as Controlled Technical Information

CTI covers more than most people assume. It includes research and engineering data, engineering drawings, technical reports, technical data packages, design analysis, specifications, test reports, technical orders, cybersecurity plans, and even things like IP addresses, nodes, and network links.

The business and financial stakes

Iviry’s compliance team frames this as both an opportunity and a risk.

  • Opportunity: there are tens of millions of dollars in contracting opportunities available as both a prime and a subcontractor. The Defense Industrial Base is significantly behind on compliance requirements right now, which means companies that get this right have a real edge in a competitive market.
  • Risk: ITAR violations can lead to civil and criminal penalties, including fines and debarment. Other consequences include denial or revocation of licenses and export authorizations, ongoing compliance oversight, lost business opportunities, and damage to your reputation with partners and clients.

The Directorate of Defense Trade Controls (DDTC) handles civil enforcement. The Department of Justice handles criminal enforcement. The numbers aren’t small:

  • Civil penalties can run $1 million or more per violation
  • Criminal violations can carry up to 20 years in prison, plus fines
  • Debarment from contracting or licensing
  • Exposure under the False Claims Act

Recent enforcement actions show how wide that range really is. A Fortune 50 defense contractor was assessed $36,000,000 over a violation involving the People’s Republic of China. A small parts manufacturer was assessed $3,000,000 over violations involving several entities in South America. Another Fortune 50 contractor was assessed $51,000,000, again tied to China. And an individual received a three-year debarment connected to a violation involving the United Arab Emirates. Company size doesn’t determine your exposure. A small manufacturer and a Fortune 50 prime can both end up on this list.

As Randy said during the session, engaging in work that requires handling CTI is a whole-of-company responsibility, not something IT can own on its own.

Whose job is it to figure this out?

Yours. It’s not the DoD contracting officer’s job to tell you whether your data is ITAR- or EAR-controlled, and if a contract doesn’t mention it, you still can’t assume the data isn’t CTI. In practice, that means:

  • Look for DFARS clauses 252.225-7048 and 252.204-7012, -7019, -7020, -7021, and -7025.
  • Do your own determination of export jurisdiction and classification for your products, technologies, and related CTI.
  • Review the USML and CCL yourself. If you’re not sure, file a Commodity Jurisdiction Request with the State Department or a Commodity Classification Request with Commerce.

Prime contractors are often a good resource here too. It’s worth asking.

Next in this series

Understanding what ITAR covers is only the first step. The harder part is knowing where controlled technical data actually lives and moves inside your business, from the moment a contract is signed to the moment a project closes out. That’s what we cover next: [The ITAR Data Lifecycle: From Contract Award to Closeout].

For the full session, including live examples and audience Q&A with Randy Delarm and Sarah Lane, watch the recording below.

Watch the ITAR Data in Manufacturing Webinar Recording

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.