Adam Kangiser, Iviry’s Compliance Analyst

We’re wrapping up our ITAR Data in Manufacturing series with the part most manufacturers are really asking about: what controls actually need to be in place, and how ITAR compliance overlaps with CMMC, so you’re not building two separate programs to solve one problem.

Access control and need-to-know

This is the foundation. In the webinar, Iviry outlined the core pieces of an access control program:

  • Role-based access in PLM and ERP systems.
  • Documented visitor and foreign national access policies.
  • Limiting ITAR technical data access strictly by role and need-to-know.
  • Screening visitors before granting access to systems.
  • Controlling privileged and remote access.
  • Keeping evidence of who accessed what, and when.

Data handling requirements under 22 CFR 120 to 130

22 CFR 120 to 130 is the regulatory framework for controlling the export, reexport, and transfer of defense articles and services under ITAR. In practice, that framework comes down to three operational requirements:

  • Marking and labeling: controlled technical data needs to be identified and labeled consistently.
  • Secure storage: encrypted enclaves for CUI and ITAR data, segmented from the general network.
  • Controlled transmission: encrypted email and file transfer for any external sharing, including with suppliers.

Your System Security Plan

A System Security Plan ties all of this together. It should document system scope, asset inventory, network and data flow, access control, policies and procedures, incident response, configuration management, risk management, continuous monitoring, and ITAR/data protection specifically. A binder that describes controls you no longer actually use isn’t a System Security Plan. It’s a liability.

Where ITAR meets CMMC

If your business also handles Controlled Unclassified Information under DFARS, you’re probably working toward CMMC 2.0 certification alongside ITAR compliance, and the two frameworks overlap more than most people expect. ITAR controls line up directly with CMMC Level 2 practices (based on NIST SP 800-171), including access control, audit and accountability, system and communications protection, configuration management, and security awareness training, among others. Addressing one strengthens the other: shared security goals, more efficiency from one set of controls supporting multiple requirements, stronger compliance across both obligations, and a more resilient security posture overall.

For context on where ITAR/CTI falls within the CMMC Model 2.0 structure: Level 1 (Foundational) covers 17 controls with an annual self-assessment. Level 2 (Advanced), where ITAR/CTI sits, covers 110 controls based on NIST SP 800-171, with a triennial third-party assessment for critical national security information and an annual self-assessment for select programs. Level 3 (Expert) covers 134 controls based on NIST SP 800-171 and 800-172, with triennial government-led assessments. Even with recent DoW CMMC program changes, NIST 800-171 still requires a Level 2 self-assessment.

Practical next steps

  • Data mapping exercise: know where your technical data actually lives, across systems, devices, and cloud environments.
  • Gap assessment against 22 CFR 120 to 130 and NIST SP 800-171: figure out where you stand today and what needs attention.
  • Build or update your SSP: document controls, policies, and compliance posture in a way that reflects reality.
  • Employee training: make sure your team understands their specific role in protecting CUI and staying compliant.
  • Engage a partner like Iviry: for ongoing monitoring, threat detection, and remediation, so you can stay focused on your mission.

Key takeaways from the series

  • Know how ITAR is actually exported: email, cloud shares, screens, and people, not just cargo.
  • You’re legally responsible. Data handling responsibility sits with you, not the contracting officer.
  • ITAR is ITAR in any form, no matter where it is or what shape it’s in. That includes printed documents.
  • Know where your ITAR data is. If you don’t know today, that’s the place to start.

Catch up on the full series

For the full session, including a live walkthrough of these controls from Randy Delarm and Sarah Lane, and audience Q&A, watch the recording below.

Watch the ITAR Data in Manufacturing Webinar Recording

Ready to see where your business stands on ITAR and CMMC? Reach out to Iviry at marketing@iviry.com or 866.960.9658. We’re happy to talk it through.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.