In our last post, we covered what ITAR actually controls and what’s at stake financially. But understanding the regulation only helps if you know where controlled technical data actually lives inside your business. In the ITAR Data in Manufacturing webinar, Randy Delarm walked through the full lifecycle, from the moment a contract is signed to the moment a project closes out.
It starts with the contract
The lifecycle begins with RFP and contract (or subcontract) clauses and language. Once the contract is executed, controlled technical data starts flowing: engineering data, engineering drawings, technical reports, and technical data packages, along with design analysis, specifications, test reports, and technical orders.
One point Randy made stuck with a lot of attendees: the contract should state requirements for how ITAR and other CTI data gets disposed of, and that data should be labeled accordingly. But at the end of the day, protecting sensitive data is your responsibility. Not the contracting officer’s, and not your customer’s.
Production and the shop floor
Controlled data doesn’t stay in engineering. It moves to production, and that’s where a lot of exposure hides in plain sight.
- ERP and shop floor automation: CAM systems touch controlled technical data, so they’re in scope for compliance whether or not anyone has treated them that way.
- Printed materials control: ITAR on paper is still ITAR. Drawings, travelers, and work instructions posted or printed on the shop floor need the same level of control as digital files.
- Access to systems and materials: who can physically reach controlled systems and materials on the floor needs to be deliberately managed, not assumed.
Manufacturing processes, equipment, and personnel are all subject to compliance requirements. The shop floor isn’t exempt just because it isn’t IT.
Procurement and supplier sharing
Every hand-off to a subcontractor or supplier is a potential compliance event. Contract clauses flow down from the prime contractor to you, and from you to your subcontractors and suppliers. Every supplier tier involved in executing a contract has to comply with ITAR.
The operating principle here is need-to-know. Apply it to anything you share with suppliers, and limit your risk by sharing only what’s actually required. The moment ITAR or CTI data is shared with a supplier, that supplier becomes subject to compliance too.
Contract closeout: destruction and retention
The lifecycle doesn’t end when the work does. Controlled data has to be destroyed or retained according to specific standards:
- Paper documents, per the DCSA Destruction Guide.
- Digital media, per NIST and NSA guidance.
Disposal tends to be the least documented part of the process, which makes it one of the easiest places for a gap to hide.
Where that leaves you
- ITAR regulates access, not just shipment. A foreign national reading a drawing inside your building counts as a deemed export.
- The determination is your responsibility. You have to do your own analysis of export jurisdiction and classification for your products, technologies, and related CTI.
- The stakes are business-level. There’s real opportunity on one side, and fines, debarment, and reputational damage on the other.
- Controlled data touches every stage. Contract, shop floor, suppliers, closeout: every handoff is a place things can go wrong.
Next in this series
Every stage above is a place controlled data can end up somewhere it shouldn’t. In our next post, we cover the compliance gaps we see most often across this lifecycle, including one that catches almost every manufacturer off guard: the office printer. [Why Printing Can Be the Death of Compliance, link once published]
For the full walkthrough of the ITAR data lifecycle, watch the recording below.


