Skip to content
Capability/Compliance Frameworks

ITAR

International Traffic in Arms Regulations

01 / Overview

ITAR controls the export of defense articles and technical data on the United States Munitions List. Thalorin supports ITAR compliance with access control documentation, export authorization tracking, and the cybersecurity controls required for systems handling ITAR-controlled information.

ITAR is export control, not cybersecurity, and treating it as a security framework is the root of most compliance failures around it. The International Traffic in Arms Regulations at 22 CFR 120–130 control defense articles, defense services, and technical data on the United States Munitions List. The Directorate of Defense Trade Controls administers them, and violations carry criminal as well as civil exposure.

The concept that catches technology organisations is the deemed export. Releasing controlled technical data to a foreign person inside the United States is treated as an export to that person's country of nationality. A foreign national engineer reading a controlled drawing on a domestic network is an export event requiring authorisation, and no border is crossed.

The encryption carve-out at 22 CFR 120.54 changed the cloud calculus materially. Technical data secured end-to-end with compliant cryptography, and not stored in specified restricted jurisdictions, is not treated as an export when it transits foreign infrastructure. This makes compliant cloud architectures viable, but only when the cryptographic and storage conditions are genuinely met rather than assumed from a provider's marketing.

Thalorin binds jurisdiction and classification decisions to the data itself, so access control, storage location, and personnel nationality are evaluated against the actual classification rather than an inherited assumption.

02 / Challenges

Framework compliance requires sustained effort

Deemed exports inside your own building

Access by a foreign person to controlled technical data is an export to their country of nationality regardless of physical location. Ordinary engineering collaboration becomes a licensing question.

Jurisdiction and classification are decisions, not lookups

Determining whether an item falls under ITAR's USML or the Export Administration Regulations' Commerce Control List requires analysis, and getting it wrong in either direction carries cost — unnecessary restriction or unlicensed export.

The 120.54 conditions are strict

The encryption carve-out applies only when end-to-end cryptographic conditions are met and data is not stored in specified restricted jurisdictions. Providers describing themselves as ITAR-ready do not by themselves establish that the conditions hold.

Supply chain and technical data flow

Controlled technical data moves to suppliers, partners, and contract manufacturers. Each transfer is an export event needing an authorisation basis, and the chain is usually longer than the register.

03 / Capabilities

How Thalorin helps

ITAREARAECA

ITAR access control documentation

Bind jurisdiction and classification determinations to the data, and carry the empowered official's decisions and their rationale as a reviewable record, so downstream access and storage decisions inherit an actual control status.

Export license tracking

Maintain DDTC registration status and licence and agreement lifecycles as tracked obligations, with expiry dates and provisos visible before a transfer depends on them.

Technical data protection

Record the authorisation basis for each transfer of technical data, whether a licence, an exemption, an agreement, or the 22 CFR 120.54 conditions.

Foreign person access control

Enforce and evidence nationality-aware access controls over controlled technical data, so a foreign person's reach is a configured fact rather than a trusted assurance.

ITAR-compliant cloud

Track storage and transit geography against restricted jurisdictions, where the 22 CFR 120.54 encryption carve-out depends on it.

Deemed export controls

Treat release to a foreign person inside your own facility or network as the export it is, tracking which technical data each individual can reach and under what authorisation.

Questions

ITAR: common questions

What is a deemed export under ITAR?

The release of controlled technical data to a foreign person within the United States, treated as an export to that person's country of nationality. It requires the same authorisation as shipping the data abroad. In practice this means access control over technical data has to be nationality-aware, which is unusual for most IT environments and frequently overlooked.

Can ITAR data be stored in the cloud?

Yes, under conditions. The carve-out at 22 CFR 120.54 provides that technical data secured with compliant end-to-end encryption, and not stored in specified restricted jurisdictions, is not treated as an export when it transits foreign infrastructure. The conditions are specific, and a provider describing itself as ITAR-compliant is not by itself evidence that they are satisfied for your data.

What is the difference between ITAR and EAR?

ITAR, administered by the State Department's DDTC, controls defense articles and services on the United States Munitions List. EAR, administered by the Commerce Department's BIS, controls dual-use items on the Commerce Control List. Determining which regime applies to a given item is a jurisdiction analysis, and items have moved between the two through export control reform.

Does CMMC or NIST 800-171 satisfy ITAR?

No. They are different regimes answering different questions. NIST 800-171 and CMMC govern the protection of Controlled Unclassified Information in contractor systems; ITAR governs whether a transfer of controlled technical data to a foreign person is lawful. Strong 800-171 controls may support ITAR compliance operationally, but they do not substitute for jurisdiction analysis, licensing, or nationality-based access restriction.

Who needs to register with DDTC?

Persons engaged in manufacturing, exporting, or brokering defense articles or defense services must register with the Directorate of Defense Trade Controls, whether or not they actually export. Registration is a prerequisite for licence applications and is renewed periodically. Manufacturing a USML item for purely domestic sale still triggers the requirement.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about ITAR.

See how one evidence artifact satisfies ITAR requirements alongside every other framework you carry.