What is ITAR Compliance? What Engineering Teams Need to Know

Chapters

Chapter 11: What is ITAR Compliance? What Engineering Teams Need to Know

Chapters

What is ITAR Compliance? What Engineering Teams Need to Know

During a design review, a systems engineer shares a screen showing a controlled printed circuit board layout with a participant who is a non-U.S. citizen. Screen-sharing a controlled printed circuit board layout can transfer technical data under United States (U.S.) export law even when the file remains in place and the hardware stays in the building.

Unauthorized disclosure can occur in this kind of moment, and the exposure rarely stays contained to one screen share. Engineering data, such as drawings, source code, and repository access, all count toward a violation total, and a single unreported incident can compound into the kind of pattern DDTC treats as systemic.

This guide covers what counts as ITAR-controlled technical data, where distributed engineering work creates the most exposure, what penalties look like when compliance fails, and how access controls and traceability practices reduce risk day to day.

What Is ITAR Compliance?

The International Traffic in Arms Regulations (ITAR) is codified at Title 22 of the Code of Federal Regulations (CFR), Parts 120 through 130, and administered by the Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act. The regulations control the export of defense articles, defense services, and technical data listed on the U.S. Munitions List (USML), which spans categories of items whose predominant application is military. ITAR overlaps with the broader regulatory compliance management work most regulated engineering teams already do.

ITAR Compliance Recent Updates

The regulatory direction points toward more conditional rules and more data-specific determinations. More than 700 authorized entities can already use license-free defense trade provisions among the U.S., the United Kingdom, and Australia under the Australia-United Kingdom-U.S. (AUKUS) exemption at ITAR § 126.7, which has been in effect since September 1, 2024, though only for data outside the Excluded Technology List. Teams with a current technical data inventory and controlled artifact relationships can evaluate an exemption like this in days.

What Are ITAR Compliance Requirements?

Technical data covers information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles, under 22 CFR § 120.33. Computer-aided design (CAD) models, drawings, schematics, source code, manufacturing notes, and test procedures all qualify before production, with no carve-out for preliminary evaluation data. Registration with DDTC is required under 22 CFR § 122.1 for any company that manufactures defense articles, even if it never exports anything.

Who Needs to Be ITAR Compliant?

Any person who manufactures, exports, or temporarily imports defense articles, or furnishes defense services, must register with DDTC, including manufacturers who never export. The obligation extends throughout the supply chain, so subcontractors, software vendors, and distributors that handle USML items or related technical data also bear compliance duties. Supplier onboarding should verify whether the part, data, or service is subject to a USML requirement before granting access. Supply chain data exchange with subcontractors is a control point in its own right, worth mapping early.

What Are the Penalties for ITAR Violations?

Fines are only part of the exposure, since consent agreements can reshape engineering access models and delay program work in ways that damage customer confidence.

Civil and Criminal Penalties for Violations

Civil penalties can be substantial, and criminal penalties under the Arms Export Control Act can include major fines and prison time per violation. Totals climb because violations count individually, and an August 2024 $200 million settlement resolving 750 violations included $100 million suspended on condition that the company spends it on remedial compliance measures.

Contract Loss and Program Delays

Settlements like RTX’s often come with years of extra compliance requirements, usually a special compliance officer and outside audits. Companies may also have to divest parts of their business or face multi-year debarment, which bars all ITAR-controlled work with no guarantee of reinstatement.

Separately, DFARS rules require companies to pass safeguarding requirements for CDI and CUI down to any subcontractor that handles this data. ITAR compliance for USML items is a distinct set of rules that must be handled on its own for these same subcontractors and vendors.

CMMC assessments can also expose ITAR problems, since both reviews touch the same systems: Technology Control Plans, access controls, and cloud architecture.

Building ITAR Compliance Into the Engineering Workflow

DDTC defines elements of an effective compliance program, including management commitment and audit and recordkeeping practices. Three of them carry most of the daily weight for engineering teams.

Access Controls Tied to Requirements and Data

Access to controlled technical data must be governed by the ITAR authorization status. A TCP documents what data is controlled, the specific means of restricting access, training obligations, and a monitoring plan, and DDTC agreements can require one as a condition of approval.

Access reviews should tie each check to current program data instead of a one-time onboarding record:

  • Authorization status: Access matches current citizenship, residency, license, or TAA scope.
  • Repository coverage and audit evidence: Controlled requirements, files, and exports remain within approved systems, and logs record who accessed or was denied access to controlled data.

Cloud storage adds a layer that teams frequently misread. Storing unclassified technical data is not an export under 22 CFR § 120.54 if the data is secured with end-to-end encryption using Federal Information Processing Standards (FIPS) 140-2-validated cryptographic modules and is never intentionally stored in proscribed countries. Provider-managed keys disqualify the arrangement, and if the cloud provider can decrypt files on request, the storage model does not qualify.

Traceability From Requirement to Export-Controlled Artifact

Controlled status flows downstream, and when a requirement describes a USML item, the derived drawings, code, and test procedures inherit that control. Teams should maintain a technical data inventory mapping USML category, classification rationale, and authorized users for each data type, paired with export-control legends on the files themselves.

Keeping that inventory accurate gets harder as artifacts multiply across tools, because an unmarked copy of a controlled specification in a test repository is a violation waiting for an audit. A governed requirements management best practices approach paired with a traceability workflow should keep relationships between a controlled requirement and every downstream specification, test case, and review visible, so teams can identify which artifacts sit inside the export-controlled boundary.

Audit-Ready Documentation Without Manual Prep

ITAR recordkeeping requires teams to maintain records for the required retention period, keep them legible and unaltered once recorded, and make them readily accessible. A failure to maintain or produce relevant records is itself a violation. Keep proof that only authorized users accessed technical data, including access logs showing who accessed what, when, from where, and whether access was granted or denied.

Late reporting can reduce voluntary disclosure credit, and a voluntary disclosure can still incur penalties if it is not timely. Centralized access history and change records let teams respond in days. Reconstructing evidence from scattered storage locations and email threads can erode the timeliness credit on which voluntary disclosure depends.

ITAR Compliance Checklist for Engineering Teams

  • Confirm authorization status (citizenship, residency, license, or TAA scope) before granting access to controlled data.
  • Maintain a technical data inventory mapping USML category, classification rationale, and authorized users.
  • Apply export-control legends to controlled files and flag unmarked copies found in shared repositories.
  • Verify cloud storage meets the 22 CFR § 120.54 encryption carve-out, including customer-held keys.
  • Keep access logs showing who accessed controlled data, when, from where, and whether access was granted or denied.
  • Report suspected violations promptly to preserve voluntary disclosure credit.
  • Vet subcontractors and vendors for USML exposure before sharing data.

Getting Started With ITAR Compliance

Access controls, technical data inventories, and classification evidence work best when they live within the same system that engineers already use to write and review requirements, rather than in a separate compliance tracker reconstructed after the fact.

A Shared Responsibility Model for ITAR-Compliant Deployments

No platform can carry ITAR compliance on its own, and Jama Connect® is no exception. Meeting these obligations depends on a shared responsibility model: the customer configures and secures the deployment, and Jama Software adapts its own support practices around that control boundary.

On the customer side, that means deploying on ITAR-compliant infrastructure, whether self-hosted on the organization’s own environment or through a specialized GovCloud hosting partner, and owning the underlying network controls, server hardening, and physical security. It also means keeping controlled technical data inside that environment rather than in support tickets or email threads, and maintaining the user authentication, authorization, and access review practices that keep only qualified personnel in the system.

On Jama Software’s side, support interactions are structured to respect that same boundary. When a customer requests a working session that touches ITAR-restricted information, Jama Software will, upon request and with advance notice, confirm that attending personnel are ITAR Accessible Persons located in the United States, and those sessions are conducted without recordings or screenshots. Jama Software documents this shared responsibility framework for teams scoping an ITAR-compliant rollout.

Jama Connect® supports this workflow with AWS GovCloud hosting for aerospace and defense programs that need US-sovereign data residency, plus a self-hosted option for air-gapped environments with CMMC-aligned data sovereignty. Role-based licensing controls who can create, edit, or only view controlled requirements, and the Activity Stream keeps a chronological audit trail record of activity on every item. Electronic signatures are FDA 21 CFR Part 11-compliant, tied to each individual user and to the specific requirements baseline or review signed, and the Live Traceability™ capability keeps that evidence connected as programs evolve. 

Turning ITAR Compliance Into a Daily Engineering Workflow

ITAR compliance isn’t a one-time registration milestone; it’s a daily engineering discipline built on access controls, traceability, and audit-ready records. Teams that connect requirements to controlled artifacts in a single system can identify what’s controlled, prove who accessed it, and respond quickly when questions arise, turning compliance from a reconstructed afterthought into a built-in part of the workflow. See how it fits your workflow with a free 30-day trial

Frequently Asked Questions About ITAR Compliance

What is the difference between ITAR and Commerce export controls?

ITAR falls under the Department of State through DDTC and controls USML items with predominantly military applications. The Export Administration Regulations (EAR), administered by the Department of Commerce’s Bureau of Industry and Security (BIS), govern dual-use items on the Commerce Control List (CCL). An item can’t appear on both lists, and ITAR takes precedence. When jurisdiction is unclear, a Commodity Jurisdiction (CJ) request to DDTC provides an official determination. That determination belongs in the requirement metadata so that requirements management and bidirectional traceability stay aligned with the correct control regime.

What counts as an ITAR violation for engineering teams?

Sending controlled CAD files via personal email, sharing design documents via consumer cloud storage, discussing controlled specifications over standard messaging apps, and screen-sharing controlled data with unauthorized foreign participants are common patterns of violation. Exceeding the scope of a TAA counts even when the agreement covers the general subject area. Screen shares, screenshots, review comments, and recordkeeping failures can all disclose or mishandle technical data. Change management records, plus linked test management evidence, can help teams show what was controlled and verified.

Does ITAR apply to cloud-based engineering tools?

Yes, and teams should not treat cloud provider claims as a substitute for their own export-control analysis. The encryption carve-out at 22 CFR § 120.54 permits cloud storage of unclassified technical data only with end-to-end encryption, FIPS-validated cryptographic modules, customer-held keys, and no storage in proscribed countries.

This article was authored by Mario Maldari and published on July 31, 2026.

Book a Demo

See Jama Connect in Action!

Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.