What Is ITAR? Registration, Requirements, and Penalties Explained
The International Traffic in Arms Regulations (ITAR) control the export, temporary import, and brokering of defense articles, defense services, and related technical data listed on the United States Munitions List (USML). Enforced by the Directorate of Defense Trade Controls (DDTC) within the U.S. Department of State, ITAR applies to a broader range of organizations than many assume — not just arms manufacturers, but any U.S. person or company that manufactures, exports, temporarily imports, or brokers defense articles, including the technical data describing them.
This guide covers who ITAR applies to, what registering and maintaining compliance actually involves, and current penalty exposure for getting it wrong.

Executive Summary
Main Idea: ITAR registration with the DDTC is mandatory for any U.S. person or company that manufactures, exports, temporarily imports, or brokers defense articles or technical data on the USML — triggered by a single instance of covered activity, not a threshold of volume. Compliance requires registration, a documented compliance program, and careful handling of technical data, including when that data is shared digitally with foreign persons.
Why You Should Care: ITAR penalties are severe and enforced actively — civil fines exceeding $1.27 million per violation, criminal penalties up to $1 million and 20 years imprisonment per violation, and debarment that can end a company’s ability to participate in the defense trade entirely. Recent enforcement actions against major defense contractors show DDTC pursuing significant penalties even from established, well-resourced organizations.
Key Takeaways
- ITAR registration is triggered by a single instance of covered activity, not a volume threshold. Any U.S. person or company that manufactures, exports, temporarily imports, or brokers a defense article — or the technical data describing one — must register with DDTC, even if they never actually ship an item overseas.
- “U.S. person” is defined more broadly than company citizenship alone. The registration and compliance obligations that flow from being a U.S. person extend to lawful permanent residents and other protected individuals under immigration law, not just U.S.-incorporated entities — a distinction that matters for staffing decisions on ITAR-related work.
- There is no such thing as “ITAR certification” — only registration and ongoing compliance. DDTC does not certify or accredit organizations, tools, or platforms as ITAR-compliant. Registration is a prerequisite for applying for export licenses, and compliance is an ongoing obligation an organization maintains and can be audited against, not a one-time credential it earns.
- Civil and criminal enforcement tracks operate independently and can run simultaneously. Civil penalties (currently up to roughly $1.27 million per violation, or twice the transaction value, whichever is greater) apply regardless of intent. Criminal penalties (up to $1 million and 20 years imprisonment per violation) apply specifically to willful violations. An organization can face both simultaneously for the same underlying conduct.
- Sharing technical data with a foreign person, even digitally and even within the U.S., counts as an export under ITAR. A “deemed export” occurs when controlled technical data is disclosed to a foreign person, regardless of whether any physical item crosses a border. This is the provision most likely to catch organizations off guard, particularly around email, file sharing, and collaboration tools used by mixed-nationality teams.
Who Must Register With DDTC
Registration is required for any U.S. person or company that manufactures, exports, temporarily imports, or brokers defense articles, defense services, or related technical data appearing on the USML. This obligation applies broadly: a manufacturer that produces a USML-listed item must register even if every unit is sold domestically and none is ever exported, since manufacturing itself — not just export activity — triggers the requirement.
“U.S. person,” the category to which registration and compliance obligations attach, is defined more expansively than company incorporation status. It includes U.S. citizens, lawful permanent residents (green card holders), and other individuals granted “protected individual” status under U.S. immigration law. This matters operationally: an organization employing foreign nationals on ITAR-related work needs to understand precisely who on staff qualifies as a U.S. person and structure access to controlled technical data accordingly.
Registration itself is a prerequisite for applying for any export license — an organization cannot seek authorization to export a controlled item or share controlled technical data with a foreign person without first being registered.
What Registering and Maintaining Compliance Involves
Registration is completed through DDTC’s Defense Export Control and Compliance System (DECCS), requiring submission of organizational information and designation of an Empowered Official — typically a senior executive, VP-level or above — who takes personal legal responsibility for the accuracy of the organization’s ITAR submissions. This is not a ceremonial designation; an Empowered Official can face individual criminal liability for willful violations submitted under their certification.
Registration carries an annual fee, which has increased in recent years — current published guidance places the fee in the range of $2,250 to $4,000 annually depending on registration tier, though organizations should confirm current fee schedules directly with DDTC given periodic adjustments.
Beyond registration, ITAR requires organizations to enact a documented compliance program addressing internal monitoring, recordkeeping, and employee training. This includes maintaining records of all ITAR-controlled transactions for a minimum of five years from the relevant license expiration or transaction date, and properly marking and classifying technical data subject to ITAR so employees can readily identify and handle it according to the organization’s compliance policies.
Technical Data, Deemed Exports, and Digital Sharing
One of ITAR’s most consequential and frequently underappreciated provisions is the “deemed export” rule: disclosing ITAR-controlled technical data to a foreign person counts as an export under ITAR, even if the disclosure happens entirely within the United States and involves no physical transfer of any item. A conversation, an emailed document, or a shared file containing controlled technical data can trigger export control obligations the same way physically shipping a controlled item would.
This has direct implications for how organizations handle digital collaboration involving ITAR-controlled technical data — schematics, design specifications, source code, and similar material. The relevant question isn’t just where data is stored, but who can access it, and whether that access is properly restricted to authorized U.S. persons. For a detailed look at what this means specifically for collaboration and file-sharing platforms — including the important point that no government body certifies any platform as officially “ITAR-approved” — see our guide on ITAR-compliant collaboration platforms.
Current ITAR Penalties
ITAR enforcement operates on two independent tracks that can apply simultaneously to the same conduct.
Civil penalties apply regardless of intent and are currently set, under the inflation-adjusted schedule at 22 CFR § 127.10, at up to approximately $1.27 million per violation or twice the value of the underlying transaction, whichever is greater. These figures adjust periodically for inflation, so organizations should confirm the current maximum directly against DDTC’s published schedule rather than relying on a fixed figure indefinitely.
Criminal penalties apply to willful violations and carry fines up to $1 million per violation, imprisonment up to 20 years, or both. A conviction under the Arms Export Control Act also triggers automatic statutory debarment for a minimum of three years — DDTC can additionally impose administrative debarment through enforcement proceedings even without a criminal conviction.
Debarment is often the most operationally severe consequence, since it excludes an organization from participating in defense trade activities entirely — a significantly larger business impact for most defense contractors than the financial penalty itself. Recent enforcement history illustrates the scale involved: in October 2024, a major defense contractor agreed to pay over $950 million to resolve multiple government investigations, including Arms Export Control Act and ITAR violations, and more recent DDTC enforcement actions have continued to impose multi-million-dollar penalties against established manufacturers.
How Kiteworks Supports ITAR-Related Data Governance
Kiteworks provides governance and protection capabilities relevant to organizations managing ITAR-controlled technical data, addressing the specific requirements that flow from NIST SP 800-171 and CMMC — frameworks that frequently overlap with ITAR obligations for defense contractors handling CUI alongside export-controlled data.
A unified Data Policy Engine enforces granular, role-based access controls across secure email, secure file sharing, managed file transfer, and SFTP — directly relevant to preventing deemed export violations, since access to ITAR-controlled technical data can be restricted specifically to verified U.S. persons. AES-256 encryption with FIPS 140-3 validated cryptographic modules protects technical data at rest and in transit, and a single, consolidated, immutable audit trail provides the recordkeeping evidence ITAR compliance programs require — tracking who accessed, edited, or uploaded controlled data, and when.
Kiteworks also holds FedRAMP Moderate Authorization, independently assessed since June 2017, and supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box — relevant given how frequently ITAR-controlled technical data and CMMC-governed CUI overlap for defense contractors. For the specific question of what a defensible collaboration platform for ITAR-controlled data requires, see our dedicated ITAR-compliant collaboration platforms guide.
To see how Kiteworks supports your organization’s ITAR-related data governance, schedule a custom demo.
Frequently Asked Questions
Any U.S. person or company that manufactures, exports, temporarily imports, or brokers defense articles, defense services, or related technical data on the United States Munitions List must register with the Directorate of Defense Trade Controls. This obligation is triggered by a single instance of covered activity — a manufacturer must register even if it never exports a single unit, since domestic manufacturing of a USML-listed item alone creates the requirement.
No. DDTC does not certify or accredit organizations, software platforms, or products as officially “ITAR-approved” or “ITAR-certified.” Organizations register with DDTC and are responsible for maintaining an ongoing compliance program — there is no credential or certification to earn. Any vendor marketing claim of official ITAR certification or approval should be treated with caution, since no such government-issued designation exists.
A deemed export occurs when ITAR-controlled technical data is disclosed to a foreign person, regardless of whether the disclosure happens inside the United States or involves any physical transfer of an item. Sharing a schematic, design specification, or other controlled technical data with a foreign national — even in an email or a shared file, and even domestically — counts as an export under ITAR and requires the same authorization a physical export would require. This provision is frequently underappreciated in digital collaboration contexts involving mixed-nationality teams.
ITAR enforcement operates on two tracks that can apply simultaneously. Civil penalties, which apply regardless of intent, currently reach approximately $1.27 million per violation or twice the value of the underlying transaction, whichever is greater, under the inflation-adjusted schedule at 22 CFR § 127.10. Criminal penalties, which apply to willful violations, reach up to $1 million in fines and 20 years imprisonment per violation. A criminal conviction under the Arms Export Control Act also triggers automatic debarment for a minimum of three years, and DDTC can impose administrative debarment separately, without a criminal conviction, through its own enforcement proceedings.
Yes, substantially, for defense contractors that handle both export-controlled technical data and Controlled Unclassified Information. Many of the same technical safeguards — access controls restricted to authorized personnel, encryption of sensitive data at rest and in transit, and comprehensive audit logging — satisfy requirements under both ITAR’s data protection expectations and NIST SP 800-171’s control set that underlies CMMC. Organizations managing both obligations generally benefit from a unified data governance approach rather than separate, disconnected compliance programs for each framework.

