
If you supply parts, materials, software or technical data into a defense or aerospace program, ITAR compliance almost certainly reaches your business — even if you never file an export license yourself. U.S. export controls flow down the supply chain, and the obligations land on primes and the suppliers behind them. This guide explains ITAR compliance from the supplier’s side: how ITAR differs from the EAR, who has to comply, how registration and licensing work, and — the part most programs get wrong — how to control flow-down clauses, technical data and “deemed exports” across every supplier who touches a controlled item.
Summary: ITAR (the International Traffic in Arms Regulations, 22 CFR) governs defense articles, defense services and technical data on the U.S. Munitions List, administered by the State Department’s Directorate of Defense Trade Controls (DDTC). The EAR (Export Administration Regulations, 15 CFR) governs dual-use and less-sensitive items on the Commerce Control List, administered by the Commerce Department’s Bureau of Industry and Security (BIS). Both flow down through the supply chain: primes push contractual obligations onto suppliers, who push them onto their suppliers. The strongest programs don’t just collect certifications once — they screen suppliers, control who can access technical data, audit against the requirements, and keep the evidence current so every export decision is defensible.
Export control compliance: by the numbers
- ITAR civil penalties now exceed $1.2 million per violation, adjusted annually for inflation — and civil, administrative and criminal enforcement can be pursued together. (U.S. Department of State, DDTC)
- Willful ITAR/AECA violations can carry criminal penalties of up to $1 million per violation and up to 20 years’ imprisonment. (Arms Export Control Act)
- A statutory period of debarment is generally three years — and continues until an application for reinstatement is approved, cutting a supplier off from ITAR-controlled work. (DDTC)
- ITAR registration must be renewed every 12 months; it confers no export rights but is a precondition to any DDTC license or approval. (DDTC, 22 CFR Part 122)
What are ITAR and EAR?
The United States controls the export of sensitive goods, software and technology through two main regimes, and knowing which one applies to a given item is the first step in export control compliance. Get the classification wrong and every downstream decision — who can build it, who can see it, where it can ship — is built on sand.
ITAR — the International Traffic in Arms Regulations — sits at 22 CFR Parts 120–130 and is administered by the State Department’s Directorate of Defense Trade Controls (DDTC). ITAR governs “defense articles” and “defense services” enumerated on the U.S. Munitions List (USML), along with the technical data directly related to them. If an item was designed or modified for a military application and appears on the USML, it is ITAR-controlled — hardware, components, and the drawings, specifications and know-how behind them alike. ITAR is strict by design: it is built around defense and national-security risk, not commercial convenience.
The EAR — the Export Administration Regulations — sits at 15 CFR Parts 730–774 and is administered by the Commerce Department’s Bureau of Industry and Security (BIS). The EAR covers “dual-use” items — commercial goods and technology that also have a potential military or proliferation application — plus some purely commercial and less-sensitive military items. Items are classified against the Commerce Control List (CCL) using a five-character Export Control Classification Number (ECCN). An item that is subject to the EAR but not described by any ECCN is designated EAR99 — the large residual category of low-sensitivity goods. EAR99 items usually need no license, but can still require one when destined for a restricted end user, end use, or country of concern.
ITAR vs EAR: what’s the difference?
ITAR and EAR are often mentioned in the same breath, but they are separate regimes with different lists, agencies and thresholds. The table below is a supplier-side orientation — not a classification tool. Determining whether a specific item is ITAR- or EAR-controlled is the manufacturer’s responsibility, based on the actual product and its technical data.
| ITAR | EAR | |
|---|---|---|
| Regulation | 22 CFR Parts 120–130 | 15 CFR Parts 730–774 |
| Agency | State Department — DDTC | Commerce Department — BIS |
| Control list | U.S. Munitions List (USML) | Commerce Control List (CCL) |
| What it covers | Defense articles, defense services & related technical data | Dual-use items, plus commercial and less-sensitive military items |
| Classification | USML category | ECCN, or EAR99 if not listed |
| Registration | Mandatory annual DDTC registration for manufacturers, exporters & brokers | No general registration; classify and license as required |
| Posture | Restrictive; national-security driven | Risk-based; end-user and end-use driven |
Who must comply — primes and their suppliers
The most common — and most dangerous — misconception is that export control compliance is only the prime contractor’s problem. It isn’t. ITAR obligations attach to any U.S. person or company that manufactures, exports, brokers or furnishes defense articles, defense services or technical data. That reaches deep into the supply chain: the machine shop that fabricates an ITAR-controlled bracket, the software house that writes controlled code, the engineering firm that receives a controlled drawing — all can carry obligations of their own.
Under ITAR, manufacturing a defense article triggers registration even if you never export it. A sub-tier supplier that only ships finished parts to a domestic prime can still be required to register with DDTC because it manufactures a USML item. The moment that supplier emails a controlled drawing to a foreign-national engineer, or a foreign-owned sister plant, it may also have made an export — often without realizing it.
This is why export control obligations cascade through tier 1, tier 2 and tier 3 suppliers. A prime cannot certify its own compliance without knowing that the suppliers behind it are registered where required, control access to technical data, and screen their own workforce and vendors. The prime’s exposure is only as strong as the weakest supplier in the chain — which is exactly why this belongs inside your wider supply chain due diligence program, not off in a legal silo.
Registration and licensing basics
ITAR and EAR handle the “permission to act” question very differently. Suppliers need to understand both — not to become filing experts, but to know what to require of the vendors below them and what evidence to keep on file.
ITAR: DDTC registration
Any person who engages in the U.S. in the business of manufacturing or exporting defense articles or defense services — or in brokering — must register with DDTC under 22 CFR Part 122 (Part 129 for brokers). Registration is annual, carries a fee, and is a precondition to any license: DDTC will not issue an export authorization to an unregistered party. Crucially, registration itself confers no export rights — it simply establishes that DDTC knows who you are and that you accept the obligations. Suppliers should treat a current DDTC registration as a baseline qualification question for any vendor that manufactures USML items, and keep the record of it. (Source: DDTC.)
EAR: BIS licenses and license exceptions
The EAR has no general registration requirement. Instead, whether a transaction needs a license depends on the item’s ECCN, the destination, the end user and the end use. Where a license would otherwise be required, BIS provides license exceptions — authorizations in Part 740 of the EAR that permit certain exports under stated conditions, so not every controlled shipment needs an individual license. For suppliers, the practical takeaways are that classification (ECCN vs EAR99) must be correct, that EAR99 is not a free pass when a restricted party or end use is involved, and that screening against restricted-party lists is mandatory regardless of classification. (Source: BIS.)
Supplier flow-down clauses and certifications
Export control obligations move through the supply chain mostly through contract language known as flow-down clauses. When a prime accepts an ITAR- or EAR-driven requirement from its government customer, it passes matching obligations to its suppliers, who pass them to theirs. A well-written flow-down does more than name the regulation — it obliges the supplier to classify items correctly, control technical data, screen personnel and vendors, restrict foreign-national access, notify the buyer of any potential violation, and flow the same terms down again.
Certifications are how suppliers attest to those obligations — but a signed certificate is only as good as the evidence behind it and the day it was signed. Ownership changes, a new foreign-national hire, a relocated server, or an added sub-tier vendor can all invalidate a certification that was accurate last quarter. That is the core weakness of a “collect a PDF once a year” approach: it captures a snapshot, not a control. The goal is a living record — current certifications, tied to the specific requirement, with a clear owner and a next-review date — so that when a prime asks you to prove flow-down, the answer is a report, not a fire drill.
Managing export compliance across suppliers? Download one of our free Supply Chain Compliance Checklists now.
Controlling technical data and “deemed exports” across suppliers
For most suppliers, the highest-probability violation isn’t shipping a controlled part overseas — it’s letting the wrong person see controlled technical data. Under both ITAR and the EAR, releasing controlled technology or source code to a foreign national inside the United States counts as an export to that person’s home country. This is the “deemed export” rule, and it catches companies off guard because nothing physically crosses a border.
Examples that trip up suppliers every day: a foreign-national engineer opening an ITAR-controlled drawing on a shared network; a controlled specification stored in a cloud instance accessible from an overseas office; a foreign-owned tier-2 supplier granted access to a controlled model to quote a job; a visiting technician shown a controlled process on the shop floor. Each can be a release requiring authorization that the supplier never obtained.
Controlling this across a supplier network is fundamentally an evidence-and-access problem. You need to know which suppliers hold controlled technical data, confirm they restrict access to authorized persons, verify that their foreign-national and foreign-ownership situations are screened, and be able to show that those controls were checked — not just promised. Because access changes constantly, this is a monitoring discipline, not a one-time attestation. The suppliers with the cleanest deemed-export posture are the ones that treat technical-data access like any other controlled process: documented, reviewed on a cycle, and evidenced.
Common violations and penalties
Export-control enforcement is real, and it reaches suppliers, not just primes. The most common failure modes are also the most preventable.
- Failure to register — a supplier manufactures USML items but never registered with DDTC, treating itself as “just a machine shop.”
- Unauthorized deemed exports — controlled technical data released to a foreign national or foreign-owned vendor without authorization.
- Misclassification — treating an ITAR-controlled item as EAR (or an ECCN item as EAR99), so licensing and access controls are never applied.
- Screening gaps — shipping to, or contracting with, a restricted or denied party because lists were never checked.
- Broken flow-down — accepting an obligation from a prime but never passing it to sub-tier suppliers, then being unable to prove it if asked.
The penalties are severe. For ITAR, civil penalties now exceed $1.2 million per violation and are adjusted annually for inflation, while willful violations under the Arms Export Control Act can bring criminal penalties of up to $1 million per violation and up to 20 years’ imprisonment. Beyond fines, DDTC can impose debarment — generally a three-year period that continues until reinstatement is approved — which effectively cuts a supplier off from ITAR-controlled work and can end its position in the defense supply chain entirely. EAR violations carry their own substantial civil and criminal penalties and denial of export privileges. And the government is explicit that it can pursue civil, administrative and criminal enforcement together. (Sources: DDTC; BIS.)
Building an export-compliance supplier program
Managing supplier export compliance well isn’t about filing more licenses — it’s about running a repeatable program that screens the right suppliers, collects the right certifications, verifies them through audits, and drives every finding to closure with evidence. Here is how the strongest programs structure it.
1. Screen and qualify suppliers
Identify which suppliers touch ITAR- or EAR-controlled items or technical data, then qualify them: DDTC registration where required, restricted-party and denied-party screening, and disclosure of foreign ownership, control or influence. Screening isn’t a one-time gate — restricted-party lists and ownership structures change, so it has to be re-run on a cycle.
2. Collect certifications and flow down obligations
Issue standardized export-compliance certifications and questionnaires tied to your flow-down clauses, so every supplier attests to classification, technical-data control, personnel screening and onward flow-down. Standardizing the request is what makes the responses comparable — and auditable — across a large supplier base.
3. Audit and verify the controls
A certification is a claim; an audit is verification. Recurring supplier audits — of technical-data access controls, foreign-national access, records and onward flow-down — turn attestations into checked facts. Risk-rank suppliers so the highest-exposure vendors are audited most often, rather than auditing everyone on the same flat schedule.
4. Drive findings to closure with evidence
The point of the program isn’t to collect documents — it’s to fix gaps and prove you fixed them. Every finding should become a corrective action with an owner, a due date and evidence of completion, so an open deemed-export or screening gap can’t quietly sit unresolved. That closure trail is exactly what a prime, a customer or an auditor wants to see: not just that you asked the question, but that you acted on the answer.
This is where Certainty fits. Certainty is supplier-compliance and audit software — not an export-license filing platform — and that is precisely the layer most defense supply chains are missing. Custom forms, automated multi-stage workflows, corrective-action tracking and configurable dashboards let you screen suppliers, issue and monitor export-compliance certifications, run and document audits, and keep an audit-ready record across every tier. The principle is the one that runs through all of Certainty’s work: don’t just collect the certification — verify it, monitor it, and improve control cycle after cycle, with the evidence to prove it.
Key Takeaways:
- ITAR (22 CFR, DDTC, USML) governs defense articles and technical data; the EAR (15 CFR, BIS, CCL/ECCN) governs dual-use and less-sensitive items — classification decides which applies.
- Export control compliance flows down: primes and their suppliers carry obligations, and a prime is only as compliant as its weakest sub-tier supplier.
- For most suppliers the biggest risk is a “deemed export” — releasing controlled technical data to a foreign national or foreign-owned vendor without authorization.
- Penalties are severe — civil penalties over $1.2M per ITAR violation, criminal exposure up to 20 years, and debarment that can end a supplier’s defense work.
- Treat supplier export compliance as a living program — screen, certify, audit, and drive findings to closure with evidence — not a once-a-year PDF.
You might also be interested in
UFLPA Compliance
Forced-labour import rules, CBP enforcement, and building a defensible due-diligence program.
Supply Chain Due Diligence
How to evidence due diligence across your supplier base — the same infrastructure export compliance needs.
REACH Regulation
The EU’s chemical safety regime — who must comply, SVHCs, and how it flows through the supply chain.
Frequently Asked Questions (FAQs)
What is ITAR compliance in simple terms?
ITAR compliance means following the International Traffic in Arms Regulations (22 CFR) when you handle defense articles, defense services or the technical data behind them. In practice it means registering with the State Department’s DDTC where required, obtaining licenses before exporting, controlling who can access controlled technical data, and keeping records to prove it. For suppliers, it also means meeting the flow-down obligations passed down by primes and passing them on again.
What is the difference between ITAR and EAR?
ITAR (22 CFR, administered by the State Department’s DDTC) controls defense articles and technical data on the U.S. Munitions List. The EAR (15 CFR, administered by Commerce’s BIS) controls dual-use and less-sensitive items on the Commerce Control List, classified by ECCN or as EAR99. ITAR is more restrictive and national-security driven; the EAR is risk-based, turning on the item, destination, end user and end use. Which regime applies depends on how the specific item is classified.
Do suppliers have to comply with ITAR, or just the prime contractor?
Suppliers have their own obligations. Under ITAR, manufacturing a USML item can trigger DDTC registration even if the supplier never exports. Obligations also flow down by contract, so sub-tier suppliers must control technical data, screen personnel and vendors, and flow the same terms down again. A prime cannot fully certify compliance without evidence that the suppliers behind it are compliant too.
What is a “deemed export”?
A deemed export is the release of controlled technology, technical data or source code to a foreign national inside the United States — which is “deemed” an export to that person’s home country. It commonly happens when a foreign-national employee, a foreign-owned vendor, or an overseas-accessible system is given access to controlled data without authorization. It’s one of the most frequent supplier violations because nothing physically crosses a border.
What are the penalties for ITAR or EAR violations?
They are significant. ITAR civil penalties now exceed $1.2 million per violation (adjusted annually for inflation), and willful violations under the Arms Export Control Act can bring criminal penalties of up to $1 million per violation and up to 20 years’ imprisonment. DDTC can also impose debarment — generally three years — cutting a supplier off from ITAR-controlled work. EAR violations carry their own substantial civil and criminal penalties and loss of export privileges. Enforcement can be civil, administrative and criminal at once.
How can compliance software help manage supplier export compliance?
Software like Certainty centralizes the supplier side of export compliance — issuing and tracking export-compliance certifications, screening and risk-ranking suppliers, running and documenting audits of technical-data and access controls, and driving findings to closure with corrective actions and evidence. It is supplier-compliance and audit software, not a license-filing platform, so it fills the gap most defense supply chains have: proving, tier by tier, that flow-down obligations are actually being met.
What is a flow-down clause in a defense contract?
A flow-down clause is contract language that passes export-control obligations from a prime contractor down to its suppliers and sub-tiers. When a prime accepts an ITAR or EAR requirement from its government customer, it uses flow-down clauses to oblige suppliers to classify items correctly, control technical data, screen personnel and vendors, restrict foreign-national access, and pass the same terms down again to their own suppliers.
How do I know if my product is ITAR-controlled or EAR-controlled?
Classification starts with the product itself. Check whether the item appears on the U.S. Munitions List (USML) — if so, it is ITAR-controlled under 22 CFR. If it does not appear on the USML, check the Commerce Control List (CCL) for an Export Control Classification Number (ECCN) — if listed, it is EAR-controlled. If it does not appear on either list but is subject to the EAR, it is EAR99. Misclassification is one of the most common supplier violations; if in doubt, obtain a formal commodity jurisdiction determination from DDTC.
Make export compliance a control you can prove — across every supplier
Certainty helps defense and aerospace supply chains screen suppliers, issue export-compliance certifications, run supplier audits, and drive findings to closure — with an audit-ready record for ITAR and EAR flow-down alike.
