Back to Home
    ITAR Compliance

    ITAR Compliance Checklist

    Work through the ten requirements below to see where your ITAR program stands. Each item is something a DDTC review or a prime's supply-chain audit will ask you to evidence — and each one we can help you close.

    Book a 30-minute, no-obligation risk discovery call.
    You keep the written snapshot either way

    The 10-Point ITAR Compliance Checklist

    Go item by item. If you can't produce evidence for one within a day, treat it as an open gap.

    1. 1

      Confirm whether you're subject to ITAR

      Check your products, components, and technical data against the United States Munitions List (USML). If anything you design, build, or store appears on it, ITAR applies — including to drawings and specifications.

    2. 2

      Register with DDTC

      Manufacturers, exporters, and brokers of defense articles must register with the Directorate of Defense Trade Controls and renew annually. Confirm your registration is current and the responsible officer is correct.

    3. 3

      Appoint an Empowered Official

      Name a U.S. person with the authority to sign license applications and stop non-compliant shipments, and document that authority in writing.

    4. 4

      Write and maintain a Technology Control Plan

      Your TCP defines who may access ITAR-controlled technical data, how access is granted and revoked, and how violations are reported. It should be a live document, not a one-time file.

    5. 5

      Verify U.S.-person status for everyone with access

      Disclosing controlled technical data to a foreign national — even an employee working in your own facility — is a deemed export. Confirm status at hire and re-verify when roles change.

    6. 6

      Segregate ITAR data in your IT environment

      Controlled technical data should live in an access-restricted enclave with logging, not on a general file share. Confirm which folders, drives, and repositories are in scope.

    7. 7

      Confirm your cloud and email meet ITAR hosting rules

      Data must remain in the United States and be accessible only to U.S. persons, including provider support staff. Standard commercial Microsoft 365 typically does not qualify — GCC High or an equivalent does.

    8. 8

      Control physical access to controlled areas and media

      Visitor logs, escort policy, badge control, marked storage for drawings, and secure destruction of printed technical data all need to be in place and evidenced.

    9. 9

      Train employees on ITAR obligations annually

      Everyone who touches controlled data should be able to recognize a deemed export and know the escalation path. Keep signed training records.

    10. 10

      Run internal audits and keep records for five years

      ITAR requires export records be retained for five years. Audit your license usage, shipments, and access logs on a set schedule so a DDTC inquiry doesn't become a scramble.

    Score yourself on the full 47-point checklist

    Who Needs ITAR Compliance?

    Manufacturers of defense articles, weapons systems, or military components
    Aerospace and defense contractors and subcontractors
    Companies providing defense services or technical data to foreign nationals
    Engineering firms with access to controlled technical drawings or specifications
    IT providers hosting or processing ITAR-controlled data
    Any organization on the USML (United States Munitions List) supply chain

    Why It Matters

    Avoid Criminal Penalties

    ITAR violations carry severe consequences — up to $1M per violation in civil fines, criminal penalties including imprisonment, and debarment from future contracts.

    Protect Controlled Data

    Ensure defense-related technical data, blueprints, and specifications are only accessed by authorized U.S. persons with proper safeguards in place.

    Maintain Contract Eligibility

    Defense primes require ITAR compliance from their supply chain. Stay eligible for contracts involving defense articles and technical data.

    How TRNSFRM Gets You There

    1

    ITAR compliance assessment to identify gaps in your current handling of controlled technical data and defense articles.

    2

    Technology Control Plan (TCP) development to govern access to ITAR-controlled information within your organization.

    3

    IT infrastructure review — ensuring cloud, email, storage, and collaboration tools meet ITAR data handling requirements.

    4

    Employee training on ITAR obligations, deemed exports, and proper handling of controlled technical data.

    5

    DDTC registration support and guidance on State Department licensing requirements.

    6

    Ongoing compliance monitoring and audit preparation to maintain your ITAR program as regulations evolve.

    Frequently Asked Questions

    Other frameworks & resources

    CMMC Level 2 Definitive Guide

    Deep-dive on controls, cost, and process.

    CMMC

    DoD contractor certification.

    NIST 800-171

    Federal contractor controls.

    ISO 27001

    International ISMS certification.

    HIPAA

    Healthcare PHI protection.

    FTC Safeguards

    Auto dealer & finance rule.

    Free Compliance Checklist

    Score yourself in 10 minutes.

    Case Studies

    Real certification outcomes.

    vCISO Leadership

    Strategic security guidance.

    Jeff Dennis, Founder & CEO of TRNSFRM
    A note from our CEO

    “Frameworks like CMMC, NIST, and HIPAA aren't just paperwork — they're the difference between winning the next contract and losing it. We've walked dozens of organizations through certification. Let's talk about your path.”

    Jeff Dennis

    Founder & CEO, TRNSFRM

    Ready to Get Compliant?

    No pressure. No sales pitch. Just a conversation with an expert to map out your risks, gaps, and next steps.

    Not ready to book? — it's free.

    Call Now