Work through the ten requirements below to see where your ITAR program stands. Each item is something a DDTC review or a prime's supply-chain audit will ask you to evidence — and each one we can help you close.
Go item by item. If you can't produce evidence for one within a day, treat it as an open gap.
Check your products, components, and technical data against the United States Munitions List (USML). If anything you design, build, or store appears on it, ITAR applies — including to drawings and specifications.
Manufacturers, exporters, and brokers of defense articles must register with the Directorate of Defense Trade Controls and renew annually. Confirm your registration is current and the responsible officer is correct.
Name a U.S. person with the authority to sign license applications and stop non-compliant shipments, and document that authority in writing.
Your TCP defines who may access ITAR-controlled technical data, how access is granted and revoked, and how violations are reported. It should be a live document, not a one-time file.
Disclosing controlled technical data to a foreign national — even an employee working in your own facility — is a deemed export. Confirm status at hire and re-verify when roles change.
Controlled technical data should live in an access-restricted enclave with logging, not on a general file share. Confirm which folders, drives, and repositories are in scope.
Data must remain in the United States and be accessible only to U.S. persons, including provider support staff. Standard commercial Microsoft 365 typically does not qualify — GCC High or an equivalent does.
Visitor logs, escort policy, badge control, marked storage for drawings, and secure destruction of printed technical data all need to be in place and evidenced.
Everyone who touches controlled data should be able to recognize a deemed export and know the escalation path. Keep signed training records.
ITAR requires export records be retained for five years. Audit your license usage, shipments, and access logs on a set schedule so a DDTC inquiry doesn't become a scramble.
ITAR violations carry severe consequences — up to $1M per violation in civil fines, criminal penalties including imprisonment, and debarment from future contracts.
Ensure defense-related technical data, blueprints, and specifications are only accessed by authorized U.S. persons with proper safeguards in place.
Defense primes require ITAR compliance from their supply chain. Stay eligible for contracts involving defense articles and technical data.
ITAR compliance assessment to identify gaps in your current handling of controlled technical data and defense articles.
Technology Control Plan (TCP) development to govern access to ITAR-controlled information within your organization.
IT infrastructure review — ensuring cloud, email, storage, and collaboration tools meet ITAR data handling requirements.
Employee training on ITAR obligations, deemed exports, and proper handling of controlled technical data.
DDTC registration support and guidance on State Department licensing requirements.
Ongoing compliance monitoring and audit preparation to maintain your ITAR program as regulations evolve.
Deep-dive on controls, cost, and process.
DoD contractor certification.
Federal contractor controls.
International ISMS certification.
Healthcare PHI protection.
Auto dealer & finance rule.
Score yourself in 10 minutes.
Real certification outcomes.
Strategic security guidance.

“Frameworks like CMMC, NIST, and HIPAA aren't just paperwork — they're the difference between winning the next contract and losing it. We've walked dozens of organizations through certification. Let's talk about your path.”
Jeff Dennis
Founder & CEO, TRNSFRM
No pressure. No sales pitch. Just a conversation with an expert to map out your risks, gaps, and next steps.
Not ready to book? — it's free.