US ITAR and EAR - Export Control and Data Security
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access Control
Per ITAR/EAR: Access Controls Based on Nationality and Need + deemed export rule + Foreign person access restrictions + Protection of Controlled Unclassified Information.
- ITAR/EAR evidence for USEXPORT-2
- classification + access + cloud partial
Classification
Per ITAR (22 CFR Parts 120-130) + EAR (15 CFR Parts 730-774): Jurisdiction and Classification of Items + USML vs CCL + Export Control Classification Number (ECCN).
- ITAR/EAR evidence for USEXPORT-1
- classification + access + cloud partial
Cloud
Per ITAR/EAR + 2020 ITAR changes: Cloud and SaaS Use for Controlled Data + encryption end-to-end safe harbor + FedRAMP High alignment.
- ITAR/EAR evidence for USEXPORT-3
- classification + access + cloud partial
Data Security for Controlled Technical Data
ITAR: protection of defence technical data (Category I-XXI USML). EAR: protection of controlled technology. End-to-end encryption required. Access limited to US persons (ITAR). Deemed export controls for foreign nationals.
- Jurisdiction and classification determinations (CJ/CCATS)
- Technology Control Plan (TCP) for ITAR/EAR controlled data
- Cloud and storage controls evidence (encryption and US-person admin)
- Access control matrix restricting controlled data to authorized U.S. persons
- Classification of technical data inconsistent across business units
- Incident response does not address controlled-data spill scenarios
- Foreign-national access not tracked against deemed-export rules
- Encryption keys held outside U.S. for ITAR data
Cloud computing restrictions for ITAR data. End-to-end encryption for cloud storage. US-person-only administrative access. Data centre location considerations. Key management. AWS GovCloud and Azure Government options.
- Access control matrix restricting controlled data to authorized U.S. persons
- Jurisdiction and classification determinations (CJ/CCATS)
- Deemed export risk assessment for foreign-national access
- Cloud and storage controls evidence (encryption and US-person admin)
- Cloud configurations allow non-US admin access to controlled data
- Foreign-national access not tracked against deemed-export rules
- Incident response does not address controlled-data spill scenarios
- Classification of technical data inconsistent across business units
US person verification for ITAR access. Need-to-know basis. Physical and logical access controls. Visitor management. Foreign national access restrictions. Export classification determination.
- Deemed export risk assessment for foreign-national access
- Access control matrix restricting controlled data to authorized U.S. persons
- Jurisdiction and classification determinations (CJ/CCATS)
- Technology Control Plan (TCP) for ITAR/EAR controlled data
- Incident response does not address controlled-data spill scenarios
- Classification of technical data inconsistent across business units
- Encryption keys held outside U.S. for ITAR data
- Foreign-national access not tracked against deemed-export rules
Enforcement
Per ITAR/EAR + DDTC + BIS: voluntary disclosure + enforcement + civil + criminal penalties + denied parties screening.
- ITAR/EAR evidence for USEXPORT-5
- classification + access + cloud partial
ITAR and EAR: Deemed Export and Access Management
Releases of controlled technology or source code to foreign persons inside the United States are deemed exports to the foreign person's country of most recent permanent residency or citizenship and require the same authorizations as a physical export.
- Foreign person screening records during hiring and onboarding
- Technology Control Plan
- Deemed export licenses where required
- Access logs showing nationality based restrictions enforced
- No country of citizenship screening for visiting researchers or contractors
- Technology Control Plan absent
- Cloud collaboration tools allow access by foreign nationals without authorization
Manage physical and logical access for visitors, contractors, and foreign nationals to facilities and systems containing controlled technical data through pre approval, escort, badging, briefings, and Technology Control Plan compliance.
- Visitor pre approval workflow
- Foreign national visit request records
- Escort assignments
- Badge access logs for controlled areas
- Foreign visitors permitted without pre approval
- No briefing on prohibited topics
- Badge logs unreviewed
ITAR and EAR: Registration and Classification
Document determinations that information qualifies as fundamental research, publicly available information, or educational information exempt from ITAR or EAR controls, and ensure research agreements do not impose publication restrictions that would defeat the exemption.
- Research agreement review procedures
- Publication restriction flagging
- Fundamental research determinations by research office
- Training for principal investigators
- Research agreements contain publication delays beyond patent review without flagging
- No determinations documented for grey area projects
- PIs unaware of export controls in joint research
Manufacturers, exporters, and brokers of defense articles or services on the US Munitions List must register with the Directorate of Defense Trade Controls. Exporters of items on the Commerce Control List must be aware of and comply with the Export Administration Regulations administered by the Bureau of Industry and Security.
- DDTC registration letter (DS 2032 evidence)
- Annual renewal records
- Designated Empowered Official appointment
- BIS contact and account records where applicable
- Lapsed DDTC registration
- No Empowered Official appointed in writing
- Subsidiaries not registered separately
ITAR and EAR: Screening and End Use Diligence
Establish know your customer procedures and resolve red flags before proceeding with transactions. Special diligence applies to military, military intelligence, and security end users in countries identified in 15 CFR 744, and to chemical, biological, nuclear, and missile end uses.
- End user statements (DSP 83 where required)
- Red flag resolution memos
- Military End User and Military End Use determinations
- Diligence questionnaires
- No red flag indicator list applied to orders
- DSP 83 missing for Significant Military Equipment
- Reliance on freight forwarder assurances without verification
Screen customers, partners, suppliers, freight forwarders, and end users against US government denied, debarred, and blocked party lists prior to export, re export, or in country transfer, and rescreen periodically and upon material change.
- Screening tool configuration covering DDTC Debarred, BIS Entity List, OFAC SDN, DPL, Unverified List, Military End User List
- Screening logs for transactions
- Periodic rescreening evidence
- Match resolution records
- Screening occurs only at onboarding
- Lists not refreshed daily
- Match resolutions not documented
ITAR and EAR: Shipping, Recordkeeping and Corporate Change
Notify DDTC of material changes including mergers, acquisitions, divestitures, changes of senior officers, address changes, and foreign ownership changes within prescribed timelines, and assess CFIUS implications for transactions involving foreign acquirers.
- Material change notification letters to DDTC
- CFIUS filings where applicable
- Updated DS 2032
- Foreign ownership control and influence (FOCI) mitigation if required
- DDTC not notified within 60 days of material change
- Foreign ownership changes unreported
- No FOCI mitigation plan despite foreign investment
Maintain records of all export transactions, license applications, classification determinations, restricted party screening, end user statements, and shipping documents for at least five years from the date of the export or expiration of the license, whichever is later.
- Document retention policy citing five year minimum
- Sample transaction file showing all required documents
- Archive storage with integrity controls
- Access controls on records
- Records dispersed across business units without central index
- Less than five year retention in shipping system
- Classification records destroyed with product
Ensure controlled shipments are accompanied by accurate Electronic Export Information filings, license citations or exception symbols, destination control statements, and tamper evident packaging, and that freight forwarders are vetted and instructed.
- AES filings
- Commercial invoices with destination control statement
- Freight forwarder agreements and instructions
- Shipping checklist for controlled items
- AES filings missing license citation
- Destination control statement absent
- Freight forwarder not vetted against denied parties
ITAR and EAR: Technical Data Protection
Use end to end encryption meeting FIPS 140 validated cryptographic modules or equivalent National Security Agency approved algorithms when storing or transmitting unclassified technical data across networks, with cryptographic keys retained under US persons control to qualify for the ITAR encryption carve out.
- FIPS 140 validation certificate of modules in use
- Key management policy showing US person control
- Encryption configuration for cloud storage and email
- Documented compliance with 22 CFR 120.54
- Cloud provider holds keys rather than the exporter
- TLS only protection without at rest encryption
- Use of non FIPS validated modules
Implement information security controls that enforce export compliance, including data loss prevention rules tuned to controlled categories, segmentation of controlled environments, monitoring of cross border data transfers, and incident response procedures for suspected unauthorized releases.
- DLP policy rules for controlled keywords and file fingerprints
- Network segmentation diagrams for ITAR enclaves
- Egress monitoring logs
- Incident response runbooks for suspected unauthorized export
- DLP not tuned to detect controlled markings
- Flat networks with controlled and uncontrolled data mixed
- No alerts for international file transfers
ITAR and EAR: Training
Provide initial and recurring export compliance training to personnel involved in research, engineering, manufacturing, sales, supply chain, IT, and human resources, with role specific modules for deemed export risks and red flag recognition.
- Annual training records by role
- Course content covering ITAR, EAR, OFAC, deemed exports, red flags
- New hire training completion
- Refresher training upon regulatory change
- Training generic and not role specific
- No training for HR on deemed export hiring obligations
- Completion below 95 percent
Licensing
Per ITAR/EAR: licensing + recordkeeping (10 years for EAR + 5 for ITAR) + Internal Audit and Self Assessment + voluntary disclosure.
- ITAR/EAR evidence for USEXPORT-4
- classification + access + cloud partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US ITAR and EAR - Export Control and Data Security framework page.