Also known as: International Traffic in Arms Regulations · ITAR compliance
The U.S. export-control rulebook governing defense-related technology, hardware, and technical data on the U.S. Munitions List.
The International Traffic in Arms Regulations (ITAR) implement the Arms Export Control Act by controlling the export, reexport, retransfer, and temporary import of "defense articles" and "defense services" designated on the United States Munitions List (USML). Administered by the State Department's Directorate of Defense Trade Controls (DDTC), ITAR covers a wide range of military and defense-related hardware — along with the technical data and software needed to develop it. (The specific controlled items, such as missiles and missile components, certain satellites and space systems, and unmanned aerial systems, are enumerated on the USML in 22 CFR Part 121, not Part 120.) ITAR obligations follow four distinct steps that startups often blur together: jurisdiction (whether an item is a defense article or defense service designated on the USML, decided item by item, not by the company's sector), classification (the specific USML category and paragraph), registration, and authorization. Any person who engages in the U.S. in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC (22 CFR 122.1), subject to that section's exemptions; registration by itself confers no export rights or privileges. A separate DDTC license, agreement, or exemption is what actually authorizes an export, and because "export" is defined to include releasing technical data to a foreign person in the United States (a deemed export, 22 CFR 120.50(a)(2)), that authorization can be needed before disclosing controlled data to a foreign-person employee on U.S. soil. Violations can carry steep civil and criminal penalties (the specific sanctions are set out in 22 CFR Part 127).
Source: 22 CFR Part 120 (GovInfo)
Yes. ITAR controls not just physical hardware but also technical data, drawings, and source code related to items on the U.S. Munitions List. Releasing that controlled technical data to a foreign person inside the U.S. is treated as a "deemed export" (22 CFR 120.50), so it can require authorization even though nothing physically leaves the country.
ITAR classification is central to underwriting: violations can drive regulatory and third-party claims across D&O, E&O, and cyber, and many policies include trade-control or sanctions exclusions that depend on your ITAR compliance.
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.
Last updated: July 2026.