Also known as: International Traffic in Arms Regulations · ITAR compliance
The U.S. export-control rulebook governing defense-related technology, hardware, and technical data on the U.S. Munitions List.
The International Traffic in Arms Regulations (ITAR) implement the Arms Export Control Act by controlling the export, reexport, retransfer, and temporary import of "defense articles" and "defense services" designated on the United States Munitions List (USML). Administered by the State Department's Directorate of Defense Trade Controls (DDTC), ITAR covers a wide range of military and defense-related hardware — along with the technical data and software needed to develop it. (The specific controlled items, such as missiles and missile components, certain satellites and space systems, and unmanned aerial systems, are enumerated on the USML in 22 CFR Part 121, not Part 120.) Because "export" includes releasing technical data to a foreign person inside the United States, a startup that builds, designs, or even shares controlled technical data — including with foreign-national employees on U.S. soil — likely must register with DDTC and obtain its approval before exporting or disclosing it. Violations can carry steep civil and criminal penalties (the specific sanctions are set out in 22 CFR Part 127).
Source: 22 CFR Part 120 (GovInfo)
Yes. ITAR controls not just physical hardware but also technical data, drawings, and source code related to items on the U.S. Munitions List — and even sharing that data with foreign persons inside the U.S. can be a controlled "export."
ITAR classification is central to underwriting: violations can drive regulatory and third-party claims across D&O, E&O, and cyber, and many policies include trade-control or sanctions exclusions that depend on your ITAR compliance.
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.
Last updated: July 2026.