Glossary / Defense / ITAR

ITAR

Also known as: International Traffic in Arms Regulations · ITAR compliance

Defense

The U.S. export-control rulebook governing defense-related technology, hardware, and technical data on the U.S. Munitions List.

The International Traffic in Arms Regulations (ITAR) implement the Arms Export Control Act by controlling the export, reexport, retransfer, and temporary import of "defense articles" and "defense services" designated on the United States Munitions List (USML). Administered by the State Department's Directorate of Defense Trade Controls (DDTC), ITAR covers a wide range of military and defense-related hardware — along with the technical data and software needed to develop it. (The specific controlled items, such as missiles and missile components, certain satellites and space systems, and unmanned aerial systems, are enumerated on the USML in 22 CFR Part 121, not Part 120.) ITAR obligations follow four distinct steps that startups often blur together: jurisdiction (whether an item is a defense article or defense service designated on the USML, decided item by item, not by the company's sector), classification (the specific USML category and paragraph), registration, and authorization. Any person who engages in the U.S. in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC (22 CFR 122.1), subject to that section's exemptions; registration by itself confers no export rights or privileges. A separate DDTC license, agreement, or exemption is what actually authorizes an export, and because "export" is defined to include releasing technical data to a foreign person in the United States (a deemed export, 22 CFR 120.50(a)(2)), that authorization can be needed before disclosing controlled data to a foreign-person employee on U.S. soil. Violations can carry steep civil and criminal penalties (the specific sanctions are set out in 22 CFR Part 127).

Source: 22 CFR Part 120 (GovInfo)

Where you'll see it

Vendor contractApplicationPolicy

Why it matters for your business

  • ITAR compliance shapes hiring, cloud infrastructure, investor, and supply-chain decisions for defense-tech startups.
  • An ITAR violation can trigger regulatory investigations, fines, and third-party claims touching D&O, E&O, and cyber policies.
  • Many policies contain trade-control/sanctions exclusions that hinge on the insured's ITAR posture.

People also ask

Does ITAR apply to software and technical data?

Yes. ITAR controls not just physical hardware but also technical data, drawings, and source code related to items on the U.S. Munitions List. Releasing that controlled technical data to a foreign person inside the U.S. is treated as a "deemed export" (22 CFR 120.50), so it can require authorization even though nothing physically leaves the country.

How does ITAR affect insurance?

ITAR classification is central to underwriting: violations can drive regulatory and third-party claims across D&O, E&O, and cyber, and many policies include trade-control or sanctions exclusions that depend on your ITAR compliance.

Ready to take the next step?

Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.

Reviewed by Andrei Craciunescu, CA Licensed Insurance Broker #4467994

Last updated: July 2026.