Guide Export Controls & Defense Tech

ITAR Compliance for Startups: A Practical Guide for Defense Tech

What founders should know about ITAR, foreign-person access, DDTC registration, export controls, and insurance.

Many defense-tech and hardware founders first hear "ITAR" when a customer, investor, or prospective hire raises it, often after the company is already building something the regulation may control.

Andrei Craciunescu Written by Andrei Craciunescu
10 min read Updated Sep 2026
ITAR compliance for startups: defense articles on the USML, technical data, foreign-person access, and where insurance fits

It is worth understanding early, because ITAR can affect who you can hire, which technology your team can access, whether you can sell internationally, what your customers and prime contractors require, and even how insurers underwrite your coverage. This guide explains what ITAR is, how to tell if it may apply to your company, the compliance issues startup teams commonly encounter, and where insurance does and does not help.

This is educational content, not legal or export-control advice. ITAR determinations are fact-specific. Confirm your classification and obligations with qualified export-control counsel.

Key takeaways

  • ITAR controls defense articles on the U.S. Munitions List, along with the related technical data and defense services, and is administered by the State Department's DDTC.
  • Releasing controlled technical data to a foreign person, even inside the United States, can count as an export (a "deemed export"), so foreign-person access is a core compliance question.
  • Jurisdiction, classification, DDTC registration, and export authorization are four separate obligations. Registration alone does not authorize an export.
  • Insurance does not replace a compliance program. Fines and penalties are frequently excluded and may be uninsurable, though certain D&O, Tech E&O, or Cyber policies may help with covered defense costs.

What Is ITAR?

The International Traffic in Arms Regulations (ITAR) implement the Arms Export Control Act by controlling the export, reexport, retransfer, and temporary import of defense articles designated on the United States Munitions List (USML), along with related technical data and defense services. ITAR is administered by the State Department's Directorate of Defense Trade Controls (DDTC).[1][2][7]

In plain terms: if your company builds, designs, or handles military or defense-related hardware, or the technical data and software needed to develop it, ITAR may govern who you can share it with, and where.

What Does ITAR Control?

Three concepts define ITAR's reach:

Defense articles

items designated on the United States Munitions List (22 CFR Part 121), which can include missiles and missile components, certain military satellites and space systems, and certain military aircraft and unmanned aircraft systems.[3]

Technical data

certain information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a USML defense article. Depending on the circumstances, this can include drawings, specifications, documentation, and directly related software.[1]

Defense services

furnishing certain assistance, including training, to a foreign person in connection with a defense article, or furnishing controlled technical data to a foreign person.[1]

Does ITAR Apply to My Startup?

Not every satellite, drone, or piece of source code at a defense-adjacent company is ITAR-controlled. What matters is whether the specific item is designated on the USML, and whether related technical data, software, or services fall within ITAR's controls. In practice, ITAR is more likely to be relevant if you design or build hardware for military use, hold controlled technical data, furnish defense services, or perform a defense contract involving ITAR-controlled articles, technical data, or services. If any of those fit, the next step is the jurisdiction and classification analysis below, ideally with qualified counsel.

Foreign-Person Access and Deemed Exports

Here is the part that surprises founders: under ITAR, releasing controlled technical data to a foreign person in the United States can be treated as an export. The regulation's definition of "export" expressly includes "releasing or otherwise transferring technical data to a foreign person in the United States (a deemed export)."[19] This can include providing access to controlled drawings, source code, engineering repositories, technical meetings, or cloud environments.

ITAR does not automatically require a company to hire only U.S. citizens. The relevant questions include whether the worker is a U.S. person or foreign person under ITAR, and whether the person will receive access to controlled technical data. For individual workers, U.S. persons generally include U.S. citizens and nationals, lawful permanent residents, refugees, and asylees. The analysis therefore should not be based on citizenship alone.[8][9] Companies should coordinate export-control and employment-law advice before restricting hiring or granting access, because citizenship-based hiring rules can create separate employment-law risk.[8]

ITAR vs. EAR: Which Regime Applies?

Not every defense-adjacent product falls under ITAR. A separate Commerce Department export-control regime is the Export Administration Regulations (EAR):

ITAR EAR
Administered by Department of State, DDTC Department of Commerce, BIS
Generally covers Defense articles designated on the USML, related technical data, and defense services Commercial, dual-use, and certain military commodities, software, and technology subject to the EAR
Classification USML category and paragraph ECCN when listed on the Commerce Control List, or EAR99 when not listed
Authorization DDTC license, agreement, approval, or applicable exemption BIS license, license exception, or no-license-required treatment, depending on classification, destination, end user, and end use

Many dual-use technologies fall under the EAR, but the result depends on the item's technical characteristics, destination, end user, and end use. Being subject to the EAR does not always mean an item is on the Commerce Control List; unlisted items are classified EAR99.[4][5]

Jurisdiction and Classification

Jurisdiction and classification come first: determine whether your item, software, technical data, or service is subject to ITAR, the EAR, or another regime, then identify the applicable USML category and paragraph, ECCN, or EAR99 designation.

Depending on the circumstances, you may document your own analysis with qualified advice, self-classify an item subject to the EAR, request a formal BIS classification, or submit a Commodity Jurisdiction request to DDTC when State Department jurisdiction is uncertain.[6][10]

When Do You Need to Register With DDTC?

Registration is a separate obligation from classification. Companies engaged in the United States in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC. Certain exemptions may apply. Registration does not itself authorize an export.[11]

When Do You Need an Export Authorization?

Depending on the activity, you may need a DDTC license, agreement, written approval, or another authorization, unless an exemption applies. Keep the four obligations distinct: jurisdiction identifies the regime, classification identifies the USML category, ECCN, or EAR99 designation, registration is a separate status obligation, and authorization permits a specific controlled activity.

A 6-Step ITAR Checklist for Startups

A useful order of operations, built around the principle of establishing export-control compliance before international demand arrives:

  1. 1

    Determine jurisdiction and classification.

    Identify whether the product, software, technical data, or service is subject to ITAR, EAR, or another regime.

  2. 2

    Document the result.

    Keep a written classification record and get qualified advice where it is uncertain.

  3. 3

    Control foreign-person access.

    Review who can reach controlled technical data: employees, contractors, founders, cloud systems, repositories, technical meetings, and facilities.

  4. 4

    Determine registration and authorization.

    Confirm whether DDTC registration is required and whether a license, agreement, approval, exception, or exemption is needed.

  5. 5

    Design for international use early.

    If you expect allied sales, consider a separately configured, exportable product version. This is a practical design step, not a legal requirement.

  6. 6

    Review the insurance program.

    Check whether export-controlled operations affect underwriting, application representations, regulatory-investigation provisions, and trade, sanctions, conduct, and data exclusions.

What Happens If You Get ITAR Wrong?

ITAR violations can lead to civil and criminal penalties, seizure or forfeiture, loss or suspension of export authorizations, and debarment from ITAR-controlled activities. Debarment is not an automatic ban on every government contract, but it can jeopardize contracts in practice.

These consequences may also affect defense contracts, customer relationships, financing, and the company's ability to enter international markets. The specific sanctions are set out in 22 CFR Part 127.[12]

Where Insurance Fits

Insurance does not replace an export-control compliance program. It is a potential financial backstop for certain covered claims, not a substitute for compliance. Three questions come up most often:

Can insurance pay an ITAR fine?

You should not assume so. Fines and penalties for export violations are frequently excluded and may also be uninsurable under applicable law.

Can insurance help with defense costs?

Sometimes, for a covered matter. Certain D&O policies may cover defense costs for a defined formal investigation of directors or officers and, more rarely, the company itself, and Tech E&O or Cyber may respond when a covered technology error, professional service, privacy event, or security incident is involved. Crime coverage may separately be relevant if the underlying event involves covered employee dishonesty, theft, or social engineering. Coverage is not automatic: it turns on the policy's definitions of Claim, Investigation, Insured, Wrongful Act, and Loss, and on conduct, sanctions, trade-control, governmental-action, and prior-knowledge exclusions.

What should a startup review in its policies?

Read your D&O, Tech E&O, Cyber, and Crime policies together to find gaps, conflicting definitions, and exclusions that could affect defense costs or third-party claims for a controlled-data event. Answer underwriting questions accurately, because incorrect or incomplete answers about government customers, export-controlled technology, foreign operations, or security controls can create rescission or coverage problems. The strongest protection stays preventive: documented classification, appropriate DDTC registration, required authorizations, foreign-person access controls, and, where appropriate, a technology control plan.

Frequently Asked Questions

Does ITAR apply to software and technical data?

It can. ITAR controls certain technical data and software directly related to a U.S. Munitions List defense article, not just hardware. Releasing that data to a foreign person, even inside the U.S., can be treated as an export.

Read more: ITAR definition of technical data, 22 CFR 120.33 [1]

Can a foreign person work for an ITAR-controlled company?

Yes. ITAR does not itself prohibit employing a foreign person, but releasing controlled technical data to a worker who is not a U.S. person may be an export requiring DDTC authorization. Confirm the worker's status and get export-control and employment-law advice before restricting hiring or access.

Read more: DOJ guidance on avoiding discrimination when complying with export-control laws [8]

What is the difference between ITAR and EAR?

ITAR (State Department, DDTC) covers defense articles on the U.S. Munitions List, related technical data, and defense services. The EAR (Commerce Department, BIS) covers commercial, dual-use, and certain military items, classified by an ECCN or as EAR99 when unlisted. Which one applies depends on the specific item.

Read more: scope of the EAR, 15 CFR Part 734 [4] and the DDTC portal [7]

Do I have to register with DDTC?

Companies engaged in the U.S. in manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC. Certain exemptions apply. Registration does not itself authorize an export, and it is separate from classification and licensing.

Read more: DDTC registration, 22 CFR Part 122 [11]

Can insurance cover an ITAR fine?

Fines and penalties are frequently excluded and may be uninsurable under applicable law. Certain policies may help with covered defense costs arising from a defined investigation or claim, but the result depends on the policy wording, governing law, parties involved, and nature of the proceeding.

This answer does not link to a single federal source because insurability depends on the policy wording, the nature of the sanction, governing state law, and applicable public-policy rules.

What insurance do defense-tech startups typically need to sell to the DoD or a defense prime?

It depends on the solicitation, contract type, work location, and any requirements a defense prime passes down; there is no single package every contractor must buy. For cost-reimbursement contracts, the Federal Acquisition Regulation ordinarily requires workers' compensation and employer's liability, general liability, and automobile liability (plus aircraft or vessel liability where those exposures apply). Fixed-price contracts do not always carry the same minimums, though a contracting officer may require coverage in special circumstances such as work on a government installation.[13][14][15][16] Primes and enterprise customers often add requirements through subcontract flow-downs (higher limits, umbrella or excess, waiver of subrogation, cyber, Tech E&O, product, aviation, or space coverage), and employees performing covered work overseas generally need Defense Base Act coverage before work begins.[17][18] These are contract- and exposure-driven, not universal FAR requirements. For the full flow-down and sourcing detail, see our Subcontractor Insurance Requirements guide.

Read more: FAR 28.307, cost-reimbursement contracts [14] and the Defense Base Act (Department of Labor) [18]

Sources and Further Reading

This guide draws on primary U.S. government sources so you can verify each point yourself. Links go to the official regulation or agency page. Regulations change, so confirm the current text and your own obligations with qualified export-control counsel.

  1. 22 CFR Part 120, Purpose and Definitions (State Department / DDTC), including 22 CFR 120.31 defense article, 120.32 defense service, and 120.33 technical data. ecfr.gov
  2. Arms Export Control Act, 22 U.S.C. 2778, Control of arms exports and imports (the statute ITAR implements). govinfo.gov
  3. 22 CFR Part 121, The United States Munitions List (USML). ecfr.gov
  4. 15 CFR Part 734, Scope of the EAR; Section 734.3(c) designates unlisted items as EAR99 (Commerce Department / BIS). ecfr.gov
  5. 15 CFR Part 738, Commerce Control List Overview and ECCN structure. ecfr.gov
  6. 22 CFR 120.12, Commodity Jurisdiction (Form DS-4076, submitted to DDTC). ecfr.gov
  7. Directorate of Defense Trade Controls (DDTC) Public Portal. pmddtc.state.gov
  8. DOJ Immigrant and Employee Rights Section, "How to Avoid Immigration-Related Discrimination when Complying with U.S. Export Control Laws." justice.gov
  9. 22 CFR 120.62, definition of "U.S. person," and 22 CFR 120.63, definition of "foreign person." ecfr.gov
  10. 15 CFR 748.3, BIS classification requests (CCATS via SNAP-R), and BIS "Classify Your Item" guidance. ecfr.gov · bis.gov
  11. 22 CFR Part 122, Registration of Manufacturers and Exporters. ecfr.gov
  12. 22 CFR Part 127, Violations and Penalties (civil and criminal penalties, seizure, debarment). ecfr.gov
  13. FAR 28.306, Insurance under fixed-price contracts (the Government is not ordinarily concerned with insurance under fixed-price contracts, but may require it in special circumstances). acquisition.gov
  14. FAR 28.307, Insurance under cost-reimbursement contracts (ordinarily requires the insurance types listed in 28.307-2). acquisition.gov
  15. FAR 28.307-2, Liability (employer's liability, general liability, automobile liability, and specialized exposures, with minimum amounts). acquisition.gov
  16. FAR 28.310, Contract clause for work on a government installation. acquisition.gov
  17. FAR 28.305, Overseas workers' compensation and war-hazard insurance (Defense Base Act clause). acquisition.gov
  18. U.S. Department of Labor, Office of Workers' Compensation Programs, Defense Base Act. dol.gov
  19. 22 CFR 120.50, definition of "Export," which at paragraph (a)(2) defines releasing or transferring technical data to a foreign person in the United States as a deemed export. ecfr.gov

Note: the eCFR (ecfr.gov) is an authoritative, continuously updated online version of the Code of Federal Regulations, but it is not the official legal edition. The annual Code of Federal Regulations and rules published in the Federal Register remain the official legal publications. Some government sites rate-limit automated tools; the links above open normally in a browser.

Building Defense Tech? Review Coverage Around Your Actual Operations

Export-controlled operations can materially affect how insurers underwrite D&O, Tech E&O, Cyber, Crime, and other coverage. RiskCube reviews these policies together, with attention to regulatory-investigation provisions, controlled-data exposure, and sanctions, trade-control, conduct, and governmental-action exclusions. Coverage availability depends on your technology, customers, foreign operations, compliance controls, disclosures, policy wording, and underwriting approval.

Building for the defense industry? See our CMMC Compliance Guide and Defense Tech Insurance overview.

Apply for a coverage review
RiskCube CA Agency License #6017028
Space, defense, and dual-use tech Educational content, not legal advice

Keep reading

Andrei Craciunescu

About the author

Andrei Craciunescu

Founder & CEO, RiskCube · CA License #4467994

LinkedIn Profile

Andrei previously worked in the Risk & Analytics division of WTW (Willis Towers Watson), one of the world's largest insurance brokers and a recognized leader in AI, space, and defense risk. He holds an M.Sc. in Mathematics from LMU Munich and conducted PhD-level research in financial mathematics, including directors and officers (D&O) insurance, at the Technical University of Munich (TUM). His work applies AI and risk analytics to translate complex exposures into actionable insurance coverage decisions for defense, space, and dual-use technology startups