It is worth understanding early, because ITAR can affect who you can hire, which technology your team can access, whether you can sell internationally, what your customers and prime contractors require, and even how insurers underwrite your coverage. This guide explains what ITAR is, how to tell if it may apply to your company, the compliance issues startup teams commonly encounter, and where insurance does and does not help.
This is educational content, not legal or export-control advice. ITAR determinations are fact-specific. Confirm your classification and obligations with qualified export-control counsel.
Key takeaways
- ITAR controls defense articles on the U.S. Munitions List, along with the related technical data and defense services, and is administered by the State Department's DDTC.
- Releasing controlled technical data to a foreign person, even inside the United States, can count as an export (a "deemed export"), so foreign-person access is a core compliance question.
- Jurisdiction, classification, DDTC registration, and export authorization are four separate obligations. Registration alone does not authorize an export.
- Insurance does not replace a compliance program. Fines and penalties are frequently excluded and may be uninsurable, though certain D&O, Tech E&O, or Cyber policies may help with covered defense costs.
What Is ITAR?
The International Traffic in Arms Regulations (ITAR) implement the Arms Export Control Act by controlling the export, reexport, retransfer, and temporary import of defense articles designated on the United States Munitions List (USML), along with related technical data and defense services. ITAR is administered by the State Department's Directorate of Defense Trade Controls (DDTC).[1][2][7]
In plain terms: if your company builds, designs, or handles military or defense-related hardware, or the technical data and software needed to develop it, ITAR may govern who you can share it with, and where.
What Does ITAR Control?
Three concepts define ITAR's reach:
Defense articles
items designated on the United States Munitions List (22 CFR Part 121), which can include missiles and missile components, certain military satellites and space systems, and certain military aircraft and unmanned aircraft systems.[3]
Technical data
certain information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a USML defense article. Depending on the circumstances, this can include drawings, specifications, documentation, and directly related software.[1]
Defense services
furnishing certain assistance, including training, to a foreign person in connection with a defense article, or furnishing controlled technical data to a foreign person.[1]
Does ITAR Apply to My Startup?
Not every satellite, drone, or piece of source code at a defense-adjacent company is ITAR-controlled. What matters is whether the specific item is designated on the USML, and whether related technical data, software, or services fall within ITAR's controls. In practice, ITAR is more likely to be relevant if you design or build hardware for military use, hold controlled technical data, furnish defense services, or perform a defense contract involving ITAR-controlled articles, technical data, or services. If any of those fit, the next step is the jurisdiction and classification analysis below, ideally with qualified counsel.
Foreign-Person Access and Deemed Exports
Here is the part that surprises founders: under ITAR, releasing controlled technical data to a foreign person in the United States can be treated as an export. The regulation's definition of "export" expressly includes "releasing or otherwise transferring technical data to a foreign person in the United States (a deemed export)."[19] This can include providing access to controlled drawings, source code, engineering repositories, technical meetings, or cloud environments.
ITAR does not automatically require a company to hire only U.S. citizens. The relevant questions include whether the worker is a U.S. person or foreign person under ITAR, and whether the person will receive access to controlled technical data. For individual workers, U.S. persons generally include U.S. citizens and nationals, lawful permanent residents, refugees, and asylees. The analysis therefore should not be based on citizenship alone.[8][9] Companies should coordinate export-control and employment-law advice before restricting hiring or granting access, because citizenship-based hiring rules can create separate employment-law risk.[8]
ITAR vs. EAR: Which Regime Applies?
Not every defense-adjacent product falls under ITAR. A separate Commerce Department export-control regime is the Export Administration Regulations (EAR):
| ITAR | EAR | |
|---|---|---|
| Administered by | Department of State, DDTC | Department of Commerce, BIS |
| Generally covers | Defense articles designated on the USML, related technical data, and defense services | Commercial, dual-use, and certain military commodities, software, and technology subject to the EAR |
| Classification | USML category and paragraph | ECCN when listed on the Commerce Control List, or EAR99 when not listed |
| Authorization | DDTC license, agreement, approval, or applicable exemption | BIS license, license exception, or no-license-required treatment, depending on classification, destination, end user, and end use |
Many dual-use technologies fall under the EAR, but the result depends on the item's technical characteristics, destination, end user, and end use. Being subject to the EAR does not always mean an item is on the Commerce Control List; unlisted items are classified EAR99.[4][5]
Jurisdiction and Classification
Jurisdiction and classification come first: determine whether your item, software, technical data, or service is subject to ITAR, the EAR, or another regime, then identify the applicable USML category and paragraph, ECCN, or EAR99 designation.
Depending on the circumstances, you may document your own analysis with qualified advice, self-classify an item subject to the EAR, request a formal BIS classification, or submit a Commodity Jurisdiction request to DDTC when State Department jurisdiction is uncertain.[6][10]
When Do You Need to Register With DDTC?
Registration is a separate obligation from classification. Companies engaged in the United States in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC. Certain exemptions may apply. Registration does not itself authorize an export.[11]
A 6-Step ITAR Checklist for Startups
A useful order of operations, built around the principle of establishing export-control compliance before international demand arrives:
- 1
Determine jurisdiction and classification.
Identify whether the product, software, technical data, or service is subject to ITAR, EAR, or another regime.
- 2
Document the result.
Keep a written classification record and get qualified advice where it is uncertain.
- 3
Control foreign-person access.
Review who can reach controlled technical data: employees, contractors, founders, cloud systems, repositories, technical meetings, and facilities.
- 4
Determine registration and authorization.
Confirm whether DDTC registration is required and whether a license, agreement, approval, exception, or exemption is needed.
- 5
Design for international use early.
If you expect allied sales, consider a separately configured, exportable product version. This is a practical design step, not a legal requirement.
- 6
Review the insurance program.
Check whether export-controlled operations affect underwriting, application representations, regulatory-investigation provisions, and trade, sanctions, conduct, and data exclusions.
What Happens If You Get ITAR Wrong?
ITAR violations can lead to civil and criminal penalties, seizure or forfeiture, loss or suspension of export authorizations, and debarment from ITAR-controlled activities. Debarment is not an automatic ban on every government contract, but it can jeopardize contracts in practice.
These consequences may also affect defense contracts, customer relationships, financing, and the company's ability to enter international markets. The specific sanctions are set out in 22 CFR Part 127.[12]
Where Insurance Fits
Insurance does not replace an export-control compliance program. It is a potential financial backstop for certain covered claims, not a substitute for compliance. Three questions come up most often:
Can insurance pay an ITAR fine?
You should not assume so. Fines and penalties for export violations are frequently excluded and may also be uninsurable under applicable law.
Can insurance help with defense costs?
Sometimes, for a covered matter. Certain D&O policies may cover defense costs for a defined formal investigation of directors or officers and, more rarely, the company itself, and Tech E&O or Cyber may respond when a covered technology error, professional service, privacy event, or security incident is involved. Crime coverage may separately be relevant if the underlying event involves covered employee dishonesty, theft, or social engineering. Coverage is not automatic: it turns on the policy's definitions of Claim, Investigation, Insured, Wrongful Act, and Loss, and on conduct, sanctions, trade-control, governmental-action, and prior-knowledge exclusions.
What should a startup review in its policies?
Read your D&O, Tech E&O, Cyber, and Crime policies together to find gaps, conflicting definitions, and exclusions that could affect defense costs or third-party claims for a controlled-data event. Answer underwriting questions accurately, because incorrect or incomplete answers about government customers, export-controlled technology, foreign operations, or security controls can create rescission or coverage problems. The strongest protection stays preventive: documented classification, appropriate DDTC registration, required authorizations, foreign-person access controls, and, where appropriate, a technology control plan.
Frequently Asked Questions
Does ITAR apply to software and technical data?
It can. ITAR controls certain technical data and software directly related to a U.S. Munitions List defense article, not just hardware. Releasing that data to a foreign person, even inside the U.S., can be treated as an export.
Read more: ITAR definition of technical data, 22 CFR 120.33 [1]
Can a foreign person work for an ITAR-controlled company?
Yes. ITAR does not itself prohibit employing a foreign person, but releasing controlled technical data to a worker who is not a U.S. person may be an export requiring DDTC authorization. Confirm the worker's status and get export-control and employment-law advice before restricting hiring or access.
Read more: DOJ guidance on avoiding discrimination when complying with export-control laws [8]
What is the difference between ITAR and EAR?
ITAR (State Department, DDTC) covers defense articles on the U.S. Munitions List, related technical data, and defense services. The EAR (Commerce Department, BIS) covers commercial, dual-use, and certain military items, classified by an ECCN or as EAR99 when unlisted. Which one applies depends on the specific item.
Read more: scope of the EAR, 15 CFR Part 734 [4] and the DDTC portal [7]
Do I have to register with DDTC?
Companies engaged in the U.S. in manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC. Certain exemptions apply. Registration does not itself authorize an export, and it is separate from classification and licensing.
Read more: DDTC registration, 22 CFR Part 122 [11]
Can insurance cover an ITAR fine?
Fines and penalties are frequently excluded and may be uninsurable under applicable law. Certain policies may help with covered defense costs arising from a defined investigation or claim, but the result depends on the policy wording, governing law, parties involved, and nature of the proceeding.
This answer does not link to a single federal source because insurability depends on the policy wording, the nature of the sanction, governing state law, and applicable public-policy rules.
What insurance do defense-tech startups typically need to sell to the DoD or a defense prime?
It depends on the solicitation, contract type, work location, and any requirements a defense prime passes down; there is no single package every contractor must buy. For cost-reimbursement contracts, the Federal Acquisition Regulation ordinarily requires workers' compensation and employer's liability, general liability, and automobile liability (plus aircraft or vessel liability where those exposures apply). Fixed-price contracts do not always carry the same minimums, though a contracting officer may require coverage in special circumstances such as work on a government installation.[13][14][15][16] Primes and enterprise customers often add requirements through subcontract flow-downs (higher limits, umbrella or excess, waiver of subrogation, cyber, Tech E&O, product, aviation, or space coverage), and employees performing covered work overseas generally need Defense Base Act coverage before work begins.[17][18] These are contract- and exposure-driven, not universal FAR requirements. For the full flow-down and sourcing detail, see our Subcontractor Insurance Requirements guide.
Read more: FAR 28.307, cost-reimbursement contracts [14] and the Defense Base Act (Department of Labor) [18]
Sources and Further Reading
This guide draws on primary U.S. government sources so you can verify each point yourself. Links go to the official regulation or agency page. Regulations change, so confirm the current text and your own obligations with qualified export-control counsel.
- 22 CFR Part 120, Purpose and Definitions (State Department / DDTC), including 22 CFR 120.31 defense article, 120.32 defense service, and 120.33 technical data. ecfr.gov
- Arms Export Control Act, 22 U.S.C. 2778, Control of arms exports and imports (the statute ITAR implements). govinfo.gov
- 22 CFR Part 121, The United States Munitions List (USML). ecfr.gov
- 15 CFR Part 734, Scope of the EAR; Section 734.3(c) designates unlisted items as EAR99 (Commerce Department / BIS). ecfr.gov
- 15 CFR Part 738, Commerce Control List Overview and ECCN structure. ecfr.gov
- 22 CFR 120.12, Commodity Jurisdiction (Form DS-4076, submitted to DDTC). ecfr.gov
- Directorate of Defense Trade Controls (DDTC) Public Portal. pmddtc.state.gov
- DOJ Immigrant and Employee Rights Section, "How to Avoid Immigration-Related Discrimination when Complying with U.S. Export Control Laws." justice.gov
- 22 CFR 120.62, definition of "U.S. person," and 22 CFR 120.63, definition of "foreign person." ecfr.gov
- 15 CFR 748.3, BIS classification requests (CCATS via SNAP-R), and BIS "Classify Your Item" guidance. ecfr.gov · bis.gov
- 22 CFR Part 122, Registration of Manufacturers and Exporters. ecfr.gov
- 22 CFR Part 127, Violations and Penalties (civil and criminal penalties, seizure, debarment). ecfr.gov
- FAR 28.306, Insurance under fixed-price contracts (the Government is not ordinarily concerned with insurance under fixed-price contracts, but may require it in special circumstances). acquisition.gov
- FAR 28.307, Insurance under cost-reimbursement contracts (ordinarily requires the insurance types listed in 28.307-2). acquisition.gov
- FAR 28.307-2, Liability (employer's liability, general liability, automobile liability, and specialized exposures, with minimum amounts). acquisition.gov
- FAR 28.310, Contract clause for work on a government installation. acquisition.gov
- FAR 28.305, Overseas workers' compensation and war-hazard insurance (Defense Base Act clause). acquisition.gov
- U.S. Department of Labor, Office of Workers' Compensation Programs, Defense Base Act. dol.gov
- 22 CFR 120.50, definition of "Export," which at paragraph (a)(2) defines releasing or transferring technical data to a foreign person in the United States as a deemed export. ecfr.gov
Note: the eCFR (ecfr.gov) is an authoritative, continuously updated online version of the Code of Federal Regulations, but it is not the official legal edition. The annual Code of Federal Regulations and rules published in the Federal Register remain the official legal publications. Some government sites rate-limit automated tools; the links above open normally in a browser.
Building Defense Tech? Review Coverage Around Your Actual Operations
Export-controlled operations can materially affect how insurers underwrite D&O, Tech E&O, Cyber, Crime, and other coverage. RiskCube reviews these policies together, with attention to regulatory-investigation provisions, controlled-data exposure, and sanctions, trade-control, conduct, and governmental-action exclusions. Coverage availability depends on your technology, customers, foreign operations, compliance controls, disclosures, policy wording, and underwriting approval.
Building for the defense industry? See our CMMC Compliance Guide and Defense Tech Insurance overview.
Apply for a coverage reviewKeep reading
Subcontractor Insurance Requirements: The Complete Guide
Subcontractor insurance requirements explained: the core coverages, endorsements, and AM Best carrier rating you need to sell to a large contractor.
Federal Contract Insurance Checklist (2026)
Government contractor insurance: required coverages, FAR limits, endorsements, Defense Base Act, AM Best ratings, and mistakes that delay starts.
About the author
Andrei Craciunescu
Founder & CEO, RiskCube · CA License #4467994
LinkedIn ProfileAndrei previously worked in the Risk & Analytics division of WTW (Willis Towers Watson), one of the world's largest insurance brokers and a recognized leader in AI, space, and defense risk. He holds an M.Sc. in Mathematics from LMU Munich and conducted PhD-level research in financial mathematics, including directors and officers (D&O) insurance, at the Technical University of Munich (TUM). His work applies AI and risk analytics to translate complex exposures into actionable insurance coverage decisions for defense, space, and dual-use technology startups