ITAR Documents: Marking, Storage, and Foreign National Access

Handling a document that describes a defense article on the U.S. Munitions List means treating the paper the same way you would treat the weapon it describes. ITAR document requirements, set out at 22 CFR Parts 120–130 and administered by the State Department’s Directorate of Defense Trade Controls (DDTC), govern how technical data must be identified, marked, stored, transmitted, shared, and retained. Get any one of those steps wrong and you are exposed to civil penalties reaching the greater of $1,271,078 or twice the transaction value per violation, and, for willful conduct, criminal fines up to $1,000,000 and up to 20 years in prison.

What Makes a Document ITAR-Controlled

The trigger is the subject matter, not the format. Under 22 CFR 120.33, technical data is information required for the design, development, production, repair, testing, or modification of a defense article. That covers blueprints, drawings, photographs, plans, instructions, manuals, and software directly related to defense articles.1eCFR. 22 CFR 120.33 – Technical Data A maintenance manual carries the same regulatory weight as the hardware it documents.

Whether the underlying item is a defense article turns on the U.S. Munitions List at 22 CFR Part 121, which runs 21 categories from firearms and ammunition through military electronics, spacecraft, and toxicological agents. If the item is listed there, the associated technical data is subject to ITAR. Physical models or mockups that reveal controlled technical data are themselves defense articles under 22 CFR 120.31, along with partially manufactured components identifiable by material or intended military function.2eCFR. 22 CFR 120.31 – Defense Article

When classification is not obvious, submit a commodity jurisdiction request to DDTC using Form DS-4076 through the Defense Export Control and Compliance System (DECCS). You do not need to be registered with DDTC to file. A case number issues immediately and the request appears in DECCS within 48 business hours.3U.S. Department of State – Directorate of Defense Trade Controls. Commodity Jurisdictions An item that is not on the USML may still be controlled under the Commerce Department’s Export Administration Regulations, so the CJ answer often decides which regime governs the paperwork.

When Documents Fall Outside ITAR

Not every defense-related document is controlled. Under 22 CFR 120.34, information that has been published and is generally accessible to the public is public domain and outside ITAR reach. That includes material available through bookstores, public libraries, unrestricted subscriptions, patent offices, and conferences open to the public within the United States.4eCFR. 22 CFR 120.34 – Public Domain

Fundamental research in science and engineering at accredited U.S. institutions also qualifies as public domain when the results are ordinarily published and shared broadly with the scientific community. The exemption disappears the moment publication restrictions, foreign national access controls, prepublication review rights, or security clearance requirements attach to the work.4eCFR. 22 CFR 120.34 – Public Domain A single sponsored research clause can pull an entire project back under the regulations.

Marking Documents and Shipping Statements

Every page of ITAR-controlled technical data should carry a cautionary notice on its face. The regulations do not prescribe exact language for internal markings, but industry practice is to reference ITAR, the applicable USML category, and a warning that unauthorized disclosure may result in criminal prosecution. The marking matters because it tells anyone who picks up the document what rules apply before they act on it.

For shipping, the language is fixed. Under 22 CFR 123.9, the commercial invoice for any defense article exported under a license or other approval must include a destination control statement identifying the country of ultimate destination, the end-user, and the license number, together with the following verbatim text: “These items are controlled by the U.S. government and authorized for export only to the country of ultimate destination for use by the ultimate consignee or end-user(s) herein identified. They may not be resold, transferred, or otherwise disposed of, to any other country or to any person other than the authorized ultimate consignee or end-user(s), either in their original form or after being incorporated into other items, without first obtaining approval from the U.S. government or as otherwise authorized by U.S. law and regulations.”5eCFR. 22 CFR 123.9 – Country of Ultimate Destination and Approval of Reexports or Retransfers

Storing and Transmitting ITAR Documents

Physical documents belong in locked cabinets or secure rooms with restricted access. Only U.S. persons with a documented need to know should be able to enter, and access logs should track who handles what and when.

The Encryption Safe Harbor

A widespread misreading of the rules treats encryption as a storage mandate. It is not. 22 CFR 120.54 creates a safe harbor that defines what does not count as an export. If you send, take, or store unclassified technical data using end-to-end encryption that meets FIPS 140-2 standards (or equivalent strength of at least AES-128), and you do not intentionally send or store the data in a country subject to a denial policy under 22 CFR 126.1, the transmission or storage is not an export.6eCFR. 22 CFR 120.54 – Activities That Are Not Exports, Reexports, Retransfers, or Temporary Imports Data merely transiting a proscribed country’s internet infrastructure is not treated as stored there.

The storage-location restriction is narrower than many companies assume. It bars intentional storage in the countries listed under 22 CFR 126.1, which currently include Belarus, Burma, China, Cuba, Iran, North Korea, Russia, Syria, Venezuela, and roughly a dozen others with country-specific restrictions.7eCFR. 22 CFR 126.1 – Prohibited Exports, Imports, and Sales To or From Certain Countries A cloud provider storing encrypted files on servers in an allied country does not, by that fact alone, create an export, provided the encryption meets the standard and access controls prevent release to unauthorized persons.

Sharing Documents With Foreign Nationals

The biggest recurring compliance failure has nothing to do with shipping. Under 22 CFR 120.50, releasing or transferring technical data to a foreign person inside the United States is itself an export. The regulations call this a “deemed export,” treated as an export to every country in which that foreign person holds or has held citizenship or permanent residency.8eCFR. 22 CFR Part 120 – Purpose and Definitions Showing a controlled drawing to a foreign national colleague in your office is legally no different from shipping it overseas.

The everyday scenarios are the risky ones: giving a foreign national employee access to a shared drive that contains controlled files, presenting technical specifications at an internal meeting where foreign nationals are in the room, emailing engineering data to a non-U.S. team member. Companies with mixed workforces need internal access controls and a written technology control plan so that only authorized U.S. persons interact with the data.

When sharing is authorized and ongoing rather than one-off, the underlying authorization sits above the document itself. A standard permanent export uses Form DSP-5; temporary exports returning to the United States within four years and involving no transfer of title use DSP-73; significant military equipment or classified articles require a DSP-83 nontransfer and use certificate binding the foreign consignee and end-user before any license issues.9Directorate of Defense Trade Controls. License Guidance10eCFR. 22 CFR 123.5 – Temporary Export Licenses11eCFR. 22 CFR 123.10 – Nontransfer and Use Assurances Long-running relationships use a Manufacturing License Agreement for foreign manufacturing of defense articles or a Technical Assistance Agreement for defense services and disclosure of technical data over a defined period.12DDTC Public Portal. FAQ Detail – Manufacturing License Agreements A TAA does not automatically cover every export need in a relationship; activities outside its approved scope require separate authorization.

Recordkeeping

Under 22 CFR 122.5, ITAR-related records must be retained for five years from the expiration of the license or other approval, or from the date of the transaction for exports made under an exemption. DDTC can prescribe a longer or shorter period in individual cases, but five years is the baseline.13eCFR. 22 CFR 122.5 – Maintenance of Records by Registrants

The categories that need to survive that full period include:

  • Export licenses and approvals
  • Shipping documentation from freight forwarders
  • Agreements and their amendments
  • Correspondence with DDTC
  • Commodity jurisdiction determinations
  • Internal classification analyses documenting why an item was or was not treated as ITAR-controlled

Companies that treat recordkeeping as an afterthought tend to discover the gap during an audit or enforcement inquiry, which is the worst possible time to find out the file is incomplete.

What Happens When Documents Are Mishandled

ITAR penalties run on two tracks, and a single violation can trigger both.

Criminal penalties under 22 U.S.C. 2778 apply to willful violations: fines up to $1,000,000 per violation, imprisonment up to 20 years, or both.14Office of the Law Revision Counsel. 22 USC 2778 – Control of Arms Exports and Imports Willful means the person knew the conduct was unlawful or acted with reckless disregard for the law; it does not require an intent to harm national security.

Civil penalties under 22 CFR 127.10 do not require proof of willfulness. Each violation of the Arms Export Control Act can reach the greater of $1,271,078 or twice the value of the underlying transaction.15eCFR. 22 CFR 127.10 – Civil Penalty Enforcement resolutions frequently include a consent agreement layering on a special compliance officer, comprehensive audits, a denial policy for new licenses, debarment from future defense trade, or a tracking system following every controlled item from production to final delivery.16U.S. Department of State – Directorate of Defense Trade Controls. Penalties and Oversight Agreements For many companies the operational weight of the consent agreement outlasts the fine.

Voluntary Self-Disclosure

When a company finds a possible violation, 22 CFR 127.12 strongly encourages voluntary self-disclosure. DDTC may treat a voluntary disclosure as a mitigating factor when setting administrative penalties, while failing to report a known violation is treated as aggravating.17eCFR. 22 CFR 127.12 – Voluntary Disclosures The process starts with an initial notification to DDTC as soon as the violation is discovered, followed by an internal review of the transactions in question. A complete disclosure must be submitted within 60 calendar days of the initial notification, or DDTC will not treat the submission as qualifying. An empowered official or senior officer can request a written extension, but the request has to explain exactly what information is missing and why. Self-disclosure is not immunity. DDTC keeps full discretion over penalties and can still refer a case to the Department of Justice for criminal prosecution, though it will inform DOJ of the voluntary nature of the disclosure.