ITAR Software Compliance: DDTC Registration, Exports, and Penalties

ITAR software compliance starts with a single question: was your software designed for a military, intelligence, or defense purpose? If the answer is yes, the International Traffic in Arms Regulations almost certainly apply, and your company must register with the State Department’s Directorate of Defense Trade Controls (DDTC), restrict access to U.S. persons, secure the code to federal encryption standards, keep detailed records for five years, and obtain licenses before any export, including sharing code with a foreign employee sitting at the next desk. The rules are administered under the Arms Export Control Act of 1976,1U.S. Congress. International Security Assistance and Arms Export Control Act of 1976 and civil fines run past $1.27 million per violation, with criminal penalties reaching $1 million and 20 years in prison.2eCFR. 22 CFR 127.10 – Civil Penalty

Is Your Software Actually ITAR-Controlled

The United States Munitions List (USML), at 22 CFR Part 121, tells you what the State Department controls. Software shows up in several USML categories depending on function. Category XIII covers military cryptographic systems, intelligence-grade encryption software, and tools that manage access between security classification levels. Modeling and simulation tools for chemical or biological weapons also fall under Category XIII when developed under a Department of Defense contract. Category XXI is the catch-all for defense articles that don’t fit cleanly elsewhere.3eCFR. 22 CFR Part 121 – The United States Munitions List Software that enables target acquisition, guides unmanned combat vehicles, operates military-grade sensors, or supports high-precision spatial mapping for artillery lands under ITAR regardless of the specific category.

What matters is original design intent, not current use. A program built for military communications encryption is ITAR-controlled even if someone later finds a commercial application. If the software has a direct commercial equivalent and was not specifically designed for military purposes, it may fall under a different regime.

ITAR or EAR

The Export Administration Regulations (EAR), run by the Commerce Department’s Bureau of Industry and Security, cover dual-use items with both commercial and potential military applications. ITAR is stricter: it generally requires a license regardless of destination country, while EAR licensing varies by destination, end use, and classification.

The order of review is set by regulation. Check the USML first. If the software was specifically designed or modified for military use, it belongs under ITAR. If it does not match any USML entry, move to the Commerce Control List under the EAR. Items on neither list receive a default “EAR99” designation and can generally be exported without a license to most destinations.4eCFR. 22 CFR 120.11 – Order of Review

When classification is genuinely unclear, you can ask DDTC for a binding commodity jurisdiction determination through the DECCS portal, with technical specifications, marketing materials, development history, and a letter arguing for your preferred classification.5U.S. Department of State Directorate of Defense Trade Controls. Commodity Jurisdictions (CJs) You do not need to be registered with DDTC to submit one, which helps if you are still figuring out whether ITAR applies at all.6eCFR. 22 CFR 120.4 – Commodity Jurisdiction

What Counts as a Software Export

The definition of “export” reaches far beyond shipping code overseas. Under 22 CFR 120.50, an export includes any transmission out of the United States and any release of technical data to a foreign person, even if that person is standing in your office.7eCFR. 22 CFR 120.50 – Export This second scenario, the “deemed export,” is where most software teams get caught.

A deemed export happens when a foreign national inside the United States gains access to controlled technical data. Emailing source code to a foreign colleague counts. Granting remote desktop access to an overseas contractor counts. Sharing credentials for a secure repository counts. Verbally describing a controlled architecture to a foreign person counts. Video calls where participants can see source code structures qualify. Pushing software updates over the internet to foreign users requires State Department authorization. Passive access is treated the same as active transfer: if a foreign IT contractor can reach a database containing controlled data, that is a violation even if they never open it.

A release to a foreign person inside the United States is deemed an export to every country where that person holds citizenship or permanent residency.7eCFR. 22 CFR 120.50 – Export Granting access to an employee with dual citizenship in a sanctioned country creates an export to that country, with the licensing consequences that follow.

For foreign licensees employing dual or third-country nationals, ITAR requires vetting before those employees touch controlled software. Under 22 CFR 126.18, the licensee must screen for ties to countries on the ITAR 126.1 proscribed list, examining regular travel, ongoing contact with officials or agents, military membership, and business or financial ties. Cleared employees must sign a non-disclosure agreement before accessing any controlled material.

Registering With DDTC

Any company that manufactures or exports defense articles, including controlled software, must register with the Directorate of Defense Trade Controls before doing anything else. Registration is the gateway to obtaining export licenses, and operating without it is itself a violation.

The Application

The registration form is DS-2032, the Statement of Registration.8eCFR. 22 CFR 129.8 – Submission of Statement of Registration You will need the company’s legal name, physical address, and federal Employer Identification Number. Senior officers provide personal identifying information for background checks. The application requires you to specify your business type (manufacturer, exporter, or broker) and disclose your corporate structure, including parent companies and foreign affiliates. A valid digital certificate is required to sign electronically. The completed form goes through the Defense Export Control and Compliance System (DECCS) online portal and must be reviewed, signed, and submitted by your Empowered Official.9Directorate of Defense Trade Controls. Create a New Registration Reviews take roughly 30 days on average.10Directorate of Defense Trade Controls. Registration Renewal Successful applicants receive a registration code that must be renewed annually.

Fees

DDTC uses a three-tier fee structure that took effect in January 2025:

  • Tier 1 is a $3,000 annual flat fee for first-time registrants (manufacturers, exporters, and standalone brokers). A temporary initiative effective January 9, 2025, allows qualifying Tier 1 registrants to petition for a $500 discount, bringing the fee to $2,500.
  • Tier 2 is $4,000 for registrants who received five or fewer approved licenses or authorizations during the 12-month period ending 90 days before their current registration expires.
  • Tier 3 is a calculated fee for registrants with more than five approvals: $4,000 plus $1,100 for each approval beyond five, with a cap tied to the total value of approvals.11Directorate of Defense Trade Controls. Registration Payment

The Empowered Official

Every registered company must designate at least one Empowered Official. This person signs license applications and other submissions to DDTC, and their actions carry the same legal weight as the company’s. To qualify, the individual must be a U.S. person, directly employed by the company (not an outside consultant or attorney), and hold a position with authority over policy or management decisions. The company must formally authorize them in writing.12eCFR. 22 CFR 120.67 – Empowered Official

The role demands more than a signature. An Empowered Official must have independent authority to investigate any proposed export and block it if it does not comply, including the ability to say no to management pressure. They bear personal responsibility for the truthfulness of every representation made to the government and must report violations or suspected violations to DDTC. False statements can result in civil or criminal penalties against the individual, not just the company.

Reporting Changes

Registration is not a set-and-forget filing. If your company changes its name, legal structure, ownership, board of directors, or senior officers, you must notify DDTC in writing within five days. If ownership will transfer to a foreign person, notice must go out by registered mail at least 60 days before closing. After a merger or acquisition, the surviving entity has 60 days to submit signed amendments to existing agreements along with the new company details.13eCFR. 22 CFR 122.4 – Notification of Changes in Information Furnished by Registrants Routine changes roll into your annual renewal.

Securing the Software

The regulations specify that controlled technical data transmitted electronically must be secured using cryptographic modules compliant with FIPS 140-2 or its successors, or with alternative encryption providing at least 128 bits of security strength (the equivalent of AES-128). FIPS 140-3 officially superseded FIPS 140-2 in 2019, and remaining FIPS 140-2 certifications move to the historical list in September 2026, so new systems should implement FIPS 140-3 validated modules.14Computer Security Resource Center. FIPS 140-3 Transition Effort

Access must be limited to U.S. persons. That term covers more than citizens. It includes lawful permanent residents and “protected individuals” as defined by federal immigration law, a category that encompasses refugees and certain asylees.15eCFR. 22 CFR 120.62 – U.S. Person Corporations incorporated in the United States and U.S. government entities also qualify. Everyone else is a “foreign person,” and their access to controlled data requires specific authorization.

ITAR-controlled data should reside on servers physically located within the United States. Cloud service providers must offer government-grade environments that restrict administrative access to cleared U.S. persons and prevent data from transiting international networks. Detailed access logs must be maintained. Workstations where developers write controlled code must be secured against unauthorized viewing. Multi-factor authentication is baseline for secure repositories. Encryption keys should be managed through hardware security modules rather than stored in software where they could be extracted. A vulnerability management program that identifies and patches security gaps on an ongoing basis rounds out the technical side.

Most organizations formalize these safeguards into a Technology Control Plan (TCP), a written document identifying the controlled technology and its ITAR classification, listing every person authorized to access it along with their citizenship status, describing physical security measures such as locked rooms, badge access, and restricted-area signage, and detailing IT security infrastructure including encryption protocols and secure distribution methods. All personnel with access must read and sign it, and staffing changes require an update.

Recordkeeping and Inspections

Registered companies must maintain records for five years from the expiration of the relevant license or authorization, or from the date of the transaction if an exemption was used.16eCFR. 22 CFR 122.5 – Maintenance of Records by Registrants The DDTC director can extend or shorten this period case by case.

The records must cover the full lifecycle of controlled articles: manufacturing, acquisition, export documentation, license applications, and defense services provided. Financial records matter too, including fees, commissions, and political contributions connected to defense trade. Electronic records must reproduce to paper with high legibility and must prevent alteration without logging who changed what and when.

Records must be available at any time for inspection by DDTC, the Diplomatic Security Service, U.S. Immigration and Customs Enforcement, or U.S. Customs and Border Protection. When an inspector arrives, you must provide the records along with the equipment and personnel needed to locate, read, and reproduce them.16eCFR. 22 CFR 122.5 – Maintenance of Records by Registrants This is not a requirement you can satisfy retroactively once an audit is announced.

Voluntary Self-Disclosure

When a company discovers it may have violated ITAR, the regulations strongly encourage self-reporting. A voluntary disclosure can serve as a mitigating factor in penalty decisions. Failing to disclose a known violation is treated as an aggravating factor.17eCFR. 22 CFR 127.12 – Voluntary Disclosures

The disclosure must be in writing and submitted immediately after the violation is discovered. If the initial notification is incomplete, the company has 60 calendar days to submit a full disclosure, and an Empowered Official or senior officer can request an extension in writing. The disclosure must describe the nature and extent of the violation, how it was discovered, and what corrective measures the company has taken.

Self-disclosure only qualifies as “voluntary” if DDTC receives it before any government agency independently discovers the same information and starts an investigation. Once the government is already looking, the window closes. Disclosure does not guarantee leniency: DDTC retains full discretion and can still refer the matter to the Department of Justice for criminal prosecution. In practice, companies that self-report, cooperate, and demonstrate improved compliance receive significantly better outcomes than those caught by investigators.17eCFR. 22 CFR 127.12 – Voluntary Disclosures

Penalties

Violations run on two tracks. On the civil side, the State Department can impose fines of up to $1,271,078 per violation, or twice the transaction value, whichever is greater.2eCFR. 22 CFR 127.10 – Civil Penalty The figure is inflation-adjusted. Civil penalties can be imposed alongside or instead of administrative actions like license revocations or debarment from future defense trade.

Criminal penalties apply to willful violations: up to $1,000,000 in fines per violation and up to 20 years in federal prison.18eCFR. 22 CFR Part 127 – Violations and Penalties The two tracks can run at the same time. A single unauthorized export of controlled software can trigger both a multi-million-dollar civil fine and a criminal prosecution, and penalties apply per violation, so multiple unauthorized transmissions multiply the exposure. Debarment from defense trade, which shuts a company out of the industry, is often the most damaging consequence.

When the Fundamental Research Exclusion Applies (and When It Doesn’t)

Not all software connected to defense topics falls under ITAR. The fundamental research exclusion applies to basic or applied research in science and engineering when the results are ordinarily published and shared broadly. University-based software projects can qualify, but only if the research is conducted in the United States, there are no publication restrictions beyond a limited proprietary review, and there are no sponsor-imposed restrictions on the nationality of personnel.

The exclusion is easier to lose than most people expect. A sponsor requirement for pre-publication review with the right to withhold results, restrictions on which nationalities can participate, or work at a secure facility all destroy it. Even informal restrictions communicated by email or conversation count. For software specifically, any access control such as a login requirement or password protection can be read as destroying the “unrestricted” status the exclusion requires. Software that qualifies as fundamental research must be freely downloadable without the institution knowing who is downloading it or from where.

Encryption software faces particular scrutiny. Even if developed in an academic setting, encryption tools generally cannot rely on the exclusion. The line between controlled and uncontrolled software in a university context is thinner than most researchers assume, and getting it wrong means the institution has been making unauthorized exports every time a foreign graduate student accessed the code.