An ITAR statement is a compliance notice placed on documents, hardware, digital files, or shipping paperwork to flag that the material is controlled under the International Traffic in Arms Regulations. It has two jobs: warn anyone handling the material that it cannot be shared with foreign persons without authorization, and satisfy the federal labeling rules that govern exports of defense articles. Getting it wrong is expensive. A willful violation can bring criminal fines of up to $1,000,000 and 20 years in prison per count, plus civil penalties up to $1,271,078 per violation.1eCFR. 22 CFR Part 127 – Violations and Penalties
The Two Kinds of ITAR Statements
ITAR statements fall into two categories, and they are not interchangeable. Mixing them up is one of the more common findings during an audit.
Internal Notices of Control
The first is a general notice of control that goes on documents, folders, and screens. Its purpose is to alert anyone handling the material that the content is ITAR-restricted and cannot be released to a foreign person without government authorization. No single regulation dictates the exact wording, but a workable notice identifies the material as subject to ITAR (22 CFR Parts 120–130) and warns against unauthorized transfer to a non-U.S. person.
Placing this notice on every controlled document is how companies guard against “deemed exports,” which happen when a foreign person gains access to controlled technical data inside the United States.2eCFR. 22 CFR 120.50 – Export The label itself does not authorize any disclosure. It puts people on notice; licensing or an applicable exception is what actually permits access.
The Destination Control Statement
The second is the Destination Control Statement, and this one is not optional or flexible. Under 22 CFR 123.9(b), the exporter must include, on the commercial invoice, bill of lading, air waybill, or other shipping document, the country of ultimate destination, the end user, the license or exemption citation, and this exact language:
“These items are controlled by the U.S. government and authorized for export only to the country of ultimate destination for use by the ultimate consignee or end-user(s) herein identified. They may not be resold, transferred, or otherwise disposed of, to any other country or to any person other than the authorized ultimate consignee or end-user(s), either in their original form or after being incorporated into other items, without first obtaining approval from the U.S. government or as otherwise authorized by U.S. law and regulations.”3eCFR. 22 CFR 123.9 – Country of Ultimate Destination and Approval of Reexports or Retransfers
The statement must be clearly visible and printed in English. Altering the language or leaving it off can result in seizure of the shipment at the border.
What Material Needs an ITAR Statement
The scope is broader than most engineers assume. A “defense article” under 22 CFR 120.31 includes any item or technical data designated on the U.S. Munitions List, along with models, mockups, forgings, castings, and unfinished products identifiable as defense articles by their properties, composition, geometry, or function.4eCFR. 22 CFR 120.31 – Defense Article “Technical data” under 22 CFR 120.33 covers the information required for design, production, assembly, operation, repair, testing, or modification of those articles — blueprints, drawings, photographs, plans, instructions, and related software.5eCFR. 22 CFR 120.33 – Technical Data General marketing information and basic system descriptions sit outside both definitions.
In practice, that means the marking requirement reaches far past finished weapons. Technical drawings, prototypes, manufacturing tooling, preliminary design sketches, discarded drafts, training materials, and maintenance guides all qualify if the content reveals controlled technical data. Rejected drafts are not exempt just because they were rejected.
Digital assets are where companies most often fall short. Source code for defense applications, cryptographic tools, CAD files, and data sitting in shared drives, cloud repositories, and email attachments all need to be identified as controlled. Physical hardware such as specialized sensors or guidance systems needs a label on the housing or on the accompanying technical manual.
How to Apply the Statement Across Formats
The goal is to make the restriction impossible to miss, whatever form the material takes.
Paper and Hardware
Blueprints and technical documents should carry the compliance notice in both the header and footer of every page. Large-format drawings benefit from a watermark across the center so the warning survives photocopying and scanning. Hardware components typically use engraved markings or durable adhesive labels that reference the specific license or contract number tied to the item.
Email, Folders, and Software Portals
Electronic environments need more than a label buried in a filename. Software portals and secure databases commonly use splash screens that force users to acknowledge the restrictions before viewing any controlled file. For email, embed the ITAR notice in the body of the message itself; do not rely on an attachment the recipient may skip. Shared-drive folders should have names that signal their controlled status, and dropping a standalone compliance notice file inside each restricted folder adds a second layer of warning.
Cloud Storage and the Encryption Carve-Out
Storing ITAR-controlled technical data in the cloud is not automatically an export, provided you meet the encryption requirements in 22 CFR 120.54. The data must be unclassified, protected with end-to-end encryption, and secured using cryptographic modules validated under FIPS 140-2 (or its successors) with at least 128-bit security strength. The encryption keys must remain under the exclusive control of U.S. persons, and the data cannot be intentionally stored in or sent from a country proscribed under 22 CFR 126.1.6eCFR. 22 CFR 120.54 – Activities That Are Not Exports, Reexports, Retransfers, or Temporary Imports If any one of those conditions fails, the cloud storage counts as an export and needs a license. Data that merely transits the internet through a proscribed country is not treated as “stored” there.
Deemed Exports and Who Can See the Material
A deemed export happens when controlled technical data is released to a foreign person inside the United States. No border crossing is required.2eCFR. 22 CFR 120.50 – Export An engineer showing a controlled schematic to a colleague who holds a foreign passport is an export event. This is where most accidental violations happen, and it is why the internal notice matters even for material that never leaves the building.
Several situations sit outside deemed-export controls:
- Sharing controlled data with U.S. citizens, lawful permanent residents, refugees, and persons granted asylum is not a deemed export.
- Under 22 CFR 120.34, technical data that has been intentionally published in books, presented at open conferences, or released through government channels is in the public domain and not controlled. Accidental disclosure does not qualify.
- Basic and applied research at accredited universities can qualify for a fundamental-research exclusion if results are ordinarily published and shared broadly and the sponsor imposes no restrictions on publication or access.
- A foreign national’s access is properly authorized if it falls within the scope of a Technical Assistance Agreement or other approved license.
Make Sure ITAR Is Actually the Right Framework
Before you label anything, confirm the item is on the U.S. Munitions List. Items designed or modified for military use generally fall under ITAR, administered by the State Department. Dual-use items with both civilian and military applications typically fall under the Export Administration Regulations and the Commerce Control List, administered by the Commerce Department’s Bureau of Industry and Security. The classification turns on the inherent nature and origin of the technology, not on who happens to be buying it. When both frameworks appear to describe an item, ITAR takes priority, and you can submit a Commodity Jurisdiction request to DDTC for a formal determination if you are unsure. Using the wrong framework means every downstream compliance statement rests on the wrong foundation.
Penalties, and What to Do If You Discover a Violation
A willful violation of the Arms Export Control Act or its regulations can bring a criminal fine of up to $1,000,000 per violation, imprisonment for up to 20 years, or both.1eCFR. 22 CFR Part 127 – Violations and Penalties The Assistant Secretary of State for Political-Military Affairs can impose civil penalties up to $1,271,078 per violation, or twice the transaction value, whichever is greater. No inflation adjustment was applied for 2026, so the 2025 figures still control. A convicted person is barred from all ITAR-regulated activities for at least three years, and reinstatement requires a formal application. DDTC can also impose administrative debarment without a criminal conviction if the record shows the company cannot be relied on to comply.7eCFR. 22 CFR 127.7 – Debarment
If you find a problem before the government does, disclose it. The Department of State encourages voluntary self-disclosure through DDTC, and DDTC may treat the disclosure as a mitigating factor when setting penalties. Failure to report a known violation cuts the other way.8eCFR. 22 CFR 127.12 – Voluntary Disclosures The process begins with an initial written notification as soon as the violation is discovered, followed by a full disclosure within 60 calendar days that details the nature and extent of the violation, the circumstances, and everyone involved. Extensions are available but must be requested in writing by an empowered official. Voluntary disclosure does not guarantee immunity — DDTC retains discretion to impose penalties and can refer matters to the Department of Justice — but companies that self-disclose and cooperate consistently see lighter outcomes than those who wait to be caught.