Aerospace & DefenseFree Interactive Tool

ITAR Compliance Checklist for Defense Manufacturers

This free ITAR compliance checklist gives defense manufacturers a structured 32-point review of their export compliance program, from DDTC registration through technical data controls, foreign person access, IT security, licensing, and recordkeeping. It is built for machine shops, electronics manufacturers, and assemblies suppliers who make USML-listed hardware or handle ITAR technical data flowed down from primes. Work through each group with your compliance, engineering, IT, and HR leads; the critical-flagged items are the ones that most often trigger consent agreements and seven-figure penalties when they fail.

0%

0 of 35 items complete

9 critical items still open - these are the highest-risk gaps.

Registration and Program Governance

Technical Data Controls

Personnel and Foreign Person Access

Physical and IT Security

Exports, Shipments, and Brokering

Recordkeeping, Audits, and Violations

Score yourself honestly: every unchecked critical item represents exposure to civil penalties that can exceed $1M per violation, plus potential debarment from defense contracting. If you cannot check all critical items, treat those gaps as your immediate remediation priorities and consider whether a voluntary disclosure conversation with counsel is warranted.

Get your full ITAR compliance gap report

We will email you a personalized analysis of your checklist results with remediation priorities ranked by penalty exposure, and an export compliance specialist will follow up to walk through it.

No spam. Your results stay private. Unsubscribe anytime.

How this checklist is organized

The checklist follows the structure DDTC expects to see in a functioning compliance program: governance and registration first, because nothing else matters if you are unregistered or have misclassified your products; then the operational controls - technical data handling, personnel screening, and IT security - where day-to-day violations actually occur; and finally transactional controls and recordkeeping, which is what investigators pull first. Critical items are flagged where enforcement history shows the highest penalty exposure: unregistered manufacturing, unmarked technical data, foreign person access without authorization, non-compliant cloud storage, and unauthorized exports. Roughly a quarter of the items carry that flag, which mirrors how consent agreements distribute their findings.

Where manufacturers most often fail

Enforcement patterns are consistent across recent DDTC consent agreements, and four failure modes dominate for mid-market manufacturers:

  • Technical data leakage - ITAR drawings emailed to offshore suppliers or stored in commercial cloud tools without the encryption carve-out
  • Deemed exports - foreign person employees or visitors given access to controlled data without a license, often because HR and engineering never compared notes
  • Registration and classification gaps - companies manufacturing USML items for years without DDTC registration, or assuming EAR jurisdiction without analysis
  • Recordkeeping failures - inability to produce screening evidence, license records, or training documentation during an audit or disclosure

Interpreting your gaps and prioritizing

If any critical item is unchecked, that is your remediation priority regardless of how the rest of the checklist looks - these are the gaps that convert from compliance debt into violations. Sequence remediation in three passes. First, stop ongoing exposure: restrict access, quarantine data, pause questionable transfers. Second, fix the systemic control - the process, marking standard, screening step, or system configuration that let the gap exist. Third, assess look-back exposure with export counsel and decide whether voluntary disclosure is appropriate; DDTC treats disclosure as a significant mitigating factor. Re-run the checklist quarterly, and after any acquisition, new program win, ERP change, or cloud migration, because those events reliably reopen closed gaps.

How Netray helps you close ITAR gaps

Most ITAR technical data at a manufacturer does not sit in a compliance tool - it sits in your ERP and the systems around it: item masters, routings, drawings attached to jobs in SyteLine or LN, supplier portals, and quoting emails. Netray helps you find and control that data where it actually lives. We implement export-control flags and access segregation inside Infor SyteLine, LN, and Baan, design ITAR-compliant data architectures including GovCloud and on-prem options, and deploy on-prem AI so your teams get modern automation without technical data ever leaving your controlled boundary. If this checklist surfaced gaps, we can turn them into a sequenced remediation plan.

Frequently Asked Questions

Do I need to register with DDTC if I only make parts for a prime contractor?

If you manufacture defense articles - items described on the U.S. Munitions List - you must register with DDTC even if you never export anything and even if you are a lower-tier subcontractor. Registration is required for manufacturing alone. Many machine shops discover this obligation years late. If you are unsure whether your parts are USML-controlled, a jurisdiction and classification analysis should be your first step, and your prime's flowdown clauses are a strong hint.

Can I store ITAR technical data in the cloud?

Yes, under conditions. DDTC's encryption carve-out allows properly end-to-end encrypted technical data to transit or be stored in cloud infrastructure without it being an export, provided keys are not accessible to foreign persons. Alternatively, ITAR-qualified environments like AWS GovCloud or Azure Government restrict data to U.S. regions and U.S.-person support staff. Standard commercial tenants of consumer SaaS tools generally do not qualify, which is where most violations occur.

What happens if I find a past violation while working through this checklist?

Stop the ongoing conduct, preserve records, and engage export counsel before communicating broadly. DDTC operates a voluntary disclosure program and treats self-disclosure as a major mitigating factor - most disclosed cases resolve without monetary penalty. The worst path is discovering an issue, fixing it quietly, and having it surface later through an audit, a whistleblower, or a prime's investigation, at which point the lack of disclosure itself aggravates the outcome.

Run through the checklist with your team, then send yourself the results to anchor your ITAR remediation plan.