ITAR Compliance Southern California | WCC Technologies
ITAR Compliance · Cybersecurity · Southern California

ITAR Compliance
for SoCal's defense industrial base.

ITAR compliance services for Southern California aerospace and defense contractors — Technology Control Plan authorship, DDTC registration support, GCC High tenancy, FIPS-validated encryption, foreign person access controls, recordkeeping systems, and ongoing program maintenance. WCC has been supporting SoCal's defense supplier base since 2003.

What ITAR is

ITAR — the export control regime for defense articles and technical data

ITAR (International Traffic in Arms Regulations) is the US export control framework administered by the State Department's Directorate of Defense Trade Controls (DDTC). It governs the export, re-export, and brokering of defense articles, defense services, and technical data on the United States Munitions List (USML) — a 21-category list ranging from firearms to spacecraft to military electronics to gas turbine engines. The penalties for violations run up to $1 million per civil violation, $1 million plus 20 years imprisonment per criminal violation, and debarment from federal contracts.

For SoCal's defense industrial base — aerospace primes and tiered suppliers in Long Beach, Huntington Beach, Hawthorne, El Segundo, Redondo Beach, Palmdale, and San Diego — ITAR compliance is rarely optional. Drawings, technical data packages, source code, test data, and program-specific information typically meet ITAR definitions, triggering export-control obligations the moment a foreign national has potential access to the systems where that data lives. The question isn't whether ITAR applies but how the company's Technology Control Plan, IT controls, and personnel screening actually work together to enforce it.

This page covers WCC's ITAR compliance services. For the parallel cybersecurity framework (most ITAR technical data is also CUI), see NIST 800-171 compliance and CMMC compliance. For executive program ownership, see vCISO services. Start with a free IT consultation.

Framework comparison

Where ITAR fits among defense compliance frameworks

ITAR is the export control framework. NIST 800-171 and CMMC are cybersecurity frameworks protecting Controlled Unclassified Information. They overlap because most ITAR technical data is also CUI, but they answer different questions and trigger from different authorities.

Export Control · Commerce Dept

EAR

Dual-use items · CCL · BIS enforced
  • Administered by Commerce Department / BIS
  • Covers dual-use items on the Commerce Control List
  • Items can have civilian + military application
  • More license exceptions available than ITAR
  • Some items moved ITAR → EAR via Export Control Reform
  • Required for any company exporting dual-use technology
Cybersecurity · DoD

NIST 800-171 / CMMC

CUI protection · DFARS-required
  • Administered by DoD via DFARS 252.204-7012 / 7021
  • Protects Controlled Unclassified Information (CUI)
  • 110 controls across 14 control families
  • Most ITAR technical data is also CUI
  • See NIST 800-171 + CMMC pages for details
  • Runs in parallel with ITAR, not as a substitute
The integrator advantage

How WCC delivers ITAR programs end-to-end

Four layers underneath every WCC ITAR engagement. Most compliance consultants own the documentation and hand the technical work to someone else. WCC owns the Technology Control Plan AND the GCC High deployment AND the foreign person access controls AND the ongoing operations — one accountable team.

1
1 — Your organization
SoCal Defense Contractor or Aerospace Supplier
Primes, tiered suppliers, machine shops, engineering services, defense electronics, and universities with ITAR-controlled research handling technical data on the USML.
AerospaceDefense ElectronicsEngineering ServicesMachine ShopsSpace & SatelliteDIB Research
2
2 — What WCC manages
WCC ITAR Program
The strategic compliance ownership — jurisdiction analysis, DDTC registration support, Technology Control Plan authorship, foreign person access tracking, recordkeeping, voluntary disclosure procedures, and DDTC coordination.
Jurisdiction AnalysisDDTC RegistrationTCP AuthorshipPersonnel ScreeningRecordkeepingVol. Disclosure
3
3 — The control framework
USML Categories & Technology Control
The actual ITAR scope — 21 USML categories, deemed export rules, license requirements, and the technical data controls that keep defense articles within authorized hands.
21 USML CategoriesDeemed ExportLicense MgmtForeign Person Tracking5-Year Records
4
4 — What WCC operates
ITAR-Aligned IT Operations
The operational stack that proves controls actually work — US-person-only cloud tenancy, FIPS-validated encryption, network segmentation, MFA, audit logging, and identity systems that enforce deemed-export tracking.
M365 GCC HighAzure GovernmentFIPS EncryptionMFA EnforcementNetwork SegmentationAudit Logging
Why it matters: ITAR programs fail at the technical implementation layer, not the documentation layer. The Technology Control Plan can look perfect on paper while the actual M365 tenancy is commercial, the file share has foreign nationals as contributors, and the network has no segmentation between ITAR and non-ITAR systems. WCC owns the documentation AND the GCC High deployment AND the ongoing operations. The compliance program manager writes the TCP, drives the framework, and walks downstairs to the team that stood up GCC High, configured the FIPS encryption, and built the deemed-export tracking. One accountable team when DDTC asks for evidence.
Why WCC for ITAR

Why choose WCC for ITAR compliance in Southern California

ITAR programs are multi-year executive engagements with criminal penalty exposure. The right partner has SoCal defense industry context, deep technical implementation experience, and the GCC High and FIPS-validated infrastructure depth to actually run the program.

2003

Founded in SoCal

22+ years operating across SoCal's defense industrial base footprint — LA County aerospace corridor, Inland Empire suppliers, San Diego defense electronics.

DIB Depth

Defense supply chain experience

Aerospace, defense electronics, machine shops, engineering services, and DoD IT vendors — the exact verticals where ITAR controls flow down through contracts.

#819788

CSLB Licensed

California Contractors State License Board #819788. C-7, C-10, and C-28 classifications. Real California regulatory accountability across the practice.

GCC High

US-only cloud expertise

Microsoft GCC High tenant deployments, Azure Government, and FIPS-validated encryption across the SoCal defense supplier base. Not a paper qualification — production deployments.

What WCC ITAR services include

End-to-end ITAR program management

Every WCC ITAR engagement is scoped to current jurisdiction status, registration history, technology stack, and DDTC interaction history. These are the six core capability areas every engagement covers.

Assess

Jurisdiction Analysis & Gap Assessment

Item-by-item analysis against the USML and CCL to determine what's ITAR-controlled, EAR-controlled, or uncontrolled. Personnel access analysis. IT systems inventory. Gap assessment against current program state.

USML Analysis · CCL Analysis · Gap Report
Register

DDTC Registration Support

Annual DDTC registration support including documentation preparation, fee handling, and renewal management. Coordination with legal counsel on jurisdictional questions. Maintenance of registration status throughout the engagement.

DS-2032 · Annual Renewal · Status Tracking
Document

Technology Control Plan

Authorship of the TCP covering personnel screening, IT systems, physical controls, training requirements, recordkeeping procedures, and incident response. The central document a DDTC compliance review will examine in detail.

TCP · Procedures · Training Materials
Implement

IT Controls Implementation

Hands-on deployment of Microsoft 365 GCC High tenancy, Azure Government infrastructure, FIPS 140-validated encryption, network segmentation isolating ITAR systems, MFA enforcement, and audit logging that satisfies DDTC review.

GCC High · FIPS Encryption · Segmentation
Track

Foreign Person Access Controls

Identity systems configured to track personnel citizenship status. Access controls that gate ITAR data systems based on US-person verification. Visitor management, escort policies, and screen-locking enforcement for any environment where foreign persons may transit.

Identity · Deemed Export Track · Visitor Mgmt
Maintain

Ongoing Program Maintenance

Annual training. Recordkeeping system operation. Personnel screening on hires and role changes. Voluntary disclosure procedures when issues arise. Coordination with vCISO services for designated compliance leadership.

Training · Records · Vol. Disclosure
The 21 USML categories

What the United States Munitions List actually covers

The USML defines 21 categories of defense articles, technical data, and defense services subject to ITAR. SoCal's defense industrial base typically encounters Categories VIII (Aircraft), XI (Military Electronics), XII (Fire Control/Laser/Imaging), XV (Spacecraft), and XIX (Gas Turbines) most often, but every category has SoCal suppliers.

I

Firearms & Combat Shotguns

Firearms, close-assault weapons, and combat shotguns.

II

Guns & Armament

Crew-served and large-caliber armament systems.

III

Ammunition / Ordnance

Ammunition, ordnance, and components for the above.

IV

Launch Vehicles & Missiles

Launch vehicles, guided missiles, ballistic missiles, rockets, torpedoes, bombs, and mines.

V

Explosives & Propellants

Explosives, energetic materials, propellants, incendiary agents.

VI

Naval Vessels of War

Surface vessels of war and special naval equipment.

VII

Ground Vehicles

Military ground vehicles and related articles.

VIII

Aircraft & Related Articles

Military aircraft, UAS, and related articles. Major SoCal category.

IX

Military Training Equipment

Military training equipment and training services.

X

Personal Protective Equipment

Military body armor, helmets, and PPE.

XI

Military Electronics

Military electronics, signal processing, EW. Major SoCal category.

XII

Fire Control & Laser/Imaging

Fire control, laser, imaging, guidance, and night vision. Major SoCal category.

XIII

Materials & Misc Articles

Materials and miscellaneous articles not elsewhere enumerated.

XIV

Toxicological Agents

Chemical agents, biological agents, and associated equipment.

XV

Spacecraft & Related Articles

Spacecraft and related articles. Major SoCal category.

XVI

Nuclear Weapons Articles

Nuclear weapons-related articles.

XVII

Classified Articles

Classified articles, technical data, and defense services not otherwise enumerated.

XVIII

Directed Energy Weapons

Directed energy weapons and related articles.

XIX

Gas Turbine Engines

Military gas turbine engines. Major SoCal category.

XX

Submersible Vessels

Military submersibles and related articles.

XXI

Other Defense Articles

Articles, technical data, and defense services not otherwise enumerated, designated by DDTC.

Who needs ITAR

ITAR across SoCal's defense industrial base

ITAR applies broadly across the defense supply chain. These are the six verticals where WCC has deepest ITAR experience — the SoCal businesses where DDTC registration and Technology Control Plans are baseline requirements.

Aerospace Primes & Tier 1 Suppliers

Aerospace primes and Tier 1 suppliers across the SoCal corridor — Long Beach, Huntington Beach, Hawthorne, El Segundo, Redondo Beach, Palmdale. Drawings, technical data packages, and program-specific information almost always meet ITAR definitions.

Defense Electronics & RF

RF systems, sensors, EW components, signal processors, and embedded systems serving DoD primes. Most Category XI work is ITAR-controlled and often paired with NIST 800-171 obligations on the same data sets.

Space & Satellite

SoCal's growing space sector — commercial and national security space, satellite components, launch systems, and ground stations. Category XV spacecraft and related articles trigger ITAR with very few exceptions.

Precision Machining & Manufacturing

Machine shops and precision manufacturers feeding aerospace and defense primes. Often the lowest tier where ITAR controls flow down with full registration and Technology Control Plan obligations. See manufacturing managed IT.

Engineering Services

Mechanical, electrical, software, and systems engineering firms providing services to defense primes. Technical data is inherently ITAR-controlled when the underlying article is on the USML, making full programs the default scope.

Universities & Research

SoCal research universities with ITAR-controlled DoD research — USC, UCLA, Caltech, UCSD, UCI. Research security offices coordinate institution-wide programs, often paired with NSPM-33 research security compliance and CUI handling requirements.

2003
Founded in SoCal — 22+ years operating
21
USML categories covered across the practice
GCC High
US-only cloud production deployments
#819788
CSLB Licensed — C-7 · C-10 · C-28
FAQs

ITAR frequently asked questions

ITAR (International Traffic in Arms Regulations) is the US export control regime administered by the State Department's Directorate of Defense Trade Controls (DDTC). It governs the export, re-export, and brokering of defense articles, defense services, and technical data on the United States Munitions List (USML). Any US person or company that manufactures, designs, develops, exports, or provides defense services for items on the USML must comply — including primes, tiered suppliers, machine shops, engineering services firms, universities with ITAR-controlled research, and the IT and cybersecurity vendors supporting them. The annual DDTC registration is the entry point; the technical and IT controls follow.

ITAR (State Department) covers defense articles on the USML — items specifically designed or modified for military application. EAR (Export Administration Regulations, administered by the Commerce Department's Bureau of Industry and Security) covers dual-use items on the Commerce Control List (CCL) — items with both civilian and military applications. ITAR is generally stricter: most ITAR-controlled technical data cannot be released to foreign persons without an export license, even inside the US (deemed export). EAR allows more license exceptions. Some items moved from USML to CCL through Export Control Reform — classification of a specific item matters more than the general framework.

ITAR is the export control framework — what you can do with defense articles and technical data. CMMC and NIST 800-171 are the cybersecurity frameworks — how you must protect Controlled Unclassified Information including ITAR-controlled technical data. Most ITAR technical data is also CUI, so ITAR-regulated businesses typically need both frameworks operating together. WCC's compliance practice runs them as an integrated program — Technology Control Plan, SSP, POA&M, GCC High tenancy, FIPS encryption, and foreign person access controls all coordinated rather than siloed.

A Technology Control Plan documents how the company will protect ITAR-controlled technical data from unauthorized access — particularly by foreign persons. It identifies the controlled data, the physical and IT systems where it lives, the personnel authorized to access it, the procedures for granting and revoking access, the screening processes, training requirements, recordkeeping, and incident response. Most TCPs cover IT controls (network segmentation, access control, encryption, logging), physical controls (badge access, visitor controls, escort policies), and administrative controls (training, agreements, screening). The TCP is the central document a DDTC compliance review or audit will examine.

A deemed export is the release of ITAR-controlled technical data to a foreign person inside the United States — through email, file share, conversation, demonstration, or even visual access to a screen. Under ITAR, this is treated as an export to the foreign person's country of nationality and typically requires a license. Most US companies discover deemed export issues when foreign national employees, contractors, or interns access systems containing ITAR technical data. Proper controls require knowing which employees are foreign persons, controlling their access to ITAR data systems, and documenting authorization. The IT systems need to enforce this — not rely on employee discretion.

ITAR doesn't prescribe specific IT controls the way NIST 800-171 does, but DDTC enforcement actions and industry practice make several controls essentially mandatory: US-person-only cloud tenancy (Microsoft GCC High, AWS GovCloud, or Google Workspace for Government) for systems handling ITAR technical data; FIPS 140-2/3 validated encryption for data at rest and in transit; strong identity and access control with MFA; network segmentation isolating ITAR systems; comprehensive audit logging; deemed-export tracking in identity systems; and 5-year recordkeeping. Email handling of ITAR data requires either licensed encryption or a separate ITAR-only mail path.

Civil penalties run up to $1 million per violation. Criminal penalties run up to 20 years imprisonment and $1 million criminal fine per violation. Beyond direct penalties, companies face debarment from federal contracts, suspension of export privileges, and the substantial cost of consent agreements (DDTC consent agreements have run $20-$80 million for major violators). Voluntary disclosure of violations to DDTC typically results in substantially reduced penalties — most experienced ITAR programs include a voluntary disclosure policy.

ITAR compliance preparation runs through five phases. Phase 1: jurisdiction analysis (what items are ITAR-controlled, what's EAR, what's uncontrolled). Phase 2: DDTC registration (annual, required before any ITAR activity). Phase 3: Technology Control Plan authorship covering personnel, IT systems, physical controls, training, and recordkeeping. Phase 4: IT implementation — GCC High tenancy, FIPS encryption, MFA, segmentation, and the deemed-export tracking in identity systems. Phase 5: ongoing operations — training, screening, recordkeeping, audit, and voluntary disclosure procedures. Implementation typically runs 4 to 12 months depending on starting maturity.

SoCal Coverage

ITAR services across Southern California

WCC delivers ITAR work across all six SoCal counties — with deepest experience in the LA County aerospace corridor and Inland Empire defense supplier base. Headquartered in Chino.

Ready to talk ITAR?

ITAR programs start with honest jurisdiction analysis.

Tell us about your contract base, your current registration status, your IT environment, and what's driving the conversation — a new program win, a DDTC question, a foreign person hire, or simply the realization that your TCP doesn't match what your systems actually do. WCC will scope the assessment, registration support, TCP authorship, IT implementation, and ongoing operations — all under one engagement plan.

Scroll to Top