ITAR Compliance
for SoCal's defense industrial base.
ITAR compliance services for Southern California aerospace and defense contractors — Technology Control Plan authorship, DDTC registration support, GCC High tenancy, FIPS-validated encryption, foreign person access controls, recordkeeping systems, and ongoing program maintenance. WCC has been supporting SoCal's defense supplier base since 2003.
ITAR — the export control regime for defense articles and technical data
ITAR (International Traffic in Arms Regulations) is the US export control framework administered by the State Department's Directorate of Defense Trade Controls (DDTC). It governs the export, re-export, and brokering of defense articles, defense services, and technical data on the United States Munitions List (USML) — a 21-category list ranging from firearms to spacecraft to military electronics to gas turbine engines. The penalties for violations run up to $1 million per civil violation, $1 million plus 20 years imprisonment per criminal violation, and debarment from federal contracts.
For SoCal's defense industrial base — aerospace primes and tiered suppliers in Long Beach, Huntington Beach, Hawthorne, El Segundo, Redondo Beach, Palmdale, and San Diego — ITAR compliance is rarely optional. Drawings, technical data packages, source code, test data, and program-specific information typically meet ITAR definitions, triggering export-control obligations the moment a foreign national has potential access to the systems where that data lives. The question isn't whether ITAR applies but how the company's Technology Control Plan, IT controls, and personnel screening actually work together to enforce it.
This page covers WCC's ITAR compliance services. For the parallel cybersecurity framework (most ITAR technical data is also CUI), see NIST 800-171 compliance and CMMC compliance. For executive program ownership, see vCISO services. Start with a free IT consultation.
Where ITAR fits among defense compliance frameworks
ITAR is the export control framework. NIST 800-171 and CMMC are cybersecurity frameworks protecting Controlled Unclassified Information. They overlap because most ITAR technical data is also CUI, but they answer different questions and trigger from different authorities.
ITAR
- Administered by State Department / DDTC
- Covers items on the US Munitions List (21 categories)
- Requires annual DDTC registration
- Restricts release to foreign persons (deemed export)
- Technology Control Plan is central document
- Penalties: $1M civil, $1M+ criminal, debarment
EAR
- Administered by Commerce Department / BIS
- Covers dual-use items on the Commerce Control List
- Items can have civilian + military application
- More license exceptions available than ITAR
- Some items moved ITAR → EAR via Export Control Reform
- Required for any company exporting dual-use technology
NIST 800-171 / CMMC
- Administered by DoD via DFARS 252.204-7012 / 7021
- Protects Controlled Unclassified Information (CUI)
- 110 controls across 14 control families
- Most ITAR technical data is also CUI
- See NIST 800-171 + CMMC pages for details
- Runs in parallel with ITAR, not as a substitute
How WCC delivers ITAR programs end-to-end
Four layers underneath every WCC ITAR engagement. Most compliance consultants own the documentation and hand the technical work to someone else. WCC owns the Technology Control Plan AND the GCC High deployment AND the foreign person access controls AND the ongoing operations — one accountable team.
Why choose WCC for ITAR compliance in Southern California
ITAR programs are multi-year executive engagements with criminal penalty exposure. The right partner has SoCal defense industry context, deep technical implementation experience, and the GCC High and FIPS-validated infrastructure depth to actually run the program.
Founded in SoCal
22+ years operating across SoCal's defense industrial base footprint — LA County aerospace corridor, Inland Empire suppliers, San Diego defense electronics.
Defense supply chain experience
Aerospace, defense electronics, machine shops, engineering services, and DoD IT vendors — the exact verticals where ITAR controls flow down through contracts.
CSLB Licensed
California Contractors State License Board #819788. C-7, C-10, and C-28 classifications. Real California regulatory accountability across the practice.
US-only cloud expertise
Microsoft GCC High tenant deployments, Azure Government, and FIPS-validated encryption across the SoCal defense supplier base. Not a paper qualification — production deployments.
End-to-end ITAR program management
Every WCC ITAR engagement is scoped to current jurisdiction status, registration history, technology stack, and DDTC interaction history. These are the six core capability areas every engagement covers.
Jurisdiction Analysis & Gap Assessment
Item-by-item analysis against the USML and CCL to determine what's ITAR-controlled, EAR-controlled, or uncontrolled. Personnel access analysis. IT systems inventory. Gap assessment against current program state.
DDTC Registration Support
Annual DDTC registration support including documentation preparation, fee handling, and renewal management. Coordination with legal counsel on jurisdictional questions. Maintenance of registration status throughout the engagement.
Technology Control Plan
Authorship of the TCP covering personnel screening, IT systems, physical controls, training requirements, recordkeeping procedures, and incident response. The central document a DDTC compliance review will examine in detail.
IT Controls Implementation
Hands-on deployment of Microsoft 365 GCC High tenancy, Azure Government infrastructure, FIPS 140-validated encryption, network segmentation isolating ITAR systems, MFA enforcement, and audit logging that satisfies DDTC review.
Foreign Person Access Controls
Identity systems configured to track personnel citizenship status. Access controls that gate ITAR data systems based on US-person verification. Visitor management, escort policies, and screen-locking enforcement for any environment where foreign persons may transit.
Ongoing Program Maintenance
Annual training. Recordkeeping system operation. Personnel screening on hires and role changes. Voluntary disclosure procedures when issues arise. Coordination with vCISO services for designated compliance leadership.
What the United States Munitions List actually covers
The USML defines 21 categories of defense articles, technical data, and defense services subject to ITAR. SoCal's defense industrial base typically encounters Categories VIII (Aircraft), XI (Military Electronics), XII (Fire Control/Laser/Imaging), XV (Spacecraft), and XIX (Gas Turbines) most often, but every category has SoCal suppliers.
Firearms & Combat Shotguns
Firearms, close-assault weapons, and combat shotguns.
Guns & Armament
Crew-served and large-caliber armament systems.
Ammunition / Ordnance
Ammunition, ordnance, and components for the above.
Launch Vehicles & Missiles
Launch vehicles, guided missiles, ballistic missiles, rockets, torpedoes, bombs, and mines.
Explosives & Propellants
Explosives, energetic materials, propellants, incendiary agents.
Naval Vessels of War
Surface vessels of war and special naval equipment.
Ground Vehicles
Military ground vehicles and related articles.
Aircraft & Related Articles
Military aircraft, UAS, and related articles. Major SoCal category.
Military Training Equipment
Military training equipment and training services.
Personal Protective Equipment
Military body armor, helmets, and PPE.
Military Electronics
Military electronics, signal processing, EW. Major SoCal category.
Fire Control & Laser/Imaging
Fire control, laser, imaging, guidance, and night vision. Major SoCal category.
Materials & Misc Articles
Materials and miscellaneous articles not elsewhere enumerated.
Toxicological Agents
Chemical agents, biological agents, and associated equipment.
Spacecraft & Related Articles
Spacecraft and related articles. Major SoCal category.
Nuclear Weapons Articles
Nuclear weapons-related articles.
Classified Articles
Classified articles, technical data, and defense services not otherwise enumerated.
Directed Energy Weapons
Directed energy weapons and related articles.
Gas Turbine Engines
Military gas turbine engines. Major SoCal category.
Submersible Vessels
Military submersibles and related articles.
Other Defense Articles
Articles, technical data, and defense services not otherwise enumerated, designated by DDTC.
ITAR across SoCal's defense industrial base
ITAR applies broadly across the defense supply chain. These are the six verticals where WCC has deepest ITAR experience — the SoCal businesses where DDTC registration and Technology Control Plans are baseline requirements.
Aerospace Primes & Tier 1 Suppliers
Aerospace primes and Tier 1 suppliers across the SoCal corridor — Long Beach, Huntington Beach, Hawthorne, El Segundo, Redondo Beach, Palmdale. Drawings, technical data packages, and program-specific information almost always meet ITAR definitions.
Defense Electronics & RF
RF systems, sensors, EW components, signal processors, and embedded systems serving DoD primes. Most Category XI work is ITAR-controlled and often paired with NIST 800-171 obligations on the same data sets.
Space & Satellite
SoCal's growing space sector — commercial and national security space, satellite components, launch systems, and ground stations. Category XV spacecraft and related articles trigger ITAR with very few exceptions.
Precision Machining & Manufacturing
Machine shops and precision manufacturers feeding aerospace and defense primes. Often the lowest tier where ITAR controls flow down with full registration and Technology Control Plan obligations. See manufacturing managed IT.
Engineering Services
Mechanical, electrical, software, and systems engineering firms providing services to defense primes. Technical data is inherently ITAR-controlled when the underlying article is on the USML, making full programs the default scope.
Universities & Research
SoCal research universities with ITAR-controlled DoD research — USC, UCLA, Caltech, UCSD, UCI. Research security offices coordinate institution-wide programs, often paired with NSPM-33 research security compliance and CUI handling requirements.
ITAR frequently asked questions
ITAR (International Traffic in Arms Regulations) is the US export control regime administered by the State Department's Directorate of Defense Trade Controls (DDTC). It governs the export, re-export, and brokering of defense articles, defense services, and technical data on the United States Munitions List (USML). Any US person or company that manufactures, designs, develops, exports, or provides defense services for items on the USML must comply — including primes, tiered suppliers, machine shops, engineering services firms, universities with ITAR-controlled research, and the IT and cybersecurity vendors supporting them. The annual DDTC registration is the entry point; the technical and IT controls follow.
ITAR (State Department) covers defense articles on the USML — items specifically designed or modified for military application. EAR (Export Administration Regulations, administered by the Commerce Department's Bureau of Industry and Security) covers dual-use items on the Commerce Control List (CCL) — items with both civilian and military applications. ITAR is generally stricter: most ITAR-controlled technical data cannot be released to foreign persons without an export license, even inside the US (deemed export). EAR allows more license exceptions. Some items moved from USML to CCL through Export Control Reform — classification of a specific item matters more than the general framework.
ITAR is the export control framework — what you can do with defense articles and technical data. CMMC and NIST 800-171 are the cybersecurity frameworks — how you must protect Controlled Unclassified Information including ITAR-controlled technical data. Most ITAR technical data is also CUI, so ITAR-regulated businesses typically need both frameworks operating together. WCC's compliance practice runs them as an integrated program — Technology Control Plan, SSP, POA&M, GCC High tenancy, FIPS encryption, and foreign person access controls all coordinated rather than siloed.
A Technology Control Plan documents how the company will protect ITAR-controlled technical data from unauthorized access — particularly by foreign persons. It identifies the controlled data, the physical and IT systems where it lives, the personnel authorized to access it, the procedures for granting and revoking access, the screening processes, training requirements, recordkeeping, and incident response. Most TCPs cover IT controls (network segmentation, access control, encryption, logging), physical controls (badge access, visitor controls, escort policies), and administrative controls (training, agreements, screening). The TCP is the central document a DDTC compliance review or audit will examine.
A deemed export is the release of ITAR-controlled technical data to a foreign person inside the United States — through email, file share, conversation, demonstration, or even visual access to a screen. Under ITAR, this is treated as an export to the foreign person's country of nationality and typically requires a license. Most US companies discover deemed export issues when foreign national employees, contractors, or interns access systems containing ITAR technical data. Proper controls require knowing which employees are foreign persons, controlling their access to ITAR data systems, and documenting authorization. The IT systems need to enforce this — not rely on employee discretion.
ITAR doesn't prescribe specific IT controls the way NIST 800-171 does, but DDTC enforcement actions and industry practice make several controls essentially mandatory: US-person-only cloud tenancy (Microsoft GCC High, AWS GovCloud, or Google Workspace for Government) for systems handling ITAR technical data; FIPS 140-2/3 validated encryption for data at rest and in transit; strong identity and access control with MFA; network segmentation isolating ITAR systems; comprehensive audit logging; deemed-export tracking in identity systems; and 5-year recordkeeping. Email handling of ITAR data requires either licensed encryption or a separate ITAR-only mail path.
Civil penalties run up to $1 million per violation. Criminal penalties run up to 20 years imprisonment and $1 million criminal fine per violation. Beyond direct penalties, companies face debarment from federal contracts, suspension of export privileges, and the substantial cost of consent agreements (DDTC consent agreements have run $20-$80 million for major violators). Voluntary disclosure of violations to DDTC typically results in substantially reduced penalties — most experienced ITAR programs include a voluntary disclosure policy.
ITAR compliance preparation runs through five phases. Phase 1: jurisdiction analysis (what items are ITAR-controlled, what's EAR, what's uncontrolled). Phase 2: DDTC registration (annual, required before any ITAR activity). Phase 3: Technology Control Plan authorship covering personnel, IT systems, physical controls, training, and recordkeeping. Phase 4: IT implementation — GCC High tenancy, FIPS encryption, MFA, segmentation, and the deemed-export tracking in identity systems. Phase 5: ongoing operations — training, screening, recordkeeping, audit, and voluntary disclosure procedures. Implementation typically runs 4 to 12 months depending on starting maturity.
ITAR work pairs with these WCC capabilities
ITAR programs touch identity, cloud, cybersecurity, and ongoing operations. The services below commonly bundle with ITAR engagements for SoCal defense contractors.
CMMC Compliance
The DoD cybersecurity certification — runs in parallel with ITAR. Most ITAR data is also CUI requiring CMMC controls.
NIST 800-171 Compliance
The cybersecurity framework underlying CMMC — the IT controls that protect ITAR technical data as CUI.
vCISO Services
Executive ownership of the ITAR program, board reporting, and coordination with legal counsel on jurisdictional questions.
Microsoft 365 GCC High
The US-person-only cloud tenancy required for ITAR technical data handling — migration and ongoing operations.
MFA Management
The identity and access control layer enforcing US-person-only access to ITAR systems.
Secure Email Encryption
FIPS-validated email encryption for ITAR technical data — either licensed encryption or ITAR-only mail path.
Cybersecurity Hub
The full cybersecurity portfolio — assessments, operations, compliance, and incident response.
Free IT Consultation
The fastest way to scope an ITAR program — a 60-90 minute conversation with a senior WCC engineer.
ITAR services across Southern California
WCC delivers ITAR work across all six SoCal counties — with deepest experience in the LA County aerospace corridor and Inland Empire defense supplier base. Headquartered in Chino.
ITAR programs start with honest jurisdiction analysis.
Tell us about your contract base, your current registration status, your IT environment, and what's driving the conversation — a new program win, a DDTC question, a foreign person hire, or simply the realization that your TCP doesn't match what your systems actually do. WCC will scope the assessment, registration support, TCP authorship, IT implementation, and ongoing operations — all under one engagement plan.
