Published 2026 | TIKC NewsWire
Export controls are one of the most underestimated risks in government contracting, because the word export misleads people. You do not have to ship anything overseas to commit a violation. Simply giving a foreign person access to controlled technical data, even on U.S. soil, even in an email or a shared drive, can be a regulated export. For contractors that touch defense articles, military technology, or sensitive technical data, two regimes govern the rules: ITAR and EAR. Getting them wrong can end in civil penalties, criminal charges, and loss of the right to export at all.
ITAR and EAR, in plain terms
The International Traffic in Arms Regulations (ITAR), administered by the State Department, control defense articles, defense services, and related technical data on the U.S. Munitions List. If your work involves military items or the technical data to build or maintain them, assume ITAR may apply. The Export Administration Regulations (EAR), administered by the Commerce Department, control dual-use items, things with both commercial and military applications, on the Commerce Control List. Many commercial technologies fall under EAR. Between them, these two regimes cover a huge swath of the technology a defense-adjacent contractor handles.
The deemed export trap
This is the concept that catches small businesses off guard. A deemed export occurs when controlled technical data or technology is released to a foreign person inside the United States. In other words, letting a foreign national employee, a visitor, or an overseas contractor access controlled drawings, specifications, or source code can count as an export to that person’s home country, requiring authorization you may not have. Your hiring, your IT access controls, and even who sits in on a technical meeting become export-control questions.
The penalties are severe, and personal
Export-control enforcement is aggressive and the penalties are among the harshest a contractor can face. Violations can bring large civil penalties per violation, criminal fines and imprisonment for willful violations, and the loss of export privileges, which for many firms is a business-ending outcome. Individuals, not just companies, are prosecuted. And because ITAR and EAR intersect with the False Claims Act and contract certifications, a compliance failure can multiply into several enforcement tracks at once.
Registration, licensing, and knowing your data
Compliance starts with knowing what you have. Firms that manufacture or export defense articles generally must register with the State Department, and specific transactions often require licenses. The foundational step is classifying your products and technical data: determining whether an item is ITAR-controlled, EAR-controlled, or not controlled, and documenting that determination. You cannot protect data you have not identified, so classification is the work that makes everything else possible.
What to do now
- Classify your technology and data. Determine ITAR, EAR, or not-controlled status for your products and technical data, and document it.
- Control access. Restrict controlled technical data so foreign persons cannot access it without authorization, including on shared drives and email.
- Screen your people and partners. Treat foreign-person access as an export question in hiring, visits, and subcontracting.
- Register and license where required. Confirm whether you must register with State and whether your transactions need licenses.
- Train and document. Build an export-compliance program and keep records that prove your determinations and controls.
Export controls reward companies that know exactly what they hold and who can touch it. Classify your data, lock down access, and the rules become a routine, not a risk. Brick by brick.
FAQ
What is the difference between ITAR and EAR?
ITAR, administered by the State Department, controls defense articles and related technical data on the U.S. Munitions List. EAR, administered by the Commerce Department, controls dual-use items on the Commerce Control List.
What is a deemed export?
Releasing controlled technical data or technology to a foreign person inside the United States, which can count as an export to that person’s home country and may require authorization.
What are the penalties for violations?
Large civil penalties per violation, criminal fines and imprisonment for willful violations, and loss of export privileges, with individuals as well as companies subject to prosecution.
How do I start complying?
Classify your products and technical data as ITAR, EAR, or not controlled, control access so foreign persons cannot see controlled data without authorization, register and license where required, and train your team.
Sources
U.S. Department of State, Directorate of Defense Trade Controls. (2026). International Traffic in Arms Regulations (ITAR).
U.S. Department of Commerce, Bureau of Industry and Security. (2026). Export Administration Regulations (EAR).
This article is general information, not legal advice.
About the Author
Melanie Patterson
Founder and CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale, brick by brick. Contact


