Aerospace
The aerospace industry is one of the most dynamic sectors in international trade, encompassing everything from commercial aviation and defense systems to space exploration and advanced technology solutions. Global demand for aerospace goods and services drives significant economic growth, fostering cross-border partnerships, enhancing trade networks, and spurring innovation across multiple industries. From manufacturing commercial aircraft to launching satellites and developing defense systems, companies in aerospace must navigate a complex landscape of export controls, trade agreements, and national security policies.
Aerospace products and technology often fall under strict export control regimes. In the U.S., the International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) regulate exports, ensuring that sensitive technologies do not end up in the hands of adversaries. These controls cover a wide array of aerospace products, including aircraft components, satellite technology, and missile systems. Compliance with the ITAR and the EAR is essential. Additionally, the aerospace industry is affected by the economic sanctions regime administered by the Department of the Treasury Office of Foreign Assets Control (OFAC) in its quest to achieve U.S. foreign policy and national security goals across the globe. Companies must maintain robust internal compliance programs and stay up to date on regulatory changes to successfully operate across borders.
Given its ties to defense and critical infrastructure, aerospace is closely monitored for national security concerns. Governments prioritize safeguarding aerospace technology to maintain strategic advantages. Foreign investment in aerospace often triggers reviews by U.S. federal interagency bodies such as the Committee on Foreign Investment in the United States (CFIUS), which can block or impose mitigation requirements on deals that pose unacceptable risks to national security.
Representative Experience
The Torres Trade Law team is deeply familiar with the aerospace industry and has assisted several aerospace companies navigate the international trade and national security law landscape, including the following representative experience:
- Preparing and implementing export control and sanctions compliance programs for multiple aerospace companies, including publicly traded multinational companies.
- Investigating violations and submitting voluntary disclosures to the Department of State Directorate of Defense Trade Controls (DDTC) and the Department of Commerce Bureau of Industry and Security (BIS) on behalf of numerous aerospace companies.
- Successfully submitting protests to U.S. Customs and Border Protection (CBP) to obtain duty-free treatment for civil aviation parts.
- Classifying hundreds of aerospace parts pursuant to the ITAR and EAR to determine export control authorization requirements.
- Successfully obtaining export control licenses and ITAR license agreements for numerous aerospace clients.
- Conducting due diligence on transaction parties to determine implications of economic sanctions and export control regulations on aerospace imports and exports.
- Advising on the application of Foreign Ownership, Control, or Influence (FOCI) regulations administered by the Defense Counterintelligence and Security Agency.
Aerospace Trade & Export Law FAQs
1. What U.S. trade and national security laws most commonly affect aerospace companies?
Aerospace companies are subject to four primary export control and national security regimes: ITAR, EAR, OFAC economic sanctions, and CFIUS review. The International Traffic in Arms Regulations (ITAR) regulate the export of defense articles, technical data, and defense services on the U.S. Munitions List (USML), including many spacecraft, missile, and military aviation systems. The Export Administration Regulations (EAR) regulate the export of “dual-use” aerospace technologies on the Commerce Control List (CCL), such as avionics, sensors, materials, and commercial aircraft components. The Office of Foreign Assets Control (OFAC) administers U.S. economic sanctions programs, restricting transactions with embargoed jurisdictions, specially-designated nationals, and certain foreign aerospace and defense entities. Additionally, foreign investment in U.S. aerospace firms may subject the transaction to the jurisdiction of the Committee on Foreign Investment in the United States (CFIUS) for a national security review and can trigger CFIUS mandatory filing requirements when the target business involves “critical technologies” controlled under ITAR or EAR. Companies should evaluate classification, licensing, sanctions screening, and investment security together, as a single aerospace program may be subject to all four regulatory frameworks.
2. What types of aerospace items are controlled under the ITAR?
The ITAR regulates defense articles and technical data listed on the U.S. Munitions List (USML). Common aerospace-related USML categories include:
-
Category VIII — Military aircraft, engines, avionics, and related systems
-
Category IV — Missiles, rockets, launch vehicles, and related components
-
Category XV — Spacecraft, satellites, and related technical data
-
Category XII — Military sensors and night vision systems
The ITAR also regulates exports of technical data such as engineering drawings, CAD files, manufacturing tolerances, and software related to USML items. Sharing this data with a foreign national employee even within the U.S. may be considered an export.
3. How do I determine whether an aerospace item is controlled under the ITAR or the EAR?
Items on the USML, such as military aircraft systems, missile and rocket components, classified spacecraft hardware, targeting and guidance systems, and technical data related to their design or operation, are generally subject to the ITAR. In contrast, most dual-use or commercial aerospace items are regulated under the EAR and are enumerated on the CCL. Importantly, a single aerospace platform can include a combination of ITAR-controlled components (such as military-grade sensors or propulsion elements), EAR-controlled parts (such as commercial avionics, materials, and electronics), and related software and technical data. Careful classification analysis must be conducted to determine whether the ITAR or EAR governs an export of an aerospace item.
4. Can sharing aerospace technical data/technology with a foreign national in the United States count as an export?
Yes. Under the EAR, releasing controlled technology or source code to a foreign person in the United States may constitute a “deemed export.” Under the ITAR, the release of ITAR-controlled technical data to a foreign national in the United States may also constitute an export, even if such data does not physically leave the U.S.
5. What should an aerospace company do if it discovers a potential ITAR or EAR violation?
If an aerospace company identifies a potential ITAR or EAR violation, it should immediately halt any potentially unlawful activity. The company must preserve all relevant records as required by 22 C.F.R. § 122.5 (ITAR) and 15 C.F.R. § 762 (EAR), as both DDTC and BIS require complete documentation for any review. Conduct a prompt, fact-based internal investigation to determine the facts, involved parties, access to technical data or technology, and whether other transactions or facilities are affected. After establishing the facts, assess whether voluntary self-disclosure is warranted. BIS states in 15 C.F.R. § 764.5 that voluntary self-disclosures are a “strong mitigating factor,” and DDTC “strongly encourages” disclosures under 22 C.F.R. § 127.12 for suspected ITAR violations. The decision to disclose depends on the severity, willfulness, and scope of the issue. Early escalation to internal compliance and legal teams as well as external expert legal counsel is critical as regulators consider the company’s initial response, including speed, transparency, and corrective action, when determining penalties.
6. How do OFAC sanctions impact aerospace companies?
OFAC sanctions are primarily issued under authorities such as the International Emergency Economic Powers Act, the Trading with the Enemy Act, and program-specific regulations in 31 C.F.R. Chapter V. The most relevant sanctions programs for aerospace companies often include the Iranian Transactions and Sanctions Regulations, Cuban Assets Control Regulations, North Korea Sanctions Regulations, Ukraine/Russia-related Sanctions Regulations, Global Terrorism Sanctions Regulations, and Weapons of Mass Destruction Proliferators Sanctions Regulations. Sanctions measures under these programs can restrict sales, leases, repairs, spare parts, software updates, financing, maintenance, training, and technical support involving sanctioned jurisdictions, SDNs, blocked aircraft, or entities owned 50 percent or more by blocked persons. Even non-U.S. aerospace companies may face OFAC sanctions risks when a transaction involves U.S.-origin goods, U.S. persons, U.S. dollars, U.S. banks, or U.S.-based software.
7. What is “technical data” and “technology” and why is it so important in aerospace compliance?
Technical data generally includes controlled information related to the design, development, production, manufacture, assembly, testing, repair, maintenance, modification, or operation of aerospace items. Under the ITAR, “technical data” is defined at 22 C.F.R. § 120.33, and “software” is separately defined at 22 C.F.R. § 120.40(g) to include items such as system functional design, logic flow, algorithms, application programs, operating systems, and support software. Under the EAR, controlled “technology” is addressed in 15 C.F.R. Part 772, and a release of controlled technology or source code to a foreign person in the United States may constitute a “deemed export” under 15 C.F.R. § 734.13(b) and 15 C.F.R. § 734.14. In the aerospace sector, technical data and technology may include engineering drawings, CAD models, blueprints, manufacturing tolerances, material specifications, software source code, test data, design analysis, schematics, and repair instructions. Sharing controlled technical information with a foreign person can constitute an export, even inside the United States; aerospace companies must carefully manage access through technology control plans, restricted databases, cloud controls, visitor procedures, and foreign national employee access reviews.
8. What are the penalties for ITAR or EAR violations?
Under the ITAR, civil penalties may exceed $1 million per violation, and willful violations can result in criminal fines and imprisonment under the Arms Export Control Act, 22 U.S.C. § 2778. Under the EAR, violations can also result in substantial civil penalties, criminal penalties, imprisonment, and denial of export privileges under the Export Control Reform Act of 2018, 50 U.S.C. §§ 4801–4852, and the EAR enforcement provisions in 15 C.F.R. Part 764. Companies may also face debarment, loss of export privileges, mandatory audits, compliance monitors, remedial reporting obligations, and reputational harm. Recent enforcement actions involving aerospace and defense companies show that regulators treat unauthorized exports of technical data/technology, software, and controlled components seriously, even where violations result from misclassification, cloud access, or foreign national employee access.
9. How do FOCI rules affect aerospace companies?
Foreign Ownership, Control, or Influence (FOCI) rules, under 32 CFR 117.11, apply to any company that requires access to classified information and seeks or maintains a facility security clearance under the National Industrial Security Program. When an aerospace or defense company has foreign shareholders, foreign board members, or foreign parent entities, the Defense Counterintelligence and Security Agency (DCSA) evaluates whether that foreign relationship could allow a foreign interest to exert control or influence over the company’s operations, decision‑making, or access to classified programs.
INSIGHTS
CMMC Assessments and the Hidden Risk of ITAR Violations
For many contractors within the Defense Industrial Base, Cybersecurity Maturity Model Certification (CMMC) assessments are becoming far more than cybersecurity hygiene exercises. As companies strive to become CMMC compliant, they are increasingly uncovering facts suggesting potential violations of export control laws, including the International Traffic in Arms Regulations (ITAR), administered by the Directorate of Defense Trade Controls under the U.S. Department of State, and the Export Administration Regulations (EAR), administered by the Bureau of Industry and Security under the U.S. Department of Commerce.
DDTC Goes Back-To-Basics in Boeing Settlement
On February 28, 2024, the U.S. Department of State and The Boeing Company (Boeing) agreed to an administrative settlement regarding 199 violations by Boeing of the Arms Export Control Act (AECA) and the International Traffic in Arms Regulations (ITAR). As a result of that settlement, Boeing was fined $51 million ($27 million to be paid over the next 3 years, plus $24 million suspended but required to be applied internally to consent agreement conditions). Boeing will also be subject to a plethora of other conditions over the next three years, including government monitoring via a Special Compliance Officer, which will oversee Boeing’s adherence to the conditions of the settlement.
When CFIUS Mitigation Agreements and FOCI Reviews Overlap: A Critical Balancing Act
On June 9, 2021, Momentus Inc., a U.S. commercial space company offering in-space transportation and infrastructure services, as a condition to its acquisition by a foreign-owned company, entered into a National Security Agreement with the Department of Defense (“DoD”) and Department of Treasury. Under this agreement, Momentus was required to “implement increased security measures, hire key positions to provide additional oversight and appoint a [Committee on Foreign Investment in the United States (“CFIUS”)]-approved director to its board of directors.”1 In doing so, Momentus agreed to mitigate the national security risks associated with its foreign ownership.
Safeguarding Technical Data: A Lesson from the Honeywell Consent Agreement
Safeguarding technical data and preventing unauthorized exports of controlled technical data is a challenge for most companies. As demonstrated by the Honeywell consent agreement, the U.S. Government (“USG”) will not take violations involving unauthorized exports of controlled technical data lightly. Therefore, industry should carefully assess their compliance programs to ensure that technical data is safeguarded properly. This article provides an overview of the Honeywell consent agreement and discusses general recommendations for safeguarding technical data.
Important Takeaways for Exporters from Honeywell’s Consent Agreement with DDTC
On April 27, 2021, Honeywell International, Inc. (“Honeywell”) entered into a consent agreement with the U.S. Department of State Directorate of Defense Trade Controls (“DDTC”) for alleged violations of the Arms Export Control Act (“AECA”) and the International Traffic in Arms Regulations (“ITAR”). Specifically, Honeywell, a defense contractor based in Charlotte, North Carolina, allegedly exported and retransferred ITAR-controlled technical data without required authorization.
U.S. Government Imposes Additional Export Controls on China Trade
Towards the end of its term, the Trump Administration continues to strengthen regulation of trade with China, even when it means leaving implementation of the new controls to the Biden Administration.
For companies doing business in and with China, the increased export controls and economic sanctions – a recent executive order prohibiting transactions with popular Chinese mobile payment apps, a new ‘Military End Use’ list that tightens export licensing for designated items, and a ban on securities investments in Chinese military entities – call for enhanced due diligence to ensure compliance.