Defense
As one of the largest and most advanced defense industries in the world, the U.S. defense sector consists of a wide range of industries, including aerospace, shipbuilding, cyber-defense, and advanced weaponry. U.S. defense exports include innovative equipment, from fighter jets and missiles to defense systems, radar, and cybersecurity solutions. Navigating the intricacies of international trade law is critical for ensuring compliance, protecting national interests, and maintaining competitive advantage in global markets.
To operate effectively, companies must understand and adhere to a complex framework of regulations, including the International Traffic in Arms Regulations (ITAR), Export Administration Regulations (EAR), and various sanctions administered by the Office of Foreign Assets Control (OFAC). These regulations are designed to safeguard against unauthorized access to sensitive technologies and prevent the export of controlled items to hostile states or entities. These regulations also include provisions that affect defense exports, including restrictions on dual-use items and requirements for government approval before exporting sensitive technologies. The Committee on Foreign Investment in the United States (CFIUS) reviews foreign acquisitions of U.S. defense companies to protect sensitive technologies and intellectual property from potential adversaries.
Cybersecurity is increasingly relevant in the defense industry, especially as many controlled technologies and information are stored or transferred digitally. Defense companies must secure their systems against unauthorized access and cyber threats, implementing controls to prevent sensitive data leaks that could jeopardize national security. Advanced encryption, regular security audits, and compliance with international cybersecurity standards are essential practices.
Representative Experience
Torres Trade Law has a very experienced defense trade practice, and Managing Member Olga Torres has been an active member of the Department of State’s Defense Trade Advisory Group (DTAG) since 2012. Torres Trade Law’s representative experience related to the defense industry includes:
- Advising a U.S.-based government contractor in connection with its acquisition by a Japanese company and related CFIUS issues, including CFIUS mitigation plan compliance and meetings with CFIUS Department of Defense monitors.
- Successfully obtaining export control licenses and ITAR license agreements for numerous defense industry clients.
- Advising defense industrial base clients regarding cybersecurity requirements, including Cybersecurity Maturity Model Certification.
- Preparing and implementing export control and sanctions compliance programs for multiple defense companies.
- Advising on the application of Foreign Ownership, Control, or Influence (FOCI) regulations administered by the Defense Counterintelligence and Security Agency.
- Operating as the outsourced export compliance department for manufacturers and exporters of defense articles.
- Conducting internal investigations of defense companies, leading to submissions of voluntary disclosures to the Department of State Directorate of Defense Trade Controls (DDTC) and the Department of Commerce Bureau of Industry and Security (BIS).
- Advising defense brokers on ITAR brokering registration and licensing requirements.
Defense Trade & Export Law FAQs
1. What are the main regulatory bodies and legal frameworks governing exporters and importers in the defense industry?
The International Traffic in Arms Regulations (ITAR), administered by the U.S. Department of State’s Directorate of Defense Trade Controls (DDTC), govern exports of defense articles, technical data, and defense services listed on the U.S. Munitions List. The Export Administration Regulations (EAR), administered by the Department of Commerce’s Bureau of Industry and Security (BIS), regulate exports of dual‑use items and certain military‑related technologies not covered by the ITAR.
The Department of the Treasury’s Office of Foreign Assets Control (OFAC) administers economic sanctions that restrict transactions with certain countries, entities, and individuals, including many state‑owned defense enterprises.
In addition, the Committee on Foreign Investment in the United States (CFIUS) reviews foreign acquisitions and investments in U.S. defense companies to assess national security risks. At the same time, the Defense Counterintelligence and Security Agency (DCSA) oversees Foreign Ownership, Control, or Influence (FOCI) mitigation for companies requiring access to classified information.
Together, these agencies form the core regulatory framework that defense exporters and importers must navigate to ensure lawful operations and protect sensitive technologies.
2. How do the EAR apply to defense companies?
The Export Administration Regulations (EAR) regulate the export of defense-related items, software, or technology that are not controlled under the ITAR but that still have national security, foreign policy, anti-terrorism, or military end-use significance. These items are listed on the Commerce Control List (CCL) and are classified under Export Control Classification Numbers (ECCNs). In the defense industry, EAR-controlled items may include certain electronics, sensors, navigation systems, encryption software, materials, propulsion components, cyber tools, manufacturing equipment, and other technologies used in both commercial and military applications. Even if an item is commercially available or not specially designed for military use, a license may still be required if the destination is restricted, the end user is a military or prohibited party, or the end use involves weapons development, military intelligence, surveillance, or other controlled activities. Defense companies should also be aware that foreign-made items can sometimes become subject to the EAR if they contain certain levels of controlled U.S.-origin content or are produced using certain U.S. technology or software. Defense programs often involve both ITAR-controlled and EAR-controlled components, so companies should not assume that an item is not controlled simply because it is not listed on the U.S. Munitions List.
3. What are “dual-use” items?
“Dual-use” items are items, software, or technologies that have both civilian and military applications. For example, a sensor may be designed for commercial aerospace or industrial use but also be useful in a military aircraft, missile system, unmanned vehicle, or surveillance platform. Similarly, encryption software, high-performance materials, navigation equipment, propulsion technology, semiconductors, and certain manufacturing tools may serve ordinary commercial purposes while also supporting defense or military capabilities. Under the EAR, a dual-use item may require an export license depending on its classification (ECCN) reason for control, destination, end user, and end use. Companies should conduct restricted party screening, confirm the end use and end user, review military end-use rules, and maintain documentation showing how the classification and licensing determination was made.
4. What types of defense items are controlled under the ITAR?
The ITAR controls defense articles, technical data, and defense services listed on the U.S. Munitions List. For defense companies, commonly implicated USML categories include:
- Category I: Firearms, close assault weapons, and combat shotguns
- Category II: Guns and armament
- Category III: Ammunition and ordnance
- Category IV: Launch vehicles, guided missiles, ballistic missiles, rockets, torpedoes, bombs, and mines
- Category V: Explosives, energetic materials, propellants, incendiary agents, and related substances
- Category VI: Surface vessels of war and special naval equipment
- Category VII: Ground vehicles
- Category VIII: Aircraft and related articles
- Category XI: Military electronics
- Category XII: Fire control, laser, imaging, and guidance equipment
- Category XIII: Materials and miscellaneous articles
- Category XV: Spacecraft and related articles
ITAR controls also apply to technical data related to these items, including engineering drawings, design information, manufacturing instructions, software, specifications, and certain repair or maintenance information. Defense services, such as assisting a foreign person with the design, development, production, testing, repair, or operation of a defense article, may also require authorization. In addition, brokering activities involving defense articles or defense services may require DDTC registration and brokering authorization or licensing under the ITAR.
5. What is the difference between a defense article, technical data, and a defense service?
A defense article is a physical item, software, or technical item listed on the U.S. Munitions List. Examples may include military aircraft parts, weapons systems, military electronics, armored vehicle components, controlled sensors, or certain satellite systems. Technical data refers to information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of a defense article. This can include blueprints, drawings, CAD files, schematics, source code, manufacturing tolerances, and testing protocols. A defense service generally involves providing assistance, training, or technical support to a foreign person in connection with a defense article, even if no physical item is exported. Export controls apply not only to physical products, but also to information, services, and technical collaboration.
6. Can sharing technical data with a foreign person count as an export even if the sharing takes place within the U.S.?
Yes. Under both the ITAR and EAR, controlled technical information or technology can be exported even when no physical item leaves the United States. Releasing controlled technical data or technology to a foreign person in the United States may constitute a “deemed export” under the EAR or an export under the ITAR. This can occur through emails, shared drives, cloud platforms, engineering meetings, facility visits, technical demonstrations, remote access, or collaboration with foreign national employees and contractors. Defense companies should carefully control access to technical data, especially when working with multinational engineering teams, foreign affiliates, overseas manufacturers, foreign investors, and international partners.
7. What should defense companies expect during a government or foreign‑visitor review of their facilities, and how does this relate to Customs and trade compliance obligations?
Facility visits often involve reviews of how imported components are stored, tracked, and integrated into production, as well as how controlled technical data is segregated and protected in accordance with ITAR and EAR requirements. Government personnel may request documentation supporting country-of-origin determinations, valuation methodologies, and licensing records, particularly when the facility handles USML-controlled parts, classified programs, or foreign-sourced materials subject to procurement restrictions such as the Buy American Act, TAA, or specialty-metals rules. U.S. Customs and Border Protection (CBP), DDTC, BIS, and DoD agencies increasingly coordinate enforcement; inconsistencies identified during a facility visit—such as improper marking, incomplete import records, or inadequate segregation of controlled items—can lead to follow‑up inquiries, CF 28/29 requests, or broader compliance reviews. Defense companies should therefore treat all visits as compliance-sensitive events and ensure that internal controls, documentation, and physical security measures are fully aligned before hosting any external party.
8. What should a defense company do if it discovers a potential ITAR or EAR violation?
If a company operating in the defense sector identifies a potential ITAR or EAR violation, it should immediately halt any potentially unlawful activity. The company must preserve all relevant records as required by 22 C.F.R. § 122.5 (ITAR) and 15 C.F.R. § 762 (EAR), as both DDTC and BIS require complete documentation for any review. Conduct a prompt, fact-based internal investigation to determine the facts, involved parties, access to technical data, and whether other transactions or facilities are affected. Defense companies should also consider how potential compliance issues impact their obligations and warranties under active government contracts. After establishing the facts, assess whether voluntary self-disclosure is warranted. BIS states in 15 C.F.R. § 764.5 that voluntary self-disclosures are a “strong mitigating factor,” and DDTC “strongly encourages” disclosures under 22 C.F.R. § 127.12 for suspected ITAR violations. The decision to disclose depends on the severity, willfulness, and scope of the issue. Early escalation to internal compliance and legal teams as well as external expert legal counsel is critical as regulators consider the company’s initial response, including speed, transparency, and corrective action, when determining penalties. In addition, prompt remediation of export compliance issues helps to maintain the company’s reputation and ensure it may have continued involvement in government contracting.
INSIGHTS
CMMC Assessments and the Hidden Risk of ITAR Violations
For many contractors within the Defense Industrial Base, Cybersecurity Maturity Model Certification (CMMC) assessments are becoming far more than cybersecurity hygiene exercises. As companies strive to become CMMC compliant, they are increasingly uncovering facts suggesting potential violations of export control laws, including the International Traffic in Arms Regulations (ITAR), administered by the Directorate of Defense Trade Controls under the U.S. Department of State, and the Export Administration Regulations (EAR), administered by the Bureau of Industry and Security under the U.S. Department of Commerce.
DOJ’s Increasing Role in the Enforcement of U.S. Trade Laws
A Primer on the Committee on Foreign Investment in the United States (CFIUS)
The Committee on Foreign Investment in the United States (“CFIUS” or “the Committee) is an interagency body of the U.S. government that plays a critical role in safeguarding national security by reviewing foreign investments in U.S. businesses and assets. Established in 1975 through an Executive Order issued by President Gerald Ford, CFIUS initially served as an advisory committee to monitor and evaluate the impact of foreign investments on the U.S. economy. Over time, its role has evolved significantly to focus on identifying and mitigating risks to national security posed by such investments.
DOJ Involvement in the Enforcement of Trade and National Security Laws
The U.S. agencies most well-known for their enforcement of U.S. trade and national security laws are the Bureau of Industry and Security (“BIS”), the Directorate of Defense Trade Controls (“DDTC”), the Office of Foreign Assets Control (“OFAC”), and U.S. Customs and Border Protection (“CBP” or “Customs”). However, the Department of Justice (“DOJ”) can often play a critical role in these types of matters.
Understanding ITAR Mandatory Disclosures and the “Duty to Inform” DDTC
The discovery of actual or potential International Traffic in Arms Regulations (“ITAR”) violations presents the question of whether to disclose the conduct to the Department of State Directorate of Defense Trade Controls (“DDTC”). For certain violations, the ITAR sets forth mandatory disclosure requirements, and specific circumstances may give rise to an affirmative duty to inform DDTC of certain activities and transactions.
ITAR Material Change Reference Guide
Any person or company in the United States that manufactures, exports, temporarily imports, or brokers items, including technical data and software (defense articles), or performs certain services (defense services) that are controlled under the International Traffic in Arms Regulations (ITAR) is required to register with the U.S. Department of State Directorate of Defense Trade Controls (DDTC) and keep that registration current. Current in the context of the ITAR means not only the information that is current at the time the registration is initially submitted, but the registration information must accurately reflect the registered entity’s current information at any point in its timeline.