ITAR & CUI

    ITAR vs CUI: Overlapping Regimes, Non-Overlapping Penalties

    ITAR and CUI are not the same thing, but they overlap heavily in the defense industrial base. ITAR (International Traffic in Arms Regulations) is an export-control statute administered by the State Department; CUI is a federal handling category established by Executive Order 13556. Almost all ITAR-controlled technical data is also CUI (specifically CUI//SP-EXPT), but not all CUI is ITAR. This page maps the overlap, the divergences, and how a CMMC Level 2 program covers both — except the parts it doesn't.

    What each regime actually controls

    ITAR controls the export and re-export of defense articles and defense services listed on the United States Munitions List (USML). The technical data itself — drawings, specs, software source — is regulated; access by a foreign person (even on U.S. soil) is an export. Penalties: up to $1M per civil violation, $1M and 20 years per criminal violation.

    CUI is a handling category for unclassified information that requires safeguarding under federal law, regulation, or government-wide policy. It's a marking and protection regime, not an export-control regime. CUI obligations attach via contract clauses (DFARS 7012, FAR CUI clause when it lands).

    The overlap: CUI//SP-EXPT

    • The CUI Registry includes Export Controlled as a specified category (CUI//SP-EXPT).
    • Almost all ITAR technical data is CUI//SP-EXPT when handled by a federal contractor.
    • Inside a CMMC Level 2 enclave, you're already protecting it from an information-security standpoint — encryption, access control, audit, incident reporting.
    • CMMC compliance does not satisfy ITAR. ITAR has its own registration, licensing, and foreign-person access controls that CMMC doesn't touch.

    Where CMMC stops and ITAR keeps going

    CMMC Level 2 + DFARS 7012 will get you to:

    • FIPS-validated encryption at rest and in transit
    • Access control, MFA, audit logging
    • 72-hour incident reporting to DC3
    • Configuration management and vulnerability scanning

    ITAR additionally requires:

    • DDTC registration (every U.S. manufacturer or exporter of defense articles)
    • Export licenses or exemptions for any release to a foreign person
    • Foreign-person access controls in the actual environment — your IT staff, your cloud provider's support team, your offshore developers
    • End-to-end encryption with U.S.-controlled keys if storing ITAR data in commercial cloud (per the State Department's 2020 carve-out)
    • Recordkeeping for five years of every export

    Practical architecture: dual-purpose enclave

    The cleanest pattern is a single enclave designed for ITAR (most restrictive) that automatically satisfies CUI/CMMC by being a superset. That means: U.S.-only personnel access (enforced technically, not just policy), GovCloud or similar U.S.-sovereign cloud region, customer-controlled encryption keys, hardware tokens for MFA, and an evidence collection pipeline that captures both ITAR access logs and CMMC audit logs in the same store. Trying to bolt ITAR onto a commercial CMMC environment after the fact is where most programs blow up the budget.

    Frequently asked questions

    If I'm CMMC Level 2 certified, am I ITAR-compliant?

    No. CMMC certifies your information-security controls against NIST 800-171. ITAR additionally requires DDTC registration, export licensing, foreign-person access control, and recordkeeping that CMMC does not assess. A Level 2 certification is a strong foundation for ITAR but not a substitute.

    Does ITAR allow commercial cloud (Microsoft 365, AWS)?

    Conditionally, since the State Department's March 2020 rule. ITAR data may be stored in commercial cloud if it is end-to-end encrypted with keys controlled by U.S. persons and the cloud provider cannot access the plaintext. In practice this means GovCloud or equivalent + customer-managed keys + access restrictions on cloud provider personnel.

    Is ITAR data always marked CUI//SP-EXPT?

    When handled under a federal contract, yes — the CUI Registry treats Export Controlled as a specified category. ITAR data held purely between private parties (e.g., between two cleared U.S. manufacturers without a federal contract) is still ITAR but not technically CUI; the contractual obligations differ.

    What happens to ITAR under the upcoming FAR CUI rule?

    The proposed FAR CUI rule will create a government-wide CUI handling clause that applies across all agencies (not just DoD). It does not change ITAR itself. Practical effect: contractors that already handle CUI//SP-EXPT for DoD will see the same obligations extended to civilian-agency contracts.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.