SK Written by Sarika Krishnan with Robert LabardeeSenior Program Manager and Founder and CEO

ITAR vs EAR: a guide to US export control compliance

Lightbridge Cloud defines US export controls as the federal regime that governs who may access controlled technology, technical data, and software. Two frameworks dominate: ITAR, administered by the State Department, covering defense articles on the USML, and the EAR, administered by Commerce, covering dual-use items on the CCL.

US export controls govern who may access controlled technology, not only what ships.

US export controls regulate the transfer of controlled items, technical data, and software to foreign persons and foreign destinations. Two federal frameworks carry most of the weight. ITAR, the International Traffic in Arms Regulations, governs defense articles. The EAR, the Export Administration Regulations, governs dual-use items. The two are administered by different agencies, rest on different statutes, and use different control lists, so the first job in any program is deciding which regime applies to a given item.

The point most relevant to cloud and contractors is that an export is not only a physical shipment. Granting a foreign person access to controlled technical data, even on a server inside the United States, can itself be an export. That single fact reframes export-control compliance as a problem of identity, access, and data handling, which is where cloud architecture meets the regulation. For the residency dimension, the data sovereignty guide sets the context.

Lightbridge Cloud is an independent, vendor-neutral cloud advisory practice. This guide describes the export-control landscape as it is, in generic terms, because the right architecture still depends on the facts of a specific program. It is general guidance, not legal advice.

ITAR and the EAR are two distinct regimes with different agencies and control lists.

ITAR and the EAR share goals but operate independently. ITAR sits under the State Department and the USML, the EAR under the Commerce Department and the CCL. Getting jurisdiction right is the foundation: it determines registration, licensing, and the access controls a program must enforce. These are the building blocks.

ITAR scope and authority

The International Traffic in Arms Regulations sit at 22 CFR parts 120 to 130 and are administered by the State Department through the Directorate of Defense Trade Controls. ITAR governs defense articles, defense services, and technical data enumerated on the United States Munitions List, the USML.

EAR scope and authority

The Export Administration Regulations sit at 15 CFR and are administered by the Commerce Department through the Bureau of Industry and Security, BIS. The EAR governs dual-use items, those with both commercial and military or proliferation uses, classified on the Commerce Control List, the CCL.

How the line is drawn

Jurisdiction follows the item. A defense article designed or modified for a military application generally falls under ITAR and the USML, while a commercial item with a possible military use generally falls under the EAR and the CCL. An item that is subject to the EAR but not listed on the CCL is typically designated EAR99.

Classification first

Compliance begins with classification: determine whether an item, its technical data, and the software are subject to ITAR, the EAR, or neither. A commodity jurisdiction request to DDTC or a classification request to BIS resolves uncertain cases. Misclassification, in either direction, is the root of most violations.

Registration and licensing

ITAR generally requires manufacturers, exporters, and brokers of defense articles to register with DDTC, separate from any license to export. Under the EAR, the need for a license turns on the item classification, the destination, the end user, and the end use, checked against the Commerce Country Chart.

Recordkeeping and screening

Both regimes require restricted-party screening against consolidated denied, debarred, and entity lists, plus recordkeeping of exports and license decisions. The control applies to the technology itself, not only to a physical shipment, which is why access management is central to compliance.

Deemed exports make access management the core of cloud export-control compliance.

In the cloud, the export-control question is rarely about a border crossing. It is about who can read controlled data. The deemed-export rule means that granting a foreign person access to controlled technical data is treated as an export, so encryption, key custody, data residency, and personnel access all become compliance controls rather than back-office details.

A deemed export is access, not shipment

Releasing controlled technical data or source code to a foreign person inside the United States is treated as an export to that person’s country of nationality, a deemed export. Hiring, screen sharing, and granting system access can all trigger this without anything crossing a border.

Encryption is access control

For controlled data at rest and in transit, encryption with US-controlled keys is a primary safeguard, because the question regulators ask is who can read the data. Key custody, not only ciphertext, determines whether a foreign person has effective access.

Data residency and personnel

Where controlled data physically resides, and which administrators and support staff can reach it, both matter. A cloud region inside the United States staffed by personnel who are not US persons can still create a deemed-export exposure if access is not restricted.

Several cloud providers offer dedicated US regions and government-oriented environments, including offerings branded AWS GovCloud and Microsoft Azure Government. AWS and GovCloud are trademarks of Amazon, and Azure and Microsoft are trademarks of Microsoft; Lightbridge Cloud is independent and is not affiliated with, or a partner of, either vendor, and selects environments on fit rather than alignment.

Export controls reach any organization that holds controlled technical data in the cloud.

Defense contractors and subcontractors are the obvious case, but the regimes reach further. Manufacturers, research organizations, universities, and software firms can all hold ITAR or EAR controlled technical data, often without a license being top of mind. Any organization that stores controlled designs, source code, or technical specifications in a cloud environment inherits an obligation to control who can access them. The exposure scales with the number of administrators, contractors, and support staff who can reach the data.

Export-control obligations rarely arrive alone. Controlled technical data is frequently also Controlled Unclassified Information, and a federal contract may layer FAR and DFARS clauses, NIST SP 800-171 controls, and a CMMC assessment on top. The controlled unclassified information guide explains the safeguarding side, and the FOCI guide explains how foreign ownership affects who may access controlled data in the first place.

An export-control-ready cloud environment is built from access, encryption, and audit controls.

The technical foundation of an ITAR or EAR program in the cloud is consistent across regimes. Identity and access management restricts controlled data to authorized persons. Encryption with keys held under US control keeps the data unreadable to anyone outside that boundary. Network segmentation isolates controlled workloads, and comprehensive audit logging records who accessed what and when, which is what regulators and assessors expect to see. None of these is exotic; the discipline is applying them precisely to the right data.

Lightbridge Cloud designs and documents these controls as readiness work, vendor-neutral and across providers, so an organization can demonstrate that controlled data is protected. Classification of items, jurisdiction questions, and licensing decisions belong with qualified export-control counsel. Because the regulations and their thresholds change, verify any specific requirement against the official source, including the DDTC and BIS guidance and the relevant NIST and acquisition publications.

This guide is general guidance for planning purposes only. It is not legal, audit, or accounting advice. Confirm specific obligations, dates, dollar thresholds, and penalties with qualified counsel and against the official sources, including acquisition.gov, the DoD CIO and OUSD, NIST, the NARA CUI Registry, DCSA, and the DDTC and BIS.

ITAR and EAR export control: frequently asked questions

What is the difference between ITAR and EAR?
ITAR, the International Traffic in Arms Regulations at 22 CFR parts 120 to 130, is administered by the State Department through the Directorate of Defense Trade Controls and governs defense articles, defense services, and technical data on the United States Munitions List. The EAR, the Export Administration Regulations at 15 CFR, is administered by the Commerce Department through the Bureau of Industry and Security and governs dual-use items on the Commerce Control List. In short, ITAR covers items designed for military use, while the EAR covers commercial and dual-use items. The first step in either case is classifying the item against the correct control list. Lightbridge Cloud helps organizations design the cloud and access controls that an export-control program depends on, and is independent and vendor-neutral.
What is ITAR compliance?
ITAR compliance means meeting the obligations of the International Traffic in Arms Regulations when an organization handles defense articles, defense services, or technical data on the USML. In practice it includes registering with DDTC where required, classifying items correctly, obtaining licenses or qualifying for exemptions before any export, screening parties against restricted lists, controlling access so that no foreign person reads controlled technical data without authorization, and keeping records. Because technical data can be exported simply by granting access, much of ITAR compliance is identity and access management. Lightbridge Cloud frames this work as readiness and advisory, designing the environment and controls; it does not provide legal determinations on jurisdiction or licensing.
What is EAR compliance?
EAR compliance means meeting the Export Administration Regulations administered by BIS when an organization handles dual-use items, software, or technology on the Commerce Control List. It turns on four questions: what the item is and its Export Control Classification Number, where it is going, who the end user is, and what the end use will be. Those determine whether a license is needed, checked against the Commerce Country Chart, and whether a license exception applies. Items not listed on the CCL are generally designated EAR99, which still carries end-user and destination restrictions. Lightbridge Cloud builds the cloud architecture, access controls, and audit trails that support an EAR program, and recommends verifying every classification against the official BIS guidance.
What is a deemed export?
A deemed export is the release of controlled technology, technical data, or source code to a foreign person located inside the United States, treated under both ITAR and the EAR as an export to that person’s country of nationality. It does not require anything to cross a border. Granting a foreign national access to controlled files, sharing a screen, or assigning a support engineer who can reach the data can all be deemed exports. This is why export-control compliance in the cloud is largely a matter of access management: who can see the data, from where, and under what authorization. Controlling identity and access is often the most direct way to manage deemed-export risk.
Does using a US cloud region make a workload export-control compliant?
Not on its own. A cloud region physically inside the United States addresses data residency, but export controls also turn on who can access the controlled data. If administrators, support staff, or other users who are not US persons can reach controlled technical data, a deemed export can still occur, regardless of region. Compliance requires restricting access to authorized US persons where the regime demands it, encrypting data with keys under US control, and maintaining an auditable record of who accessed what. Region selection is one input among several. Lightbridge Cloud is vendor-neutral and designs these controls across providers rather than steering toward any single platform.
How do ITAR and EAR relate to CMMC and CUI?
They overlap but are distinct. ITAR and the EAR are export-control regimes governing who may access controlled technology. CMMC and the Controlled Unclassified Information program govern how contractors safeguard sensitive federal information, often under FAR and DFARS clauses and NIST SP 800-171 controls. Export-controlled technical data is frequently also CUI, so a single dataset can carry both export-control and CUI obligations at once. The access controls, encryption, and recordkeeping that support one regime usually support the others. For the safeguarding side, see the guides on controlled unclassified information and on data sovereignty.
How does foreign ownership affect export-control access?
Foreign ownership, control, or influence can directly affect who is permitted to access controlled technical data, because both ITAR and the EAR treat release to a foreign person as an export. An organization with foreign ownership may need to demonstrate that its access controls prevent unauthorized foreign-person access to controlled data, sometimes alongside formal mitigation arrangements. The cloud and identity architecture that enforces those access boundaries is the technical foundation of that demonstration. The FOCI guide explains the ownership-and-influence dimension in more detail, including how it interacts with access to controlled information.
How does Lightbridge Cloud support export-control readiness?
Lightbridge Cloud is an independent, vendor-neutral cloud advisory practice. It designs the cloud architecture, identity and access management, encryption and key-custody model, network segmentation, and audit logging that an ITAR or EAR program relies on, and it does so across providers rather than committing to one. Lightbridge frames this work as readiness and advisory: building and documenting the controls an organization needs. It is not a law firm and does not make jurisdiction or licensing determinations, and it does not claim any certification or government authorization. Classification and legal questions should go to qualified export-control counsel, verified against the official DDTC and BIS guidance.

From understanding export controls to a cloud that enforces them.

When the question shifts from what ITAR and the EAR require to how your cloud should enforce them, Lightbridge Cloud designs the access, encryption, and audit controls, independent and vendor-neutral.