ITAR Compliance IT Services

Build the U.S.-person access boundary, encryption, and audit evidence your export control officer can defend.

ITAR compliance IT services secure the systems where ITAR technical data lives, restricting access to U.S. persons, encrypting storage and transfer, controlling where data sits, and producing evidence an auditor accepts. The U.S. State Department enforces it, not the Pentagon. The compliance determination stays with your export control officer. The environment that makes that determination defensible is what we build and run.

Three Questions That Tell You Whether You Have an ITAR Problem

Ask your team three questions this week.

Who can open the folder where customer drawings live? Where does the backup copy of that folder physically sit? And who at your IT provider holds domain admin?

If any answer takes more than a minute, ITAR compliance IT services aren't a future project for you. They're a current gap.

Aerospace and defense suppliers rarely fail ITAR because someone shipped a part to the wrong country. They fail because a drawing sat in a commercial Microsoft 365 tenant that a contract engineer in another country could reach. That's a deemed export, which means releasing controlled technical data to a foreign person, and it counts as an export even when nobody leaves the building.

The penalty math is public. $1,271,078 per violation, or twice the transaction value, whichever is greater, under the civil monetary penalty adjustment that took effect in January 2025. Enforcement sits with the Directorate of Defense Trade Controls at the State Department. Per violation. Not per incident.

We build the technical side of this alongside Consilien's compliance readiness work. Your export counsel decides what's controlled. We make the systems match that decision, and we make it provable.

Debarment is the quieter one. A prime doesn't announce that you've been removed from the bid list. The RFQs just stop.

What Counts as ITAR Technical Data on Your Network

A machinist emails a revised tolerance to a plating vendor. Nobody thinks twice. That email is technical data now, and it just moved through three mail servers.

ITAR technical data is information required to design, develop, produce, manufacture, assemble, operate, repair, test, maintain, or modify a defense article. On a network that means CAD and CAM files, drawings carrying distribution markings, test results, tooling instructions, inspection reports, and any email or chat thread that quotes them.

It's broader than most shops assume when they first map it.

Where it turns up during scoping:

  • The engineering share, obviously. Everybody guesses that one.
  • Quoting and estimating files, because the RFQ package from the prime came with the drawing attached.
  • Quality records with dimensional data traceable back to a controlled print.
  • Somebody's Downloads folder. There's always a Downloads folder.
  • A shared mailbox that four people use and nobody owns.

ITAR doesn't care that the drawing came from your customer.

Does ITAR Even Apply to a Shop Your Size?

Company size isn't a factor in the regulation. There's no small business exemption, no revenue floor, and no carve-out for a supplier making one bracket.

  1. You manufacture something on the U.S. Munitions List. Under 22 CFR 122.1, a manufacturer of defense articles must register with the Directorate of Defense Trade Controls even if it never exports anything. Registration isn't a license and it isn't a certification. It's a precondition.
  2. Your prime sends you controlled technical data. ITAR flows down the supply chain. A distribution statement on a print is the signal.
  3. You furnish a defense service. Repair, modification, testing, or technical assistance on a defense article counts.

Registration runs $3,000 a year at Tier 1 and $4,000 at Tier 2 and Tier 3 under the fee schedule that took effect January 9, 2025, per Holland & Knight's summary of the final rule. Tier 1 registrants can apply for a $500 discount when the fee is 1% or more of prior-year revenue.

Shops that come to us already registered are usually surprised by the same thing. Registration said nothing about whether their network was defensible. We see that pattern most often in aerospace manufacturing.

That's the cheap part. The IT environment is where the real budget goes.

The Four Places ITAR Data Leaks in a Normal IT Stack

Email and Teams

Quotes, revisions, and drawing attachments move through commercial tenants that carry no export controls at all.

CAD, PDM, and ERP

Engineering files replicate to vendor clouds, contractor laptops, and a plugin nobody scoped.

Backup and Disaster Recovery

Your DR copy inherits none of your access rules, and its region may not be U.S.-resident.

Helpdesk, RMM, and Monitoring

Every tool with remote access is a potential release path, including the ones your provider owns.

One thing worth flagging on that last card. Backups are the most common miss by a wide margin. A shop will spend four months hardening the engineering share, then discover the nightly job has been replicating to a region they never chose, under a vendor account administered by somebody they've never met.

Your IT Provider Sits Inside the Boundary

If your MSP can reach the systems holding ITAR technical data, your MSP is inside your export control boundary. Their after-hours tier. Their RMM platform, meaning the remote monitoring and management software they use to administer your machines. Their backup vendor. Their offshore Level 1 queue, if they have one.

So the questions run both directions. At this stage the owner or COO usually asks the same three.

Can you tell me, in writing, that every person with privileged access to our systems is a U.S. person? Where does your after-hours support team physically sit? Who administers the tenant our backups land in?

Ask any provider those. Ask us those.

A policy document stating U.S.-person-only access, with no technical control enforcing it, fails the first serious questionnaire a prime sends you. Access has to be enforced at the identity layer, logged, and reviewed. Otherwise it's a statement of intent.

Three Ways to Build the Boundary

Microsoft 365 GCC High is the answer most often recommended here, and it's a legitimate one. It isn't the only one, and for a 45-person machine shop with a narrow ITAR footprint it's frequently the wrong one on cost.

There are three architectures that actually work. The decision is scope and money, not vendor preference.

  Microsoft 365 GCC High Encryption Carve-Out Enclave On-Prem or Private Enclave
What ITAR relies on U.S.-sovereign tenant, screened U.S. support personnel End-to-end encryption under 22 CFR 120.54(a)(5), keys held only by U.S. persons Physical and network control of the environment
Public per-user cost $35.80 Business Premium, $65.20 G3, $97.50 G5 per user monthly Enclave license layered on your existing commercial tenant Capex plus ongoing administration
Migration effort Full tenant migration, AOS-G authorized partner required Overlay, no tenant move Build or re-architect
Best fit Broad CUI and ITAR scope, CMMC Level 2 already committed Narrow ITAR footprint, small user count, cost pressure Shop-floor-heavy or air-gapped environments
Where it breaks Cost at scale, application and Copilot gaps Discipline, since one file saved outside the enclave defeats it Backup, remote access, and the evidence burden

The middle column is the one that usually goes unexplained. In March 2020 the State Department created an end-to-end encryption carve-out, now sitting at 22 CFR 120.54(a)(5). Send or store unclassified technical data with end-to-end encryption, using cryptographic modules validated to FIPS 140-2 or providing security at least comparable to AES-128, keep the decryption keys away from foreign persons, and don't intentionally store it in a country listed under Section 126.1, and it isn't an export. Data merely transiting the internet through another country doesn't count as stored there.

A small supplier can sometimes keep its commercial Microsoft 365 tenant and put the controlled data in an encrypted enclave on top. Cheaper. Faster. Narrower.

It also fails badly if people work around it. We've written up the tradeoff in detail in our enclave versus GCC High comparison for aerospace suppliers.

Walk us through where your drawings actually live. We'll tell you which of the three fits, and roughly what it costs.

Speak to an ITAR compliance expert

The Numbers Worth Knowing Before You Budget

Four figures shape almost every ITAR IT conversation.

$1,271,078

Maximum civil penalty per ITAR violation, effective January 2025. Criminal exposure runs higher and reaches individuals.

$3,000 to $4,000

Annual DDTC registration by tier, effective January 9, 2025.

$35.80 to $97.50

Publicly listed reseller planning prices per user per month for Microsoft 365 GCC High tiers as of July 2026, following the government price increase that took effect July 1.

November 10, 2026

The date CMMC Phase 2 begins, when a third-party C3PAO assessment becomes the standard for applicable DoD contracts under the 48 CFR acquisition rule effective November 10, 2025.

That last one matters for sequencing. Suppliers racing toward a C3PAO assessment are usually the same suppliers with an unresolved ITAR boundary, and the control sets overlap heavily. Run them as separate projects and you pay for the same work twice.

How the Engagement Runs

Five stages. Each one ends in a decision, not a deliverable, which is deliberate. Nothing gets built until the scope is settled.

1

Classify the Data

We separate what's genuinely ITAR from what's EAR-controlled, CUI, or just proprietary. Over-scoping is the most expensive mistake in this work, and it's the common one.

2

Draw the Boundary

Systems, people, third parties, and providers. If it can reach the data, it's on the map, including us.

3

Pick the Architecture

GCC High, encryption enclave, or private enclave. Decided against scope, headcount, and budget, using the table above.

4

Enforce It Technically

Identity and conditional access, encryption and key custody, device controls, data loss prevention, and logging. Controls map cleanly to NIST 800-171 requirements and to identity and access controls already in place.

5

Keep It Defensible

Quarterly access reviews, offboarding that actually revokes, annual re-attestation, and an evidence package your export control officer can hand to a prime without a two-week scramble.

What's Actually Included

Engagements vary by architecture, but the scope of work stays consistent. Here's what sits inside it.

Layered access boundary protecting ITAR controlled technical data

What Buyers Push Back On

"GCC High for 70 seats is real money."

It is. At $65.20 per user monthly for G3, 70 seats runs roughly $54,800 a year in licensing alone, before migration. That's exactly the situation the encryption carve-out enclave was designed for. Narrow the controlled footprint, encrypt it properly, keep the commercial tenant for everything else. We'll model both and show you the five-year number, because the cheaper option isn't always cheaper once the enclave discipline slips.

"We already have an IT provider."

Plenty of clients do, and this work runs alongside them more often than it replaces them. The question isn't whether your provider is competent. It's whether they can attest to U.S.-person-only privileged access and produce logs proving it. If they can, keep them. If they can't, that gap is yours, not theirs, when the prime asks.

"We're too small for anyone to care."

Size affects your risk of being audited. It has no effect on whether you're in violation. And the trigger is rarely an audit, it's a customer questionnaire, an insurance application, or a prime tightening its supply chain requirements ahead of the November 2026 CMMC phase.

"We did our CMMC work, so we're covered."

Different regulator, different trigger. CMMC comes from the Department of Defense and attaches to contracts. ITAR comes from the State Department and attaches to the article itself. The control sets overlap heavily, and a well-built CMMC environment gets you most of the way. Most is not all. The gaps are usually in third-party access and in physical or personnel screening. A gap assessment closes that question in a few weeks.

"Our attorney handles ITAR."

Good. They should. Your attorney determines what's controlled and files what needs filing. Nobody in that conversation is configuring conditional access policies or auditing who has domain admin on the file server. Those two jobs have to line up, and they usually don't.

What Clients Say

"Consilien has a great depth of knowledge and experience throughout their team."

Joel Poindexter, IT Manager, Hixson Metal Finishing

Manufacturing. Partner since 2010. Clutch-verified 5.0.

"Consilien is a quality IT partner that has done a great job keeping our business up and running."

Charles Warren, Financial Analyst, Interactive Health

Compliance consulting and managed IT. Roughly 14 years. Clutch-verified 5.0.

Common Questions About ITAR and IT

Does ITAR apply if we never ship anything overseas?


Shipping isn't the trigger. Manufacturing is. Under 22 CFR 122.1, a company producing defense articles has to register with DDTC whether or not it ever exports. And the everyday risk isn't shipping at all, it's a foreign person on your network reading a controlled drawing.

Still researching? Start with the CMMC gap assessment, our work on CMMC for aerospace manufacturers, or our breakdown of managed IT services.

One drawing in the wrong folder is a $1.2M question you'd rather answer before someone asks it.

Phase 2 of CMMC starts November 10, 2026. Primes are tightening supply chain requirements now, and the questionnaire asking who has access to your technical data is already in circulation. A scoping conversation takes about 30 minutes and tells you which of the three architectures you're looking at.