Your organization needs to be ITAR compliant. We can help.

Apr 9, 2021 | Cyber Security, IT News

Last year in 2020, V2 Systems became ITAR registered, and we posted an article about what that means for you as a valued V2 partner. Today we’ll cover ITAR a bit more, give you a brief overview over its primary components and explain how your organization can become ITAR compliant. And yes, you definitely need to be compliant. There are stiff penalties if you’re not.

What is ITAR?

As we mentioned before, the International Traffic in Arms Regulations is the United States regulation that controls the manufacture, sale and distribution of defense- and space-related articles and services as defined in the United States Munitions List. What’s important to note is that it doesn’t just cover physical weapons and military hardware, but also plans, diagrams, photos and other documentation used to build ITAR-controlled military gear. This is referred to by ITAR as “technical data.” Access to physical materials or technical data related to defense and military technologies is restricted to U.S. citizens only.

Who does ITAR apply to?

Any company that handles, manufactures, designs, sells or distributes items on the USML must be ITAR compliant. The State Department’s Directorate of Defense Trade Controls (DDTC) manages the list of companies who can deal in USML goods and services, and it is up to each company to establish policies to comply with ITAR regulations. This includes wholesalers, distributors, computer software and hardware vendors, third-party suppliers and contractors. Essentially, every company in the supply chain needs to be ITAR compliant. If company A sells a part to company B and then company B sells the same part to a foreign power, company A is also in violation of ITAR. This fact alone should demonstrate the importance of V2 Systems being officially registered — and why you need to be compliant as well.

ITAR and Overseas Companies

As stated above, only U.S. citizens can access items on the USML list. This can be problematic for U.S.-based companies with overseas operations, as they are prohibited from sharing ITAR technical data with employees locally hired, unless they gain authorization from the State Department. This rule applies to U.S. companies working with non-U.S. subcontractors, too.

The United States Munitions List

There are 21 categories of “Defense Articles” in the USML. Anything that appears on this list is subject to ITAR regulation.

  1. Firearms, Close Assault Weapons and Combat Shotguns
  2. Guns and Armament
  3. Ammunition/Ordnance
  4. Launch Vehicles, Guided Missiles, Ballistic Missiles, Rockets, Torpedoes, Bombs and Mines
  5. Explosives and Energetic Materials, Propellants, Incendiary Agents and Their Constituents
  6. Surface Vessels of War and Special Naval Equipment
  7. Ground Vehicles
  8. Aircraft and Related Articles
  9. Military Training Equipment and Training
  10. Personal Protective Equipment
  11. Military Electronics
  12. Fire Control, Laser, Imaging and Guidance Equipment
  13. Materials and Miscellaneous Articles
  14. Toxicological Agents, Including Chemical Agents, Biological Agents and Associated Equipment
  15. Spacecraft and Related Articles
  16. Nuclear Weapons Related Articles
  17. Classified Articles, Technical Data and Defense Services Not Otherwise Enumerated
  18. Directed Energy Weapons
  19. Gas Turbine Engines and Associated Equipment
  20. Submersible Vessels and Related Articles
  21. Articles, Technical Data and Defense Services Not Otherwise Enumerated

Your organization needs to be ITAR compliant. We can help.As you can see, that list covers a lot. If you’re not careful, you could miss something and then get hit with a nasty million dollar fine or even prison time. This is especially true for items 17 and 21 which include “articles, technical data and defense services not otherwise enumerated.” V2 Systems can take that pressure off of you and make sure you’re fully compliant with ITAR. For more information, contact us today for a free consultation.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Backups Alone Are Not Enough: What True Recovery Looks Like in 2026

Backups are a critical part of business resilience, but they are not the same as recovery. In 2026, small businesses and government contractors need validated backups, tested recovery procedures, clear response plans, and secure restoration processes to keep operations moving when ransomware, outages, or system failures occur.

Downtime Is a Cybersecurity Problem, Not Just an IT Problem

Downtime can affect payroll, customer service, compliance, productivity, revenue, and reputation. For small businesses and government contractors, outages are no longer just technical issues. This blog explains why downtime should be treated as a cybersecurity and business resilience problem, and how organizations can better prepare for disruptions.

Zero Trust Without the Buzzwords: What It Actually Looks Like in Practice

Zero Trust is often discussed as a complex cybersecurity strategy, but at its core, it is about verifying access, limiting unnecessary permissions, and reducing risk. This blog explains what Zero Trust actually looks like in practice for small businesses and government contractors — without the buzzwords, hype, or confusion.

Access Creep Is a Business Risk: How Over-Permissioned Users Create Exposure

Access creep happens when users accumulate permissions over time and keep access they no longer need. For small businesses and government contractors, this creates unnecessary cybersecurity, compliance, and operational risk. This blog explains how over-permissioned users increase exposure and what organizations can do to strengthen access controls, reduce privilege misuse, and improve audit readiness.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic