Browse Definitions :
Definition

ITAR and EAR compliance

The International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR) are two important United States export control laws that affect the manufacturing, sales and distribution of technology.

The legislation seeks to control access to specific types of technology and the associated data. Its goal is to prevent the disclosure or transfer of sensitive information to a foreign national. 

ITR contains a United States Munitions List (USML) of restricted articles and services.  EAR contains a Commerce Control List (CCL) of regulated commercial items, including those items that have both commercial and military applications. 

To be ITAR or EAR compliant, a manufacturer or exporter whose articles or services appear on the USML or CCL lists must register with the U.S. State Department’s Directorate of Defense Trade Controls (DDTC). ITAR and EAR compliance can be problematic for a global corporation because the data related to a specific type of technology may need to be transferred over the Internet or stored locally outside the United States to make business processes flow smoothly. It is the responsibility of the manufacturer or exporter to take the necessary steps to certify that they are in compliance with the regulations. 

Export control laws provide for substantial penalties, both civil and criminal.  Failure to comply with ITAR can result in civil fines as high as $500,000 per violation, while criminal penalties include fines of up to $1,000,000 and 10 years imprisonment per violation.  Under EAR, maximum civil fines can reach $250,000 per violation. Criminal penalties can be as high as $1,000,000 and 20 years imprisonment per violation. 

 

ITAR [22 CFR 120-130] EAR [15 CFR 730-774]

Covers military items or defense articles.

Regulates goods and technology designed to kill or defend against death in a military setting.

Includes space related technology because of application to missile technology.

Includes technical data related to defense articles and services.

Strict regulatory licensing - does not address commercial or research objectives.

Regulates items designed for commercial purpose which could have military applications such as computers or software. 

Covers both the goods and the technology.

Licensing addresses competing interests and foreign availability. 

Combines commercial and research objectives with national security.

 

Learn more:

The U.S. Department of State has more information on ITAR.

The Bureau of Industry and Security has a webinar on EAR compliance.

The Bureau of Industry and Security has an Introduction to Commerce Department Export Controls. 

Shon Harris created a chart that shows different types of data protected by U.S. regulations and laws.

This was last updated in February 2012
SearchCompliance
  • ISO 31000 Risk Management

    The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for ...

  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

SearchSecurity
  • Pretty Good Privacy (PGP)

    Pretty Good Privacy or PGP was a popular program used to encrypt and decrypt email over the internet, as well as authenticate ...

  • email security

    Email security is the process of ensuring the availability, integrity and authenticity of email communications by protecting ...

  • Blowfish

    Blowfish is a variable-length, symmetric, 64-bit block cipher.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • direct access

    In computer storage, direct access is the process of reading and writing data on a storage device by going directly to where the ...

  • kibi, mebi, gibi, tebi, pebi and exbi

    Kibi, mebi, gibi, tebi, pebi and exbi are binary prefix multipliers that, in 1998, were approved as a standard by the ...

  • holographic storage (holostorage)

    Holographic storage is computer storage that uses laser beams to store computer-generated data in three dimensions.

Close