ITAR - International Traffic in Arms Regulations
ITAR Parts 123-125 Export Licensing

ITAR - International Traffic in Arms Regulations ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed: ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions

Parts 123-125 of ITAR establish the export licensing framework administered by DDTC. (1) Part 123 Licensing of Defense Articles: (a) Form DSP-5 Application for Permanent Export of Unclassified Defense Articles - the basic ITAR license type + must be obtained prior to export + valid for 4 years + specific quantities + values + end users + end uses; (b) Form DSP-73 Application for Temporary Export of Unclassified Defense Articles - for short-term exports including exhibitions + demonstrations + trade shows + repair + reverse engineering + valid for 4 years + must be returned to US; (c) Form DSP-61 Application for Temporary Import of Unclassified Defense Articles - for foreign-origin defense articles temporarily imported to US for repair + modification + processing; (d) Form DSP-83 Nontransfer and Use Certificate - end-use assurance from foreign government for sensitive items; (e) Form DSP-119 Amendment - to amend existing licenses. (2) Part 124 Agreements for Manufacture or Technical Assistance: (a) Manufacturing License Agreement (MLA) - authorisation for foreign person to manufacture defense articles using US technology + 22 CFR 124.1-124.13 + DDTC approval + 5-year term typical + provisions including diversion controls + export reporting + non-diversion certificates + end-use restrictions; (b) Technical Assistance Agreement (TAA) - authorisation for furnishing of defense services + technical data + training to foreign persons + 5-year term typical + DDTC approval + provisions including end-use + retransfer + record-keeping; (c) Distribution Agreement - 22 CFR 124.14 + authorisation for distribution of defense articles to foreign distributors; (d) Warehousing Agreement - authorisation for warehousing in foreign country. (3) Part 125 Technical Data and Defense Services: (a) Form DSP-5 for technical data export including drawings + specifications + software + processes + know-how (Part 125.4); (b) Classified Defense Articles + Technical Data per 22 CFR 125.3 - requires special licensing + DDTC + Department of Defense + Industrial Security Letter (ISL) per DD 254 + Facility Security Clearance + Personnel Security Clearance + Department of State Industrial Security Program; (c) Public Domain Technical Data per 22 CFR 125.4 - exempt from ITAR including (i) published information; (ii) general scientific + mathematical + engineering principles; (iii) information lawfully in public domain; (iv) data from public + accessible libraries + websites + academic publications. (4) Routed Export Transactions per 22 CFR 123.1: when foreign principal party in interest (FPPI) arranges export of US defense articles through US agent + US Principal Party in Interest (USPPI) responsibilities + Electronic Export Information (EEI) filing via Automated Export System (AES) + Customs and Border Protection (CBP) requirements. (5) DDTC DECCS Defense Export Control and Compliance System: online portal for license applications + approval tracking + amendment requests + record management + DDTC communications. (6) Commodity Jurisdiction (CJ): per 22 CFR 120.4 + entity may request DDTC determination of whether item is ITAR vs EAR + 60-day response + binding determination + interagency coordination with Commerce BIS + significant for classification disputes. (7) End-User and End-Use Verification: per 22 CFR 123.10 + 124.7 + 125.6 + verification of foreign end-users + foreign end-uses + non-diversion + reporting suspicious orders + Blue Lantern End-Use Monitoring Program. (8) Export Documentation: licenses must accompany exports + Commercial Invoice + Packing List + Bill of Lading + AES filing + customs entry + Department of Defense DD-2345 Militarily Critical Technology List (MCTL). (9) License Conditions and Provisos: ITAR licenses typically include provisos addressing (a) end-use restrictions; (b) non-retransfer; (c) reporting requirements; (d) destination restrictions; (e) quantity limits; (f) value limits; (g) party restrictions; (h) other DDTC-specific conditions. (10) AUKUS-Related Authorizations: 2024 + 2025 + AUKUS Pillar 2 (Australia + UK + US trilateral) reformed ITAR including (a) automatic Australia + UK exemptions for many ITAR-controlled items; (b) streamlined licensing for AUKUS partners; (c) expanded Open General License; (d) reduced licensing burden. Coordinates with DDTC DECCS + Defense Trade Controls Licensing (DTCL) + Defense Trade Controls Compliance (DTCC) + Defense Trade Controls Policy (DTCP) + Bureau of Political-Military Affairs + Industry Council Cooperation. ITAR Parts 123-125 Export Licensing applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 44 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP Top 10:2025 · 2 controls

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • EAR-Part748 Applications (Classification, Advisory, and License) and Documentation
  • 62351-8 Role-based access control (RBAC)

ISO 13485 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO 27799 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

ISO/SAE 21434 · 1 control

MITRE D3FEND · 1 control

MiFID II / MiFIR · 1 control

  • NIS2I-6 Access Control, Asset Management, and Physical Security

OWASP ASVS · 1 control

South Korea ISMS-P · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 44 it maps to, and the evidence behind each claim, over MCP and REST.