Back to Frameworks

US ITAR and EAR - Export Control and Data Security

United States (State Dept/BIS)
v2024 (ongoing updates)
12 domains
20 controls

The International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130) and Export Administration Regulations (EAR, 15 CFR Parts 730-774) are US export control regimes with significant cybersecurity and data protection implications. ITAR covers defence articles and technical data on the US Munitions List (USML), administered by the State Department Directorate of Defense Trade Controls (DDTC). EAR covers dual-use items on the Commerce Control List (CCL), administered by the Bureau of Industry and Security (BIS). Both require: access controls for controlled data, encryption of technical data, deemed export controls for foreign nationals, cloud computing restrictions, and cybersecurity incident reporting. Violations carry criminal penalties up to $1M and 20 years imprisonment.

Verified

US ITAR and EAR - Export Control and Data Security is a compliance framework from United States (State Dept/BIS) with 12 domains and 20 controls that map to 85 other frameworks. The largest domains are Data Security for Controlled Technical Data (3 controls), ITAR and EAR: Shipping, Recordkeeping and Corporate Change (3 controls), ITAR and EAR: Deemed Export and Access Management (2 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

Access Control

1 controls
Controls in the Access Control domain of US ITAR and EAR - Export Control and Data Security1 controls
CodeTitle
USEXPORT-2Access Controls, Deemed Export, Nationality

Classification

1 controls
Controls in the Classification domain of US ITAR and EAR - Export Control and Data Security1 controls
CodeTitle
USEXPORT-1Jurisdiction and Classification (ITAR USML / EAR CCL)

Cloud

1 controls
Controls in the Cloud domain of US ITAR and EAR - Export Control and Data Security1 controls
CodeTitle
USEXPORT-3Cloud and SaaS Use for Controlled Data

Data Security for Controlled Technical Data

3 controls
Controls in the Data Security for Controlled Technical Data domain of US ITAR and EAR - Export Control and Data Security3 controls
CodeTitle
US-ITAR-EAR-DS-01Technical Data Protection
US-ITAR-EAR-DS-02Cloud and Storage
US-ITAR-EAR-DS-03Access Controls

Enforcement

1 controls
Controls in the Enforcement domain of US ITAR and EAR - Export Control and Data Security1 controls
CodeTitle
USEXPORT-5Voluntary Disclosure, Enforcement, Penalties

ITAR and EAR: Deemed Export and Access Management

2 controls
Controls in the ITAR and EAR: Deemed Export and Access Management domain of US ITAR and EAR - Export Control and Data Security2 controls
CodeTitle
ITAR-EAR-DeemedExportDeemed Export Controls
ITAR-EAR-VisitorVisitor and Foreign National Access Management

ITAR and EAR: Registration and Classification

2 controls
Controls in the ITAR and EAR: Registration and Classification domain of US ITAR and EAR - Export Control and Data Security2 controls
CodeTitle
ITAR-EAR-FundamentalResearchFundamental Research and Public Domain
ITAR-EAR-RegistrationDDTC Registration and BIS Awareness

ITAR and EAR: Screening and End Use Diligence

2 controls
Controls in the ITAR and EAR: Screening and End Use Diligence domain of US ITAR and EAR - Export Control and Data Security2 controls
CodeTitle
ITAR-EAR-EndUseEnd Use and End User Diligence
ITAR-EAR-RestrictedPartyRestricted Party Screening

ITAR and EAR: Shipping, Recordkeeping and Corporate Change

3 controls
Controls in the ITAR and EAR: Shipping, Recordkeeping and Corporate Change domain of US ITAR and EAR - Export Control and Data Security3 controls
CodeTitle
ITAR-EAR-MAMergers, Acquisitions, and Divestitures
ITAR-EAR-RecordkeepingRecordkeeping
ITAR-EAR-ShippingPhysical Export Controls and Shipping

ITAR and EAR: Technical Data Protection

2 controls
Controls in the ITAR and EAR: Technical Data Protection domain of US ITAR and EAR - Export Control and Data Security2 controls
CodeTitle
ITAR-EAR-EncryptionEncryption of Technical Data and Technology
ITAR-EAR-ITSecurityIT Security Controls Supporting Export Compliance

ITAR and EAR: Training

1 controls
Controls in the ITAR and EAR: Training domain of US ITAR and EAR - Export Control and Data Security1 controls
CodeTitle
ITAR-EAR-TrainingExport Compliance Training

Licensing

1 controls
Controls in the Licensing domain of US ITAR and EAR - Export Control and Data Security1 controls
CodeTitle
USEXPORT-4Licensing, Recordkeeping, Self-Assessment

Your Compliance Coverage

If you comply with US ITAR and EAR - Export Control and Data Security, you already cover:

Maps to 85 other frameworks

20 total controls
Virginia CDPA
3 source controls mapped|2 target controls covered
15%
Uruguay DPL
3 source controls mapped|3 target controls covered
15%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
3 source controls mapped|5 target controls covered
15%
ISO 13485
3 source controls mapped|8 target controls covered
15%
Bahrain PDPL
3 source controls mapped|4 target controls covered
15%
Saudi Arabia PDPL
3 source controls mapped|4 target controls covered
15%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
3 source controls mapped|7 target controls covered
15%
ISO/IEC 27011:2024
3 source controls mapped|6 target controls covered
15%
NIST SP 800-53 Rev 5
3 source controls mapped|7 target controls covered
15%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|4 target controls covered
15%
ISO 27799
3 source controls mapped|8 target controls covered
15%
ISO 20000-1
3 source controls mapped|2 target controls covered
15%
ISO 27043
3 source controls mapped|7 target controls covered
15%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
3 source controls mapped|4 target controls covered
15%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|2 target controls covered
15%
ISO/SAE 21434
3 source controls mapped|7 target controls covered
15%
ISO/IEC 27010:2015
3 source controls mapped|3 target controls covered
15%
South Korea ISMS-P
3 source controls mapped|3 target controls covered
15%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
3 source controls mapped|2 target controls covered
15%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
3 source controls mapped|1 target controls covered
15%
BSI IT-Grundschutz
3 source controls mapped|4 target controls covered
15%
APPI
3 source controls mapped|2 target controls covered
15%
NSA Guidance for Transition to Quantum-Resistant Cryptography
2 source controls mapped|3 target controls covered
10%
ISO/IEC 27400:2022
2 source controls mapped|3 target controls covered
10%
PCI SSF
2 source controls mapped|1 target controls covered
10%
ISO 27017
2 source controls mapped|6 target controls covered
10%
Uganda Data Protection and Privacy Act (2019)
2 source controls mapped|4 target controls covered
10%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
2 source controls mapped|1 target controls covered
10%
ISO 27005
2 source controls mapped|1 target controls covered
10%
NIST SP 800-190
2 source controls mapped|6 target controls covered
10%
3GPP 5G Security Architecture (TS 33.501)
2 source controls mapped|2 target controls covered
10%
ISO 27018
2 source controls mapped|7 target controls covered
10%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
2 source controls mapped|3 target controls covered
10%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|2 target controls covered
10%
FFIEC IT Examination Handbook
2 source controls mapped|1 target controls covered
10%
FBI CJIS Security Policy
2 source controls mapped|3 target controls covered
10%
ISO 19011
2 source controls mapped|2 target controls covered
10%
10%
ISO 31000:2018
2 source controls mapped|2 target controls covered
10%
PCI PIN Security
2 source controls mapped|1 target controls covered
10%
TISAX - Trusted Information Security Assessment Exchange
2 source controls mapped|1 target controls covered
10%
PCI P2PE
2 source controls mapped|1 target controls covered
10%
Secure by Design: A Guide for Manufacturers (CISA)
2 source controls mapped|1 target controls covered
10%
UK Open Banking Standard
2 source controls mapped|2 target controls covered
10%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|2 target controls covered
10%
Sigstore - Software Artifact Signing and Verification
2 source controls mapped|1 target controls covered
10%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
2 source controls mapped|1 target controls covered
10%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|2 target controls covered
10%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|1 target controls covered
10%
W3C Verifiable Credentials (VC) Data Model 2.0
2 source controls mapped|1 target controls covered
10%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|3 target controls covered
10%
Canada ITSG-33 - IT Security Risk Management
2 source controls mapped|2 target controls covered
10%
UK Age Appropriate Design Code (Children's Code)
1 source controls mapped|2 target controls covered
5%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|3 target controls covered
5%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
5%
ISO 26000:2010
1 source controls mapped|1 target controls covered
5%
Barbados Data Protection Act 2019
1 source controls mapped|2 target controls covered
5%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|2 target controls covered
5%
Telecommunications Sector Security Reforms (TSSR)
1 source controls mapped|1 target controls covered
5%
Nebraska Data Privacy Act
1 source controls mapped|2 target controls covered
5%
5%
GDPR
1 source controls mapped|3 target controls covered
5%
5%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
5%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
5%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
5%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|2 target controls covered
5%
IEC 62443
1 source controls mapped|3 target controls covered
5%
ISO 27019
1 source controls mapped|3 target controls covered
5%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|1 target controls covered
5%
US OFAC Sanctions Compliance Framework
1 source controls mapped|4 target controls covered
5%
API 1164
1 source controls mapped|3 target controls covered
5%
ITIL 4
1 source controls mapped|1 target controls covered
5%
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
1 source controls mapped|1 target controls covered
5%
UK Security and Emergency Measures Direction (SEMD) - Water Industry
1 source controls mapped|1 target controls covered
5%
SOC 2
1 source controls mapped|1 target controls covered
5%
NIST SP 1800-32
1 source controls mapped|3 target controls covered
5%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|1 target controls covered
5%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
5%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
5%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
5%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
1 source controls mapped|1 target controls covered
5%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
5%

What is US ITAR and EAR - Export Control and Data Security and who does it apply to?

US ITAR and EAR - Export Control and Data Security is a compliance framework from United States (State Dept/BIS) with 12 domains and 20 controls. The International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130) and Export Administration Regulations (EAR, 15 CFR Parts 730-774) are US export control regimes with significant cybersecurity and data protection implications. ITAR covers defence articles and technical data on the US Munitions List (USML), administered by the State Department Directorate of Defense Trade Controls (DDTC). EAR covers dual-use items on the Commerce Control List (CCL), administered by the Bureau of Industry and Security (BIS). Both require: access controls for controlled data, encryption of technical data, deemed export controls for foreign nationals, cloud computing restrictions, and cybersecurity incident reporting. Violations carry criminal penalties up to $1M and 20 years imprisonment. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does US ITAR and EAR - Export Control and Data Security actually require?

US ITAR and EAR - Export Control and Data Security has 20 controls organised across 12 domains. The largest domains are Data Security for Controlled Technical Data (3 controls), ITAR and EAR: Shipping, Recordkeeping and Corporate Change (3 controls), ITAR and EAR: Deemed Export and Access Management (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of US ITAR and EAR - Export Control and Data Security do I already cover?

US ITAR and EAR - Export Control and Data Security maps to 85 other compliance frameworks. The top mapping partners are Virginia CDPA (15% coverage), Uruguay DPL (15% coverage), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement US ITAR and EAR - Export Control and Data Security?

Start your US ITAR and EAR - Export Control and Data Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US ITAR and EAR - Export Control and Data Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required