CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

ITAR

How do ITAR technical data rules and NIST SP 800-171 fit together?

ITAR and NIST SP 800-171 protect overlapping information for different reasons. The International Traffic in Arms Regulations control who may receive defense related technical data, with the goal of keeping it from unauthorized foreign persons. NIST SP 800-171, required through DFARS 252.204-7012, sets the security requirements for systems that hold Controlled Unclassified Information, which includes export controlled information. A manufacturer holding ITAR drawings usually has to satisfy both at once. This article explains where they overlap, where they do not, and how the encryption provision in 22 CFR 120.54 changes how technical data can be stored and sent.

What is ITAR technical data?

ITAR technical data is information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance or modification of a defense article on the United States Munitions List. It includes blueprints, drawings, photographs, plans, instructions and documentation, in any form. Software directly related to defense articles is treated in a similar way.

The ITAR definition excludes some things, such as information in the public domain and general scientific, mathematical or engineering principles commonly taught in schools. Whether a particular file is technical data is a classification question, and the answer belongs to the company's export compliance function, not to IT. What IT needs to know is which data has been classified that way and where it lives.

How does ITAR differ from NIST SP 800-171?

ITAR controls who may access the data, while NIST SP 800-171 controls how the systems holding it are secured. ITAR asks whether a foreign person could receive technical data without an authorization. NIST SP 800-171 asks whether the system has access control, logging, encryption, incident response and the other requirements in place.

Meeting one does not meet the other. A system can satisfy all 110 requirements and still allow an unauthorized foreign person to read an ITAR drawing if nobody checked who the users are. A system can restrict access perfectly by citizenship and still fail CMMC because nobody reviews its logs. A sound program designs for both questions from the start.

Is ITAR technical data also CUI?

Usually yes, when it is created or received under a DoD contract. Export controlled information is one of the categories in the federal CUI program, so ITAR technical data handled under a defense contract is generally CUI as well, and DFARS 252.204-7012 applies to the systems that hold it.

That overlap is useful. One enclave, designed with both sets of rules in mind, can hold both. The access rules are tighter than NIST SP 800-171 alone would require, because export control adds the question of who is a U.S. person, but the infrastructure, the documentation and the evidence can be shared.

What does DFARS 252.204-7012 add for technical data?

It adds security, reporting and cloud requirements on top of the export rules. Covered defense information, which includes controlled technical information and other CUI, must be protected by NIST SP 800-171. Cyber incidents affecting it must be reported to DoD within 72 hours of discovery, with images and relevant data preserved for DoD to review.

If a cloud service stores, processes or transmits covered defense information, the clause requires that the provider meet security requirements equivalent to the FedRAMP Moderate baseline and comply with the clause's incident reporting, malicious software and forensic provisions. The clause also flows down to subcontractors whose work involves covered defense information, so a prime's obligations become its suppliers' obligations.

What is the 22 CFR 120.54 encryption carve out?

22 CFR 120.54 lists activities that are not exports, and one of them covers sending, taking or storing unclassified technical data that is protected by end to end encryption meeting the standard the rule sets. When the conditions are met, the transfer or storage is not treated as an export, even if the encrypted data passes through or rests on servers outside the United States.

The rule sets its own conditions. The encryption must be end to end, meaning the data is encrypted before it leaves the originator's security boundary and stays encrypted until the intended recipient decrypts it. The cryptography must be validated under the FIPS 140 standard or be of at least equivalent effectiveness as the rule describes. The data must not be sent to a person in, or stored in, a country the ITAR proscribes. Read the rule text itself before relying on it.

Why does the carve out matter in practice?

It matters because cloud services rarely let a customer see every location where data rests or every person who administers the infrastructure. Without the carve out, a contractor would need certainty that no unauthorized foreign person could ever access the unencrypted data on a provider's systems. With it, properly applied encryption can change that analysis.

It is not a shortcut around the other rules. The data is still CUI, DFARS 7012 still applies, and the people who decrypt it must still be authorized to receive it. Key management becomes central. If the provider holds the keys, the conditions may not be met, so the design has to show who controls the keys and where decryption happens.

How should a manufacturer set up systems for both rules?

Start with classification and data flow: which customers send ITAR technical data, in what form, and who needs it. Then design an enclave where only authorized users can reach that data, with identity proofing that records U.S. person status where it matters, and with the 110 NIST SP 800-171 requirements implemented across it.

Choose platforms that support the obligations contractually as well as technically. Document the encryption approach and key custody if the 120.54 provision is relied on. Train the people who handle drawings, including on the shop floor, because a printed drawing handed to the wrong visitor is an export problem no firewall will catch. Keep the export compliance function and the security program talking, since each holds half of the answer.

Where do contractors most often get this wrong?

The most common mistake is assuming that a compliant cloud platform settles the export question. The platform is a foundation, but access decisions, foreign national employees, offshore support from IT vendors and visiting engineers are all company decisions that the platform does not make for you.

The second is treating ITAR as a paperwork exercise owned only by contracts staff. Technical data lives in CAD systems, file shares, email and machine controllers. If the security program does not know which files are controlled and where they go, it cannot protect them, and the export compliance function cannot show that they were protected.

Which engagements cover this?

ITAR cybersecurity program

Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.

CUI enclave design

CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

What else do readers ask?

Does GCC High make us ITAR compliant?

No platform makes a company ITAR compliant. A platform built for export controlled data can support the obligations, but access decisions, classification and procedures remain the company's responsibility.

Can ITAR technical data be stored in a commercial cloud?

It can when the conditions are met, for example when the data is protected as 22 CFR 120.54 describes and the cloud service meets DFARS 252.204-7012 for covered defense information. Confirm both before moving data.

Who decides whether a file is ITAR technical data?

The company's export compliance function, using the ITAR definitions and the United States Munitions List. The security program then protects what has been classified.

Does the 120.54 provision remove the need for NIST SP 800-171?

No. It concerns whether a transfer or storage is an export. If the data is covered defense information, DFARS 252.204-7012 and NIST SP 800-171 still apply.

This article is general information about the regulations as written, not legal advice. Read your contract clauses and the regulation text, and take legal advice where the answer matters.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.