CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

ITAR cybersecurity program

How do you protect ITAR technical data in your IT environment?

Where a DoD contract carries DFARS 252.204-7012, export controlled technical data is Controlled Unclassified Information and the safeguarding requirements are NIST SP 800-171. Protecting it means access limited to authorized persons and storage in an environment built for it. Capital Cyber designs and leads that cybersecurity program. Export classification, licensing and registration remain decisions for your empowered official and export counsel.

Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.

Book a 30 minute call

What does the engagement include?

  • A map of where ITAR technical data is stored and how it moves
  • Access controls that limit the data to authorized persons
  • Environment or enclave design for export controlled data
  • Alignment with the NIST SP 800-171 requirements
  • Incident response procedures that cover export controlled data
  • Coordination with your empowered official and export counsel

Who is this for?

Manufacturers and engineering firms that receive ITAR controlled drawings, specifications or technical data from a prime or the government and need their IT environment to protect it.

What do you get?

A data map for export controlled informationAn access modelAn environment designSSP sections covering the data

How does the engagement run?

  1. A 30 minute call about your contracts, your deadline and where your sensitive data lives.
  2. A written scope that names the deliverables, the schedule and who does what.
  3. A kickoff with your leadership and your IT provider, then regular progress briefings until the deliverables are accepted.

No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.

What else do buyers ask?

Is ITAR the same as CMMC?

No. ITAR, the International Traffic in Arms Regulations at 22 CFR Parts 120 through 130, is administered by the State Department and controls the export of defense articles and technical data. CMMC verifies cybersecurity for CUI on defense contracts. When ITAR technical data arrives under a defense contract, both apply.

Do we need GCC High for ITAR data?

Not by name. ITAR restricts access by foreign persons, so unless the data is protected under the ITAR encryption carve-out at 22 CFR 120.54, the environment must keep it to authorized persons, including the provider's own support staff. Many contractors choose Microsoft GCC High for this reason, and we help you decide whether it fits.

Do you handle export licensing?

No. Registration, classification and licensing are legal and compliance decisions for your empowered official and export counsel. We protect the data in your IT environment and work alongside them.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.