Exporting products that are regulated under the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR) requires more than simply shipping an item outside the United States. Defense contractors must understand product classifications, export authorization requirements, customer screening, recordkeeping obligations, and government regulations before any controlled product leaves the country.
Failure to follow U.S. export control regulations can result in shipment delays, financial penalties, loss of export privileges, and damage to an organization’s reputation. Whether your company manufactures defense articles, dual-use products, or controlled technical data, establishing a structured export compliance process is essential.
If you are unfamiliar with the differences between ITAR and EAR, read our guide “ITAR vs. EAR: What Defense Contractors Need to Know” to better understand how these regulations apply to your business.
What Is Considered an Export?
An export is more than physically shipping a product outside the United States. Under U.S. export control regulations, an export may include shipping hardware internationally, transferring controlled technical data, providing defense services to foreign persons, or electronically transmitting controlled information outside the United States.
Because exports take many forms, every transaction involving controlled products or technical data should be reviewed before it occurs to determine whether additional compliance requirements apply. The definition of export under ITAR is provided at 22 CFR § 120.50. The definition of export under EAR is provided at 15 CFR § 734.13.
ITAR vs. EAR: What Is the Difference?
Before exporting any product, organizations must determine whether the item falls under the International Traffic in Arms Regulations or the Export Administration Regulations.
ITAR, administered by the U.S. Department of State’s Directorate of Defense Trade Controls (DDTC), regulates defense articles, defense services, and technical data listed on the United States Munitions List (USML). These items are considered critical to U.S. national security and generally have stricter export controls.
The EAR, administered by the U.S. Department of Commerce’s Bureau of Industry and Security (BIS), governs commercial, dual-use, and certain military-related products. Many controlled products appear on the Commerce Control List (CCL), while others may be classified as EAR99.
Determining which regulation applies is one of the most important steps in the export process because it affects licensing requirements, shipping restrictions, documentation, and who may legally receive the product.

Step 1: Determine Whether the Product Is Subject to ITAR or EAR
Every export transaction should begin by determining which export regulations apply to the product.
Organizations should identify whether an item falls under ITAR, is listed on the Commerce Control List (CCL) under the EAR or is classified as EAR99. This determination establishes the compliance requirements that apply before the shipment can move forward.
Product classification should be performed by qualified personnel and documented as part of the organization’s export compliance program. Maintaining accurate classifications helps ensure consistency across future exports and supports internal audits. The DDTC commodity jurisdiction procedure is available for organizations that need formal government determination of whether a product is subject to ITAR.
Understanding EAR99
Not every product regulated by the EAR appears on the Commerce Control List.
Products that are not specifically identified on the CCL may be designated EAR99 under 15 CFR § 734.3. Although EAR99 items generally have fewer export restrictions than products assigned to an Export Control Classification Number (ECCN), they may still require authorization depending on the destination country, end user, or intended end use.
Many organizations mistakenly assume that EAR99 means a product can always be exported without restrictions. EAR99 products remain subject to the EAR and should be reviewed before every export transaction.
Step 2: Determine Whether Export Authorization Is Required
Once a product has been properly classified, the next step is determining whether government authorization is required before export.
Not every international shipment requires an export license. Instead, every export transaction should be reviewed to determine whether an export license, an EAR License Exception under 15 CFR Part 740, an ITAR License Exemption under 22 CFR Part 123, or no export authorization is required. The appropriate authorization depends on the product classification, destination country, end user, and intended end use.
ITAR license applications are submitted to DDTC through the DECCS system. EAR license applications are submitted to BIS through the SNAP-R system.
If a proposed transaction violates U.S. export control regulations or involves a prohibited destination, restricted party, or unauthorized end use, the shipment should not proceed.

Not sure where your organization stands with CMMC, ITAR, or federal cybersecurity requirements? The fastest way to get clarity is to talk with an expert. Book a call with our team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.
SCHEDULE YOUR FREE CONSULTATION!
Step 3: Screen Customers, End Users, and Destinations
Export compliance extends beyond the product itself. Organizations are responsible for understanding who will receive the product, where it will be shipped, and how it will ultimately be used.
Before approving an export, companies should screen customers, intermediaries, freight forwarders, and end users against applicable U.S. government restricted party lists, including the following.
The Denied Persons List, maintained by BIS, identifies individuals and entities that have been denied export privileges. The Entity List, maintained by BIS under [15 CFR Part 744, Supplement No. 4](https://www.ecfr.gov/current/title-15/subtitle-B/chapter-VII/subchapter-C/part-744/appendix-Supplement No. 4 to Part 744), identifies foreign parties subject to specific license requirements. The Specially Designated Nationals (SDN) List, maintained by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), identifies individuals and organizations subject to sanctions. The ITAR Debarred Parties List, maintained by DDTC, identifies parties who have been debarred from participating in defense trade.
The Consolidated Screening List maintained by the U.S. Department of Commerce’s International Trade Administration consolidates multiple restricted party lists into a single searchable tool.
Screening helps identify prohibited transactions before products are exported and significantly reduces compliance risk.
Step 4: Review Temporary Exports
Export controls apply to more than permanent international shipments.
Temporary exports can include equipment sent to trade shows, product demonstrations, evaluation units, loaned equipment, warranty replacements, and products shipped overseas for repair and returned. Although these exports may be temporary, they are still subject to applicable ITAR or EAR requirements. ITAR temporary export provisions are addressed at 22 CFR Part 123, Subpart D. Organizations should review each transaction before products leave the United States.

Common Export Compliance Mistakes
Many export compliance violations occur because organizations overlook routine procedures rather than intentionally violating regulations.
Some of the most common mistakes include shipping products before determining whether export authorization is required, misclassifying products under ITAR or EAR, failing to screen customers or end users, shipping products to restricted countries or prohibited parties, assuming EAR99 products never require authorization, maintaining incomplete export documentation, and allowing unauthorized access to controlled technical data.
Establishing standardized export procedures helps reduce these risks while improving operational efficiency. The DDTC compliance program guidance and BIS export compliance guidance provide official resources for building effective export compliance programs.
Recordkeeping Is a Critical Part of Export Compliance
Maintaining complete and accurate export records is an essential part of every export compliance program.
Organizations should retain documentation supporting each export transaction, including product classifications, export authorizations, internal approvals, shipping records, commercial invoices, customer information, and other compliance documentation.
Under 22 CFR § 122.5, ITAR registrants must maintain records of transactions including licenses, agreements, exports, and related documentation. Under 15 CFR § 762.2, EAR recordkeeping requirements specify which records must be maintained and for how long. Both ITAR and EAR generally require records to be maintained for five years from the date of export or from the expiration of a license, whichever is later.
Proper recordkeeping demonstrates due diligence, supports internal audits, and helps organizations respond efficiently to government inquiries.
Export Compliance Checklist
Before exporting any controlled product, verify that you have completed the following.
Determine whether the product is subject to ITAR or EAR. Verify the product classification against the USML or CCL, or confirm EAR99 status. Confirm the destination country. Verify the customer and ultimate end user. Screen all parties against the Consolidated Screening List, SDN List, Denied Persons List, Entity List, and ITAR Debarred Parties List. Review the intended end use. Determine whether an EAR License Exception, ITAR License Exemption, export license, or no authorization applies. Obtain all required internal approvals. Maintain complete export documentation and supporting records in accordance with 22 CFR § 122.5 and 15 CFR § 762.2.
Frequently Asked Questions
Do all ITAR products require an export license? Not always. Some exports may qualify for an ITAR License Exemption under 22 CFR Part 123, while others require authorization from DDTC. Every transaction should be reviewed individually.
What is EAR99? EAR99 is a designation for products regulated under the Export Administration Regulations that are not specifically listed on the Commerce Control List. Depending on the destination, end user, and intended use, EAR99 products may still require export authorization.
What is the difference between ITAR and EAR? ITAR regulates defense articles, defense services, and related technical data listed on the United States Munitions List, while the EAR regulates commercial, dual-use, and certain military-related products listed on the Commerce Control List.
Are replacement parts considered exports? Yes. Replacement parts, warranty shipments, demonstration equipment, repair shipments, and temporary exports may all be subject to U.S. export control regulations under ITAR or EAR and should be reviewed before shipment.
Who is responsible for export compliance? Export compliance is a shared responsibility across the organization. Employees involved in engineering, manufacturing, sales, logistics, shipping, purchasing, and management all contribute to maintaining compliance with U.S. export control regulations.
Additional Resources
For additional guidance on export control requirements, consult the following official government resources.
- International Traffic in Arms Regulations (ITAR) — 22 CFR Parts 120-130
- Export Administration Regulations (EAR) — 15 CFR Parts 730-774
- U.S. Department of State — Directorate of Defense Trade Controls (DDTC)
- U.S. Department of Commerce — Bureau of Industry and Security (BIS)
- DDTC — DECCS Export License Application System
- BIS — SNAP-R Export License Application System
- BIS — Export Compliance Guidance
- DDTC — Commodity Jurisdiction Procedure
- DDTC — ITAR Registration Requirements
- United States Munitions List (USML) — 22 CFR Part 121
- Commerce Control List (CCL) — 15 CFR Part 774
- Consolidated Screening List — U.S. Department of Commerce
- Specially Designated Nationals (SDN) List — OFAC
- Denied Persons List — BIS
- Entity List — BIS
- ITAR Debarred Parties List — DDTC
- ITAR Recordkeeping — 22 CFR § 122.5
- EAR Recordkeeping — 15 CFR § 762.2
- EAR License Exceptions — 15 CFR Part 740
- ITAR License Exemptions — 22 CFR Part 123
- National Archives — About CUI
The Bottom Line
Export compliance is not about slowing down business. It is about ensuring controlled products, technical data, and defense-related technologies are exported legally, securely, and efficiently. Organizations with well-defined export compliance programs are better positioned to reduce delays, avoid costly violations, and maintain eligibility to support the U.S. defense industrial base.
By implementing structured procedures for product classification, export authorization reviews, customer screening, recordkeeping, and ongoing compliance under 22 CFR Parts 120-130 and 15 CFR Parts 730-774, defense contractors can build stronger export compliance programs while reducing operational risk.
If your organization needs assistance navigating ITAR or EAR requirements, Brea Networks provides practical guidance to help defense contractors develop effective export compliance programs and protect their business for the future.

If your organization supports defense contracts and is unsure how CMMC timelines, SPRS requirements, or assessment readiness apply to you, now is the time to get clarity.
About Brea Networks
Brea Networks is a cybersecurity and compliance-focused IT partner dedicated to supporting Defense Industrial Base (DIB) contractors. We help organizations understand and implement the security requirements outlined in FAR 52.204-21, DFARS 252.204-7012, and the CMMC framework. From Level 1 self-assessments to Level 2 readiness and certification preparation, our team works alongside contractors to strengthen system security, define scope, prepare documentation, and build sustainable compliance programs that protect FCI and CUI.
What Changes: The Affirmation Requirement. The annual affirmation requirement applies at Level 3 just as it does at Level 2. Under 32 CFR § 170.22, a senior company official must submit an annual affirmation in SPRS confirming continued compliance within the CMMC Assessment Scope. Given that Level 3 status also satisfies Level 1 and Level 2 status requirements for the same scope, the annual affirmation at Level 3 covers the full body of requirements across all three levels.