Skip to content
Back to Compliance Academy

Product context is educational relevance, not a feature-status or compliance claim.

Context: Visitor
Context: Trade
Context: Regulated Access
Export Controls
Front Desk
Compliance Manager
Admin
Executive

What is ITAR?

The International Traffic in Arms Regulations, 22 CFR Parts 120–130, which govern defense articles, defense services, technical data, and related exports under State Department authority.

Last Reviewed: 2026-09-19Plain-English reference · not legal advice

Plain-English Summary

ITAR implements export controls administered by the State Department’s Directorate of Defense Trade Controls. The rules define defense articles and technical data, regulate specified defense services and exports, and include registration, licensing, agreement, and recordkeeping requirements. Whether a particular item, activity, person, or transfer is covered must be determined from the regulations and the facts.

Why This Matters

ITAR can treat a release of controlled technical data to a foreign person in the United States as an export. That makes access to technical data important at facilities handling ITAR-controlled work. It does not mean every foreign visitor is automatically prohibited or that ITAR itself prescribes one universal visitor-badge or escort workflow.

Explanation Depth

Concept Explanation

ITAR controls certain U.S. defense items, services, and technical information. One important rule is that releasing controlled technical data to a foreign person in the United States can count as an export. Facilities therefore need to control who can reach the controlled information, but the regulation does not say that every foreign visitor must automatically be denied.

When You'll See This in SecurePoint

SecurePoint Visitor can capture U.S.-person or foreign-person status, route foreign-person access for host or security review, apply customer-configured escort or area rules, and preserve the access decision. SecurePoint does not classify items or make the customer’s export-licensing determination, and foreign-person status alone should not be described as an automatic denial.

What You Should Do Next

Confirm jurisdiction and classification of the defense article, service, or technical data involved; identify where controlled technical data can be accessed; determine whether a proposed transfer or release requires authorization; and apply the facility’s documented access controls to prevent unauthorized releases. Use the export-control function or qualified counsel for consequential jurisdiction and licensing decisions.

What Can Go Wrong

Common errors include assuming that physical presence alone determines an ITAR violation, treating foreign-person status as an automatic denial instead of analyzing access to controlled articles or data, confusing ITAR with CMMC physical-security requirements, or assuming every U.S.-based employee is a U.S. person for ITAR purposes.
What is ITAR? | Compliance Academy | SecurePoint USA