ITAR, EAR and CUI work, under control.
Regulated hardware is where schedule and compliance risk is highest. Our process keeps technical data off the internet and puts a named step, and a sign-off, between your program and every supplier.
The short version
Controlled requests never carry technical data through this website. You tell us about the program: jurisdiction if known, clauses, DPAS rating, quantities and dates. We then work through ten documented release steps with you. Technical data moves only after every step is signed off, only over a channel your security team approves, and only to U.S. persons and suppliers whose authorization we have verified.
What we never accept online
- Technical data subject to the ITAR (22 CFR 120 to 130), including drawings, models and process data for USML items.
- Technology controlled under the EAR with an ECCN other than EAR99.
- Controlled Unclassified Information, including covered defense information under DFARS 252.204-7012.
- Anything your export compliance team has not yet classified.
The upload control on the request form only unlocks when a requester selects a commercial classification and attests that the files contain none of the above. The server rejects files on any other request.
Program intake
For a controlled or unclassified request the form collects program facts only: jurisdiction, USML category or ECCN if your team has determined it, the clauses that flow down, any DPAS rating, the transfer method you prefer and an unclassified program identifier. It also asks the requester to acknowledge that no technical data will be requested until the release steps are complete.
The ten release steps
| Step | What happens |
|---|---|
| 01 | Customer confirmed export jurisdiction and classification in writing |
| 02 | Mutual NDA fully executed |
| 03 | Technology control plan acknowledged for this program |
| 04 | U.S. person access list recorded for our team |
| 05 | Supplier DDTC registration or EAR authorization verified |
| 06 | Supplier NIST SP 800-171 / SPRS score and CMMC status verified |
| 07 | Flow-down clauses and NDA issued to supplier |
| 08 | Secure transfer channel agreed and tested |
| 09 | Technical data released to authorized recipients only |
| 10 | Data returned or destroyed at closeout, certificate filed |
Each step is recorded against your request with a date. Our team will not release data while any step is open, and you can ask for the status of every step at any time.
Supplier verification
For controlled work we verify, for each supplier, the authorization the work requires (for ITAR manufacturing, current registration with the State Department's Directorate of Defense Trade Controls), that only U.S. persons will access the data, the supplier's NIST SP 800-171 assessment score in SPRS where DFARS 252.204-7012 applies, its CMMC status as the contract requires, and its quality system and special process approvals for the part.
Flow-down clauses
| Clause | What it requires |
|---|---|
| FAR 52.204-21 | Basic safeguarding of covered contractor information systems (15 security requirements) for federal contract information. |
| DFARS 252.204-7012 | Safeguarding covered defense information: NIST SP 800-171 controls, cyber incident reporting to DoD within 72 hours, flow-down to subcontractors handling CDI. |
| DFARS 252.204-7019 / 7020 | NIST SP 800-171 DoD assessment requirements; a current assessment score posted in SPRS. |
| DFARS 252.204-7021 | Contractor compliance with the CMMC level required by the contract, flowed to subcontractors at the level their work requires. |
| DFARS 252.225-7009 | Restriction on certain specialty metals (for example titanium, certain steels and nickel alloys) to qualifying countries, with documentation. |
| DFARS 252.246-7007 / 7008 | Counterfeit electronic part detection and avoidance system, and the sourcing hierarchy for electronic parts. |
Your purchase order and prime contract govern which clauses apply. We flow them to suppliers in writing along with the NDA, and keep the acknowledgements on file.
Secure transfer
The channel is chosen with your security team: your own managed file transfer or portal, DoD SAFE where a DoD party is involved, end-to-end encrypted email suited to CUI, or encrypted media hand carried. We test the channel with a non-sensitive file first and confirm each recipient against the access list before release.
Closeout and records
At closeout, controlled technical data held by our team is returned or destroyed and each supplier is instructed to do the same, with a written certificate on file. ITAR recordkeeping requirements at 22 CFR 122.5 call for records to be maintained for five years, and we keep records for the period each applicable regulation requires.
Questions
Can you take ITAR work?
We take controlled requests through a defined process rather than through the website. You submit program details, never technical data. Before any data moves we confirm jurisdiction with you in writing, execute the NDA, record a U.S. person access list, verify each supplier's DDTC registration or other authorization and cybersecurity posture, issue flow-downs and agree a secure channel. Where an activity requires our own registration or authorization, we obtain it before performing that activity.
Who decides whether my part is ITAR or EAR?
The owner of the design is responsible for the jurisdiction and classification of its technical data and hardware. We ask your export compliance team to confirm it in writing at step one. If it has not been determined, we treat the request as controlled until it is, and we do not ask for files in the meantime.
How do you move controlled files?
Through a channel your security team approves: your own managed file transfer or portal, DoD SAFE where a DoD party is involved, end-to-end encrypted email suited to CUI, or encrypted media hand carried. The channel is tested before release and every recipient is on the recorded access list.
What happens to my data when the job ends?
At closeout we return or destroy controlled technical data held by our team and instruct each supplier to do the same, then file a written certificate. Records required by regulation, such as ITAR transaction records, are kept for the period the regulation requires.
What is the current status of CMMC?
The DFARS rule implementing CMMC took effect on November 10, 2025. On July 13, 2026 DoD suspended the move to Phase 2, which would have made third-party Level 2 certification the default on November 10, 2026, pending a task force review. DFARS 252.204-7012, NIST SP 800-171 and SPRS scores still apply, so we verify those for every supplier on controlled work.
Sources
Controlled
request?
Submit program details only. We take it from there with you, step by step.
Start a controlled request