ITAR vs. EAR: What’s the Difference?
You know ITAR and EAR both control exports. The confusing part is knowing which one applies and what changes when it does.
Engineers and startup operators usually meet export controls while trying to accomplish a perfectly ordinary task: buy components, qualify a contract manufacturer, debug a prototype, or give a contractor access to technical files. Then somebody asks whether the work is ITAR or EAR controlled, and everyone suddenly finds the conference-room carpet fascinating.
You do not need to become an export-control attorney. You need to recognize the few moments when ITAR or EAR changes what you can buy, ship, share, upload, or explain.
This article gives you that working knowledge. It is a decision aid, not legal advice or a substitute for a formal classification review.
Export Controls Do Not Involve Tariffs
One of the first things to understand is that ITAR and EAR are export controls. They have nothing to do with tariffs, which fall under import controls.
Import controls govern what enters the United States. You may already be familiar with HTS codes, which are used for customs classification, duties, country of origin, and related import requirements. HTS codes have nothing to do with export controls, ITAR, or EAR.
Export controls govern what may leave the United States and what may be released to a foreign person. That release can involve a physical product, software, source code, technical data, engineering support, or access to a controlled file.
With very few exceptions, you will encounter two primary export-control regimes:
- ITAR, administered by the State Department
- EAR, administered by the Commerce Department
The hard part is identifying which regime owns your item or activity before parts and files begin moving.
Read More: Navigating Tariffs: What Manufacturers Need to Know
What is ITAR?
ITAR stands for the International Traffic in Arms Regulations. It covers defense articles, defense services, and related technical data identified through the U.S. Munitions List, or USML. The State Department’s Directorate of Defense Trade Controls, usually shortened to DDTC, administers ITAR and the USML.
The purpose of ITAR is to keep sensitive U.S. defense technology from reaching non-U.S. persons, organizations, or governments without authorization.
ITAR can apply to:
- A defense article sent outside the United States
- Bills of Materials
- Drawings or production instructions supplied to a non-U.S. person
- Engineering assistance related to a defense article
- Repair, testing, maintenance, or modification information
The weird part is that the physical component may be sitting on your desk, while the thing ITAR actually cares about is the CAD file, test report, or supplier portal access that explains how it works. By a non-U.S. person, they generally mean anyone who is not a U.S. citizen, lawful permanent resident, or certain protected individual.
DDTC reviews about 1,000 compliance-related matters in a typical year, so most subcontractors are far more likely to encounter ITAR through a prime contractor than through direct contact with the government. The prime may ask you to confirm your ITAR registration or U.S.-person status, disclose foreign ownership or foreign employees, explain who can access drawings, complete an export-control questionnaire, restrict access to files and production areas, or provide evidence of training and procedures. It may also audit you or ask questions after a suspected disclosure.
The prime is doing this because it needs to know that controlled hardware and technical data remain properly handled throughout its supply chain. Applicable DoD contract clauses also make contractors responsible for complying with export-control laws, which gives prime contractors a very practical reason to scrutinize their subcontractors.
ITAR-controlled work therefore calls for serious attention to access. Who can open the file? Who can join the technical call? Who can see the screen during a design review? You can create an ITAR problem through completely ordinary actions, even when nobody involved has bad intentions.
What is EAR?
EAR stands for the Export Administration Regulations. The Commerce Department’s Bureau of Industry and Security, or BIS, administers it.
EAR covers everything except what is controlled under ITAR or a few narrow exceptions (see below).
The real question is whether the item appears on the Commerce Control List, or CCL. The CCL is the list of items subject to specific controls under the EAR. If an item appears on the CCL, it has an Export Control Classification Number, or ECCN. An ECCN is a five-character code used to identify an item’s control category and the rules that apply to it. In plain English, ECCN = red flag.
The ECCN tells you:
- Whether the item requires a license
- Why the item is controlled
- Whether an exception may apply
- Which end-use or end-user restrictions deserve review
An item not described by an ECCN is generally classified as EAR99. You do not need to worry about EAR99 transactions unless you are exporting to sketchy destinations, weapons producers, evildoers, or somebody whose business model has a strong “international incident” vibe. See below for details.
What falls outside ITAR and EAR?
A small number of items and activities fall under other U.S. authorities, and therefore neither ITAR nor EAR applies.
Nuclear equipment and material may require review under Nuclear Regulatory Commission rules. Certain unclassified nuclear technology and assistance may fall under Department of Energy regulations. A real nuclear connection deserves specialist review. Guessing your way through Part 810 is a poor use of engineering intuition.
Sanctions add another layer. The Treasury Department’s Office of Foreign Assets Control, or OFAC, administers sanctions involving designated countries, organizations, and people. Sanctions can block or restrict a transaction even when the item itself looks unremarkable.
OFAC is generally a transaction overlay rather than your normal product-classification system. You still need to screen the parties and destination.
Which Roles Need to Care About Export Controls?
Unless you’re at a big company, export compliance probably falls to whoever notices the problem first. If you’re reading this article, it’s probably you.
The two places where export controls usually become real are sales and procurement. Sales is sending products, software, or services to customers. Procurement and engineering are sending parts, files, data, and technical help to suppliers.
Sales operations
Sales needs to know whether the product, software, or technical information being sold is subject to any special export controls. That is the starting point.
Once an item is ITAR controlled or has an ECCN, ordinary sales activity can create problems. A salesperson may send technical files to a prospective customer, arrange a demo for non-U.S. personnel, promise overseas support, or accept an order without checking the final destination.
EAR99 items do not require any attention, except in the rare cases where the customer, destination, or end use raises a concern. The basic job for sales is to recognize when an item carries special controls and avoid moving the deal forward on autopilot.
Procurement and engineering
Just like sales, procurement and engineering need to know whether the item, software, or technical data involved is ITAR controlled or has an ECCN.
The special controls you are most likely to encounter are ITAR controls, and the ITAR problem you are most likely to create is exposing technical data to a non-U.S. person. That can happen through a drawing package, shared folder, supplier portal, email attachment, or an ordinary technical conversation.
That includes very normal requests such as:
- Sending fabrication drawings to an overseas CM
- Giving a foreign contractor repository access
- Sharing firmware with a test-services company
- Shipping samples abroad for repair or failure analysis
- Providing controlled test data during supplier qualification
- Explaining how to manufacture or modify a controlled assembly
Nobody in these examples is trying to export weapons technology to a cartoon villain. They are trying to get a quote, fix a problem, or keep a build on schedule. The export issue comes from what was shared, who received it, and where that person or company is located.
The product may remain in the United States while the drawing package, firmware, or technical explanation crosses the line first.
That’s why you need to understand the export classification before the RFQ package goes out. Once the controlled drawing is sitting in a supplier’s inbox, the compliance discussion has arrived a little late.
Read More: Should Your 3PL Be ITAR/EAR Compliant?
A practical workflow for ITAR vs. EAR
When it falls to you to figure out whether export controls could affect a transaction, you do not need to solve the entire legal question on your own. You just need a sensible way to spot the risk, identify which rules may apply, and know when to stop and ask for help. Start with this workflow.
1. Check whether ITAR applies
If somebody gives you documents or data marked ITAR, treat them as ITAR controlled. Do not circulate them to non-U.S. persons or upload them into a system that may allow the wrong people to see them.
The harder case is physical items or technical data your company creates. Then you need to check the U.S. Munitions List, or USML, and determine whether the underlying article, service, or technical data falls within one of its categories.
A military customer does not automatically make a commercial item ITAR controlled. Intended military use alone does not settle the question. The regulatory description and the item’s actual characteristics do.
When the answer remains genuinely unclear, DDTC offers the Commodity Jurisdiction process for an official determination.
If ITAR applies, stop here and follow the ITAR rules. If it does not, continue.
2. Check for specialized nuclear jurisdiction
An obvious nuclear connection belongs with a nuclear-specific reviewer. NRC Part 110 is commonly the first stop for nuclear equipment or material. DOE Part 810 addresses certain unclassified nuclear technology and assistance.
If a nuclear-specific regime applies, stop here and get specialized guidance. If it does not, continue.
3. Screen the destination and relevant parties
You do not need to investigate every company you encounter. Pay attention when the transaction involves a sanctioned country, an unfamiliar intermediary, unusual routing, a customer who will not identify the final recipient, or an end use that does not make much sense.
When something feels off, search the company and person names in the federal Consolidated Screening List. It checks multiple Commerce, State, and Treasury lists at once. Start with the full legal name, then try alternate spellings or fewer search fields if you get no useful result. OFAC also has a free sanctions search tool for checking names against its sanctions lists. A possible match does not automatically mean you found the same person or company, so compare details such as the address, country, aliases, and identification information before drawing a conclusion.
A prohibited recipient can stop the transaction before the item’s EAR classification even matters.
If you find a likely match or another serious concern, stop and resolve it before moving forward. If nothing raises a concern, continue.
4. Move into the EAR workflow
When the item does not fall under ITAR or another agency’s exclusive jurisdiction, determine whether it appears on the CCL.
Start by asking the manufacturer, producer, or developer for the ECCN. For electronic components, the manufacturer’s product page, export-compliance database, or distributor documentation may already provide it. Do not confuse the ECCN with an HTS or Schedule B code. They are unrelated classification systems.
When the manufacturer cannot provide an ECCN, use BIS’s Interactive Commerce Control List. Search by the item type and technical characteristics, then open any likely ECCN and compare the complete technical description against the product specifications. A keyword match alone is not enough, and you may need to review several entries.
BIS also provides a CCL Order of Review tool. If the answer still remains unclear, you can ask BIS for an official commodity classification through SNAP-R. BIS will determine whether the item falls under a particular ECCN or is EAR99.
If the item has an ECCN, follow the controls tied to that ECCN. If it does not, treat it as EAR99.
What changes when something is ITAR controlled?
ITAR calls for a restrictive default posture around the article, technical data, services, and access.
In practice, ITAR changes how you handle the work. You need to control access to the item and its technical data, use suppliers and systems that can support those restrictions, and keep non-U.S. persons from seeing controlled information unless the proper authorization is in place. Registration, licenses, and technical-assistance agreements matter in some cases, but they are usually not the first problem you will encounter.
You also need to know whether each person receiving access is a U.S. person or non-U.S. person under the applicable rules. A non-U.S. person can be sitting in your U.S. office, working through a domestic staffing company, or joining a meeting from the desk next to yours.
That affects:
- Shared-drive permissions
- Supplier and contractor accounts
- Plant tours
- Design reviews
- Customer support
- Repair instructions
- Remote debugging sessions
Cloud access deserves special attention. Uploading a controlled file to an unsuitable environment and inviting the wrong user can create the same basic problem as emailing it directly, with the added joy of a permissions log nobody has examined since the intern who configured it left the company.
ITAR registration is a separate question. Simply receiving and properly handling an ITAR-controlled drawing does not necessarily mean you need to register, but once your company starts making the controlled hardware or performing controlled technical work, registration deserves a close look. Registration also does not give you permission to export anything; it just gets you into DDTC’s system.
Read More: How We Accomplished ITAR Compliance for Our Software
What changes when something has an ECCN?
The rules you need to follow depend on the ECCN and what you are actually trying to do with the item.
The ECCN is the essential starting point. You will need to review the reason for control, destination, end user, end use, licensing requirements, and any available exceptions.
For some ECCN-classified items, the related technical information or software may also be controlled. Sharing that information with a non-U.S. person, even inside the United States, may create a deemed export issue. This is why engineering access, supplier collaboration, and shared file systems can matter even when nothing is being shipped internationally.
This matters in multinational engineering groups, where a single repository may contain commercial documentation, controlled technology, source code, manufacturing instructions, and test artifacts. Giving everybody access because it keeps the project moving is efficient right until somebody asks for the authorization supporting that access.
What controls apply to EAR99?
EAR99 is where most ordinary commercial items land. In most cases, you do not need to do anything special before shipping.
The exceptions are when the customer, destination, or intended use raises a concern. A normal component going to a normal customer is usually straightforward. A vague customer, unusual destination, or request that does not make sense for the product is when you should stop and ask a few questions.
The practical takeaway
If export control falls to you and you are not sure what to do next, come back to these three basic questions:
Is this item controlled?Is it ITAR, does it have an ECCN, or is it EAR99?
Who will have access?Are you sharing technical data, software, or other information with a non-U.S. person?
Where is it going?Does the destination, customer, or end use raise a concern?
You do not need to become the export-control expert at your company. You just need to recognize when you know enough to move forward, and when it is time to bring in a know-it-all.
Ready to let Cofactr handle sourcing, negotiations, storage, kitting, and delivery while your team focuses on building products? It’s free to get started with Cofactr today.
Frequently Asked Questions
What is the difference between ITAR and EAR?
ITAR regulates defense articles, defense services, and related technical data listed on the U.S. Munitions List. EAR governs most commercial and dual-use items that are not controlled by ITAR and uses Export Control Classification Numbers (ECCNs) to determine restrictions.
How do I know if my product is subject to ITAR or EAR?
Start by checking whether the item appears on the U.S. Munitions List. If it does not, determine whether it has an ECCN under the Commerce Control List. Items without an ECCN are generally classified as EAR99.
What is an ECCN, and why does it matter?
An Export Control Classification Number (ECCN) is a five-character code that identifies how an item is regulated under the EAR. It determines licensing requirements, reasons for control, and whether any export exceptions may apply.
What is EAR99?
EAR99 covers most low-risk commercial products that are not specifically listed on the Commerce Control List. These items usually do not require an export license unless the destination, end user, or intended use raises compliance concerns.
Does sharing technical data count as an export?
Yes. Export controls apply to technical data, software, source code, engineering support, and manufacturing instructions. Sharing controlled information with a non-U.S. person can trigger export compliance requirements, even if the physical product never leaves the United States.
Who needs to pay attention to ITAR and EAR compliance?
Export controls affect engineers, procurement teams, sales staff, program managers, and anyone sharing products, software, drawings, or technical information with suppliers, contractors, or customers. Many compliance issues begin during routine engineering and sourcing activities.
What changes when an item is ITAR controlled?
ITAR requires strict control over who can access defense articles and technical data. Companies must restrict access by non-U.S. persons, manage file permissions carefully, and follow applicable registration, licensing, or authorization requirements when necessary.
Are ITAR and EAR related to tariffs or import duties?
No. ITAR and EAR regulate exports, including physical shipments and technical data shared with foreign persons. Tariffs and customs duties fall under import regulations and use HTS codes, which are separate from export classifications.
What is the first step when evaluating an export-controlled transaction?
Begin by identifying the item's export classification. Determine whether it falls under ITAR, another specialized regulatory authority, an EAR ECCN, or EAR99. Then review the destination, end user, and intended use before moving forward.