Partners About Blogs Contact
discover Our services
Closed Menu
Our Services
No items found.
Home>Blogs>Security>ITAR and CMMC: Why CMMC Level 2 Compliance Does Not Make a Defense Contractor ITAR Compliant
ITAR and CMMC compliance are two separate regimes for defense contractors
September 10, 2026

ITAR and CMMC: Why CMMC Level 2 Compliance Does Not Make a Defense Contractor ITAR Compliant

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Two things happened this summer that most of the defense industrial base has not reconciled. The Department of Defense suspended the phase of CMMC that would have required third-party assessments, and eleven days from now the cryptographic standard that underpins the ITAR encryption carve-out moves to historical status at NIST. One of those is being read as relief. Neither should be.

This article is about the gap between two compliance frameworks that get treated as one. It covers what ITAR compliance actually restricts versus what CMMC 2.0 governs, why passing a CMMC Level 2 assessment leaves an export-control hole wide open, what the cloud carve-out really permits, and what changes for your encryption documentation on September 21. If you own ITAR compliance or CMMC readiness and the other function reports somewhere else, this is the piece that explains why that arrangement keeps producing findings.

What changed in 2026, and what did not?

On July 13, 2026, the Department suspended CMMC Phase 2 and placed later milestones in abeyance pending a reform task force review. Federal News Network covered the announcement, which halted the third-party assessment mandate that had been scheduled for November. Self-assessment requirements introduced in November 2025 remain in force.

Nothing about ITAR changed. Not one provision, not one deadline, not one dollar of penalty exposure. The International Traffic in Arms Regulations sit at 22 CFR 120 through 130, administered by the Directorate of Defense Trade Controls at the Department of State, and they operate on an entirely separate statutory authority from anything the Pentagon suspended. A contractor who slowed ITAR compliance because of a CMMC memo has misread which agency was speaking, and the obligation to comply with ITAR regulations is unchanged. The requirements of ITAR sit with the Department of State and do not move when the Department of Defense adjusts a schedule.

This is the specific error the title refers to. Defense contractors must treat these as two regimes with different owners, different triggers, and different failure modes. Compliance is required under both, and satisfying one has never satisfied the other. CMMC compliance and ITAR compliance are separate compliance obligations with separate evidence.

What is ITAR, and when does ITAR apply to your data?

ITAR controls defense articles and technical data on the United States Munitions List. Technical data means the information required for the design, development, production, manufacture, assembly, operation, repair, maintenance, or modification of a defense article. Drawings, specifications, source code, test data, and process documentation all qualify. ITAR applies the moment your organisation handles that material, regardless of contract value or company size.

A foreign person reading a drawing in your Ohio office is still an export.
A foreign person reading a drawing in your Ohio office is still an export.

The trigger that surprises people is that ITAR restricts access by person, not by network. Releasing technical data to a foreign person is an export even if that person sits in your office in Ohio and never leaves the building. This is the deemed export concept, and it reaches employees on visas, contractors, and, importantly, the administrators employed by whichever platform hosts your data.

Registration with DDTC is a separate obligation from any of this. Manufacturers, exporters, and brokers of defense articles must register, and being subject to ITAR begins there rather than at your first shipment. Firms that discover ITAR obligations mid-programme frequently discover the registration gap at the same time. ITAR requires registration before the first controlled activity, not after it.

How do ITAR and CMMC differ in what they actually protect?

CMMC 2.0 focuses on cybersecurity outcomes for controlled unclassified information. It asks whether your environment implements a defined control set well enough to protect data at rest, in transit, and in use. Nationality does not appear in it. CMMC governs how well the information is defended.

ITAR asks a completely different question: who is permitted to see this. It does not much care whether your encryption is elegant. It cares whether an unauthorised foreign person obtained access. You can run an exemplary security programme, pass every technical test, and still release controlled data by giving a cleared-but-foreign engineer read access to a folder.

The Cybersecurity Maturity Model Certification framework and the ITAR regulations therefore relate to CMMC scoping in opposite directions: one drives cybersecurity depth, the other drives access narrowness. Put plainly, one regime is about strength and the other is about eligibility. That distinction is the whole article, and it is why the CMMC framework alone will never demonstrate compliance with export control. Compliance strategies built around CMMC requirements produce excellent evidence of control implementation and almost no evidence of nationality-based access restriction, and an ITAR reviewer wants the second thing.

Why does a clean Level 2 result leave an export-control hole?

Because NIST SP 800-171 contains no U.S. person requirement anywhere in its 110 controls. Access control requires that you limit system access to authorised users. It never defines authorised in citizenship terms. A contractor can achieve compliance with NIST 800-171, hold a CMMC Level 2 certification, and still have a foreign national systems administrator with domain-level access to export-controlled drawings.

A clean CMMC result says nothing about your deemed-export exposure.
A clean CMMC result says nothing about your deemed-export exposure.

The inverse is equally true and less often noticed. A firm with rigorous export control discipline, well-versed in ITAR and running nationality checks on every access grant, may still fail a CMMC Level 2 assessment for entirely unrelated reasons: no documented audit log review, weak configuration management, an incomplete system security plan. Compliance with CMMC 2.0 and compliance with ITAR fail independently, and the compliance challenges each presents are different in kind. To meet ITAR requirements you need eligibility records; to satisfy CMMC you need control evidence.

The practical consequence is scoping. Your enclave for CMMC Level 2 and your ITAR boundary are usually different shapes, and firms that assume one drawing covers both find the mismatch during an assessment. Our CMMC preparation work now starts by asking which systems carry export-controlled material, because that answer changes the scope for CMMC Level 2 as well.

What are the penalties for ITAR violations?

Civil penalties run up to $1,271,078 per violation or twice the transaction value, whichever is greater. That figure did not move this year: because the government shutdown prevented publication of the October 2025 inflation data, no adjustment could be calculated for 2026 and agencies continue applying 2025 levels. Criminal exposure under the Arms Export Control Act reaches $1 million and twenty years per violation.

Note the phrase per violation. These penalties count instances, not incidents. A misconfigured share that exposed four hundred ITAR drawings to an unauthorised person is not one violation in the government's arithmetic, which is why non-compliance with ITAR scales into numbers that look implausible until you understand the counting.

Most matters never reach that. DDTC's compliance office reviews roughly a thousand compliance-related matters annually and generally works with industry, with civil penalties reserved for conduct that is egregious or harmful to national security. Voluntary disclosure is the mechanism that keeps most findings administrative, and it works considerably better when you can show a documented compliance program that caught the issue yourself.

Can you store ITAR technical data in the cloud?

Yes, and the rule that permits it is more precise than the folklore around it. Under 22 CFR 120.54(a)(5), sending, taking, or storing technical data is not an export if the data is unclassified, secured end to end so it is never in unencrypted form between originator and recipient, protected by cryptographic modules compliant with FIPS 140-2 or its successors, and not intentionally sent to or stored in a country proscribed under 126.1. Data in transit across the internet is not treated as stored in the countries it crosses.

Verify who holds the keys and who administers the platform.
Verify who holds the keys and who administers the platform.

Two limits matter more than the permission. First, the carve-out covers the encrypted blob only. The moment the data is decrypted where an unauthorised foreign person can see it, you are back to a controlled export. Second, ITAR treats access information as its own category: handing decryption keys to a foreign person is a release requiring authorisation, even if the ciphertext itself was never controlled.

Which is why the hyperscaler government regions exist. They combine FedRAMP-aligned controls with contractual restriction of administrative access to U.S. persons, and that second half is the part addressing ITAR rather than CMMC. If you handle ITAR data in a commercial tenant on the theory that encryption solves it, verify who holds the keys and who administers the platform before you rely on that reasoning.

What changes for your encryption on September 21, 2026?

On that date the NIST Cryptographic Module Validation Program moves every remaining FIPS 140-2 certificate to its historical list. NIST's transition page states that modules remain active for five years after validation or until September 21, 2026, and that CMVP continues to support purchase and use of historical modules for existing systems.

Read that carefully, because the alarmist version circulating is wrong. Historical status is not revocation, your hardware does not stop working, and the ITAR carve-out itself does not break, because 120.54(a)(5) already says FIPS 140-2 "or its successors" and FIPS 140-3 is the successor. What changes is procurement posture and documentation. A historical certificate should not be used to satisfy a new acquisition, and contracting officers increasingly want an active one.

The real exposure is textual. Plenty of ITAR compliance program documentation, vendor questionnaires, and subcontract clauses name FIPS 140-2 explicitly. On September 22 those documents will cite a standard whose certificates sit on a historical list, and an auditor reading them will ask a question you should already have answered. Inventory where that string appears, confirm each vendor has a FIPS 140-3 successor validated or in queue, and update the language. That is a documentation exercise, not an engineering one, and it is cheap right now.

Where do NIST SP 800-171 and CMMC Level 2 overlap with ITAR requirements?

There is real overlap, and using it is how you control compliance costs. CMMC 2.0 Level 2 and ITAR both reward the same underlying hygiene: access control, identification and authentication, media protection, and physical protection all produce artefacts that serve both regimes, and the CMMC Level 2 requirements behind them are largely reusable. Encryption of data at rest and in transit satisfies a CMMC control and supports the 120.54 analysis simultaneously. Personnel security screening maps onto both, once you extend it to capture nationality.

The gaps are narrow and specific. The baseline controls do not require you to determine person eligibility, to maintain a technical data classification tied to the Munitions List, to track deemed exports, or to hold DDTC registration. Add those four and most of an export-control programme sits on top of infrastructure you already built, which is how you streamline compliance rather than duplicate it.

Sequence the work that way and your compliance efforts stop competing for the same budget. Build the technical baseline once against the 800-171 control set, then layer the export-control determinations on top rather than running two parallel projects. That is what streamlines compliance in practice, and it is a far better answer than buying a second toolset. The control mapping between NIST 800-171 and CMMC we published walks the baseline in detail.

How do ITAR obligations flow down through the supply chain?

Contractually, and further than most subcontractors expect. A prime contractor passes export-control clauses down, and everyone touching those articles and drawings inherits them. If Company A supplies a part and Company B exports it without authorisation, both can face exposure. Shared liability is the default in defense contracting, not the exception.

That reality is why prime security questionnaires now ask about both regimes. A supplier who answers the CMMC 2.0 compliance questions well and then cannot say who administers the system holding export-controlled drawings has demonstrated exactly the compliance gaps this article is about. Suppliers within the defense industrial base are increasingly screened on both before award.

Extend your supply chain risk management view to the vendors holding controlled files on your behalf: cloud providers, engineering service bureaus, MRO partners, translation and CAD vendors. The most common ITAR export nobody intended is a drawing package sent to an offshore engineering partner because procurement never knew the file was subject to ITAR control.

What does an integrated compliance program actually look like?

One owner, one data inventory, two determinations. Give a single accountable person visibility across cybersecurity requirements and export control compliance, because the split ownership model is what produces the failures described above. Then build one inventory of where sensitive material lives, and run two questions against each item: what protection does it require under the appropriate CMMC 2.0 level, and who is permitted to access it. CMMC 2.0 applies by data type and contract, so the compliance requirements and CMMC scoping follow the inventory rather than the other way round.

One owner, one data inventory, two determinations protection and eligibility
Document how you determined a person was eligible, not just that access was restricted.

Document the second determination as deliberately as the first. Nationality-based access decisions need a record showing who approved them and on what basis, and that record is what demonstrates compliance when DDTC asks. Most firms have thorough evidence of control implementation and nothing at all showing how a person was determined eligible. Compliance measures that align with ITAR have to name people, not just systems.

Then keep both current. Review access when people change roles, when vendors change subprocessors, and when a programme adds a Munitions List item. Common compliance failures cluster at exactly those three moments, because that is where cybersecurity controls and export determinations drift apart. Our cybersecurity consulting teams run these as one engagement across the defense industrial base because separating them is what created the problem, and the assessment mechanics are covered in our companion piece, C3PAO Assessment: A Defense Contractor 90-Day Prep Plan, alongside the CMMC 2.0 readiness guide and the list of live DoD solicitations requiring certification.

Find your gaps before an auditor does

Our ITAR and CMMC Compliance Checklist walks a compliance lead through data classification, boundary definition, person-eligibility determinations, and the vendor questions that surface deemed-export risk. It is built to be run by your existing team without external compliance support.

VisioneerIT treats this as one engineering problem rather than two paperwork exercises. If you want to know where your compliance posture actually stands, or what it takes to achieve ITAR and CMMC readiness together before a prime's questionnaire, talk to our team.

Key things to remember

  • The CMMC suspension changed nothing about ITAR compliance. Different agency, different statute, different penalties. Slowing export control work because of a Pentagon memo is a category error.
  • CMMC and ITAR ask different questions. CMMC asks how well the information is protected. ITAR asks who is allowed to see it.
  • NIST SP 800-171 has no U.S. person requirement in any of its 110 controls, so a clean CMMC Level 2 result says nothing about your deemed-export exposure.
  • Civil penalties remain $1,271,078 per violation for 2026, since no inflation adjustment could be calculated. Criminal exposure reaches $1 million and twenty years.
  • Per violation means per instance. One misconfigured share holding hundreds of drawings is not one finding.
  • The cloud carve-out under 22 CFR 120.54(a)(5) covers the encrypted blob only. Decryption where an unauthorised foreign person can see it, or handing over the keys, is still an export.
  • FIPS 140-2 certificates move to NIST's historical list on September 21, 2026. That is not revocation, but any document naming FIPS 140-2 needs updating and any new acquisition should require an active FIPS 140-3 certificate.
  • Build one technical baseline, then layer export-control determinations on top. Running two parallel programmes wastes money and still leaves gaps.
  • Document how you determined a person was eligible, not just that access was restricted. That record is the one most firms cannot produce.
ITAR and CMMC: Why CMMC Level 2 Compliance Does Not Make a Defense Contractor ITAR Compliant
Book your free Discovery Call Today!

Embark on the path to efficiency and success by filling out the form to the right.

Our team is eager to understand your unique needs and guide you towards a tailored ClickUp solution that transforms your business workflows.