Why Buyers Need an Export-Compliance Roadmap
Defense programs do not fail export audits on the regime they prepared for — they fail on the regime they did not realize applied. A buyer can run a perfect ITAR DDTC verification on a USML-covering supplier and still be exposed if the same chain also ships items under an EAR ECCN to a dual-use customer, if a CMMC L2 supplier handles CUI on a network that hasn’t passed DFARS 252.204-7012, or if a deemed-export release happens in a facility where foreign-national engineers share airspace with controlled technical data. The four regimes overlap constantly, and the buyer is the one who has to keep them straight.
This hub splits the buyer’s job into three questions: which regime is the contract under, which supplier chain touches each regime, and where the deemed-export exposure sits. Routing by situation — incoming RFP, sourcing supplier, prepping a C3PAO assessment, vetting a foreign-national hire, ITAR vs EAR classification, ECCN classification — gives you the right article to read for each of those three questions.
Route by Situation
The table below maps the situations defense procurement teams encounter onto the right starting article. Pick the row that matches what you’re working on — the “Start at” column is the article to read first.
| Your situation | Start at | Reason |
|---|---|---|
| You’re reviewing an incoming RFP | Article 6: ITAR vs EAR comparison → | Bid packets surface an export-control clause first; this walkthrough tells you which regime applies. |
| You’re sourcing a supplier for a controlled program | Article 8: Finding ITAR-certified suppliers → | Pre-vetted directories cut RFP-side verification load. |
| You’re prepping a C3PAO assessment | Article 9: AS9100 vs ITAR vs CMMC deep dive → | CUI-handling posture determines the lane. |
| You’re vetting a foreign-national hire | Article 10: Deemed exports (TODO) → | Deemed-export exposure is the gap audits hit hardest. |
| You’re answering the ITAR vs EAR classification question | Article 11: ITAR vs EAR classification → | Often the first regime question a buyer has to answer in writing before the supplier search even starts. |
| You’re vetting a supplier under ITAR | Article 5: Reading a capabilities statement → | Capabilities statement read-through flags DDTC, USML, and EAR commingling risk. |
| You’re classifying an item against ECCN / EAR99 | Article 7: ECCN classification (TODO) → | ECCN classification step-by-step for dual-use and 600-series items. |
Skip the deep-dives — pull a shortlist of certified suppliers today
The fastest path past export-controls friction is sourcing from manufacturers whose ITAR, EAR posture, and CMMC cert are already verified. Filter the ForgeLine directory in seconds — every supplier is pre-vetted.
One-Paragraph Summary per Article
Short frame per Article 5 through 11 so you can decide whether to drop in or skip ahead. Use the routing table above if you already know which situation you’re working on.
Article 5 — How to Read a Defense Supplier Capabilities Statement
A capabilities statement is the most common artifact a prime or DCAA reviewer will ask a supplier to produce, and most suppliers write it for marketing rather than for export audit. Article 5 walks a buyer through what a strong capabilities statement looks like — explicit DDTC registration, named USML categories the supplier works in, CMMC L-level, ECCN handling note, and facility clearance status — so you can spot the gaps in the doc before the audit opens.
Article 6 — ITAR vs EAR: Which Regime Applies to Your RFP
The bifurcation between ITAR and EAR is the first thing every defense RFP forces you to answer in writing: are the items on the USML (ITAR, State / DDTC) or are they dual-use items subject to the Commerce Control List (EAR, BIS), including the 600-series that re-imports “specially designed” defense articles back into EAR? Article 6 traces the decision logic buyers actually use, with the commingling case (parts partly USML, partly ECCN) and the EAR99 fallback explained end-to-end.
Article 7 — ECCN Classification Step-by-Step
If your RFP lands in the EAR lane, the next question is classification: which ECCN applies, and is it EAR99 with no license required? Article 7 is the step-by-step buyers walk through when they need to defend a classification to a prime or a BIS review — CCL category by category, with notes on the 600-series treaties and the de minimis rule.
/blog/<slug>, swap ARTICLE_URLS.article7 in routes/pages.js — one line.
Article 8 — Finding ITAR-Certified US Suppliers
Once you know the regime, the buyer’s next step is supplier sourcing under that regime. Article 8 walks the ITAR sourcing path specifically — what DDTC verification looks like in practice, which supplier attributes matter most for export-control posture, and where a pre-vetted directory saves you the verification work a prime or DCAA reviewer will otherwise expect you to perform yourself.
Article 9 — AS9100 vs ITAR vs CMMC: When Each Certification Matters
Three certifications show up on virtually every defense supplier profile, and a procurement program needs to know which one the contract actually requires. Article 9 maps the three — AS9100 (aerospace QMS), ITAR (export registration), and CMMC (cybersecurity maturity with DFARS 252.204-7012 / NIST SP 800-171 backing) — onto the typical RFP clause and onto the C3PAO assessment path a prime will run.
Article 10 — Foreign-National Hire & the ITAR Deemed-Export Rule
The deemed-export rule (22 CFR 120.17) treats the release of controlled technical data to any foreign national inside the US as an export to that person’s country. Hiring an F-1 / H-1B / L-1 engineer onto a program that touches USML technical data, training a foreign-national teammate on USML tooling, or even letting foreign nationals tour a USML production floor can all trigger a licensing requirement. Article 10 walks the buyer-side controls — technology-control plans, foreign-person screening, license-first vs. license-after posture, and the audit trail DDTC expects to see — so the deemed-export exposure is closed before the hire ships, not after the enforcement letter arrives.
Article 11 — ITAR vs EAR: Which Regime Applies to Your RFP
The first regime question every defense RFP forces a buyer to answer in writing: is the part on the USML (ITAR, State / DDTC) or is it dual-use on the Commerce Control List (EAR, BIS), including the 600-series that re-imports “specially designed” articles back into EAR? Article 11 traces the decision logic buyers actually use, with the commingling case (parts partly USML, partly ECCN) and the EAR99 fallback explained end-to-end. Pair this with Article 7 (ECCN classification) when the answer lands in the EAR lane.
Recommended Read Sequence
If the table above isn’t decisive — if you’re new to export-controls on the buyer side and want to read the cluster in order — start with Article 5 and follow the sequence below. Each hop links to the article and gives you the reason the next step makes sense from there.
| Step | Article | Why this hop |
|---|---|---|
| 1 | Article 5: How to read a capabilities statement → | Establishes what “export-ready” looks like at the supplier artifact level before you read about regimes. |
| 2 | Article 11: ITAR vs EAR → | Establishes the regime question before sourcing in the wrong lane; pairs with Article 6, which covers the same ITAR-vs-EAR decision from the RFP-walkthrough angle. |
| 3 | Article 8: Finding ITAR-certified suppliers → | Jumps from regime theory to the buyer’s sourcing step — ITAR-first, the most common lane. |
| 4 | Article 7: ECCN classification → | Handles the EAR-side classification buyers hit when the program slips into dual-use territory. |
| 5 | Article 9: AS9100 vs ITAR vs CMMC → | Closes the loop with the C3PAO / CMMC deep-dive — the cert posture that survives a prime review. |
| 6 | Article 10: Foreign-national hire & deemed exports → | Closes the loop on the deemed-export gap audits hit hardest, after the sourcing & classification lanes are settled. |
ARTICLE_URLS.article10 in routes/pages.js.
Already know the regime? Pull a shortlist.
ForgeLine at forgeline-2.polsia.app indexes pre-vetted US defense manufacturers so you can filter on ITAR registration, CMMC L-level, AS9100, and DFARS posture in one query — saving the verification work a prime or DCAA reviewer will otherwise expect from you.
Search the ForgeLine directory →