Compliance Hub · July 25, 2026 · ~7 min read

Defense Export Compliance Roadmap — ITAR, EAR, CMMC, and DFARS for Defense Buyers

Every defense procurement program touches several overlapping export-control and cybersecurity regimes at once: ITAR (State / DDTC / USML), EAR (Commerce / CCL / ECCN / 600-series), CMMC with its DFARS 252.204-7012 flow-down, and the deemed-export rule that re-exports controlled technical data to any foreign national on US soil. This hub is the buyer-side roadmap: route by situation, then read Articles 5–11 in the recommended sequence.

Why Buyers Need an Export-Compliance Roadmap

Defense programs do not fail export audits on the regime they prepared for — they fail on the regime they did not realize applied. A buyer can run a perfect ITAR DDTC verification on a USML-covering supplier and still be exposed if the same chain also ships items under an EAR ECCN to a dual-use customer, if a CMMC L2 supplier handles CUI on a network that hasn’t passed DFARS 252.204-7012, or if a deemed-export release happens in a facility where foreign-national engineers share airspace with controlled technical data. The four regimes overlap constantly, and the buyer is the one who has to keep them straight.

This hub splits the buyer’s job into three questions: which regime is the contract under, which supplier chain touches each regime, and where the deemed-export exposure sits. Routing by situation — incoming RFP, sourcing supplier, prepping a C3PAO assessment, vetting a foreign-national hire, ITAR vs EAR classification, ECCN classification — gives you the right article to read for each of those three questions.

Regime overlap, in one line: ITAR governs defense articles on the USML (State / DDTC); EAR governs dual-use items on the CCL — including the 600-series that “specially designed” items commingle back to (Commerce / BIS); CMMC / DFARS 252.204-7012 governs CUI cybersecurity on DoD contracts (DoD); and the deemed-export rule treats a release to any foreign national in the US as an export to that person’s country.

Route by Situation

The table below maps the situations defense procurement teams encounter onto the right starting article. Pick the row that matches what you’re working on — the “Start at” column is the article to read first.

Your situation Start at Reason
You’re reviewing an incoming RFP Article 6: ITAR vs EAR comparison → Bid packets surface an export-control clause first; this walkthrough tells you which regime applies.
You’re sourcing a supplier for a controlled program Article 8: Finding ITAR-certified suppliers → Pre-vetted directories cut RFP-side verification load.
You’re prepping a C3PAO assessment Article 9: AS9100 vs ITAR vs CMMC deep dive → CUI-handling posture determines the lane.
You’re vetting a foreign-national hire Article 10: Deemed exports (TODO) → Deemed-export exposure is the gap audits hit hardest.
You’re answering the ITAR vs EAR classification question Article 11: ITAR vs EAR classification → Often the first regime question a buyer has to answer in writing before the supplier search even starts.
You’re vetting a supplier under ITAR Article 5: Reading a capabilities statement → Capabilities statement read-through flags DDTC, USML, and EAR commingling risk.
You’re classifying an item against ECCN / EAR99 Article 7: ECCN classification (TODO) → ECCN classification step-by-step for dual-use and 600-series items.

Skip the deep-dives — pull a shortlist of certified suppliers today

The fastest path past export-controls friction is sourcing from manufacturers whose ITAR, EAR posture, and CMMC cert are already verified. Filter the ForgeLine directory in seconds — every supplier is pre-vetted.

🔍 Search Verified Suppliers → Or take the readiness self-assessment →

One-Paragraph Summary per Article

Short frame per Article 5 through 11 so you can decide whether to drop in or skip ahead. Use the routing table above if you already know which situation you’re working on.

Article 5 — How to Read a Defense Supplier Capabilities Statement

Read article →

A capabilities statement is the most common artifact a prime or DCAA reviewer will ask a supplier to produce, and most suppliers write it for marketing rather than for export audit. Article 5 walks a buyer through what a strong capabilities statement looks like — explicit DDTC registration, named USML categories the supplier works in, CMMC L-level, ECCN handling note, and facility clearance status — so you can spot the gaps in the doc before the audit opens.

Article 6 — ITAR vs EAR: Which Regime Applies to Your RFP

Read article →

The bifurcation between ITAR and EAR is the first thing every defense RFP forces you to answer in writing: are the items on the USML (ITAR, State / DDTC) or are they dual-use items subject to the Commerce Control List (EAR, BIS), including the 600-series that re-imports “specially designed” defense articles back into EAR? Article 6 traces the decision logic buyers actually use, with the commingling case (parts partly USML, partly ECCN) and the EAR99 fallback explained end-to-end.

Article 7 — ECCN Classification Step-by-Step

Read article →

If your RFP lands in the EAR lane, the next question is classification: which ECCN applies, and is it EAR99 with no license required? Article 7 is the step-by-step buyers walk through when they need to defend a classification to a prime or a BIS review — CCL category by category, with notes on the 600-series treaties and the de minimis rule.

TODO guard — Article 7: not yet published. Routing link above resolves to this anchor today. When Article 7 publishes at /blog/<slug>, swap ARTICLE_URLS.article7 in routes/pages.js — one line.

Article 8 — Finding ITAR-Certified US Suppliers

Read article →

Once you know the regime, the buyer’s next step is supplier sourcing under that regime. Article 8 walks the ITAR sourcing path specifically — what DDTC verification looks like in practice, which supplier attributes matter most for export-control posture, and where a pre-vetted directory saves you the verification work a prime or DCAA reviewer will otherwise expect you to perform yourself.

Article 9 — AS9100 vs ITAR vs CMMC: When Each Certification Matters

Read article →

Three certifications show up on virtually every defense supplier profile, and a procurement program needs to know which one the contract actually requires. Article 9 maps the three — AS9100 (aerospace QMS), ITAR (export registration), and CMMC (cybersecurity maturity with DFARS 252.204-7012 / NIST SP 800-171 backing) — onto the typical RFP clause and onto the C3PAO assessment path a prime will run.

Article 10 — Foreign-National Hire & the ITAR Deemed-Export Rule

Read article →

The deemed-export rule (22 CFR 120.17) treats the release of controlled technical data to any foreign national inside the US as an export to that person’s country. Hiring an F-1 / H-1B / L-1 engineer onto a program that touches USML technical data, training a foreign-national teammate on USML tooling, or even letting foreign nationals tour a USML production floor can all trigger a licensing requirement. Article 10 walks the buyer-side controls — technology-control plans, foreign-person screening, license-first vs. license-after posture, and the audit trail DDTC expects to see — so the deemed-export exposure is closed before the hire ships, not after the enforcement letter arrives.

Article 11 — ITAR vs EAR: Which Regime Applies to Your RFP

Read article →

The first regime question every defense RFP forces a buyer to answer in writing: is the part on the USML (ITAR, State / DDTC) or is it dual-use on the Commerce Control List (EAR, BIS), including the 600-series that re-imports “specially designed” articles back into EAR? Article 11 traces the decision logic buyers actually use, with the commingling case (parts partly USML, partly ECCN) and the EAR99 fallback explained end-to-end. Pair this with Article 7 (ECCN classification) when the answer lands in the EAR lane.

Recommended Read Sequence

If the table above isn’t decisive — if you’re new to export-controls on the buyer side and want to read the cluster in order — start with Article 5 and follow the sequence below. Each hop links to the article and gives you the reason the next step makes sense from there.

Step Article Why this hop
1 Article 5: How to read a capabilities statement → Establishes what “export-ready” looks like at the supplier artifact level before you read about regimes.
2 Article 11: ITAR vs EAR → Establishes the regime question before sourcing in the wrong lane; pairs with Article 6, which covers the same ITAR-vs-EAR decision from the RFP-walkthrough angle.
3 Article 8: Finding ITAR-certified suppliers → Jumps from regime theory to the buyer’s sourcing step — ITAR-first, the most common lane.
4 Article 7: ECCN classification → Handles the EAR-side classification buyers hit when the program slips into dual-use territory.
5 Article 9: AS9100 vs ITAR vs CMMC → Closes the loop with the C3PAO / CMMC deep-dive — the cert posture that survives a prime review.
6 Article 10: Foreign-national hire & deemed exports → Closes the loop on the deemed-export gap audits hit hardest, after the sourcing & classification lanes are settled.
TODO guard — Article 10 (deemed exports): not yet published. Routing link in the situational table resolves to this anchor today. When Article 10 publishes, swap ARTICLE_URLS.article10 in routes/pages.js.

Already know the regime? Pull a shortlist.

ForgeLine at forgeline-2.polsia.app indexes pre-vetted US defense manufacturers so you can filter on ITAR registration, CMMC L-level, AS9100, and DFARS posture in one query — saving the verification work a prime or DCAA reviewer will otherwise expect from you.

Search the ForgeLine directory →
Legal disclaimer: This page summarizes export-control and CMMC readiness criteria for buyer-intent reference only and is not legal or compliance advice. ITAR & EAR & DFARS 252.204-7012 & CMMC regimes are administered by State / DDTC, Commerce / BIS, and the US Department of Defense respectively. Consult licensed export-control or CMMC counsel before making classification or certification decisions.