ITAR Compliant Spacecraft Machining Services

ITAR Spacecraft Machining: Supplier Audit Checklist

Last updated: August 23, 2026

Key Takeaways for ITAR Spacecraft Machining

  • ITAR compliant spacecraft machining services require active DDTC registration, U.S.-person data controls and full material traceability to prevent export-control violations and production delays.
  • A six-step supplier-audit checklist maps verification items to standard RFQ language, covering registration, security controls, alloy experience, AS9102 FAI, CMMC alignment and scalability.
  • Spacecraft programs depend on AS9100D-certified suppliers with documented prototype-to-flight transitions and integrated capabilities that protect compliance and documentation continuity.
  • ITAR and CMMC obligations must be managed at the same time; ITAR registration alone does not satisfy CMMC Level 2 requirements for DoD contracts.
  • Request a quote from Precision Advanced Manufacturing to qualify an ITAR-registered, AS9100D-certified partner for spacecraft machining programs.

Definition of ITAR Compliant Spacecraft Machining Services

ITAR compliant spacecraft machining services are precision metal-cutting and fabrication operations performed under 22 CFR Parts 120–130. The supplier holds active DDTC registration, restricts access to controlled technical data to verified U.S. persons, maintains full lot traceability and flows ITAR obligations to every subcontractor touching flight hardware. The six-step checklist below maps each verification item to standard RFQ language.

A satellite orbiting above the Earth.
Space-grade components tolerate no rework in orbit. Precision machining and controlled processes deliver the reliability satellite and launch programs build on.

6-Step Supplier-Audit Checklist for ITAR Registered Spacecraft Machining

  1. Verify active DDTC registration. Confirm the supplier registration is current under 22 CFR § 122.1 and request the registration certificate with expiration date.
  2. Confirm data-security and U.S.-person controls. Review the Technology Control Plan, IT environment, MFA enforcement and CMMC/NIST 800-171 alignment.
  3. Evaluate spacecraft alloy experience and traceability. Confirm material certifications, heat-lot traceability and AMS or MIL-spec conformance documentation for program-relevant alloys.
  4. Validate AS9102 FAI and CMM capabilities. Require a sample AS9102 Rev C package including ballooned drawings, Forms 1, 2 and 3, and CMM reports.
  5. Assess CMMC/NIST alignment and subcontractor flow-down. Sample active subcontracts for ITAR and DFARS clause presence and confirm an annual review cadence.
  6. Confirm prototype-to-flight scalability. Verify multi-shift capacity, facility certifications and a documented transition process from prototype to full-rate production.

DDTC Registration Checks for Spacecraft Machining Suppliers

22 CFR § 122.2 addresses the frequency and renewal of DDTC registration. A lapsed registration constitutes a violation independent of any actual export activity. Request the supplier registration certificate and compare the expiration date against the program timeline.

Red flags during verification reveal gaps in operational readiness. An Empowered Official who cannot walk through recent licensing decisions signals that the role is ceremonial rather than functional. Training records that show only onboarding-level completion for employees in controlled roles longer than one year indicate that the organization does not maintain competency. These documentation failures often appear alongside absent or outdated subcontract flow-down language, which points to systemic compliance gaps.

Required documentation at qualification includes the DDTC registration certificate and a current Empowered Official designation letter. It also includes training records cross-referenced against the past 18 months of hires and transfers and evidence that counterparties are screened against the Consolidated Screening List on a defined cadence. ITAR records must be retained, and retrieval testing should confirm complete files can be produced within hours.

Civil penalties for ITAR violations reach $1,271,078 per violation or twice the transaction value, whichever is greater, effective January 2025. Criminal penalties reach up to $1 million per violation and 10 years imprisonment for willful ITAR violations.

Data-Security and U.S.-Person Controls for ITAR Programs

Under 22 CFR § 120.17, releasing controlled technical data to a foreign person inside the United States constitutes a deemed export. Every supplier maintains a written Technology Control Plan that describes controlled data categories, physical and logical access controls, U.S.-person verification procedures and incident response processes.

An ITAR-compliant IT environment starts with role-based access control limited to verified U.S. persons. Each person has a unique user account because shared credentials prevent tracing who accessed controlled data. Remote access to these accounts requires MFA to reduce credential theft risk, and the entire access structure is reviewed at least annually to catch permission creep and departed employees. Standard commercial tiers of Microsoft 365, AWS and Google Workspace are not ITAR-compliant. Approved alternatives include Microsoft 365 GCC High, Azure Government and AWS GovCloud because they provide U.S.-only data residency and contractual limits on non-U.S.-person administrator access.

IT access logs for systems containing ITAR-controlled data are retained and stored in a tamper-evident manner. ITAR-controlled technical data must be stored on systems physically located in the United States and not accessible from outside the country without export authorization.

Most organizations handling ITAR data also fall in scope for CMMC Level 2 because ITAR-controlled technical data typically qualifies as CUI under the Export Controlled category (CUI//SP-EXPT). Many suppliers manage ITAR and CMMC obligations as a combined compliance program.

Spacecraft Alloys and Traceability Expectations

Spacecraft and satellite flight hardware programs routinely specify alloys that present machining challenges and carry stringent traceability requirements. Aerospace programs require full material traceability including mill test certificates, heat-lot traceability linking each part to a specific material batch and conformance documentation to AMS, ASTM or MIL-spec standards. AS9100D requires bidirectional traceability at the individual serial-number level, which supports real-time answers on raw-material batch, operators, calibrated equipment and inspection results.

A machined metal part fixtured inside a CNC machining center.
Mission-critical components leave no room for deviation. Multi-axis CNC machining holds tight tolerances part after part, with full material traceability behind every feature.

AS9102 FAI and CMM Requirements for Flight Hardware

SAE AS9102 Rev C (published June 2023) governs First Article Inspection packages for aerospace components. It requires complete dimensional balloon drawings with measurement results, material certifications and traceability documentation, special process certifications, functional test results where applicable and nonconformance documentation.

A compliant AS9102 FAIR consists of three standardized forms. Form 1 records part number, drawing revision, assembly information and supplier details. Form 2 confirms current material certifications, special process certifications and traceable customer specifications. Form 3 lists every ballooned drawing characteristic with its nominal dimension, required tolerance, actual measured value, inspection method and acceptance status.

CMMs are required for tight-tolerance machined parts, complex geometries, hole positions, datums, profiles and GD&T controls during FAI. CMM reports include inspection equipment identification, operator, date, drawing revision and measured characteristics. These details support traceability and allow quality teams to verify completeness and repeatability.

A CMM touch probe measuring a machined aluminum bracket.
Every critical dimension is verified — CMM inspection and AS9100D-controlled quality workflows produce first-article and in-process data you can trace to each part.

A full FAI is required at first production of a new part number, after a production lapse, after transfer of production to a different facility, after a major drawing revision or when mandated by the customer on the purchase order. When a change is ambiguous, defaulting to a full FAI avoids the risk of an inadequate partial FAI.

Beyond inspection capabilities, spacecraft machining suppliers also demonstrate robust cybersecurity controls, particularly when handling data that falls under both ITAR and DoD contract requirements.

CMMC/NIST Alignment and Subcontractor Flow-Down

CMMC and ITAR are separate regulatory obligations. ITAR controls who may access export-controlled technical data and where it may live, while CMMC and NIST 800-171 govern how that data is protected under DoD contracts. Compliance with ITAR does not make a supplier CMMC-ready.

CMMC Level 2 maps to the 110 security requirements of NIST SP 800-171 Rev. 2. The CMMC Program rule (32 CFR Part 170) became effective December 16, 2024, and the companion acquisition rule became effective November 10, 2025. Prime contractors including Boeing, Lockheed Martin, Raytheon and Northrop Grumman are actively assessing and gatekeeping their supply chains based on CMMC compliance status.

ITAR requirements flow down to subcontractors through DFARS § 252.225-7048, which requires primes to scrutinize supplier export-control posture when handling defense technical data. Sample active subcontracts to confirm ITAR clauses are present, current and referenced during supplier onboarding. Establish an annual review cadence for all flow-down language. Replacing a failed supplier takes 25 days on average, so proactive qualification reduces disruption.

Prototype-to-Flight Scalability for Spacecraft Programs

A qualified ITAR registered spacecraft machining partner demonstrates a documented, repeatable transition from prototype through full-rate production without changes to quality systems or traceability controls. Precision Advanced Manufacturing integrated capabilities include multi-axis CNC machining, precision fabrication, specialty welding and secondary finishing that operate under a single AS9100D and ITAR-compliant quality system at its California facility. This structure eliminates supplier handoffs and maintains documentation continuity from first article through sustained production.

A five-axis CNC head machining a round metal workpiece.
Five-axis machining reaches complex geometries in a single setup — fewer fixtures, tighter true position, and the repeatability aerospace and defense programs demand.

Request a quote to discuss prototype-to-flight program requirements with Precision Advanced Manufacturing engineering staff.

Steps to Achieve ITAR Compliance

  1. Register with DDTC under 22 CFR § 122.2 and renew annually. A lapsed registration is a violation regardless of export activity.
  2. Develop and implement a Technology Control Plan that maps controlled data categories, physical and logical access controls, U.S.-person verification procedures and incident response processes.
  3. Restrict access to verified U.S. persons across all systems touching ITAR-controlled technical data, including engineering drives, PLM systems and physical prototype areas.
  4. Deploy an ITAR-compliant IT environment using U.S.-only data residency platforms such as Microsoft 365 GCC High or AWS GovCloud, with MFA, role-based access control and tamper-evident logging.
  5. Train personnel and designate an Empowered Official with current product-line knowledge and operational authority to make licensing determinations.
  6. Flow ITAR obligations to subcontractors through DFARS § 252.225-7048 language in every active subcontract and conduct annual reviews.

Precision Advanced Manufacturing maintains active ITAR (DDTC) registration and AS9100D/ISO 9001-certified quality systems at its California facility, which provides customers with a documented, audit-ready compliance posture.

ITAR in the Aerospace Context

  1. ITAR stands for the International Traffic in Arms Regulations, codified at 22 CFR Parts 120–130 and administered by the State Department Directorate of Defense Trade Controls.
  2. ITAR controls the export and transfer of defense articles and technical data listed on the United States Munitions List, which includes spacecraft, satellites and related components and manufacturing data.
  3. ITAR applies to non-U.S. companies when they handle, retransfer or re-export U.S.-origin defense articles or technical data on the USML.
  4. A deemed export occurs when controlled technical data is released to a foreign person inside the United States, which requires prior DDTC authorization under 22 CFR § 120.17.
  5. ITAR registration is a baseline requirement alongside AS9100D certification for suppliers that produce spacecraft or satellite flight hardware under defense-related programs.

Three Core Actions for ITAR Compliance

  1. Register and maintain active DDTC registration. The annual renewal requirement mentioned earlier is mandatory. Conduct ITAR readiness self-assessments at minimum annually, timed to registration renewal, with lighter quarterly reviews for organizations with active foreign-person hiring or frequent product changes.
  2. Control access to ITAR-controlled technical data. Implement a written Technology Control Plan, restrict access to verified U.S. persons, deploy ITAR-compliant IT infrastructure, enforce MFA and role-based access control and retain access logs.
  3. Flow ITAR obligations through the supply chain. Sample subcontract language to confirm ITAR clauses are present and current, screen all counterparties against the Consolidated Screening List on a defined cadence and conduct annual reviews of all flow-down controls.

Conclusion: Selecting a Low-Risk ITAR Machining Partner

Qualifying a supplier for ITAR compliant spacecraft machining services requires structured verification across six domains. These domains include active DDTC registration, U.S.-person data-security controls, spacecraft alloy traceability, AS9102 FAI and CMM capability, CMMC or NIST alignment with subcontractor flow-down and prototype-to-flight scalability. Each step reduces program risk and creates a defensible audit record.

Precision Advanced Manufacturing is an ITAR-registered, AS9100D and ISO 9001-certified satellite hardware machining services provider operating from its California facility. Multi-axis CNC machining, precision fabrication, specialty welding and integrated finishing operate under a single quality system. This structure supports programs from engineering prototype through multi-shift full-rate production without supplier transitions or documentation gaps.

A precision machine shop floor with CNC equipment and work cells.
Advanced manufacturing under one roof — a climate-stable, AS9100D-run shop floor where multi-axis CNC, turning, and fabrication cells work prototype-to-full-rate volumes.

Request a quote and connect with Precision Advanced Manufacturing aerospace specialists to define program requirements, confirm certifications and receive a tailored production plan.

Frequently Asked Questions

Required Certifications for ITAR Spacecraft Machining Suppliers

A spacecraft machining supplier holds active DDTC registration with renewal addressed under 22 CFR § 122.2. DDTC registration establishes the legal baseline for handling ITAR-controlled technical data and manufacturing defense articles on the USML. AS9100D certification is the aerospace quality management standard that governs traceability, configuration management and supplier monitoring for flight hardware. ISO 9001:2015 supports the broader quality management system. For programs involving DoD contracts where systems process, store or transmit CUI, CMMC Level 2 alignment to NIST SP 800-171 Rev. 2 is increasingly required by prime contractors as a condition of subcontract award. Precision Advanced Manufacturing holds DDTC registration, AS9100D certification and ISO 9001:2015 certification at its California facility.

Purpose of a Technology Control Plan for ITAR Programs

A Technology Control Plan is a written document that describes how a supplier identifies, stores, accesses and protects ITAR-controlled technical data. It maps controlled data categories to physical and logical access controls, documents U.S.-person verification procedures for every user with system access, defines IT security controls including MFA and role-based access and establishes incident response and annual review processes. DDTC guidance and industry practice treat a Technology Control Plan as the foundational document for demonstrating that a supplier IT environment and facility controls prevent deemed exports, which are unauthorized releases of controlled data to foreign persons inside the United States. During supplier qualification, procurement and supplier-quality teams request the Technology Control Plan and compare it line by line against actual access controls, badge logs, IT permissions and physical facility layout to identify discrepancies.

Timing and Content of Full AS9102 First Article Inspection

A full AS9102 First Article Inspection is required at first production of a new part number, after a production lapse, after transfer of production to a different facility, after a major drawing revision and when mandated by the customer on the purchase order. The FAI package must include the three AS9102 forms described earlier, with Form 1 for part accountability, Form 2 for certifications and Form 3 for characteristic accountability. CMM inspection is required for tight-tolerance machined parts, complex geometries and GD&T controls. Precision Advanced Manufacturing produces full AS9102-compliant FAI packages with CMM-generated dimensional reports and complete material traceability documentation.

Interaction Between ITAR and CMMC for Machining Suppliers

As noted earlier, ITAR and CMMC address different risks, with ITAR controlling access and location and CMMC governing protection methods. When ITAR-controlled technical data is received or generated under a DoD contract, it is typically designated CUI under the Export Controlled category, which places the supplier in scope for CMMC Level 2 and its 110 NIST SP 800-171 Rev. 2 security requirements. ITAR compliance does not satisfy CMMC requirements, and CMMC certification does not replace ITAR obligations. Both programs are managed concurrently. Prime contractors including Boeing, Lockheed Martin and Raytheon are actively enforcing CMMC flow-down requirements and requesting NIST 800-171 compliance assurances from their supply chains.

Precision Advanced Manufacturing Support for Mid-Program Transitions

Precision Advanced Manufacturing supports mid-program supplier transitions through complete documentation, material traceability and engineering support that protect continuity. The team can begin with pilot builds or validation runs to reduce risk while integrating into existing supply chains. Because multi-axis CNC machining, precision fabrication, specialty welding and secondary finishing operate under a single AS9100D and ITAR-compliant quality system at its California facility, customers receive consistent documentation and traceability from the first pilot part through full-rate production. The integrated capability model removes handoffs between separate vendors and reduces the coordination burden on program managers during transitions.