Common ITAR Violations in Aerospace Supply Chains

Common ITAR Violations in Aerospace Supply Chains

Last updated: July 24, 2026

Key Takeaways for Aerospace ITAR Compliance

  • ITAR compliance applies to every aerospace supplier that manufactures, handles or transfers defense articles or technical data on the U.S. Munitions List, regardless of tier.
  • Frequent violations cluster around RFQ issuance, unmarked drawing release, supplier onboarding, unencrypted data transfers and unauthorized cloud storage.
  • Recent DDTC enforcement actions against GE Aerospace, RTX and Boeing show penalties from $36 million to $200 million for misclassification, unauthorized exports and registration failures.
  • Effective prevention relies on DDTC registration verification, export-control legends on all documents, encrypted data systems, citizenship screening and formal classification reviews at every program stage.
  • Precision Advanced Manufacturing provides a single ITAR-registered, AS9100D-certified partner that consolidates machining, fabrication and finishing under one roof to reduce supply-chain exposure, explore integrated ITAR manufacturing today.

High-Risk Supply-Chain Activities and Violation Patterns

Each major supply-chain step carries a documented pattern of ITAR exposure. The list below highlights the most frequent violation at each stage.

  • RFQ issuance: sharing controlled drawings with unvetted or foreign suppliers.
  • Drawing release: unmarked or improperly marked ITAR technical data.
  • Supplier selection: onboarding non-DDTC-registered Tier 2 or Tier 3 vendors.
  • Data transfer: unencrypted email or file-share of ITAR technical data.
  • Cloud storage: uploading controlled files to non-ITAR-compliant platforms.
  • Foreign-national access: deemed export of controlled data visible to non-U.S. persons.
  • Classification review: misclassifying USML items as EAR or EAR99.
  • Shipping and logistics: routing ITAR hardware through restricted or sanctioned countries.
  • Returns and reverse logistics: unauthorized retransfer or wrong-recipient shipment.
  • M and A integration: failure to update DDTC registration and Technology Control Plans after corporate restructuring.

The sections that follow examine each violation pattern in detail, starting with the earliest exposure point in the process: the RFQ stage.

Unauthorized Technical Data in RFQs

RFQs for ITAR-controlled items require a compliance gate because they often contain export-controlled technical data. Sharing that data with a foreign person, including a foreign national employed by a U.S. company, creates a deemed export violation before any part is manufactured.

The RTX Corporation consent agreement announced in August 2024 shows the scale of RFQ-stage exposure. RTX paid a $200 million fine to resolve 750 ITAR violations, some tied to misclassification that caused unauthorized exports to multiple countries. Weak jurisdiction reviews at the RFQ stage allowed controlled data to move without authorization.

Prevention Playbook: RFQ Stage

  • Verify DDTC registration status for every supplier before releasing any controlled document. This step confirms that the recipient is legally authorized to receive controlled data.
  • After registration is confirmed, mark all RFQ packages with an ITAR distribution-restriction legend before transmission so recipients understand that handling restrictions apply.
  • Document the authorization basis, whether license, agreement or exemption, in procurement records for every controlled data release to create the audit trail DDTC expects.

Unmarked Drawings Released to Suppliers

Many ITAR mistakes start in ordinary engineering workflows such as supplier quotes, shared folders and design reviews. When drawings lack export-control legends, downstream recipients receive no notice that handling restrictions apply, and the originating company remains liable.

In the GE Aerospace settlement, an F118 engine drawing went to a Chinese supplier without proper recognition that the data was ITAR-controlled. The drawing carried no flag that triggered trade-compliance review.

Prevention Playbook: Drawing Release

  • Apply ITAR export-control legends to every controlled drawing, model and specification at the point of creation.
  • Limit drawing-release permissions to authorized U.S. persons within the PLM or PDM system.
  • Audit released-document logs quarterly to confirm legends are present and recipients are authorized.

Onboarding Non-DDTC-Registered Tier 2 and Tier 3 Vendors

Aerospace OEMs and Tier 1 contractors often delegate compliance to supply chains but fail to confirm that Tier 2 and Tier 3 suppliers screen every transaction. U.S. authorities can pursue the top-tier entity for weak supervision of subcontractors.

ITAR applies to Tier 3 subcontractors that produce components integrated into USML-listed end items such as missiles, fighter jets or satellites, even when the manufacturer never exports anything itself. Any U.S. company that manufactures defense articles must register with DDTC even when no exports are planned.

Prevention Playbook: Supplier Selection

  • Screen every candidate supplier against the DDTC Debarred Parties List, Commerce Entity List and Treasury SDN list before issuing an RFQ.
  • Require written confirmation of DDTC registration and flow down ITAR obligations into all purchase orders and subcontracts.
  • Re-screen the existing vendor base on a recurring schedule, not only at onboarding.

Reduce your Tier 2 and Tier 3 exposure with Precision Advanced Manufacturing, a U.S.-based, ITAR-registered manufacturer whose integrated capabilities cut the supplier hand-offs that create compliance risk.

Unencrypted Data Transfers of ITAR Technical Files

Unencrypted transmission of ITAR technical data by standard email, FTP or unsecured file-share constitutes an unauthorized export when the recipient is a foreign person or the data crosses foreign infrastructure. This pattern is a primary deemed exports aerospace risk because the violation occurs at the moment of transmission.

Missing audit logs of technical-data transfers prevent proof of compliance and create independent ITAR violations that compound exposure. DDTC requires manufacturers to maintain records of all exports, exemptions and related transactions for at least five years.

Prevention Playbook: Data Transfer

  • Use encrypted, access-controlled portals for all ITAR technical data transfers, and prohibit standard email for controlled files.
  • Maintain an audit log for every transfer that captures the date, recipient, content description and authorization basis.
  • Confirm that no foreign national, including offshore IT support, can access the transfer system or its logs.

Unauthorized Cloud Storage of ITAR Data

Unauthorized cloud storage violations occur when controlled files are uploaded to general-purpose platforms such as SharePoint, Google Drive, Dropbox, GitHub or Jira where foreign administrators, overseas support teams or offshore affiliates can access them. Uploading ITAR-controlled technical data to cloud servers counts as an export to the country where the servers sit.

A documented case shows the risk at every tier. Controlled CAD drawings stored in a shared SharePoint folder created potential ITAR violations. The situation included a deemed export, an unauthorized transfer and a recordkeeping violation, all carrying significant civil penalty exposure.

Prevention Playbook: Cloud Storage

  • Use only ITAR-compliant, U.S.-based cloud environments with documented access controls that exclude foreign nationals and overseas support staff.
  • Avoid uploading controlled drawings, CAD models, source code or test data to general-purpose AI tools, meeting transcription services or design assistants.
  • Review cloud-platform permission settings and administrative access quarterly and document the results.

Foreign-National Access Without Authorization

A deemed export occurs when ITAR-controlled technical data is released to a non-U.S. person inside the United States. Visual access to a controlled document, verbal disclosure or physical presence in a controlled area where USML items are assembled is sufficient to create a deemed export.

This pattern sits at the center of many deemed exports aerospace cases. The GE Aerospace settlement illustrates it clearly. An employee left an unattended laptop containing USML technical data with university officials in China, one of the 116 violations detailed in the enforcement action discussed below.

Prevention Playbook: Foreign-National Access

  • Capture citizenship and visa status for all employees, contractors and visitors before granting access to any controlled area or data system.
  • Use zone-based access restrictions with mandatory U.S.-person escorts in areas where USML items or data are present.
  • Screen all visitors against the Consolidated Screening List before arrival and retain timestamped records for at least five years.

Misclassification of USML Items as EAR

Misclassifying USML items as EAR99 occurs when teams assume commercial-looking hardware falls under the Export Administration Regulations rather than ITAR, even when the part is specially designed for military or aerospace applications. Each shipment of a misclassified item creates a separate violation.

In the RTX consent agreement, a substantial portion of the 750 violations came from misclassification of defense articles as EAR-regulated items, which led to unauthorized exports to multiple countries. GE Aerospace also faced violations involving incorrect classification that bypassed trade-compliance review.

Prevention Playbook: Classification

  • Conduct a formal jurisdiction and classification review for every part number at the program level before any transfer occurs.
  • Use change management controls so that classification decisions are re-evaluated when design changes, new applications or corporate restructuring occur.
  • Train engineering, procurement and logistics staff to escalate any classification uncertainty to the Empowered Official before data or hardware moves.

Shipping and Returns Through Restricted Routes

General Electric failed to configure its logistics systems to prevent ITAR-controlled shipments from transiting restricted countries, which showed weak oversight of freight forwarders and shipping routes. Engine maintenance manuals were transshipped through China on the way to Singapore.

Returns create similar risk. A USML engine combustion liner went to Sweden instead of the intended U.S. recipient.

Prevention Playbook: Shipping and Returns

  • Provide freight forwarders with written ITAR routing instructions that clearly prohibit transit through restricted or sanctioned countries.
  • Use a dual-verification step for shipping documentation on all USML hardware before release to the carrier.
  • Treat every return shipment as a new export event that requires classification review and authorization confirmation.

M&A Integration Without Updated Technology Control Plans

GE Aerospace did not notify DDTC of material changes to its registration after corporate restructuring. Authorization management issues appeared as a root cause across many of the violations.

Corporate events such as mergers, acquisitions, spin-offs and name changes require immediate DDTC registration review. When Technology Control Plans stay unchanged after these events, the combined entity operates under controls that no longer match its structure, personnel or data flows.

Prevention Playbook: M&A Integration

  • Trigger a full ITAR compliance review, including DDTC registration update, TCP revision and classification audit, within five business days of any material corporate change.
  • Assign the Empowered Official responsibility for signing and submitting all DDTC registration amendments before integration activities begin.
  • Audit all authorization management SOPs inherited from acquired entities and retire any that are more than two years old without documented review.

Penalties and Recent ITAR Cases, 2025–2026

Recent DDTC Enforcement Actions

  • GE Aerospace, $36 million (April 2026): 116 ITAR violations from 2018 to 2024, including unauthorized exports of F-35 and F414 engine technical data to China, misclassification of USML items and failure to update DDTC registration after corporate restructuring. A 36-month consent agreement requires an external Special Compliance Officer for at least 24 months.
  • RTX Corporation, $200 million (August 2024): 750 ITAR violations across Collins Aerospace, Pratt and Whitney and Raytheon, driven by misclassification of defense articles as EAR-regulated items. Half of the penalty is allocated to remedial compliance measures.
  • Boeing, $51 million: Resolved alleged AECA and ITAR violations involving unauthorized exports and weak compliance controls across multiple business units and supply-chain tiers.

How to Vet and Onboard an ITAR-Compliant Precision Manufacturer

This eight-step checklist aligns with the certifications, processes and capabilities maintained by Precision Advanced Manufacturing under AS9100D, ISO 9001:2015 and ITAR-registered quality systems.

  1. Confirm DDTC registration. Request the supplier’s current DDTC registration certificate. Verify that registration is active and covers the relevant USML categories for the program. Precision Advanced Manufacturing maintains active ITAR registration for defense and space-related programs.
  2. Verify AS9100D and ISO 9001:2015 certification. Request current certificates from an accredited registrar. Confirm that the scope covers the manufacturing processes, including machining, fabrication and finishing, required for the program. Precision Advanced Manufacturing holds both registrations.
  3. Review the Technology Control Plan. Confirm that the supplier has a written TCP that addresses data marking, access controls, cloud storage policy, visitor management and foreign-national access restrictions. Ask when the TCP was last updated and audited.
  4. Screen against denied-party lists. Run the supplier and its key personnel against the DDTC Debarred Parties List, Commerce Entity List and Treasury SDN list. Document the screening date, lists checked and results, then repeat screening at least annually.
  5. Assess data-handling controls. Confirm that the supplier uses encrypted, access-controlled systems for ITAR technical data. Verify that no foreign nationals or overseas support staff can access controlled repositories, portals or PLM systems.
  6. Evaluate integrated capabilities to reduce hand-offs. Each supplier hand-off, such as machining to finishing or fabrication to coating, creates a new data-transfer and access-control event. Suppliers that consolidate multi-axis machining, fabrication and finishing under one roof reduce the number of ITAR exposure points. Precision Advanced Manufacturing integrates these capabilities at facilities in California and Texas.
  7. Confirm traceability and documentation systems. Require full material traceability, in-process inspection records and final inspection reports for every deliverable. Confirm that the supplier retains export-related records for at least five years per DDTC requirements.
  8. Conduct a pre-award compliance audit or pilot build. Before full-rate production, run a pilot build or validation lot. Review quality records, inspection reports and ITAR documentation from the pilot to confirm that compliance is built into production, not added afterward.

Start the vetting process and connect with Precision Advanced Manufacturing’s aerospace specialists, a supplier that already meets every step on this checklist.

Conclusion: Reducing ITAR Risk Across Every Tier

Every hand-off in the aerospace supply chain, from RFQ to drawing release and from data transfer to logistics, creates an ITAR violation opportunity. The enforcement record from 2024 through 2026 shows that misclassification, unauthorized foreign access, unencrypted transfers and outdated compliance procedures carry penalties measured in tens or hundreds of millions of dollars, along with debarment risk.

Precision Advanced Manufacturing reduces the hand-offs that generate these risks. As a U.S.-based, ITAR-registered manufacturer operating under AS9100D and ISO 9001:2015 certified quality systems, Precision Advanced Manufacturing consolidates multi-axis CNC machining, precision sheet-metal fabrication, specialty welding and secondary finishing under one roof at facilities in California and Texas. Controlled technical data stays within a single, auditable environment. Traceability is built into every production step, and classification, access controls and documentation align to the standards DDTC auditors expect.

Procurement managers, program managers and supplier quality engineers who need a single ITAR-registered partner that removes supply-chain fragmentation and the compliance gaps that come with it can begin that conversation now.

Connect with our aerospace team at Precision Advanced Manufacturing.

Frequently Asked Questions

What is a deemed export in aerospace manufacturing supply chains?

A deemed export occurs when ITAR-controlled technical data is released to a foreign national inside the United States. The release does not require a physical shipment. Visual access to a controlled drawing on a workstation, participation in a meeting where controlled specifications are discussed or access to a shared file repository all constitute deemed exports when the recipient is a non-U.S. person. In aerospace manufacturing, this risk appears across every tier, from Tier 1 OEM engineering reviews to Tier 3 machine shop floor access. Foreign national employees on H-1B or other visas are treated as non-U.S. persons under ITAR. Granting them access to controlled technical data without a DDTC license or applicable exemption creates a violation. Aerospace manufacturers should implement citizenship capture at onboarding, zone-based access controls in facilities and access-restricted repositories for all controlled data.

How does ITAR apply to Tier 2 and Tier 3 aerospace suppliers?

ITAR applies to every company in the supply chain that manufactures, handles or receives defense articles or controlled technical data listed on the U.S. Munitions List. This coverage includes Tier 2 and Tier 3 subcontractors that produce components integrated into USML-listed end items, even when those companies never export anything themselves. Any U.S. company that manufactures defense articles must register with DDTC. Tier 1 contractors hold responsibility for supervising their supply chains, and DDTC can pursue top-tier entities for failures to confirm that Tier 2 and Tier 3 suppliers screen transactions and partners appropriately. Procurement teams should flow ITAR obligations down through purchase orders and subcontracts, verify DDTC registration before onboarding any supplier and re-screen the vendor base on a recurring basis.

What makes cloud storage a specific ITAR risk for aerospace manufacturers?

Uploading ITAR-controlled technical data to a cloud platform counts as an export to the country where the servers are located. Even when servers sit in the United States, access by foreign nationals, including overseas IT administrators, offshore support teams or foreign-national employees working remotely, creates a deemed export. General-purpose platforms such as SharePoint, Google Drive, GitHub or project management tools are high risk because they often expose controlled files to broad user groups without strong access controls. Aerospace manufacturers should use ITAR-compliant, U.S.-based cloud environments with documented access restrictions that exclude foreign nationals and overseas support staff. Uploading controlled drawings, CAD models or manufacturing notes into AI tools or meeting transcription services creates the same risk because the data may be disclosed to the tool provider’s support personnel or overseas infrastructure.

What causes most ITAR misclassification violations in aerospace supply chains?

Misclassification violations occur when teams assume a part or dataset is commercial, either EAR-controlled or EAR99, without a documented jurisdiction and classification review. Parts that appear commercial but are specially designed for military or aerospace applications often fall under the USML and require State Department authorization before any transfer. Common root causes include applying the wrong Export Control Classification Number before a trade-compliance review, using outdated classification records that predate design changes or new applications and failing to re-evaluate classification after corporate events such as mergers or spin-offs. Each shipment of a misclassified item creates a separate ITAR violation. Aerospace manufacturers should use a formal classification review process at the program level, with change management controls that require re-evaluation whenever design, application or corporate structure changes.

How does a single ITAR-registered manufacturer reduce supply-chain compliance risk?

Each supplier hand-off in an aerospace supply chain creates a new ITAR compliance event. When a program uses one vendor for machining, a second for fabrication and a third for finishing, controlled technical data must be transferred, access must be authorized and documentation must be maintained at each transition. Each transfer point becomes an opportunity for a deemed export, an unauthorized disclosure or a recordkeeping gap. Consolidating machining, fabrication and finishing under one ITAR-registered, AS9100D-certified roof removes those intermediate transfers. Technical data stays within a single auditable environment. Access controls, traceability and documentation apply consistently across the full production process. Precision Advanced Manufacturing integrates these capabilities at U.S. facilities, operating under ITAR-registered and AS9100D and ISO 9001:2015 certified quality systems built for mission-critical aerospace and defense programs.