Last updated: July 27, 2026
Key Takeaways
- ITAR compliance for sheet metal fabricators requires active DDTC registration plus a documented program for personnel screening, data security, physical controls, traceability and recordkeeping. No official “ITAR certification” exists.
- Eight mandatory requirements apply, including U.S.-person-only access, a written Technology Control Plan, secure storage of technical data and full material traceability from raw stock through finishing.
- Common violations such as releasing controlled data to foreign nationals, using non-compliant cloud storage or failing to flow down ITAR clauses to subcontractors can result in penalties exceeding $1 million per violation.
- Buyer qualification should verify active DDTC registration, AS9100D and ISO 9001 certifications, documented access controls and annual self-assessments before awarding defense or aerospace programs.
- Precision Advanced Manufacturing maintains active ITAR registration under AS9100D and ISO 9001:2015; contact the team to receive a compliance documentation package and begin supplier qualification.
8 Core Requirements for ITAR-Compliant Sheet Metal Fabrication
This checklist maps each core DDTC obligation directly to sheet metal fabrication workflows. Each item is a mandatory requirement, not a best practice.
- Any person engaging in the United States in the business of manufacturing or exporting defense articles or furnishing defense services must register with the Directorate of Defense Trade Controls under 22 CFR 122.1. One occasion of covered manufacturing is enough to trigger this obligation. Renewal requirements appear separately in 22 CFR 122.2.
- Access to ITAR defense articles and technical data is restricted to U.S. persons, defined in 22 CFR 120.62 to include U.S. citizens, lawful permanent residents, certain refugees or asylees (protected individuals under 8 U.S.C. §1324b(a)(3)) and U.S. entities.
- A written Technology Control Plan (TCP) that covers physical controls, IT controls, personnel screening, visitor procedures and incident response.
- ITAR-controlled technical data stored with access limited to authorized U.S. persons.
- Physical controls for manufacturing areas where ITAR-controlled sheet metal is cut, formed, assembled or stored.
- Material traceability maintained from raw stock through finishing and shipment.
- ITAR flow-down clauses included in all subcontractor and finishing-vendor purchase orders.
- Retention of all ITAR-related records, including access logs, visitor logs, shipping documents and technical data transfers, under 22 CFR § 122.5.
Precision Advanced Manufacturing operates under AS9100D, ISO 9001:2015 and active ITAR registration, with all eight obligations embedded in its quality management system. Start supplier qualification by requesting documentation that maps these controls to each requirement.
DDTC Registration and Annual Renewal Obligations
Under 22 CFR 122.1(a), any U.S. person who engages in the business of manufacturing a defense article must register with DDTC, even without export activity. A single occasion of covered manufacturing triggers this obligation, which is fulfilled through DDTC’s electronic Defense Export Control and Compliance System (DECCS).
Once registered, the fabricator must renew annually before the registration expiration date. The renewal request is submitted through DECCS. A lapse requires payment of back fees for any intervening period of ITAR-controlled activity.
The three-tier fee structure under 22 CFR 122.3 sets Tier 1 at $3,000 annually for new registrants or those with no favorable DDTC license determinations in the prior period. Tier 2 is $4,000 for renewing registrants with five or fewer favorable determinations. Tier 3 adds a per-determination fee above that threshold. Most sheet metal fabricators that do not regularly submit DDTC license applications fall into Tier 1.
Paying the registration fee does not establish compliance with ITAR’s operational requirements. Registration is not a finding of compliance. DDTC registration does not confer export rights or privileges. It serves as a threshold precondition for applying for ITAR licenses or approvals.
Because registration is often misunderstood, buyers frequently ask whether a fabricator can be “ITAR certified.”
ITAR Registration vs Informal “Certification” Language
No official “ITAR certified” designation exists. DDTC issues registration, not certification. A fabricator claiming to be “ITAR certified” is using informal shorthand. The qualifying question is whether the fabricator holds active DDTC registration and maintains a documented compliance program covering personnel, data, facilities and supply chain.
Personnel and Visitor Access Controls Limited to U.S. Persons
Under ITAR, access to USML defense articles and technical data is limited to U.S. persons as defined in requirement 2 above. Disclosure of controlled technical data to a foreign national inside the United States constitutes a deemed export under 22 CFR § 120.50 and requires prior DDTC authorization.
Fabricators must verify U.S. person status before granting any employee or contractor access to controlled data or hardware. Human resources must notify the compliance function before extending offers to foreign nationals for positions involving ITAR-controlled activities. Annual ITAR training is required for all personnel handling controlled information, with records retained for a minimum of three years.
Beyond permanent personnel, temporary visitors to controlled areas require equally rigorous controls. Visitor protocols require preapproval, escorted access through controlled areas, cleared screens and whiteboards before entry and a compliant visitor log capturing arrival time, departure time, purpose, escort identity and citizenship status. Foreign national visitors require an approved DDTC license or documented license exemption determination before accessing controlled areas or data. This determination must be documented.
The 2018 FLIR Systems settlement resulted in $30 million in civil penalties for multiple ITAR violations, including unauthorized exports to foreign-person employees. Personnel access failures are among the most common and costly ITAR violations in manufacturing environments.
Technical Data Security, Storage and Transmission Rules
ITAR-controlled technical data includes CAD models, drawings, schematics, manufacturing notes, test procedures and repair instructions for USML items. Every document and digital file containing such data must carry an ITAR legend restricting distribution to U.S. persons unless authorized by the U.S. Department of State.
Storage must use access-controlled folders or repositories separate from commercial data, with role-based permissions restricted to verified U.S. persons. Standard commercial cloud services are not compliant for ITAR data storage because cloud provider administrators may be foreign nationals. Only environments such as AWS GovCloud (US), Microsoft Azure Government or Google Cloud Government with U.S.-person-only operations models meet this requirement, and the manufacturer’s own account administrators must also be U.S. persons.
Network segmentation must isolate systems containing ITAR-controlled data, and multi-factor authentication is required for all access points. These perimeter controls must extend to outbound communications. Emails containing ITAR file attachments to foreign email domains must be blocked or flagged, and sharing of ITAR folders to external accounts must be disabled.
A written TCP must govern all data handling through role-based access, multi-factor authentication, granular file permissions and regular vulnerability scanning. Access logs must document employee identity, timestamp, file path and action taken for every access to controlled repositories, retained under 22 CFR § 122.5. Understanding which data requires these controls begins with a clear definition of what qualifies as ITAR-controlled technical data in fabrication.
ITAR-Controlled Technical Data in Sheet Metal Operations
Any information required to design, develop, produce, manufacture, assemble, operate, repair, test, maintain or modify a defense article is ITAR-controlled. In a sheet metal fabrication context, this includes part drawings, forming and bending instructions, weld procedures, finishing specifications, inspection criteria and test results tied to USML items. Photos linked to controlled design or production details and emails discussing controlled technical content also qualify.
Physical Facility and Material Traceability Controls
ITAR-controlled manufacturing areas must implement physical security measures that restrict entry to authorized U.S. persons only. Every entry and exit must create an audit trail.
Material traceability begins at raw stock receipt and must be maintained through finishing and shipment. This traceability obligation extends to material that does not reach the customer. Scrap from ITAR-controlled sheet metal work requires physical segregation and controlled disposal. Under FAR 45.606(b), classified or otherwise controlled scrap may require unique disposal processing or separate plant clearance reporting. Fabricators must record actual material usage and scrap, and obtain authorization before disposing of any unused, excess or scrap material from controlled programs.
Finishing subcontractors, including anodizing, passivation, plating and similar operations, present a significant traceability risk because parts leave the fabricator’s direct control. To maintain chain of custody, ITAR-controlled parts must be immediately segregated upon receipt at the finishing facility. Segregation alone is insufficient. Parts must then be stored in designated locked areas with entry restricted to verified U.S. employees, and tracked with serialized job travelers through every process step to prevent commingling with commercial work. Fabricators must include ITAR flow-down clauses in all purchase orders. Work transfer to sub-tier suppliers without prior written authorization is prohibited under standard defense supply chain requirements.
Precision Advanced Manufacturing integrates secondary finishing services, including anodizing, passivation, plating, sandblasting and ultrasonic cleaning, under its AS9100D quality system, maintaining chain-of-custody traceability without transferring oversight risk to unvetted vendors. Despite clear requirements, fabricators frequently fail to implement these controls correctly, which results in costly violations.
Common ITAR Violations in Fabrication Environments
Civil penalties for ITAR violations reach $1,271,078 per violation or twice the transaction value, whichever is greater. Criminal penalties include fines up to $1 million and imprisonment up to 20 years per count, with possible debarment from defense contracting. In 2011, BAE Systems paid a $79 million fine for 2,591 ITAR violations.
The most common violations in sheet metal and fabrication environments fall into three categories. Registration failures include treating DDTC registration as sufficient without maintaining a documented compliance program, failing to register when producing USML items and failing to renew on time (see registration section for lapse consequences). Personnel and data access violations include releasing controlled technical data to foreign-national employees without a deemed-export license, using non-compliant cloud storage (see technical data section for approved alternatives) and visitor logs that omit citizenship status or escort identity. Supply chain and material control violations include transferring controlled hardware to finishing subcontractors without confirming their DDTC registration, inadequate scrap segregation and omitting ITAR flow-down clauses from purchase orders.
Because these violations carry severe penalties and can disrupt supply chains, buyers must verify that fabricators have controls in place to prevent them.
Buyer Qualification Checklist for ITAR-Registered Fabricators
Because ITAR violations carry severe penalties and can disrupt supply chains, supplier quality engineers and procurement managers must verify that fabricators have documented controls in place. The following checklist focuses on how to confirm those controls before awarding a defense or aerospace sheet metal program.
- Verify active DDTC registration by requesting the registration number and confirming currency through DECCS or direct DDTC confirmation.
- Confirm AS9100D and ISO 9001:2015 registrations with current certificates from an accredited registrar.
- Request a copy of the written Technology Control Plan.
- Review documented U.S. person screening procedures for all employees and contractors with access to controlled data or hardware.
- Inspect physical controls for ITAR-controlled manufacturing areas, including badge-reader or equivalent access controls.
- Confirm access controls for all systems storing ITAR technical data and verify hosting on compliant cloud infrastructure.
- Review material traceability records from raw stock through finishing.
- Check that ITAR flow-down clauses appear in all subcontractor and finishing-vendor purchase orders.
- Confirm a record retention program covering access logs, visitor logs, shipping documents and technical data transfers under 22 CFR § 122.5.
- Request evidence of an annual internal ITAR self-assessment with documented results and corrective actions.
Precision Advanced Manufacturing meets every item on this checklist. Verify compliance by requesting documentation that addresses each checklist item.
Next Steps: Compliance Documentation and Program Review
Qualifying an ITAR-registered sheet metal fabricator requires more than a registration number. It requires documented evidence that every pillar, including registration, personnel controls, data security and material traceability, is active and auditable. Precision Advanced Manufacturing provides compliance documentation packages, inspection reports, material certifications and program review support to accelerate supplier qualification for defense and aerospace programs.
Operations span two specialized facilities in California and Texas, supporting prototype through full-rate production under AS9100D, ISO 9001:2015 and active ITAR registration. This integrated structure eliminates the traceability risks that arise when fabricators rely on external finishing vendors. Every program benefits from sheet metal fabrication, multi-axis CNC machining, precision welding and in-house finishing under one quality system with no traceability gaps between vendors.
Once a fabricator passes initial qualification, the next step is to request formal compliance documentation and schedule a detailed program review. Schedule a program review and receive the documentation needed to complete supplier qualification.
Frequently Asked Questions
The following questions address common points of confusion that arise during supplier qualification and program setup.
Difference Between ITAR Registration and ITAR Compliance
ITAR registration is the formal act of enrolling with DDTC under 22 CFR Part 122. It is a legal prerequisite for manufacturing defense articles in the United States and requires periodic renewal. ITAR compliance is the broader, ongoing obligation to maintain personnel access controls, technical data security, physical facility controls, material traceability, subcontractor oversight and recordkeeping in accordance with applicable ITAR provisions. A fabricator can hold active registration while remaining noncompliant if any of those operational obligations are unmet. Procurement and supplier quality teams must evaluate both the registration status and the documented compliance program when qualifying a fabricator for a defense program.
Meaning of ITAR Flow-Down for Subcontractors and Finishers
ITAR flow-down means that every obligation applicable to the prime fabricator must pass through contractually and operationally to any sub-tier supplier receiving ITAR-controlled hardware or technical data. This includes finishing vendors performing anodizing, passivation, plating or other secondary operations on defense-related sheet metal components. The sub-tier supplier must hold active DDTC registration, maintain a functioning compliance program, segregate controlled parts upon receipt, restrict access to U.S. persons and maintain chain-of-custody documentation. The prime fabricator remains responsible for confirming sub-tier compliance before any transfer occurs. Purchase orders must include explicit ITAR flow-down clauses, and work transfer to unapproved sub-tier suppliers is prohibited under standard defense supply chain requirements.
Record Retention Periods for ITAR-Registered Fabricators
Under 22 CFR § 122.5, ITAR-related records must be retained for the period required from the date of the transaction or the expiration of the relevant license or agreement. This retention requirement covers export licenses, technical data transfer records, access logs documenting who accessed controlled data and when, visitor logs for controlled-area entries, shipping documents and end-use documentation. Records must be maintained in a format that prevents unauthorized alteration and preserves an audit trail. When an investigation or litigation is pending, destruction schedules must be suspended. Cloud-stored records must reside in infrastructure that restricts access exclusively to U.S. persons.
ITAR Registration Costs for Sheet Metal Fabricators in 2026
DDTC uses a three-tier fee structure. Tier 1 applies to new registrants and renewing registrants who received no favorable DDTC license determinations in the prior period, with an annual fee of $3,000. Tier 2 applies to renewing registrants with five or fewer favorable determinations and carries a $4,000 annual fee. Tier 3 adds a per-determination fee for registrants exceeding that threshold. Most sheet metal fabricators that do not regularly submit DDTC license applications fall into Tier 1 and pay $3,000 per year. Registration alone does not represent the full cost of ITAR compliance. A complete first-year compliance program, including documentation, training and classification review, carries additional implementation costs that vary by company size and program scope.
Loss of ITAR Registration and Consequences
DDTC can suspend or revoke registration for violations of ITAR provisions, and a lapse caused by failure to renew on time requires payment of back fees for any intervening period of controlled activity. Beyond registration loss, ITAR violations carry civil penalties up to $1,271,078 per violation or twice the transaction value, criminal fines up to $1 million per count, imprisonment up to 20 years per count and debarment from future defense trade. Reputational consequences include loss of existing defense contracts and disqualification from future program awards. Voluntary self-disclosure of suspected violations to DDTC is recognized as a mitigating factor in determining administrative penalties and is recommended when a potential violation is identified.