Last updated: July 29, 2026
Key ITAR Requirements for Sheet Metal Fabricators
- ITAR compliance for sheet metal fabricators functions as an ongoing discipline that covers physical access, digital controls, personnel screening, recordkeeping and documented training.
- Auditors first confirm three foundations: DDTC registration, documented access controls that restrict ITAR data to U.S. persons and five-year minimum auditable record retention.
- Frequent violations include unauthorized technical data transfers, deemed exports to foreign nationals, missing ITAR markings, weak physical access controls and cloud or IT misconfigurations.
- Buyers can verify compliance through active DDTC registration, a named Empowered Official, access controls, ITAR markings, documented training and a Technology Control Plan when foreign nationals are present.
- Precision Advanced Manufacturing maintains active DDTC registration, AS9100D and ISO 9001:2015 certifications and full traceability documentation. Start a qualification review with complete compliance support.
Three Core Actions That Establish ITAR Compliance
Three actions create the base that auditors confirm at the start of any ITAR review.
- Register with DDTC. Manufacturers of defense articles must register with the Directorate of Defense Trade Controls (DDTC) even when no physical export occurs.
- Implement and document access controls. Operations must restrict all ITAR-controlled technical data and hardware to U.S. persons. Facilities enforce physical barriers, role-based digital permissions, visitor logs and individual authentication on every system that stores controlled data.
- Maintain auditable records for a minimum of five years. 22 CFR § 122.5 requires registrants to maintain records concerning the manufacture, acquisition and disposition of defense articles, technical data, defense services, brokering activities and documentation on exports, exemptions, applications and licenses, with electronic records reproducible on paper.
Precision Advanced Manufacturing operates under all three controls as daily practice rather than as short-term audit preparation.
DDTC Registration Steps and 2025 Fee Updates
DDTC registration follows a defined sequence that begins with executive approval. A senior U.S. person officer such as a CEO, president or general counsel signs and submits Form DS-2032 electronically through the DDTC DECCS portal. Processing typically takes 30 to 60 days. After approval, DDTC issues a registration code that must appear on all export documents for ITAR-controlled items.
A December 10, 2024 DDTC final rule (89 FR 99081), effective January 9, 2025, updated the fee structure:
- Tier 1: A set fee of $3,000 per year that applies to new registrants and to those renewing registrations for whom the Department did not issue a favorable determination on a license application or other request for authorization during the 12-month period ending 90 days prior to the expiration of the current registration.
- Tier 2: $4,000 for registrants with five or fewer approvals
- Tier 3: $4,000 plus $1,100 for each approval beyond the first five
DDTC registration renewal becomes available to submit 60 days prior to expiration, and preparation can begin at 90 days. A lapsed registration constitutes a separate ITAR violation. Every registered company must also designate an Empowered Official, a U.S. person directly employed by the company with authority to commit it to legally binding actions.
No government-issued “ITAR certification” exists. When prime contractors ask whether a supplier is “ITAR certified,” they seek confirmation of active DDTC registration under 22 CFR Part 122 and a documented Trade Compliance Program.
Frequent ITAR Violations in Fabrication Environments
Enforcement data and DDTC consent agreements highlight recurring violation patterns that appear often in sheet metal fabrication shops.
- Unauthorized technical data transfers: Emailing controlled CAD files or drawings to a foreign supplier for quoting purposes constitutes an export, even when no part is manufactured. University of Tennessee professor John Reece Roth was convicted under the Arms Export Control Act and sentenced to four years in prison for allowing foreign students access to sensitive data on military drone technology and taking data to China without a license.
- Deemed export violations: Allowing a foreign national employee, including H-1B visa holders, to access controlled drawings, CAD files or manufacturing instructions without a DDTC license counts as an export under 22 CFR § 120.17. Companies have paid penalties for unauthorized disclosures to foreign nationals at their facilities.
- Unmarked technical data: Drawings, digital files and shop floor documents that contain ITAR-controlled data must carry the appropriate export-control legend. Missing markings create a standalone violation.
- Inadequate physical access controls: Controlled articles stored in unrestricted areas, unescorted visitors in fabrication zones and missing visitor logs all represent access-control failures.
- Cloud and IT misconfigurations: The U.S. Department of State concluded a $200 million ITAR settlement with RTX in 2024 for export violations stemming from improper classification of defense articles and unauthorized exports including by employee hand-carry to proscribed countries. Backups stored on non-U.S. servers and admin privileges granted without U.S. person verification often trigger similar issues.
- Incomplete recordkeeping: Missing inventory records, absent training certifications and destroyed records create audit failures that increase penalties.
ITAR violations do not require intent. Negligent or accidental unauthorized disclosure can result in significant civil and criminal penalties, including fines and imprisonment.
Verifying Whether a Supplier Operates ITAR Compliantly
Buyers and supplier quality engineers can verify compliance through a structured audit approach that begins with registration and extends into daily practice. Active DDTC registration forms the starting point, and the supplier must provide its registration code and confirm current status. Several operational indicators then distinguish a functioning program from a paper-only policy set.
- A documented Trade Compliance Program with a named Empowered Official
- Physical access controls such as badge readers, keypad locks and posted signage that separate controlled manufacturing areas
- Visitor logs that capture arrival time, departure time, escort identity and citizenship status
- Role-based digital access controls on PLM, ERP and network folders that store controlled data
- ITAR markings on all controlled drawings and digital files
- Documented employee training records with completion dates
- A Technology Control Plan when foreign nationals are employed or hosted
- Five-year minimum record retention with accessible, auditable files
The compliance infrastructure described in this article already operates at Precision Advanced Manufacturing, including registration, access controls, training and records. Access the full evidence package that supplier quality teams review during qualification.
Shop Floor Access Controls for ITAR Work
Physical and digital access controls form the most audited element of any shop-floor ITAR program. ITAR-controlled manufacturing areas must be physically separated, clearly designated with posted signage and restricted by badge readers or keypad locks to authorized personnel only.
Digital practices must support the same discipline. Shared credentials on production floor terminals violate ITAR deemed-export rules and CMMC access-control requirements because individual attribution becomes impossible. Every person who accesses controlled data must authenticate individually.
Key shop-floor access control requirements include:
- Physical barriers that separate ITAR-controlled areas from general production
- Individual authentication, not shared logins, on all terminals that display controlled drawings or specifications
- Visitor escort and logging for every controlled-area entry, including citizenship status
- Color-coded visitor badges that provide immediate visual indicators of access level
- Shop floor printers that produce controlled drawings located in secured areas with print logging enabled
- Role-based access controls on all PLM, ERP and network systems that store controlled data
- Foreign national access documented with license or exemption determination before entry
Precision Advanced Manufacturing structures multi-axis CNC and precision sheet metal fabrication operations around these controls. Traceability systems document material and process custody at every production step to support ITAR compliance and AS9100D flow-down requirements.
ITAR Record Retention Expectations for Metal Fabricators
22 CFR § 122.5 requires maintaining records for a minimum period that begins on the date of the transaction. For licenses that cover multiple shipments, the clock starts after the last transaction under that license. Defense contracts governed by FAR and DFARS may impose retention periods up to ten years, which supersede the ITAR minimum for specific record types.
Required records for a sheet metal fabricator include:
- Export license applications, approvals and amendments (DSP-5, DSP-61, DSP-73)
- Shipping documents and Electronic Export Information filings
- Records of all technical data disclosures to foreign persons, including oral and visual disclosures
- Foreign national visitor logs with nationality and escort details
- Employee ITAR training records with completion certificates (minimum five-year retention)
- Technology Control Plans and all amendments
- Inventory records for ITAR-controlled articles with part numbers, serial numbers, locations and custody transfers
- Restricted-party screening results
- DDTC correspondence
Electronic recordkeeping is permissible under 22 CFR § 122.5(b) when records remain accurate, complete and accessible for DDTC inspection. Cloud storage is permissible only in ITAR-compliant environments that restrict access to U.S. persons. If an organization is under investigation, normal destruction schedules must pause until the matter resolves.
Many compliance programs treat the five-year floor as a minimum and retain records for seven to ten years to provide a buffer against late-emerging enforcement actions.
How NIST SP 800-171 and ITAR Interact for Sheet Metal Suppliers
ITAR and NIST SP 800-171, which forms the basis for CMMC Level 2, operate as parallel obligations with different agencies, control sets and enforcement mechanisms. ITAR, administered by the State Department’s DDTC under 22 CFR Parts 120-130, governs who may access defense-related technical data and where that data may reside. CMMC, enforced by the Department of Defense through contractual requirements, governs how Controlled Unclassified Information is technically protected through 110 cybersecurity practices.
A supplier can hold full ITAR registration and still fail a CMMC Level 2 assessment. ITAR does not require immutable audit logs for all CUI access events, FIPS 140-2 validated encryption for data at rest and in transit, a System Security Plan that documents all 110 NIST SP 800-171 controls or multi-factor authentication for CUI system access.
Both frameworks apply at the same time when a supplier handles ITAR-controlled technical data under a Department of Defense contract. CMMC Phase II requirements, originally scheduled to begin November 10, 2026 and make C3PAO certification mandatory for applicable Level 2 contracts, were suspended by the Department of War on July 13, 2026.
Supplier Qualification Checklist for ITAR Programs
Procurement managers and supplier quality engineers can use this checklist to evaluate ITAR compliance readiness during supplier qualification or re-qualification audits.
- Active DDTC registration confirmed with valid registration code
- Named Empowered Official documented and currently employed
- Written Trade Compliance Program in place and current
- Physical access controls such as badge readers, keypad locks and signage that separate controlled areas
- Visitor log that captures arrival time, departure time, escort identity and citizenship status
- Individual authentication enforced on all terminals that access controlled drawings or specifications
- Role-based access controls on PLM, ERP and network folders that store ITAR data
- ITAR export-control legends on all controlled drawings and digital files
- Technology Control Plan in place when foreign nationals are employed or hosted
- Employee ITAR training records with completion dates retained for a minimum of five years
- New employees complete ITAR training before accessing controlled data
- Five-year minimum record retention program with accessible, auditable files
- Inventory records for ITAR-controlled articles with serial numbers and custody transfers
- Restricted-party screening results documented for all employees and visitors
- Voluntary disclosure procedures documented per 22 CFR § 127.12
- Annual self-assessment of the compliance program completed and documented
- AS9100D or equivalent quality management system certification active
- Full material and process traceability documentation available for audit
- Flow-down clause compliance verified for all ITAR-relevant subcontractors
Precision Advanced Manufacturing satisfies every item on this checklist as a standing operational condition rather than as a pre-audit exercise. Receive full compliance documentation with the initial response.
Conclusion: Applying This ITAR Evaluation Framework
ITAR compliance for sheet metal fabrication suppliers requires active DDTC registration, continuous access controls, documented training and auditable records maintained for at least five years. The 2025 fee structure update, recent USML revisions and CMMC Phase 2 developments all shape the compliance burden on suppliers and the qualification risk for buyers that select unverified partners.
These requirements, including registration, access controls, training and records, form the operational foundation at Precision Advanced Manufacturing. Multi-axis CNC machining and precision sheet metal fabrication capabilities run on the same compliance infrastructure that supports every defense and aerospace program the company serves.
Procurement managers, supplier quality engineers and program managers working on ITAR-controlled programs can begin qualification with complete documentation already prepared. Begin qualification with a supplier that maintains standing export-control discipline.
Frequently Asked Questions
Does ITAR registration expire, and what happens if a supplier lets it lapse?
ITAR registration requires periodic renewal, with submission available 60 days before expiration and preparation beginning at 90 days. A lapsed registration counts as a separate ITAR violation. A supplier that allows registration to lapse and later seeks to re-register must pay registration fees for any intervening period during which it continued manufacturing or exporting defense articles or services. Buyers should verify active registration status, not only historical registration, before awarding ITAR-controlled work.
What is a deemed export, and why does it matter for sheet metal fabrication shops?
A deemed export occurs when ITAR-controlled technical data is disclosed to a foreign national inside the United States. The disclosure is treated as an export to that person’s country of origin under 22 CFR Part 120. For a sheet metal fabrication shop, a foreign national employee or visitor who views a controlled drawing, CAD file or manufacturing instruction, even briefly on a shared terminal, triggers an export event unless a DDTC license or applicable exemption covers that access. Shops that employ foreign nationals must maintain a Technology Control Plan and document the authorization basis for every access event that involves controlled data.
How does AS9100D certification relate to ITAR compliance for a sheet metal supplier?
AS9100D and ITAR operate as separate requirements with different governing bodies, but they reinforce each other in practice. AS9100D requires documented quality management processes, traceability across materials and processes, internal audits and corrective action systems. Those elements support the recordkeeping and process discipline that ITAR audits examine. A supplier that holds active AS9100D certification has already built the documentation infrastructure that ITAR compliance depends on. Precision Advanced Manufacturing operates under AS9100D and ISO 9001:2015 registrations alongside active ITAR registration to provide buyers with a single supplier that satisfies quality and export-control requirements together.
What is the difference between ITAR compliance and CMMC Level 2 for a defense sheet metal supplier?
ITAR governs who may access defense-related technical data and where that data may reside, enforced by the State Department’s DDTC. CMMC Level 2 governs how Controlled Unclassified Information is technically protected through 110 cybersecurity practices derived from NIST SP 800-171, enforced by the Department of Defense through contract requirements. A supplier can hold active ITAR registration and still fail a CMMC Level 2 assessment because ITAR does not require immutable audit logs, FIPS 140-2 validated encryption for data at rest, a System Security Plan or multi-factor authentication for CUI system access. Both frameworks apply at the same time when a supplier handles ITAR-controlled technical data under a Department of Defense contract. CMMC Phase II requirements, originally scheduled to begin November 10, 2026 and make C3PAO certification mandatory for applicable Level 2 contracts, were suspended by the Department of War on July 13, 2026.
What records must a sheet metal fabricator retain to pass an ITAR audit?
The minimum retention period for ITAR records is five years from the date of the transaction, with defense contracts governed by FAR and DFARS potentially extending that period to ten years for specific record types. Required records include export license applications and approvals, shipping documents, records of all technical data disclosures to foreign persons, foreign national visitor logs with nationality and escort details, employee ITAR training records with completion certificates, Technology Control Plans, inventory records for ITAR-controlled articles with serial numbers and custody transfers, restricted-party screening results and all DDTC correspondence. Records must be retrievable, auditable and protected against unauthorized modification. Many compliance programs retain records for seven to ten years to provide a buffer against late-emerging enforcement actions.