What Are ITAR Countries?
If you are a defense contractor, manufacturer, exporter, or supplier supporting the Defense Industrial Base, you have likely heard the phrase “ITAR countries.”
Despite its popularity, the term can be misleading.
ITAR does not publish an official list of approved countries. Instead, the International Traffic in Arms Regulations establish U.S. export control policies for certain countries through Section 126.1 — 22 CFR § 126.1.
Depending on the destination country and the specific transaction, exports of defense articles, defense services, and technical data may be prohibited, subject to a policy of denial, reviewed on a case-by-case basis, or subject to other licensing policies established by the U.S. Department of State.
Understanding these restrictions is critical for organizations that manufacture, export, or support defense-related products.
What Is ITAR?
The International Traffic in Arms Regulations are U.S. export control regulations administered by the Directorate of Defense Trade Controls (DDTC) within the U.S. Department of State.
ITAR regulates defense articles, defense services, technical data, and certain defense-related software. These items are identified on the United States Munitions List (USML) — 22 CFR Part 121 and are controlled to protect U.S. national security and foreign policy interests.
Unlike many people assume, ITAR is not limited to shipping military equipment overseas. It also governs how controlled technical data is accessed, stored, shared, and transferred. The full text of ITAR is available at 22 CFR Parts 120-130.
Does ITAR Have an Approved Country List?
No.
One of the biggest misconceptions about ITAR is that it includes a list of countries where exports are automatically allowed. It does not.
Every export involving ITAR-controlled items is evaluated based on the destination country, the defense article or technical data involved, the foreign recipient, the intended end use, and current U.S. foreign policy and national security interests.
Approval for one transaction does not guarantee approval for another, even if the destination country remains the same.
Not sure where your organization stands with CMMC, ITAR, or federal cybersecurity requirements? The fastest way to get clarity is to talk with an expert. Book a call with our team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.
SCHEDULE YOUR FREE CONSULTATION!
What Is ITAR §126.1?
The official source for ITAR country restrictions is 22 CFR § 126.1, administered by DDTC.
Rather than serving as a simple country list, ITAR § 126.1 establishes U.S. policy toward exports involving specified countries and territories. Depending on the destination and transaction, exports may be prohibited, subject to a policy of denial, reviewed under special licensing policies, or evaluated on a case-by-case basis.
Licensing decisions are made by DDTC in accordance with U.S. export control laws and foreign policy objectives established under the Arms Export Control Act (AECA).
Important: ITAR § 126.1 is periodically updated. Organizations should consult the current version of 22 CFR § 126.1 and applicable DDTC guidance before exporting defense articles, defense services, or technical data. Online articles and previously published country lists may become outdated.
Why ITAR Country Restrictions Matter
Country restrictions are one of the most important components of ITAR compliance.
Before exporting any ITAR-controlled item, organizations should determine whether the item is listed on the USML, whether the destination country is subject to special licensing policies under 22 CFR § 126.1, whether export authorization is required from DDTC, whether the recipient is authorized to receive the item, and whether the intended end use complies with U.S. export regulations.
Failure to properly evaluate these factors can result in civil penalties under 22 CFR Part 127, criminal penalties under the Arms Export Control Act, loss of export privileges, suspension or debarment from government contracts, reputational damage, and shipment delays.
Strong export compliance procedures help reduce these risks while protecting sensitive defense technologies.
ITAR Applies to More Than Physical Exports
Many organizations assume ITAR only applies when shipping products internationally. ITAR also controls many transfers of technical data and defense services.
An export may occur whenever controlled technical information is disclosed to a foreign person, even if that individual is physically located inside the United States. These are commonly referred to as exports under 22 CFR § 120.50.
Examples include emailing engineering drawings, sharing CAD or manufacturing files, cloud collaboration platforms, remote desktop sessions, screen sharing during virtual meetings, source code repositories, file-sharing platforms, providing technical assistance, and remote access to controlled technical data.
Because many ITAR-controlled exports involve digital information rather than physical shipments, cybersecurity plays a critical role in export compliance. Defense contractors handling ITAR-controlled technical data on contractor-owned systems are also subject to cybersecurity requirements under DFARS 252.204-7012 and the 110 security requirements in NIST SP 800-171.
ITAR Country Restrictions briefly
| Question | Answer |
| Does ITAR publish an approved country list? | No |
| Where are country restrictions defined? | ITAR § 126.1 — 22 CFR § 126.1 |
| Do countries’ restrictions change? | Yes consult current 22 CFR § 126.1 before each transaction |
| Can technical data transfers be exports? | Yes see deemed export rule at 22 CFR § 120.50 |
| Are licenses always required? | It depends on the transaction and applicable regulations |
| Should organizations verify current regulations before exporting? | Yes consult DDTC and current 22 CFR § 126.1 |
The Role of Cybersecurity in ITAR Compliance
Because a significant portion of ITAR-controlled exports involve digital technical data rather than physical shipments, organizations that handle ITAR-controlled information on contractor-owned systems face overlapping compliance obligations.
DFARS 252.204-7012 requires contractors to implement adequate security using the 110 security requirements in NIST SP 800-171 for any systems that process, store, or transmit covered defense information. For organizations also subject to CMMC Level 2 under 32 CFR Part 170, third-party certification of those controls is required for most contracts involving Controlled Unclassified Information.
Export-controlled technical data that flows through contractor systems is frequently both ITAR-regulated and subject to CMMC cybersecurity requirements. Organizations that treat ITAR compliance and CMMC compliance as separate programs often discover gaps at the intersection of the two, particularly around access control, system boundary definition, and data flow documentation.
Common ITAR Country Restriction Mistakes
Many organizations unintentionally increase their compliance risk by assuming ITAR publishes an approved country list, that only physical shipments are considered exports, that emailing technical drawings is not an export, that using a U.S.-based cloud provider automatically satisfies ITAR requirements, that foreign nationals working inside the United States are automatically exempt from ITAR, or that country restrictions never change.
Each of these assumptions is incorrect under 22 CFR Parts 120-130. Avoiding these common misconceptions is an important step toward building a stronger export compliance program. DDTC’s compliance guidance provides official resources to help organizations understand their obligations.
Does ITAR have an approved country list? No. ITAR does not publish an approved country list. Export decisions depend on the destination, recipient, defense article, end use, and current U.S. government policy as established in 22 CFR § 126.1.
Where can I find the ITAR country list? Country restrictions are defined in 22 CFR § 126.1, maintained by the U.S. Department of State’s Directorate of Defense Trade Controls (DDTC). The full ITAR text is available at 22 CFR Parts 120-130.
Does ITAR apply inside the United States? Yes. Sharing controlled technical data with certain foreign persons inside the United States may constitute a deemed export under 22 CFR § 120.50. The definition of a foreign person under ITAR is at 22 CFR § 120.63.
Does ITAR prohibit all exports to China? ITAR § 126.1 establishes U.S. policy toward exports involving China. Depending on the defense article, technical data, licensing requirements, and current regulations, many transactions are prohibited or subject to a policy of denial. Organizations should consult the current 22 CFR § 126.1 and DDTC guidance before proceeding with any transaction.
Is Canada exempt from ITAR? Canada benefits from certain ITAR exemptions and regulatory provisions under 22 CFR § 126.5, but it is not exempt from ITAR. Each export should be evaluated under the applicable regulations.
What is an ITAR registration? Most organizations that manufacture, export, or temporarily import defense articles, or furnish defense services, are required to register with DDTC under 22 CFR Part 122. Registration does not authorize any export it is a prerequisite for applying for licenses and other authorizations.
What is voluntary disclosure under ITAR? If an organization discovers a potential ITAR violation, 22 CFR § 127.12 provides a voluntary disclosure process. Voluntary disclosure may be considered a mitigating factor in determining administrative penalties. Organizations that discover potential violations should consult qualified legal counsel promptly.
Additional Government Resources
For authoritative guidance on ITAR country restrictions and export compliance, consult the following official government sources.
- ITAR Full Text — 22 CFR Parts 120-130
- ITAR § 126.1 — Country Policies and Embargoes
- ITAR § 120.50 — Definition of Export and Deemed Export
- ITAR § 120.63 — Definition of Foreign Person
- ITAR § 126.5 — Canada Exemptions
- United States Munitions List — 22 CFR Part 121
- ITAR Registration Requirements — 22 CFR Part 122
- ITAR Violations and Penalties — 22 CFR Part 127
- ITAR Voluntary Disclosure — 22 CFR § 127.12
- Arms Export Control Act (AECA)
- U.S. Department of State — DDTC
- DDTC — ITAR Registration
- DDTC — Commodity Jurisdiction Procedure
- DDTC — Compliance Program Guidance
- Export Administration Regulations (EAR) — 15 CFR Parts 730-774
- Commerce Control List — 15 CFR Part 774
- Bureau of Industry and Security (BIS)
- Consolidated Screening List
- Specially Designated Nationals (SDN) List — OFAC
- DFARS 252.204-7012 — Safeguarding Covered Defense Information
- NIST SP 800-171 Revision 2
- DoD CIO — CMMC Program
- 32 CFR Part 170 — CMMC Program Rule
- National Archives — About CUI
The Bottom Line
Export compliance is not about slowing down business. It is about ensuring controlled products, technical data, and defense-related technologies are exported legally, securely, and efficiently in accordance with 22 CFR Parts 120-130.
ITAR § 126.1 does not provide a simple approved country list. It establishes U.S. policy toward exports to specified countries and territories, with restrictions that range from full prohibition to case-by-case review depending on the transaction. That policy changes over time. Every export must be evaluated against the current regulation before it proceeds.
Organizations that handle ITAR-controlled technical data on contractor-owned systems face a combined compliance obligation: ITAR export controls on the information itself, and CMMC and DFARS cybersecurity requirements on the systems that store and process it. Building a compliance program that addresses both together is the most efficient and defensible approach.
If your organization needs assistance navigating ITAR country restrictions, export authorization requirements, or the intersection of ITAR and CMMC cybersecurity obligations, Brea Networks provides practical guidance to help defense contractors build compliant, sustainable programs that protect both their export privileges and their government contracts.
If your organization is unsure whether your technologies will fall under ITAR or EAR, it is important to identify risks early.
Download the ITAR Compliance Checklist to better understand how to protect controlled data and reduce export control exposure.
About Brea Networks
Brea Networks is a cybersecurity and compliance-focused IT partner dedicated to supporting Defense Industrial Base (DIB) contractors. We help organizations understand and implement the security requirements outlined in FAR 52.204-21, DFARS 252.204-7012, and the CMMC framework from Level 1 self-assessments to Level 2 and Level 3 readiness. Our team works alongside contractors to strengthen system security, define assessment scope, prepare documentation such as System Security Plans (SSPs) and POA&Ms, and build sustainable cybersecurity programs that protect FCI and CUI. Whether you are preparing for a self-assessment, a C3PAO certification, or simply improving your security posture, Brea Networks provides practical guidance and technical expertise to help you move forward with confidence.
Brea Networks, LLC
471 W Lambert Rd Ste 105
Brea, CA 92821
https://www.cmmccompliance.us
https://www.breanetworks.com
Telephone: 714-592-0063