Export control changes who can touch the data — not just how it's stored.
CMMC asks whether the boundary is secure. ITAR and EAR ask a different question: who is allowed to see what's inside it. If you hold export-controlled technical data, US-person access becomes a design constraint, not a checkbox.
Governs items on the U.S. Munitions List. Access is restricted to U.S. persons; exports (including a foreign national viewing the data) require State Department licensing.
Governs commercial items with potential military application. Controls depend on the item's classification (ECCN) and destination — often lighter than ITAR, but still enforceable.
Three constraints export control adds.
Support staff, admins, and infrastructure operators who can reach the data must be U.S. persons — including your cloud's operators.
Technical data stays in the United States, at rest and in transit — which is why GovCloud regions and controlled environments exist.
FIPS-validated end-to-end encryption can narrow — not erase — export exposure. It's a tool in the design, not a loophole.
ITAR is the one case that most often points to GCC High.
If export-controlled collaboration is where your data actually lives, a Microsoft government tenant is a strong fit — and we'll say so. But US-person controls and data residency are equally achievable in AWS GovCloud, Azure Government, and Google Assured Workloads. The right answer depends on where the controlled data flows, not on which vendor markets hardest. We're not export-control counsel; we design the boundary and coordinate with yours.
Holding ITAR or EAR data?
A readiness check maps where your controlled data flows and what the boundary needs to enforce.