Readiness check
Compliance / ITAR & EAR

Export control changes who can touch the data — not just how it's stored.

CMMC asks whether the boundary is secure. ITAR and EAR ask a different question: who is allowed to see what's inside it. If you hold export-controlled technical data, US-person access becomes a design constraint, not a checkbox.

Two regimes, one question: who can access it
ITAR
Defense articles & technical data

Governs items on the U.S. Munitions List. Access is restricted to U.S. persons; exports (including a foreign national viewing the data) require State Department licensing.

RegulatorDDTC (State)
ListUSML
Citation22 CFR 120–130
EAR
Dual-use items & technology

Governs commercial items with potential military application. Controls depend on the item's classification (ECCN) and destination — often lighter than ITAR, but still enforceable.

RegulatorBIS (Commerce)
ListCCL / ECCN
Citation15 CFR 730–774
What it means for your boundary

Three constraints export control adds.

01
US-person access

Support staff, admins, and infrastructure operators who can reach the data must be U.S. persons — including your cloud's operators.

02
Data residency

Technical data stays in the United States, at rest and in transit — which is why GovCloud regions and controlled environments exist.

03
Encryption caveat

FIPS-validated end-to-end encryption can narrow — not erase — export exposure. It's a tool in the design, not a loophole.

Where this connects to GCC High

ITAR is the one case that most often points to GCC High.

If export-controlled collaboration is where your data actually lives, a Microsoft government tenant is a strong fit — and we'll say so. But US-person controls and data residency are equally achievable in AWS GovCloud, Azure Government, and Google Assured Workloads. The right answer depends on where the controlled data flows, not on which vendor markets hardest. We're not export-control counsel; we design the boundary and coordinate with yours.

Holding ITAR or EAR data?

A readiness check maps where your controlled data flows and what the boundary needs to enforce.