Is ITAR Data Covered Defense Information?

Written by Teramis | Sep 8, 2026, 3:39:08 PM

How the rules stack and when export-controlled technical data becomes Covered Defense Information

Defense contractors often treat Controlled Unclassified Information (CUI), DFARS cybersecurity clauses, CMMC, and ITAR as interchangeable labels for “sensitive defense data.” They are not. They answer different questions, they are enforced by different agencies, and they only overlap when a specific legal test is met.

CMMC and NIST SP 800-171 ask how information is protected on contractor systems. ITAR and
the Export Administration Regulations (EAR) ask who may see it, where it may go, and whether a license is required. Covered Defense Information (CDI) is the contract-scope term that decides whether DFARS 252.204-7012 applies at all.

Getting those distinctions wrong produces two expensive mistakes: over-scoping systems that do not hold CDI, or putting ITAR technical data in an environment that satisfies CMMC but still creates an export violation.

The cybersecurity stack: CUI, DFARS 7012, NIST 800-171, and CMMC

CUI is a government-wide information category created by Executive Order 13556 and implemented in 32 CFR Part 2002. It is unclassified information the government creates or possesses or that a nonfederal organization creates or possesses for or on behalf of the government, that requires safeguarding or dissemination controls under law, regulation, or government-wide policy.

The CUI Registry, maintained by the National Archives, is the authoritative list of approved categories. DoD implements the program for the Department in DoDI 5200.48.

For defense contractors, three instruments turn that category into a contract obligation:

  1. DFARS 252.204-7012, the safeguarding and cyber incident reporting clause. If a covered contractor information system processes, stores, or transmits Covered Defense Information, the contractor must provide “adequate security,” implement NIST SP 800-171, and report cyber incidents to DoD within 72 hours.
  2. NIST SP 800-171, the security requirements for protecting CUI in nonfederal systems. DoD contracts under 7012 still treat Revision 2 as the operative baseline; NIST has also published Revision 3.
  3. DFARS 252.204-7021 and the CMMC Program rule at 32 CFR Part 170, the verification layer. Contractors must have and maintain the CMMC status required by the contract for systems that process, store, or transmit Federal Contract Information or CUI. CMMC Level 2 maps to the 800-171 baseline.

Those rules govern confidentiality on contractor networks. They do not register a company with the Directorate of Defense Trade Controls, issue an export license, or decide whether a foreign-person engineer may open a drawing.

The export-control stack: ITAR and EAR

The International Traffic in Arms Regulations (22 CFR Parts 120–130), administered by the Department of State’s Directorate of Defense Trade Controls, control defense articles, defense services, and technical data on the U.S. Munitions List.

ITAR technical data includes information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles — blueprints, drawings, plans, documentation, and certain software directly related to defense articles. It does not include information in the public domain or general scientific principles commonly taught in universities.

An export is not only a shipment out of the United States. Releasing technical data to a foreign person in the United States is a deemed export. That is why nationality of employees, cloud administrators, and managed-service staff is an ITAR issue even when the servers never leave Virginia.

The Export Administration Regulations, administered by the Bureau of Industry and Security, cover dual-use items and technology on the Commerce Control List. The same stacking problem applies: EAR-controlled technology can also be CUI, and can also be CDI, without EAR becoming a cybersecurity framework.

ITAR has its own encryption rule. Under 22 CFR 120.54, sending or storing unclassified technical data with specified end-to-end encryption and FIPS-compliant modules is not itself an export with important limits, including transfers involving prohibited destinations and nationals. Encryption that satisfies NIST 800-171 does not, by itself, satisfy ITAR.

Where the stacks meet: export-controlled CUI

Export-controlled information is a category in the CUI Registry. NARA describes it as unclassified information concerning items, commodities, technology, software, or other information whose export could reasonably be expected to affect U.S. national security and nonproliferation objectives, including items identified in the EAR, ITAR, and the Munitions List.

Specified authorities in that category are marked CUI//SP-EXPT. The official entry is here: CUI Category: Export Controlled.

32 CFR 2002.4 distinguishes CUI Basic from CUI Specified. Basic uses the uniform CUI handling rules. Specified means a particular law or regulation already writes extra controls. Export control is the textbook Specified category: ITAR and EAR nationality, licensing, and release rules sit on top of the CUI baseline. They do not disappear because a contractor implemented 800-171 or received a CMMC Level 2 status.

DoDI 5200.48 is explicit that export-controlled information must also carry the export-control warning required by DoDI 5230.24, Distribution Statements on Technical Documents, and related issuances. A CUI banner without the export-control warning is incomplete marking for that data.

A single engineering file on a DoD program can therefore be all of the following at once:

  • ITAR technical data or EAR-controlled technology
  • CUI Specified (Export Controlled), marked CUI//SP-EXPT
  • Controlled technical information under DoDI 5230.24
  • Covered Defense Information under DFARS 252.204-7012
  • In scope for CMMC Level 2 if it resides on a contractor system used in contract performance

Not all CUI is export-controlled. Not all ITAR data is CUI. The “both” pile is what forces U.S.-person access controls on top of the CMMC boundary.

Is ITAR Data Covered Defense Information?

Sometimes. Not automatically.

CDI is defined in DFARS 252.204-7012. It means unclassified controlled technical information, or other information described in the CUI Registry that requires safeguarding or dissemination controls, and that information is either:

  1. marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of contract performance; or
  2. collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance.

Controlled technical information, in the same clause, means technical information with military or space application that is subject to controls on access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. If disseminated, it would meet the criteria for Distribution Statements B through F under DoDI 5230.24. The term excludes information that is lawfully publicly available without restrictions.

ITAR technical data on a defense article often satisfies the first half of that definition. Export-controlled information is in the CUI Registry, so it can also enter CDI through the “other information described in the CUI Registry” prong.

The second half is what decides the question.

ITAR data is CDI when DoD furnishes it under a contract that includes 7012, or when the contractor creates, receives, or uses ITAR-controlled technical data in performance of that contract — including flow-down to a subcontractor.

ITAR data is not CDI when it exists only in company-funded IR&D, a purely commercial defense sale, or work for a non-DoD customer with no DoD contract tying the data to 7012. That data remains export-controlled. The 7012 cybersecurity obligation does not attach until the contractual test is met.

DoD’s own training on 7012 also notes that “in support of the performance of the contract” is not meant to sweep in the contractor’s internal information, such as human resources or financial records, that is only incidental to performance.

When ITAR data is and is not CDI

Data ITAR / EAR? CUI? CDI under 7012?
DoD-furnished USML technical data on a 7012 contract Yes Typically yes (EXPT / CTI) Yes
Contractor-created ITAR drawings for that same contract Yes Typically yes Yes
Same technical data held only for commercial or internal IR&D Yes Not automatically No
Non-export CUI on a DoD contract (some privacy or procurement-sensitive data) No Yes Often yes
Information lawfully in the public domain No (ITAR excludes public-domain technical data) No No

CMMC does not change this test. 32 CFR Part 170 assesses whether contractor systems that handle FCI or CUI meet the prescribed cybersecurity standard. It does not certify DDTC registration, licensing, deemed-export controls, or technology control plans. A contractor can pass a CMMC assessment and still violate ITAR. A contractor can run a mature ITAR program and still fail 7012 or CMMC.

What each regime actually requires

Question CUI / DFARS 7012 / CMMC ITAR / EAR
What is being protected? Confidentiality of CUI and CDI on contractor systems Export, reexport, and release of USML or CCL technical data
Who may access it? Authorized users with a lawful government purpose U.S. persons unless a license, agreement, or exemption applies
Foreign employees, MSP staff, cloud admins Still subject to access control and audit Often a deemed export
Company registration Not required by CMMC ITAR manufacturers and exporters generally register with DDTC
Marking CUI banner; Specified categories use CUI//SP-EXPT Export-control warning and, for DoD technical documents, Distribution Statements B–F
Cloud External cloud handling CDI must meet FedRAMP Moderate-equivalent security U.S.-person control of the data; commercial support staff can create a release problem
Incident reporting 72-hour report to DoD under 7012 Separate disclosure obligations to DDTC or BIS
Enforcement Contract remedies; False Claims Act exposure Civil and criminal export penalties, debarment

The practical operating model is two programs on one dataset. The cyber program scopes the CUI boundary, implements 800-171, maintains the required CMMC status, flows down 7012 and 7021, and reports incidents. The export program classifies the item (USML versus CCL/ECCN), marks it, restricts access to screened U.S. persons, controls deemed exports, keeps licenses and records, and registers with DDTC when required.

If you only do the first, a foreign-person administrator or a commercial collaboration tenant can still create an ITAR problem. If you only do the second, missing logging, multifactor authentication, a system security plan, or FedRAMP-equivalent cloud can still breach 7012.

Start with classification, not tooling

The first split that matters is operational, not architectural:

  • Which files are CUI only?
  • Which files are export-controlled only?
  • Which files are both?
  • Which of those sit on systems used to perform a DoD contract?

The “both” pile is Covered Defense Information and ITAR technical data at the same time. That is the pile that must live inside a CMMC-aligned boundary and a U.S.-person export-control boundary. Until an organization can point to where those files actually are in email, file shares, engineering vaults, scanned drawings, CAD, and legacy shares scoping is a guess, and guesses fail assessments and disclosures.

While CUI and ITAR have different rules and enforcement agencies, both still have to be safeguarded wherever they live. CMMC and NIST SP 800-171 do not replace ITAR. An ITAR compliance program does not replace DFARS 252.204-7012. When the same file is export-controlled technical data and Covered Defense Information, both stacks apply, and the work starts with knowing which files those are.

How Teramis Helps

Teramis can identify CUI and ITAR in your environment across Microsoft 365, file shares, endpoints, email, PDFs, images, scanned documents, and CAD files, so you can separate CUI-only data from export-controlled technical data, size the CMMC boundary against where Covered Defense Information actually lives, and keep watching for spillage after the files are moved into an approved enclave. Request a Demo to learn more.

Sources