Key takeaways for sourcing ITAR-compliant manufacturers
- ITAR registration is an administrative filing, not a certification of operational controls. Buyers verify active DDTC registration, a designated Empowered Official and documented procedures.
- Program scope must be defined before RFQ release, including USML jurisdiction determinations and whether DFARS 252.204-7012 or CUI requirements apply.
- ITAR registration alone does not confirm manufacturing capability. Suppliers demonstrate in-house fabrication, finishing, assembly and AS9100D certification.
- ITAR and CMMC 2.0 overlap on CUI data. Suppliers must meet nationality-based access controls and NIST SP 800-171 cybersecurity practices.
- Request a quote from Fabcon, an ITAR-registered, AS9100D-certified partner providing precision sheet metal and assembly for defense programs.
Core elements of ITAR-compliant contract manufacturing
An ITAR-compliant contract manufacturer holds active DDTC registration under 22 CFR Part 122 and restricts controlled technical data to U.S. persons. The manufacturer maintains documented access controls and employee training and operates physical and cybersecurity safeguards that prevent unauthorized disclosure of U.S. Munitions List items.
Checklist to verify ITAR compliance at a supplier
ITAR registration is an administrative filing, not a certification of operational controls. Buyers verify compliance through direct documentation requests. The following checklist covers the core verification actions.
- Confirm active DDTC registration. Request the supplier’s current DDTC registration acknowledgment letter and M-prefix registration code. Registration must be renewed annually under ITAR Part 122, with renewal submitted before expiration.
- Verify an Empowered Official is designated. An ITAR-credible manufacturer designates a named Empowered Official who holds legal authority to bind the company on export-control matters and signs all license applications.
- Review the compliance manual. The manual should be revised within the last 12 to 18 months and cover technical-data access controls, foreign-person screening, physical security and recordkeeping procedures.
- Confirm foreign-person access controls. Under 22 CFR § 120.62, transfer of controlled technical data to a foreign person inside the United States constitutes a deemed export. Suppliers document citizenship verification and either hold DDTC authorization or implement controls that prevent any foreign-person access.
- Request annual training records. ITAR-compliant operations require recurring employee training with documented completion records. Confirm training covers export classifications, data-handling procedures and violation reporting.
- Examine recordkeeping practices. Suppliers retain export licenses, technical data transfer logs, visitor records and related documentation for the required period under 22 CFR § 122.5.
- Assess Technology Control Plan documentation. DDTC encourages manufacturers employing or working with foreign persons to maintain a Technology Control Plan outlining physical and digital security measures and visitor screening protocols.
Define program requirements and compliance scope before RFQs
Sourcing teams define the compliance scope of the program before issuing an RFQ. Teams identify whether the end item or its technical data appears on the U.S. Munitions List, determine whether DFARS 252.204-7012 applies to the contract and establish whether Controlled Unclassified Information will be processed by the supplier.
A written jurisdiction determination from the OEM customer for each program is required because the contract manufacturer cannot unilaterally classify whether a product falls under the USML. This determination must be documented in the supplier’s quality management system before production begins so all parties operate from the same compliance baseline.
Program scope also shapes which supplier model is appropriate. Mid-volume, high-mix programs with evolving bills of materials require a partner with agile production infrastructure, not a rigid large-CM structure built for fixed, high-volume runs. Once program scope is defined, sourcing teams can evaluate whether potential suppliers possess the manufacturing capabilities to execute the work.
Evaluate manufacturing capabilities for precision sheet metal and assembly
ITAR registration alone does not confirm that a supplier can execute the work. Buyers evaluate integrated manufacturing capabilities against program requirements. Key capability areas to assess include:
- In-house laser cutting, CNC forming, certified welding and hardware insertion across required materials and thicknesses
- CNC machining for tight-tolerance components that support fabricated assemblies
- In-house finishing including powder coat, wet paint, CARC military-grade finishing and mil-spec coatings
- Light electromechanical assembly including wiring and component integration under the same roof as fabrication
- First Article Inspection capability, CMM inspection and full material traceability documentation
- AS9100D certification with a scope that explicitly covers the work being placed
- Design-for-manufacturability collaboration available before production begins
Single-source accountability across fabrication, finishing and assembly reduces vendor handoffs, compresses lead times and simplifies quality ownership. Suppliers that subcontract finishing or assembly introduce traceability gaps that create audit risk on defense programs.
Fabcon operates integrated manufacturing space across two U.S. facilities and holds ISO 9001:2015, AS9100D and ITAR registration. Fabrication, machining, finishing and light electromechanical assembly are managed under one roof. Connect with an ITAR-registered, AS9100D-certified partner for integrated fabrication and assembly support.
Align cybersecurity, CMMC 2.0 and ITAR obligations
ITAR and CMMC 2.0 address overlapping but distinct obligations. ITAR governs access by nationality and jurisdiction. CMMC governs cybersecurity practices regardless of nationality. A supplier can hold active DDTC registration and still fail a CMMC Level 2 assessment.
ITAR-controlled technical data is also commonly CUI, because export-controlled information is explicitly listed as a category in the CUI Registry. The same document can trigger both export-control obligations under ITAR and CMMC cybersecurity requirements under 32 CFR Part 170.
CMMC Level 2 maps directly to the 110 controls in NIST SP 800-171, which DFARS 252.204-7012 has required since 2015. The CMMC final DFARS rule became effective Nov. 10, 2025, making third-party assessments by C3PAOs a requirement for Level 2 contracts handling CUI. On July 13, 2026, the Department of War suspended the Phase II C3PAO assessment requirement pending a 60-day review, but the underlying NIST SP 800-171 Rev 2 cybersecurity obligations and DFARS 252.204-7012 enforcement remain fully in force.
Additional cybersecurity requirements buyers verify in supplier assessments include:
- Encrypted storage and multi-factor authentication for ITAR-controlled systems
- Network segmentation isolating ITAR and CUI data from general enterprise systems
- Cloud services meeting FedRAMP Moderate equivalence or higher for any CUI processing
- ERP and PLM systems hosted in U.S.-based data centers with no foreign access pathways
- A documented System Security Plan and current SPRS score submission
- Cyber incident reporting procedures meeting the 72-hour DoD reporting requirement
Server-side encryption where the cloud provider holds the keys does not satisfy the ITAR encryption carve-out under 22 CFR § 120.54(a)(5). Only client-side end-to-end encryption with customer-held keys meets the requirement for unclassified technical data.
ITAR violations can result in significant civil and criminal penalties, with criminal penalties up to $1,000,000 per violation and up to 20 years imprisonment. The DDTC maintains an aggressive enforcement posture, with voluntary disclosures and substantial penalty amounts in consent agreements.
Fabcon’s compliance infrastructure supports defense and aerospace programs that require documented data controls and full traceability. Discuss program compliance requirements with Fabcon’s team.
Compare job shops, mid-tier suppliers and large contract manufacturers
Three supplier models serve the ITAR-compliant precision sheet metal market, and each model presents distinct trade-offs for mid-volume defense and aerospace programs.
Low-complexity job shops handle build-to-print sheet metal but lack engineering depth for DFM and cannot manage light electromechanical assembly. These shops typically do not hold AS9100D certification. Programs sourced through job shops require buyers to manage multiple vendors for fabrication, finishing and assembly, which creates vendor handoff delays and fragmented quality accountability.
Large contract manufacturers offer scale and infrastructure but impose high minimum volumes, long onboarding timelines and limited flexibility for high-mix or evolving BOM programs. Their production lines are optimized for fixed, high-volume runs. Mid-volume programs with changing configurations often face rigid constraints that slow program execution.
Mid-tier integrated manufacturers occupy the critical middle ground. These suppliers combine the scale advantages of large CMs with the flexibility to support mid-volume, high-mix programs without high minimums or extended onboarding. For ITAR programs, single-source accountability across the full build reduces traceability risk and simplifies compliance documentation.
The most acute supply chain constraints in U.S. defense manufacturing sit in the sub-tier supply chain, where multi-tier visibility is limited and qualification timelines are long. Consolidating fabrication, finishing and assembly under one ITAR-registered, AS9100D-certified roof directly addresses this risk.
Build a defensible RFQ for ITAR-compliant partners
A structured RFQ process reduces compliance risk before contract award. The following questions establish a defensible supplier evaluation record:
- Provide the current DDTC registration acknowledgment letter and M-prefix registration code.
- Identify the designated Empowered Official and describe that person’s authority scope.
- State when the ITAR compliance manual was last revised and whether it can be reviewed under NDA.
- Describe the foreign-person screening and citizenship verification process for personnel with access to ITAR-controlled programs.
- Describe the physical and electronic controls that prevent foreign-person access to controlled technical data.
- Provide the current SPRS score and describe NIST SP 800-171 implementation status.
- Confirm whether cloud systems are used to store or process CUI and, if so, confirm FedRAMP Moderate equivalence or higher.
- Describe FAI, CMM inspection and material traceability documentation processes for defense programs.
- List finishing and light electromechanical assembly capabilities performed in-house versus subcontracted.
- Explain how subcontractors are screened for ITAR compliance and DFARS 252.204-7012 obligations.
Many U.S. defense and aerospace companies are preparing for supply chain localization or reshoring to build resilience. Selecting an integrated, ITAR-registered domestic partner directly supports that resilience objective.
Fabcon supports defense and aerospace programs from prototype through mid-volume production with full traceability, AS9100D quality management and integrated fabrication, finishing and assembly. Submit program specifications to Fabcon’s engineering and sourcing team.
Frequently asked questions about ITAR-compliant suppliers
What is the difference between ITAR registration and ITAR compliance?
ITAR registration is an annual administrative filing with the DDTC under 22 CFR Part 122. Registration establishes that a company is authorized to engage in manufacturing, exporting or temporarily importing defense articles on the U.S. Munitions List. ITAR compliance is the operational state of maintaining all required controls, including foreign-person access restrictions, technical data handling procedures, employee training, recordkeeping and cybersecurity safeguards. A company can hold active registration while failing to maintain the operational controls that constitute genuine compliance. Buyers verify both the registration status and the underlying compliance program through documentation requests.
How do ITAR requirements interact with CMMC 2.0 for contract manufacturers?
ITAR and CMMC 2.0 operate in parallel and address different obligations. ITAR governs who can access controlled technical data based on nationality and jurisdiction. CMMC 2.0 governs cybersecurity practices for systems that process, store or transmit Controlled Unclassified Information, regardless of the nationality of users. ITAR-controlled technical data is commonly also CUI, so the same document can trigger both frameworks simultaneously. A contract manufacturer must satisfy ITAR access controls and implement the 110 cybersecurity practices in NIST SP 800-171 to meet CMMC Level 2 requirements. Failing one does not excuse the other. Defense buyers assess both frameworks independently when evaluating suppliers.
What certifications should an ITAR-compliant precision sheet metal supplier hold for aerospace and defense programs?
The baseline certifications for aerospace and defense precision sheet metal programs are active DDTC registration, AS9100D certification with a scope covering the specific work being placed and ISO 9001:2015 quality management system certification. Suppliers performing welded assemblies for aerospace applications should hold relevant AWS welding certifications. Suppliers performing mil-spec finishing should document the specific finishing standards their processes meet. For programs involving CUI, suppliers also demonstrate NIST SP 800-171 implementation and a current SPRS score. Buyers confirm that certification scopes explicitly cover the program type, materials and processes involved rather than accepting general certification claims.
Why does vertical integration matter for ITAR-compliant defense programs?
Vertical integration reduces the number of parties that handle ITAR-controlled technical data and physical components. Each handoff between vendors introduces a new access-control boundary that must be managed, documented and audited. When fabrication, finishing and light electromechanical assembly are performed under one roof by a single ITAR-registered entity, the compliance boundary is simpler to define and maintain. Traceability documentation covers the full build within one quality management system. Subcontracted operations require buyers to verify ITAR compliance and DFARS flow-down obligations for each additional party, which increases audit complexity and program risk.
What should sourcing teams do if a supplier claims ITAR compliance but cannot provide documentation?
Sourcing teams treat an inability to provide documentation as a disqualifying condition for ITAR-sensitive programs. Genuine ITAR compliance requires a current DDTC registration acknowledgment letter, a designated Empowered Official, a revised compliance manual, employee training records and five-year recordkeeping under 22 CFR § 122.5. A supplier that cannot produce these documents on request has not demonstrated the operational controls that ITAR requires. Civil and criminal penalties for ITAR violations extend to corporate officers and can reach significant amounts per violation. Sourcing teams that place programs with non-compliant suppliers share exposure to those consequences. Documentation requests form a standard and necessary part of supplier qualification for defense and aerospace programs.
Conclusion: select an ITAR-compliant partner with proven controls
Selecting an ITAR-compliant contract manufacturer requires verified DDTC registration, documented operational controls and manufacturing capabilities that match program requirements. Registration alone does not equal compliance. Buyers who apply a structured verification process, assess cybersecurity overlap with CMMC and NIST SP 800-171 and compare supplier models against mid-volume program needs reduce both compliance risk and supply chain complexity.
Fabcon serves defense and aerospace programs across U.S. manufacturing facilities. AS9100D certification, ISO 9001:2015 quality management and ITAR registration support full traceability from prototype through production. Start a supplier evaluation with Fabcon’s team.