International Business · September 24, 2026

Export Controls for Small Companies: EAR and ITAR Basics

A small company can face export restrictions without shipping weapons or operating overseas. Sending technical files, providing remote access to software, or sharing controlled information with certain people in the United States can raise export questions. California businesses need to understand which federal rules apply before accepting international orders or granting access to sensitive technology. This guide explains the export controls small business owners should understand, including EAR and ITAR jurisdiction, licensing, screening, and practical compliance steps.

Start with EAR and ITAR jurisdiction

Two major federal systems govern many U.S. exports. The Export Administration Regulations, or EAR, are administered by the Commerce Department’s Bureau of Industry and Security, known as BIS. The International Traffic in Arms Regulations, or ITAR, are regulations of the U.S. Department of State, administered primarily by its Directorate of Defense Trade Controls, known as DDTC.

  • EAR: These rules cover many commercial and dual-use commodities, software, and technologies. They appear in 15 C.F.R. Parts 730–774.
  • ITAR: These rules regulate defense articles—including ITAR-controlled technical data—and defense services. They are codified at 22 C.F.R. Parts 120–130; the U.S. Munitions List appears in 22 C.F.R. § 121.1. Their statutory authority includes the Arms Export Control Act, 22 U.S.C. § 2778.

“Dual-use” generally describes items with both civilian and military applications. Sensors, manufacturing equipment, software, and aerospace components can raise classification questions, but a military customer alone does not automatically make an item ITAR-controlled.

These are federal requirements. A California location, small workforce, or modest sales volume does not create a general exemption. Businesses and individuals can have obligations. An international business attorney can help identify the legal questions surrounding products, counterparties, and cross-border agreements.

Classify the item before deciding whether a license is needed

First determine which agency has jurisdiction. For items subject to the EAR, review whether the item falls under an Export Control Classification Number, or ECCN, on the Commerce Control List. Items subject to the EAR that are not listed generally receive the designation EAR99.

EAR99 does not mean unrestricted. An otherwise ordinary product may require authorization because of its destination, recipient, or intended use. Similarly, having an ECCN does not mean every shipment requires a license.

A transaction review should ask:

  • What commodity, software, or technology is being exported?
  • What is its classification, and what supports that conclusion?
  • Where will it go, including any later transfer or reexport?
  • Who will receive it, and who is the actual end user?
  • What will the recipient use it for?
  • Does an authorization requirement apply, and are any exception or exemption conditions satisfied?

If it is unclear whether an item is subject to the ITAR, a formal commodity-jurisdiction request to DDTC may be appropriate. For items subject to the EAR, BIS classification procedures can establish the applicable ECCN or EAR99 designation; they do not determine ITAR jurisdiction. Identifying the responsible agency and classifying an item are not the same as obtaining permission for a transaction.

Exports can happen through email, cloud access, and services

Export review should extend beyond the shipping department. Sending controlled technical information abroad, enabling access from another country, or transferring controlled software can trigger requirements. Remote support and engineering collaboration may also involve regulated technical data or defense services.

Under the EAR, releasing controlled technology or source code to a foreign person in the United States can constitute a “deemed export.” The rules contain important definitions and exclusions, including for certain lawful permanent residents and protected individuals. Do not assume that citizenship alone resolves every access question.

ITAR has its own definitions and rules for technical data, foreign persons, exports, and defense services. An ITAR analysis should not simply reuse an EAR conclusion.

For example, a California engineering company inviting an overseas consultant into a design repository should review the files, access permissions, consultant’s status, and applicable authorization requirements first. Cloud storage is not automatically prohibited or exempt. Under the EAR, review both overseas transmission or storage and any release of controlled technology or source code to provider personnel or other foreign persons. Certain encrypted transmissions and storage are not exports when all conditions in 15 C.F.R. § 734.18 are met; encryption or lack of provider access alone does not establish that exclusion. ITAR-controlled data requires a separate analysis under ITAR rules. Employment and access policies also need review for applicable anti-discrimination requirements.

Build a proportionate export compliance process

A small company does not need to copy a multinational’s entire compliance department. It does need a repeatable process that catches risks before a shipment, disclosure, or service begins.

  1. Assign responsibility. Identify who approves export-related transactions and who can pause them.
  2. Document classifications. Keep product specifications, classification reasoning, and relevant agency determinations together.
  3. Screen transaction parties. Check applicable restricted-party lists and sanctions restrictions, including those administered by the Treasury Department’s Office of Foreign Assets Control.
  4. Review end uses and destinations. Investigate unclear answers, unusual routing, or requests to conceal the recipient.
  5. Control information access. Set permissions for technical files, collaboration tools, and outside consultants.
  6. Preserve records and train staff. Follow applicable retention requirements and teach employees when to escalate questions.

Screening alone is not a complete review. A customer absent from a restricted-party list may still propose a prohibited end use. Contract provisions addressing destinations, end uses, and unauthorized transfers can support compliance, but they do not replace legal authorization.

Under 22 C.F.R. § 122.1, a person engaged in the United States in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, generally must register with DDTC unless a specific regulatory exemption applies. Engaging in that business can require only one occasion, and a manufacturer may have to register even if it does not export. Registration itself does not authorize exports or defense services.

Pause questionable transactions and assess next steps

If an employee discovers a possible unauthorized shipment or disclosure, stop related activity and preserve relevant records. Do not delete messages, revise historical documents, or assume a later license will resolve an earlier violation.

Counsel can assess the facts, applicable reporting requirements, and whether a voluntary self-disclosure is appropriate. Disclosure procedures differ among agencies and do not eliminate potential liability. Classification, sanctions, and licensing rules can change, so periodically revisit prior decisions rather than treating an old approval as permanent clearance.

Talk to a California business attorney

Itkin Law offers a free consultation to discuss export-control questions affecting your company, technical information, or proposed international transaction. Schedule a free consultation or call (424) 603-8888.

This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. The law changes, and this article reflects the law as of its publication date. Every situation is different — contact us to discuss how the law applies to your exact circumstances. See our full disclaimer.

Free Consultation

Ready to move? Start with a free consultation.

Tell us what you're facing — a contract, a dispute, a debt, a decision. We will map the legal path in plain language, and you will leave the first call knowing your options.

Call Now Free Consultation