Skip to main content
Federal statuteEAR / ITAR

Export Administration Regulations / Arms Export Control Act

Export-controlled technical data can be a contract, national-security, and cybersecurity issue at the same time.

Last reviewedJune 28, 2026Version v1

Export-controlled technical data can be a contract, national-security, and cybersecurity issue at the same time.

In plain terms. Export-controlled technical data can be a contract, national-security, and cybersecurity issue at the same time. Contractors that receive controlled technical data must protect it and prevent unauthorized exports or deemed exports.

Who it applies to. It applies to contractors, subcontractors, cloud providers, and personnel handling export-controlled technology, technical data, defense articles, or defense services.

What it requires. In practice, contractors should classify data under the Export Administration Regulations (EAR) or International Traffic in Arms Regulations (ITAR); restrict access by nationality and authorization; use approved storage and transfer methods; and coordinate export licensing or exemptions before disclosure.

Why it matters. For GovConCyber, the key is to translate the law into contract-performance terms without overstating the source. The page should tell readers whether the requirement affects eligibility, representations, contract performance, flowdowns, data handling, incident response, or enforcement exposure.

Citation. Export Administration Regulations, 15 C.F.R. parts 730–774; International Traffic in Arms Regulations, 22 C.F.R. parts 120–130; Arms Export Control Act, 22 U.S.C. § 2751 et seq..