research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
ITAR vs EAR compliance requirements crosswalk
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/compliance-matrixContext preview
What this command does when you run it.
ITAR vs EAR compliance requirements crosswalk
description: ITAR vs EAR compliance requirements crosswalk
> **Engineering guidance only. Not legal advice.** The matrix below is a simplified planning aid; DDTC and BIS make the actual determinations. The country lists, retention requirements, and residency postures shown here are starting points to discuss with export-control counsel. Sanctions rules in particular shift fast; verify against the [BIS country guidance](https://www.bis.doc.gov/index.php/policy-guidance/country-guidance) before acting on the country-list rows.
Side-by-side comparison of ITAR and EAR requirements to understand overlaps, differences, and compliance strategies.
| Aspect | ITAR | EAR | |--------|------|-----| | **Authority** | State Department (DDTC) | Commerce Department (BIS) | | **Scope** | Defense articles, services, technical data (USML) | Dual-use commercial items (CCL) | | **Item List** | US Munitions List (USML) - 21 categories | Commerce Control List (CCL) - 10 categories | | **Personnel** | US persons per 22 CFR 120.62 (citizens, LPRs, "protected individuals" under 8 USC 1324b(a)(3), US entities) | No personnel restrictions (except deemed exports) | | **Geography** | US-located data by default; 22 CFR 120.54 carves out properly-encrypted technical data | BIS-driven (15 CFR 734.6). Sanctions rules in 15 CFR 746 cover comprehensive embargoes (CU, IR, KP, SY), Russia/Belarus (746.8), Crimea/DNR/LNR (746.6), and shift; check current BIS country guidance | | **Registration** | DDTC registration required ($3,000/year) | No registration (except encryption items) | | **Licensing** | License required for most exports | License required for high-level ECCNs, exceptions available |
| Control Area | ITAR | EAR | Overlap | |--------------|------|-----|---------| | **Access Control** | US persons only verification | Denied party screening (Entity List, DPL, SDN) | ⚠️ Different mechanisms | | **Data Residency** | US-located regions by default (encryption carve-out per 22 CFR 120.54) | Driven by ECCN-specific licensing and current 15 CFR 746 sanctions | ⚠️ Different posture | | **Encryption** | FIPS 140-2 Level 2+ required | FIPS 140-2 for Category 5 Part 2 | ✅ Same standard | | **Audit Logging** | 5-year retention for records within 22 CFR 122.5 scope (not all logs) | Varies by requirement | ⚠️ ITAR has scoped recordkeeping | | **Network Isolation** | Dedicated VPCs for ITAR | No specific requirement | ⚠️ ITAR only | | **Marking** | ITAR classification on all data | ECCN classification on items | ⚠️ Different schemes | | **Third-Party Access** | Restricted CSP access | Normal CSP access | ⚠️ ITAR more restrictive |
**ITAR-1: US Person Verification**
**EAR-2: End-User Screening**
**Overlap**: ❌ No overlap - different mechanisms
**Compliance Strategy**: Implement both
**ITAR-2: Data-Residency Posture**
**EAR-4: Geographic Access Controls**
**Overlap**: ✅ Partial overlap
**Compliance Strategy**:
**ITAR-3: Encryption Requirements**
**EAR-3: Encryption Compliance**
**Overlap**: ✅ Complete overlap
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.