CUI vs. ITAR: How Export Controls and Controlled Unclassified Information Differ

Written by: 
Team Knox
Published on: 
August 3, 2026

A single technical drawing on a defense contract can fall under two federal regimes at once. One regime dictates how the file must be secured. The other dictates who is legally permitted to view it. Contract review often separates Controlled Unclassified Information (CUI) handling requirements from International Traffic in Arms Regulations (ITAR) access restrictions because the two frameworks answer different questions and carry different consequences.

Confusing the two creates unclear architecture, contract language, and access policy. CUI governs protection. ITAR governs access. For SaaS CTOs, compliance leaders, and program managers at prime contractors, the practical stakes come down to one infrastructure decision that both frameworks converge on.

Key Takeaways

  • Protection versus access. CUI defines how sensitive federal data must be secured. ITAR defines who is legally allowed to touch defense-related technical data.  
  • Frameworks can overlap. When ITAR-controlled technical data is provided or generated under a federal contract that identifies it as CUI or includes applicable CUI flowdowns, it is generally handled as Export Control CUI.  
  • Penalty exposure differs. CUI violations typically produce contract consequences and civil penalties. ITAR violations can carry severe criminal liability per violation.  
  • Infrastructure converges. Any cloud system handling export-controlled CUI or dual-framework data needs Federal Risk and Authorization Management Program (FedRAMP)-authorized infrastructure with U.S.-person access controls.

CUI And ITAR Often Govern The Same Data

Controlled Unclassified Information (CUI) is a government-wide program that standardizes how federal agencies and contractors protect sensitive but unclassified data. The International Traffic in Arms Regulations (ITAR) export control rules restrict who can access defense-related technology and technical data.

CUI is administered by the National Archives and Records Administration (NARA) under Executive Order 13556 and codified in 32 CFR Part 2002. ITAR controls who can access defense-related technical data and where that data is allowed to reside. The same document can fall under both frameworks when export-controlled technical data is created for, provided by, or handled under a federal contract.

The NARA CUI Registry explicitly lists export-controlled information, including ITAR-regulated data, as CUI when certain legal conditions are met. The distinction starts with CUI’s role as a broad handling framework for federal information.

CUI Protects A Broad Range Of Federal Information

CUI standardizes how the executive branch handles unclassified information that requires safeguarding or dissemination controls under law, regulation, and government-wide policy. NARA is the CUI Executive Agent, and its Information Security Oversight Office implements the program.

The program replaced a patchwork of agency-specific markings with one consistent set of rules for marking, handling, and storing sensitive federal data.

CUI Covers More Than Defense Data

CUI spans far beyond defense technical data. It can include personally identifiable information held by federal agencies, federal financial and procurement records, law enforcement sensitive data, health information, Controlled Technical Information (CTI), and export-controlled data.

The CUI Registry lists 126 approved categories across numerous organizational groupings. The Federal Acquisition Regulation (FAR) proposed FAR CUI rule, published January 15, 2025, with comments closing March 17, 2025, would extend National Institute of Standards and Technology (NIST) SP 800-171 compliance to non-defense federal contractors handling CUI. That rule remains in the proposed rule stage after moving to the final rule stage in the Fall 2025 Semiannual Regulatory Agenda, with no final rule published.

CUI Imposes Cybersecurity Requirements For Protected Data

NIST SP 800-171 governs CUI security requirements in nonfederal systems. NIST published Revision 3 in May 2024, but for Department of Defense (DoD) contractors under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, NIST SP 800-171 Rev2 remains the operative standard.

CUI is fundamentally about protection. For SaaS vendors deploying cloud systems that handle CUI on DoD contracts, FedRAMP Moderate is the required cloud baseline. The obligation is technical: implement the controls, document them in a System Security Plan, undergo Third-Party Assessment Organization (3PAO) assessment, and maintain continuous monitoring.

ITAR Controls Access To Defense Technical Data

ITAR controls who is legally permitted to access defense-related data and where that data is allowed to go. That access question is separate from whether a system has strong cybersecurity controls.

ITAR Covers Defense Articles, Defense Services And Technical Data

ITAR governs the export, reexport, retransfer, and temporary import of defense articles, defense services, and related technical data:

  • Defense articles, services, and technical data are listed on the U.S. Munitions List (USML) at 22 CFR § 121.1, which defines the USML category spanning military aircraft, weapons systems, spacecraft, naval vessels, and energetic materials.  
  • The Department of State administers ITAR through its Directorate of Defense Trade Controls (DDTC), under the authority of the Arms Export Control Act (22 U.S.C. § 2778).  
  • Any U.S. person or entity that manufactures, exports, or brokers defense articles or services must register with DDTC, regardless of whether a federal contract is involved.  
  • Technical data under 22 CFR § 120.33 includes blueprints, drawings, plans, instructions, and software directly related to defense articles.

ITAR Restricts Access By Nationality

ITAR is often more restrictive than CUI because it limits access based on nationality. Any release or transfer of ITAR-controlled technical data to a foreign person is an export, including a deemed export when the release occurs in the United States, and requires State Department authorization unless an exemption applies.

Under 22 CFR § 120.17(b), any release of technical data to a foreign person in the United States is treated as an export to every country in which that person holds or has held citizenship or permanent residency. This restriction applies to employees, contractors, cloud platform administrators, and sub-processors.

Physical ITAR controls, such as restricted areas, ITAR cover sheets, warning signs, and segregated workstations, address facility and workstation access. Cloud deployments add network, administrator, and sub-processor access paths to that same access-control problem.

EAR Adds A Parallel Export Control Regime

While ITAR governs defense articles on the USML, the Export Administration Regulations (EAR) apply to dual-use and commercial technologies that may still be restricted based on end use, end user, or destination. The EAR are codified at 15 CFR Parts 730 to 774 and administered by the Bureau of Industry and Security within the Department of Commerce.

Within the CUI framework, both ITAR- and EAR-controlled technical data are handled as Export Control CUI. For SaaS vendors, ITAR covers military-specific items; EAR covers commercial items with potential military application. Both can generate CUI obligations when the data is created under or provided in connection with a federal contract.

CUI And ITAR Diverge On Authority, Scope, Enforcement And Penalty

A vendor scoping a compliance program has to compare the frameworks across authority, scope, enforcement, and penalty.

DimensionCUIITAR
What it isFederal data protection and handling frameworkExport control regime restricting access and transfer
Governing authorityExecutive Order 13556; 32 CFR Part 2002; NARA CUI RegistryArms Export Control Act (AECA); 22 CFR Parts 120-130
Administered byNARA, with agency and DoD implementationU.S. Department of State, DDTC
What it coversUnclassified information requiring safeguarding or dissemination controls, across 126 categoriesDefense articles, defense services, and related technical data on the USML
Core restrictionHow data must be secured and protectedWho can access data, and where it can be transferred or stored
Cybersecurity standardNIST SP 800-171; FedRAMP Moderate for cloud systemsNo built-in cybersecurity standard; access restrictions govern
Access restriction basisClearance, need-to-know, contract scopeNationality; State Department authorization
Enforcement bodyAgency contracting officers; DoD for DFARS mattersState Department and Justice Department
PenaltiesContract termination; debarment; civil penaltiesITAR civil penalties up to $1,271,078 per violation; criminal penalties up to $1M and 20 years imprisonment
Cloud overlapFedRAMP Moderate required for CUI in the cloudITAR alone requires cloud providers to restrict foreign national access; CUI or contract requirements drive FedRAMP

Three distinctions determine which obligations apply. First, CUI imposes a cybersecurity obligation, while ITAR imposes an access obligation. Second, CUI arises from a federal relationship, while ITAR arises from the nature of the data. Third, CUI violations typically result in contract consequences and civil penalties enforced through acquisition mechanisms, often via the False Claims Act, while ITAR violations can carry criminal liability under the Arms Export Control Act.

Classifying any specific document under ITAR involves legal judgment. Readers should consult qualified export-control counsel on classification questions.

ITAR Data And CUI Obligations Can Apply To The Same Document

A single document can trigger both frameworks at once. That overlap has direct consequences for how a cloud environment must be scoped.

ITAR-Controlled Data Becomes CUI In Federal Contract Contexts

The NARA CUI Registry maps both ITAR- and EAR-controlled data to the Export Controlled (EXPT) category. ITAR technical data becomes CUI under specific conditions:

  • Export-controlled technical data under ITAR and EAR qualifies as Export Control CUI when provided by or generated during DoD contract performance.  
  • A company-funded internal design, funded by internal research and development, never shared with or generated for the government, remains ITAR-controlled outside the CUI framework.  
  • Once that same data is shared with or created for a federal agency under contract, it becomes CUI as well.  
  • If the technical information is lawfully publicly available without restriction, it is excluded from the CUI Controlled Technical Information definition; export-control public-domain exclusion rules may also apply.

The contract and markings determine the practical test: contract terms determine whether the industry must generate and mark CUI, and either the government marks the information as CUI or the contractor creates export-controlled information subject to that contract.

Dual-Framework Data Requires Parallel Controls

When data carries both labels, the organization must satisfy two independent compliance stacks through the following actions:

  • Implement the applicable NIST SP 800-171 Rev2 controls for the CUI obligation. For DoD contracts under DFARS 252.204-7012, that means all 110 Revision 2 controls.  
  • Restrict system access to U.S. persons only for the ITAR obligation. This restriction covers cloud administrators, support staff, and sub-processors, with documented screening and access control policies.  
  • Prepare for Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment or certification as specified in the applicable DoD contract, when handling covered defense information under DFARS 252.204-7012. Contractors handling ITAR-controlled technical data that also qualifies as CUI will need to meet this level at a minimum. Mandatory third-party assessment had been scheduled to phase in by November 10, 2026, but DoD suspended that transition on July 13, 2026, pending a 60-day program review; Phase 1 self-assessment and the underlying DFARS 252.204-7012 safeguarding obligation remain in force and unaffected.  
  • Ensure the cloud infrastructure hosting the data meets the applicable FedRAMP impact baseline, such as FedRAMP Moderate or equivalent controls where permitted, and that no foreign nationals hold administrative or privileged access to the environment.  
  • Apply the required CUI banner markings and export-control markings per the contract.

A CMMC Level 2 certification covers only CUI protection. ITAR compliance still requires export-control classification, authorization where required, and U.S.-person access restrictions.

Cloud Infrastructure Requirements Converge For CUI, ITAR And Dual-Framework Data

Understanding the difference between CUI and ITAR matters for legal analysis, contract review, marking, and access policy. The underlying infrastructure requirement still converges. Any cloud system handling export-controlled CUI or dual-framework data under a DoD contract needs FedRAMP-authorized infrastructure, restricted access controls, and continuous monitoring.

A compliant cloud environment for CUI and ITAR data requires five operating decisions:

  1. Target FedRAMP Moderate for cloud services handling CUI where applicable; for DoD CUI, the cloud service may need FedRAMP Moderate authorization or DoD-recognized equivalency.  
  2. Implement access controls restricting privileged system access to U.S. persons, satisfying the ITAR nationality-based access restriction at the cloud infrastructure layer.  
  3. Implement and document the applicable NIST SP 800-171 Rev2 controls in a System Security Plan.  
  4. For DoD contracts with a CMMC Level 2 certification requirement, achieve Level 2 certification and scope the cloud boundary to cover systems processing covered defense information. Under DoD Cloud Computing SRG V1R6 (December 2025), Defense Information Systems Agency Impact Level 4 (DISA IL-4) is the designated entry point for CUI, including export-controlled data, and requires FedRAMP Moderate plus CUI-specific FedRAMP+ controls.  
  5. Ensure any external cloud service used to store, process, or transmit CUI meets FedRAMP Moderate or equivalent requirements, and ensure that only authorized U.S. persons can access ITAR-controlled data.

Building this on the traditional do-it-yourself path is where vendors stall. For a SaaS company with a federal deal in the pipeline and a deadline that does not move, the traditional authorization timeline of 12 to 36 months is incompatible with the opportunity. A pre-authorized boundary changes the math.

CUI And ITAR Require Different Analysis And The Same Authorized Infrastructure

For vendors moving into defense and federal markets, the classification exercise matters because it determines who can see the data, how the environment is scoped, and what contract risk follows. The business decision is narrower: if export-controlled CUI may enter the product boundary, the infrastructure has to be ready before the deal reaches contract review. Building that boundary on the do-it-yourself path can cost upwards of $3.5 million and take up to three years before a vendor signs a single federal contract.

Knox Systems is a FedRAMP-as-a-Service platform that manages the infrastructure layer for vendors handling CUI, export-controlled data, or both. Its pre-authorized Knox FedRAMP allows vendors to inherit most required controls rather than build them from scratch. U.S.-person access controls are built in, and continuous monitoring is handled through Knox's automated continuous monitoring platform. Vendors come as they are, deploy across AWS, Azure, or GCP, and inherit active authorizations within approximately 90 days.

Knox currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4. These authorization levels support general CUI and defense workloads involving export-controlled data. IL-5 authorization is in process, with an estimated completion date of December 2026.

If your product handles federal data with export control implications, the compliance requirements run in parallel. Book a meeting with Knox to assess your path.

FAQs about CUI and ITAR

Does ITAR require FedRAMP authorization on its own?

No. ITAR governs access to controlled technical data. FedRAMP becomes relevant when CUI, covered defense information, or contract clauses require an authorized cloud environment.

Can a CMMC Level 2 certification satisfy my ITAR obligations?

No. CMMC Level 2 addresses CUI protection. Export-control classification, authorization analysis, and U.S.-person access restrictions remain separate.

Is ITAR-controlled data always CUI?

No. Privately funded ITAR technical data can remain outside CUI if it is never shared with or generated for the government. Federal contract context changes that analysis.

What encryption exemption does ITAR allow for cloud storage?

ITAR recognizes a carve-out referenced in 22 CFR § 120.54(a)(5) for certain storage or transmission scenarios involving Federal Information Processing Standards (FIPS) 140-3 validated cryptography. The carve-out addresses encrypted storage or transmission, not unauthorized access by foreign persons to unencrypted data.