What Are ITAR, EAR, CUI, JCP, NIST 800-171 & CMMC? A Plain-English Guide
- 01The Big Picture: It’s All About the Data
- 02What Is CUI? (Start Here: It Ties Everything Together)
- 03What Is ITAR? (And the USML)
- 04What Is the EAR? (And the CCL)
- 05ITAR or EAR: Which Covers My Part?
- 06What Is JCP / DD Form 2345?
- 07What Is NIST SP 800-171? (And DFARS 252.204-7012)
- 08What Is CMMC? Level 1 vs Level 2
- 09How It All Fits Together + a Buyer’s Checklist
01The Big Picture: It’s All About the Data
None of these rules is really about aluminum or titanium. They are about the information that travels with defense hardware: drawings, models, specifications, and process data. The U.S. government controls that information in three ways, and each acronym belongs to one of them:
| Control | The question | The acronyms |
|---|---|---|
| Export control | Who may this information be released to? | ITAR & the USML · EAR & the CCL |
| Access control | Who may receive DoD’s own technical data? | JCP · DD Form 2345 |
| Safeguarding | How must the systems holding it be protected, and proven? | CUI · DFARS 7012 · NIST SP 800-171 · CMMC |
Keep that map in mind and the rest of this article is just filling in the boxes.
02What Is CUI? (Start Here: It Ties Everything Together)
CUI stands for Controlled Unclassified Information: information the government requires to be protected, without being classified. No security clearance is involved. Think of the tier below Confidential/Secret: part drawings, technical orders, specifications, program data. Created by Executive Order 13556 to replace a chaos of agency labels (FOUO, SBU, and friends), the program is run government-wide by NARA, which maintains the official registry of CUI categories.
Two categories matter most in manufacturing:
Controlled Technical Information (CTI) is technical data with military or space application: drawings, 3D models, specs, process sheets. If DoD gives a supplier a drawing marked with a distribution statement, that drawing is almost certainly CTI.
Export-controlled information is data whose release is limited by ITAR or the EAR (sections 03 and 04). Yes: ITAR technical data handled on a DoD contract is also CUI. The regimes overlap on the same file.
Distribution statements: the marking that tells you who may have it
DoD technical documents carry a distribution statement (per DoD Instruction 5230.24), usually printed near the title block, stating exactly how far the document may travel. If you machine defense parts, you will see these constantly:
| Statement | Who may receive the document |
|---|---|
| A | Approved for public release; distribution unlimited. The only statement with no handling burden. |
| B | U.S. Government agencies only (for the stated reason; others must request through the controlling office). |
| C | U.S. Government agencies and their contractors. |
| D | Department of Defense and DoD contractors only. |
| E | DoD components only. |
| F | Only as directed by the controlling DoD office (the most restrictive). |
In practice: anything B through F is controlled. A supplier holding such a drawing may not forward it to a sub-vendor, a finisher, or anyone else without confirming the recipient is eligible; this is exactly what JCP certification (section 06) establishes for contractors. Statements are commonly paired with an export-control warning notice and destruction instructions, and a distribution-marked technical drawing is, on a DoD contract, CUI, which brings the NIST SP 800-171 safeguarding duties of section 07 with it.
One caution on over-marking. CUI is a government designation, not a general label for sensitive drawings. Information is CUI when the designation flows from a government contract that requires safeguarding; commercial work does not become CUI because a title-block template says so. We have received customer drawings with CUI banners applied by template to purely commercial parts, and the unnecessary marking adds handling burden for every supplier downstream without a legal basis. Put CUI on the drawing only when it flows from a government contract, and leave it off when it does not.
Why start here? Because in essence, everything else in this article is machinery for handling CUI correctly: export control says who may see it, JCP governs receiving it from DoD, 800-171 says how to store it, and CMMC checks that you actually do.
03What Is ITAR? (And the USML)
ITAR, the International Traffic in Arms Regulations, is the State Department’s rulebook for defense articles. Administered by the Directorate of Defense Trade Controls (DDTC), it implements the Arms Export Control Act and covers items on the United States Munitions List (USML): 21 categories from firearms to spacecraft, including the technical data for those items.
Three things follow in practice:
Manufacturers must register. Any U.S. company that manufactures USML items must register with DDTC even if it never exports anything. Registration identifies the manufacturer to the government; it is a prerequisite to export licensing, not a license itself.
Drawings are defense articles too. Showing an ITAR drawing to a foreign person, even an employee inside the U.S., is a deemed export requiring authorization. That is why ITAR shops control who can open a file, not just where parts ship.
People are part of compliance. Because deemed exports happen inside the building, who a shop employs matters as much as its IT systems. C&W hires only U.S. persons, and every employee has cleared a background check. If you run supplier onboarding or security questionnaires, that is the answer to the personnel question, and we are glad to certify it in writing.
ITAR follows the item, not the company. “ITAR-registered shop” describes the supplier. Whether ITAR applies to your part depends on whether the part or its data is on the USML.
04What Is the EAR? (And the CCL)
The EAR, or Export Administration Regulations, is the Commerce Department’s rulebook for everything dual-use. Run by the Bureau of Industry and Security (BIS), it controls commercial items with potential military application through the Commerce Control List (CCL), where items carry an ECCN (Export Control Classification Number). Controlled-but-unlisted items fall to the catch-all EAR99.
Here is the part people miss: much genuinely military hardware is not ITAR. Export Control Reform moved many military vehicle and aircraft components from the USML to the CCL’s “600 series”: still tightly controlled, but under Commerce rules. A shop machining colloquially “defense” components may be doing EAR-controlled work, ITAR work, or both. C&W does both, under the same controlled-handling practices.
05ITAR or EAR: Which Covers My Part?
Jurisdiction is decided by the item, in order: is it described on the USML? Then ITAR. If not, does it carry a CCL classification? Then EAR. Neither? EAR99. When genuinely unclear, the formal answer is a Commodity Jurisdiction (CJ) determination from DDTC.
The most common real-world failure isn’t data going to the wrong country; it’s mislabeling. Programs stamp everything “ITAR” defensively, pushing cost onto parts that are actually EAR or uncontrolled; or they leave controlled prints unmarked and email them to unvetted vendors.
The fix is unglamorous: classify the part (USML category or ECCN), mark the drawing accordingly, and state the jurisdiction in your RFQ before anything is transmitted. And never push controlled data through a public web upload, checkbox or not; a compliant shop will give you a secure channel instead.
06What Is JCP / DD Form 2345?
The U.S./Canada Joint Certification Program is how a company gets permission to receive DoD’s own technical data. Administered by DLA, it certifies contractors, via DD Form 2345, to access militarily critical technical data: the drawings and specs behind weapons-system parts. Without JCP certification, a shop cannot pull the technical data package to bid a DLA solicitation or produce many defense spares.
Certification names a data custodian, binds the company to lawful handling, and renews on a five-year cycle. For a buyer, a supplier’s JCP certification is a strong signal: the shop is already vetted to receive the government’s controlled drawings, and handling yours properly is the same discipline.
07What Is NIST SP 800-171? (And DFARS 252.204-7012)
NIST SP 800-171 is the security standard for protecting CUI on non-government systems. It contains 110 requirements across 14 families, from access control and encryption to audit logging, incident response, and media protection. It answers, control by control, the question “what does ‘protect the drawing’ actually mean for a company’s computers?”
What makes it binding is the contract clause DFARS 252.204-7012, flowed down through virtually every DoD prime contract to every subcontractor that touches covered defense information. The clause requires implementing 800-171, reporting cyber incidents to DoD within 72 hours, and, via the companion 7019/7020 clauses, posting a scored self-assessment to DoD’s SPRS database. If a supplier says they are “800-171 compliant,” the natural follow-up is whether that SPRS assessment is current.
08What Is CMMC? Level 1 vs Level 2
CMMC, the Cybersecurity Maturity Model Certification, is DoD’s program for verifying that the protection is real. For years, 800-171 ran on self-attestation, and DoD concluded that self-attestation wasn’t working. CMMC (finalized at 32 CFR Part 170) adds proof, at levels matched to what a contract handles:
| Level | Protects | Based on | How it’s verified |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 17 basic safeguarding practices (FAR 52.204-21) | Annual self-assessment |
| Level 2 | CUI | The same 110 controls as NIST SP 800-171 | Third-party assessment (C3PAO) for most programs; self-assessment for some |
| Level 3 | CUI on the most sensitive programs | Level 2 + selected NIST SP 800-172 controls | Government-led assessment |
Note what Level 2 is: the same 110 controls as 800-171. CMMC adds no new substance for most shops; it moves the proof from “we say so” to “an assessor checked.” Requirements are phasing into new DoD contracts through the late 2020s, and the direction of travel is clear: expect access to controlled technical data, including JCP-adjacent access, to lean increasingly on verified cybersecurity. ITAR, JCP, and CMMC are formally separate programs, but on real contracts they are converging into a single supplier qualification.
09How It All Fits Together + a Buyer’s Checklist
Follow one drawing through the system: DoD releases it to a JCP-certified shop. It is marked CUI//SP-CTI with an export-control warning, so ITAR (or the EAR) limits who may see it. The DFARS 7012 clause on the PO requires the shop’s systems to meet NIST SP 800-171, and, increasingly, CMMC Level 2 is how the shop proves it. Five acronyms, one file.
If you’re buying: ask a shop for its DDTC registration (for USML work), JCP DD-2345, AS9100D certificate, NIST SP 800-171 / DFARS 7012 posture, and its personnel practices, plus a secure channel for sending data. These are the same items on nearly every supplier-onboarding questionnaire. Any established defense supplier can produce all of them; C&W’s are on our certifications page, our workforce is U.S. persons only with cleared background checks, and our export-control practices are described on the ITAR-registered machine shop page.
If you’re sending an RFQ: state the data’s jurisdiction and markings (USML category, ECCN, CUI banner, distribution statement, or state that it is uncontrolled), flag any DFARS flow-downs, and ask for secure transmission instead of a public upload. A compliant shop will thank you for asking first. Our RFQ guide covers where this belongs in your package.