V5 Ultimate
ITAR · USML · DFARS 252.204-7012 · CMMC 2.0 · On-Prem

ITAR compliance software with US-person access control as a physical block, not a policy PDF.

ITAR-controlled technical data — drawings, routings, eBR content, measurement data — gated by US-person / foreign-person attribute per USML category. On-premises deployment for sites that cannot host tech data in a multi-tenant cloud. DFARS 252.204-7012 and CMMC 2.0 Level 2 aligned by construction.

Start a free trial See execution + configuration control
ITAR
USML-category gating
DFARS 7012
Aligned
CMMC 2.0 L2
Aware
On-prem / air-gap
Available
Part 11
Native
If any of these sound familiar

You're shopping for ITAR compliance software because a foreign-person export violation on tech data is a bet-the-company event.

Foreign-person access to ITAR tech data is a policy, not a control

Cloud QMS/MES vendors can't tell you where data physically sits

DFARS 7012 SSP evidence is a Word document, not a live artefact

CMMC 2.0 Level 2 assessment prep is a six-month project

Empty-drawer / clean-desk enforcement is a poster, not a system

ECCN / USML determinations live in a spreadsheet nobody trusts

What's in the box

Access control that survives an ITAR audit.

US-person / foreign-person RBAC

Every user has an attested US-person status. Every controlled object (drawing, routing, eBR content) has a USML category. Access is the intersection — enforced at every fetch, not just at login.

USML category tagging

Category I–XXI tagging on objects, with export authorisation (TAA, MLA, DDL) recorded and expiry-tracked. Objects with expired authorisations become unreachable automatically.

On-premises deployment

V5 Ultimate On-Premises is containerised, air-gap capable, customer-owned encryption keys, customer-owned database. Tech data never leaves the site.

DFARS 252.204-7012 evidence

Access logs, incident response workflow, media protection, encryption at rest and in transit — all native and evidenced live, not documented in a static SSP.

CMMC 2.0 Level 2 mapping

NIST SP 800-171 rev 2 practices mapped to platform controls — audit log (AU), access control (AC), configuration management (CM), incident response (IR), system & information integrity (SI).

Signed, hash-chained audit trail

Every access to ITAR-controlled tech data is logged, signed and hash-chained. Investigator can prove exactly who saw what, when, from which physical location.

What changes the day this goes live

What changes when ITAR access control is a system, not a policy.

  • Foreign-person exposure to controlled tech data becomes physically impossible
  • DFARS 7012 self-assessment is a report extract, not a project
  • CMMC 2.0 Level 2 assessment prep drops from months to weeks
  • Prime supplier due-diligence questionnaires answer themselves
  • Empty-drawer policy is enforced in-system, not posted on the wall
  • Export-authorisation expiry stops being a surprise
Regulatory anchor

Every export-control control your CISO and DFARS auditor will ask about.

ITAR (22 CFR 120-130)

Access to USML-controlled technical data gated by attested US-person status per category. Export authorisations (TAA, MLA, DDL) recorded and enforced.

EAR (15 CFR 730-774)

ECCN-tagged objects with dual-use export control expectations aligned. Denied-party screening hooks at user provisioning.

DFARS 252.204-7012

Adequate security (NIST SP 800-171 rev 2), incident reporting within 72 hours, cyber incident information preservation — all live, evidenced controls.

CMMC 2.0 (Level 2 aware)

110 NIST 800-171 practices mapped to platform controls — access control, audit and accountability, configuration management, incident response, media protection, system and information integrity.

21 CFR Part 11 (where applicable)

For dual-use defence-medical suppliers: bound e-signatures and hash-chained audit trail on top of the ITAR access layer.

Questions buyers actually ask

ITAR compliance software, answered.

What is ITAR compliance software?

ITAR compliance software gates access to USML-controlled technical data — drawings, routings, eBR content, measurement data, source code — by attested US-person status per USML category. It replaces policy-only controls (posters, training, honor-system access) with a system control that physically blocks foreign-person access to controlled objects.

Does V5 support on-premises deployment?

Yes. V5 Ultimate On-Premises is containerised (Docker/Kubernetes), air-gap capable, with customer-owned encryption keys, customer-owned database and customer-controlled patch cycle. Tech data never leaves the site, which is often the only acceptable deployment for USML Category XV, XVI or XXI work.

How does US-person status work?

Every user carries an attested US-person status (per 22 CFR 120.62). Every controlled object carries a USML category. Access is the intersection — foreign-persons are blocked from category-tagged objects, and the attempt is logged. Expiry of an export authorisation (TAA, MLA, DDL) revokes access automatically.

Is V5 DFARS 252.204-7012 compliant?

V5 supports the adequate-security expectations of DFARS 7012 — NIST SP 800-171 rev 2 practices, 72-hour incident reporting workflow, cyber incident information preservation, and evidence generation for the required self-assessment. Compliance ultimately requires a full SSP; V5 provides the platform controls and live evidence that populate it.

Does V5 map to CMMC 2.0?

Yes. All 110 NIST SP 800-171 rev 2 practices required for CMMC 2.0 Level 2 have a mapped control in V5. The platform is not itself an assessor — you still need a C3PAO — but assessment prep collapses when access, audit, configuration and incident controls are live in-system rather than documented in a Word file.

How long does implementation take?

Most defence suppliers stand up ITAR-tagged RBAC and controlled-object access within 21–30 days of an on-prem install. Full CMMC 2.0 Level 2 assessment prep on top typically runs 8–16 weeks depending on the scope of the Assessment Boundary.

Make US-person access a control your auditor can verify — not a policy your training tries to remember.

Free trial (cloud) or on-prem evaluation. No sales gate.