V5 Ultimate
Ultimate
PricingResourcesCompany
Start free trial

ITAR · USML · DFARS 252.204-7012 · CMMC · On-Prem

ITAR program software with role-based access and on-premises deployment options.

Supports evidence for DFARS 252.204-7012 and CMMC Level 2 (NIST SP 800-171 Rev 2).

Start a free trial See execution + configuration control
  1. US-person / foreign-person RBAC

  2. USML category tagging

  3. On-premises deployment

  4. DFARS 252.204-7012 evidence

Access control that survives an ITAR audit.
Full product detailCommon problems, what's included, why teams choose it, and where commercial meets regulated.+
If any of these sound familiar

You're shopping for ITAR compliance software because a foreign-person export violation on tech data is a bet-the-company event.

Foreign-person access to ITAR tech data is a policy, not a control

Cloud QMS/MES vendors can't tell you where data physically sits

DFARS 7012 SSP evidence is a Word document, not a live artefact

CMMC 2.0 Level 2 assessment prep is a six-month project

Empty-drawer / clean-desk enforcement is a poster, not a system

ECCN / USML determinations live in a spreadsheet nobody trusts

What's in the box

Access control that survives an ITAR audit.

US-person / foreign-person RBAC

Every user has an attested US-person status. Every controlled object (drawing, routing, eBR content) has a USML category. Access is the intersection — enforced at every fetch, not just at login.

USML category tagging

Category I–XXI tagging on objects, with export authorisation (TAA, MLA, DDL) recorded and expiry-tracked.

On-premises deployment

V5 Ultimate On-Premises is containerised, air-gap capable, customer-owned encryption keys, customer-owned database.

DFARS 252.204-7012 evidence

Access logs, incident response workflow, media protection, encryption at rest and in transit — all native and evidenced live, not documented in a static SSP.

CMMC 2.0 Level 2 mapping

NIST SP 800-171 rev 2 practices mapped to platform controls — audit log (AU), access control (AC), configuration management (CM), incident response (IR), system & information integrity (SI).

Signed, hash-chained audit trail

Every access to ITAR-controlled tech data is logged, signed and hash-chained. Investigator can prove exactly who saw what, when, from which physical location.

What changes the day this goes live

What changes when ITAR access control is a system, not a policy.

  • DFARS 7012 self-assessment is a report extract, not a project
  • CMMC 2.0 Level 2 assessment prep drops from months to weeks
  • Prime supplier due-diligence questionnaires answer themselves
  • Empty-drawer policy is enforced in-system, not posted on the wall
  • Export-authorisation expiry stops being a surprise
Regulatory anchor

Every export-control control your CISO and DFARS auditor will ask about.

ITAR (22 CFR 120-130)

Export authorisations (TAA, MLA, DDL) recorded and enforced.

EAR (15 CFR 730-774)

ECCN-tagged objects with dual-use export control expectations aligned. Denied-party screening hooks at user provisioning.

CMMC 2.0 (Level 2 aware)

110 NIST 800-171 practices mapped to platform controls — access control, audit and accountability, configuration management, incident response, media protection, system and information integrity.

21 CFR Part 11 (where applicable)

For dual-use defence-medical suppliers: bound e-signatures and hash-chained audit trail on top of the ITAR access layer.

Questions buyers actually ask

ITAR compliance software, answered.

Does V5 support on-premises deployment?+

Yes. V5 Ultimate On-Premises is containerised (Docker/Kubernetes), air-gap capable, with customer-owned encryption keys, customer-owned database and customer-controlled patch cycle.

How does US-person status work?+

Every user carries an attested US-person status (per 22 CFR 120.62). Every controlled object carries a USML category.

Is V5 DFARS 252.204-7012 compliant?+

V5 supports the adequate-security expectations of DFARS 7012 — NIST SP 800-171 rev 2 practices, 72-hour incident reporting workflow, cyber incident information preservation, and evidence generation for the required self-assessment. Compliance ultimately requires a full SSP; V5 provides the platform controls and live evidence that populate it.

Does V5 map to CMMC 2.0?+

Yes. All 110 NIST SP 800-171 rev 2 practices required for CMMC 2.0 Level 2 have a mapped control in V5. The platform is not an assessor, and whether a C3PAO assessment applies depends on your contract (DoD suspended CMMC Phase II on July 13, 2026; Phase I self-assessments remain) — but assessment prep collapses when access, audit, configuration and incident controls are live in-system rather than documented in a Word file.

Capabilities vary by plan and setup. Confirm specifics with our team before relying on them.

Make US-person access a control your auditor can verify — not a policy your training tries to remember.

Free trial (cloud) or on-prem evaluation.

Start free trial

Next step

Try V5 with your own records, or ask a question first. Ask V5 opens with an editable question; nothing is sent until you choose to.

Start your free trial Browse all features
V5 Ultimate
Ultimate

Warehouse, quality and manufacturing software for regulated operations.

ProductIndustriesPricingResourcesSecurity & TrustCompanyLegal centre

© V5 Ultimate

Page version 1.2 · Last revised 28 Sep 2026