ITAR compliance software with US-person access control as a physical block, not a policy PDF.
ITAR-controlled technical data — drawings, routings, eBR content, measurement data — gated by US-person / foreign-person attribute per USML category. On-premises deployment for sites that cannot host tech data in a multi-tenant cloud. DFARS 252.204-7012 and CMMC 2.0 Level 2 aligned by construction.
You're shopping for ITAR compliance software because a foreign-person export violation on tech data is a bet-the-company event.
Foreign-person access to ITAR tech data is a policy, not a control
Cloud QMS/MES vendors can't tell you where data physically sits
DFARS 7012 SSP evidence is a Word document, not a live artefact
CMMC 2.0 Level 2 assessment prep is a six-month project
Empty-drawer / clean-desk enforcement is a poster, not a system
ECCN / USML determinations live in a spreadsheet nobody trusts
Access control that survives an ITAR audit.
US-person / foreign-person RBAC
Every user has an attested US-person status. Every controlled object (drawing, routing, eBR content) has a USML category. Access is the intersection — enforced at every fetch, not just at login.
USML category tagging
Category I–XXI tagging on objects, with export authorisation (TAA, MLA, DDL) recorded and expiry-tracked. Objects with expired authorisations become unreachable automatically.
On-premises deployment
V5 Ultimate On-Premises is containerised, air-gap capable, customer-owned encryption keys, customer-owned database. Tech data never leaves the site.
DFARS 252.204-7012 evidence
Access logs, incident response workflow, media protection, encryption at rest and in transit — all native and evidenced live, not documented in a static SSP.
CMMC 2.0 Level 2 mapping
NIST SP 800-171 rev 2 practices mapped to platform controls — audit log (AU), access control (AC), configuration management (CM), incident response (IR), system & information integrity (SI).
Signed, hash-chained audit trail
Every access to ITAR-controlled tech data is logged, signed and hash-chained. Investigator can prove exactly who saw what, when, from which physical location.
What changes when ITAR access control is a system, not a policy.
- Foreign-person exposure to controlled tech data becomes physically impossible
- DFARS 7012 self-assessment is a report extract, not a project
- CMMC 2.0 Level 2 assessment prep drops from months to weeks
- Prime supplier due-diligence questionnaires answer themselves
- Empty-drawer policy is enforced in-system, not posted on the wall
- Export-authorisation expiry stops being a surprise
Every export-control control your CISO and DFARS auditor will ask about.
ITAR (22 CFR 120-130)
Access to USML-controlled technical data gated by attested US-person status per category. Export authorisations (TAA, MLA, DDL) recorded and enforced.
EAR (15 CFR 730-774)
ECCN-tagged objects with dual-use export control expectations aligned. Denied-party screening hooks at user provisioning.
DFARS 252.204-7012
Adequate security (NIST SP 800-171 rev 2), incident reporting within 72 hours, cyber incident information preservation — all live, evidenced controls.
CMMC 2.0 (Level 2 aware)
110 NIST 800-171 practices mapped to platform controls — access control, audit and accountability, configuration management, incident response, media protection, system and information integrity.
21 CFR Part 11 (where applicable)
For dual-use defence-medical suppliers: bound e-signatures and hash-chained audit trail on top of the ITAR access layer.
ITAR compliance software, answered.
What is ITAR compliance software?
ITAR compliance software gates access to USML-controlled technical data — drawings, routings, eBR content, measurement data, source code — by attested US-person status per USML category. It replaces policy-only controls (posters, training, honor-system access) with a system control that physically blocks foreign-person access to controlled objects.
Does V5 support on-premises deployment?
Yes. V5 Ultimate On-Premises is containerised (Docker/Kubernetes), air-gap capable, with customer-owned encryption keys, customer-owned database and customer-controlled patch cycle. Tech data never leaves the site, which is often the only acceptable deployment for USML Category XV, XVI or XXI work.
How does US-person status work?
Every user carries an attested US-person status (per 22 CFR 120.62). Every controlled object carries a USML category. Access is the intersection — foreign-persons are blocked from category-tagged objects, and the attempt is logged. Expiry of an export authorisation (TAA, MLA, DDL) revokes access automatically.
Is V5 DFARS 252.204-7012 compliant?
V5 supports the adequate-security expectations of DFARS 7012 — NIST SP 800-171 rev 2 practices, 72-hour incident reporting workflow, cyber incident information preservation, and evidence generation for the required self-assessment. Compliance ultimately requires a full SSP; V5 provides the platform controls and live evidence that populate it.
Does V5 map to CMMC 2.0?
Yes. All 110 NIST SP 800-171 rev 2 practices required for CMMC 2.0 Level 2 have a mapped control in V5. The platform is not itself an assessor — you still need a C3PAO — but assessment prep collapses when access, audit, configuration and incident controls are live in-system rather than documented in a Word file.
How long does implementation take?
Most defence suppliers stand up ITAR-tagged RBAC and controlled-object access within 21–30 days of an on-prem install. Full CMMC 2.0 Level 2 assessment prep on top typically runs 8–16 weeks depending on the scope of the Assessment Boundary.
Make US-person access a control your auditor can verify — not a policy your training tries to remember.
Free trial (cloud) or on-prem evaluation. No sales gate.
