Aerospace Sourcing
Controlled programs

ITAR, EAR and CUI work, under control.

Regulated hardware is where schedule and compliance risk is highest. Our process keeps technical data off the internet and puts a named step, and a sign-off, between your program and every supplier.

The short version

Controlled requests never carry technical data through this website. You tell us about the program: jurisdiction if known, clauses, DPAS rating, quantities and dates. We then work through ten documented release steps with you. Technical data moves only after every step is signed off, only over a channel your security team approves, and only to U.S. persons and suppliers whose authorization we have verified.

What we never accept online

  • Technical data subject to the ITAR (22 CFR 120 to 130), including drawings, models and process data for USML items.
  • Technology controlled under the EAR with an ECCN other than EAR99.
  • Controlled Unclassified Information, including covered defense information under DFARS 252.204-7012.
  • Anything your export compliance team has not yet classified.

The upload control on the request form only unlocks when a requester selects a commercial classification and attests that the files contain none of the above. The server rejects files on any other request.

Program intake

For a controlled or unclassified request the form collects program facts only: jurisdiction, USML category or ECCN if your team has determined it, the clauses that flow down, any DPAS rating, the transfer method you prefer and an unclassified program identifier. It also asks the requester to acknowledge that no technical data will be requested until the release steps are complete.

The ten release steps

StepWhat happens
01Customer confirmed export jurisdiction and classification in writing
02Mutual NDA fully executed
03Technology control plan acknowledged for this program
04U.S. person access list recorded for our team
05Supplier DDTC registration or EAR authorization verified
06Supplier NIST SP 800-171 / SPRS score and CMMC status verified
07Flow-down clauses and NDA issued to supplier
08Secure transfer channel agreed and tested
09Technical data released to authorized recipients only
10Data returned or destroyed at closeout, certificate filed

Each step is recorded against your request with a date. Our team will not release data while any step is open, and you can ask for the status of every step at any time.

Supplier verification

For controlled work we verify, for each supplier, the authorization the work requires (for ITAR manufacturing, current registration with the State Department's Directorate of Defense Trade Controls), that only U.S. persons will access the data, the supplier's NIST SP 800-171 assessment score in SPRS where DFARS 252.204-7012 applies, its CMMC status as the contract requires, and its quality system and special process approvals for the part.

Flow-down clauses

ClauseWhat it requires
FAR 52.204-21Basic safeguarding of covered contractor information systems (15 security requirements) for federal contract information.
DFARS 252.204-7012Safeguarding covered defense information: NIST SP 800-171 controls, cyber incident reporting to DoD within 72 hours, flow-down to subcontractors handling CDI.
DFARS 252.204-7019 / 7020NIST SP 800-171 DoD assessment requirements; a current assessment score posted in SPRS.
DFARS 252.204-7021Contractor compliance with the CMMC level required by the contract, flowed to subcontractors at the level their work requires.
DFARS 252.225-7009Restriction on certain specialty metals (for example titanium, certain steels and nickel alloys) to qualifying countries, with documentation.
DFARS 252.246-7007 / 7008Counterfeit electronic part detection and avoidance system, and the sourcing hierarchy for electronic parts.

Your purchase order and prime contract govern which clauses apply. We flow them to suppliers in writing along with the NDA, and keep the acknowledgements on file.

Secure transfer

The channel is chosen with your security team: your own managed file transfer or portal, DoD SAFE where a DoD party is involved, end-to-end encrypted email suited to CUI, or encrypted media hand carried. We test the channel with a non-sensitive file first and confirm each recipient against the access list before release.

Closeout and records

At closeout, controlled technical data held by our team is returned or destroyed and each supplier is instructed to do the same, with a written certificate on file. ITAR recordkeeping requirements at 22 CFR 122.5 call for records to be maintained for five years, and we keep records for the period each applicable regulation requires.

Questions

Can you take ITAR work?

We take controlled requests through a defined process rather than through the website. You submit program details, never technical data. Before any data moves we confirm jurisdiction with you in writing, execute the NDA, record a U.S. person access list, verify each supplier's DDTC registration or other authorization and cybersecurity posture, issue flow-downs and agree a secure channel. Where an activity requires our own registration or authorization, we obtain it before performing that activity.

Who decides whether my part is ITAR or EAR?

The owner of the design is responsible for the jurisdiction and classification of its technical data and hardware. We ask your export compliance team to confirm it in writing at step one. If it has not been determined, we treat the request as controlled until it is, and we do not ask for files in the meantime.

How do you move controlled files?

Through a channel your security team approves: your own managed file transfer or portal, DoD SAFE where a DoD party is involved, end-to-end encrypted email suited to CUI, or encrypted media hand carried. The channel is tested before release and every recipient is on the recorded access list.

What happens to my data when the job ends?

At closeout we return or destroy controlled technical data held by our team and instruct each supplier to do the same, then file a written certificate. Records required by regulation, such as ITAR transaction records, are kept for the period the regulation requires.

What is the current status of CMMC?

The DFARS rule implementing CMMC took effect on November 10, 2025. On July 13, 2026 DoD suspended the move to Phase 2, which would have made third-party Level 2 certification the default on November 10, 2026, pending a task force review. DFARS 252.204-7012, NIST SP 800-171 and SPRS scores still apply, so we verify those for every supplier on controlled work.

Sources

Controlled
request?

Submit program details only. We take it from there with you, step by step.

Start a controlled request