Skip to main content
All posts

ITAR and Contract Engineering Staffing: Who Can Touch the Design

By Game 7 Staff3 min read
ITAR access whiteboard in defense lab, badge on ledge and lab gear reflected

Do contract engineers need to be US persons under ITAR? If they access controlled technical data, yes, regardless of employment structure.

Do Contract Engineers Need to Be US Persons Under ITAR?

If they access ITAR-controlled technical data, yes. The US-person requirement applies to anyone who touches controlled data, regardless of employment structure: full-time, W2 contract, or corp-to-corp. The verification obligation sits with the program, and a staffing partner working defense programs should confirm US-person status before anyone is submitted, not after. This is educational context, not legal advice; confirm specifics with export-control counsel.


What ITAR Controls

The International Traffic in Arms Regulations (22 CFR Part 120), administered by the State Department’s Directorate of Defense Trade Controls, govern defense articles and their associated technical data on the US Munitions List. Technical data is the part staffing decisions turn on: it includes the information required to design, develop, or produce a defense article, so schematics, drawings, specifications, and source code are as controlled as the hardware they describe. Commercial and dual-use items fall under a separate regime, the Export Administration Regulations, and some defense electronics have moved there under export-control reform, but on a genuine ITAR program the schematic is a controlled item.


The US-persons Requirement In Plain Terms

A “US person” under ITAR (22 CFR 120.62) means a US citizen, a lawful permanent resident (green-card holder), or a protected individual such as a refugee or asylee. Releasing controlled technical data to anyone who isn’t a US person is treated as an export to that person’s country, even when it happens inside a US facility. That concept, the deemed export, is why a visa holder’s access to controlled data ends the conversation unless the program holds a specific authorization from DDTC.


Why Employment Structure Is Irrelevant

The rule attaches to access, not to a badge color. An engineer who reads a controlled schematic has accessed controlled technical data whether they’re a full-time employee, a W2 contractor, or working corp-to-corp. That’s the piece a generalist staffing firm most often gets backwards, assuming a contractor sits outside the requirement. On an ITAR program, everyone who can see the data has to qualify.


DFARS Flow-downs and CMMC

Defense contracts add obligations that land on staffing arrangements too. DFARS clause 252.204-7012 requires safeguarding covered defense information to the NIST SP 800-171 control set and reporting cyber incidents, and it flows down to subcontractors and to partners who handle that information. The Cybersecurity Maturity Model Certification (CMMC) program is extending certified cybersecurity requirements across the defense supply chain on a phased schedule, and a staffing firm handling controlled unclassified information is part of that chain, not exempt from it.


Who Verifies What

Splitting the obligations keeps both sides honest. The matrix below is the version worth confirming with counsel for your specific program.

Game 7 table showing ITAR requirements and who owns each responsibility


Red Flags In a Staffing Partner On ITAR Programs

A vendor that shrugs at export control is a liability you inherit. Five questions surface the weak ones quickly.

Five ITAR questions to ask any staffing vendor
1. How do you verify US-person status, and at what point in the process?
2. Where is candidate data stored and handled, and is any of it processed offshore?
3. How do you keep controlled technical data out of resumes, job descriptions, and your ATS?
4. What’s your process when a program requires a DDTC authorization for a specific engineer?
5. Who on your side owns export-control compliance, and can we talk to them?


A Necessary Disclaimer

This post is educational context for hiring and program teams, not legal advice. ITAR determinations are fact-specific, and the regulations change. Confirm the specifics of your program with qualified export-control counsel before acting.


Working an ITAR Program?

Tell us what you’re looking for and the program you need to staff, and you’ll get a partner that verifies US-person status before the first submit and handles controlled data accordingly.

FAQ

Frequently Asked Questions

Do contract engineers need to be US persons under ITAR?

If they access ITAR-controlled technical data, yes. The US-person requirement applies to anyone who touches controlled data, regardless of employment structure: full-time, W2 contract, or corp-to-corp. The verification obligation sits with the program, and a staffing partner working defense programs should verify US-person status before anyone is submitted, not after. This is educational context, not legal advice; confirm specifics with export-control counsel.

What counts as a US person under ITAR?

A US citizen, a lawful permanent resident (green-card holder), or a protected individual such as a refugee or asylee. Anyone else is a foreign person, and releasing controlled technical data to them, even inside the US, is treated as an export requiring authorization from the State Department’s DDTC. This is not legal advice; confirm with export-control counsel.

Does ITAR treat contractors differently from employees?

No. ITAR attaches to who accesses controlled technical data, not to employment status. A contractor who reads a controlled schematic is in the same position as an employee who does. Everyone with access has to qualify as a US person or the program needs a specific export authorization.

Written by

Game 7 Staff