Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

Technology Control Plan (TCP)

An institutional document, developed and implemented by a research institution (typically coordinated by the export control office or research security office together with the Principal Investigator), that specifies the physical, IT, and administrative safeguards used to prevent unauthorized access to a specific set of ITAR- or EAR-controlled technology, technical data, software, or equipment. A TCP is required whenever controlled technology is present in a project or lab and no exclusion (fundamental research exclusion) or license exception/exemption fully removes the access restriction — most commonly because a foreign national who is not a US person, per 22 CFR 120.62 and 15 CFR 772.1, will otherwise have physical, visual, electronic, or oral access to the controlled item or data. Its defining feature is that it names the specific controlled technology, identifies by name and citizenship every individual authorized to access it, and sets out concrete, auditable controls — not general policy language — covering access restriction, physical and IT security, personnel screening, and training.

ByCASRAI Editorial Board
· Last updated 17 Jul 2026

Examples

Worked examples

  • Is an instance

    A materials-science lab receives a piece of dual-use, EAR-controlled test equipment from an industry sponsor. Because a postdoctoral researcher on the team is not a US person and no license exception applies, the export control office requires a TCP before the equipment arrives: it names the postdoc and every other lab member with access, restricts the equipment to a keyed room, requires sign-in logs, and mandates that the PI review the plan before any new personnel join the project.

  • Is an instance

    A defense-related engineering project involves ITAR-controlled technical data (specifications on the US Munitions List) shared under a State Department license that lists specific authorized foreign-national recipients by name. The university's TCP for that project encrypts the technical data at rest, restricts email transmission, requires all authorized personnel to sign a briefing/certification form, and is reviewed annually as a condition of the license.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A basic-science project with no proprietary sponsor restrictions, open publication plans, and no ITAR/EAR-controlled inputs falls under the fundamental research exclusion and needs no TCP — the exclusion, not a TCP, is what keeps the project outside the regulated perimeter in the first place.

  • Not an instance

    A general lab safety plan or a data management plan covering routine, non-controlled research data is not a TCP; a TCP applies specifically, and only, to material that has been formally determined to be export-controlled and lacks an available exclusion, exception, or exemption.

Editorial commentary

A Technology Control Plan (TCP) is the operational document a research institution puts in place to manage access to a specific item, technology, technical data set, or piece of software that has been determined to be controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). Rather than describing export control policy in general terms, a TCP is item- and project-specific: it names what is controlled, names who may access it, and sets out the concrete physical, IT, and administrative safeguards that keep access limited to authorized US persons and specifically approved, licensed foreign nationals.

TCPs sit downstream of a classification decision. An export control or research security office first determines whether a given item, dataset, or piece of equipment is subject to ITAR or EAR jurisdiction and whether an exclusion, exemption, or license exception removes it from restriction — most commonly the fundamental research exclusion rooted in NSDD-189, which covers most open, publication-intended university research. When that review concludes the item genuinely is controlled and no exclusion or exception fully applies, a TCP becomes the mechanism for managing the resulting access risk, particularly the risk of a deemed export — the release of controlled technology or technical data to a foreign person inside the United States, which US regulations treat as an export to that person’s country of citizenship even with no physical shipment involved.

When a university needs a TCP

A TCP is typically triggered by one or more of the following:

  • A foreign national on the project who is not a US citizen, lawful permanent resident, or other protected individual under 8 U.S.C. § 1324b(a)(3) will have physical, visual, electronic, or oral access to a controlled item or dataset, and no deemed-export license exception applies.
  • Defense-related or dual-use research involving equipment, software, or technical data on the US Munitions List (ITAR) or the Commerce Control List (EAR), including sponsor-furnished or contractor-furnished controlled items brought onto campus.
  • A specific export license issued by the Department of State’s Directorate of Defense Trade Controls (DDTC) or the Department of Commerce’s Bureau of Industry and Security (BIS) that itself requires a TCP as a condition of approval — BIS’s own published guidance on deemed-export license applications describes the elements it expects to see in a supporting TCP.
  • A sponsor or contractual restriction that removes a project from the fundamental research exclusion (e.g., publication restrictions or access limited by nationality), making export control review — and potentially a TCP — applicable where it otherwise would not be.

A project with no controlled items, no publication restrictions, and no nationality-based access limits generally never reaches this point: the fundamental research exclusion keeps it outside ITAR/EAR jurisdiction entirely, and no TCP is needed. Determining which situation applies is a classification decision made by the institution’s export control office, not by individual researchers — see Export-controlled research for the broader operational definition of when a project is controlled at all.

What a TCP typically contains

Published TCP guidance and templates from university export control offices, and BIS’s own guidance on what it looks for in a TCP submitted to support a deemed-export license application, converge on a consistent set of elements:

  • Identification of the controlled technology — a specific description of the item, technical data, software, or equipment covered, including its ITAR/USML category or EAR Export Control Classification Number (ECCN) where applicable, so the plan’s scope is unambiguous.
  • Named, screened personnel with access — every individual authorized to access the controlled technology, listed by name and citizenship/immigration status, checked against US government restricted- and denied-party lists before access is granted.
  • Physical security measures — restricted-access signage, locked and key- or badge-controlled rooms or cabinets, visitor logs, and clear labeling of controlled items and materials to prevent inadvertent exposure to unauthorized individuals.
  • IT/information security measures — password protection and encryption for controlled electronic data, restrictions on transmitting it by unencrypted email or cloud storage, access logging, and secure destruction or return of controlled data and media at project close-out.
  • Training and certification requirements — a mandatory briefing on the specific restrictions in force, with each authorized individual signing the TCP or an accompanying certification confirming they understand and will comply with it before being granted access.
  • Ongoing administration — a designated responsible party (typically the Principal Investigator, working with the export control office), a defined review cycle (often annual), and a requirement that any change in personnel or scope be approved before it takes effect rather than reported after the fact.

Who is responsible

The Principal Investigator is generally responsible for day-to-day compliance with an active TCP — controlling physical access, briefing new personnel, and flagging changes — while the institution’s export control office or Empowered Official (the individual authorized to make ITAR classification and licensing determinations on the institution’s behalf) develops the plan’s terms, confirms it satisfies the applicable regulation or license condition, and reviews it periodically. Because a TCP is frequently a precondition for equipment or data actually being allowed onto campus, and can also be a formal condition attached to a DDTC or BIS export license, institutions generally require it to be in place and signed before controlled items arrive or before a newly identified foreign national is given access — not retroactively.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Technology Control Plan (TCP)"
      vocab-term-identifier="https://casrai.org/dictionary/term/technology-control-plan-tcp" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/technology-control-plan-tcp",
  "name": "Technology Control Plan (TCP)",
  "identifier": "https://casrai.org/dictionary/term/technology-control-plan-tcp",
  "description": "An institutional document, developed and implemented by a research institution (typically coordinated by the export control office or research security office together with the Principal Investigator), that specifies the physical, IT, and administrative safeguards used to prevent unauthorized access to a specific set of ITAR- or EAR-controlled technology, technical data, software, or equipment. A TCP is required whenever controlled technology is present in a project or lab and no exclusion (fundamental research exclusion) or license exception/exemption fully removes the access restriction — most commonly because a foreign national who is not a US person, per 22 CFR 120.62 and 15 CFR 772.1, will otherwise have physical, visual, electronic, or oral access to the controlled item or data. Its defining feature is that it names the specific controlled technology, identifies by name and citizenship every individual authorized to access it, and sets out concrete, auditable controls — not general policy language — covering access restriction, physical and IT security, personnel screening, and training.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/research-security#set",
  "url": "https://casrai.org/dictionary/term/technology-control-plan-tcp",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-17T04:33:23",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →