Most guidance on export control for universities walks through the regulations themselves — the Export Administration Regulations (EAR), the International Traffic in Arms Regulations (ITAR), and the fundamental research exclusion that keeps the bulk of academic research outside either regime. CASRAI’s Export Control (EAR/ITAR) and International Research Collaboration guide covers that ground, and Export Control Reform and Research Security: What’s Changing and Why covers how the policy landscape itself has shifted. This guide is different: it’s about how a research-compliance office actually organizes an export control program once the regulatory basics are understood — the operational structure most university export control offices converge on, whether or not they use this exact language.
Across the export control policies published by research universities, four recurring operational areas do most of the work: securing controlled technology from unauthorized access (including deemed exports inside a US lab), screening people and destinations before international travel, disclosing participation in foreign talent recruitment programs, and training the people who actually trigger these obligations day to day. None of the four is a formal regulatory category on its own — you won’t find “the four pillars” defined in 15 CFR or 22 CFR — but organizing a program this way maps cleanly onto where compliance offices actually spend their time, and onto four genuinely different failure modes that require different controls.
Why organize a program around these four areas
EAR and ITAR are the substantive law; a compliance program is the operational answer to “how do we not violate it.” The four areas below aren’t arbitrary — they correspond to four distinct points where a university actually creates export control exposure:
- Cybersecurity / deemed exports — exposure created by who has access to controlled technology, software, and technical data inside the institution, independent of anyone crossing a border.
- International travel — exposure created by physically carrying controlled items, software, or technical data out of the country, or engaging with sanctioned or restricted destinations and parties.
- Foreign talent recruitment program participation — exposure created by undisclosed relationships with foreign government talent programs, which is a disclosure and research-security problem that frequently intersects with, but is legally distinct from, export control itself.
- Training — the control that makes the other three actually work, since most deemed-export and hand-carry violations happen through an ordinary lab conversation, email, or packed bag, not a deliberate transfer.
A program that only covers one or two of these — for example, careful license classification but no travel-screening process — has a real gap, because the regulations don’t distinguish between “we didn’t know it was controlled” and “we knew but didn’t check before the trip.”
Pillar 1: Cybersecurity and deemed-export controls
The deemed export rule (15 CFR §734.13(a)(2)) treats the release of controlled technology or source code to a foreign person inside the United States as an export to that person’s country of citizenship or permanent residency. CASRAI’s deemed export dictionary entry and the EAR/ITAR guide linked above cover the rule itself in detail; the compliance-program question is how an institution actually prevents an unauthorized release from happening in a lab that has both US and foreign-national personnel working side by side.
In practice, this pillar covers:
- Classification before access is granted. Determining whether a given piece of equipment, software, or technical data carries an Export Control Classification Number (ECCN) under the EAR or appears on the US Munitions List under ITAR — see CASRAI’s ITAR US Munitions List (USML) guide — before it’s deployed into a lab with foreign-national members.
- Technology Control Plans (TCPs). A documented set of physical, IT, and procedural restrictions — badge-controlled lab access, segregated network shares or VLANs, supervised-only access to specific instruments — scoped to a specific controlled item and the specific individuals who may access it. See CASRAI’s Technology Control Plan (TCP) entry.
- IT and network segmentation. Isolating systems, drives, and lab networks that hold controlled technical data from general campus IT infrastructure, so that access can be restricted and logged at the system level rather than relying entirely on individual discretion.
- Overlap with federal cybersecurity mandates. Institutions holding Department of Defense contracts or subcontracts involving controlled unclassified information (CUI) face a separate but related set of information-security obligations under NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC) framework, formalized into DFARS contract clauses effective November 10, 2025. These aren’t export-control requirements per se, but the same IT infrastructure — access controls, network segmentation, audit logging — that supports deemed-export compliance is frequently the infrastructure that also has to meet CMMC’s control baseline, which is why cybersecurity and export control are usually managed by overlapping, coordinating offices rather than entirely separate ones.
The fundamental research exclusion (see the fundamental research exemption entry) narrows this pillar considerably where it applies: if the underlying research genuinely qualifies as unrestricted fundamental research, there’s typically nothing controlled to protect from deemed-export exposure in the first place. Deemed-export risk concentrates specifically on discrete controlled inputs — equipment, software, defense articles — brought into an otherwise-open project, not on the open research output itself.
Pillar 2: International travel screening
Travel is where export control stops being an abstract classification exercise and becomes a concrete, deadline-driven review. University export control offices typically run three distinct checks before a researcher travels internationally with any institutional equipment, data, or in connection with sponsored work:
- Destination screening. Checking the destination country against comprehensive-sanctions and embargoed-country lists maintained by the Treasury Department’s Office of Foreign Assets Control (OFAC) and Commerce’s country groups under the EAR. See CASRAI’s Embargoed Countries List for Export Control guide and the OFAC List (SDN List) entry. A handful of destinations (Cuba, Iran, North Korea, Syria, and the Russia-occupied regions of Ukraine, as of current OFAC comprehensive sanctions programs) trigger the most restrictive review; many other countries carry narrower, item-specific licensing requirements rather than a blanket restriction.
- Restricted-party screening. Checking any foreign institutions, collaborators, or conference co-organizers the traveler will meet against BIS’s Entity List, Denied Persons List, and Unverified List, and OFAC’s Specially Designated Nationals (SDN) list. See CASRAI’s Restricted Party Screening guide for how this process runs in practice, including how a hit doesn’t automatically bar the trip but changes what’s permissible.
- Hand-carry and technology review. A laptop, external drive, sample, or piece of equipment that a researcher physically carries across a border can itself constitute a controlled export if it contains or embodies controlled technology or technical data — this is a distinct trigger from the deemed export rule above, since it involves the item leaving the country rather than a foreign person accessing it domestically. Many institutions address this with loaner “clean” laptops for travel to higher-risk destinations, standing guidance to avoid carrying controlled data on personal or lab devices, and a pre-travel checklist that flags when a specific license exception (such as the EAR’s License Exception TMP for tools of trade) is or isn’t available for the item and destination in question.
Because all three checks are time-sensitive — a license determination or an Entity List review can take days to weeks — institutions that build this into standard pre-travel authorization workflows (travel booking systems that prompt an export control flag for international trips, tied to sponsored-programs and department-level sign-off) catch most issues before departure. Institutions that treat travel screening as optional or ad hoc are the ones that end up making the determination retroactively, after a trip has already happened.
Pillar 3: Foreign talent recruitment program disclosure
This pillar is legally distinct from EAR/ITAR export control, but it sits inside the same compliance office in most institutions and is frequently confused with export control by researchers, which is exactly why it belongs in the same operational framework. CASRAI’s Foreign talent recruitment programme entry and dedicated Malign Foreign Talent Recruitment Program (MFTRP) guide cover the definition and consequences in depth; the compliance-program question here is disclosure infrastructure, not the underlying legal definition.
The core obligation, driven by National Security Presidential Memorandum 33 (NSPM-33) and its implementing agency policies, requires researchers to disclose all foreign and domestic research support, affiliations, and participation in foreign talent recruitment programs — not just export-controlled activity. NIH and NSF have each built this into their standard proposal and progress-reporting documents (the NSPM-33 Common Form for Biographical Sketch and Current and Pending Support, delivered via SciENcv), and NIH’s Common Forms mandate (effective for due dates on or after January 25, 2026, per NIH Guide Notice NOT-OD-26-018) requires a certification regarding non-participation in a malign foreign talent recruitment program as part of that submission. Named programs such as China’s Thousand Talents Plan are the most-cited example of what these disclosure requirements target — see CASRAI’s Thousand Talents Program and Research Security guide.
Operationally, this pillar requires a disclosure-collection and cross-checking process largely separate from export control classification work: gathering current and pending support statements at proposal and progress-report stages, reconciling them against what a researcher’s public CV, grant history, and institutional appointment records actually show, and flagging discrepancies before a funder or federal agency does. This is also where NSPM-33’s four mandated research-security-program elements (a distinct federal framework covering institutional certification, cybersecurity, foreign travel, and insider-threat awareness at the program level) overlaps with, but is not identical to, the four operational pillars this guide describes for export control specifically — the two frameworks share vocabulary and often the same compliance staff, but NSPM-33’s program elements are a broader research-security mandate, while export control’s four pillars are scoped specifically to EAR/ITAR exposure.
Pillar 4: Training requirements
Training is the pillar that makes the other three operational rather than theoretical, because the majority of real deemed-export and hand-carry incidents happen through ordinary work — an unscreened lab visitor, a laptop packed the night before a conference, an email thread that includes a foreign-national collaborator — not through a deliberate attempt to evade the regulations. CASRAI’s Research Security Training guide covers the broader training landscape agencies now require; the export-control-specific slice of that training typically covers:
- Role-based awareness training for principal investigators, lab managers, and international-program staff, covering how to recognize a deemed-export or classification trigger in the ordinary course of running a lab — not just at the point a formal review is requested.
- Pre-travel training tied to the destination and restricted-party screening described in Pillar 2, delivered close enough to departure that it’s actually acted on rather than a once-a-year generic session.
- New-hire and visiting-scholar onboarding that identifies deemed-export exposure before, not after, a foreign national is given lab access — this is one of the more common sources of preventable delay when export control review is treated as a step after onboarding rather than part of it.
- Agency-driven research security training, which increasingly overlaps this pillar even though it’s legally separate: see CASRAI’s guides to NSF Research Security Training Requirements and NIH Research Security Training Requirements, and the NIH Research Security Training (RST) dictionary entry.
Institutions typically track completion the same way they track other mandatory compliance training (RCR, human-subjects, biosafety) — through a learning-management or CITI-style platform — but the content itself needs to be maintained and updated specifically for export control, since generic research-security training doesn’t cover ECCN/USML classification, TCP scope, or the destination- and party-screening mechanics described above.
How the four pillars work together
Treated separately, these four areas produce exactly the kind of gap that leads to a preventable violation: an office that’s rigorous about license classification but has no pre-travel screening step; a program that trains researchers once at hire but never revisits training before high-risk international trips; a disclosure process for foreign talent programs that never talks to the export control classification process, even though the same foreign collaboration frequently touches both. CASRAI’s broader Seven Elements of an Effective Compliance Program, Applied to Research Compliance guide covers the general compliance-program-design principles (risk assessment, monitoring, corrective action) that apply here too; the four-pillar structure in this guide is the export-control-specific application of that same discipline. In practice, the institutions that manage this well route cybersecurity/TCP decisions, travel screening, foreign-talent disclosure review, and training delivery through a single coordinating export control office or Empowered Official, even where the underlying legal authority for each pillar sits in a different regulation — because the same international collaboration or the same foreign national researcher is very often the fact pattern that triggers more than one pillar at once.
Frequently asked questions
Is “the four pillars of export control compliance” an official regulatory framework?
No. EAR and ITAR don’t define a “four pillars” structure, and there’s no single federal document that mandates organizing a program this way. It’s a practical, commonly-used way research-compliance offices structure a program around the four areas — controlled-technology security, travel, foreign talent disclosure, training — that actually generate export control exposure. Treat it as an organizational tool, not a compliance checklist a regulator will audit against by that name.
How is this different from NSPM-33’s “four elements” of a research security program?
They’re related but not the same framework. NSPM-33 (see CASRAI’s guide to its four mandated elements) is a government-wide research-security mandate covering certification, cybersecurity, foreign travel, and insider-threat/training requirements at the institutional level, independent of whether export-controlled items are involved at all. The four pillars in this guide are scoped specifically to EAR/ITAR export control exposure. The two frameworks overlap in practice — the same travel-screening or training infrastructure often serves both — but they rest on different legal authorities and cover different scope.
Does every international trip require export control review?
Not every trip requires a full license determination, but every international trip involving institutional equipment, sponsored-project data, or engagement with foreign institutions should go through a destination and restricted-party screening step, because the screening itself is what determines whether anything further is needed. Skipping the screening is the actual risk, not every trip turning out to require a license.
Who owns the foreign talent recruitment program disclosure pillar if it isn’t legally export control?
Most institutions route it through the same research-compliance or research-security office that handles export control, sponsored-programs disclosure review, or both, precisely because the same international collaboration frequently touches both. The legal basis is different (NSPM-33 and funder-specific disclosure policy, not EAR/ITAR), but the operational and staffing overlap is real, which is why this guide treats it as one of the four pillars rather than a wholly separate program.
What’s the single most common preventable violation across these four pillars?
Based on the pattern institutional export control guidance consistently warns about, it’s an ordinary, undocumented release — a lab conversation, an email thread, or a packed laptop — that happens because training didn’t reach the person involved before the moment it mattered, not a deliberate attempt to evade the rules. This is precisely why training (Pillar 4) is treated as the pillar that makes the other three actually work, rather than a separate compliance checkbox.







