Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

ITAR-Compliant Cloud Storage: Requirements for Export-Controlled Technical Data

ITAR-compliant cloud storage is a property of encryption and access control, not a vendor label. This guide covers the 22 CFR 120.54 encryption carve-out, deemed-export access rules, and what to evaluate before storing controlled technical data in the cloud.

Ask about ITAR-Compliant Cloud Storage: Requirements for Export-Controlled Technical Data

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

ITAR-compliant cloud storage is cloud storage configured and operated so that unclassified technical data controlled under the International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130, administered by the US Department of State’s Directorate of Defense Trade Controls) can be stored, transmitted, and accessed without triggering an unauthorized “export” — including the “deemed export” that happens the moment a foreign person, anywhere, gains access to the data. No cloud provider is automatically ITAR-compliant out of the box; compliance is a property of how a specific environment is configured, encrypted, and access-controlled, and the exporting institution — not the vendor — carries the legal responsibility for getting it right.

For research labs and university export-control offices, this question usually comes up when a project generates or receives ITAR-controlled technical data — defense-article design data, test data, engineering specifications — and the lab wants to use commercial cloud storage instead of (or alongside) an air-gapped local system. This guide covers what the regulation actually requires, the specific encryption carve-out that makes commercial cloud storage possible at all under ITAR, and what to evaluate before choosing a storage environment.

What “ITAR-Compliant” Means for Cloud Storage

ITAR treats the release of controlled technical data to a foreign person as a “deemed export,” legally equivalent to physically shipping the item to that person’s home country — even if the data never leaves US soil and the foreign person is a lab’s own employee or a cloud vendor’s system administrator. That single rule is why ordinary commercial cloud storage is not automatically usable for ITAR-controlled technical data: most major cloud providers operate globally distributed infrastructure and support staff, and routine cloud storage gives the provider technical means to access customer data.

Historically, this pushed export-controlled research toward on-premises servers or storage physically walled off from cloud infrastructure entirely. That changed in 2016, when the Department of State added a specific carve-out for cloud computing.

The Encryption Carve-Out: 22 CFR 120.54

DDTC’s 2016 revision to ITAR’s definitions added 22 CFR 120.54, which lists activities that are not considered exports, reexports, retransfers, or temporary imports. Among them: sending, taking, or storing unclassified technical data via cloud computing, provided the data is secured end-to-end using encryption that meets specific conditions — in practice, FIPS 140-2 (or later NIST-validated successor) compliant cryptographic modules, keys that are never made accessible to the cloud provider or to any foreign person, and no intentional storage or routing through a country listed in ITAR §126.1 (the list of countries subject to a US arms embargo) or Russia.

The practical effect: if a lab genuinely end-to-end encrypts ITAR-controlled technical data before it reaches the cloud provider’s infrastructure, and retains sole control of the decryption keys, the cloud provider’s own foreign staff or globally distributed data centers do not create a deemed-export problem — because the provider never has the technical means to view the plaintext data. This is what “ITAR-compliant cloud storage” actually means in regulatory terms: it is an encryption-and-key-control property, not a marketing label a vendor applies to a product tier.

Because export control regulations are amended periodically, a lab’s export control office (not the vendor’s sales material) should be the source that confirms current requirements against the live text at eCFR Title 22, Part 120 before finalizing a storage decision.

Key Technical Requirements to Verify Before Adopting a Cloud Environment

  • End-to-end encryption with validated modules. Encryption has to happen before data reaches the provider’s systems and use cryptographic modules meeting the current FIPS 140 standard — not just “encryption at rest” as a generic cloud-provider feature, which typically leaves the provider holding the keys.
  • Institutional key custody. The lab or its institution — not the cloud vendor — controls the decryption keys. If the vendor (or a foreign-national vendor employee) can decrypt the data on request, the encryption carve-out doesn’t apply.
  • Data residency and routing. Data must not be intentionally stored in, or routed through, a §126.1 arms-embargoed country or Russia. Most institutions handle this by contractually restricting storage regions to US data centers.
  • Access provisioning by citizenship, not just by role. IT and system-administrator access to the encrypted environment — not just researcher access to the data itself — has to be screened for foreign-person status, since deemed exports apply to anyone who could access unencrypted technical data, including infrastructure staff.
  • A documented Technology Control Plan. Most institutional export control offices require a Technology Control Plan (TCP) naming the specific controlled technology, every authorized (and screened) individual, and the physical/IT safeguards in place — the cloud storage configuration is one component of that plan, not a substitute for it.

The Deemed-Export Problem: Who Can Have Access

The encryption carve-out solves the infrastructure problem — it does not solve the personnel problem. Every person who could plausibly access the decrypted data still has to be a US citizen, lawful permanent resident, or otherwise not a “foreign person” under 22 CFR 120.63, unless the lab has obtained a specific export license or applicable exemption for a named foreign national. This includes:

  • Graduate students, postdocs, and visiting researchers on the project, regardless of how long they’ve been at the institution.
  • IT staff who administer the storage environment, if their role gives them any technical path to the plaintext data.
  • Collaborators at partner institutions, domestic or foreign, who are granted sharing access.

A deemed export occurs the instant an unauthorized foreign person gains access — regardless of intent, and regardless of whether any data actually left the country. Cloud storage access controls (role-based permissions, single sign-on group membership, shared drives) need to be built around citizenship screening from the start, not retrofitted after a foreign national is accidentally added to a shared folder.

Choosing a Cloud Environment: What to Evaluate

Several major cloud providers offer government- or defense-oriented environments (commonly marketed as sovereign, government, or “GovCloud”-style regions) built around US-only data centers, US-person-only support staff, and government compliance baselines such as a FedRAMP Moderate or High authorization or a DoD Impact Level (IL) certification. These are useful signals of a provider’s general seriousness about regulated workloads, but none of them is, by itself, equivalent to ITAR compliance:

  • FedRAMP authorization addresses federal information security controls generally; it doesn’t specifically evaluate ITAR’s deemed-export/foreign-person-access requirements.
  • A government-region product tier narrows the pool of infrastructure and staff, but the institution still has to configure end-to-end encryption and key custody itself — a government cloud region with provider-managed encryption keys does not automatically satisfy 120.54.
  • Vendor “ITAR-ready” marketing language describes a platform capable of supporting a compliant configuration, not a certification that the institution’s specific setup is compliant. There is no government agency that issues an “ITAR-compliant cloud” seal to a product.

In practice, most institutions evaluating cloud storage for export-controlled technical data run the decision through the export control office and IT security jointly, documenting the specific encryption implementation, key-management approach, and access-control model in the project’s Technology Control Plan — rather than relying on a vendor’s compliance claims alone.

Where This Fits in a Lab’s Broader Compliance Picture

ITAR-controlled technical data is one of several categories of sensitive research data a lab may need to handle, and the requirements aren’t interchangeable. Controlled Unclassified Information (CUI) follows a separate federal framework (NIST SP 800-171) with its own safeguarding rules that overlap with, but are not identical to, ITAR’s; see CASRAI’s comparison of CUI Basic vs. CUI Specified and the guide on who is responsible for CUI compliance at a university. Export-controlled technical data more broadly — including EAR-controlled items, which follow a parallel but distinct regime administered by the Department of Commerce — is covered in CASRAI’s ITAR vs. EAR comparison and the export-controlled research dictionary entry. Most institutions assign a designated Empowered Official to make ITAR licensing determinations and sign off on technology control plans — that person, not the lab or IT alone, should confirm any cloud storage arrangement before controlled data goes into it.

Frequently Asked Questions

Is Amazon S3, Google Drive, or Dropbox ITAR-compliant?

Not by default. Consumer and standard commercial tiers of these services are not configured for ITAR’s encryption and access-control requirements and generally should not be used for ITAR-controlled technical data without a specifically configured, end-to-end-encrypted, access-restricted deployment reviewed by the institution’s export control office.

Does encrypting the data mean a lab doesn’t need an export license?

Only for the storage/transmission activity itself, and only if the encryption meets 22 CFR 120.54’s specific conditions. It does not authorize giving a foreign person access to the decrypted data, sharing the data with a foreign collaborator, or any other activity that would otherwise require a license or exemption — the carve-out is narrow and specific to the storage/transmission act.

Who decides whether a lab’s cloud storage setup actually satisfies ITAR?

The institution’s Empowered Official or export control office makes that determination, typically as part of reviewing and approving the project’s Technology Control Plan — not the lab, and not the cloud vendor’s compliance documentation alone.

Does this apply to data that hasn’t been formally classified as ITAR-controlled yet?

If there’s genuine uncertainty about whether specific technical data is ITAR-controlled (for example, whether it falls under a US Munitions List category), that determination should go to the export control office before a storage decision is made, not after. The fundamental research exclusion under NSDD-189 keeps most ordinary university research outside ITAR jurisdiction entirely, but funded defense-related design or test data frequently does not qualify for that exclusion.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →