Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

ITAR and EAR Compliance for University Research

A compliance-framework overview of ITAR (22 CFR 120-130) and EAR (15 CFR 730-774) for research administrators: jurisdictional split, EAR99, the fundamental research exclusion, deemed exports, Entity List/Denied Persons List screening, travel risk, and penalties.

Ask about ITAR and EAR Compliance for University Research

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Last verified: August 16, 2026. This page explains the general compliance framework under the International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130) and the Export Administration Regulations (EAR, 15 CFR Parts 730-774) as they apply to university research. It is general guidance for research administrators, not a legal determination for any specific project. Jurisdiction and classification determinations belong to your institution’s Empowered Official or export control officer, who must review the actual technology, funding terms, and contract language involved.

What “ITAR and EAR compliance” means for a university

ITAR and EAR are two separate, non-overlapping U.S. export control regimes. Both restrict the transfer — physical, electronic, or verbal/visual — of certain items, software, and technical data to foreign persons and foreign destinations. For a research institution, “compliance” means being able to answer three questions correctly for every sponsored project, piece of equipment, and collaborator before access happens, not after: (1) is anything in this project subject to ITAR or EAR at all; (2) if so, does the fundamental research exclusion actually protect it; and (3) is anyone involved — a collaborator, subcontractor, visiting scholar, or equipment vendor — a restricted party.

Getting the first two questions wrong is the single largest source of university export-control exposure, because a project that a principal investigator assumes is “just basic research” can lose its exclusion the moment a sponsor inserts a publication-approval clause or a foreign-national-access restriction into the award terms — often without anyone flagging it as an export-control issue at all.

ITAR vs. EAR: which regime applies

The two regimes are administered by different federal departments, cover different categories of items, and use different tests for what counts as an “export.” A single research program can be subject to one, the other, both (for different components), or neither.

  • ITAR (22 CFR Parts 120-130), administered by the State Department’s Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA), controls defense articles, defense services, and related technical data enumerated on the U.S. Munitions List (USML) — 22 CFR Part 121. If an item, software, or piece of technical data is specifically designed, developed, modified, or adapted for a military application and appears on (or is a “specially designed” component/technology for) a USML category, ITAR applies, generally without a de minimis exception and without regard to how sensitive the underlying science otherwise seems.
  • EAR (15 CFR Parts 730-774), administered by the Commerce Department’s Bureau of Industry and Security (BIS) under export control law reauthorized through the Export Control Reform Act (ECRA), controls “dual-use” items — things with both commercial and potential military or proliferation applications — plus some purely commercial items, listed on the Commerce Control List (CCL), Supplement No. 1 to 15 CFR Part 774.

Our companion page, ITAR US Munitions List (USML): What It Is and How It Applies to University Research, walks through USML category structure and how to read a category entry. For the classification mechanics on the EAR side (self-classification against the CCL vs. filing a formal Commodity Classification request with BIS), see the ECCN determination process below.

Quick jurisdictional test

As a starting screen (not a substitute for an actual determination): if the item, technology, or software was designed or modified specifically for military use, or appears by name on the USML, start with ITAR. If it’s an item with civilian applications that also has military, proliferation, or dual-use significance — or if it doesn’t appear on the USML at all — start with the EAR and the CCL. Items can move between the lists (DDTC and BIS jointly administer periodic “Export Control Reform” category transfers), so a jurisdiction determination made several years ago for a recurring piece of equipment should be re-checked, not assumed to still hold.

ITAR vs. EAR at a glance

Dimension ITAR EAR
Administering agency Department of State, Directorate of Defense Trade Controls (DDTC) Department of Commerce, Bureau of Industry and Security (BIS)
Regulatory citation 22 CFR Parts 120-130 15 CFR Parts 730-774
Statutory authority Arms Export Control Act (AECA) Export Control Reform Act (ECRA)
Controlled-item list U.S. Munitions List (USML), 22 CFR Part 121 Commerce Control List (CCL), Supp. No. 1 to 15 CFR Part 774
Catch-all / no-license-required category No direct equivalent — everything on the USML is controlled EAR99: items subject to the EAR that don’t appear on the CCL (see below)
Fundamental research exclusion Applies — 22 CFR 120.34 (“public domain”) and related provisions Applies — 15 CFR 734.8
Deemed export / release to foreign persons Yes — disclosure of controlled technical data to a foreign person is treated as an export Yes — 15 CFR 734.13(a)(2)/734.15, release of controlled technology to a foreign person is a “deemed export”
Restricted-party lists most relevant AECA Debarred List; also screen against Entity List / Denied Persons List for dual-role transactions Entity List, Denied Persons List, Unverified List, Military End-User List
Typical civil penalty exposure Up to roughly $1.27M per violation (or twice the transaction value), inflation-adjusted Roughly $300K+ per violation (or twice the transaction value), inflation-adjusted
Typical criminal exposure Up to 20 years imprisonment, up to $1M in fines per violation Up to 20 years imprisonment, up to $1M in fines per violation

This table covers the dimensions most load-bearing for the compliance questions on this page. For a fuller 12-dimension breakdown (registration requirements, licensing systems, jurisdiction-request procedures), see ITAR vs. EAR: A Side-by-Side Comparison for Research Administrators. For the shared and diverging definitions in dictionary form, see ITAR and EAR, 22 CFR Part 120 (ITAR — Purpose and Definitions), and 15 CFR Part 734 (EAR Scope and Definitions).

EAR99: what it means and what it doesn’t

EAR99 is not a license or an exemption — it’s a classification. Every item, software package, and piece of technology “subject to the EAR” (i.e., within Commerce’s jurisdiction at all, generally U.S.-origin or containing controlled U.S. content) gets checked against the ten CCL categories (0 through 9) and five product groups (A through E) that make up an Export Control Classification Number (ECCN). If nothing on the CCL matches, the item falls into the residual catch-all classification: EAR99.

For most EAR99 items, no export license is required to most destinations and end users — this is why EAR99 is often treated, informally, as “the EAR’s version of unrestricted.” That shorthand is where universities get into trouble, because EAR99 status does not override the other three things that can still require a license regardless of classification:

  • Restricted destinations — shipping or transmitting an EAR99 item to an embargoed or sanctioned country can still require a license.
  • Restricted parties — an EAR99 item going to an Entity List, Denied Persons List, or other restricted-party entry can still require a license or be prohibited outright, regardless of classification.
  • Prohibited end uses — EAR99 items destined for a nuclear, missile, chemical/biological weapons, or certain military end use in specific countries can trigger a license requirement under the EAR’s end-use/end-user controls even with no ECCN match.

In practice, this means a research group cannot conclude “our software is EAR99, so we can share it with anyone” without also screening the recipient and destination. EAR99 answers the classification question; it does not answer the restricted-party or destination question. Formal classification runs through BIS’s own published order-of-review process; ambiguous cases (particularly encryption-related software) can be submitted to BIS as a formal Commodity Classification request under 15 CFR 748.3, returned as a CCATS determination.

The fundamental research exclusion: what actually protects a university project

This is the single most consequential concept on this page, because it is both the reason most university basic research is not export-controlled in practice, and the most common way institutions accidentally lose that protection.

Under U.S. export control law (rooted in National Security Decision Directive 189, and implemented in the regulations at 15 CFR 734.8 for the EAR and in the ITAR’s “public domain” provisions at 22 CFR 120.34), information resulting from fundamental research is not subject to the EAR or ITAR at all — not licensed, not restricted, simply outside the regulatory scope, because it is intended for open, unrestricted publication. “Fundamental research” is defined narrowly: basic and applied research in science and engineering performed or conducted at an accredited U.S. institution of higher education, where the resulting information is ordinarily published and shared broadly within the research community, and where neither the university nor the researchers have accepted any restriction on publication or on participation by foreign nationals for proprietary or national-security reasons.

What the exclusion covers

  • The information and technical data that result from a genuinely open research project — the findings, methods, and analysis that will be published.
  • Research performed under an award with no publication-approval or -delay clause beyond a short, standard sponsor pre-publication review for patent or proprietary-information screening purposes (commonly 30-90 days, not a right to suppress).
  • Basic and applied research broadly — the exclusion is not limited to “pure” basic science.

What the exclusion does NOT cover

This is where universities actually get into trouble, and it is worth stating each condition explicitly:

  • Proprietary or publication-restricted work. The moment a sponsor’s contract gives the sponsor the right to review, delay beyond a routine patent-screening window, or refuse publication of results — or the university otherwise accepts a confidentiality or non-disclosure obligation on the research results themselves — the project is no longer “fundamental research” for export control purposes, even if the underlying science is identical to an unrestricted project down the hall. A single clause buried in a sponsored-research agreement, negotiated by a contracts office without export-control input, is a common way this happens without anyone noticing until later.
  • Foreign-national participation restrictions. If an award or contract restricts which researchers — based on citizenship or national origin — may work on the project, the project again falls outside the exclusion, because the restriction itself signals the sponsor does not intend the results to be openly shared. (Separately, restricting participation by citizenship alone can also raise its own legal issues; this is a compliance flag on both fronts, not just export control.)
  • Physical items and encrypted software, regardless of research context. The fundamental research exclusion protects information — publishable results and technical data. It does not protect the export of a controlled physical item (a piece of USML- or CCL-listed hardware shipped abroad), nor does it exempt controlled encrypted software from separate encryption-specific EAR provisions. A university can be doing entirely unrestricted, publishable fundamental research and still have an export control obligation the moment a controlled instrument, component, or encrypted tool physically leaves the country or is shipped to a non-U.S. collaborator.
  • Foreign-national access to controlled equipment or software before any publication occurs. The exclusion covers the eventual published information, not necessarily every intermediate step. If a foreign national needs hands-on access to a controlled instrument, source code, or technical data set to do the work, that access can itself be a “deemed export” requiring its own analysis (see below) even while the resulting publication remains unrestricted.
  • Once lost, generally not regained retroactively for that project. A project that starts fully open and later accepts a publication restriction (a common pattern when a grant is modified, or when a subaward or teaming agreement is added mid-project) should be re-evaluated at that point, not assumed to still carry its original exclusion.

Because the trigger is almost always contractual language rather than the science itself, the practical safeguard is procedural: export control review needs to see the actual award terms — not just a project abstract — before access begins, specifically checking for publication-restriction and foreign-national-access clauses. Our guide on Export Control (EAR/ITAR) and International Research Collaboration covers this pre-award screening workflow and the deemed-export licensing timeline in more operational detail.

Deemed exports: when access itself is the export

Under the EAR (15 CFR 734.13(a)(2) and 734.15) and the analogous ITAR concept, releasing export-controlled technology, technical data, or source code to a foreign person inside the United States is legally treated as an export to that person’s most recent country of citizenship or permanent residency — a “deemed export.” This applies even though nothing physically crosses a border. Common deemed-export triggers on a campus include:

  • A foreign-national graduate student, postdoc, or visiting scholar being given hands-on access to a controlled instrument, restricted dataset, or controlled source code.
  • Verbal or visual disclosure of controlled technical data — in a lab meeting, over email, on a shared screen during a video call, or on a whiteboard a foreign national can read.
  • Granting network or system access (even read-only) to controlled software or technical files.

Whether a specific individual triggers deemed-export analysis depends on their immigration/citizenship status against the regulatory “U.S. person” definitions (which include not just citizens but also lawful permanent residents and certain protected/asylee categories) — not simply “foreign vs. domestic.” Where deemed-export exposure exists, institutions typically manage it through a Technology Control Plan (TCP) — a documented set of physical, IT, and procedural access restrictions — put in place before access begins, not after a foreign national has already started on the project.

Restricted-party screening: the Entity List and Denied Persons List

Even a fully EAR99, fundamental-research-excluded project can still be prohibited if it involves a restricted party. Screening every collaborator, subcontractor, visiting-scholar host institution, and equipment vendor against the relevant lists before engagement is a baseline compliance step, independent of item classification.

  • Entity List (maintained by BIS under the EAR, 15 CFR Part 744 Supplement No. 4) — names foreign parties (companies, universities, research institutes, individuals) determined to present an unacceptable risk of contributing to activities contrary to U.S. national security or foreign policy interests. A listing typically imposes a license requirement — often with a presumption of denial — for exports, reexports, or transfers to that party, and the specific license requirement and scope can vary entry by entry, so the actual Federal Register entry for a listed party has to be checked, not just the fact of listing. A 2025 BIS “Affiliates Rule” also automatically extends Entity List and Military End-User List restrictions to any unlisted entity that listed parties own, in aggregate, 50% or more of.
  • Denied Persons List (maintained by BIS under the EAR) — individuals and entities that have been denied export privileges entirely, typically following an enforcement action; a Denied Persons List entry generally bars nearly all participation in an EAR-subject export transaction with that party, not just a license-required subset.
  • Other lists that regularly matter for the same screening pass, even though they sit under different authorities: the Unverified List and Military End-User List (BIS/EAR), the AECA Debarred List (State/ITAR), and OFAC’s Specially Designated Nationals (SDN) list (Treasury — a distinct, broader sanctions authority, not an EAR/ITAR list itself). The Commerce Department’s Consolidated Screening List (CSL), published at trade.gov, lets an institution check a name against all of the Commerce, State, and Treasury lists in a single search — a practical starting point, though any match still has to be traced back to its source list and regulation to determine the actual consequence.

Screening should happen at each of several points, not just once at award setup: before adding a foreign collaborator or subrecipient, before onboarding a visiting scholar or student, before engaging an equipment vendor for controlled hardware, and periodically for ongoing relationships, since listings change. For the officer role responsible for these determinations institutionally, see Empowered Official: The ITAR-Required Export-Control Compliance Role.

Travel with controlled data and laptops

International travel is a frequently overlooked deemed-export and physical-export trigger. Two distinct risks apply:

  • Carrying a device. A laptop, phone, or storage device that contains export-controlled technical data is itself subject to export control the moment it’s carried out of the United States — this is a physical export of the technology on the device, separate from any deemed-export analysis. EAR and ITAR each provide narrow license exceptions/exemptions for a traveler’s own device under specific conditions (commonly summarized in institutional policy as a “clean laptop” or temporary-export approach), but these exceptions have real conditions attached (encryption, control over the device, destination) and don’t apply automatically — check with export control before international travel with any device that may hold controlled technical data, not after booking.
  • Destination restrictions. Certain destinations carry additional restrictions (comprehensively sanctioned/embargoed countries in particular) where even routine, uncontrolled activity can raise separate concerns, and where the “clean laptop” approach is the standard recommendation regardless of whether the traveler believes their device contains anything controlled.

The safest practical baseline most institutions adopt: travel with a loaner or wiped device to higher-risk destinations, and route any trip involving known controlled technical data through export control review before departure, not as a post-trip cleanup exercise.

Penalty exposure

Both regimes carry meaningful civil and criminal exposure, and penalties attach to the institution as well as to individual researchers or staff who commit or facilitate a violation.

  • ITAR/AECA: civil penalties have run into seven figures per violation (or twice the value of the underlying transaction, whichever is greater) as of recent inflation adjustments; criminal violations can carry fines up to $1 million per violation and imprisonment up to 20 years. Administrative or statutory debarment — loss of export privileges entirely — is also available and, for criminal convictions, can be automatic.
  • EAR/ECRA: administrative monetary penalties (inflation-adjusted periodically by BIS) and criminal penalties that can likewise reach up to 20 years imprisonment and up to $1 million in fines per violation for willful violations, plus denial of export privileges.

Beyond the statutory maximums, the more common institutional exposure is indirect: a federal sponsor learning of an unaddressed export-control gap can affect an institution’s broader standing on federal awards, and named individuals can face personal criminal liability distinct from any institutional penalty. Employees who identify a potential violation have specific legal protections for reporting it — see Whistleblower Protections for Reporting Export Control (EAR/ITAR) Violations in Research. Exact current-year penalty figures are adjusted periodically for inflation; confirm the current cap directly against DDTC/BIS guidance before citing a specific dollar figure in an institutional policy document.

Building a compliance framework: where to start

  1. Pre-award screening. Route every new award, contract, MOU, or material transfer agreement through export control review before acceptance, specifically checking for publication-restriction and foreign-national-access clauses that would forfeit the fundamental research exclusion.
  2. Classification. For any physical item, software, or technical data involved, determine jurisdiction (ITAR/USML vs. EAR/CCL) and, on the EAR side, classification (specific ECCN vs. EAR99).
  3. Restricted-party screening. Screen every named collaborator, subrecipient, visiting scholar, and vendor against the Entity List, Denied Persons List, and the broader Consolidated Screening List before engagement, and re-screen periodically.
  4. Technology Control Plans. Put a TCP in place before granting any foreign national access to controlled equipment, software, or technical data — not retroactively.
  5. Travel review. Route international travel involving controlled technical data or higher-risk destinations through export control before departure.
  6. Training and escalation path. Ensure PIs and lab staff know what to flag and to whom — most violations trace back to a compliance-relevant fact (a contract clause, a new foreign national on the project, a device leaving the country) that never reached the export control office at all.

Frequently asked questions

What is ITAR compliance?

ITAR compliance means identifying whether a project, item, or piece of technical data is controlled under the International Traffic in Arms Regulations (22 CFR Parts 120-130) because it appears on the U.S. Munitions List, and then meeting the applicable registration, licensing, access-control, and recordkeeping requirements for any USML-controlled item, service, or data — including screening participants against restricted-party lists and, where foreign nationals need access, putting a Technology Control Plan in place.

What are the Export Administration Regulations?

The Export Administration Regulations (EAR), 15 CFR Parts 730-774, are the U.S. Commerce Department/BIS regulations controlling the export, reexport, and in-country transfer of “dual-use” items — things with both civilian and potential military, security, or proliferation significance — along with some purely commercial items, as listed on the Commerce Control List. They are the Commerce-administered counterpart to the State Department’s ITAR.

What is EAR99?

EAR99 is the classification for an item, software package, or technology that is subject to the EAR but does not appear on the Commerce Control List. Most EAR99 items can be exported to most destinations and end users without a license, but EAR99 status does not override separate restrictions tied to embargoed destinations, restricted parties (such as Entity List or Denied Persons List entries), or prohibited end uses.

What is the Entity List?

The Entity List is a BIS-maintained list of foreign parties determined to present an unacceptable risk of contributing to activities contrary to U.S. national security or foreign policy interests. Exports, reexports, or transfers to a listed party generally require a license, often with a presumption of denial, and the specific requirements can vary by the individual party’s Federal Register entry.

What is the Denied Persons List?

The Denied Persons List is a BIS-maintained list of individuals and entities whose export privileges have been formally denied, typically following an enforcement action. A listing generally bars nearly all participation by that party in an EAR-subject export transaction.

Does the fundamental research exclusion mean my project can never be export-controlled?

No. The exclusion protects information intended for open publication under specific conditions — no publication-restriction clause and no foreign-national-access restriction in the award terms. It does not exempt physical controlled items, encrypted controlled software, or foreign-national hands-on access to controlled equipment from separate analysis, and it can be forfeited mid-project if the award terms change.

Related CASRAI guidance

This page is general compliance guidance, not legal advice, and does not substitute for an institution-specific jurisdiction, classification, or restricted-party determination made by your Empowered Official or export control office.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →