Last verified: August 16, 2026. This page explains the general compliance framework under the International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130) and the Export Administration Regulations (EAR, 15 CFR Parts 730-774) as they apply to university research. It is general guidance for research administrators, not a legal determination for any specific project. Jurisdiction and classification determinations belong to your institution’s Empowered Official or export control officer, who must review the actual technology, funding terms, and contract language involved.
What “ITAR and EAR compliance” means for a university
ITAR and EAR are two separate, non-overlapping U.S. export control regimes. Both restrict the transfer — physical, electronic, or verbal/visual — of certain items, software, and technical data to foreign persons and foreign destinations. For a research institution, “compliance” means being able to answer three questions correctly for every sponsored project, piece of equipment, and collaborator before access happens, not after: (1) is anything in this project subject to ITAR or EAR at all; (2) if so, does the fundamental research exclusion actually protect it; and (3) is anyone involved — a collaborator, subcontractor, visiting scholar, or equipment vendor — a restricted party.
Getting the first two questions wrong is the single largest source of university export-control exposure, because a project that a principal investigator assumes is “just basic research” can lose its exclusion the moment a sponsor inserts a publication-approval clause or a foreign-national-access restriction into the award terms — often without anyone flagging it as an export-control issue at all.
ITAR vs. EAR: which regime applies
The two regimes are administered by different federal departments, cover different categories of items, and use different tests for what counts as an “export.” A single research program can be subject to one, the other, both (for different components), or neither.
- ITAR (22 CFR Parts 120-130), administered by the State Department’s Directorate of Defense Trade Controls (DDTC) under the Arms Export Control Act (AECA), controls defense articles, defense services, and related technical data enumerated on the U.S. Munitions List (USML) — 22 CFR Part 121. If an item, software, or piece of technical data is specifically designed, developed, modified, or adapted for a military application and appears on (or is a “specially designed” component/technology for) a USML category, ITAR applies, generally without a de minimis exception and without regard to how sensitive the underlying science otherwise seems.
- EAR (15 CFR Parts 730-774), administered by the Commerce Department’s Bureau of Industry and Security (BIS) under export control law reauthorized through the Export Control Reform Act (ECRA), controls “dual-use” items — things with both commercial and potential military or proliferation applications — plus some purely commercial items, listed on the Commerce Control List (CCL), Supplement No. 1 to 15 CFR Part 774.
Our companion page, ITAR US Munitions List (USML): What It Is and How It Applies to University Research, walks through USML category structure and how to read a category entry. For the classification mechanics on the EAR side (self-classification against the CCL vs. filing a formal Commodity Classification request with BIS), see the ECCN determination process below.
Quick jurisdictional test
As a starting screen (not a substitute for an actual determination): if the item, technology, or software was designed or modified specifically for military use, or appears by name on the USML, start with ITAR. If it’s an item with civilian applications that also has military, proliferation, or dual-use significance — or if it doesn’t appear on the USML at all — start with the EAR and the CCL. Items can move between the lists (DDTC and BIS jointly administer periodic “Export Control Reform” category transfers), so a jurisdiction determination made several years ago for a recurring piece of equipment should be re-checked, not assumed to still hold.
ITAR vs. EAR at a glance
| Dimension | ITAR | EAR |
|---|---|---|
| Administering agency | Department of State, Directorate of Defense Trade Controls (DDTC) | Department of Commerce, Bureau of Industry and Security (BIS) |
| Regulatory citation | 22 CFR Parts 120-130 | 15 CFR Parts 730-774 |
| Statutory authority | Arms Export Control Act (AECA) | Export Control Reform Act (ECRA) |
| Controlled-item list | U.S. Munitions List (USML), 22 CFR Part 121 | Commerce Control List (CCL), Supp. No. 1 to 15 CFR Part 774 |
| Catch-all / no-license-required category | No direct equivalent — everything on the USML is controlled | EAR99: items subject to the EAR that don’t appear on the CCL (see below) |
| Fundamental research exclusion | Applies — 22 CFR 120.34 (“public domain”) and related provisions | Applies — 15 CFR 734.8 |
| Deemed export / release to foreign persons | Yes — disclosure of controlled technical data to a foreign person is treated as an export | Yes — 15 CFR 734.13(a)(2)/734.15, release of controlled technology to a foreign person is a “deemed export” |
| Restricted-party lists most relevant | AECA Debarred List; also screen against Entity List / Denied Persons List for dual-role transactions | Entity List, Denied Persons List, Unverified List, Military End-User List |
| Typical civil penalty exposure | Up to roughly $1.27M per violation (or twice the transaction value), inflation-adjusted | Roughly $300K+ per violation (or twice the transaction value), inflation-adjusted |
| Typical criminal exposure | Up to 20 years imprisonment, up to $1M in fines per violation | Up to 20 years imprisonment, up to $1M in fines per violation |
This table covers the dimensions most load-bearing for the compliance questions on this page. For a fuller 12-dimension breakdown (registration requirements, licensing systems, jurisdiction-request procedures), see ITAR vs. EAR: A Side-by-Side Comparison for Research Administrators. For the shared and diverging definitions in dictionary form, see ITAR and EAR, 22 CFR Part 120 (ITAR — Purpose and Definitions), and 15 CFR Part 734 (EAR Scope and Definitions).
EAR99: what it means and what it doesn’t
EAR99 is not a license or an exemption — it’s a classification. Every item, software package, and piece of technology “subject to the EAR” (i.e., within Commerce’s jurisdiction at all, generally U.S.-origin or containing controlled U.S. content) gets checked against the ten CCL categories (0 through 9) and five product groups (A through E) that make up an Export Control Classification Number (ECCN). If nothing on the CCL matches, the item falls into the residual catch-all classification: EAR99.
For most EAR99 items, no export license is required to most destinations and end users — this is why EAR99 is often treated, informally, as “the EAR’s version of unrestricted.” That shorthand is where universities get into trouble, because EAR99 status does not override the other three things that can still require a license regardless of classification:
- Restricted destinations — shipping or transmitting an EAR99 item to an embargoed or sanctioned country can still require a license.
- Restricted parties — an EAR99 item going to an Entity List, Denied Persons List, or other restricted-party entry can still require a license or be prohibited outright, regardless of classification.
- Prohibited end uses — EAR99 items destined for a nuclear, missile, chemical/biological weapons, or certain military end use in specific countries can trigger a license requirement under the EAR’s end-use/end-user controls even with no ECCN match.
In practice, this means a research group cannot conclude “our software is EAR99, so we can share it with anyone” without also screening the recipient and destination. EAR99 answers the classification question; it does not answer the restricted-party or destination question. Formal classification runs through BIS’s own published order-of-review process; ambiguous cases (particularly encryption-related software) can be submitted to BIS as a formal Commodity Classification request under 15 CFR 748.3, returned as a CCATS determination.
The fundamental research exclusion: what actually protects a university project
This is the single most consequential concept on this page, because it is both the reason most university basic research is not export-controlled in practice, and the most common way institutions accidentally lose that protection.
Under U.S. export control law (rooted in National Security Decision Directive 189, and implemented in the regulations at 15 CFR 734.8 for the EAR and in the ITAR’s “public domain” provisions at 22 CFR 120.34), information resulting from fundamental research is not subject to the EAR or ITAR at all — not licensed, not restricted, simply outside the regulatory scope, because it is intended for open, unrestricted publication. “Fundamental research” is defined narrowly: basic and applied research in science and engineering performed or conducted at an accredited U.S. institution of higher education, where the resulting information is ordinarily published and shared broadly within the research community, and where neither the university nor the researchers have accepted any restriction on publication or on participation by foreign nationals for proprietary or national-security reasons.
What the exclusion covers
- The information and technical data that result from a genuinely open research project — the findings, methods, and analysis that will be published.
- Research performed under an award with no publication-approval or -delay clause beyond a short, standard sponsor pre-publication review for patent or proprietary-information screening purposes (commonly 30-90 days, not a right to suppress).
- Basic and applied research broadly — the exclusion is not limited to “pure” basic science.
What the exclusion does NOT cover
This is where universities actually get into trouble, and it is worth stating each condition explicitly:
- Proprietary or publication-restricted work. The moment a sponsor’s contract gives the sponsor the right to review, delay beyond a routine patent-screening window, or refuse publication of results — or the university otherwise accepts a confidentiality or non-disclosure obligation on the research results themselves — the project is no longer “fundamental research” for export control purposes, even if the underlying science is identical to an unrestricted project down the hall. A single clause buried in a sponsored-research agreement, negotiated by a contracts office without export-control input, is a common way this happens without anyone noticing until later.
- Foreign-national participation restrictions. If an award or contract restricts which researchers — based on citizenship or national origin — may work on the project, the project again falls outside the exclusion, because the restriction itself signals the sponsor does not intend the results to be openly shared. (Separately, restricting participation by citizenship alone can also raise its own legal issues; this is a compliance flag on both fronts, not just export control.)
- Physical items and encrypted software, regardless of research context. The fundamental research exclusion protects information — publishable results and technical data. It does not protect the export of a controlled physical item (a piece of USML- or CCL-listed hardware shipped abroad), nor does it exempt controlled encrypted software from separate encryption-specific EAR provisions. A university can be doing entirely unrestricted, publishable fundamental research and still have an export control obligation the moment a controlled instrument, component, or encrypted tool physically leaves the country or is shipped to a non-U.S. collaborator.
- Foreign-national access to controlled equipment or software before any publication occurs. The exclusion covers the eventual published information, not necessarily every intermediate step. If a foreign national needs hands-on access to a controlled instrument, source code, or technical data set to do the work, that access can itself be a “deemed export” requiring its own analysis (see below) even while the resulting publication remains unrestricted.
- Once lost, generally not regained retroactively for that project. A project that starts fully open and later accepts a publication restriction (a common pattern when a grant is modified, or when a subaward or teaming agreement is added mid-project) should be re-evaluated at that point, not assumed to still carry its original exclusion.
Because the trigger is almost always contractual language rather than the science itself, the practical safeguard is procedural: export control review needs to see the actual award terms — not just a project abstract — before access begins, specifically checking for publication-restriction and foreign-national-access clauses. Our guide on Export Control (EAR/ITAR) and International Research Collaboration covers this pre-award screening workflow and the deemed-export licensing timeline in more operational detail.
Deemed exports: when access itself is the export
Under the EAR (15 CFR 734.13(a)(2) and 734.15) and the analogous ITAR concept, releasing export-controlled technology, technical data, or source code to a foreign person inside the United States is legally treated as an export to that person’s most recent country of citizenship or permanent residency — a “deemed export.” This applies even though nothing physically crosses a border. Common deemed-export triggers on a campus include:
- A foreign-national graduate student, postdoc, or visiting scholar being given hands-on access to a controlled instrument, restricted dataset, or controlled source code.
- Verbal or visual disclosure of controlled technical data — in a lab meeting, over email, on a shared screen during a video call, or on a whiteboard a foreign national can read.
- Granting network or system access (even read-only) to controlled software or technical files.
Whether a specific individual triggers deemed-export analysis depends on their immigration/citizenship status against the regulatory “U.S. person” definitions (which include not just citizens but also lawful permanent residents and certain protected/asylee categories) — not simply “foreign vs. domestic.” Where deemed-export exposure exists, institutions typically manage it through a Technology Control Plan (TCP) — a documented set of physical, IT, and procedural access restrictions — put in place before access begins, not after a foreign national has already started on the project.
Restricted-party screening: the Entity List and Denied Persons List
Even a fully EAR99, fundamental-research-excluded project can still be prohibited if it involves a restricted party. Screening every collaborator, subcontractor, visiting-scholar host institution, and equipment vendor against the relevant lists before engagement is a baseline compliance step, independent of item classification.
- Entity List (maintained by BIS under the EAR, 15 CFR Part 744 Supplement No. 4) — names foreign parties (companies, universities, research institutes, individuals) determined to present an unacceptable risk of contributing to activities contrary to U.S. national security or foreign policy interests. A listing typically imposes a license requirement — often with a presumption of denial — for exports, reexports, or transfers to that party, and the specific license requirement and scope can vary entry by entry, so the actual Federal Register entry for a listed party has to be checked, not just the fact of listing. A 2025 BIS “Affiliates Rule” also automatically extends Entity List and Military End-User List restrictions to any unlisted entity that listed parties own, in aggregate, 50% or more of.
- Denied Persons List (maintained by BIS under the EAR) — individuals and entities that have been denied export privileges entirely, typically following an enforcement action; a Denied Persons List entry generally bars nearly all participation in an EAR-subject export transaction with that party, not just a license-required subset.
- Other lists that regularly matter for the same screening pass, even though they sit under different authorities: the Unverified List and Military End-User List (BIS/EAR), the AECA Debarred List (State/ITAR), and OFAC’s Specially Designated Nationals (SDN) list (Treasury — a distinct, broader sanctions authority, not an EAR/ITAR list itself). The Commerce Department’s Consolidated Screening List (CSL), published at trade.gov, lets an institution check a name against all of the Commerce, State, and Treasury lists in a single search — a practical starting point, though any match still has to be traced back to its source list and regulation to determine the actual consequence.
Screening should happen at each of several points, not just once at award setup: before adding a foreign collaborator or subrecipient, before onboarding a visiting scholar or student, before engaging an equipment vendor for controlled hardware, and periodically for ongoing relationships, since listings change. For the officer role responsible for these determinations institutionally, see Empowered Official: The ITAR-Required Export-Control Compliance Role.
Travel with controlled data and laptops
International travel is a frequently overlooked deemed-export and physical-export trigger. Two distinct risks apply:
- Carrying a device. A laptop, phone, or storage device that contains export-controlled technical data is itself subject to export control the moment it’s carried out of the United States — this is a physical export of the technology on the device, separate from any deemed-export analysis. EAR and ITAR each provide narrow license exceptions/exemptions for a traveler’s own device under specific conditions (commonly summarized in institutional policy as a “clean laptop” or temporary-export approach), but these exceptions have real conditions attached (encryption, control over the device, destination) and don’t apply automatically — check with export control before international travel with any device that may hold controlled technical data, not after booking.
- Destination restrictions. Certain destinations carry additional restrictions (comprehensively sanctioned/embargoed countries in particular) where even routine, uncontrolled activity can raise separate concerns, and where the “clean laptop” approach is the standard recommendation regardless of whether the traveler believes their device contains anything controlled.
The safest practical baseline most institutions adopt: travel with a loaner or wiped device to higher-risk destinations, and route any trip involving known controlled technical data through export control review before departure, not as a post-trip cleanup exercise.
Penalty exposure
Both regimes carry meaningful civil and criminal exposure, and penalties attach to the institution as well as to individual researchers or staff who commit or facilitate a violation.
- ITAR/AECA: civil penalties have run into seven figures per violation (or twice the value of the underlying transaction, whichever is greater) as of recent inflation adjustments; criminal violations can carry fines up to $1 million per violation and imprisonment up to 20 years. Administrative or statutory debarment — loss of export privileges entirely — is also available and, for criminal convictions, can be automatic.
- EAR/ECRA: administrative monetary penalties (inflation-adjusted periodically by BIS) and criminal penalties that can likewise reach up to 20 years imprisonment and up to $1 million in fines per violation for willful violations, plus denial of export privileges.
Beyond the statutory maximums, the more common institutional exposure is indirect: a federal sponsor learning of an unaddressed export-control gap can affect an institution’s broader standing on federal awards, and named individuals can face personal criminal liability distinct from any institutional penalty. Employees who identify a potential violation have specific legal protections for reporting it — see Whistleblower Protections for Reporting Export Control (EAR/ITAR) Violations in Research. Exact current-year penalty figures are adjusted periodically for inflation; confirm the current cap directly against DDTC/BIS guidance before citing a specific dollar figure in an institutional policy document.
Building a compliance framework: where to start
- Pre-award screening. Route every new award, contract, MOU, or material transfer agreement through export control review before acceptance, specifically checking for publication-restriction and foreign-national-access clauses that would forfeit the fundamental research exclusion.
- Classification. For any physical item, software, or technical data involved, determine jurisdiction (ITAR/USML vs. EAR/CCL) and, on the EAR side, classification (specific ECCN vs. EAR99).
- Restricted-party screening. Screen every named collaborator, subrecipient, visiting scholar, and vendor against the Entity List, Denied Persons List, and the broader Consolidated Screening List before engagement, and re-screen periodically.
- Technology Control Plans. Put a TCP in place before granting any foreign national access to controlled equipment, software, or technical data — not retroactively.
- Travel review. Route international travel involving controlled technical data or higher-risk destinations through export control before departure.
- Training and escalation path. Ensure PIs and lab staff know what to flag and to whom — most violations trace back to a compliance-relevant fact (a contract clause, a new foreign national on the project, a device leaving the country) that never reached the export control office at all.
Frequently asked questions
What is ITAR compliance?
ITAR compliance means identifying whether a project, item, or piece of technical data is controlled under the International Traffic in Arms Regulations (22 CFR Parts 120-130) because it appears on the U.S. Munitions List, and then meeting the applicable registration, licensing, access-control, and recordkeeping requirements for any USML-controlled item, service, or data — including screening participants against restricted-party lists and, where foreign nationals need access, putting a Technology Control Plan in place.
What are the Export Administration Regulations?
The Export Administration Regulations (EAR), 15 CFR Parts 730-774, are the U.S. Commerce Department/BIS regulations controlling the export, reexport, and in-country transfer of “dual-use” items — things with both civilian and potential military, security, or proliferation significance — along with some purely commercial items, as listed on the Commerce Control List. They are the Commerce-administered counterpart to the State Department’s ITAR.
What is EAR99?
EAR99 is the classification for an item, software package, or technology that is subject to the EAR but does not appear on the Commerce Control List. Most EAR99 items can be exported to most destinations and end users without a license, but EAR99 status does not override separate restrictions tied to embargoed destinations, restricted parties (such as Entity List or Denied Persons List entries), or prohibited end uses.
What is the Entity List?
The Entity List is a BIS-maintained list of foreign parties determined to present an unacceptable risk of contributing to activities contrary to U.S. national security or foreign policy interests. Exports, reexports, or transfers to a listed party generally require a license, often with a presumption of denial, and the specific requirements can vary by the individual party’s Federal Register entry.
What is the Denied Persons List?
The Denied Persons List is a BIS-maintained list of individuals and entities whose export privileges have been formally denied, typically following an enforcement action. A listing generally bars nearly all participation by that party in an EAR-subject export transaction.
Does the fundamental research exclusion mean my project can never be export-controlled?
No. The exclusion protects information intended for open publication under specific conditions — no publication-restriction clause and no foreign-national-access restriction in the award terms. It does not exempt physical controlled items, encrypted controlled software, or foreign-national hands-on access to controlled equipment from separate analysis, and it can be forfeited mid-project if the award terms change.
Related CASRAI guidance
- ITAR US Munitions List (USML): What It Is and How It Applies to University Research
- NIST SP 800-171 and CUI in University Research — the separate contractual safeguarding obligation that often applies alongside export-controlled awards, and how it differs from the fundamental research exclusion described above
- ITAR vs. EAR: A Side-by-Side Comparison for Research Administrators
- Export Control (EAR/ITAR) and International Research Collaboration
- Empowered Official: The ITAR-Required Export-Control Compliance Role
- Whistleblower Protections for Reporting Export Control (EAR/ITAR) Violations in Research
- Technology Control Plan (TCP)
- Deemed Export
- Fundamental Research Exemption
- ITAR and EAR
This page is general compliance guidance, not legal advice, and does not substitute for an institution-specific jurisdiction, classification, or restricted-party determination made by your Empowered Official or export control office.







