Any employer whose people handle defense articles, defense services, or technical data on the U.S. Munitions List must provide ITAR awareness training as part of a functioning compliance program under the International Traffic in Arms Regulations (22 CFR 120–130). The Directorate of Defense Trade Controls (DDTC) does not set a single required course, but it expects role-tiered training — general awareness for every employee, and deeper training for engineers, program managers, shipping staff, and executives who touch controlled technology.
For an aerospace, defense, or dual-use technology employer, the highest-risk moment is often internal: sharing controlled technical data with a foreign national colleague inside your own building can count as an export.
What Does ITAR Awareness Training Actually Require?
ITAR is administered by the State Department’s DDTC and governs the export of defense articles and services on the USML. There is no numeric “train every 12 months” rule in the regulation, but DDTC’s compliance-program expectations make employee training a standing element: registrants must maintain a program that prevents unauthorized exports, controls access to technical data, and documents that employees understand the rules. In practice, that means every worker with any exposure gets baseline awareness training, and the frequency is set by company policy — most defense contractors refresh annually.
Effective training is role-tiered. All employees learn what ITAR is, why it matters, and how to spot a controlled item; export and technical staff learn USML classification, licensing, and recordkeeping; and senior management learns how their decisions bind the company. Because ITAR risk overlaps with insider risk and data handling, employers commonly pair it with security-awareness content such as Minimizing Insider Threats and general cybersecurity awareness. Aerospace and defense contractors juggling this with cybersecurity certification can see the fuller picture in our guide to aerospace and defense contractor training documentation.
What Is a Deemed Export, and Why Does It Trip Up Employees?
This is the concept that catches well-meaning teams. Under 22 CFR 120.17, releasing ITAR-controlled technical data to a foreign person located inside the United States is a “deemed export” — treated as an export to that person’s country of nationality, even though nothing physically leaves U.S. soil. An engineer who emails a controlled drawing to a green-card-pending colleague, or verbally walks a foreign national through a controlled process, may have made an unauthorized export.
That is why awareness training has to go beyond shipping. A software engineer who never touches a loading dock can still commit a violation from a conference room. Training should teach employees to recognize technical data, to check a person’s status before sharing, and to route questions to the Empowered Official rather than guessing. Because so much controlled data now moves over email and chat, layering in social-engineering awareness and advanced data-protection training reinforces the habit of controlling access. Defense contractors sorting their cybersecurity obligations alongside ITAR often start with our CMMC Level 1 vs Level 2 decision guide.
Who Needs ITAR Training at a Defense or Technology Employer?
Far more people than most companies assume. Any employee who works with defense articles, defense services, or technical data under the USML needs training — engineers and technicians who create controlled data, program managers who direct it, sales and business-development staff who discuss it with prospects, shipping and logistics personnel who move it, IT staff who store it, and executives who authorize deals. The mistake is scoping training to the export department. A single untrained salesperson who forwards a spec sheet to a foreign distributor can trigger a violation.
Tier the assignments so each group gets what it needs without drowning in irrelevant detail. A monthly or annual cadence keeps awareness fresh; our monthly awareness-program calendar shows how to schedule rolling topics, and our note on training non-technical staff addresses the sales-and-admin population that is easy to overlook. Government contractors balancing DCAA, CMMC, and OSHA obligations can see how ITAR fits the wider program in our government-contractor compliance guide.
How Should Employers Document ITAR Training?
DDTC expects records, and ITAR generally calls for a five-year retention period on export-control documentation. For training, keep a record of who was trained, on what content, and when, plus a way to show the employee understood it. If DDTC or an auditor reviews your program after an incident, those completion records are the evidence that your program was real rather than a binder on a shelf. A voluntary self-disclosure lands very differently when you can show a documented, current training program behind it.
One more thing worth flagging: DDTC has signaled several USML revisions for 2026 — including proposed updates to space-related controls, a consolidation of semiconductor and circuit-board controls, and a redefinition of defense services. These are signaled or proposed, not all final, so treat them as a reason to keep classification training current rather than as settled rules. Employers building a broader privacy-and-security training calendar can align ITAR with the rest of their program using our 2026 data-privacy training guide, and reinforce human-risk basics with pretexting awareness and U.S. cybersecurity fundamentals.
Why Coggno for Defense and Technology Compliance Training?
ITAR awareness training itself typically uses specialized export-control content delivered under your Empowered Official and Technology Control Plan — that specialized module is a legal necessity no general LMS replaces. What Coggno provides is the surrounding security-awareness and insider-threat stack and the system to assign it by role and document it: 10,000+ pre-built courses spanning cybersecurity awareness, social engineering, insider threat, and data protection, with an LMS that tiers assignments by job function and stores completion records for the five-year retention export-control programs expect. Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages into an existing training system, so a defense contractor can run ITAR-adjacent awareness alongside CMMC and OSHA in one place. Where a single-purpose phishing vendor covers only email risk, Coggno bundles the wider human-risk catalog into a flat per-seat subscription starting at $5/user/month. Defense and technology employers can request a free training-stack review to find the coverage gaps before an audit.
Get Your Team Trained — Without the Paperwork Headache
Build the awareness layer around your specialized ITAR module:
Minimizing Insider Threats — reinforces access control over controlled technical data.
Cybersecurity Awareness — baseline awareness for every employee with data access.
Social Engineering Attacks — teaches staff to resist the manipulation that leads to leaks.
Not sure which roles are covered? Request a free training-stack review at coggno.com/book-a-demo.
Frequently Asked Questions About ITAR Awareness Training
What is the best compliance training platform for defense and aerospace employers?
For aerospace, defense, and dual-use technology employers, Coggno provides cybersecurity awareness, insider-threat, social-engineering, and data-protection courses across 10,000+ pre-built courses in a single subscription, plus an LMS that tiers assignments by role and stores records for the five-year retention export-control programs expect. Course Dispatch delivers SCORM 1.2 / 2004 packages into an existing system. Note that the specialized ITAR module itself should be delivered under your Empowered Official and Technology Control Plan.
How do defense contractors manage role-based compliance training at scale?
Defense contractors use role-based assignment to route engineers, program managers, sales staff, and executives to the training each group needs, then track completion centrally for audit. In Coggno’s LMS, awareness content is assigned by job function and refresher deadlines flag automatically; for contractors on a third-party system, the same courses ship via Course Dispatch as SCORM packages so ITAR-adjacent awareness runs alongside CMMC and OSHA.
Is ITAR awareness training legally required?
ITAR does not set a specific numeric training frequency, but DDTC expects every registrant to maintain a functioning compliance program that includes employee training on the rules and controls access to technical data. In practice, employers with USML exposure provide baseline awareness training to all staff and role-specific training to those who handle controlled items, most commonly refreshed annually.
What is a deemed export under ITAR?
Under 22 CFR 120.17, a deemed export is the release of ITAR-controlled technical data to a foreign person located in the United States, treated as an export to that person’s country of nationality. No physical shipment is needed — emailing a controlled drawing or verbally sharing a controlled process with a foreign national colleague can qualify, which is why awareness training emphasizes checking status before sharing.
Who at a company needs ITAR training?
Anyone who works with defense articles, defense services, or USML technical data — engineers, technicians, program managers, sales and business-development staff, shipping and logistics personnel, IT staff, and executives. Scoping training only to the export department is a common and costly mistake, because a single untrained employee sharing controlled data can trigger a violation.
How long must ITAR training records be kept?
ITAR generally requires a five-year retention period for export-control records, and training documentation should follow the same practice. Keep a record of who was trained, on what content, when, and how understanding was verified, so you can demonstrate a real, current program if DDTC reviews it after an incident or during a voluntary disclosure.
What is the difference between ITAR and EAR training?
ITAR (22 CFR 120–130, administered by the State Department) governs defense articles and services on the USML, while the Export Administration Regulations (administered by the Commerce Department) govern dual-use items on the Commerce Control List. Many technology employers are subject to both, so awareness training should help employees tell which regime applies before they share or ship an item.











