Deemed exports under EAR treat a release of controlled technology to a foreign national inside the United States as an export. ITAR defense services covers a wider set of controlled activity, including technical assistance, training, and oral or visual disclosure tied to defense articles. The distinction matters because it changes who is regulated and when authorisation is required.
How deemed exports and defense services differ in scope
Deemed exports under EAR are centered on a release of controlled technology, software, or source code to a foreign national in the United States. The regulatory trigger is the transfer of controlled information to a person who is not a U.S. person, even if nothing crosses a border. ITAR defense services are broader in activity scope, because the rule can capture technical assistance, training, and oral or visual disclosure tied to defense articles.
The practical distinction is that EAR deemed exports focus on controlled technology and the nationality or status of the recipient, while ITAR defense services focus on the nature of the support being provided and its link to defense articles. That means the same conversation, demo, lab session, or design review can fall under different rules depending on whether the controlled item is EAR technology or an ITAR defense article.
For practitioners, the key question is not simply whether information is being shared, but what is being shared, to whom, and under which regime the item is controlled. A release that is only a deemed export under EAR may require a different authorization analysis than technical assistance under ITAR, even when the underlying project looks similar operationally.
Why the classification changes authorization decisions
The classification determines who is regulated and when permission is required. Under EAR, the compliance question often turns on whether a foreign national will access controlled technology inside the United States. Under ITAR, the question can arise from providing expertise, instruction, or a visual/oral disclosure that supports a defense article, even if no physical handoff occurs.
This matters because organizations can misread “no shipment” as “no export.” In reality, controlled knowledge transfer can be enough to create export-control exposure. That is why controlled access, visitor handling, engineering review, and training sessions need to be mapped to the relevant rule set before the discussion happens, not after.
Organizations that handle both EAR and ITAR items should treat classification as an operational control, not just a legal label. The same collaboration process may be acceptable for one item and restricted for another, so inventory, marking, and participant screening must be accurate enough to support the right authorization decision at the point of disclosure.
How practitioners distinguish the two in daily operations
In practice, the cleanest way to separate them is to start with the controlled item and then test the activity. If the subject is controlled technology or software under EAR, ask whether access by a foreign national inside the U.S. would be a deemed export. If the subject is an ITAR defense article, ask whether the interaction includes technical assistance, training, or oral or visual disclosure that constitutes a defense service.
That workflow helps prevent two common errors. First, teams may over-focus on physical transfer and miss controlled conversation or screen sharing. Second, they may assume all foreign-national access is handled the same way, when the governing rule depends on the item, the content, and the form of disclosure.
For this reason, export-control decisions often need input from legal, compliance, engineering, and program leadership together. The operational question is whether the proposed interaction changes the controlled status of the information being shared, and whether a license, exemption, or other authorization path is required before the exchange occurs.
Risk and Threat Considerations
Export-control mistakes usually arise from ordinary collaboration workflows: meetings, training, shared repositories, screen sharing, and informal technical discussion. The exposure is not limited to deliberate evasion, because uncontrolled disclosure can create a violation even when the team intended to support legitimate work.
Failure mechanism: A controlled technical disclosure is treated as non-sensitive collaboration, so a foreign national receives regulated technology under EAR or regulated technical assistance under ITAR without the required authorization.
Impact: The organisation can face regulatory penalties, project delays, loss of export privileges, and broader restrictions on future collaboration or contracting.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-3 — Access Enforcement | Controls who can access controlled technical information before disclosure occurs. |
| AC-6 — Least Privilege | Limits unnecessary exposure of controlled technology and defense-related information. | |
| AU-2 — Event Logging | Logs who accessed or disclosed controlled information, supporting export-control accountability. | |
| Recommendation — Enforce access rules so only authorized personnel can view controlled export-sensitive material. Restrict access to export-controlled material to the minimum set of approved users. Log access and disclosure events for export-controlled technical content. | ||
| ISO/IEC 27001:2022 | A.5.10 — Acceptable Use of Information and Associated Assets | Supports handling rules for controlled technical information and communication channels. |
| A.5.12 — Classification of Information | Classification determines whether information is EAR-controlled or ITAR-controlled. | |
| Recommendation — Define and enforce handling rules for export-controlled information sharing. Classify controlled technical information before allowing disclosure or collaboration. | ||
Practitioner Guidance
What to verify: Confirm the controlled item first, then classify the interaction. If the item is EAR technology, assess deemed-export exposure from foreign-national access; if it is an ITAR defense article, assess whether the activity is technical assistance or disclosure tied to that article.
Decision rule: If the interaction includes technical discussion, training, review, or screen-based disclosure, do not rely on the absence of shipment as a reason to proceed. Treat the communication path itself as the compliance decision point.
Practitioner takeaway: The practical difference is that EAR is often triggered by who receives controlled technology, while ITAR can be triggered by the kind of assistance or disclosure being provided, so classification must happen before collaboration begins.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?