A US person is an individual or entity that ITAR treats as eligible to receive certain controlled defense related information without the same restrictions that apply to foreign persons. In the employee context, this generally includes US citizens, lawful permanent residents, protected persons, and certain US government employees.
What a US Person Means in ITAR Context
A US person is not a generic nationality label, it is a legal eligibility category that affects who may receive controlled defense information, participate in regulated work, or access certain exports without foreign-person restrictions.
In practice, the term matters because ITAR treatment can change access decisions, disclosure boundaries, onboarding checks, and whether a person may be included in a controlled program, project, or technical discussion.
Who Counts as a US Person
In employee and contractor settings, the category usually includes US citizens, lawful permanent residents, protected persons, and certain US government employees. That scope is narrower than “anyone working in the United States,” and broader than citizenship alone.
The practical point is that the classification depends on legal status and ITAR treatment, not on job title, location, or whether someone works for a US-based company. A person can be physically present in the US and still be treated differently under export control rules if they do not meet the definition used for the controlled material.
Why the Definition Matters for Access and Disclosure
US person status is a boundary for controlled information sharing. It helps determine whether a person may be given direct access to defense technical data, whether a discussion must be segmented, and whether additional controls are needed before collaboration can proceed.
That makes the term operational, not merely legal. It affects who can join a meeting, view a repository, receive an attachment, or be routed into a workflow involving export-controlled material. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful background for the broader access control and authorization discipline that these decisions depend on.
How US Person Status Is Commonly Applied
Organizations usually apply the term at the point where access could create export-control exposure, such as engineering, procurement, research, cross-border collaboration, or vendor support. The question is not only “can this person do the work,” but “can this person lawfully receive the information needed to do it.”
Because the category is tied to controlled information, it often appears in onboarding screens, project intake, data handling procedures, and approval workflows. EU NIS2 Directive is not an export-control rule, but it is a useful comparator for how legal obligations can shape access control, governance, and accountability in regulated environments.
Common Misunderstandings and Boundary Cases
A frequent mistake is assuming that “US person” means “any employee in the United States” or “anyone on a US payroll.” Another is assuming that citizenship alone is always enough without checking whether the specific material or program has a tighter controlled-access rule.
Boundary cases matter because the same person may be eligible for one controlled dataset, ineligible for another, and subject to different handling rules depending on the export classification. In other words, the term is context-sensitive and must be interpreted against the exact controlled information involved.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-3 — Access Enforcement | US person status drives who may be allowed to receive controlled information. |
| AC-6 — Least Privilege | The term is used to limit exposure of controlled material to eligible recipients only. | |
| IA-8 — Identification and Authentication (Non-Organizational Users) | External recipients and collaborators must be correctly identified before access is granted. | |
| Recommendation — Enforce access decisions so only eligible personnel can receive controlled defense information. Limit distribution of controlled material to the minimum set of authorized recipients. Verify external recipients before granting access to controlled information. | ||
| ISO/IEC 27001:2022 | A.5.12 — Classification of information | US person status is applied to information that is classified or controlled for sharing. |
| A.5.15 — Access control | The term determines which people may be permitted to access regulated material. | |
| Recommendation — Classify controlled defense information so sharing rules are applied consistently. Define and enforce access rules that reflect controlled-information eligibility. | ||
Related resources from NHI Mgmt Group
- What does the hardcoded credential in a Docker image breach scenario teach us?
- Why do online identity verification workflows create more governance pressure than in-person checks?
- Why do non-person entities need the same lifecycle discipline as user identities?
- What breaks when one person can create and approve the same financial transaction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org