ITAR controls who is allowed to access certain defense-related technical data and hardware. CMMC governs how that data has to be protected once you have access to it. They’re related, but they answer different questions.
Quick summary: ITAR (International Traffic in Arms Regulations, 22 CFR Parts 120–130) is an export-control regime restricting access to defense articles and technical data to authorized U.S. persons and registered entities. CMMC (Cybersecurity Maturity Model Certification), built on the NIST SP 800-171 security controls, governs how Controlled Unclassified Information must be protected in a contractor’s IT environment. A company can be ITAR-registered without being CMMC-certified, and vice versa, depending on what data it handles.
What Does ITAR Actually Control?
ITAR restricts the export — including disclosure to foreign persons — of defense articles and associated technical data. Registration under ITAR is a prerequisite for legally handling that category of information at all.
What Does CMMC Actually Control?
CMMC is a cybersecurity certification framework, built on NIST SP 800-171, that verifies a contractor’s IT systems and processes meet defined security-control levels for protecting Controlled Unclassified Information (CUI).
Can a Company Have One Without the Other?
Yes. ITAR registration is about legal eligibility to handle defense technical data. CMMC is about whether your systems are secure enough to protect that data once you have it. A company can be ITAR-registered while still working toward CMMC certification, or vice versa depending on contract requirements.
Why Do Both Matter to a Customer Choosing a Machine Shop?
If a program requires a shop to receive ITAR-controlled technical data, the shop needs both — the legal eligibility under ITAR and, increasingly, the security posture required by CMMC — to be a viable long-term partner.
FAQ
Does ITAR registration automatically mean CMMC compliance? No — they’re governed by different regulations and evaluate different things (legal eligibility vs. cybersecurity posture).
Which one applies to unclassified technical data specifically? Both can, depending on the data’s classification — ITAR governs export control of defense articles/data broadly, while CMMC governs protection of CUI specifically.
Sources: 22 CFR Parts 120–130 (ITAR); NIST SP 800-171 (basis for CMMC controls). Related: eMachineShop is ITAR Registered and JCP Certified — see Our Company.