Commendations and Recommendations from Visiting Universities and Research Centers

FederalAgency guidance

Ask Donna

How this section applies to your facts.

DDTC Policy Guidance Documents › Commendations and Recommendations from Visiting Universities and Research Centers

This text was captured on Aug 14, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

1

General Commendations and Recommendations from University Visits

by the Directorate of Defense Trade Controls

This white paper provides general findings from visiting various universities

and research centers that are engaged in activities of the International Traffic in

Arms Regulations from 2020 to early 2024. The paper provides “commendations”

and “recommendations” that the Office of Defense Trade Controls Compliance

(DTCC) provided to the universities following each visit. DTCC highlights “best

practices” in complying with the ITAR in the commendations section and offers

ways to improve a compliance program in the recommendations section.

Commendations

Export Controls Awareness/Commitment

• Demonstrates a strong commitment to ITAR compliance by university

leadership with adequate resources.

• Has strong awareness and knowledge of the various ITAR compliance

requirements and how they apply in a research context.

• Builds a culture of compliance.

Compliance Approach

• Institutes a risk-based compliance approach allowing the university to focus

resources and time on high-risk departments, e.g., engineering and physics.

• Involves export control personnel at the beginning of the research project

process and applies “control gates” in processes.

• Places export control concerns and vetting procedures at the forefront of

program development process to ensure all concerns are addressed.

Organizational Structure

• Centralizes compliance function for the university system, which allows for

the quick and effective dissemination of updated export control guidance to

multiple campuses.

• Integrates export control functions into university functional areas and

personnel position descriptions.

• Includes the export compliance function under the Office of the General

Counsel with a direct line to the President, to include regular briefings.

• Has a dedicated compliance officer at each institution within the university

system.

xport control guidance to

multiple campuses.

• Integrates export control functions into university functional areas and

personnel position descriptions.

• Includes the export compliance function under the Office of the General

Counsel with a direct line to the President, to include regular briefings.

• Has a dedicated compliance officer at each institution within the university

system.

2

Training

• Issues training materials and conducts trainings that reinforce key topics

such as identifying compliance responsibilities, risks, and consequences.

• Ensures that both Principal Investigators (PI) and other university research

staff understand their obligations through general awareness and tailored

ITAR training.

• Creates, uses, and trains on a compliance manual, supported by technology

control plans and policies and procedures.

• Demonstrates general awareness and job-specific training (e.g.,

authorization use, insider threat, and counterintelligence briefings) to

research staff about their obligations under U.S. export control laws and

regulations and maintains records of such training with employee-signed

acknowledgements.

Outreach/Participation

• Participates in the Association of University Export Control Officers

(AUECO) and shares compliance policies, procedures, and best practices

with university peers.

• Conducts regularly outreach to key university groups by the Office of

Compliance to help facilitate research and prevent export compliance

concerns from becoming a roadblock.

Fundamental/Controlled Research

• Demonstrates a thorough understanding of the distinction between

controlled and fundamental research under the ITAR and its applicability.

Foreign Students/Faculty

• Screens foreign gifts and funding sources as well as foreign-person students,

scholars, and faculty for export control concerns.

IT Resources

• Uses a tool that tracks university suppliers and their compliance rules

regarding the sharing of controlled information

he distinction between

controlled and fundamental research under the ITAR and its applicability.

Foreign Students/Faculty

• Screens foreign gifts and funding sources as well as foreign-person students,

scholars, and faculty for export control concerns.

IT Resources

• Uses a tool that tracks university suppliers and their compliance rules

regarding the sharing of controlled information.

• Utilizes external and develops in-house, automation tools that incorporate

export control decision gates (e.g., tools for risk assessments, foreign travel

reporting, visitor requests, review and release of information, and shipping

requests).

• Uses restricted party screening tools.

3

• Creates a centralized website to receive compliance questions, streamlining

reporting of compliance concerns throughout multiple campuses.

Travel

• Ensures that faculty and staff use sanitized laptops for international travel,

which in turn reduces the risk of unauthorized exports.

Personnel Resources

• Employs empowered officials who have experience with interpreting and

applying export control laws and regulations.

Technology Control Plans (TCPs)

• Develops, implements, reviews, and updates TCPs specifically to the

university’s environment and to individual research initiatives, which allows

for anticipating unique risks for each facility and program.

• Monitors TCPs regularly and requires that relevant academic departments

conduct annual risk assessments and establish disposal procedures in every

TCP.

Policies and Procedures

• Maintains comprehensive written export controls compliance policies.

• Demonstrates a hands-on approach to implementing compliance procedures

and adapts those procedures to individual facilities and programs to reduce

risks.

• Requires PIs obtain permission before beginning research funded by foreign

persons and before conducting controlled research

every

TCP.

Policies and Procedures

• Maintains comprehensive written export controls compliance policies.

• Demonstrates a hands-on approach to implementing compliance procedures

and adapts those procedures to individual facilities and programs to reduce

risks.

• Requires PIs obtain permission before beginning research funded by foreign

persons and before conducting controlled research.

• Involves the Compliance Offices at the beginning of the project decision-

making process and applies “control gates” to prevent violations.

• Creates, uses, and trains on a compliance manual, supported by technology

control plans and policies and procedures.

• Institutes an import and procurement process that includes routine vendor

screening.

• Creates standardized review processes that create opportunities to identify

potentially export-controlled activities, e.g., government grants and

technology transfers.

• Performs classification assessments of incoming and outgoing ITAR-

controlled defense articles, including technical data.

4

Physical Security

• Possesses a high level of physical security and access controls

commensurate with the sensitivity of the controlled research.

• Performs semi-annual walkthroughs of laboratories to identify equipment

that may be ITAR-controlled and identify any security gaps.

Technical Data Controls

• Segregates ITAR-controlled technical data from publicly accessible

databases to prevent unauthorized access.

Auditing/Assessments

• Performs tailored annual risk assessments for program areas and annually

audits Technical Assistance Agreements, export authorizations, and

recordkeeping.

• Performs internal audits of compliance program.

Recommendations

Compliance Approach

• Pursue research projects that require DDTC authorization, including ones

capable of utilizing ITAR exemptions, rather than be ITAR-risk averse

• Performs tailored annual risk assessments for program areas and annually

audits Technical Assistance Agreements, export authorizations, and

recordkeeping.

• Performs internal audits of compliance program.

Recommendations

Compliance Approach

• Pursue research projects that require DDTC authorization, including ones

capable of utilizing ITAR exemptions, rather than be ITAR-risk averse.

• Continue to identify potential ITAR-controlled projects early in the research

process through continued assessments and established alerts that require PIs

to obtain export control reviews.

• Conduct risk assessments and establish procedures to identify risk areas

involving ITAR-controlled activities and defense articles, including technical

data.

Organizational Structure

• Position the export compliance office to have a direct line to the Office of

the General Counsel, Office of the President, or similar level of authority.

• Consider consolidating multiple DDTC registrations into one registration to

conserve resources and to facilitate the tracking of licenses associated with

one registration code.

Training

• Establish mandatory training for the PIs involved in ITAR-controlled

projects to aid in identification of ITAR-controlled projects and research.

5

Engage the Department Chairs from Departments such as Engineering,

Computer Science, and Chemistry.

• Develop and document a training plan for department heads and scholars

that is tailored and routine.

• Conduct more frequent export compliance awareness trainings and tailored

trainings for university faculty and staff.

• Provide tailored training to PIs – particularly to all outbound PIs who are

going to teach at overseas campuses – to ensure that they understand the

aspects of their research, including research conducted between academic

semesters or away from a PI’s home campus, that may be ITAR-controlled

quent export compliance awareness trainings and tailored

trainings for university faculty and staff.

• Provide tailored training to PIs – particularly to all outbound PIs who are

going to teach at overseas campuses – to ensure that they understand the

aspects of their research, including research conducted between academic

semesters or away from a PI’s home campus, that may be ITAR-controlled.

• Offer additional tailored training for department administrative staff

responsible for travel authorizations, foreign vendors, visa and scholar

applications, and foreign shipping.

Outreach/Participation

• Meet regularly with the Defense Technology Security Administration

(DTSA) to provide an overview of research projects, discuss potential

limitations, and to communicate future licensing needs. DTSA can also

advise on license provisos and current U.S. government policy regarding the

export of critical technologies.

• Engage with faculty and other researchers regularly to track the progress of

controlled research, identify compliance risks early, and conduct ITAR

training.

• Reach out to DDTC with any questions/concerns related to the ITAR,

jurisdiction and classification, compliance, or licensing.

• Adopt a centralized mechanism for vetting outside PI consulting

engagements so that the research security officer may address export control

concerns when appropriate.

Fundamental/Controlled Research

• Articulate and disseminate the distinction between fundamental research and

controlled research to faculty and staff through required annual training.

Foreign Students, Faculty, Partners, Persons

• Review all services that university staff provide to foreign person

researchers to ensure no defense services are furnished without

authorization.

ate.

Fundamental/Controlled Research

• Articulate and disseminate the distinction between fundamental research and

controlled research to faculty and staff through required annual training.

Foreign Students, Faculty, Partners, Persons

• Review all services that university staff provide to foreign person

researchers to ensure no defense services are furnished without

authorization.

6

• Establish a uniform process for vetting gifts and donations from foreign

persons in order to determine whether individual donations have export

control ramifications.

• Enhance identification and control of defense services. Assistance rendered

by U.S. person PIs to foreign person graduate students, for example, may

constitute a defense service and should be consistently and explicitly flagged

for review.

• Apply for licenses when PIs identify foreign-person students and researchers

who could contribute to the advancement of ITAR-controlled research.

Contracts

• Formalize a requirement for visiting researchers to obtain export licenses as

necessary.

IT Resources

• Leverage IT resources to automate tracking of export authorizations and

exports of defense articles and services.

• Maintain export control documentation, risk assessments, and project data

within the same database.

• Develop automated tools to streamline and focus compliance program

processes where possible.

Travel

• Adopt more thorough pre-departure foreign travel procedures for faculty and

researchers.

• Consider requiring sanitized laptops for certain departments that pose a

higher export control risk when traveling (i.e., Engineering, Physics).

Personnel Resources

• Empower compliance staff to participate in the restricted party screening

process.

• Monitor and reassess resource needs on at least an annual basis. Consider

increasing resources, including personnel and budget, when the scope and

nature of controlled research changes

in departments that pose a

higher export control risk when traveling (i.e., Engineering, Physics).

Personnel Resources

• Empower compliance staff to participate in the restricted party screening

process.

• Monitor and reassess resource needs on at least an annual basis. Consider

increasing resources, including personnel and budget, when the scope and

nature of controlled research changes.

Technology Control Plans

• Routinely visit all projects involved in ITAR-controlled activities, create

TCPs where needed, and administer training.

• Conduct annual reviews of TCPs to ensure they are current and effective.

7

Policies and Procedures/Compliance Manuals

• Create process and review/approval system to evaluate publications for

potential export control concerns prior to release.

• Institute an import and procurement process that includes routine restricted

party screening.

• Assess whether the university is adequately tracking and documenting

compliance policies and procedures, and their implementation.

• Consider establishing written procedures to delineate what circumstances

trigger a TCP and which circumstances require a classification

determination, especially for technical data.

• Establish more robust procedures to monitor export-controlled research

projects after they commence in order to ensure that PIs abide by any

guidelines or restrictions the university establishes for such projects.

Physical Security

• Expand the technology protection process to include the tracking of foreign

person access to IT systems, rooms, offices, and labs.

• Implement access controls where ITAR-controlled activity takes place or

defense articles are stored.

• Separate ITAR controlled and non-ITAR-controlled inventory.

Handling Technical Data

• Monitor the highly used and less access-restricted IT systems to ensure

technical data is not stored

ocess to include the tracking of foreign

person access to IT systems, rooms, offices, and labs.

• Implement access controls where ITAR-controlled activity takes place or

defense articles are stored.

• Separate ITAR controlled and non-ITAR-controlled inventory.

Handling Technical Data

• Monitor the highly used and less access-restricted IT systems to ensure

technical data is not stored.

• Assess whether the university is adequately tracking and documenting the

exports of technical data, particularly within Engineering.

• Implement more jurisdiction-specific markings on technical data.

• Segregate ITAR-controlled technical data to prevent unauthorized access.

Jurisdiction and Classification

• Involve Engineering early when conducting jurisdiction classification of

defense articles and technical data.

Authorization Management

• Enhance understanding of ITAR licensing agreements. TAAs would help

facilitate exports of technical data with foreign research partners.

8

Auditing and Assessments

• Conduct risk assessments and establish procedures to identify unknown

ITAR-controlled activities and defense articles, including technical data.

• Budget for and implement external audits.

• Conduct a risk assessment to identify publications that should have an

Export Control review.

• Complete an audit of on-campus ITAR-controlled defense articles, including

technical data and defense services, and establish a database to track these

ITAR-controlled items. Also, consider making this an annual or semiannual

task.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.