Per-MW pricing, regional variance, and cost drivers for owners scoping hyperscale & AI builds.
Salary benchmarks across the 14 mission-critical disciplines.
ITAR does not impose a blanket U.S.-citizen-only hiring rule. I recommend checking each role’s controlled access before setting hiring requirements. Under 22 C.F.R. § 120.62, U.S. persons include citizens, nationals, lawful permanent residents, and qualifying protected individuals, including refugees and asylees.
I separate staffing review into 3 questions: Can the person work in the United States? Can they receive the required controlled access? Do contract or security rules add restrictions?
For operators, engineers, and maintenance contractors, my checklist is simple:
I would confirm the final plan with export-compliance staff or counsel; U.S.-person status alone does not satisfy every program requirement.
ITAR Staffing: From Role Review to Authorized Access
Build an access matrix that maps each role to the articles, documents, software, spaces, testing, and discussions it touches. This makes the U.S.-person question a role-by-role access decision. Before hiring moves forward, translate status into access limits and have export compliance classify the information and activities.
The table offers a quick reference. The subsections show where access usually expands.
Removing a drawing doesn't remove every source of exposure. Shared screens, printed records, rejected-part tags, defense-article handling, and oral directions may still expose controlled information or articles. Limit permissions to assigned work, check what quality records reveal, and assign an authorized supervisor for defect escalation. Compliance must confirm that segregated-task boundaries prevent unapproved access.
Read-only access still exposes controlled data. Before troubleshooting or supplier support starts, have export compliance determine whether the activity involves controlled technical data, a defense service, or both. Assistance to foreign persons involving manufacturing, testing, repair, or operation of defense articles can fall within the defense-service definition.[4]
Use redacted instructions, escorts, segmented networks, and temporary credentials where needed. Verify their limits before work starts: an escort doesn't block a diagnostic screen, and a restricted badge doesn't restrict remote access.
Require the contractor to stop and escalate unexpected exposure. Maintenance assistance involving a defense article and a foreign person needs export-compliance review.[4] Apply these role-level limits when screening candidates and setting approvals before onboarding.
Screen candidates for defense manufacturing lines based on the access their role requires, not citizenship alone. Apply the rules to operators, engineers, and contractors according to their duties and access needs.
Before posting the job, turn the access matrix into a role profile that lists duties, access scope, start date, and approver. Keep Form I-9 verification separate from export-access review. Employees choose from permitted I-9 documents; don't require a passport or Green Card. Follow consistent procedures for similarly situated candidates.[6][7]
Citizenship alone doesn't determine access eligibility. Confirm status before assigning controlled access, and have counsel review any citizenship restriction. Customer preference is not a legal exception.[2][3][9]
A compliant posting can explain that the role requires access to ITAR-controlled technical data and that access depends on legal eligibility or prior authorization.
Use the role profile to determine who can be screened for controlled access, then confirm the required authorization path.
Export compliance should confirm ITAR jurisdiction, the U.S. Munitions List category, worker status, and the exact articles, data, or services involved. Access by a foreign person within the United States can still trigger export-control obligations. Authorization must be effective before access begins - submitting a request isn't enough.[5][3]
Check each license, agreement, or exemption for its parties, scope, effective dates, and provisos. A technical assistance agreement (TAA) may authorize technical-data disclosure or defense services. Assistance to foreign persons involving engineering, production, testing, repair, maintenance, or commissioning requires defense-service analysis.[5][8][10]
Once the authorization path is set, document the access decision and assign the role.
Record the decision date, assignment, authorization reviewed, controls, training, and approving official. This gives onboarding teams a clear record of approved access for the production start date. Give managers access instructions, not immigration details. Review access again when duties, programs, locations, or authorization terms change.
Use the table to settle the access decision before onboarding.
Complete these approvals before finalizing the start-date checklist.
Once access decisions are documented, resolve the requirements before the worker’s scheduled start date. Keep one readiness record per role, with an owner, due date, and status. Record the program, articles, data, duties, work areas, and systems. Keep I-9 verification separate from ITAR access approval. Confirm authorizations, exemptions, provisos, expiration dates, and security restrictions.
Before controlled work starts, verify least-privilege settings for badges, accounts, printing, downloads, removable media, remote access, and escorts. Log who checked each control. Reopen the review whenever duties, sites, systems, or subcontractors change.
Mark unresolved access as pending, not approved. Give the supervisor a documented interim assignment, review date, and backup coverage plan. Without these, onboarding, maintenance, and commissioning can slip. Use an escort or sanitized work package only if compliance confirms it prevents unauthorized access. Neither replaces required authorization.[5]
Turn the approved access scope into tasks tied to the start date. Before sourcing begins, assign each access task to recruiting, HR, export compliance, security, IT, and site leadership.
Recruiting checks technical fit and availability. HR handles I-9 verification, while export compliance owns status and authorization decisions. Security and IT activate approved permissions. Program owners confirm contract limits, and site leadership checks readiness for the assigned shift.
Schedule controlled tasks only after required access is active. Track authorization dependencies against maintenance outages and commissioning milestones. Keep qualified backup coverage in place, and don’t promise approval dates.
ITAR staffing depends on access, not citizenship alone. U.S. persons include U.S. citizens and nationals, lawful permanent residents, and qualifying protected individuals. Base staffing decisions on the role’s access to controlled technical data or defense articles. Verify status using lawful documents and role requirements - not birthplace, accent, or national origin.
For a foreign person, determine whether the role can be limited to noncontrolled duties or requires prior authorization. Do not grant controlled access until authorization is confirmed.
Once the role is approved and access is mapped, settle access permissions before the start date. Document restrictions, maintain assignment-specific controls, and review access when duties change. Coordinate recruiting handoffs with production dates so workers are ready for authorized work on day one.
Screen candidates only for what the role requires, and avoid blanket citizenship requirements [1]. Under ITAR, a U.S. person includes citizens, lawful permanent residents, and certain protected individuals. Requiring citizenship when any U.S. person qualifies can trigger Department of Justice enforcement [1].
Make the requirement clear in the job posting. For example:
"U.S. person per 22 CFR 120,"
Have export-control and employment counsel approve the wording [1].
The requirements depend on the work. Before anyone accesses ITAR-controlled technical data or defense articles, verify their U.S.-person status - U.S. citizens, lawful permanent residents, or qualifying protected individuals - or confirm the required authorization for non-U.S.-person access.
Classified work generally requires an active security clearance. An interim clearance isn’t guaranteed. Site badging, export-control eligibility, and security clearances are separate checks. Verify each through official channels before starting tasks that require them.
Report any accidental exposure of controlled technical data immediately to your Facility Security Officer (FSO) or the appropriate security representative. Document the incident securely in your compliance records room, using a format that allows you to retrieve it later. Under 22 CFR 122.5, covered records, including incident reports, must be kept for at least five years.
Work with your FSO to assess the breach, reduce further risk, and address project-specific gaps. Follow established security protocols and regulatory requirements.