October 5, 2026

ITAR U.S. Person Rules for Staffing Defense Manufacturing Lines

By:
Dallas Bond

ITAR does not impose a blanket U.S.-citizen-only hiring rule. I recommend checking each role’s controlled access before setting hiring requirements. Under 22 C.F.R. § 120.62, U.S. persons include citizens, nationals, lawful permanent residents, and qualifying protected individuals, including refugees and asylees.

I separate staffing review into 3 questions: Can the person work in the United States? Can they receive the required controlled access? Do contract or security rules add restrictions?

For operators, engineers, and maintenance contractors, my checklist is simple:

  • Map access to defense articles, drawings, software, work areas, and technical assistance - including remote support.
  • Keep Form I-9 verification separate from export-access review. Don’t judge status by birthplace, name, or accent.
  • For foreign persons, assess noncontrolled assignments or the required authorization.
  • <u>Approve access before controlled work begins.</u> Document limits, coordinate HR and site teams, and review access when duties change.

I would confirm the final plan with export-compliance staff or counsel; U.S.-person status alone does not satisfy every program requirement.

ITAR Staffing: From Role Review to Authorized Access

ITAR Staffing: From Role Review to Authorized Access

Can A Foreign National Work At A Company With ITAR Data?

Assess Controlled Access for Each Manufacturing Role

Build an access matrix that maps each role to the articles, documents, software, spaces, testing, and discussions it touches. This makes the U.S.-person question a role-by-role access decision. Before hiring moves forward, translate status into access limits and have export compliance classify the information and activities.

Role Information or equipment encountered Controlled access risk Access-control questions Required compliance review
Production Operator Controlled drawings, work instructions, inspection records, test fixtures, supervisor directions, and defense articles Controlled technical data, defense-article handling, or production assistance What appears on screens and printed packets? Can the operator access adjacent cells, quality records, or testing? Classify data and defense articles; confirm authorization and Technology Control Plan requirements.
Manufacturing Engineer Tooling specifications, tolerances, bills of material, process software, test procedures, and engineering changes Technical-data access; possible defense-service exposure when assisting a foreign person Are full drawings needed? Who receives supplier instructions or remote troubleshooting support? Determine technical-data and defense-service exposure; identify the applicable license, agreement, exemption, or restriction.
Maintenance Contractor Diagnostic screens, equipment logs, service tickets, controllers, and remote-support tools Controlled information exposed through diagnostics; possible repair or maintenance assistance What can local and remote users see? Are work areas, network permissions, and support channels restricted? Export compliance, information security, facilities, and the program owner approve physical, system, and remote access before work begins.

The table offers a quick reference. The subsections show where access usually expands.

Production Operator: Drawings, Instructions, and Article Handling

Removing a drawing doesn't remove every source of exposure. Shared screens, printed records, rejected-part tags, defense-article handling, and oral directions may still expose controlled information or articles. Limit permissions to assigned work, check what quality records reveal, and assign an authorized supervisor for defect escalation. Compliance must confirm that segregated-task boundaries prevent unapproved access.

Manufacturing Engineer: Process Data and Technical Support

Read-only access still exposes controlled data. Before troubleshooting or supplier support starts, have export compliance determine whether the activity involves controlled technical data, a defense service, or both. Assistance to foreign persons involving manufacturing, testing, repair, or operation of defense articles can fall within the defense-service definition.[4]

Maintenance Contractor: Site and Remote Access

Use redacted instructions, escorts, segmented networks, and temporary credentials where needed. Verify their limits before work starts: an escort doesn't block a diagnostic screen, and a restricted badge doesn't restrict remote access.

Require the contractor to stop and escalate unexpected exposure. Maintenance assistance involving a defense article and a foreign person needs export-compliance review.[4] Apply these role-level limits when screening candidates and setting approvals before onboarding.

Screen Candidates Lawfully and Approve Access

Screen candidates for defense manufacturing lines based on the access their role requires, not citizenship alone. Apply the rules to operators, engineers, and contractors according to their duties and access needs.

Verify Status Without Citizens-Only Screening

Before posting the job, turn the access matrix into a role profile that lists duties, access scope, start date, and approver. Keep Form I-9 verification separate from export-access review. Employees choose from permitted I-9 documents; don't require a passport or Green Card. Follow consistent procedures for similarly situated candidates.[6][7]

Citizenship alone doesn't determine access eligibility. Confirm status before assigning controlled access, and have counsel review any citizenship restriction. Customer preference is not a legal exception.[2][3][9]

A compliant posting can explain that the role requires access to ITAR-controlled technical data and that access depends on legal eligibility or prior authorization.

Use the role profile to determine who can be screened for controlled access, then confirm the required authorization path.

Confirm ITAR Coverage and Authorization Options

Export compliance should confirm ITAR jurisdiction, the U.S. Munitions List category, worker status, and the exact articles, data, or services involved. Access by a foreign person within the United States can still trigger export-control obligations. Authorization must be effective before access begins - submitting a request isn't enough.[5][3]

Check each license, agreement, or exemption for its parties, scope, effective dates, and provisos. A technical assistance agreement (TAA) may authorize technical-data disclosure or defense services. Assistance to foreign persons involving engineering, production, testing, repair, maintenance, or commissioning requires defense-service analysis.[5][8][10]

Once the authorization path is set, document the access decision and assign the role.

Record Access Decisions and Program Restrictions

Record the decision date, assignment, authorization reviewed, controls, training, and approving official. This gives onboarding teams a clear record of approved access for the production start date. Give managers access instructions, not immigration details. Review access again when duties, programs, locations, or authorization terms change.

Use the table to settle the access decision before onboarding.

Review category Control question Access limit Approver
U.S. persons needing controlled access What articles, data, tasks, and program or contract restrictions apply? Approve only defined access; apply training and need-to-know controls Export compliance with program and security owners
Foreign persons without controlled access Can assigned duties exclude controlled data, articles, and defense services? Assign noncontrolled work; segregate systems and areas; prevent incidental access Export compliance and site manager
Foreign persons needing authorization Does effective authorization cover the person, activity, parties, destination, and applicable conditions? Withhold controlled access until authorization and required controls are in place Empowered export official or designated compliance owner
Defense-service reviews Does assistance or training for a foreign person constitute a defense service? Escalate for analysis; restrict assistance to the approved scope Export compliance and legal counsel
Separate contract or security restrictions Do contract clauses, classified-information rules, proprietary-data limits, or flow-down obligations restrict access? Apply required contractual or security limits separately from ITAR eligibility Contract, security, program, and legal owners

Complete these approvals before finalizing the start-date checklist.

Staffing Checklist for On-Time Production Starts

Complete Access Checks Before the Start Date

Once access decisions are documented, resolve the requirements before the worker’s scheduled start date. Keep one readiness record per role, with an owner, due date, and status. Record the program, articles, data, duties, work areas, and systems. Keep I-9 verification separate from ITAR access approval. Confirm authorizations, exemptions, provisos, expiration dates, and security restrictions.

Before controlled work starts, verify least-privilege settings for badges, accounts, printing, downloads, removable media, remote access, and escorts. Log who checked each control. Reopen the review whenever duties, sites, systems, or subcontractors change.

Mark unresolved access as pending, not approved. Give the supervisor a documented interim assignment, review date, and backup coverage plan. Without these, onboarding, maintenance, and commissioning can slip. Use an escort or sanitized work package only if compliance confirms it prevents unauthorized access. Neither replaces required authorization.[5]

Coordinate Recruiting, Compliance, and Site Teams

Turn the approved access scope into tasks tied to the start date. Before sourcing begins, assign each access task to recruiting, HR, export compliance, security, IT, and site leadership.

Recruiting checks technical fit and availability. HR handles I-9 verification, while export compliance owns status and authorization decisions. Security and IT activate approved permissions. Program owners confirm contract limits, and site leadership checks readiness for the assigned shift.

Schedule controlled tasks only after required access is active. Track authorization dependencies against maintenance outages and commissioning milestones. Keep qualified backup coverage in place, and don’t promise approval dates.

Conclusion: Hire for Authorized Access, Not Citizenship Alone

ITAR staffing depends on access, not citizenship alone. U.S. persons include U.S. citizens and nationals, lawful permanent residents, and qualifying protected individuals. Base staffing decisions on the role’s access to controlled technical data or defense articles. Verify status using lawful documents and role requirements - not birthplace, accent, or national origin.

For a foreign person, determine whether the role can be limited to noncontrolled duties or requires prior authorization. Do not grant controlled access until authorization is confirmed.

Once the role is approved and access is mapped, settle access permissions before the start date. Document restrictions, maintain assignment-specific controls, and review access when duties change. Coordinate recruiting handoffs with production dates so workers are ready for authorized work on day one.

FAQs

How can we ask about ITAR eligibility without discriminating?

Screen candidates only for what the role requires, and avoid blanket citizenship requirements [1]. Under ITAR, a U.S. person includes citizens, lawful permanent residents, and certain protected individuals. Requiring citizenship when any U.S. person qualifies can trigger Department of Justice enforcement [1].

Make the requirement clear in the job posting. For example:

"U.S. person per 22 CFR 120,"

Have export-control and employment counsel approve the wording [1].

Can a new hire start while ITAR authorization is pending?

The requirements depend on the work. Before anyone accesses ITAR-controlled technical data or defense articles, verify their U.S.-person status - U.S. citizens, lawful permanent residents, or qualifying protected individuals - or confirm the required authorization for non-U.S.-person access.

Classified work generally requires an active security clearance. An interim clearance isn’t guaranteed. Site badging, export-control eligibility, and security clearances are separate checks. Verify each through official channels before starting tasks that require them.

What should we do after accidental controlled-data exposure?

Report any accidental exposure of controlled technical data immediately to your Facility Security Officer (FSO) or the appropriate security representative. Document the incident securely in your compliance records room, using a format that allows you to retrieve it later. Under 22 CFR 122.5, covered records, including incident reports, must be kept for at least five years.

Work with your FSO to assess the breach, reduce further risk, and address project-specific gaps. Follow established security protocols and regulatory requirements.

Related Blog Posts

Keywords:
ITAR, U.S. person, export compliance, defense manufacturing, controlled technical data, access matrix, Technology Control Plan, hiring compliance
Free Download

Data Center Construction Labor Trends in 2026

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

More mission critical construction news

NAS 410 and ASNT NDT Levels Explained
October 5, 2026

NAS 410 and ASNT NDT Levels Explained

Explains differences between NAS 410, SNT‑TC‑1A, and ASNT Level III, focusing on issuer, portability, employer authorization, and hiring checks.
Shift-Differential Pay in Aerospace and Defense Manufacturing: 2026 Benchmarks
October 5, 2026

Shift-Differential Pay in Aerospace and Defense Manufacturing: 2026 Benchmarks

Planning ranges and policy guidance for evening, overnight, and weekend shift premiums in aerospace and defense manufacturing.
MIL-STD-810 Test Roles: Who Runs Environmental Qualification
October 5, 2026

MIL-STD-810 Test Roles: Who Runs Environmental Qualification

Assign clear ownership for MIL-STD-810 testing: who plans, runs, reviews, and approves environmental qualification.
DCMA, FAI and AS9102: First Article Inspection for Defense Programs
October 4, 2026

DCMA, FAI and AS9102: First Article Inspection for Defense Programs

Prepare AS9102 Forms 1–3, set full/partial FAI scope, and coordinate DCMA/QAR oversight and approvals for defense contracts.