ITAR and Export Control Software: Why a Foreign National Opening a CAD File Is Already an Export
$90,000 to $190,000 over 14 to 20 weeks is a realistic first release in our delivery experience: a classification workspace tied to your part master, a person register joined to HR (Human Resources) for deemed export control, a license and agreement register with drawdown, and an immutable access log. A full platform adding enforcement hooks into PLM and file storage, continuous restricted party rescreening, technical data transfer workflow and audit reporting runs $250,000 to $600,000 over 9 to 15 months. Build if you hold ITAR controlled technical data, employ any foreign persons, and cannot currently show who accessed what. If you export a handful of EAR99 items a year, buy screening software and stop there.
Why export control fails quietly, and then all at once
An engineer needs a supplier to quote a bracket, so he shares a folder link. A contractor on the CAD team holds dual nationality and opens the assembly on a Tuesday. A repair unit arrives back from an overseas customer and goes onto the shop floor because the receiving clerk saw a returned goods number and not a controlled article. None of those three people did anything they understood to be wrong, and all three are potential unlicensed exports. The Empowered Official finds out four months later during an internal audit, and then has to decide whether to file a voluntary disclosure with the Directorate of Defense Trade Controls.
This is what makes ITAR different from almost every other compliance regime a manufacturer deals with. Under 22 CFR Parts 120 to 130 a release of technical data to a foreign person, even inside your own building in the United States, is deemed an export to that person's country. There is no shipment, no customs entry, no border. The violation is a file being opened. Quality and safety failures announce themselves. Export failures do not, which is why companies discover them in batches, years deep, usually during due diligence for an acquisition.
The consequences are why this gets board attention rather than manager attention: civil and criminal penalties per violation, and debarment from federal contracting, which for a defense manufacturer is the business. In our experience this is one of the few areas where the buyer is not trying to be talked into a budget. They want the truth about what a system can and cannot prevent.
Problem 1: classification is a backlog with one qualified person at the end of it
Every part, assembly, drawing, test report and piece of software has to be classified before anyone can decide what is allowed. Is it on the United States Munitions List and in which category, or is it subject to the Export Administration Regulations with an ECCN, or is it EAR99. That decision needs the Empowered Official or a trained trade compliance analyst, and there is one of them for tens of thousands of part numbers.
So classification happens on demand, when a quote or a shipment forces it, and the answer lives in an email. The same part gets classified twice differently by two people two years apart. Nobody can produce a list of everything the company has decided is USML Category VIII.
What a custom build does: make classification an object rather than an opinion. Each part or document has a classification record with the determination, the reasoning, the regulatory citation, the approver, the date, and a review trigger when the design changes. Because it hangs off your part master rather than off a separate spreadsheet, a new revision inherits and flags for re-review, and a bill of materials rolls up to show the highest classification in an assembly. That rollup is the thing people ask for constantly and cannot produce today.
Machine learning has a supporting role here and only a supporting one. A model reading part descriptions, drawing notes and specification references can propose a category with the relevant regulation text alongside it, which turns a blank page into a review. It cannot make the determination, and the system must be built so it cannot record one. The Empowered Official signs, or nothing is classified.
Problem 2: deemed export control is an HR and IT problem wearing a trade costume
To prevent a deemed export you need three facts joined together at the moment someone clicks a file: what is this data classified as, who is this person in terms of citizenship and immigration status, and is there a license or agreement authorising this release to that nationality. Trade compliance owns the first, HR owns the second, and IT owns the enforcement point. Almost nowhere are those three joined.
This is the most important gap in the entire category and it is precisely what the incumbent products do not close. Descartes Visual Compliance is genuinely excellent at restricted party screening and is built screening first. E2open carries deep global trade content and is aimed at large enterprise supply chains. SAP Global Trade Services is powerful and it presumes SAP as the transactional core, with its strongest ground in customs and export declarations rather than in engineering system access. OCR Services EASE handles license management competently. None of them sits inside Windchill, Teamcenter, your file storage or your source repositories deciding whether this person may open this file right now, because that is not what they were built to be.
What a custom build does: maintain a person register fed from HR with nationality, status, and the licenses or agreements each individual is named on, then enforce at the systems that hold the data. In practice this is a mix of provisioning integration, group membership driven by classification and nationality, and a gateway for the systems that cannot enforce natively. Where enforcement is genuinely impossible, the system at least detects and alerts within minutes rather than at the next audit. Being honest about that distinction matters, because a vendor promising perfect prevention across every tool you own is selling you something that does not exist.
Problem 3: licenses and agreements have scope, parties and a balance
A DSP-5 authorises specific articles or technical data, to specific parties, up to a value, until an expiry. A Technical Assistance Agreement names parties and sublicensees and scopes what may be discussed. Every shipment and every technical data release draws against one of these, and if you exceed the value or ship to a party outside the agreement, you have a violation even though you hold a license.
In most companies drawdown is tracked in a spreadsheet by the trade compliance team, updated after the fact from shipping records. That works until you have thirty active authorisations and a sales engineer promises a customer a design review next week.
What a custom build does: hold authorisations as structured records with articles, parties, value, provisos and expiry, and make every controlled transaction consume against them at the moment it happens. Shipments draw value. Technical data transfers record against the TAA that permits them. Provisos become checklists that must be satisfied rather than paragraphs somebody skimmed once. The system then answers the questions people cannot answer today: how much is left on this license, which agreements expire in ninety days and have open work against them, and which parties are receiving data with no authorisation covering them.
Problem 4: screening happens once, and the world keeps moving
Most companies screen a customer at onboarding and a shipment at order entry. Restricted party lists change constantly. A supplier you cleared two years ago may now be on the Entity List, and an ownership change can bring a party into scope without their name changing at all.
What a custom build does: rescreen the entire master of customers, suppliers, freight forwarders, visitors and employees on a schedule, and on every change to the lists, with a hit review queue that records the disposition and the reasoning. False positive management is the real work, because a screening system that produces two hundred hits a day gets ignored. The value is a defensible record showing that every hit was reviewed by a named person with a reason, which is what an auditor actually asks for.
Problem 5: your developer may be your first violation
This is the part most agencies will not raise with you, so we will. If a development team includes foreign persons and those developers can see production technical data, your compliance system has itself created deemed exports. It is a genuinely common way for this to go wrong, because everybody is focused on the engineers and nobody thinks about the contractors building the tool.
The architecture has to answer it up front. Development and testing happen against synthetic data that contains no controlled technical data. Production environments sit in a US region with access restricted to US persons, commonly in a government cloud region if your contracts require it. Support access is brokered and logged rather than standing. If your contracts bring CMMC obligations and NIST SP 800-171 controls for controlled unclassified information, the hosting and access model has to be designed for that from the first sprint, not retrofitted, because retrofitting an environment boundary is close to rebuilding.
Any developer who does not raise this in the first conversation has not built for a defense manufacturer, and you should treat that as disqualifying rather than as a detail to sort out later.
What this costs and how long it takes
A first release covering the classification workspace tied to your part master, the person register with HR integration, the license and agreement register with drawdown, and immutable logging runs $90,000 to $190,000 in 14 to 20 weeks. A full platform adding enforcement integration with PLM and file storage, continuous rescreening with hit disposition, technical data transfer request workflow, visitor and facility access control, and audit and disclosure reporting runs $250,000 to $600,000 over 9 to 15 months.
Cost drivers here are unusual. The compliant hosting environment is a real line item rather than a rounding error, particularly under CMMC obligations. PLM integration depth matters because Windchill, Teamcenter and 3DEXPERIENCE each have their own permission models and none of them was designed for nationality based access. The number of systems requiring enforcement is the multiplier that people underestimate: engineering vault, file shares, email, source control, the ERP (Enterprise Resource Planning), and the shop floor viewer are six integrations, not one. What keeps cost down: start with classification and the person register, because together they are the foundation everything else needs and they deliver value on their own.
Build versus buy, honestly
Buy if your exports are occasional and mostly EAR99, you employ no foreign persons in engineering, and your main need is restricted party screening. Descartes will do that well for a fraction of a build. Buy SAP GTS if you are a large SAP shop whose primary volume is customs and export declarations rather than engineering data access, because reproducing customs content is not a sensible use of a development budget.
Build when two or more of these are true. You hold ITAR controlled technical data and employ foreign persons anywhere in the organisation. You cannot produce, today, a report of who accessed a given controlled drawing in the last year. Your classification decisions live in email. You track license drawdown in a spreadsheet after the fact. Or you have already filed a voluntary disclosure and committed to remediation, in which case you need an auditable system rather than a better process document.
How to choose a developer for export control software
Ask, in the first meeting, how they will keep controlled technical data away from their own team. If they do not have an immediate answer involving synthetic development data, a US person production boundary and brokered support access, end the conversation.
Ask them to model the objects. Classification determination, authorisation, party, person with nationality and status, controlled transaction and access event should be distinct, and the audit log should be append only by design. If they propose a permissions matrix and a document library, they are building a file sharing product.
Ask what enforcement actually looks like in your engineering vault, by product name and version, and what happens for systems that cannot enforce natively. Prefer the developer who tells you which cases are detection rather than prevention over the one who promises prevention everywhere.
Ask who owns the code, the repository and the cloud accounts, and get it in the contract before kickoff. At Digital Heroes the client owns it from the first commit. In this category you may need to demonstrate the control environment to an auditor or to a government customer, and pointing at a system your vendor controls is not a demonstration.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Poor software quality cost the US economy an estimated $2.41 trillion in 2022, including roughly $1.52 trillion in accumulated technical debt, driven partly by unsuccessful development projects and low-quality legacy systems. Source: Consortium for Information & Software Quality (CISQ) - Herb Krasner (2022) →
- In a survey of 579 supply chain professionals (July 31 to October 1, 2024), only 29% had built at least three of the five capabilities Gartner identifies as needed for future competitiveness (agility, resilience, regionalization, integrated ecosystems, and enterprise-wide strategy). Source: Gartner (2025) →
- The right combination of digital transformation actions can unlock as much as US$1.25 trillion in additional market capitalization across Fortune 500 companies, while the wrong combinations put more than US$1.5 trillion at risk; companies with all three core factors (strategy, aligned technology, and change capability) saw a 5% market-value lift relative to peers. Source: Deloitte (2023) →
- SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
Charlotte manages accounts at Digital Heroes, keeping projects and clients aligned through the middle stretch of a build where enthusiasm fades and detail matters. She turns technical progress into language a business owner can act on. Read her for a clearer sense of what to expect from your agency.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does custom ITAR compliance software cost?
What is a deemed export and can software prevent one?
Is Descartes Visual Compliance or SAP GTS enough on its own?
Can AI classify parts against the USML or the CCL?
How do we track license and agreement drawdown properly?
Will our development team need to be US persons?
How does CMMC affect an export control system build?
How often should we rescreen customers and suppliers?
Who owns the code if an agency builds our export compliance system?
How much does custom supply chain software cost for a small business?
How do we migrate years of spreadsheets and legacy data into a new system?
Who owns the code when an agency builds my software?
What should I prepare before contacting a software development agency?
What security and compliance requirements should supply chain software meet?
Should I hire a freelancer or an agency for my software project?
What happens to our system if the agency shuts down or we part ways?
Who can build a custom supply chain software system?
Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other supply chain software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.