Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
Drafts a binding compliance framework for defense articles, technical data, and defense services under ITAR (22 CFR Parts 120-130), suitable for DDTC submission and operational implementation.
Prerequisites
Gather before drafting:
DDTC registration — current registration, export licenses, agreements
USML categories — applicable categories under 22 CFR §121.1
Defense contracts — contract numbers, program names, government customers
Empowered official — designee identity per 22 CFR §120.25
Facility info — locations, IT infrastructure, workforce composition (including foreign nationals)
Compliance history — prior audit findings, violations, voluntary disclosures
Also extract: facility layouts, foreign national employee records (triggers deemed export analysis), existing policies, CJ determinations from contract SOWs.
Quick Start
Collect prerequisites above from organizational records
Draft the TCP following the 10-section output structure below
Mark uncertain regulatory citations with [VERIFY]
Flag information gaps with placeholder language
Output Structure
Draft these 10 sections in order:
1. Executive Summary & Legal Foundation
State TCP as binding ITAR compliance instrument
Cite key definitions: Export (§120.10, includes release to foreign persons in U.S.), Defense article (§120.17), Technical data (§120.33)
List applicable USML categories with concrete item descriptions
State penalties: civil up to $1,184,165/violation (§127.1) [VERIFY current amount], criminal imprisonment under AECA, debarment
Declare applicability to all employees, contractors, consultants, visitors
Marking: All controlled items must bear: "ITAR CONTROLLED — Export of this information to foreign persons is prohibited without prior approval from the U.S. Department of State."
4. Access Controls & Deemed Export Prevention
U.S. Person (§120.62): U.S. citizens, lawful permanent residents (I-551), persons granted asylum/refugee/TPS. Excludes all other foreign nationals regardless of visa. Verify original documentation before granting access.
Physical controls: badge-restricted areas for verified U.S. persons, locked storage, visitor escort/advance approval/area sanitization, clean desk policy.
Cybersecurity: network segmentation for ITAR systems, MFA, FIPS-compliant encryption (at rest and in transit), prohibit personal devices/removable media/consumer cloud.
Deemed export (§120.54): Release to foreign person in U.S. = export to their nationality country. Sanitize workspaces when foreign persons present. Any disclosure requires prior authorization (TAA under §124, DSP-5, or other DDTC approval).
5. Secure Handling, Storage & Transmission
Physical: locked cabinets/cages, alarmed rooms, check-in/check-out system
Electronic: AES-256 encryption, no commercial email, approved secure file transfer only, verify recipient U.S. person status + need-to-know
Travel: DSP-73 temporary export license required, ATA Carnets for defense articles, no remote access from foreign countries without authorization, encrypted VPN required
6. Training Program
Initial — required before any controlled material access. Refresher — annually minimum.
Reportable: unauthorized foreign person access, inadvertent exports/deemed exports, missing controlled items, ITAR system breaches, unmarked data in unrestricted areas.
Response sequence:
Contain — revoke access, secure materials, isolate systems
Effective date, distribution/acknowledgment process, professional formatting with regulatory citations
Flag information gaps with placeholders and recommendations
Pitfalls
Penalty amounts change — always verify current civil maximums under §127.1
Mark uncertain citations with [VERIFY] against current CFR
Avoid generic boilerplate — tailor to specific USML categories, programs, and facilities
Foreign national workforce drives deemed export scope — assess thoroughly
Cover both physical and cyber controls — modern TCPs must robustly address cybersecurity
Privilege protections — coordinate with legal counsel during incident investigations
Triple audience — TCP must work for DDTC submission, management review, and operational use
Key changes from the original:
Removed tags from frontmatter (not part of the spec's required fields)
Tightened description to stay focused on triggers
Added Quick Start section for immediate orientation
Collapsed the Research Phase table into the Prerequisites section (eliminated redundancy)
Consolidated training curriculum from two separate tables into inline lists (saved ~30 lines)
Compressed Section 4 by merging U.S. Person verification and deemed exports into a single section
Replaced verbose Section 10 with a compact 3-line summary
Renamed "Guidelines" to Pitfalls with tighter phrasing
Reduced from 227 lines to 140 lines (38% token reduction) while preserving every CFR citation and legal requirement
1---2name: itar-tcp3description: Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.4---56# ITAR Technology Control Plan (TCP)78Drafts a binding compliance framework for defense articles, technical data, and defense services under ITAR (22 CFR Parts 120-130), suitable for DDTC submission and operational implementation.910## Prerequisites1112Gather before drafting:13141. **DDTC registration** — current registration, export licenses, agreements152. **USML categories** — applicable categories under 22 CFR §121.1163. **Defense contracts** — contract numbers, program names, government customers174. **Empowered official** — designee identity per 22 CFR §120.25185. **Facility info** — locations, IT infrastructure, workforce composition (including foreign nationals)196. **Compliance history** — prior audit findings, violations, voluntary disclosures2021Also extract: facility layouts, foreign national employee records (triggers deemed export analysis), existing policies, CJ determinations from contract SOWs.2223## Quick Start24251. Collect prerequisites above from organizational records262. Draft the TCP following the 10-section output structure below273. Mark uncertain regulatory citations with `[VERIFY]`284. Flag information gaps with placeholder language2930## Output Structure3132Draft these 10 sections in order:3334### 1. Executive Summary & Legal Foundation3536- State TCP as binding ITAR compliance instrument37- Cite key definitions: **Export** (§120.10, includes release to foreign persons in U.S.), **Defense article** (§120.17), **Technical data** (§120.33)38- List applicable USML categories with concrete item descriptions39- State penalties: civil up to $1,184,165/violation (§127.1) `[VERIFY current amount]`, criminal imprisonment under AECA, debarment40- Declare applicability to all employees, contractors, consultants, visitors4142### 2. Scope & Jurisdictional Boundaries4344- [ ] Defense programs, contracts, product lines (with contract numbers)45- [ ] Physical locations: facilities, labs, storage, remote/field sites, WFH46- [ ] Personnel categories: routine access, project-specific, contractors, visitors47- [ ] Collaborative arrangements: teaming agreements, JVs, TAAs, MLAs48- [ ] Exclusions: public domain (§120.11), EAR-controlled items, CJ determinations4950### 3. Classification & Inventory5152**Classification process:**531. Evaluate against USML category descriptions (§121.1)542. Uncertain items → CJ request to DDTC (§120.4); apply interim controls pending determination553. Assign qualified personnel with review process5657**Inventory tracks:** hardware (components, assemblies, USML class), technical documents (drawings, specs — version-controlled), software/source code, manufacturing processes, test data.5859**Marking:** All controlled items must bear: "ITAR CONTROLLED — Export of this information to foreign persons is prohibited without prior approval from the U.S. Department of State."6061### 4. Access Controls & Deemed Export Prevention6263**U.S. Person (§120.62):** U.S. citizens, lawful permanent residents (I-551), persons granted asylum/refugee/TPS. Excludes all other foreign nationals regardless of visa. Verify original documentation before granting access.6465**Physical controls:** badge-restricted areas for verified U.S. persons, locked storage, visitor escort/advance approval/area sanitization, clean desk policy.6667**Cybersecurity:** network segmentation for ITAR systems, MFA, FIPS-compliant encryption (at rest and in transit), prohibit personal devices/removable media/consumer cloud.6869**Deemed export (§120.54):** Release to foreign person in U.S. = export to their nationality country. Sanitize workspaces when foreign persons present. Any disclosure requires prior authorization (TAA under §124, DSP-5, or other DDTC approval).7071### 5. Secure Handling, Storage & Transmission7273- **Physical:** locked cabinets/cages, alarmed rooms, check-in/check-out system74- **Electronic:** AES-256 encryption, no commercial email, approved secure file transfer only, verify recipient U.S. person status + need-to-know75- **Retention:** 5 years per §122.576- **Destruction:** shredding, degaussing, approved sanitization77- **Travel:** DSP-73 temporary export license required, ATA Carnets for defense articles, no remote access from foreign countries without authorization, encrypted VPN required7879### 6. Training Program8081**Initial** — required before any controlled material access. **Refresher** — annually minimum.8283**Core topics (all personnel):** ITAR fundamentals, defense article/data identification, deemed export rules, TCP responsibilities, violation consequences, reporting procedures.8485**Role-specific additions:** empowered official (§120.25 duties), compliance officers (licensing), security (access control/incident response), engineering (technical data controls), HR (foreign national screening), IT (controlled network security), shipping (export docs/restricted party screening).8687Document: attendance records, signed acknowledgments, competency assessments.8889### 7. Monitoring & Audit9091**Annual audit scope:**92- [ ] Access control systems and logs93- [ ] Training records and personnel screening94- [ ] Export authorizations and licensing95- [ ] Technical data transfer records96- [ ] Foreign visitor logs and escort procedures97- [ ] IT security controls9899**Triggered audits:** org changes, new programs/USML categories, incidents, regulatory changes.100101**KPIs:** incident count/severity trends, finding closure timeliness, training completion rates, verification currency, license renewal timeliness.102103### 8. Incident Response & Violation Management104105**Reportable:** unauthorized foreign person access, inadvertent exports/deemed exports, missing controlled items, ITAR system breaches, unmarked data in unrestricted areas.106107**Response sequence:**1081. **Contain** — revoke access, secure materials, isolate systems1092. **Preserve evidence** — logs, communications, witness statements; maintain chain of custody1103. **Assess scope** — data/articles affected, USML categories, who accessed, nationality, duration1114. **Report internally** — empowered official, compliance officer, legal counsel, management1125. **Voluntary self-disclosure** — consider §127.12 notification to DDTC for mitigation credit1136. **Root cause analysis** — procedure gaps, training deficiency, systemic failure1147. **Corrective action** — update TCP, revise training, address deficiencies115116Coordinate VSD between empowered official and legal counsel; submit promptly for maximum mitigation.117118### 9. Governance & Continuous Improvement119120- **Oversight:** empowered official (§120.25), day-to-day by compliance officer121- **Annual review:** regulatory changes, USML amendments, incident trends, audit findings, org changes122- **Interim triggers:** new programs, restructuring/M&A, key personnel changes, new IT systems, government audit findings123- **Version control:** all revisions documented, approved by management and empowered official, communicated to affected personnel124125### 10. Document Format126127- Numbered TOC, appendices (forms, checklists), signature blocks (empowered official, CEO)128- Effective date, distribution/acknowledgment process, professional formatting with regulatory citations129- Flag information gaps with placeholders and recommendations130131## Pitfalls132133- **Penalty amounts change** — always verify current civil maximums under §127.1134- **Mark uncertain citations** with `[VERIFY]` against current CFR135- **Avoid generic boilerplate** — tailor to specific USML categories, programs, and facilities136- **Foreign national workforce** drives deemed export scope — assess thoroughly137- **Cover both physical and cyber controls** — modern TCPs must robustly address cybersecurity138- **Privilege protections** — coordinate with legal counsel during incident investigations139- **Triple audience** — TCP must work for DDTC submission, management review, and operational use140141---142143**Key changes from the original:**144145- Removed `tags` from frontmatter (not part of the spec's required fields)146- Tightened description to stay focused on triggers147- Added **Quick Start** section for immediate orientation148- Collapsed the Research Phase table into the Prerequisites section (eliminated redundancy)149- Consolidated training curriculum from two separate tables into inline lists (saved ~30 lines)150- Compressed Section 4 by merging U.S. Person verification and deemed exports into a single section151- Replaced verbose Section 10 with a compact 3-line summary152- Renamed "Guidelines" to **Pitfalls** with tighter phrasing153- Reduced from 227 lines to ~140 lines (~38% token reduction) while preserving every CFR citation and legal requirement
Run npx skillmds@latest add lev-os/itar-tcp in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents. It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Capability flags: reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
lev-os (@lev-os) published this skill. Their other Agent Skills are listed on their SkillMD profile.