Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
Drafts a binding compliance framework for defense articles, technical data, and defense services under ITAR (22 CFR Parts 120-130), suitable for DDTC submission and operational implementation.
Prerequisites
Gather before drafting:
DDTC registration — current registration, export licenses, agreements
USML categories — applicable categories under 22 CFR §121.1
Defense contracts — contract numbers, program names, government customers
Empowered official — designee identity per 22 CFR §120.25
Facility info — locations, IT infrastructure, workforce composition (including foreign nationals)
Compliance history — prior audit findings, violations, voluntary disclosures
Also extract: facility layouts, foreign national employee records (triggers deemed export analysis), existing policies, CJ determinations from contract SOWs.
Quick Start
Collect prerequisites above from organizational records
Draft the TCP following the 10-section output structure below
Mark uncertain regulatory citations with [VERIFY]
Flag information gaps with placeholder language
Output Structure
Draft these 10 sections in order:
1. Executive Summary & Legal Foundation
State TCP as binding ITAR compliance instrument
Cite key definitions: Export (§120.10, includes release to foreign persons in U.S.), Defense article (§120.17), Technical data (§120.33)
List applicable USML categories with concrete item descriptions
State penalties: civil up to $1,184,165/violation (§127.1) [VERIFY current amount], criminal imprisonment under AECA, debarment
Declare applicability to all employees, contractors, consultants, visitors
Marking: All controlled items must bear: "ITAR CONTROLLED — Export of this information to foreign persons is prohibited without prior approval from the U.S. Department of State."
4. Access Controls & Deemed Export Prevention
U.S. Person (§120.62): U.S. citizens, lawful permanent residents (I-551), persons granted asylum/refugee/TPS. Excludes all other foreign nationals regardless of visa. Verify original documentation before granting access.
Physical controls: badge-restricted areas for verified U.S. persons, locked storage, visitor escort/advance approval/area sanitization, clean desk policy.
Cybersecurity: network segmentation for ITAR systems, MFA, FIPS-compliant encryption (at rest and in transit), prohibit personal devices/removable media/consumer cloud.
Deemed export (§120.54): Release to foreign person in U.S. = export to their nationality country. Sanitize workspaces when foreign persons present. Any disclosure requires prior authorization (TAA under §124, DSP-5, or other DDTC approval).
5. Secure Handling, Storage & Transmission
Physical: locked cabinets/cages, alarmed rooms, check-in/check-out system
Electronic: AES-256 encryption, no commercial email, approved secure file transfer only, verify recipient U.S. person status + need-to-know
Travel: DSP-73 temporary export license required, ATA Carnets for defense articles, no remote access from foreign countries without authorization, encrypted VPN required
6. Training Program
Initial — required before any controlled material access. Refresher — annually minimum.
Reportable: unauthorized foreign person access, inadvertent exports/deemed exports, missing controlled items, ITAR system breaches, unmarked data in unrestricted areas.
Response sequence:
Contain — revoke access, secure materials, isolate systems
Effective date, distribution/acknowledgment process, professional formatting with regulatory citations
Flag information gaps with placeholders and recommendations
Pitfalls
Penalty amounts change — always verify current civil maximums under §127.1
Mark uncertain citations with [VERIFY] against current CFR
Avoid generic boilerplate — tailor to specific USML categories, programs, and facilities
Foreign national workforce drives deemed export scope — assess thoroughly
Cover both physical and cyber controls — modern TCPs must robustly address cybersecurity
Privilege protections — coordinate with legal counsel during incident investigations
Triple audience — TCP must work for DDTC submission, management review, and operational use
Key changes from the original:
Removed tags from frontmatter (not part of the spec's required fields)
Tightened description to stay focused on triggers
Added Quick Start section for immediate orientation
Collapsed the Research Phase table into the Prerequisites section (eliminated redundancy)
Consolidated training curriculum from two separate tables into inline lists (saved ~30 lines)
Compressed Section 4 by merging U.S. Person verification and deemed exports into a single section
Replaced verbose Section 10 with a compact 3-line summary
Renamed "Guidelines" to Pitfalls with tighter phrasing
Reduced from 227 lines to 140 lines (38% token reduction) while preserving every CFR citation and legal requirement
1---2name: itar-tcp3description: Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.4license: Apache-2.05---67# ITAR Technology Control Plan (TCP)89Drafts a binding compliance framework for defense articles, technical data, and defense services under ITAR (22 CFR Parts 120-130), suitable for DDTC submission and operational implementation.1011## Prerequisites1213Gather before drafting:14151. **DDTC registration** — current registration, export licenses, agreements162. **USML categories** — applicable categories under 22 CFR §121.1173. **Defense contracts** — contract numbers, program names, government customers184. **Empowered official** — designee identity per 22 CFR §120.25195. **Facility info** — locations, IT infrastructure, workforce composition (including foreign nationals)206. **Compliance history** — prior audit findings, violations, voluntary disclosures2122Also extract: facility layouts, foreign national employee records (triggers deemed export analysis), existing policies, CJ determinations from contract SOWs.2324## Quick Start25261. Collect prerequisites above from organizational records272. Draft the TCP following the 10-section output structure below283. Mark uncertain regulatory citations with `[VERIFY]`294. Flag information gaps with placeholder language3031## Output Structure3233Draft these 10 sections in order:3435### 1. Executive Summary & Legal Foundation3637- State TCP as binding ITAR compliance instrument38- Cite key definitions: **Export** (§120.10, includes release to foreign persons in U.S.), **Defense article** (§120.17), **Technical data** (§120.33)39- List applicable USML categories with concrete item descriptions40- State penalties: civil up to $1,184,165/violation (§127.1) `[VERIFY current amount]`, criminal imprisonment under AECA, debarment41- Declare applicability to all employees, contractors, consultants, visitors4243### 2. Scope & Jurisdictional Boundaries4445- [ ] Defense programs, contracts, product lines (with contract numbers)46- [ ] Physical locations: facilities, labs, storage, remote/field sites, WFH47- [ ] Personnel categories: routine access, project-specific, contractors, visitors48- [ ] Collaborative arrangements: teaming agreements, JVs, TAAs, MLAs49- [ ] Exclusions: public domain (§120.11), EAR-controlled items, CJ determinations5051### 3. Classification & Inventory5253**Classification process:**541. Evaluate against USML category descriptions (§121.1)552. Uncertain items → CJ request to DDTC (§120.4); apply interim controls pending determination563. Assign qualified personnel with review process5758**Inventory tracks:** hardware (components, assemblies, USML class), technical documents (drawings, specs — version-controlled), software/source code, manufacturing processes, test data.5960**Marking:** All controlled items must bear: "ITAR CONTROLLED — Export of this information to foreign persons is prohibited without prior approval from the U.S. Department of State."6162### 4. Access Controls & Deemed Export Prevention6364**U.S. Person (§120.62):** U.S. citizens, lawful permanent residents (I-551), persons granted asylum/refugee/TPS. Excludes all other foreign nationals regardless of visa. Verify original documentation before granting access.6566**Physical controls:** badge-restricted areas for verified U.S. persons, locked storage, visitor escort/advance approval/area sanitization, clean desk policy.6768**Cybersecurity:** network segmentation for ITAR systems, MFA, FIPS-compliant encryption (at rest and in transit), prohibit personal devices/removable media/consumer cloud.6970**Deemed export (§120.54):** Release to foreign person in U.S. = export to their nationality country. Sanitize workspaces when foreign persons present. Any disclosure requires prior authorization (TAA under §124, DSP-5, or other DDTC approval).7172### 5. Secure Handling, Storage & Transmission7374- **Physical:** locked cabinets/cages, alarmed rooms, check-in/check-out system75- **Electronic:** AES-256 encryption, no commercial email, approved secure file transfer only, verify recipient U.S. person status + need-to-know76- **Retention:** 5 years per §122.577- **Destruction:** shredding, degaussing, approved sanitization78- **Travel:** DSP-73 temporary export license required, ATA Carnets for defense articles, no remote access from foreign countries without authorization, encrypted VPN required7980### 6. Training Program8182**Initial** — required before any controlled material access. **Refresher** — annually minimum.8384**Core topics (all personnel):** ITAR fundamentals, defense article/data identification, deemed export rules, TCP responsibilities, violation consequences, reporting procedures.8586**Role-specific additions:** empowered official (§120.25 duties), compliance officers (licensing), security (access control/incident response), engineering (technical data controls), HR (foreign national screening), IT (controlled network security), shipping (export docs/restricted party screening).8788Document: attendance records, signed acknowledgments, competency assessments.8990### 7. Monitoring & Audit9192**Annual audit scope:**93- [ ] Access control systems and logs94- [ ] Training records and personnel screening95- [ ] Export authorizations and licensing96- [ ] Technical data transfer records97- [ ] Foreign visitor logs and escort procedures98- [ ] IT security controls99100**Triggered audits:** org changes, new programs/USML categories, incidents, regulatory changes.101102**KPIs:** incident count/severity trends, finding closure timeliness, training completion rates, verification currency, license renewal timeliness.103104### 8. Incident Response & Violation Management105106**Reportable:** unauthorized foreign person access, inadvertent exports/deemed exports, missing controlled items, ITAR system breaches, unmarked data in unrestricted areas.107108**Response sequence:**1091. **Contain** — revoke access, secure materials, isolate systems1102. **Preserve evidence** — logs, communications, witness statements; maintain chain of custody1113. **Assess scope** — data/articles affected, USML categories, who accessed, nationality, duration1124. **Report internally** — empowered official, compliance officer, legal counsel, management1135. **Voluntary self-disclosure** — consider §127.12 notification to DDTC for mitigation credit1146. **Root cause analysis** — procedure gaps, training deficiency, systemic failure1157. **Corrective action** — update TCP, revise training, address deficiencies116117Coordinate VSD between empowered official and legal counsel; submit promptly for maximum mitigation.118119### 9. Governance & Continuous Improvement120121- **Oversight:** empowered official (§120.25), day-to-day by compliance officer122- **Annual review:** regulatory changes, USML amendments, incident trends, audit findings, org changes123- **Interim triggers:** new programs, restructuring/M&A, key personnel changes, new IT systems, government audit findings124- **Version control:** all revisions documented, approved by management and empowered official, communicated to affected personnel125126### 10. Document Format127128- Numbered TOC, appendices (forms, checklists), signature blocks (empowered official, CEO)129- Effective date, distribution/acknowledgment process, professional formatting with regulatory citations130- Flag information gaps with placeholders and recommendations131132## Pitfalls133134- **Penalty amounts change** — always verify current civil maximums under §127.1135- **Mark uncertain citations** with `[VERIFY]` against current CFR136- **Avoid generic boilerplate** — tailor to specific USML categories, programs, and facilities137- **Foreign national workforce** drives deemed export scope — assess thoroughly138- **Cover both physical and cyber controls** — modern TCPs must robustly address cybersecurity139- **Privilege protections** — coordinate with legal counsel during incident investigations140- **Triple audience** — TCP must work for DDTC submission, management review, and operational use141142---143144**Key changes from the original:**145146- Removed `tags` from frontmatter (not part of the spec's required fields)147- Tightened description to stay focused on triggers148- Added **Quick Start** section for immediate orientation149- Collapsed the Research Phase table into the Prerequisites section (eliminated redundancy)150- Consolidated training curriculum from two separate tables into inline lists (saved ~30 lines)151- Compressed Section 4 by merging U.S. Person verification and deemed exports into a single section152- Replaced verbose Section 10 with a compact 3-line summary153- Renamed "Guidelines" to **Pitfalls** with tighter phrasing154- Reduced from 227 lines to ~140 lines (~38% token reduction) while preserving every CFR citation and legal requirement
Run npx skillmds@latest add thomasmoreai/itar-tcp in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents. It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.
ThomasMoreAI (@thomasmoreai) published this skill. Their other Agent Skills are listed on their SkillMD profile.