Don’t do SECURITY. Do business SECURELY.

US ITAR encryption carve-out for defence technical data takes effect

Properly end-to-end encrypted ITAR technical data can now be sent or stored outside the US without being treated as an export.

A change to the US International Traffic in Arms Regulations (ITAR) takes effect today, allowing properly encrypted technical data to be transmitted and stored abroad without constituting an export.

Key points

  • Unclassified technical data secured with end-to-end encryption is not an export, re-export or retransfer.
  • Encryption must meet FIPS 140-2 validated modules, or be at least as strong as AES-128.
  • Data may not be stored in countries subject to US arms embargoes, such as China or Russia.
  • Decryption keys must not be shared with unauthorised persons.

UK organisations working with US defence technical data can use cloud services more flexibly, provided encryption and key management meet the new standard.

Source: ITAR interim final rule on activities that are not exports (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights