| name | itar-technology-control-plan |
| title | ITAR Technology Control Plan |
| description | Drafts an ITAR Technology Control Plan (TCP) for U.S. export control compliance under 22 CFR 120-130. Use when a user needs to create or update a TCP, export control program, or deemed-export compliance plan. Trigger on mentions of ITAR, TCP, DDTC, USML, deemed export, technical data, or defense article in a compliance-planning context. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/itar-technology-control-plan |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | sanctions |
| language | en |
| tags | ["drafting","memo","research"] |
ITAR Technology Control Plan
Produces an organization-specific, auditable TCP covering USML scoping, technical data controls, U.S. person screening, deemed-export safeguards, cybersecurity, training, audits, and incident response.
Prerequisites
Collect before drafting:
- Org profile — entity names, DDTC registration status, empowered official, compliance contacts.
- Programs & scope — contracts, USML categories, items/technical data, facility list.
- People & access — personnel roster, foreign nationals, visitor workflows, subcontractors.
- Systems & storage — IT architecture, data repos, collaboration tools, physical storage.
- Authorizations — licenses/agreements (DSP-5, DSP-73, TAA, MLA), CJ determinations, prior disclosures.
- Existing policies — security, HR screening, IT, visitor control, incident response, records retention.
Quick Start
- Gather all prerequisites; flag gaps early.
- Draft each required section (see Section Outline below).
- Populate the role matrix, inventory, and training tables with org-specific data.
- Mark every regulatory citation with [VERIFY] for counsel review.
- Attach appendices (forms, checklists, facility maps, access roster).
- Route for empowered-official approval and signature.
Required Sections
| # | Section | Key Content |
|---|
| 1 | Purpose & Authority | TCP applicability; cite ITAR 22 CFR 120-130 [VERIFY]. |
| 2 | Definitions | Defense article, technical data, export, U.S. person, deemed export — with citations [VERIFY]. |
| 3 | Scope | Programs/contracts, USML categories (22 CFR 121.1) [VERIFY], facilities, remote-work boundaries. |
| 4 | Roles & Governance | Empowered official, compliance officer, IT/security, HR, program owners. |
| 5 | Classification & Inventory | USML mapping, CJ workflow (22 CFR 120.4) [VERIFY], marking, version control. |
| 6 | Access Controls | U.S. person verification, badge logic, visitor escorts, need-to-know. |
| 7 | IT & Cybersecurity | Segmentation, MFA, encryption, logging, device/media restrictions. |