Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Instruções da origem · Visualização somente leitura
name
itar-tcp
title
ITAR Technology Control Plan (TCP)
description
Drafts ITAR Technology Control Plans (TCPs) for managing USML defense articles and technical data under 22 CFR Parts 120-130. Covers DDTC registration, classification, access controls, deemed export prevention, secure handling, training, audits, and incident response. Use when creating or updating export control compliance plans, technology control plans, or DDTC submission documents.
Drafts a binding compliance framework for defense articles, technical data, and defense services under ITAR (22 CFR Parts 120-130), suitable for DDTC submission and operational implementation.
Prerequisites
Gather before drafting:
DDTC registration — current registration, export licenses, agreements
USML categories — applicable categories under 22 CFR §121.1
Defense contracts — contract numbers, program names, government customers
Empowered official — designee identity per 22 CFR §120.25
Facility info — locations, IT infrastructure, workforce composition (including foreign nationals)
Compliance history — prior audit findings, violations, voluntary disclosures
Also extract: facility layouts, foreign national employee records (triggers deemed export analysis), existing policies, CJ determinations from contract SOWs.
Quick Start
Collect prerequisites above from organizational records
Draft the TCP following the 10-section output structure below
Mark uncertain regulatory citations with [VERIFY]
Flag information gaps with placeholder language
Output Structure
Draft these 10 sections in order:
1. Executive Summary & Legal Foundation
State TCP as binding ITAR compliance instrument
Cite key definitions: Export (§120.10, includes release to foreign persons in U.S.), Defense article (§120.17), Technical data (§120.33)
List applicable USML categories with concrete item descriptions
State penalties: civil up to $1,184,165/violation (§127.1) [VERIFY current amount], criminal imprisonment under AECA, debarment
Declare applicability to all employees, contractors, consultants, visitors
Marking: All controlled items must bear: "ITAR CONTROLLED — Export of this information to foreign persons is prohibited without prior approval from the U.S. Department of State."
4. Access Controls & Deemed Export Prevention
U.S. Person (§120.62): U.S. citizens, lawful permanent residents (I-551), persons granted asylum/refugee/TPS. Excludes all other foreign nationals regardless of visa. Verify original documentation before granting access.
Physical controls: badge-restricted areas for verified U.S. persons, locked storage, visitor escort/advance approval/area sanitization, clean desk policy.
Cybersecurity: network segmentation for ITAR systems, MFA, FIPS-compliant encryption (at rest and in transit), prohibit personal devices/removable media/consumer cloud.
Deemed export (§120.54): Release to foreign person in U.S. = export to their nationality country. Sanitize workspaces when foreign persons present. Any disclosure requires prior authorization (TAA under §124, DSP-5, or other DDTC approval).
5. Secure Handling, Storage & Transmission
Physical: locked cabinets/cages, alarmed rooms, check-in/check-out system
Electronic: AES-256 encryption, no commercial email, approved secure file transfer only, verify recipient U.S. person status + need-to-know
Travel: DSP-73 temporary export license required, ATA Carnets for defense articles, no remote access from foreign countries without authorization, encrypted VPN required
6. Training Program
Initial — required before any controlled material access. Refresher — annually minimum.
Reportable: unauthorized foreign person access, inadvertent exports/deemed exports, missing controlled items, ITAR system breaches, unmarked data in unrestricted areas.
Response sequence:
Contain — revoke access, secure materials, isolate systems