compliance
ITAR Visitor Management System Checklist for SMB Plants
A practical checklist for what an ITAR visitor management system needs to capture, retain, and hand over on request — for manufacturers setting one up for the first time.
By InstaCheckin Team Updated September 4, 2026
A DDTC compliance review doesn’t ask whether you have a sign-in sheet. It asks you to produce every visitor who walked your floor in a specific two-week window three years ago, name the host who was responsible for each one, and show what they signed on the way in. If the answer involves flipping through a spiral notebook in a drawer, you already know how that meeting goes.
That’s the actual bar an ITAR visitor management system has to clear: not “did we log visitors” but “can we reconstruct and hand over the record on demand, five years from now.” Most SMB manufacturers inherit this requirement the same way — someone in legal says the site is ITAR-registered, a sign goes up at reception, and whoever’s on the front desk that day gets told to “keep better track of who comes in.”
Here’s what actually has to be true of the system you put at that desk, field by field.
This post describes product capabilities and general information, not legal advice. Whether a specific visitor, technology, or activity is covered by ITAR is a determination for your export-control officer or counsel, not a blog post or a vendor.
What Your ITAR Visitor Management System Needs to Capture
Registration with the Directorate of Defense Trade Controls is triggered by manufacturing a defense article, not by exporting one — a detail that catches SMB machine shops off guard when they assume ITAR is only about shipping overseas. Once you’re registered, the recordkeeping obligation applies to visitors regardless of destination.
A defensible log needs, at minimum:
- Full name and employer of the visitor
- The specific host who accepted responsibility for them — not “front desk,” a named person
- Arrival and departure timestamps
- A photo taken at check-in
- Any document the visitor signed (NDA, export-control acknowledgment, safety waiver) archived with that specific visit
A yes/no “US citizen?” checkbox is a common shortcut and a weak one. It doesn’t capture permanent-residency status, and it gives your compliance officer nothing to work with beyond a single bit of unverified self-report.
Escort Documentation, Not Just an Escort Policy
Most ITAR sites already have an escort rule: foreign nationals and unbadged visitors don’t walk the floor unaccompanied near controlled work areas. The gap is usually documentation, not policy — everyone knows the rule, nobody can prove on a specific date that it was followed for a specific visitor.
A kiosk that routes documents by visitor type closes that gap. If a contractor is heading into a controlled area, the sign-in flow can present an export-control acknowledgment or escort agreement on screen before the badge prints, and the signed copy is stored with that visit record instead of living in a separate binder someone has to cross-reference later. That’s a documentation trail, not a legal determination — your export-control officer still decides which visitor types trigger which document, same as they always did.
Five Years Is the Retention Period That Breaks Paper
22 CFR §122.5 requires ITAR-covered records be kept for five years. Five years is long enough that the person who wrote the logbook entry may not work there anymore, the notebook may have moved buildings twice, and the handwriting was never that legible to begin with.
A cloud-stored log sidesteps the retrieval problem specifically: every visit is timestamped and searchable, so producing “everyone who was on-site between these two dates” is a filter, not an archaeology project. It also sidesteps the exposure problem paper creates — a shared sign-in sheet shows every visitor the names above theirs, which at a site where the visitor list itself signals which programs are active is a disclosure you’re making for free, several times a day. Our visitor policy template covers the retention and badge-return details most written policies skip.
Deemed Exports Don’t Require Anything to Leave the Building
Nothing has to cross a border for a release to happen. Under ITAR, releasing technical data to a foreign person inside the US — a “deemed export” — is treated the same as shipping it abroad, per 22 CFR §120.50. A plant tour that walks a visitor past an uncovered assembly can count.
This is also where ITAR and its sibling regime, EAR, start to overlap — a site can be covered by one, the other, or both depending on what’s on the floor. We break down the differences and where they cross over in a separate ITAR vs. EAR comparison, including which regime governs which visitor scenario.
Setting Up InstaCheckin for an ITAR-Covered Site
InstaCheckin’s iPad kiosk captures the visitor’s name, company, and reason for visit, takes a photo at sign-in, and prints a badge with the logo, name, photo, host, and date. Documents route by visitor type, so the export-control acknowledgment or NDA a contractor needs to sign shows up on the kiosk before the badge prints, and the signed record archives with that visit automatically. Host notifications go out by email and SMS the moment the visitor checks in, which puts a named, timestamped person on record as having accepted responsibility — useful both for getting an escort to the lobby promptly and for the record itself. Every visit lands in a searchable cloud log, filterable by location, host, or date range, and exportable to CSV or PDF for whoever’s running the manufacturing visitor management rollout across your entrances.
What it doesn’t do: automated denied-party screening against the BIS Entity List or any other restricted-party list, and no biometric or facial-recognition matching. If your program requires screening, that has to run in a dedicated tool before the visit — a vendor claiming otherwise is handing you a gap you don’t know you have.
FAQ
What fields does an ITAR-compliant visitor log need?
At minimum: the visitor’s full name and employer, the specific host who accepted responsibility, arrival and departure timestamps, a photo, and a record of any escort or non-disclosure document the visitor signed. A checkbox that only asks citizenship status isn’t enough on its own — your export-control officer decides what’s controlled, but the log has to be precise enough for them to reconstruct the visit later.
How long do we have to keep ITAR visitor records?
Five years under 22 CFR §122.5, which covers records related to manufacturing, export, and other activities regulated under ITAR. That clock runs from the date of the record, not the date you review it, so a system that quietly ages out or misplaces old entries creates a gap you won’t notice until an auditor asks for it.
Do we need to screen visitors against a denied-parties list?
That’s a separate compliance step from visitor logging, and most sign-in kiosks — InstaCheckin included — don’t do it. If your program requires screening against the BIS Entity List or similar restricted-party lists, run it through a dedicated screening tool before the visit and keep that result with your other compliance records.
Can a paper logbook satisfy ITAR visitor logging requirements?
Legally, maybe, if you can actually produce five years of legible, complete records on request. In practice a shared paper sheet also exposes every prior visitor’s name to whoever signs in next, which is its own disclosure problem at a site where the visitor list can reveal which programs are active. Most plants that get audited once switch to a system they can search and export instead of re-testing their luck.
Talk Through Your Site’s Setup
Export-controlled sites rarely have one entrance and one visitor type — contractors, auditors, and vendors often need different documents and different escort rules at the same front desk. Our full ITAR visitor management page covers the feature set in more depth, or contact our team and we’ll map your specific document routing and multi-entrance setup before you roll it out.
Frequently asked questions
What fields does an ITAR-compliant visitor log need?
How long do we have to keep ITAR visitor records?
Do we need to screen visitors against a denied-parties list?
Can a paper logbook satisfy ITAR visitor logging requirements?
Related reading
ITAR vs EAR: What Each One Requires at Your Front Desk
ITAR and EAR are two different regimes with the same lobby problem: proving who was in the building and who was responsible for them. Here's what actually changes at sign-in depending on which one covers you.
Manufacturing Visitor Management: The Facility Guide
Manufacturing visitor management for plant floors: how digital sign-in captures visitor data, collects safety waivers, and keeps your audit log ready.
Visitor Policy Template: 9 Sections Every Office Needs
The nine sections a workplace visitor policy needs, a copy-paste skeleton you can drop into your own document, and the parts most offices leave out.