Skip to content

compliance

ITAR vs EAR: What Each One Requires at Your Front Desk

ITAR and EAR are two different regimes with the same lobby problem: proving who was in the building and who was responsible for them. Here's what actually changes at sign-in depending on which one covers you.

By InstaCheckin Team Updated August 23, 2026

ITAR vs EAR is a question most front-desk teams inherit rather than choose. Someone in legal says the building is export-controlled, a laminated sign goes up next to the reception counter, and whoever is on the desk that morning gets handed a clipboard and told to write down whether each visitor is a US citizen.

That clipboard is the problem. Both regimes care about the same physical moment — a foreign person standing close enough to something they aren’t authorised to see — and neither one gives you a lobby procedure. They give you definitions, a recordkeeping obligation, and a very specific question an investigator will ask you two years later.

Here’s what actually differs between the two, and what changes at the sign-in kiosk depending on which one covers you.

This post is general and product information, not legal advice. Export-control obligations depend on your technology, your classifications, and your specific facts. Your export-control officer or outside counsel makes those calls, not a blog post and not a visitor system.

ITAR vs EAR: two agencies, two lists, one lobby

ITAR is a State Department regime, administered by the Directorate of Defense Trade Controls. It covers defense articles, defense services, and the technical data behind them. If you’re in the business of manufacturing, exporting, or temporarily importing defense articles, you register with DDTC — and 22 CFR §122.1 makes clear that manufacturers register even if they never export a thing.

EAR is a Commerce Department regime, administered by the Bureau of Industry and Security. It covers dual-use and commercial technology, classified by number on the Commerce Control List, with a catch-all designation for items that are subject to the rules but aren’t specifically listed.

The practical difference for a front desk isn’t strictness. It’s awareness. ITAR facilities generally know they’re ITAR facilities — there was a registration, a fee, a compliance hire. EAR facilities often find out during an audit. A machine shop that has never thought about export control can hold controlled technology on a bench in plain view of the tour route.

Deemed exports are why the lobby is in scope at all

Nothing has to leave the country. Under ITAR, 22 CFR §120.50 defines an export to include “releasing or otherwise transferring technical data to a foreign person in the United States (a deemed export).” Under the EAR, 15 CFR §734.13(b) says any release in the United States of technology or source code to a foreign person is a deemed export to that person’s most recent country of citizenship or permanent residency.

Note that last phrase. Permanent residency, not just citizenship. Which is why “Are you a US citizen?” is a poor kiosk question — it isn’t the test either regime applies, and a yes/no checkbox gives your compliance officer nothing to work with.

A quick note if you’re working from an older compliance guide: the ITAR export definition used to sit at §120.17, which is where a lot of published guidance still points. In the 2018 edition of 22 CFR §120.17 that section was headed “Export.” In the current edition, §120.17 is end-use monitoring and the export definition has moved to §120.50. Same rule, different address.

The EAR is more explicit than most people expect about what “release” means. 15 CFR §734.15 includes visual or other inspection by a foreign person that reveals technology, and oral or written exchanges. A plant tour that walks past an uncovered assembly can be a release. So can a conversation in a hallway. The Bureau of Industry and Security guidance on deemed exports frames it the same way: sharing or releasing controlled technology or source code to a foreign person inside the US.

Where the two regimes diverge at the desk

Question at the deskITAREAR
Who administers itDDTC, State DepartmentBIS, Commerce Department
What’s controlledDefense articles, defense services, and technical data on the US Munitions ListDual-use and commercial items classified on the Commerce Control List, plus unlisted items subject to the rules
Is there a registration stepYes — manufacturers register even without exportingNo equivalent registration
Deemed export basisRelease or transfer of technical data to a foreign person in the USRelease of technology or source code to a foreign person in the US
Record retentionFive yearsFive years
Who decides scopeYour export-control officer, not the receptionistYour export-control officer, not the receptionist

The bottom two rows are the ones that matter for the person actually running sign-in. Everything above them is somebody else’s determination. What reaches the front desk is a rule — this visitor type gets escorted, this one signs a document, this one doesn’t go past the badge-controlled door — and an obligation to prove the rule was followed.

If you want the regime-specific detail, we keep separate write-ups for ITAR visitor management and EAR compliance visitor management, including what each one does and doesn’t cover.

Both regimes want five years, and paper won’t survive it

Under ITAR, 22 CFR §122.5 requires covered records be maintained for five years. Under the EAR, 15 CFR §762.6 sets the same five-year period, running from the latest of the triggering events.

Five years is a long time for a spiral-bound logbook. Think about what you’d actually have to do with one: a reviewer asks who was on the floor across a two-week window in a year you’d rather not revisit, and someone has to find the right book, read handwriting, and hope no page went missing during an office move. Then hope the entries are legible enough to name a host.

There’s a second problem with paper that has nothing to do with retrieval. Every visitor who signs a shared sheet reads the names above theirs. At a site where the visitor list itself tells you which programs are active, that’s a disclosure you’re making dozens of times a week, at the door, for free. Our visitor policy template covers the retention and badge-return sections most offices leave out entirely.

What a sign-in kiosk does about this — and what it doesn’t

InstaCheckin’s job here is narrow and worth stating plainly. The iPad kiosk captures each visitor’s name, company, and reason for visit, takes a photo at sign-in, and prints a badge carrying the logo, name, photo, host, and date. Documents route by visitor type, so a contractor heading to a controlled area can be shown an export-control acknowledgment or an NDA on the kiosk and sign it on the screen before the badge prints — the signed document is archived with that visit record.

Host notifications go out by email and SMS the moment the visitor checks in, which does two things at an export-controlled site. It gets the host to the lobby instead of leaving a visitor unattended, and it puts a named person on the record as the one who accepted responsibility for the visit. Every visit lands in a cloud log you can filter by location, host, date range, or visitor name, and export to CSV or PDF when someone asks for the two-week window. For a plant-floor rollout, the manufacturing visitor management page covers the multi-entrance setup.

What it doesn’t do: automated denied-party screening. InstaCheckin doesn’t check names against the BIS Entity List, the Consolidated Screening List, or any other restricted-party list, and it doesn’t do biometric matching or facial recognition. If your program requires screening, run it in a dedicated screening tool and record the result. A vendor that blurs this line is handing you a false sense of coverage, and false coverage is worse than a gap you know about.

FAQ

Is ITAR stricter than EAR?

For the items it covers, yes — but that framing misleads people. ITAR covers a narrow list of defense articles and technical data and requires registration with DDTC before you manufacture or export them. EAR covers a far wider range of dual-use and commercial technology with no registration step at all, which is why plenty of EAR-covered facilities have no idea they’re in scope. The regime that catches you off guard is usually the more dangerous one.

Can one facility be subject to both ITAR and EAR?

Frequently. A plant can build a defense article on one line and a commercial dual-use product on the next, and the visitor walking the aisle between them is a release risk under both regimes. Your export-control officer classifies the technology, not the front desk. What the front desk owes you is a record precise enough to reconstruct where a given visitor went and who signed for them.

Does a foreign national visitor need a license to tour our plant?

That depends on what they can see and what country they hold citizenship or permanent residency in, and only your export-control officer can answer it. Under the EAR, a release includes visual inspection that reveals controlled technology, so a walk past an open bench can count. This is general information, not legal advice.

What should a visitor log capture at an export-controlled site?

At minimum: full name, employer, the specific host who accepted responsibility, arrival and departure timestamps, a photo, and any document the visitor signed on the way in. The retention rules under both regimes run five years, so whatever you capture has to survive that long in a searchable form. A paper logbook that lives in a drawer fails on both counts.

Is a visitor management system enough for ITAR or EAR compliance?

No, and any vendor who says otherwise is selling you a problem. A visitor system produces one artifact — a defensible access record. Classification, license determination, denied-party screening, technology control plans, and training all sit outside it. Treat the kiosk as evidence, not as a program.

Talk through your site’s setup before you roll it out

Export-controlled sites rarely have one door and one visitor type. If you’re mapping sign-in flows across multiple entrances, or working out which documents route to which visitor type, contact our team and we’ll walk through the configuration with you against your own program requirements.

Frequently asked questions

Is ITAR stricter than EAR?
For the items it covers, yes — but that framing misleads people. ITAR covers a narrow list of defense articles and technical data and requires registration with the Directorate of Defense Trade Controls before you manufacture or export them. EAR covers a far wider range of dual-use and commercial technology with no registration step at all, which is why plenty of EAR-covered facilities have no idea they are in scope. The regime that catches you off guard is usually the more dangerous one.
Can one facility be subject to both ITAR and EAR?
Frequently. A plant can build a defense article on one line and a commercial dual-use product on the next, and the visitor walking the aisle between them is a release risk under both regimes. Your export-control officer classifies the technology, not the front desk. What the front desk owes you is a record precise enough to reconstruct where a given visitor went and who signed for them.
Does a foreign national visitor need a license to tour our plant?
That depends on what they can see and what country they hold citizenship or permanent residency in, and only your export-control officer can answer it. Under the EAR, a release includes visual inspection that reveals controlled technology, so a walk past an open bench can count. This is general information, not legal advice.
What should a visitor log capture at an export-controlled site?
At minimum: full name, employer, the specific host who accepted responsibility, arrival and departure timestamps, a photo, and any document the visitor signed on the way in. The retention rules under both regimes run five years, so whatever you capture has to survive that long in a searchable form. A paper logbook that lives in a drawer fails on both counts.
Is a visitor management system enough for ITAR or EAR compliance?
No, and any vendor who says otherwise is selling you a problem. A visitor system produces one artifact — a defensible access record. Classification, license determination, denied-party screening, technology control plans, and training all sit outside it. Treat the kiosk as evidence, not as a program.

Related reading

Ready when you are

Have questions? Talk to us