compliance
Visitor Log Requirements: ITAR, C-TPAT, ISO, OSHA Guide
A consolidated look at what ITAR, C-TPAT, ISO 27001, and OSHA actually require for visitor logs — and where a paper sign-in sheet falls short of each one.
By InstaCheckin Team Updated September 6, 2026

Visitor log requirements aren’t one rule — they’re four different rulebooks that happen to converge on the same clipboard at your front desk. An ITAR-registered manufacturer needs a five-year audit trail. A C-TPAT-certified importer needs positively identified, escorted visitors. An ISO 27001 shop needs a supervised entry log tied to its information security controls. An OSHA-covered site needs to know who’s still in the building when the alarm goes off.
Four sets of visitor log requirements, four different auditors, and most front desks are trying to satisfy all of them with the same paper sheet. Here’s what each regime actually asks for, and where that sheet runs out of road.
This post describes general regulatory information and product capabilities, not legal advice. Whether a specific regime applies to your site, and what it requires, is a determination for your compliance officer, export-control counsel, or certifying body — not a blog post or a vendor.
What ITAR Visitor Log Requirements Actually Cover
ITAR registration is triggered by manufacturing a defense article, not by exporting one, and once a site is registered the recordkeeping duty applies to every visitor regardless of where they’re headed next. 22 CFR § 122.5 sets a five-year retention floor for ITAR-covered records — long enough that the notebook has usually changed drawers, buildings, or legibility by the time someone asks for it.
What the log needs, at minimum: full name and employer, a named host (not “front desk”), arrival and departure timestamps, a photo, and any NDA or export-control acknowledgment the visitor signed, archived with that specific visit. We go deeper on the field-by-field breakdown in our ITAR visitor management system checklist.
C-TPAT: Positive ID, an Escort, and a Log
C-TPAT sits in a different lane — it’s a supply-chain security program run by U.S. Customs and Border Protection for importers, carriers, brokers, and manufacturers in the trade chain, not an export-control regime. U.S. Customs and Border Protection’s C-TPAT Minimum Security Criteria call for visitors, vendors, and service providers to be positively identified at every point of entry, issued visible temporary identification, escorted, and logged.
The gap most facilities have isn’t the escort policy — it’s proving the escort actually happened for a specific person on a specific date. A log that ties a named host to a timestamped visit closes that gap without changing the underlying policy your security team already wrote.
ISO 27001 Treats Your Front Desk as a Security Control
If your organization is certified to ISO/IEC 27001, your front desk isn’t just a lobby — it’s a physical entry control in your information security management system. The standard’s Annex A physical-security controls expect visitor access to secure areas to be identified, logged, and supervised, the same way a firewall rule gets logged and reviewed on the network side.
An auditor working through that control doesn’t want a policy document. They want to see the log: who signed in, who they saw, when they left, and whether that record is protected from casual tampering the way a shared paper sheet isn’t.
OSHA Doesn’t Regulate Visitor Logs — It Regulates Knowing Who’s Still Inside
This is the one people get backwards. OSHA has no standard called “visitor log requirements.” What it has is OSHA’s emergency action plan rule, 29 CFR 1910.38, which requires a written procedure to account for all employees after an evacuation — a roll call, an area sweep, a designated warden checking names off a list.
Most sites extend that same accounting to visitors and contractors for the obvious reason: a fire marshal doing a headcount at the muster point doesn’t stop caring about someone because they weren’t on payroll. If your evacuation plan can’t answer “who else was in the building,” the sign-in log is the gap-filler, even though OSHA never names it directly. Our emergency evacuation plan guide covers the rest of what that written plan needs.
Where a Paper Sign-In Sheet Fails All Four
Run any of the four regimes above against a shared paper logbook and the same two failures show up. First, retrieval: producing “everyone on-site between these two dates” from a stack of loose sheets is an archaeology project, not a filter. Second, exposure: a shared sheet shows every visitor the name, company, and reason for visit of everyone who signed in before them — which is its own finding in an ISO 27001 physical-security review and a bad look during a C-TPAT site walk.
A digital log doesn’t need a written policy explaining why it’s more defensible. It just is, because each visitor only sees their own entry, and every record is searchable and exportable on request instead of transcribed by hand after the fact. Our workplace security policy template covers the written-procedure side most sites still need alongside the log itself.
Setting Up InstaCheckin for Compliance-Driven Sign-In
InstaCheckin’s iPad kiosk captures the visitor’s name, company, and reason for visit, takes a photo at check-in, and prints a badge with the logo, name, photo, host, and date. NDAs, export-control acknowledgments, or escort agreements can be routed to the kiosk by visitor type and signed on screen, with the signed copy archived against that specific visit automatically. Host notifications go out by email and SMS the moment a visitor checks in, which puts a named, timestamped person on record as having accepted responsibility for them. Every visit lands in a searchable cloud log you can filter by location, host, or date range and export to CSV or PDF for whoever’s building the audit binder — details we cover further in our manufacturing visitor management facility guide.
What it doesn’t do: automated denied-party or watchlist screening, biometric or facial-recognition matching, or an admin-configurable retention schedule tied to a specific regulation. If your program needs any of those, run them as a separate step alongside the sign-in log — a vendor claiming otherwise is handing you a gap you don’t know you have.
FAQ
Is there one universal visitor log requirement that covers every regulation?
No. ITAR, C-TPAT, ISO 27001, and OSHA come from different bodies with different goals, so they don’t share a single checklist. What overlaps in practice is the underlying data — who came in, who they saw, and when they left — which is why one searchable log usually satisfies all four instead of running separate paper processes.
Does OSHA require a visitor sign-in sheet?
Not by that name. OSHA’s emergency action plan standard requires a way to account for everyone after an evacuation, and most sites extend that headcount to visitors and contractors because an auditor doesn’t care whether the missing person was on payroll. The sign-in log is the practical tool, not a named OSHA form.
How long do I need to keep visitor logs for compliance?
It depends which regime applies to your site. ITAR sets a specific five-year floor for covered records. C-TPAT, ISO 27001, and OSHA don’t set one universal number — retention typically follows your own documented policy, which your auditor will ask to see and expect you to follow consistently. Check with your compliance officer or certifying body for your specific retention obligation.
Can a spreadsheet or paper logbook satisfy these requirements?
Sometimes, on paper. The practical failure is retrieval and exposure: producing a specific date range fast when an auditor asks, and not showing every visitor the names of everyone who signed in before them. A shared paper sheet fails the second test by design, which is its own finding in an ISO 27001 or C-TPAT physical security review. Our visitor logbook comparison walks through the rest of what paper loses.
Move Off Paper Before the Next Audit
Whichever regime your site answers to, the front desk needs the same foundation first: a record you can search, a badge that names the visitor and their host, and no exposure of one visitor’s details to the next. That part isn’t controversial in any of the four frameworks above.
If that’s the gap, start a free trial and set up a kiosk on an iPad you already own — sign-in, photo badge, host alert, exportable log. Bring the specific regulatory citation to your auditor once the record itself is no longer the weak point.
Frequently asked questions
Is there one universal visitor log requirement that covers every regulation?
Does OSHA require a visitor sign-in sheet?
How long do I need to keep visitor logs for compliance?
Can a spreadsheet or paper logbook satisfy these requirements?
Related reading
ITAR Visitor Management System Checklist for SMB Plants
A practical checklist for what an ITAR visitor management system needs to capture, retain, and hand over on request — for manufacturers setting one up for the first time.
Manufacturing Visitor Management: The Facility Guide
Manufacturing visitor management for plant floors: how digital sign-in captures visitor data, collects safety waivers, and keeps your audit log ready.
Visitor Logbook vs Digital Sign-In: 8 Things You Lose
A paper visitor logbook still works for one-day events and off-grid sites. Everywhere else, here are 8 things you give up by not switching to digital.