ITAR, EAR & Export Control for Defense Work
From an Active SAM.gov registration to a truthful JCP / DD Form 2345 application and DSIP Volume V upload — including NIST SP 800-171 in SPRS, Proper Handling training, Data Custodian rules, and what JCP does not replace.
Read this first
This guide takes a U.S. small business that already has an Active SAM.gov registration (UEI + CAGE) through the administrative path to apply for Joint Certification Program (JCP) / DD Form 2345 certification so it can support export-controlled Defense SBIR/STTR proposals — without false certifications.
What JCP does — and does not do
| JCP / DD Form 2345 helps with | JCP does not replace |
|---|---|
| Eligibility to receive certain nonpublic, unclassified military technical data | DDTC registration when required |
| Demonstrating a legitimate business need for controlled technical data | An ITAR or EAR export license / authorization |
| Supporting an ITAR-marked SBIR/STTR proposal when the solicitation requires DD Form 2345 | A USML/ECCN classification decision |
| Identifying a responsible Data Custodian and certified physical CAGE location | NIST implementation, CMMC status, a Technology Control Plan, or access controls |
- Active SAM; legal name, address, UEI, and CAGE exact and current
- SAM will not expire within 90 days of the JCP application
- PIEE account and Contractor Account Administrator (CAM) for the CAGE
- SPRS Cyber Vendor User role active
- NIST SP 800-171 Basic Assessment completed from an SSP and posted in SPRS
- Primary Data Custodian selected for the physical CAGE location
- Designated U.S.-located computer/server with permanent hardware MAC
- Secretary of State proof of business/good standing dated within 12 months
- Current DLA Proper Handling training reviewed; Page 15 completed and signed
- USML/CCL, DDTC registration, and license answers documented
- JCP portal account with Google Authenticator
- Specific BAA, Component instructions, topic, and DSIP deadline reviewed
1. Determine what the topic actually requires
Start with the current program BAA/CSO, Component-specific instructions, topic text, amendments, and DSIP Topic Q&A. Topic-specific instructions control when they differ from general guidance.
- 1Identify control language
Does the topic identify ITAR, EAR, export-controlled data, controlled technical information, CUI, or U.S.-person restrictions?
- 2Map your work
Will the proposed work receive, generate, store, transmit, discuss, or deliver controlled technical data?
- 3Separate proposal vs award gates
What documentation is required at proposal submission versus before award? Projected CMMC level? Facility clearance? Foreign-national restrictions?
- 4Confirm Volume V evidence rule
Does the Component accept an approved DD Form 2345 only, or an approved form OR evidence of a submitted JCP application? Example: Section 3.2 of the 2026 Defense SBIR BAA commonly allows certified DD Form 2345 or evidence of application submission — always re-confirm in the controlling solicitation.
| DSIP item | How to decide |
|---|---|
| Use Federal facilities/labs/equipment? | Yes only when the proposed work actually uses Government facilities, laboratories, or equipment. |
| Understand and comply with export-control regulations? | Yes only after the responsible corporate official accepts the obligation and the company has a workable compliance path. |
| ITAR/EAR data in work or deliverables? | Yes when the proposal will receive, generate, handle, or deliver controlled data — not merely because the customer is DoD. |
2. Build the NIST SP 800-171 Basic Assessment package
Define the actual system boundary that will process, store, or transmit covered defense information or export-controlled technical data. A deliberately isolated enclave may reduce scope for a small business, but it must be real, documented, and technically separated from out-of-scope systems.
| Internal artifact | What it must contain | Upload to JCP? |
|---|---|---|
| System Security Plan (SSP) | Boundary, architecture, roles, environment, implementation narrative for each applicable requirement | No — retain unless requested |
| Control assessment workbook | Requirement-by-requirement status, objective evidence, owner, test date, findings | No |
| DoD scoring sheet | Deductions under official DoD methodology; summary score and assessment date | Summary entered in SPRS |
| POA&M | Deficiencies, milestones, resources, owners, target dates, closure evidence | No — completion date summarized in SPRS |
| Evidence repository | Screenshots, configs, policies, logs, training, inventories, test results | No — preserve for review |
- 1Use the required NIST revision and DoD methodology
The 2026 Defense SBIR BAA commonly references the 110 requirements in NIST SP 800-171 Revision 2. Confirm what your solicitation and SPRS guidance require.
- 2Verify every requirement against objective evidence
A policy statement alone does not prove technical implementation.
- 3Score under the official methodology
Start from the methodology maximum and apply required deductions. Do not invent partial credit the methodology does not allow.
- 4Record unresolved items in the POA&M
Assign realistic completion dates. Have an accountable executive review scope, SSP, evidence, score, and remediation before posting.
3. Obtain PIEE and SPRS access — then post the assessment
Every CAGE group needs a Contractor Account Administrator (CAM) in PIEE. The CAM approves privileged roles. A one-person company still needs this role established.
- 1Request SPRS Cyber Vendor User
In PIEE: My Account → Add Additional Roles → SPRS → SPRS Cyber Vendor User → select correct CAGE/vendor group → business justification → submit. CAM approves. Log out and back in after activation.
- 2Verify Active role
Manage Roles should show SPRS Cyber Vendor User — Active for the correct CAGE hierarchy. If the SPRS tile appears but “Add New NIST Assessment” is missing, you likely have a view/support role only.
- 3Open Cyber Reports and enter the summary
Enter assessment date, DoD methodology summary score, assessing scope (Enterprise / Enclave / Contract matching the SSP), POA&M completion date when applicable, SSP name/version/date, and included CAGE(s).
- 4Save evidence of the posted record
Capture the SPRS details page, internal approval record, and freeze the SSP/workbook/scoring/POA&M/evidence set as of the assessment date.
4. Assemble the JCP / DD Form 2345 package
| Prerequisite | Acceptance standard |
|---|---|
| SAM / CAGE | Active and accurate; should not expire within 90 days of application |
| NIST in SPRS | Completed Basic Assessment summary actually posted for the relevant CAGE/system |
| Data Custodian | Company employee/authorized person at the physical CAGE site who can control access — not an outside proposal consultant with no operational authority |
| Portal 2FA | Google Authenticator installed and working |
| Proof of business | Secretary of State good-standing/equivalent from the state of incorporation in SAM, dated within 12 months |
| Training certificate | Page 15 of the current DLA Proper Handling training completed and signed |
| Attachment | When required |
|---|---|
| Proof of Business (good standing) | All U.S. applicants — Articles of Organization alone may not prove current status |
| Certification Statement of Export Control Compliance (Page 15) | All applicants |
| DDTC registration letter | Only if the application says the entity is registered with DDTC |
| Export license | Only if the application says the entity possesses one |
| TAA / MLA / distribution agreement | When answers or arrangements trigger it |
| Other evidence | Only when requested by an analyst |
Designated computer/server: company-controlled device physically in the United States; permanent hardware MAC (not 00:00:00:00:00:00, not a randomized/private Wi-Fi MAC); IP address per current portal help / JCP user guide (Windows: ipconfig /all — a private 192.168.x.x address may be correct; do not auto-replace with a public gateway IP); physical street address of the device; answer “server?” from actual architecture.
5. Create/link the organization and pass the pre-screen
- 1Register the individual portal user
Configure Google Authenticator and retain recovery information securely.
- 2Search for the organization before creating
If it exists, request to join. If not, create it using exact SAM/CAGE data — punctuation and suffix included.
- 3Wait for SAM/CAGE synchronization
Organization/SAM data can take up to 24 hours to populate. Do not submit when legal name, address, UEI, CAGE, or SAM status is blank, stale, expired, or wrong.
- 4Start a standard JCP Certification Request
Do not choose DLA Enhanced Validation (DEV) unless you also need DLA systems such as DIBBS/cFolders. Standard Navy/Army/Air Force SBIR JCP does not by itself require DIBBS.
6. Complete the application, upload, sign, and submit
Answer every field from documented facts: applicant/submission type; Data Custodian and device; prime/sub/neither; business activity and NAICS that match SAM; USML/CCL/DDTC/license answers from a classification analysis — not from the topic title alone; purpose for access tied to real DoD solicitations/contracts/R&D.
- 01_Secretary_of_State_Good_Standing.pdf — mandatory Proof of Business
- 02_Proper_Handling_Page15_Signed.pdf — mandatory training certification
- 03_DDTC_Registration_Letter.pdf — only if DDTC answer is Yes
- 04_Export_License_or_Authorization.pdf — only if license answer is Yes
- 05_TAA_MLA_or_Distribution_Agreement.pdf — only when applicable
- 1Review every answer against SAM, CAGE, SPRS, SSP, and classification records
Confirm attachments are legible, current, correctly categorized, and free of unnecessary PII.
- 2Complete Conditions of Certification and authorized signature
Signer must be able to legally obligate the company. Same legal name/title throughout.
- 3Click Submit and wait for success confirmation
Save confirmation page, application number, dashboard status, and submission email as one evidence PDF.
- 4Monitor Pending Action and email
Respond to analyst requests within the stated deadline (DLA currently references responses within 90 days).
7. Use the JCP result in DSIP Volume V
| Situation | Volume V action |
|---|---|
| Approved/current JCP / DD Form 2345 | Upload the approved certificate/form or official certification evidence as required |
| JCP submitted; solicitation expressly accepts application evidence | Upload submission-evidence PDF with application number, status, and date |
| JCP only in Draft | Not acceptable evidence of submission |
| Solicitation requires approval, not application evidence | Obtain approval before the deadline or follow the Component’s official clarification process |
Suggested filename: [LegalName]_[CAGE]_JCP-DD2345_Submission-Evidence_[YYYYMMDD].pdf — with a one-page cover naming legal name, CAGE, topic, application number, and submission datetime.
- Cover Sheet and export-control questions complete and factually correct
- Technical Volume follows page, marking, foreign-citizen, facilities, subcontractor, and data-rights instructions
- Cost Volume complete; workshare percentages compliant
- Volume V includes every mandatory Component-specific supporting document
- Fraud, Waste, and Abuse training complete
- Foreign affiliations/relationships webform complete
- Corporate official electronically certified the full proposal
- Final status is Submitted — not In Progress or Ready to Certify
- Submission confirmation and final package archived
8. Sustainment, troubleshooting, and fast answers
| Record | Maintenance |
|---|---|
| SAM | Renew annually; keep legal name, address, ownership, contacts current |
| CAGE | Update authoritative CAGE data before changing JCP records |
| NIST / SPRS | Reassess at least every three years or sooner when materially changed |
| JCP | Current guidance describes a five-year certification; submit a Revision when entity, site, signer, Data Custodian, or DDTC status changes |
| Users / data / subcontractors | Authorized-user lists, training, logs, transfer approvals; flow-downs before releasing controlled data |
| Fast question | Accurate answer |
|---|---|
| Does a CAGE code make the company ITAR compliant? | No. It identifies the entity; it is not an export authorization or cyber assessment. |
| Can we submit JCP before posting NIST in SPRS? | Current DLA guidance says no. The assessment must be documented in SPRS first. |
| Can we check Yes and finish NIST later? | No. That would make the portal certification inaccurate. |
| Is ISO 9000 the cybersecurity requirement? | No. The relevant JCP prerequisite is NIST SP 800-171 in SPRS. |
| Does standard JCP require DIBBS? | No. DIBBS/cFolders relates to DLA Enhanced Validation / DLA technical-data systems. |
| Do we need an outside assessor for the Basic Assessment? | Not necessarily — it is a contractor self-assessment — but it must follow the official methodology and be supported by an SSP and evidence. |
| Is JCP approval immediate? | No. Processing is often extended; start well in advance. |
| Can application evidence be used in DSIP? | Only when the controlling solicitation permits it. A draft does not count. |









