Export control & compliance glossary
Plain-English definitions of the terms that come up in export controls, CUI protection, and due diligence — written by practitioners, linked to where each concept shows up in real workflows.
Export controls
ITAR
The International Traffic in Arms Regulations, administered by the U.S. State Department's Directorate of Defense Trade Controls (DDTC). ITAR governs the export of defense articles, defense services, and related technical data listed on the United States Munitions List — including sharing technical data with foreign persons, which can count as an export even inside the U.S.
EAR
The Export Administration Regulations, administered by the Commerce Department's Bureau of Industry and Security (BIS). The EAR governs dual-use and commercial items — goods, software, and technology with both civilian and potential military applications — through the Commerce Control List.
ECCN
Export Control Classification Number — the five-character code (e.g., 5A002) that places an item on the Commerce Control List and determines what licenses it needs for which destinations. Classifying items correctly is the foundation of EAR compliance, and where AI-assisted classification saves compliance teams the most time.
EAR99
The designation for items subject to the EAR but not listed under a specific ECCN on the Commerce Control List. EAR99 items generally need no license for most destinations — but still can't go to sanctioned parties or prohibited end-uses.
Deemed export
The release of controlled technical data or source code to a foreign person located in the United States, which regulations treat as an export to that person's home country. Deemed exports are why access control inside a company matters, not just shipments across borders.
Technical data
Under ITAR, information required for the design, development, production, or use of defense articles — drawings, specifications, documentation, software. Sharing technical data is regulated just as physically shipping hardware is.
Restricted-party screening
Checking the people and organizations you deal with against government lists of sanctioned, denied, or debarred parties before transacting with them. Screening should run before files are shared or goods ship — automated screening makes it a workflow step instead of a periodic project.
Export license
A government authorization to export specific controlled items to a specific party for a specific use. License conditions must be tracked and honored over the life of the authorization, not just at approval time.
Data protection & certification
CUI
Controlled Unclassified Information — government-created or -owned information that requires safeguarding under law, regulation, or policy but isn't classified. For defense contractors, protecting CUI in their own systems is the core obligation behind NIST SP 800-171 and CMMC Level 2.
NIST SP 800-171
The NIST standard defining security requirements for protecting CUI in nonfederal systems — 110 requirements across 14 families in its widely-implemented Revision 2. See our explainer on how it relates to CMMC Level 2.
CMMC
The Cybersecurity Maturity Model Certification — the Department of Defense's program for verifying that contractors implement required cybersecurity practices. CMMC 2.0 has three levels; Level 2 aligns to NIST SP 800-171 and applies to contractors handling CUI.
DFARS 252.204-7012
The Defense Federal Acquisition Regulation Supplement clause requiring contractors to safeguard covered defense information per NIST SP 800-171 and to report cyber incidents to DoD. It's how 800-171 becomes a contractual obligation.
SSP
System Security Plan — the document describing how each security requirement is implemented in a given system. Assessors read the SSP first; it's the map your evidence has to match.
POA&M
Plan of Action and Milestones — the tracked list of security requirements not yet fully implemented, with owners and dates. A living POA&M signals a managed program; a stale one signals the opposite.
Audit trail
A chronological, tamper-resistant record of who did what, when — classifications, approvals, access, changes. The compliance test of an audit trail is whether it's produced automatically by the workflow, or reconstructed by hand when someone asks.
Least privilege
The principle that every user and system gets only the access its task requires, and no more. In multi-tenant operations it pairs with per-tenant isolation — the model behind AzCmd's certificate-based, credential-free connections.
Deals & data rooms
Virtual data room
A controlled online workspace for sharing confidential documents with outside parties during due diligence — permissioned per user and folder, NDA-gated, watermarked, and fully logged. See OVI Virtual Data Rooms.
Due diligence
The structured investigation a buyer, investor, or auditor performs before committing to a transaction — reviewing corporate, financial, legal, and commercial records. Our data room setup guide covers how to prepare for it.
NDA gating
Requiring reviewers to execute a non-disclosure agreement as a condition of entering a data room, enforced by the room itself rather than chased over email — leaving a record of who agreed to what, when.
Dynamic watermarking
Overlaying each viewed or printed page with the viewer's identity, so any leaked copy identifies its source. Watermarking changes forwarding behavior even when nothing leaks.
View-only rendering
Displaying documents in the browser without delivering the underlying file, so reviewers can read but not download, save, or re-share the original.
Q&A workflow
Diligence questions asked and answered inside the data room, threaded to the specific document or folder they concern — one channel, one answer, and a record of both.
Engagement analytics
Data-room reporting on which documents each reviewer opened, how long they engaged, and what they returned to — negotiating intelligence about counterparty seriousness and likely questions.
A term we should add?
Tell us what tripped you up and we'll define it — or ask us how these concepts apply to your workload.