Reference Glossary

Export control & compliance glossary

Plain-English definitions of the terms that come up in export controls, CUI protection, and due diligence — written by practitioners, linked to where each concept shows up in real workflows.

Export controls

ITAR

The International Traffic in Arms Regulations, administered by the U.S. State Department's Directorate of Defense Trade Controls (DDTC). ITAR governs the export of defense articles, defense services, and related technical data listed on the United States Munitions List — including sharing technical data with foreign persons, which can count as an export even inside the U.S.

EAR

The Export Administration Regulations, administered by the Commerce Department's Bureau of Industry and Security (BIS). The EAR governs dual-use and commercial items — goods, software, and technology with both civilian and potential military applications — through the Commerce Control List.

ECCN

Export Control Classification Number — the five-character code (e.g., 5A002) that places an item on the Commerce Control List and determines what licenses it needs for which destinations. Classifying items correctly is the foundation of EAR compliance, and where AI-assisted classification saves compliance teams the most time.

EAR99

The designation for items subject to the EAR but not listed under a specific ECCN on the Commerce Control List. EAR99 items generally need no license for most destinations — but still can't go to sanctioned parties or prohibited end-uses.

Deemed export

The release of controlled technical data or source code to a foreign person located in the United States, which regulations treat as an export to that person's home country. Deemed exports are why access control inside a company matters, not just shipments across borders.

Technical data

Under ITAR, information required for the design, development, production, or use of defense articles — drawings, specifications, documentation, software. Sharing technical data is regulated just as physically shipping hardware is.

Restricted-party screening

Checking the people and organizations you deal with against government lists of sanctioned, denied, or debarred parties before transacting with them. Screening should run before files are shared or goods ship — automated screening makes it a workflow step instead of a periodic project.

Export license

A government authorization to export specific controlled items to a specific party for a specific use. License conditions must be tracked and honored over the life of the authorization, not just at approval time.

Data protection & certification

CUI

Controlled Unclassified Information — government-created or -owned information that requires safeguarding under law, regulation, or policy but isn't classified. For defense contractors, protecting CUI in their own systems is the core obligation behind NIST SP 800-171 and CMMC Level 2.

NIST SP 800-171

The NIST standard defining security requirements for protecting CUI in nonfederal systems — 110 requirements across 14 families in its widely-implemented Revision 2. See our explainer on how it relates to CMMC Level 2.

CMMC

The Cybersecurity Maturity Model Certification — the Department of Defense's program for verifying that contractors implement required cybersecurity practices. CMMC 2.0 has three levels; Level 2 aligns to NIST SP 800-171 and applies to contractors handling CUI.

DFARS 252.204-7012

The Defense Federal Acquisition Regulation Supplement clause requiring contractors to safeguard covered defense information per NIST SP 800-171 and to report cyber incidents to DoD. It's how 800-171 becomes a contractual obligation.

SSP

System Security Plan — the document describing how each security requirement is implemented in a given system. Assessors read the SSP first; it's the map your evidence has to match.

POA&M

Plan of Action and Milestones — the tracked list of security requirements not yet fully implemented, with owners and dates. A living POA&M signals a managed program; a stale one signals the opposite.

Audit trail

A chronological, tamper-resistant record of who did what, when — classifications, approvals, access, changes. The compliance test of an audit trail is whether it's produced automatically by the workflow, or reconstructed by hand when someone asks.

Least privilege

The principle that every user and system gets only the access its task requires, and no more. In multi-tenant operations it pairs with per-tenant isolation — the model behind AzCmd's certificate-based, credential-free connections.

Deals & data rooms

Virtual data room

A controlled online workspace for sharing confidential documents with outside parties during due diligence — permissioned per user and folder, NDA-gated, watermarked, and fully logged. See OVI Virtual Data Rooms.

Due diligence

The structured investigation a buyer, investor, or auditor performs before committing to a transaction — reviewing corporate, financial, legal, and commercial records. Our data room setup guide covers how to prepare for it.

NDA gating

Requiring reviewers to execute a non-disclosure agreement as a condition of entering a data room, enforced by the room itself rather than chased over email — leaving a record of who agreed to what, when.

Dynamic watermarking

Overlaying each viewed or printed page with the viewer's identity, so any leaked copy identifies its source. Watermarking changes forwarding behavior even when nothing leaks.

View-only rendering

Displaying documents in the browser without delivering the underlying file, so reviewers can read but not download, save, or re-share the original.

Q&A workflow

Diligence questions asked and answered inside the data room, threaded to the specific document or folder they concern — one channel, one answer, and a record of both.

Engagement analytics

Data-room reporting on which documents each reviewer opened, how long they engaged, and what they returned to — negotiating intelligence about counterparty seriousness and likely questions.

Contact One business day

A term we should add?

Tell us what tripped you up and we'll define it — or ask us how these concepts apply to your workload.