ITAR Compliance and Technology Law for the US Market

Technology, Defence & Innovation with US lawyers in Munich

Software, deep tech and security-related technologies are subject to a specific set of regulations in the US market: ITAR compliance for armaments and defence technology, EAR export controls for dual-use goods, government contracting for contracts with US authorities, and CFIUS reviews for security-related investments. Each of these regulatory frameworks requires its own compliance structures and contractual provisions.

We guide German technology and defence companies through this complex web of export controls, public procurement law and investment screening. The advice is provided by our US lawyers in Munich, who have an equal understanding of both technology and US law.

Challenges

Anyone who develops or supplies US-related products or technologies must first determine whether ITAR or EAR applies. An incorrect classification may result in licensing requirements being overlooked or export transactions being blocked retrospectively – with serious consequences for ongoing collaborations.

US authorities and CFIUS follow their own rules: licensing requirements and investment reviews of which German companies are often only made aware at a late stage – by which time a transaction or contract has already run into difficulties.

Solutions

We classify products and technologies under ITAR or EAR at an early stage and establish the compliance framework to support your ongoing export operations.

When it comes to government contracting and CFIUS reviews, we clarify at an early stage which procurement rules and notification requirements apply – before they become a time-sensitive risk for your contract or transaction.

Let’s talk about your US compliance.

Whether it’s ITAR compliance, government contracting or a CFIUS review: during the initial consultation, we clarify which regulatory framework applies to your project and what steps need to be taken, and in what order. You’ll be speaking directly to our US lawyers in Munich – and where necessary, we’ll bring in our colleagues in New York, Boston or San Francisco.

Our services

Four key elements for technology and defence companies operating in the US – from SaaS contracts and deep-tech investor agreements to ITAR compliance, government contracting and CFIUS. All four follow the same principle: structures and contracts that are legally sound under US law and safeguard your technology business.

Software & SaaS Contracts

Software-as-a-Service contracts in the US market follow different standards to those in Germany: Licence models differ in terms of scope of use and pricing structure; service level agreements often define availability and response times much more strictly; and liability clauses limit claims according to different standards than those under German law governing general terms and conditions. Anyone who simply translates a German SaaS contract often thereby assumes liability risks that are not provided for under US law, or forgoes limitations of liability that would be customary there.

We draft and review SaaS contracts in strict accordance with US standards – from the licensing structure and service level agreements right through to limitations of liability and warranties. This creates a contractual framework that stands up to scrutiny in the US market whilst also aligning with your business model.

Deep Tech & AI

Deep-tech and AI business models bring together IP protection, data law and investor agreements. Patents and know-how must be structured in such a way that they hold up in the US market, whilst AI applications also raise data protection issues: what training data was used, what rules apply to data flows between the EU and the US, and what requirements a US investor imposes regarding the documentation of these issues prior to a funding round. Anyone who overlooks these intersections will find themselves having to explain themselves, at the latest during the due diligence phase of an investment round.

We support deep-tech and AI companies at the intersection of technology, intellectual property law and data law – from safeguarding intellectual property to drafting investor agreements that stand up to scrutiny on these issues.

Armaments and defence industry: ITAR/EAR export controls

US-related armaments and defence technology are subject to either the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR) – two distinct export control regimes, each with its own licensing procedures, reporting requirements and penalties for non-compliance. Whether a product or technology falls under ITAR or EAR determines which deliveries, collaborations and data transfers require authorisation, and what compliance structure a company must maintain on an ongoing basis. For German suppliers and business partners with US-related activities, ITAR compliance is therefore not a one-off assessment, but an ongoing task that affects every new delivery, every new collaboration and every new employee joining the company.

We classify products and technologies under ITAR or EAR, establish compliance frameworks for ongoing export transactions, and provide support with licensing procedures and reporting obligations. Our ITAR consultancy is aimed at German companies that cooperate with US partners, supply goods to the US or use US technology – from the initial assessment through to ongoing export control.

Government Procurement & CFIUS

Contracts with US authorities and the US Department of Defence are subject to their own procurement and contractual rules, which differ from those governing US civilian contracts and, even more so, from German public procurement law: they have their own certification requirements, their own reporting obligations and their own rules on subcontracting. Investments from Germany in US companies involved in security-related activities may also trigger a review by the Committee on Foreign Investment in the United States (CFIUS) – with the result that a transaction can only be completed once it has been approved.

We prepare German suppliers and partners for the requirements of US government contracting and assess at an early stage whether and how CFIUS affects your project – before this becomes a time risk for the contract or transaction.

Frequently Asked Questions

ITAR compliance means that your defence-related products, technologies and data are correctly classified under the International Traffic in Arms Regulations and that the relevant licensing and reporting requirements are met. This applies not only to exports themselves, but also to collaborations, access to data and the deployment of non-US nationals. We assess the classification of your technology and set up the necessary compliance framework.

The EAR applies to dual-use goods, i.e. technologies with both civilian and military applications, whilst the ITAR applies specifically to military equipment and defence technology. The two regimes differ significantly in terms of licensing procedures, reporting requirements and the consequences of non-compliance. Which regime applies depends on the specific classification of your product – we will clarify this before you commence export operations.

A CFIUS review may be triggered if a foreign investment gives a foreign entity influence over a US company possessing security-relevant technology, critical infrastructure or sensitive data. Whether and to what extent this is the case depends on the structure of the transaction and the nature of the US company involved. We assess this at an early stage to ensure that CFIUS does not become a time-consuming risk for your transaction.