ITAR Compliance and Technology Law for the U.S. Market

Technology, Defense & Innovation with U.S. Attorneys in Munich

Software, deep tech, and security-related technologies are subject to a separate set of regulations in the U.S. business environment: ITAR compliance for military equipment and defense technology, EAR export controls for dual-use goods, government contracting for agreements with U.S. government agencies, and CFIUS reviews for security-related investments. Each of these regulatory frameworks requires its own compliance structures and contractual provisions.

We guide German technology and defense companies through this complex web of export controls, public procurement law, and investment reviews. Our advice is provided by our U.S. attorneys in Munich, who have an equal understanding of both technology and U.S. law.

Challenges

Anyone who develops or supplies U.S.-related products or technologies must first determine whether ITAR or EAR applies. An incorrect classification can lead to licensing requirements being overlooked or export transactions being blocked retroactively—with serious consequences for ongoing collaborations.

U.S. authorities and CFIUS follow their own rules: licensing requirements and investment reviews that German companies often don’t learn about until it’s too late—by which time a transaction or contract has already stalled.

Solutions

We classify products and technologies under ITAR or EAR at an early stage and establish the compliance framework that supports your ongoing export operations.

When it comes to government contracting and CFIUS reviews, we determine early on which procurement rules and reporting requirements apply—before they become a time risk for your contract or transaction.

Let's talk about your U.S. compliance.

Whether it’s ITAR compliance, government contracting, or a CFIUS review: During the initial consultation, we’ll determine which regulations apply to your project and what steps need to be taken and in what order. You’ll speak directly with our U.S. attorneys in Munich—and when necessary, we’ll bring in our colleagues in New York, Boston, or San Francisco.

Our Services

Four building blocks for technology and defense companies doing business in the U.S.—from SaaS contracts and deep-tech investor agreements to ITAR compliance, government contracting, and CFIUS. All four follow the same principle: structures and contracts that are legally sound under U.S. law and safeguard your technology business.

Software & SaaS Contracts

Software-as-a-Service contracts in the U.S. market follow different standards than those in Germany: Licensing models differ in scope of use and pricing structure; service level agreements often define availability and response times much more strictly; and liability clauses limit claims according to different standards than those under German law governing general terms and conditions. Simply translating a German SaaS contract often results in assuming liability risks not provided for under U.S. law or omitting liability limitations that would be customary there.

We draft and review SaaS contracts in strict accordance with U.S. standards—from licensing structures and service level agreements to liability limitations and warranties. This creates a contractual framework that stands up to the rigors of doing business in the U.S. while also aligning with your business model.

Deep Tech & AI

Deep-tech and AI business models bring together IP protection, data law, and investor agreements. Patents and know-how must be structured in a way that holds up in the U.S. market, while AI applications also raise data protection issues: what training data was used, what rules apply to data flows between the EU and the U.S., and what requirements a U.S. investor has regarding documentation of these issues prior to a funding round. Anyone who overlooks these intersections will find themselves struggling to explain themselves, at the latest, during the due diligence phase of an investment round.

We support deep-tech and AI companies at the intersection of technology, intellectual property law, and data law—from protecting intellectual property to drafting investor agreements that stand up to these challenges.

Arms and Defense Industry: ITAR/EAR Export Controls

U.S.-related military goods and defense technology are subject to either the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR)—two distinct export control regimes with their own licensing procedures, reporting requirements, and penalties for violations. Whether a product or technology falls under ITAR or EAR determines which shipments, collaborations, and data transfers require authorization and what compliance structure a company must maintain on an ongoing basis. For German suppliers and business partners with ties to the U.S., ITAR compliance is therefore not a one-time review, but an ongoing task that affects every new shipment, every new collaboration, and every new employee hire.

We classify products and technologies under ITAR or EAR, establish compliance frameworks for ongoing export transactions, and provide support for licensing procedures and reporting requirements. Our ITAR consulting services are designed for German companies that collaborate with U.S. partners, ship to the U.S., or use U.S. technology—from the initial assessment through ongoing export controls.

Government Contracting & CFIUS

Contracts with U.S. government agencies and the U.S. Department of Defense are subject to their own procurement and contracting rules, which differ from those governing civilian U.S. contracts and, even more so, from German procurement law: they have their own certification requirements, reporting obligations, and rules for subcontracting. Investments from Germany in U.S. companies involved in national security matters may also trigger a review by the Committee on Foreign Investment in the United States (CFIUS)—meaning that a transaction cannot be completed until it has been approved.

We prepare German suppliers and partners for the requirements of U.S. government contracting and determine early on whether and how CFIUS affects your project—before it becomes a time risk for the contract or transaction.

Frequently Asked Questions

ITAR compliance means that your defense-related products, technologies, and data are correctly classified under the International Traffic in Arms Regulations and that the corresponding licensing and reporting requirements are met. This applies not only to exports themselves, but also to collaborations, data access, and the employment of non-U.S. citizens. We assess the classification of your technology and establish the necessary compliance framework.

The EAR applies to dual-use goods—that is, technologies with both civilian and military uses—while the ITAR applies specifically to military equipment and defense technology. The two regimes differ significantly in terms of licensing procedures, reporting requirements, and the consequences of violations. Which regime applies depends on the specific classification of your product—we will clarify this before you begin your export business.

A CFIUS review may be triggered if a foreign investment gives a foreign entity influence over a U.S. company that possesses security-related technology, critical infrastructure, or sensitive data. Whether and to what extent this is the case depends on the structure of the transaction and the nature of the U.S. company involved. We assess this early on to ensure that CFIUS does not become a time-consuming risk for your transaction.