IT compliance for a DFW manufacturer means 4 obligations at once. ITAR registration and access control, NIST 800-171 for defense work, Texas SB 2610 data safeguards, and prime contract flow-downs that arrive with no room to negotiate.
Most DFW plants treat compliance as a purchasing problem the prime owns. It is not. ITAR registration is triggered by manufacturing, not by exporting. CMMC Phase 2 is suspended but DFARS 252.204-7012 is not. And every hour your line is down is also an hour your audit trail stops writing. Here is what each rulebook demands of your network, and the order to fix it in.
We have supported Texas manufacturing since 1999, and the same conversation keeps repeating itself in Garland, Grand Prairie and Arlington. A shop wins a subcontract. Signs the flow-down. Then finds out 6 months later that the clause it agreed to obligated the network, not the shipping department.
Dallas-Fort Worth carried 313,300 manufacturing jobs in June 2026, according to the Bureau of Labor Statistics. The mix matters more than the total. A large share of it sits in the aerospace and defense supply chain feeding Lockheed Martin in Grand Prairie and Fort Worth, Bell in Hurst, and the hundreds of tier-2 and tier-3 machine shops that orbit them. Those shops routinely hold export-controlled drawings on a file server that anyone with a domain login can browse, which is the single most common finding we hit when a new manufacturing client hands us their environment for the first time.
Our own industry earns some blame here. Managed IT providers market CMMC readiness loudly because there is a certificate at the end of it. ITAR gets mentioned far less, because ITAR has nothing to sell you. No certification body. No badge for the website. Just a registration, a set of controls, and a penalty schedule.
What IT compliance actually means inside a DFW plant
For a manufacturer, IT compliance is the set of technical controls that prove who touched which file, when, and whether that person was allowed to. It is an evidence problem before it is a security problem. Regulators and primes do not ask whether you are secure. They ask you to show the log.
That reframe changes what you buy. A firewall does not produce evidence. An access review does. So does an immutable audit log, a documented offboarding process, and a current list of every person who can open the folder where the drawings live. Auditors read artifacts, not intentions.
It is also a different discipline from defending the machines themselves, which we covered separately in what Texas manufacturers get wrong about OT/IT security. Securing a PLC and evidencing an access decision are 2 different projects with 2 different owners. Different skills. Different budgets. Plants that treat them as one job usually finish neither.
The 4 rulebooks a DFW manufacturer answers to

Almost every compliance conversation in a DFW plant is really about 1 of 4 documents. Just 4. They overlap, they use different vocabulary for the same control, and only 1 of them ends in a certificate.
| Rulebook | What triggers it | What it demands from IT | Enforced by |
|---|---|---|---|
| ITAR, 22 CFR parts 120 to 130 | Manufacturing or exporting an item on the US Munitions List | DDTC registration, US-person-only access to technical data, FIPS-validated encryption, 5-year records | State Department, through DDTC |
| NIST SP 800-171 via DFARS 252.204-7012 | A defense contract or subcontract carrying controlled unclassified information | 110 controls, a system security plan, a POA&M, a current SPRS score, 72-hour incident reporting | Department of War contracting officers |
| Texas SB 2610 | Holding sensitive personal information on Texas residents | A written cybersecurity program scaled to headcount, in exchange for safe-harbor protection | Texas Attorney General |
| Prime contract flow-downs | Signing the purchase order | Whatever the prime’s own program requires, frequently stricter than the regulation itself | Your customer, through audit and lost work |
Only 1 of those 4 has a certificate at the end. That is roughly why the other 3 keep getting postponed. The Texas piece is the newest and the least understood, and we walked through the headcount tiers in the Texas data storage compliance checklist.
ITAR is an IT problem, and DFW shops find out late

ITAR is the one that surprises people. Everyone assumes it governs shipping. It governs data. Drawings, specs, process sheets.
The registration rule that catches machine shops
Read 22 CFR 122.1 and it requires registration from any person who engages in the United States in the business of manufacturing defense articles. Then it adds a sentence that ends most of the arguments we have on this topic. A manufacturer who does not engage in exporting must nevertheless register. Read that twice.
So the shop in Carrollton that cuts a bracket for a missile program, trucks it 20 miles to a prime, and never touches a customs form, still registers with the Directorate of Defense Trade Controls. Tier 1 registration runs $3,000 a year under 22 CFR 122.3. Cheap, next to the alternative.
Deemed exports, or why your help desk is an export control function
A deemed export happens when a foreign person inside the United States is given access to controlled technical data. No border gets crossed. No package ships. The moment a non-US person can open the file, the regulation treats it as an export to that person’s home country.
Now count the access paths honestly. Your engineers, obviously. Your systems administrator, your backup software, your ERP vendor’s support team when they remote in to fix a posting error, and the overnight help desk queue your IT provider may or may not staff offshore. Count them. Every one is a way into the drawing folder, and the regulation does not care that the access was incidental to a support ticket.
That is the strongest operational reason not to buy IT support from a provider that quietly runs its after-hours queue from another country. Ask the question directly. Get the answer in writing.
The encryption carve-out that makes cloud storage workable
For years the standard advice was that ITAR data could not live in the cloud at all. That advice is out of date. It costs shops money they do not need to spend. Under 22 CFR 120.54(a)(5), sending or storing unclassified technical data is not an export at all when 4 conditions hold together.
- The data is unclassified
- It is secured using end-to-end encryption, so it is never in unencrypted form between the originator and the intended recipient
- The cryptographic modules comply with FIPS 140-2 or a successor, or provide security strength at least comparable to AES-128
- It is not intentionally sent to, stored in, or sent from a country proscribed under 22 CFR 126.1
The definition in the same section carries the sting. Read it closely. The means of decryption are not provided to any third party. That excludes any arrangement where your cloud provider holds the keys. All of them.
In the past we gave clients the loose version of this and had to walk it back, so here is the precise one. Encrypted at rest is not end-to-end encrypted. Not the same thing. If your provider can decrypt your files to run search indexing or malware scanning, the carve-out does not cover you, and a default commercial Microsoft 365 tenant falls on the wrong side of that line without additional client-side encryption or customer-managed keys.
Where CMMC actually stands in August 2026
On July 13, 2026, the Department of War suspended Phase 2 of CMMC implementation, which had been due to take effect on November 10, 2026. A reform task force opened a 60-day review, and the public comment window closed on August 14, 2026.
Plenty of shops read that as permission to stop. It is not. Read what did not change first.
- Phase 1 self-assessment requirements, in force since November 10, 2025, still apply
- DFARS 252.204-7012 still requires NIST SP 800-171 implementation on any contract carrying CUI
- The 72-hour cyber incident reporting clause is untouched
- Your SPRS score still has to be current, and primes still read it before they award
- Your prime’s supplier requirements are a contract term, not a federal rule, and no pause in Washington edits your purchase order
A pause on third-party assessment is not a pause on the underlying controls. The full sequence, phase by phase, sits in the CMMC 2.0 compliance timeline for Texas defense contractors.
Why downtime is a compliance event, not just a production event

Most plants price downtime in units not produced. That is the smaller number. Far smaller. Ransomware still appears in the majority of manufacturing breaches in the 2026 Verizon Data Breach Investigations Report manufacturing snapshot, and a plant that gets encrypted is rarely just losing shifts.
When a defense supplier’s environment goes down, 3 clocks start at the same time.
- The reporting clock. DFARS gives you 72 hours to report a cyber incident affecting covered defense information. That is 72 hours to report, not 72 hours to understand what happened.
- The evidence clock. Logging stops when the log server stops. Restore from a backup taken before the intrusion and you may have written over the forensic record the auditor is going to ask for.
- The delivery clock. Miss a milestone on a defense subcontract and the conversation moves from IT to contract performance very quickly, and it moves there without you.
Recovery objectives on a regulated plant network are not only about how fast the line restarts. They are also about whether the restart preserved your ability to answer questions afterwards. Different goals. The second one is usually missing from the runbook. We break down the production side of the math in the cost of IT downtime.
What a compliant DFW plant network actually looks like

Strip the frameworks down and the same 8 things show up in all of them. Every framework.
- A named inventory of every system holding technical data or CUI, including the machines nobody logs into anymore
- Segmentation between the business network and the plant floor, enforced at a boundary rather than implied by a VLAN tag
- Role-based access to drawing repositories, reviewed quarterly, with a written record of who approved each grant
- US-person status verified and recorded for every account that can reach controlled data, service and vendor accounts included
- Multi-factor authentication on remote access, email, and every administrative account without exception
- FIPS-validated encryption for controlled data at rest and in transit, with keys your organization controls
- Immutable, offline-capable backups proven by an actual restore test rather than a green checkmark on a dashboard
- Centralized logging retained long enough to survive a slow investigation, which in practice means a year or more
Nothing on that list is exotic. All of it is boring. Boring is what passes an audit, and the plants that struggle are almost never the ones missing an expensive tool. They are the ones who cannot say who has access to what. If the plant floor side of this is where you are weakest, start with manufacturing cybersecurity in Texas.
What compliance costs against what a violation costs
| Line item | Cost | Notes |
|---|---|---|
| DDTC Tier 1 registration | $3,000 per year | Set by 22 CFR 122.3 and renewed annually |
| Fully managed IT with compliance support | From $138 per user per month | Uprite published Texas rate, co-managed from $100 |
| NIST 800-171 gap assessment | One-time project | Produces the SSP and POA&M a prime will ask to see |
| A single ITAR civil penalty | Up to $1,271,078 per violation | Or twice the transaction value, whichever is greater |
| BAE Systems settlement, August 13, 2026 | $36,000,000 across 104 violations | Half suspended, conditioned on remedial compliance spending |
That last row deserves a minute. It is 1 day old as this publishes, and the details are instructive rather than just alarming. The State Department announced the settlement on August 13, 2026, resolving 104 violations that included unauthorized exports of technical data to multiple countries, 1 of them China.
BAE voluntarily disclosed all but 1 of the alleged violations and cooperated fully with the review. It still signed a 36-month consent agreement, agreed to fund an external Special Compliance Officer for at least 24 months, and committed to an external audit of its ITAR compliance program. That is what full cooperation buys you at the top end of this industry.
BAE runs a compliance department larger than the entire headcount of most plants in this metroplex. If that program still produced 104 violations, the 60-person shop in Arlington running drawings off an open shared drive should not feel comfortable. Sit with that.
Where Uprite fits, and where we do not
We are a managed IT and cybersecurity provider. We are not an export control consultancy and not a certified third-party assessor. That is not our lane. We do not classify your parts against the US Munitions List and we do not file your DDTC registration. Your export control officer or outside counsel owns that work, and you should be suspicious of any IT company that says otherwise. Ask your counsel.
What we own is the network side of the answer. Segmenting the plant floor from the business network. Locking drawing repositories to verified US persons and producing the access review that proves it. Standing up FIPS-validated encryption and key management. Building backups that survive an encryption event and logging that survives an investigation. Running the help desk with US-based staff so the deemed export question has a clean answer. All of it evidenced.
Uprite has done this for Texas plants since 1999, with a team of 42 across Houston, San Antonio and Dallas-Fort Worth, ticket response measured in single-digit minutes, and a 120-day satisfaction guarantee. Our Dallas office is at 5757 Alpha Road.
For the service detail rather than the regulatory background, start with manufacturing IT services for Dallas. Start there. If the defense side is the pressing part, our CMMC and NIST 800-171 compliance services page covers the assessment path. And if you are still shortlisting providers for the metroplex generally, managed IT services in Dallas-Fort Worth is the place to start.
Find out what an auditor would find first
Book a Business Technology Assessment and we will map your environment against ITAR access control, NIST 800-171 and SB 2610 in one pass, then hand you the gap list. You keep the list whether or not you hire us.
Questions DFW manufacturers ask us about IT compliance
Does ITAR apply to us if we never ship anything overseas?
Yes. 22 CFR 122.1 requires registration from any person engaged in the business of manufacturing defense articles, and it states plainly that a manufacturer who does not engage in exporting must nevertheless register.
The export question and the registration question are separate. Registration follows from what you make. Whether you need a license follows from where the data or the hardware goes. A shop can be fully domestic, ship only to a prime in Fort Worth, and still owe DDTC an annual registration plus the access controls that protect the drawings. Both, not either.
Can we keep ITAR technical data in Microsoft 365?
Only where the encryption is genuinely end to end and your organization holds the keys. A standard commercial tenant, where Microsoft can decrypt your content to index and scan it, does not satisfy the 120.54(a)(5) carve-out on its own.
There are 2 workable routes. Neither is free. Move to a government cloud offering designed for this data, or add a client-side encryption layer so the plaintext never exists on the provider side. Either one needs documenting, because the carve-out is something you have to be able to demonstrate rather than assert.
Is CMMC dead now that Phase 2 is suspended?
No. The Department of War paused third-party assessment on July 13, 2026. DFARS 252.204-7012, the NIST 800-171 controls, the 72-hour reporting clause and your SPRS score all remain in force during the pause.
Treat the suspension as runway, not a cancellation. Shops that keep working through their POA&M during the pause will be ready when the assessment requirement returns. Shops that stop will be doing the same work later, under a deadline, at a worse price.
One of our engineers is a green card holder. Can he open the controlled drawings?
Yes. ITAR defines a US person to include lawful permanent residents, so a green card holder needs no export authorization to access controlled technical data. A worker in the United States on a temporary work visa is a different case.
What matters operationally is that you can evidence the determination. Write it down. Keep the status verification with the access grant, in the record, dated. When a prime asks how you control access to technical data, “we know our people” is not an answer that survives the follow-up question.
What does an ITAR violation actually cost a company our size?
Civil penalties run to $1,271,078 per violation or twice the transaction value, whichever is greater. For most small manufacturers, the debarment risk hurts more than the fine, because it removes future defense work entirely.
Penalties stack per violation rather than per incident. That is how a single mishandled data set becomes a 6-figure exposure. The BAE settlement announced on August 13, 2026 covered 104 separate violations and closed at $36 million.
Our prime says they will audit us. What will they actually look at?
Artifacts, mostly. Access records for controlled data, your system security plan, your POA&M, evidence that multi-factor authentication is enforced, and proof that a backup restore has been tested rather than assumed.
The uncomfortable pattern is that plants pass on tooling and fail on paperwork. Every time. The controls are usually there in some form. What is missing is the record showing they were there last quarter too.
How long does it take to get a DFW plant compliant?
Plan on 90 to 180 days for a mid-sized plant, assuming you can already identify where the controlled drawings live. Most of that window goes to access cleanup and segmentation, not to buying tools.
Budget is rarely the variable. What moves the schedule is whether anyone can produce an accurate list of systems and accounts on day 1. Plants that have that list finish near 90 days. Plants that have to build it from scratch land closer to 180.









