How cloud PDM supports EAR and dual-use workflows and where its limits begin.
Cloud PDM can support an export-control programme by limiting access to engineering data, preserving revision history, enabling controlled external collaboration, and recording selected platform activities. It cannot determine EAR or ITAR jurisdiction, assign ECCNs, screen restricted parties, obtain licences, or decide whether a transfer is authorised.
Space-tech companies therefore need to combine technical controls with item-by-item classification, legal review, restricted-party screening, employee training, and documented procedures. Before publication or operational reliance, organisations should have export-control content and workflows reviewed by qualified export-control counsel or an authorised internal export-control specialist.
Introduction: Export Controls in the New Space Economy
Space technology is moving fast. Private companies are building satellites, launch systems, robotics, advanced sensors, ground equipment, propulsion-related components, and mission-critical software for commercial and government markets.
Many of these products are not weapons. However, space and advanced hardware technologies can still be sensitive because they may have both civilian and military applications. That is why export-control compliance matters for companies that build, store, or share engineering data related to space systems and other dual-use hardware.
This article focuses on EAR and dual-use engineering-data workflows for commercial space and hardware teams. It explains where cloud PDM can help, which responsibilities remain with the exporter, and what companies should validate before storing or sharing controlled CAD data.
EAR and EU Dual-Use Controls, with an ITAR Boundary Note
For some commercial space and hardware teams, the main export-control framework will be the Export Administration Regulations (EAR), including the Commerce Control List (CCL) and the EAR’s defined terms such as "technology" and "source code." Some commercial spacecraft and related items are controlled under the EAR. Certain defence-related, military, launch, propulsion, or specially designed items may instead fall under ITAR or stricter EAR controls. Where ITAR may apply, companies should obtain a formal jurisdiction and classification review rather than rely on a workflow article. [1]-[3]
For companies exporting from the European Union, Regulation (EU) 2021/821 controls exports, brokering, technical assistance, transit, and transfer of dual-use items. It shares the broad objective of controlling sensitive dual-use technology but is not equivalent to the EAR: it has its own scope, authorisations, catch-all provisions, cyber-surveillance rules, and member-state implementation requirements. This article uses "engineering data" as a general description unless a specific regulatory definition is required; ITAR commonly uses the term "technical data," while the EAR uses defined terms including "technology" and "source code." [4][1][3]
Questions to Answer Before Sharing Engineering Data
If the EAR applies, which ECCN and technical thresholds are relevant?
Could any defence-related, military, launch, propulsion, or specially designed items require a separate ITAR jurisdiction review?
Is the information required for the development, production, or use of a controlled item?
Who will receive it, where are they located, and what is their applicable nationality or permanent-residence status?
What is the intended end use and end user?
Do sanctions, restricted-party, military end-use, or other controls apply?
What licence, exception, or other authorisation supports the transfer?
Satellite Export-Control Reform and the 2024 BIS Updates
Following earlier legislative authority, the U.S. Departments of State and Commerce published rules in May 2014 that moved many commercial satellites and related items from the USML to the CCL. The changes became effective in phases during 2014. They made the EAR more relevant to many commercial satellite companies, but they did not remove all space-related items from ITAR. [5]
In October 2024, the Bureau of Industry and Security (BIS) released three separate space-related actions. Their legal status matters; proposed provisions should not be treated as final. [9]
BIS action
Status
Practical takeaway
Removal of licence requirements for certain spacecraft and related items for Australia, Canada, and the United Kingdom
Final rule; effective 23 October 2024
Removes specific EAR licence requirements for covered items and destinations. Check ECCNs, conditions, and exclusions.
Revisions to space-related export controls
Interim final rule; effective 23 October 2024
Changes and clarifies selected controls. Review the operative text before changing internal procedures.
Proposed License Exception Commercial Space Activities (CSA) and related revisions
Proposed rule
Do not rely on proposed provisions unless and until they are adopted in a final rule.
These actions may reduce licensing friction for particular items and destinations, but they do not mean that commercial satellites are generally free from export controls. Eligibility depends on the item, ECCN, destination, end use, end user, conditions, exclusions, and final rule status. [9]
Export-Control Workflow at a Glance
Identify engineering data
Determine jurisdiction and classification
Screen the recipient and end use
Confirm the required licence, exception, or other authorisation
Configure PDM and identity access
Share the approved revision
Review activity records and retain required records
Where Export-Control Risk Appears in Engineering Work
Export-control risk can arise before a physical product is shipped. CAD files, assemblies, drawings, manufacturing specifications, firmware, source code, test procedures, performance data, and release packages may require review before they are shared. Not every file is controlled; public information, fundamental research, and other exclusions or exemptions depend on the facts and applicable regime.
International collaboration
When controlled engineering data is shared with a foreign person or entity, the company must consider whether an export, reexport, transfer, or release has occurred and whether authorisation is required. Cloud access can raise the same questions when foreign users or locations can receive controlled data. The answer depends on the data, access model, users, locations, and applicable rules.
Deemed exports
A release of controlled EAR technology or source code to a foreign person in the United States can constitute a deemed export. Whether authorisation is required depends on the technology, classification, the person's applicable nationality or permanent-residence status, available exceptions, and other regulatory factors. U.S. permanent residents and protected persons may be treated differently. Access should therefore be tied to documented authorisation, not merely to team membership. [6]
Evidence and recordkeeping
A company may need to show which files were classified, who received access, which revisions were shared, which permissions changed, and what authorisation supported the activity. Under the EAR, required records generally must be kept for five years from the latest applicable date identified in Part 762, including section 762.6. [7]
Export-control violations can lead to civil, criminal, and administrative penalties, including denial of export privileges. Because civil penalty maxima are adjusted, organisations should check the current EAR and BIS enforcement guidance rather than rely on a fixed amount in a blog article. [8]
What Cloud PDM Can Help With — and What It Cannot Replace
Cloud PDM is a supporting system for export-control workflows. It can help enforce customer-defined controls, but it does not make legal determinations.
Compliance requirement
Cloud PDM contribution
Additional control required
Jurisdiction and classification
Store classification information if supported.
Export specialist or counsel assigns jurisdiction and ECCN.
User access
Roles, project permissions, and controlled workspaces.
Identity, nationality, permanent-residence, and licence-authorisation process.
External collaboration
Guest access, scoped sharing, and version control.
Approved sharing process and documented authorisation.
Geographic restrictions
May integrate with identity, network, or endpoint controls depending on the environment.
IdP, geofencing, VPN, network, endpoint, or DLP tooling.
Restricted-party screening
Not a normal PDM function.
BIS, OFAC, EU, UK, UN, or other screening tools and procedures. [10]
Audit evidence
Records supported platform activities.
Confirm event coverage, retention, exportability, and evidentiary requirements.
Export authorisation
May attach or store supporting records if supported.
Legal review, licence exception analysis, or government licence.
Training and procedures
May host workflow documentation or approval records.
Compliance programme, training, escalation, and periodic review.
The goal is to connect compliance decisions to operational controls. A spreadsheet of approved users is not enough if collaboration tools still allow broad access to controlled files.
How Cloud PDM Supports Export-Control Workflows
Role-based and project-based access
Sensitive engineering data should not be accessible simply because someone belongs to the company workspace. Access should be scoped by project, role, need-to-know, and documented authorisation.
User type
Typical access need
PDM control
Internal engineer
Edit assigned project files
Project-level permissions
External supplier
Access approved release package
Scoped guest access
Customer reviewer
Review selected documentation
Controlled external sharing
Compliance lead
Review relevant activity records
Audit or activity visibility
Contractor
Limited access to assigned work
Role-based restrictions
Secure external collaboration
Hardware teams often need to share design files with suppliers, manufacturing partners, certification bodies, and customers. Email attachments and unmanaged file links create risk because they are difficult to track and revoke.
Invite external users into specific collaboration spaces
Limit access by role or project
Share selected files or versions
Revoke access when a project ends
Review supported activity records
Before using any platform for export-controlled data, companies should validate whether the platform supports the exact access, logging, download-control, retention, and hosting requirements required by their programme.
Revision history and release traceability
Export-control compliance often depends on knowing exactly which version of a file was shared. A small design change can affect classification, performance, or licence scope.
Revision history helps teams answer:
Which version did the supplier receive?
Was the shared file approved?
Who made the change?
When was the file released?
Did the external partner receive the latest version or an older one?
This traceability is especially important for aerospace and other regulated hardware environments.
Audit and activity records
Audit records can help companies monitor supported platform activity, investigate issues, and prepare evidence for internal or external reviews.
However, companies should avoid assuming that every platform records every event. Before relying on audit records for export-control evidence, confirm:
Which file events are recorded
Whether views, downloads, uploads, deletions, and permission changes are logged
Whether external sharing events are logged
Whether authentication events are logged
Whether failed attempts or location data are available
Whether logs can be exported
How long records are retained
Whether logs are tamper-resistant or otherwise meet evidentiary requirements
CAD ROOMS Export-Control Support
CAD ROOMS is a cloud-native PDM & PLM platform for engineering teams. It can support customer-managed export-control workflows through role-based permissions, project and workspace access control, revision history, controlled external collaboration, documented activity history, encryption, SAML SSO options, and Enterprise hosting or regional data-residency options. [11]
For companies working with sensitive space-tech or dual-use data, CAD ROOMS can help with:
Role-based permissions: Teams can manage who has access to projects, files, and collaboration spaces.
Project and workspace access control: Sensitive work can be separated by project or workspace structure to reduce unnecessary exposure.
Revision history: Teams can track file changes and understand which version was reviewed, shared, or released.
Secure guest collaboration: External partners can be invited into controlled collaboration workflows instead of relying on unmanaged email attachments or generic file links.
Documented activity: Supported activity history can help teams review documented project events such as contributions, role changes, and ECO releases. Event coverage, retention, and exportability should be validated for the intended compliance use case.
Enterprise hosting options: Enterprise customers can discuss hosting, regional data residency, identity, security, and access-control requirements with the CAD ROOMS team.
CAD ROOMS does not classify technology, assign ECCNs, determine ITAR versus EAR jurisdiction, screen restricted parties, decide whether a licence is required, or provide legal advice.
Capabilities such as ECCN-specific workflow automation, citizenship or nationality attributes, geofencing, watermarking, DLP, failed-login location logging, suspicious-access alerts, bulk classification updates, export-licence authorisation tracking, or immutable-log requirements should be validated directly with the CAD ROOMS product and security teams before they are promised to customers or relied on for a compliance programme.
Practical Workflow: Managing Controlled Engineering Data in PDM
A practical export-control workflow can look like this:
Identify sensitive projects. Flag work that may involve controlled products, components, software, or technical data.
Determine jurisdiction and classification. Confirm whether ITAR, EAR, EU dual-use, or another regime applies.
Document classification decisions. Record ECCNs, USML categories, legal analysis, licence determinations, or internal control labels as appropriate.
Limit access by need-to-know. Grant access only to users with documented business need and authorisation.
Control external sharing. Use scoped guest access or secure collaboration spaces instead of unmanaged file transfers.
Screen external parties. Use appropriate restricted-party, sanctions, and end-use screening processes outside the PDM.
Review supported activity records. Review available activity records for supported events, such as contributions, role changes and releases, and validate whether external-collaboration events are recorded.
Retain required records. Maintain classification, screening, licence, authorisation, training, and audit records according to applicable rules.
Reassess after changes. Review controls after regulatory updates, product changes, new destinations, or new external partners.
This workflow helps turn export-control compliance from a one-time legal review into a repeatable operating process.
Real-World Scenarios for Space-Tech Companies
Scenario 1: Satellite Manufacturer Sharing CAD Files With a European Partner
A U.S. satellite manufacturer is working with a European aerospace partner. Some satellite subsystem files may be controlled under the EAR, while others may require further jurisdiction analysis.
Compliance challenge: The team needs to collaborate internationally without giving broad access to all technical data.
PDM approach:
Classify files before sharing
Create a dedicated partner workspace or project area
Share only approved files and versions
Limit access to authorised users
Preserve supported activity records
Keep legal and screening documentation outside or alongside the PDM as required
Scenario 2: Launch or Propulsion Company With a Distributed Engineering Team
A launch, propulsion, or avionics company has employees and contractors in multiple countries. Some technical data may remain ITAR-controlled or subject to strict EAR controls.
Compliance challenge: The company needs to prevent unauthorised releases of controlled technology while still enabling productive engineering work.
PDM approach:
Separate highly sensitive files from general project documentation
Apply role-based access by subsystem
Review authorisation before granting access
Validate whether the platform logs the events the compliance team needs
Revoke access promptly when contractors leave the project
After a regulatory update, a company determines that some space-related components may qualify for different treatment when exported to specific destinations.
Compliance challenge: The company needs to update classifications and permissions without losing historical traceability.
PDM approach:
Identify files with affected classifications
Update internal tags or records after legal review, if supported
Adjust access policies if needed
Preserve previous records for audit purposes
Notify project teams of the updated workflow
Best Practices for Export-Control Compliance
Technology is only one part of compliance. Hardware companies should also establish a formal process that includes people, policies, and documentation.
Build a Written Compliance Programme
A strong export-compliance programme should define:
Who owns export compliance internally
How jurisdiction and classification are determined
How licence requirements are reviewed
How restricted-party screening is handled
How external sharing is approved
How controlled data is stored
How records are retained
How employees are trained
How incidents are escalated
Classify Products and Technical Data
Companies should review products, software, and engineering data against the relevant control lists. When classification is uncertain, teams may need help from export counsel or a formal classification request.
Classification decisions should be documented and revisited when products, software, engineering data, destinations, or regulations change.
Screen Customers, Suppliers, and Partners
Before sharing controlled data or shipping products, companies should screen relevant parties against restricted-party lists, sanctions lists, and applicable end-use or end-user controls.
This process may apply to customers, suppliers, distributors, investors, contractors, and other external collaborators.
Train Employees
Engineers, product managers, sales teams, and operations staff should understand how export controls affect daily work.
Training should cover:
What types of engineering data may be controlled
Why cloud access can involve export-control issues
How to share files securely
When to involve compliance or legal teams
What to do if a mistake occurs
Maintain Required Records
Export-control compliance requires records, but retention obligations depend on the applicable regulation and the type of record. Under the EAR, required records generally must be retained for five years from the later of the relevant dates specified in EAR Part 762, including § 762.6. [7]
Companies should maintain documentation related to:
Conclusion: Compliance Needs Process, Proof, and Control
Export-control compliance is an ongoing responsibility for space-tech and hardware companies. It requires item-by-item classification, disciplined access management, secure collaboration practices, screening, training, legal review, and reliable records.
Cloud PDM can help by operationalising customer-defined controls: limiting access, preserving revision history, supporting secure collaboration, and recording selected platform activities. It does not replace export-control counsel or determine whether a transfer is authorised.
CAD ROOMS helps engineering teams protect product data, collaborate securely, and maintain traceability across the product lifecycle. To learn how CAD ROOMS can support secure collaboration and compliance-ready workflows, schedule a demo with our team.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Export-control regulations are complex and subject to change. Companies should consult qualified export-control counsel before making jurisdiction, classification, licensing, or export decisions.
Frequently Asked Questions
Q: Is commercial space technology controlled by EAR or ITAR?
A: It depends on the item and technical data. Some commercial spacecraft and related items are controlled under the EAR, while some launch, propulsion, military, defence-related, or specially designed items may remain subject to ITAR or stricter EAR controls. Jurisdiction and classification must be determined item by item.
Q: Does uploading controlled CAD data to the cloud constitute an export?
A: Uploading data to a cloud system can raise export-control questions, especially if controlled technology may be accessed by foreign persons, foreign locations, or external partners. Whether an export, reexport, transfer, or release occurs depends on the data, access model, users, locations, and applicable rules. Legal review is recommended.
Q: What is a deemed export?
A: A deemed export can occur when controlled technology is released to a foreign person inside the United States. Whether authorisation is required depends on the technology, classification, nationality or permanent-residence status, available licence exceptions, and other regulatory factors. Access should be tied to documented authorisation. [6]
Q: Can CAD ROOMS be used in an EAR-controlled engineering workflow?
A: CAD ROOMS can support customer-managed EAR workflows through role-based permissions, project and workspace access control, revision history, controlled guest collaboration, documented activity records, encryption, SAML SSO options, and Enterprise hosting or regional data-residency options. However, CAD ROOMS does not determine jurisdiction, assign ECCNs, screen restricted parties, obtain licences, or decide whether a transfer is authorised. Before storing controlled data, organisations should validate their hosting, identity, access, download, logging, and retention requirements with the CAD ROOMS product and security teams and qualified export-control counsel.
Q: What controls should a company validate before storing export-controlled CAD data?
A: Validate role permissions, project access controls, external sharing rules, download controls, SSO and identity controls, hosting location, event logging, log exportability, retention periods, backup policies, incident response, and whether the platform's records meet the organisation's compliance and evidentiary requirements.
I'm Christina Rebel, CEO of CAD ROOMS. For over a decade, I've worked at the intersection of cloud engineering collaboration, digital manufacturing, and distributed product development.
Throughout my career, I've worked closely with engineers, designers, and manufacturing teams to improve CAD data management, version control, supplier collaboration, and browser-based design review. My focus is on making modern engineering workflows more accessible, secure, and efficient, particularly for SMEs and startups. I also write about engineering collaboration, with contributed articles published by Design News and DEVELOP3D.
Christina Rebel is CEO of CAD ROOMS and Co-founder of Wikifactory. She has over a decade of experience in cloud engineering collaboration, digital manufacturing, CAD data management, and distributed product development. Her writing on modern engineering workflows has appeared in Design News and DEVELOP3D.