Why Most Defense Contractors’ Compliance Model Is Broken (And Why It’s Costing You Money)

By Nicholas Thorne, PhD, Director of Solutions Development, Defense Trade Solutions. Nick brings deep expertise in export licensing and authorizations for U.S. defense companies, paired with an academic background teaching international relations and arms trade policy at the University of Arizona.

You shipped a radar system to a foreign military customer under a DSP-5 permanent export license. That license cleared the hardware. Nothing more.

Now the customer wants integration support.

You go back to the DSP-5 and realize it only cleared you for the export of the hardware. Does a DSP-5 permanent export license cover post-delivery integration support? No. You have no authorization to provide the integration support your customer needed yesterday.

This is where defense contractors get blindsided as bad as a Cleveland Browns quarterback—and it’s where most companies that treat export compliance as a transactional relationship fail, sometimes badly enough to close shop.

Here’s how it typically unfolds. Sales asks one narrow question: “Can we export this radar to a foreign military customer?” Whoever owns exports confirms a DSP-5 will cover the hardware, preps the application, and files it with DDTC. Done.

That one question, answered cleanly.

But it was never just one question.

Once the radar arrives in-country, the customer asks for integration support: “Can you send engineers to help us integrate this with our air defense network?”

Is that request covered by the original license? No; it’s a separate authorization. That post-delivery work is a defense service under 22 CFR § 120.32(a), a different pathway entirely from the hardware export. You need either a Technical Assistance Agreement (TAA) for ongoing work, or a DSP-5 limited-defense-service (LDS) exception, granted case by case under 22 CFR § 124.1(a), for time-bound work. 

Separate application, separate DDTC review, and weeks of delay while the customer waits.

You’ve just discovered, mid-commitment, that you only authorized half the engagement.

The One-Off Compliance Model Only Catches Fragments

Companies typically bring in export compliance advisors to answer specific, isolated questions:

  • Can we export this hardware?
  • Can we provide this service?
  • What’s our contract exposure here?

Each answer is answered in isolation, and each answer is tactically correct on its own. However, they rarely connect. The hardware classification doesn’t inform the services strategy. The services determination doesn’t shape the license language. And none of it accounts for deemed export risk: disclosure of controlled technical data to a foreign national, which counts as an export under ITAR even if nothing physically leaves the country. Something as ordinary as a foreign-national engineer sitting in on a technical review can trigger it. And the list goes on.

By the time all the pieces surface, you’re either operating without authorization, delaying customer delivery, or scrambling to unwind relationships.

Those gaps have a direct, measurable cost:

  • Customer relationship. Your customer expects post-sale support as a matter of course. Every day you spend discovering you’re not authorized to provide it reads as unreliability, not diligence.
  • Organizational frustration. Sales commits to a delivery date compliance never cleared. Engineering gets blocked waiting on a determination. Finance can’t forecast a date that hinges on a DDTC review nobody scoped in advance.
  • Velocity loss. Every authorization gap discovered after signature triggers a full new decision cycle: classification, drafting, DDTC review, that could have been resolved before the contract was signed. DDTC’s own published data puts average total processing time across license actions is 32 days once a complete application is filed, but that clock doesn’t start until you’ve noticed you need a second application. The real cost is the weeks lost before filing even begins, not the review itself. 
  • Scaled complexity. One misaligned relationship is a costly surprise. Five, across different customer types, is a systemic compliance failure.

GE Aerospace’s 2026 ITAR consent agreement shows what this failure mode looks like at scale: of the 116 violations in its $36 million settlement, 103 charges traced back to mismanaged DDTC authorizations, compounded across years and business units.

A Managed Service Relationship Maps the Whole Picture Upfront

Instead of answering questions as they come, map the entire engagement before customer commitment. 

This list covers the six areas that have to align before you sign: what’s authorized on the hardware side, what’s authorized on the services side, which license vehicle you’ll use, how the contract reflects it, who on either side has been screened, and who’s actually cleared to talk to the customer about it.

  1. Hardware export authorization: The DSP-5 permanent export license to the foreign military customer, with scope clearly defined.
  2. Services classification: Is the post-delivery work (integration, system optimization, training) a defense service under the ITAR? If so, which license pathway fits: a TAA or a time-bound DSP-5 LDS?
  3. Licensing strategy: If you’ll offer ongoing services, file for a Technical Assistance Agreement upfront. If support stays limited, structure it as a DSP-5 LDS with a defined scope.
  4. Contract framework: The master services agreement specifies exactly what’s authorized, under which license, with what controls. No gaps discovered mid-engagement.
  5. Deemed export screening: Screening protocols are in place before customer engineers interact with your staff during integration, so foreign-national access is flagged and managed upfront, not discovered informally.
  6. Personnel clearance: Your people know who’s authorized to provide defense services to foreign military customers and what they can disclose, so there’s no informal briefing that crosses a legal line.

When the customer asks for support three months post-delivery, you already know the answer. You execute on schedule, with no surprise delays, no choosing between the relationship and compliance.

Quick Reference

DSP-5 vs. DSP-5 Limited Defense Service vs. TAA: Which One Applies

  • DSP-5 (permanent export license): Covers the one-time, permanent export of unclassified hardware or technical data. It does not cover any ongoing support, training, or integration work.
  • DSP-5 Limited Defense Service (LDS): An exception to the standard DSP-5, granted at DDTC’s discretion under 22 CFR § 124.1(a), for a single, time-bound defense service tied to a specific, narrow scope of work.
  • Technical Assistance Agreement (TAA): The standard authorization for ongoing defense services or disclosure of technical data over the life of a program — the right instrument when support isn’t a one-off.

Frequently Asked Questions

Under 22 CFR § 120.32(a), a defense service includes furnishing assistance (including training) to a foreign person, whether in the U.S. or abroad, in the design, development, engineering, manufacture, production, assembly, testing, repair, maintenance, modification, or operation of a defense article—separate from, and not authorized by, a license covering the hardware itself.

When the work is ongoing rather than a single, time-bound engagement. A DSP-5 LDS exception can cover a narrow, limited defense service, but recurring integration support, training programs, or multi-year assistance need a TAA.

A deemed export occurs when controlled technical data is disclosed to a foreign national, even without anything physically crossing a border; for example, a foreign-national engineer reviewing a technical drawing or sitting in on a design review. It affects any program with foreign-national employees, subcontractors, or visiting partners with access to controlled information.

Key Terms

  • DSP-5: Permanent export license for unclassified defense hardware or technical data.
  • TAA (Technical Assistance Agreement): Authorization for ongoing defense services or technical data disclosure.
  • LDS (Limited Defense Service): A case-by-case DSP-5 exception for a single, time-bound defense service.
  • Deemed export: Disclosure of controlled technical data to a foreign national, treated as an export under ITAR regardless of physical location.
  • DDTC (Directorate of Defense Trade Controls): The State Department office that reviews and approves ITAR license and agreement applications.

This Is Why Managed Service Compliance Works

It’s not reactive: compliance is integrated into the customer engagement model from the beginning. You’re not hiring export compliance to answer questions one at a time; you’re embedding compliance into your business operations so questions don’t become crises.

Companies that scale defense relationships profitably don’t do it by getting lucky with point-in-time compliance reviews. They do it with compliance infrastructure embedded in customer qualification, contract structuring, and team protocols.

The strongest contractors have compliance advisors embedded in their business model continuously, not brought in transactionally. That’s the difference between surviving an audit and winning in market.

Talk to DTS Before You Sign

This is the model DTS runs for clients: not a series of answers to isolated questions, but full-engagement visibility that keeps programs moving without compromising compliance.

If your last engagement surfaced a gap like this after signature, talk to DTS about mapping the next one before it does.

Contact our team of compliance experts →

Defense Insights