us-export-expert

Determine ITAR and EAR jurisdiction and screening requirements for cloud deployments.

367|83|Updated Dec 26, 2025
One-click install
npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill us-export-expert-grcengclub
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: us-export-expert
Source: https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/frameworks/us-export/skills/us-export-expert
Command: npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill us-export-expert-grcengclub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

US export-control guidance and actionable checkpoints for ITAR and EAR, helping security, compliance, and engineering teams determine jurisdiction, classify items, and design compliant cloud deployments.

Core Features & Use Cases

  • Framework mapping: ITAR vs EAR jurisdiction determination, licensing posture guidance, and crosswalks for export controls.
  • Encryption & residency guidance: FIPS encryption standards, data residency considerations, and CSP attestations.
  • Operational guidance: Denied-party screening, logging recommendations, and marking/ tagging strategies for controlled data.

Quick Start

Provide a compliant ITAR/EAR posture for a new cloud workload.

Frequently Asked Questions about us-export-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine ITAR or EAR jurisdiction for a new cloud workload?

Determining ITAR or EAR jurisdiction involves mapping workload items to defense-related or dual-use categories. The Skill provides framework crosswalks and licensing posture guidance to classify cloud deployments and identify applicable export-control requirements.

What encryption standards are required for EAR export-controlled data in the cloud?

EAR export-controlled data in the cloud requires FIPS 140-2 encryption standards. The Skill specifies FIPS encryption requirements alongside CSP attestation guidelines to ensure compliant data residency and protect controlled technologies.

Can I deploy ITAR-controlled workloads to public cloud environments?

Deploying ITAR-controlled workloads to public clouds requires specific data residency configurations and denied-party screening. The Skill outlines explicit cloud deployment requirements and cross-framework mitigations for production-ready compliant architectures.

What is denied-party screening and when do I need it for export compliance?

Denied-party screening checks entities against restricted export lists. It is required for ITAR and EAR export compliance when deploying defense-related items or dual-use technologies, and the Skill provides operational guidance for implementing these checks.

How do I tag and log controlled data to meet ITAR and EAR requirements?

Tagging and logging controlled data for ITAR and EAR requires specific marking strategies and operational logging recommendations. The Skill delivers actionable checkpoints to help engineers implement tracking mechanisms for export-controlled architectures.