us-export-expert

Provide ITAR and EAR export-control guidance for cloud deployments and encryption decisions.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill us-export-expert-rifh2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: us-export-expert
Source: https://github.com/rifh2000/claude-grc-engineering./tree/main/plugins/frameworks/us-export/skills/us-export-expert
Command: npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill us-export-expert-rifh2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

ITAR and EAR compliance challenges are mitigated by this skill through expert export-control guidance and structured decision support.

Core Features & Use Cases

  • Comprehensive ITAR and EAR framework guidance for risk assessment, classification, and implementation.
  • Guidance on data residency, encryption, logging, and third-party access controls across cloud providers.
  • Real-world scenarios and checklists for onboarding, procurement, and post-deployment audits.

Quick Start

Request a compliant ITAR/EAR plan for your cloud deployment, covering classification, data residency, encryption, logging, and access controls.

Frequently Asked Questions about us-export-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I navigate ITAR and EAR export controls for cloud deployments?

You can navigate ITAR and EAR export controls for cloud deployments by generating a structured compliance plan covering USML classification, data residency, encryption, and access controls to align with DDTC and BIS guidance.

What is ECCN classification and when do I need it for data residency?

ECCN classification determines export control requirements for your data and technology. You need it when planning data residency to ensure cloud storage and processing comply with EAR regulations across international boundaries.

Does my encryption approach need to meet FIPS standards for EAR compliance?

Yes, EAR compliance often requires FIPS-validated encryption for securing technical data. Implementing FIPS encryption helps meet export control exemptions and secure your cloud infrastructure against unauthorized access.

How do I perform denied party screening for third-party access?

Perform denied party screening by validating all third-party users and entities against restricted lists before granting access. This process mitigates ITAR and EAR violations by ensuring unauthorized parties do not receive controlled technical data.

What is the best way to prepare for a post-deployment ITAR audit?

The best way to prepare for a post-deployment ITAR audit is to maintain comprehensive logging, verify CSP attestations, and review access controls against USML categories to ensure continuous compliance with DDTC requirements.

Can I use standard cloud providers for ITAR-controlled technical data?

You can use cloud providers for ITAR-controlled data if they provide sufficient CSP attestations, support required data residency boundaries, enforce strict access controls, and enable necessary logging to meet DDTC compliance standards.