If your company is building hardware under a defense contract or a government-funded research program, the engineering partner you choose matters as much as the engineering itself. Before a single drawing is reviewed, these two acronyms determine whether a partner is even eligible to help: ITAR and CMMC. Let’s examine what they mean, why they matter in product development, and how Porticos is positioned on both.
What Is ITAR?
The International Traffic in Arms Regulations (ITAR) control the export of defense articles, defense services, and related technical data listed on the U.S. Munitions List. Any company that designs, manufactures, or handles technical data for defense-related hardware, including radios, munitions components, and satellite communications equipment, typically needs to be ITAR registered. For a product development partner, this is not a paperwork exercise; it determines who is legally allowed to see your drawings, test data, and design files in the first place. Porticos is ITAR registered, so our engineering teams can join export-controlled programs without adding a compliance gap to your supply chain.
What Is CMMC Level 2?
The Cybersecurity Maturity Model Certification (CMMC) is the DoD’s framework for protecting Controlled Unclassified Information (CUI). This category of information includes most technical data generated during defense-related product development, including CAD files, test reports, and requirements documents. CMMC Level 2 requires implementing all 110 security controls in NIST SP 800-171 Revision 2, covering areas like access control, incident response, and system monitoring.
As of mid-2026, CMMC Level 2 compliance is verified through self-assessment, with results submitted to the Supplier Performance Risk System (SPRS). The planned move to mandatory third-party (C3PAO) assessment was paused in July 2026 while the Department conducts a broader program review. Porticos has completed its CMMC Level 2 self-assessment and treats the underlying NIST 800-171 controls as the operating standard for how we handle CUI today, regardless of how the certification pathway evolves.
Why This Matters During Product Development
Compliance conversations often get treated as an IT department problem. In product development, that framing misses where the actual exposure sits. CUI is created the moment an engineer opens a CAD model, writes a test protocol, or documents a failure mode for a government-funded program, long before anything reaches a formal document management system. A development partner without the right controls in place is a CUI handling risk for your organization.
- Design data such as CAD files, FEA models, and DFM documentation frequently qualifies as CUI on defense and government-funded programs.
- Test results and engineering reports often contain performance data that is itself export-controlled or CUI.
- Email and file-sharing habits that are fine for a commercial program can create a compliance gap the moment a program touches CUI.
How Porticos Handles This in Practice
Porticos backs its ITAR registration and CMMC Level 2 self-certification with operational controls that embed compliance best practices:
- End-to-end encrypted, access-controlled CUI handling using PreVeil, aligned to NIST SP 800-171 control requirements.
- Documented CUI handling procedures and staff training, verified through our internal Annual Management Review.
- A network enclave and associated laptops allocated specifically for CMMC-impacted projects.
- A history of working directly inside export-controlled and defense programs.
A Track Record, Not Just a Certification
Porticos has supported defense, export-controlled, and government programs for over a decade. Our experience includes continuous mechanical, hardware, and firmware design work on L3Harris tactical radios since 2010, full product design and manufacturing support for Iridium satellite handsets (including a unit built specifically for the U.S. Government), and engineering relationships with NAVSEA, Raytheon, Sierra Nevada Corporation, etc. Porticos has also been awarded a Department of Homeland Security Phase 1 SBIR and a Department of Energy award under the American Recovery and Reinvestment Act.
What This Means for You
If your company anticipates funding tied to a defense contract, SBIR/STTR award, or other government-funded program, your next engineering partner needs to clear the ITAR/CMMC bar before technical fit is even on the table. Porticos already has, and brings decades of experience along with it.
Ready to talk about your program? Contact Porticos to discuss ITAR and CMMC compliant product development support for your defense or government-funded program.




