us-export-expert

Determine ITAR and EAR jurisdiction and screening requirements for cloud deployments.

367|83|Updated Dec 26, 2025
One-click install
npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill us-export-expert-grcengclub
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: us-export-expert
Source: https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/frameworks/us-export/skills/us-export-expert
Command: npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill us-export-expert-grcengclub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

US export-control guidance and actionable checkpoints for ITAR and EAR, helping security, compliance, and engineering teams determine jurisdiction, classify items, and design compliant cloud deployments.

Core Features & Use Cases

  • Framework mapping: ITAR vs EAR jurisdiction determination, licensing posture guidance, and crosswalks for export controls.
  • Encryption & residency guidance: FIPS encryption standards, data residency considerations, and CSP attestations.
  • Operational guidance: Denied-party screening, logging recommendations, and marking/ tagging strategies for controlled data.

Quick Start

Provide a compliant ITAR/EAR posture for a new cloud workload.

Frequently Asked Questions about us-export-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine ITAR or EAR jurisdiction for a new cloud workload?▼

Determining ITAR or EAR jurisdiction involves mapping workload items to defense-related or dual-use categories. The Skill provides framework crosswalks and licensing posture guidance to classify cloud deployments and identify applicable export-control requirements.

What encryption standards are required for EAR export-controlled data in the cloud?▼

EAR export-controlled data in the cloud requires FIPS 140-2 encryption standards. The Skill specifies FIPS encryption requirements alongside CSP attestation guidelines to ensure compliant data residency and protect controlled technologies.

Can I deploy ITAR-controlled workloads to public cloud environments?▼

Deploying ITAR-controlled workloads to public clouds requires specific data residency configurations and denied-party screening. The Skill outlines explicit cloud deployment requirements and cross-framework mitigations for production-ready compliant architectures.

What is denied-party screening and when do I need it for export compliance?▼

Denied-party screening checks entities against restricted export lists. It is required for ITAR and EAR export compliance when deploying defense-related items or dual-use technologies, and the Skill provides operational guidance for implementing these checks.

How do I tag and log controlled data to meet ITAR and EAR requirements?▼

Tagging and logging controlled data for ITAR and EAR requires specific marking strategies and operational logging recommendations. The Skill delivers actionable checkpoints to help engineers implement tracking mechanisms for export-controlled architectures.