Three different things that get written into one line of a purchase order. Each statement below links to the official source.
This is a plain-language reading list, not legal advice. Which requirements apply to your part comes from your contract and your own counsel.
Registration with the U.S. State Department’s Directorate of Defense Trade Controls (DDTC) is required of manufacturers, exporters and brokers of defense articles on the U.S. Munitions List. Registration is not an export licence and DDTC does not “certify” a company. Source · Shops with ITAR registration →
The clause requires contractors handling covered defense information to provide “adequate security” and to report cyber incidents to DoD within 72 hours; it points to NIST SP 800-171 for the security requirements. Source · Shops with DFARS 252.204-7012 →
The catalogue of requirements for protecting controlled unclassified information in non-federal systems, referenced by the DFARS clause. Source
The Department of Defense’s Cybersecurity Maturity Model Certification programme, which verifies those requirements at three levels; the level a contract needs is stated in the solicitation. Source · Shops with CMMC →
The aerospace quality management standard, audited by an accredited registrar; certificates name a scope and an expiry date. Source · Shops with AS9100 →
“ITAR certified” is not a thing — a shop registers with DDTC. “DFARS compliant” describes meeting the security requirements the clause points to, which CMMC then verifies. A shop can hold AS9100 and none of the others, or the reverse.
On BidMyPart, each of these appears on a shop page only with the sentence from the shop’s own site or certificate that states it, and we show the certificate’s expiry where the certificate gives one.