Technology Transfer and Export Control · 5 of 5

Anti-tamper and system specific release requirements

← All Insights

In short

  • An offer containing critical program information cannot be made until the anti-tamper plan has written approval, and testing must finish 60 days before export.
  • A desire to be interoperable, or to support a weapons sale, is not sufficient justification for a communications security release.
  • Electronic warfare, identification, signals intelligence, cross domain and depleted uranium items each carry a separate written approval held outside the selling program office.
Published9 September 2026
Last reviewed9 September 2026
Sources current as of9 September 2026

1. A right the government reserves

Some technology is not withheld from a partner. It is delivered with a protection built into it. The manual states the position at the start of the chapter's anti-tamper section. The government "reserves the right to incorporate Anti-Tamper (AT) technologies and methodologies in weapons systems and components that contain Critical Program Information (CPI)" offered under any security cooperation program (SAMM C3.6.1).

Critical program information is defined as the capability elements that give a technical advantage and whose compromise would undermine military preeminence. It can sit in software algorithms, and it can sit in training or maintenance support equipment rather than in the end item itself (SAMM C3.6.1).

Planning for it normally happens long before a foreign sale. In the ordinary course of research, development and acquisition, the anti-tamper executive agent approves a plan before critical design review, and that plan is later tested through validation and verification (SAMM C3.6.1).

2. Two gates with dates attached

For a case, the requirement turns into two hard gates. The first is on the offer.

"An LOA that includes any weapons system or components that contain CPI may not be offered until the DoD ATEA has issued written approval of the AT plan" (SAMM C3.6.3). Where no plan exists yet, the program office "must submit an AT plan to the DoD ATEA at least 60 days prior to planned offer of an LOA" (SAMM C3.6.3).

The second gate is on the shipment. Testing "must be completed 60 days prior to hardware export", and export may not happen until final written concurrence that the testing was satisfactory has been issued (SAMM C3.6.3).

The cost sits on the case. The implementing agency must ensure that any necessary sustainment mechanisms and their costs are included in the offer document, and must certify compliance on the cover memorandum submitted for processing (SAMM C3.6.2).

3. Missile technology

The Missile Technology Control Regime is described as "an informal and voluntary international political arrangement designed to control the proliferation of rocket and unmanned aerial vehicle (UAV) systems and associated equipment and technology capable of delivering weapons of mass destruction" (SAMM C3.7.1). It is a political commitment rather than a treaty, but participating states have passed laws restricting the exports it covers.

Controlled items are annotated on the munitions list, and the screening runs early. On receipt of a request, and before the offer document is developed, the program office performs a technical review to identify controlled items in the case or in the program around it (SAMM C3.7.1.1.1). Reviewers must have completed an approved proliferation course.

For the most sensitive category the manual states a starting presumption against transfer. Policy stipulates a "strong presumption to deny" for surveillance and combat unmanned aircraft in the top regime category (SAMM C3.7.2.1). A twenty element assessment supports any request that proceeds, one of which asks why a manned aircraft or a lower category system would not meet the requirement.

4. Communications security and the two releases

Networked systems carry a separate approval chain, run by the Committee on National Security Systems and the National Security Agency. The manual describes the standard applied: transfers "are approved only when there is a clearly defined benefit to USG foreign policy, military, intelligence, or economic objectives" (SAMM C3.7.3.3.2).

It also rules out the two arguments that come most naturally to a program office. "A nation's desire to be interoperable with the United States, or to support the sale of a weapon system is not considered sufficient justification for release" (SAMM C3.7.3.3.2.2). Justification normally rests on a combatant command requirement to communicate securely, or on a foreign policy objective.

Approvals come in two forms, and the difference matters to a schedule.

  • Release in principle. A policy decision supporting a secure interoperability requirement. It "is not an approval to physically transfer any COMSEC product", and it is "required prior to any detailed discussions with the foreign nation regarding COMSEC products or associated COMSEC information requirements".
  • Release in specific. Approval "for release of a defined set (quantity and nomenclature) of COMSEC information, products, or services to a partner nation", required for most communication devices included with a platform sale.

Those approvals gate the paperwork as well as the hardware. A release in principle is needed before price and availability data containing such products is provided, and a release in specific before the offer document itself. For congressional notification, a release in principle is the minimum, unless the products are major defense equipment, in which case a release in specific is required first (SAMM C3.7.3.4.2). The notification process is described in congressional notification and what it is for.

Positioning equipment follows a different route again. User equipment for the precise positioning service is not a cryptographic controlled item, and the department's chief information officer is the release authority for it and for anti-jam technology (SAMM C3.7.3.3.3).

5. Systems with their own conditions

Several capabilities carry named requirements that sit on top of everything above.

  • Electronic warfare. The system, including its mission data file, must be approved for release and certified in writing before an offer. Where certification is outstanding, "Delivery cannot take place without this certification unless the FMS customer uses its own technical parametric performance data instead of DoD data".
  • Identification systems. Release follows the communications security process, and the equipment and the installed platform must each be certified against the applicable standards. The offer document must identify the components and state whether the platform has been or will be certified.
  • Signals intelligence. A foreign disclosure review is required on every offer document containing it, and "NSA must provide an Approval to Sell letter before SIGINT equipment and services can be offered on a LOA".
  • Cross domain solutions. Devices must be tested and certified, and their transfer approved, before the solution is offered.
  • Depleted uranium rounds. Where no standing authority exists, "a Presidential Determination is required to support the transfer", coordinated through the National Security Council.

The common shape is easy to miss in the detail. Each of these is a written approval held by an organization outside the selling program office, obtained on its own timescale, and each is a precondition to a step the buyer can see. What is delivered under them is then monitored, which is covered in routine and enhanced end use monitoring.

Key terms

Anti-tamperTechnologies incorporated to protect critical program information in a delivered system. SAMM C3.6.1.
ATEAThe anti-tamper executive agent, whose written approval gates both offer and export.
MTCRMissile Technology Control Regime, a voluntary arrangement controlling delivery system proliferation.
RIPRelease in principle, a policy decision that permits detailed discussion but not transfer.
RISRelease in specific, approval of a defined quantity and nomenclature for a partner.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Protected technology travels under conditions that continue after it lands. Sentfore provides protective security, secure movement, accommodation and site support around defense programs in complex environments, and its principals have worked on overseas defense and security programs. Requirements can be sent through the contact page.