Build vs Buy ITAR and Export Control Software for Defense Manufacturers
If your exports are occasional and mostly EAR99 and you employ no foreign persons in engineering, buy screening software and stop there.
On this page
If your exports are occasional and mostly EAR99 and you employ no foreign persons in engineering, buy screening software and stop there. Build when you hold ITAR controlled technical data, employ foreign persons anywhere in the organisation, and cannot today produce a list of who opened a given drawing. That access question is what no packaged product answers.
The companies that should buy and go back to work
A machine shop that ships commercial parts, occasionally quotes something classified EAR99, and employs no foreign persons in engineering does not need a compliance platform. It needs restricted party screening, a written procedure, and a trade compliance analyst who reads the regulations. Descartes Visual Compliance is genuinely excellent at screening and will cost a fraction of any build. That is the whole answer, and a vendor telling that company otherwise is selling scope.
Buying is also right when your volume is customs paperwork rather than engineering data. If you are a large enterprise resource planning (ERP) shop whose exposure is export declarations, classification content for commercial goods and customs filings, SAP Global Trade Services is powerful and reproducing its content library would be an expensive way to arrive where you already are. E2open carries deep global trade content for the same reason. OCR Services EASE handles licence management competently.
Notice what those products have in common. They sit at the transaction, the shipment, the declaration and the counterparty. That is a legitimate and well served part of the problem, and it is where most companies exposure actually lives.
If you are in this group, the useful spend is not software at all. It is getting your classification decisions out of email and into a document your Empowered Official signs, and getting your screening set to rescreen rather than to screen once. Both are process changes and both close more risk per dollar than a platform.
When the access layer has to be yours
The build case rests on one uncomfortable fact. Under the ITAR, releasing controlled technical data to a foreign person is treated as an export to that person country even when it happens inside your own building in the United States. There is no shipment and no customs entry. The violation is a file being opened.
Preventing that requires three facts joined at the moment of access: what this data is classified as, who this person is in terms of citizenship and status, and whether a licence or agreement authorises release to that nationality. Trade compliance owns the first. Human resources (HR) owns the second. Information technology owns the enforcement point. Almost nowhere are the three joined, and no product in this category sits inside Windchill, Teamcenter, 3DEXPERIENCE, your file shares or your source repositories deciding whether this person may open this file right now.
Build when two or more of these are true. You hold ITAR controlled technical data and employ foreign persons anywhere in the organisation, including contractors and interns. You cannot produce, today, a report of everyone who accessed a given controlled drawing in the last year. Your classification determinations live in an analyst mailbox. You track licence and agreement drawdown in a spreadsheet updated after shipments have gone. Or you have already filed a voluntary disclosure and committed to remediation, in which case you need an auditable system rather than a better written procedure.
One honest limit. A build gives prevention where enforcement is technically possible and detection where it is not. Any vendor promising prevention across every tool you own is describing something that does not exist, and the difference between the two should be documented per system rather than glossed over.
What each path costs
Screening products are commonly priced with the software and the list content licensed separately, and screening itself charged per transaction or per named user. That pricing shape has a consequence worth naming: a full rescreen of your entire customer, supplier, forwarder, visitor and employee master is expensive by design, which is precisely why most companies screen once at onboarding and never again. The control you actually need is the one the pricing model discourages. Ask for rescreening economics explicitly at renewal.
Building carries a different shape of cost. A first release with a classification workspace tied to your part master, a person register joined to human resources for deemed export control, a licence and agreement register with drawdown, and an immutable access log runs $90,000 to $190,000 over 14 to 20 weeks. A full platform adding enforcement hooks into product lifecycle management and file storage, continuous rescreening with hit disposition, technical data transfer workflow, visitor and facility access, and audit and disclosure reporting runs $250,000 to $600,000 over 9 to 15 months.
Two cost drivers are unusual here. Compliant hosting is a real line item rather than a rounding error, particularly where contracts bring assessment obligations. And the number of systems needing enforcement is the multiplier people underestimate: engineering vault, file shares, email, source control, the enterprise resource planning system and the shop floor viewer are six integrations, not one.
The costs that nobody puts in the business case
Human resources data is the first and the most awkward. Your people system probably records a work authorisation flag and a country, but not the nationality and immigration status detail a deemed export decision needs, and privacy rules constrain who may see it and how it may be stored. Expect a project inside human resources to capture the missing attributes lawfully before the software can use them. Contractors are worse: many have no record in the people system at all, which means the register that governs access has a population it cannot see.
The second is retroactive classification. When a determination changes, every access already granted under the old answer becomes a question. A system that only holds current classifications cannot tell you who saw what under the previous one, and reconstructing it after the fact is exactly the work a voluntary disclosure demands. Effective dating has to be in the model from the start.
The third is the returned article. A unit comes back from an overseas customer for repair, arrives against a returned goods number, and lands on the shop floor because the receiving clerk saw logistics paperwork rather than a controlled article. That path bypasses every control built around engineering data, and it needs its own hook in receiving.
The fourth is timing. Where your contracts bring cybersecurity assessment obligations for controlled unclassified information, the hosting boundary, access model and logging have to be designed for that from the first sprint. Retrofitting an environment boundary is close to rebuilding the system, so the assessment date on your contract flow down is a hard input to the schedule.
A test that takes one afternoon and one drawing
Choose one controlled drawing, ideally an assembly with a supplier package built from it. Ask four questions and time the answers.
Who has opened this file in the last twelve months, by name and by nationality. Which classification determination applies to it, who approved that determination, on what date and under which citation. Which licence or agreement authorised each external release of it, and how much value remains on that authorisation. And if the determination were changed tomorrow, which prior accesses would become questionable.
Most defense manufacturers can answer the second question and struggle with the first. Very few can answer the fourth at all. Write down which of the four you could evidence to an auditor rather than assert, because that distinction is the entire subject. Then repeat the exercise on a drawing that was revised in the last year, since revisions are where classification inheritance quietly breaks.
How to sequence it, and one question to ask first
Ask this before anything else, in the first meeting with any developer: how will you keep controlled technical data away from your own team. The correct answer is immediate and specific. Development and testing on synthetic data containing no controlled technical data. A production environment in a United States region with access restricted to United States persons. Support access brokered and logged rather than standing. If a firm has to think about it, they have not built for a defense manufacturer, and hiring them is a plausible route to your first violation.
Sequence the build so classification and the person register come first. Together they are the foundation everything else needs, and they deliver value on their own by turning a mailbox of determinations into a queryable record. Enforcement integrations follow system by system, prioritised by where controlled data actually sits rather than by which interface is easiest.
Digital Heroes fixes the object model on paper first, classification determination, authorisation, party, person with nationality and status, controlled transaction and access event, so your Empowered Official reviews it while it is still a document. The firm has completed more than two thousand projects with a team past fifty people, holds Fiverr Vetted Pro status, and contracts through its US, UK or Indian arm so that both the signing party and the assignment of intellectual property match your compliance posture. Its YouTube channel carries 2.5 million subscribers.
Put ownership of the code, the repository and the cloud accounts in the contract before kickoff. You may need to demonstrate the control environment to an auditor or a government customer, and pointing at a system your vendor controls is not a demonstration.
If you would rather someone argued with your brief than agreed with it, Digital Heroes builds and runs its own products, so the people choosing your architecture live with those decisions on their own revenue. The document is yours whichever way you go.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Across 1,471 IT projects the average cost overrun was 27%, but one in six projects was a 'black swan' with an average cost overrun of 200% and a schedule overrun of nearly 70%. Source: Harvard Business Review (Bent Flyvbjerg & Alexander Budzier, University of Oxford) (2011) →
- In a survey of 579 supply chain professionals (July 31 to October 1, 2024), only 29% had built at least three of the five capabilities Gartner identifies as needed for future competitiveness (agility, resilience, regionalization, integrated ecosystems, and enterprise-wide strategy). Source: Gartner (2025) →
- The NRF discontinued its long-running annual shrink report, stating that a broad study of retail shrink 'is no longer sufficient for capturing the key challenges and needs of the industry' - important context that qualifies how POS/shrink benchmarks should be cited going forward. Source: Retail Dive (2024) →
- The share of tasks performed mainly by humans is projected to fall from 47% to 33% by 2030 as human-machine collaboration expands, with 170 million jobs created and 92 million displaced (a net gain of 78 million). Source: World Economic Forum (2025) →
Frequently asked questions
How much does custom ITAR compliance software cost?
A first release covering classification tied to your part master, a person register joined to human resources for deemed export control, licence and agreement drawdown and immutable access logging runs $90,000 to $190,000 over 14 to 20 weeks. A full platform adding enforcement in product lifecycle management and file storage, continuous rescreening and audit reporting runs $250,000 to $600,000 across 9 to 15 months.
How long does it take, and what sets the deadline?
Fourteen to twenty weeks for a first release and nine to fifteen months for a full platform. The deadline usually comes from a contract rather than a roadmap: where cybersecurity assessment obligations flow down for controlled unclassified information, the hosting boundary and access model must be designed for that from the first sprint, because retrofitting an environment boundary later is close to rebuilding the system.
Can we migrate existing classification decisions?
Yes, and it is worth doing, but treat it as a review rather than an import. Determinations currently sitting in email arrive without a consistent citation, approver or date, and loading them unchanged creates a record that looks authoritative and is not. The usual pattern is to import them as proposals and have the Empowered Official confirm the ones that matter most, prioritised by part usage.
Which integration is hardest in an export control build?
The human resources feed. People systems typically hold a work authorisation flag and a country rather than the nationality and status detail a deemed export decision requires, and privacy rules constrain how those attributes may be stored and who may see them. Contractors are worse, because many have no record in the people system at all while holding engineering vault accounts.
Do our developers need to be United States persons?
Anyone with access to production controlled technical data does, which is why architecture matters more than the staffing question. Development and testing should run on synthetic data containing no controlled technical data, production should sit in a United States region with access restricted appropriately, and support access should be brokered and logged rather than standing. Treat a firm that does not raise this unprompted as disqualified.
How often should we rescreen customers and suppliers?
Continuously against list updates plus a scheduled full sweep, not once at onboarding. The obstacle is commercial rather than technical: screening priced per transaction makes a full rescreen expensive by design, which is exactly why most companies never do it. Negotiate rescreening economics explicitly, and invest the engineering effort in false positive handling, because an ignored hit queue is worse than no control.
Who actually builds export control software of this kind?
Established trade compliance vendors own screening and declarations, and custom firms pick up the access enforcement layer they were never designed to reach. Digital Heroes fits manufacturers needing classification versioned by effective date and nationality aware enforcement across engineering systems, with signing available under American, British or Indian law. A compliance officer can verify the Fiverr Vetted Pro listing and a delivery record past two thousand projects.
How do we verify a development partner before signing?
Verify the D-U-N-S record against the entity named in your draft contract. On Clutch and Trustpilot, read only what identified client organisations wrote. Ask directly how the firm keeps controlled technical data away from its own staff, and put that answer in the agreement. Secure repository, cloud account and exported data ownership before the first invoice, since an auditor may want to see the control environment.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
Who owns the code when an agency builds my supply chain software?
You should own it outright, with full IP assignment on payment written into the contract, and you should walk away from any agency that only licenses the software to you. Insist on the code living in a repository under your own GitHub or GitLab account from day one, not handed over at the end. Digital Heroes contracts assign all custom code, database schemas, and documentation to the client; the only carve-outs should be clearly listed open source libraries.
Why do companies replace generic SCM software with custom systems?
The usual trigger is workflow mismatch: generic SCM tools model a standard distributor, so anything unusual, like mixed lot and serial tracking, consignment inventory, or customer-specific routing rules, ends up managed in spreadsheets beside the system. Companies also leave when per-user pricing punishes growth or the vendor's API cannot support needed integrations. In Digital Heroes projects, the number of spreadsheets living around the official system is the most reliable signal a team has outgrown its off-the-shelf tool.
What happens to my software if the agency shuts down or we stop working together?
Nothing dramatic, if the engagement was set up correctly: the code sits in your repository, hosting runs on your cloud account, and a handover document explains how to deploy and operate the system. Any competent replacement team can then take over in days rather than months. If the agency controls the repo, the servers, or the domain, fix that now, because renegotiating access during a dispute is the most expensive place to discover the problem.
What should I prepare before contacting a software development agency?
A one-page brief beats a 40-page requirements document: the business problem in plain words, who will use the system, the 5 to 10 workflows it must handle, the tools it must connect to, and your budget range and deadline driver. You do not need wireframes, a specification, or technical vocabulary; producing those is the agency's job during discovery. Stating a budget range up front is the single best move, because it gets you honest scoping instead of a quote engineered to win the meeting.
What does it cost to maintain custom supply chain software each year?
Budget 15 to 20 percent of the original build cost per year, so roughly $9,000 to $12,000 annually on a $60,000 system, covering hosting management, dependency updates, bug fixes, and small enhancements. Across its maintenance contracts, Digital Heroes sees supply chain systems need more upkeep than typical web apps because carrier APIs, EDI specs, and ERP versions keep changing underneath them. Hosting itself is usually minor, often $100 to $500 per month for a mid-size operation.
Is custom supply chain software cheaper than SAP over five years?
For small and mid-size operations it usually is, because SAP costs compound through licensing, implementation partners, and per-user fees, while custom costs are front-loaded. SAP Business One's published list price has run roughly $3,200 per professional user as a perpetual license plus annual maintenance near 20 percent, and the S/4HANA proposals Digital Heroes clients share are typically in the hundreds of thousands before any customization. A $60,000 to $100,000 custom build with 15 to 20 percent annual upkeep often costs less by year three for a 10 to 30 user company, and you stop paying per seat as you hire.
Who can build a custom supply chain software system?
Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other supply chain software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .